From 4b4eecdc84831b8a8904d4cda25ed6298c51bee3 Mon Sep 17 00:00:00 2001 From: mthcht Date: Mon, 4 Aug 2025 02:27:48 +0200 Subject: [PATCH] Add files via upload --- offensive_tool_keyword_network_detection.csv | 17391 +++++++++++++++++ 1 file changed, 17391 insertions(+) create mode 100644 offensive_tool_keyword_network_detection.csv diff --git a/offensive_tool_keyword_network_detection.csv b/offensive_tool_keyword_network_detection.csv new file mode 100644 index 00000000..d05ad2c4 --- /dev/null +++ b/offensive_tool_keyword_network_detection.csv @@ -0,0 +1,17391 @@ +keyword,metadata_keyword_regex,metadata_keyword_type,metadata_tool,metadata_description,metadata_tool_techniques,metadata_tool_tactics,metadata_malwares_name,metadata_groups_name,metadata_category,metadata_link,metadata_enable_endpoint_detection,metadata_enable_proxy_detection,metadata_tags,metadata_comment,metadata_severity_score,metadata_popularity_score,metadata_github_stars,metadata_github_forks,metadata_github_updated_at,metadata_github_created_at,metadata_entry_id +"*$C2_SERVER*",".{0,1000}\$C2_SERVER.{0,1000}","offensive_tool_keyword","cobaltstrike","Convert Cobalt Strike profiles to modrewrite scripts","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/cs2modrewrite","1","1","N/A","N/A","10","10","599","117","2023-01-30T17:47:51Z","2017-06-06T14:53:57Z","3948" +"*../../../../../../etc/passwd*",".{0,1000}\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/etc\/passwd.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","4097" +"*../../../../../../etc/shadow*",".{0,1000}\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/etc\/shadow.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","4098" +"*./*octopus.py*",".{0,1000}\.\/.{0,1000}octopus\.py.{0,1000}","offensive_tool_keyword","octopus","Octopus is an open source. pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S.","T1059.001 - T1105 - T1071.001 - T1219 - T1573","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/mhaskar/Octopus","1","1","#linux","N/A","10","10","750","156","2021-07-06T23:52:37Z","2019-08-30T21:09:07Z","4102" +"*./awsloot.py*",".{0,1000}\.\/awsloot\.py.{0,1000}","offensive_tool_keyword","AWS-Loot","Searches an AWS environment looking for secrets. by enumerating environment variables and source code. This tool allows quick enumeration over large sets of AWS instances and services.","T1552","TA0002","N/A","N/A","Exploitation tool","https://github.com/sebastian-mora/AWS-Loot","1","1","#linux","N/A","N/A","1","70","25","2020-02-02T00:51:56Z","2020-02-02T00:25:46Z","4107" +"*./Brutesploit*",".{0,1000}\.\/Brutesploit.{0,1000}","offensive_tool_keyword","BruteSploit","BruteSploit is a collection of method for automated Generate. Bruteforce and Manipulation wordlist with interactive shell. That can be used during a penetration test to enumerate and maybe can be used in CTF for manipulation.combine.transform and permutation some words or file text","T1110","N/A","N/A","N/A","Exploitation tool","https://github.com/screetsec/BruteSploit","1","1","#linux","N/A","N/A","8","741","263","2020-04-05T00:29:26Z","2017-05-31T17:00:51Z","4110" +"*./Dirty-Pipe*",".{0,1000}\.\/Dirty\-Pipe.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","t1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/bbaranoff/CVE-2022-0847","1","1","#linux","N/A","N/A","1","49","25","2022-03-07T15:52:23Z","2022-03-07T15:50:18Z","4123" +"*./Dirty-Pipe*",".{0,1000}\.\/Dirty\-Pipe.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/puckiestyle/CVE-2022-0847","1","1","#linux","N/A","N/A","1","2","1","2022-03-10T08:10:40Z","2022-03-08T14:46:21Z","4124" +"*./dome.py*",".{0,1000}\.\/dome\.py.{0,1000}","offensive_tool_keyword","DOME","DOME - A subdomain enumeration tool","T1583 - T1595 - T1190","TA0011 - TA0009","N/A","N/A","Reconnaissance","https://github.com/v4d1/Dome","1","1","#linux","N/A","5","6","531","74","2024-02-07T09:12:17Z","2022-02-20T15:09:40Z","4126" +"*./dynasty.sh*",".{0,1000}\.\/dynasty\.sh.{0,1000}","offensive_tool_keyword","DynastyPersist","Linux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd Service","T1055 - T1037 - T1078 - T1547 - T1546 - T1556","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/Trevohack/DynastyPersist","1","1","#linux","N/A","9","2","153","17","2024-05-16T05:19:48Z","2023-08-13T15:05:42Z","4129" +"*./fee.py*",".{0,1000}\.\/fee\.py.{0,1000}","offensive_tool_keyword","fileless-elf-exec","Execute ELF files without dropping them on disk","T1059.003 - T1055.012 - T1027.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/nnsee/fileless-elf-exec","1","1","#linux","N/A","8","5","491","49","2024-06-28T15:23:21Z","2020-01-06T12:19:34Z","4138" +"*./getExploit*",".{0,1000}\.\/getExploit.{0,1000}","offensive_tool_keyword","getExploit","Python script to explore exploits from exploit-db.com. Exist a similar script in Kali Linux. but in difference this python script will have provide more flexibility at search and download time.","T1587 - T1068 - T1211 - T1210 - T1588","TA0006 - TA0002 - TA0009 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/Gioyik/getExploit","1","1","#linux","N/A","N/A","1","43","27","2015-06-26T16:38:55Z","2015-01-03T03:26:21Z","4142" +"*./gimmeSH*",".{0,1000}\.\/gimmeSH.{0,1000}","offensive_tool_keyword","gimmeSH","gimmeSH. is a tool that generates a custom cheatsheet for Reverse Shell. File Transfer and Msfvenom within your terminal. you just need to provide the platform. your Internet protocol address and your port number.","T1059 - T1505","TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/A3h1nt/gimmeSH","1","1","#linux","N/A","N/A","2","183","28","2021-08-27T03:12:15Z","2021-08-02T07:22:15Z","4143" +"*./Havoc",".{0,1000}\.\/Havoc","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","#linux","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","4149" +"*./koadic*",".{0,1000}\.\/koadic.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","#linux","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","4160" +"*./Lalin.sh*",".{0,1000}\.\/Lalin\.sh.{0,1000}","offensive_tool_keyword","LALIN","this script automatically install any package for pentest with uptodate tools . and lazy command for run the tools like lazynmap . install another and update to new","T1588","N/A","N/A","N/A","Exploitation tool","https://github.com/screetsec/LALIN","1","1","#linux","N/A","N/A","4","366","150","2017-04-13T13:47:21Z","2016-06-10T07:53:49Z","4162" +"*./litefuzz.py*",".{0,1000}\.\/litefuzz\.py.{0,1000}","offensive_tool_keyword","litefuzz","A multi-platform fuzzer for poking at userland binaries and servers","T1587.004","TA0009","N/A","N/A","Exploitation tool","https://github.com/sec-tools/litefuzz","1","1","#linux","N/A","7","1","68","9","2024-09-15T22:43:02Z","2021-09-17T14:40:07Z","4163" +"*./manjusaka*",".{0,1000}\.\/manjusaka.{0,1000}","offensive_tool_keyword","cobaltstrike","Chinese clone of cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/YDHCUI/manjusaka","1","1","#linux","N/A","10","10","818","150","2023-05-09T03:31:53Z","2022-03-18T08:16:04Z","4166" +"*./Microsploit*",".{0,1000}\.\/Microsploit.{0,1000}","offensive_tool_keyword","BruteSploit","Fast and easy create backdoor office exploitation using module metasploit packet . Microsoft Office . Open Office . Macro attack . Buffer Overflow","T1587 - T1588 - T1608","N/A","N/A","N/A","Exploitation tool","https://github.com/screetsec/Microsploit","1","1","#linux","N/A","N/A","5","439","121","2017-07-11T16:28:27Z","2017-03-16T05:26:55Z","4167" +"*./monkey.sh*",".{0,1000}\.\/monkey\.sh.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","#linux","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","4168" +"*./Ninja.py*",".{0,1000}\.\/Ninja\.py.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1024 - T1071 - T1029 - T1569","TA0002 - TA0003 - TA0040","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","#linux","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","4172" +"*./RedGuard*",".{0,1000}\.\/RedGuard.{0,1000}","offensive_tool_keyword","RedGuard","RedGuard is a C2 front flow control tool.Can avoid Blue Teams.AVs.EDRs check.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/wikiZ/RedGuard","1","1","#linux","N/A","10","10","1466","204","2024-08-20T17:43:35Z","2022-05-08T04:02:33Z","4188" +"*./rpcrt.py*",".{0,1000}\.\/rpcrt\.py.{0,1000}","offensive_tool_keyword","POC","Remote Code Execution Exploit in the RPC Library CVE-2022-26809","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/yuanLink/CVE-2022-26809","1","1","#linux","N/A","N/A","1","61","27","2022-05-25T00:57:52Z","2022-05-01T13:19:10Z","4192" +"*./sudomy*",".{0,1000}\.\/sudomy.{0,1000}","offensive_tool_keyword","Sudomy","Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting","T1595 - T1046","TA0002","N/A","N/A","Reconnaissance","https://github.com/screetsec/Sudomy","1","1","#linux","N/A","N/A","10","2139","396","2024-06-27T10:07:42Z","2019-07-26T10:26:34Z","4212" +"*./Vegile*",".{0,1000}\.\/Vegile.{0,1000}","offensive_tool_keyword","BruteSploit","Ghost In The Shell - This tool will setting up your backdoor/rootkits when backdoor already setup it will be hidden your spesisifc process.unlimited your session in metasploit and transparent. Even when it killed. it will re-run again. There always be a procces which while run another process.So we can assume that this procces is unstopable like a Ghost in The Shell","T1587 - T1588 - T1608","N/A","N/A","N/A","Exploitation tool","https://github.com/screetsec/Vegile","1","1","#linux","N/A","N/A","8","726","164","2022-09-01T01:54:35Z","2018-01-02T05:29:48Z","4219" +"*./zabbix.py*",".{0,1000}\.\/zabbix\.py.{0,1000}","offensive_tool_keyword","POC","POC exploitaiton of zabbix saml bypass exp vulnerability cve-2022-23131 (Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML)","T1548 - T1190","TA0006 - TA0008","N/A","N/A","Exploitation tool","https://github.com/pykiller/CVE-2022-23131","1","1","#linux","N/A","N/A","1","2","0","2022-02-24T11:59:48Z","2022-02-24T11:34:27Z","4224" +"*.2miners.com*",".{0,1000}\.2miners\.com.{0,1000}","offensive_tool_keyword","lolminer","NVIDIA+AMD GPU Miner","T1496","TA0040","N/A","N/A","Cryptomining","https://github.com/Lolliedieb/lolMiner-releases","1","1","N/A","N/A","9","10","2781","601","2025-02-01T20:03:57Z","2018-10-27T20:35:03Z","4235" +"*.admin.123456.*",".{0,1000}\.admin\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4239" +"*.adminusers.txt*",".{0,1000}\.adminusers\.txt.{0,1000}","offensive_tool_keyword","msldapdump","LDAP enumeration tool implemented in Python3","T1018 - T1210.001","TA0007 - TA0001","N/A","N/A","Reconnaissance","https://github.com/dievus/msLDAPDump","1","1","N/A","N/A","N/A","3","226","31","2024-09-23T18:11:26Z","2022-12-30T23:35:40Z","4240" +"*.api.123456.*",".{0,1000}\.api\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4241" +"*.apps.123456.*",".{0,1000}\.apps\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4245" +"*.asreproast.txt*",".{0,1000}\.asreproast\.txt.{0,1000}","offensive_tool_keyword","msldapdump","LDAP enumeration tool implemented in Python3","T1018 - T1210.001","TA0007 - TA0001","N/A","N/A","Reconnaissance","https://github.com/dievus/msLDAPDump","1","1","N/A","N/A","N/A","3","226","31","2024-09-23T18:11:26Z","2022-12-30T23:35:40Z","4248" +"*.beta.123456.*",".{0,1000}\.beta\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4257" +"*.blog.123456.*",".{0,1000}\.blog\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4267" +"*.BruteRatel*",".{0,1000}\.BruteRatel.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4268" +"*.cobaltstrike*",".{0,1000}\.cobaltstrike.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4270" +"*.cobaltstrike.beacon_keys*",".{0,1000}\.cobaltstrike\.beacon_keys.{0,1000}","offensive_tool_keyword","cobaltstrike","Practice Go programming and implement CobaltStrike's Beacon in Go","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/darkr4y/geacon","1","1","N/A","N/A","10","10","1189","206","2020-10-02T10:34:37Z","2020-02-14T14:01:29Z","4272" +"*.com/dcsync/*",".{0,1000}\.com\/dcsync\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","4274" +"*.dev.123456.*",".{0,1000}\.dev\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4284" +"*.doc.bat*",".{0,1000}\.doc\.bat.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4290" +"*.doc.dll*",".{0,1000}\.doc\.dll.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4291" +"*.doc.exe*",".{0,1000}\.doc\.exe.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4292" +"*.doc.htm*",".{0,1000}\.doc\.htm.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4293" +"*.doc.iso*",".{0,1000}\.doc\.iso.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4294" +"*.doc.jar*",".{0,1000}\.doc\.jar.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4295" +"*.doc.js*",".{0,1000}\.doc\.js.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4296" +"*.doc.sfx*",".{0,1000}\.doc\.sfx.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4297" +"*.doc.vbs*",".{0,1000}\.doc\.vbs.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4298" +"*.docx.bat*",".{0,1000}\.docx\.bat.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4299" +"*.docx.exe*",".{0,1000}\.docx\.exe.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4300" +"*.docx.htm*",".{0,1000}\.docx\.htm.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4301" +"*.docx.iso*",".{0,1000}\.docx\.iso.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4302" +"*.docx.jar*",".{0,1000}\.docx\.jar.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4303" +"*.docx.js*",".{0,1000}\.docx\.js.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4305" +"*.docx.sfx*",".{0,1000}\.docx\.sfx.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4306" +"*.docx.vbs*",".{0,1000}\.docx\.vbs.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4307" +"*.events.123456.*",".{0,1000}\.events\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4316" +"*.feeds.123456.*",".{0,1000}\.feeds\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4662" +"*.files.123456.*",".{0,1000}\.files\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4663" +"*.forums.123456.*",".{0,1000}\.forums\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4664" +"*.ftp.123456.*",".{0,1000}\.ftp\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4666" +"*.get_c2profile*",".{0,1000}\.get_c2profile.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","4667" +"*.go.123456.*",".{0,1000}\.go\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4669" +"*.groups.123456.*",".{0,1000}\.groups\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4671" +"*.help.123456.*",".{0,1000}\.help\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4672" +"*.herominers.com*",".{0,1000}\.herominers\.com.{0,1000}","offensive_tool_keyword","lolminer","NVIDIA+AMD GPU Miner","T1496","TA0040","N/A","N/A","Cryptomining","https://github.com/Lolliedieb/lolMiner-releases","1","1","N/A","N/A","9","10","2781","601","2025-02-01T20:03:57Z","2018-10-27T20:35:03Z","4673" +"*.imap.123456.*",".{0,1000}\.imap\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4675" +"*.img.123456.*",".{0,1000}\.img\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4676" +"*.jpg.exe*",".{0,1000}\.jpg\.exe.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4680" +"*.jpg.iso*",".{0,1000}\.jpg\.iso.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4681" +"*.kb.123456.*",".{0,1000}\.kb\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4683" +"*.kerberoast.txt*",".{0,1000}\.kerberoast\.txt.{0,1000}","offensive_tool_keyword","msldapdump","LDAP enumeration tool implemented in Python3","T1018 - T1210.001","TA0007 - TA0001","N/A","N/A","Reconnaissance","https://github.com/dievus/msLDAPDump","1","1","N/A","N/A","N/A","3","226","31","2024-09-23T18:11:26Z","2022-12-30T23:35:40Z","4684" +"*.lab.evilginx.com*",".{0,1000}\.lab\.evilginx\.com.{0,1000}","offensive_tool_keyword","evilginx2","Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication","T1557.002 - T1114 - T1539","TA0001","N/A","BlackCat - COLDRIVER - Black Basta","Phishing","https://github.com/kgretzky/evilginx2","1","1","N/A","N/A","10","10","12879","2234","2025-01-21T15:16:19Z","2018-07-10T09:59:52Z","4687" +"*.ldapdump.txt*",".{0,1000}\.ldapdump\.txt.{0,1000}","offensive_tool_keyword","msldapdump","LDAP enumeration tool implemented in Python3","T1018 - T1210.001","TA0007 - TA0001","N/A","N/A","Reconnaissance","https://github.com/dievus/msLDAPDump","1","1","N/A","N/A","N/A","3","226","31","2024-09-23T18:11:26Z","2022-12-30T23:35:40Z","4691" +"*.link/links/windows/target/x86_64-pc-windows-gnu/release/link.exe*",".{0,1000}\.link\/links\/windows\/target\/x86_64\-pc\-windows\-gnu\/release\/link\.exe.{0,1000}","offensive_tool_keyword","link","link is a command and control framework written in rust","T1071 - T1094 - T1132 - T1008 - T1024","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/postrequest/link","1","1","N/A","N/A","10","10","575","90","2021-08-18T11:53:55Z","2021-02-02T11:15:43Z","4692" +"*.lists.123456.*",".{0,1000}\.lists\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4693" +"*.live.123456.*",".{0,1000}\.live\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4694" +"*.local.kirbi*",".{0,1000}\.local\.kirbi.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","1","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","4695" +"*.m.123456.*",".{0,1000}\.m\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4698" +"*.mail.123456.*",".{0,1000}\.mail\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4699" +"*.media.123456.*",".{0,1000}\.media\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4700" +"*.mobile.123456.*",".{0,1000}\.mobile\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4702" +"*.mysql.123456.*",".{0,1000}\.mysql\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4706" +"*.news.123456.*",".{0,1000}\.news\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4708" +"*.nimplant*",".{0,1000}\.nimplant.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","4710" +"*.onion:31337*",".{0,1000}\.onion\:31337.{0,1000}","offensive_tool_keyword","onionpipe","onionpipe forwards ports on the local host to remote Onion addresses as Tor hidden services and vice-versa.","T1090.003 - T1573.002","TA0005 - TA0011","N/A","Black Basta","Defense Evasion","https://github.com/cmars/onionpipe","1","1","N/A","N/A","10","6","553","33","2025-04-22T16:34:56Z","2022-01-23T06:52:13Z","4718" +"*.onion:8000*",".{0,1000}\.onion\:8000.{0,1000}","offensive_tool_keyword","onionpipe","onionpipe forwards ports on the local host to remote Onion addresses as Tor hidden services and vice-versa.","T1090.003 - T1573.002","TA0005 - TA0011","N/A","Black Basta","Defense Evasion","https://github.com/cmars/onionpipe","1","1","N/A","N/A","10","6","553","33","2025-04-22T16:34:56Z","2022-01-23T06:52:13Z","4719" +"*.pdf.bat*",".{0,1000}\.pdf\.bat.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4721" +"*.pdf.dll*",".{0,1000}\.pdf\.dll.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4722" +"*.pdf.exe*",".{0,1000}\.pdf\.exe.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4723" +"*.pdf.htm",".{0,1000}\.pdf\.htm.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4724" +"*.pdf.iso*",".{0,1000}\.pdf\.iso.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4725" +"*.pdf.jar*",".{0,1000}\.pdf\.jar.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4726" +"*.pdf.js*",".{0,1000}\.pdf\.js.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4728" +"*.pdf.sfx*",".{0,1000}\.pdf\.sfx.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4729" +"*.pdf.vbs*",".{0,1000}\.pdf\.vbs.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4730" +"*.photos.123456.*",".{0,1000}\.photos\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4732" +"*.php?cmd=cat+/etc/passwd*",".{0,1000}\.php\?cmd\=cat\+\/etc\/passwd.{0,1000}","offensive_tool_keyword","webshell","A collection of webshell","T1505.003 - T1100 - T1190 - T1505.004","TA0003 - TA0011 ","N/A","N/A","Persistence","https://github.com/Peaky-XD/webshell","1","1","#linux","N/A","10","1","N/A","N/A","N/A","N/A","4733" +"*.pic.123456.*",".{0,1000}\.pic\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4734" +"*.pipename_stager*",".{0,1000}\.pipename_stager.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4735" +"*.pop.123456.*",".{0,1000}\.pop\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4737" +"*.ppt.bat*",".{0,1000}\.ppt\.bat.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4739" +"*.ppt.dll*",".{0,1000}\.ppt\.dll.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4740" +"*.ppt.exe*",".{0,1000}\.ppt\.exe.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4741" +"*.ppt.htm*",".{0,1000}\.ppt\.htm.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4742" +"*.ppt.iso*",".{0,1000}\.ppt\.iso.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4743" +"*.ppt.jar*",".{0,1000}\.ppt\.jar.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4744" +"*.ppt.js*",".{0,1000}\.ppt\.js.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4745" +"*.ppt.sfx*",".{0,1000}\.ppt\.sfx.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4746" +"*.ppt.vbs*",".{0,1000}\.ppt\.vbs.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4747" +"*.pptx.bat*",".{0,1000}\.pptx\.bat.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4748" +"*.pptx.dll*",".{0,1000}\.pptx\.dll.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4749" +"*.pptx.exe*",".{0,1000}\.pptx\.exe.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4750" +"*.pptx.htm*",".{0,1000}\.pptx\.htm.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4751" +"*.pptx.iso*",".{0,1000}\.pptx\.iso.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4752" +"*.pptx.jar*",".{0,1000}\.pptx\.jar.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4753" +"*.pptx.js*",".{0,1000}\.pptx\.js.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4755" +"*.pptx.sfx*",".{0,1000}\.pptx\.sfx.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4756" +"*.pptx.vbs*",".{0,1000}\.pptx\.vbs.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4757" +"*.rar.exe*",".{0,1000}\.rar\.exe.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4858" +"*.rar.iso*",".{0,1000}\.rar\.iso.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4859" +"*.resources.123456.*",".{0,1000}\.resources\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4868" +"*.revshells.com*",".{0,1000}\.revshells\.com.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","4870" +"*.rtf.bat*",".{0,1000}\.rtf\.bat.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4873" +"*.rtf.dll*",".{0,1000}\.rtf\.dll.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4874" +"*.rtf.exe*",".{0,1000}\.rtf\.exe.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4875" +"*.rtf.htm*",".{0,1000}\.rtf\.htm.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4876" +"*.rtf.jar*",".{0,1000}\.rtf\.jar.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4877" +"*.rtf.js*",".{0,1000}\.rtf\.js.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4878" +"*.rtf.sfx*",".{0,1000}\.rtf\.sfx.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4879" +"*.rtf.vbs*",".{0,1000}\.rtf\.vbs.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4880" +"*.search.123456.*",".{0,1000}\.search\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4882" +"*.secure.123456.*",".{0,1000}\.secure\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4883" +"*.ShellcodeRDI*",".{0,1000}\.ShellcodeRDI.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","4906" +"*.sites.123456.*",".{0,1000}\.sites\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4907" +"*.SliverRPC/*",".{0,1000}\.SliverRPC\/.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","4908" +"*.smtp.123456.*",".{0,1000}\.smtp\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4909" +"*.ssl.123456.*",".{0,1000}\.ssl\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4911" +"*.stage.123456.*",".{0,1000}\.stage\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","4912" +"*.static.123456.*",".{0,1000}\.static\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4914" +"*.status.123456.*",".{0,1000}\.status\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4916" +"*.store.123456.*",".{0,1000}\.store\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4917" +"*.striker.local*",".{0,1000}\.striker\.local.{0,1000}","offensive_tool_keyword","Striker","Striker is a simple Command and Control (C2) program.","T1071 - T1071.001 - T1071.004 - T1071.005 - T1071.006 - T1071.007 - T1071.008 - T1071.009 - T1071.010 - T1071.012 - T1071.013 - T1071.014 - T1071.015 - T1071.016 - T1071.018 - T1105 - T1105.002 - T1573 - T1573.002 - T1573.003 - T1573.004 - T1573.005","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/4g3nt47/Striker","1","1","N/A","N/A","10","10","301","42","2023-05-04T18:00:05Z","2022-09-07T10:09:41Z","4918" +"*.support.123456.*",".{0,1000}\.support\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4919" +"*.torproject.org/*/download/tor/*",".{0,1000}\.torproject\.org\/.{0,1000}\/download\/tor\/.{0,1000}","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","4922" +"*.txt.bat*",".{0,1000}\.txt\.bat.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4933" +"*.txt.dll*",".{0,1000}\.txt\.dll.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4934" +"*.txt.exe*",".{0,1000}\.txt\.exe.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4935" +"*.txt.htm*",".{0,1000}\.txt\.htm.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4936" +"*.txt.iso*",".{0,1000}\.txt\.iso.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4937" +"*.txt.jar*",".{0,1000}\.txt\.jar.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4938" +"*.txt.js",".{0,1000}\.txt\.js","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4940" +"*.txt.sfx*",".{0,1000}\.txt\.sfx.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4941" +"*.txt.vbs*",".{0,1000}\.txt\.vbs.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4942" +"*.unconstrained.txt*",".{0,1000}\.unconstrained\.txt.{0,1000}","offensive_tool_keyword","msldapdump","LDAP enumeration tool implemented in Python3","T1018 - T1210.001","TA0007 - TA0001","N/A","N/A","Reconnaissance","https://github.com/dievus/msLDAPDump","1","1","N/A","N/A","N/A","3","226","31","2024-09-23T18:11:26Z","2022-12-30T23:35:40Z","4943" +"*.videos.123456.*",".{0,1000}\.videos\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4946" +"*.villain_core*",".{0,1000}\.villain_core.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","4947" +"*.vpn.123456.*",".{0,1000}\.vpn\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4949" +"*.webmail.123456.*",".{0,1000}\.webmail\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4951" +"*.wiki.123456.*",".{0,1000}\.wiki\.123456\..{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","4952" +"*.win10.config.fireeye*",".{0,1000}\.win10\.config\.fireeye.{0,1000}","offensive_tool_keyword","commando-vm","CommandoVM - a fully customizable Windows-based security distribution for penetration testing and red teaming.","T1059 - T1053 - T1055 - T1070","TA0002 - TA0004 - TA0008","N/A","N/A","Exploitation OS","https://github.com/mandiant/commando-vm","1","1","N/A","N/A","N/A","10","7168","1313","2024-09-24T19:14:18Z","2019-03-26T22:36:32Z","4953" +"*.win7.config.fireeye*",".{0,1000}\.win7\.config\.fireeye.{0,1000}","offensive_tool_keyword","commando-vm","CommandoVM - a fully customizable Windows-based security distribution for penetration testing and red teaming.","T1059 - T1053 - T1055 - T1070","TA0002 - TA0004 - TA0008","N/A","N/A","Exploitation OS","https://github.com/mandiant/commando-vm","1","1","N/A","N/A","N/A","10","7168","1313","2024-09-24T19:14:18Z","2019-03-26T22:36:32Z","4954" +"*.xls.bat*",".{0,1000}\.xls\.bat.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4957" +"*.xls.dll*",".{0,1000}\.xls\.dll.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4958" +"*.xls.exe*",".{0,1000}\.xls\.exe.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4959" +"*.xls.htm*",".{0,1000}\.xls\.htm.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4960" +"*.xls.iso*",".{0,1000}\.xls\.iso.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4961" +"*.xls.jar*",".{0,1000}\.xls\.jar.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4962" +"*.xls.js*",".{0,1000}\.xls\.js.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4963" +"*.xls.sfx*",".{0,1000}\.xls\.sfx.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4964" +"*.xls.vbs*",".{0,1000}\.xls\.vbs.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4965" +"*.xlsx.bat*",".{0,1000}\.xlsx\.bat.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4966" +"*.xlsx.dll*",".{0,1000}\.xlsx\.dll.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4967" +"*.xlsx.exe*",".{0,1000}\.xlsx\.exe.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4968" +"*.xlsx.htm*",".{0,1000}\.xlsx\.htm.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4969" +"*.xlsx.iso*",".{0,1000}\.xlsx\.iso.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4970" +"*.xlsx.jar*",".{0,1000}\.xlsx\.jar.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4971" +"*.xlsx.js*",".{0,1000}\.xlsx\.js.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4973" +"*.xlsx.sfx*",".{0,1000}\.xlsx\.sfx.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4974" +"*.xlsx.vbs*",".{0,1000}\.xlsx\.vbs.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4975" +"*.zip.exe*",".{0,1000}\.zip\.exe.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4977" +"*.zip.iso*",".{0,1000}\.zip\.iso.{0,1000}","offensive_tool_keyword","_","Suspicious extensions files","T1204 - T1212 - T1562","TA0001 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Phishing","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","4978" +"*/#kali-installer-images*",".{0,1000}\/\#kali\-installer\-images.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","4982" +"*/*_priv_esc.*",".{0,1000}\/.{0,1000}_priv_esc\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","4984" +"*/*SandboxEscapes/*",".{0,1000}\/.{0,1000}SandboxEscapes\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","4985" +"*/../../../../../../../../../../../../../../etc/apache/conf/httpd.conf*",".{0,1000}\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/etc\/apache\/conf\/httpd\.conf.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","#linux","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","4986" +"*/../../../../../../../../../../../../../../etc/apache2/conf/httpd.conf*",".{0,1000}\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/etc\/apache2\/conf\/httpd\.conf.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","#linux","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","4987" +"*/../../../../../../../../../../../../../../etc/http/conf/httpd.conf*",".{0,1000}\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/etc\/http\/conf\/httpd\.conf.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","#linux","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","4988" +"*/../../../../../../../../../../../../../../etc/http/httpd.conf*",".{0,1000}\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/etc\/http\/httpd\.conf.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","#linux","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","4989" +"*/../../../../../../../../../../../../../../etc/httpd.conf*",".{0,1000}\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/etc\/httpd\.conf.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","#linux","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","4990" +"*/../../../../../../../../../../../../../../etc/httpd/conf/httpd.conf*",".{0,1000}\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/etc\/httpd\/conf\/httpd\.conf.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","#linux","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","4991" +"*/../../../../../../../../../../../../../../etc/httpd/httpd.conf*",".{0,1000}\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/etc\/httpd\/httpd\.conf.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","#linux","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","4992" +"*/../../../../../../../../../../../../../../usr/apache/conf/httpd.conf*",".{0,1000}\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/usr\/apache\/conf\/httpd\.conf.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","#linux","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","4993" +"*/../../../../../../../../../../../../../../usr/apache2/conf/httpd.conf*",".{0,1000}\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/usr\/apache2\/conf\/httpd\.conf.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","#linux","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","4994" +"*/../../../../../../../../../../../../../../usr/local/etc/apache2/conf/httpd.conf*",".{0,1000}\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/usr\/local\/etc\/apache2\/conf\/httpd\.conf.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","#linux","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","4995" +"*/../../../../../../../../../../../../../../usr/local/etc/httpd/conf/httpd.conf*",".{0,1000}\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/usr\/local\/etc\/httpd\/conf\/httpd\.conf.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","#linux","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","4996" +"*/../../../../../../../../Volumes/webBackup/opt/apache2/conf/httpd.conf*",".{0,1000}\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/Volumes\/webBackup\/opt\/apache2\/conf\/httpd\.conf.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","#linux","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","4997" +"*/../../../../../../../../Volumes/webBackup/private/etc/httpd/httpd.conf.default*",".{0,1000}\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/Volumes\/webBackup\/private\/etc\/httpd\/httpd\.conf\.default.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","#linux","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","4998" +"*/../../../../../../../Volumes/webBackup/private/etc/httpd/httpd.conf*",".{0,1000}\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/Volumes\/webBackup\/private\/etc\/httpd\/httpd\.conf.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","#linux","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","4999" +"*/../../../../../boot.ini*",".{0,1000}\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/boot\.ini.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","5000" +"*/.aggressor.prop*",".{0,1000}\/\.aggressor\.prop.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","5002" +"*/.antproxy.php*",".{0,1000}\/\.antproxy\.php.{0,1000}","offensive_tool_keyword","antSword","cross-platform website management toolkit - abused by attackers - supports the use of web shells","T1505.003 - T1059 - T1100 - T1027 - T1219 - T1071","TA0002 - TA0003 - TA0005 - TA0011","antSword webshell","APT41 - APT15","C2","https://github.com/AntSwordProject/antSword","1","1","N/A","N/A","10","10","4010","616","2025-01-20T12:48:42Z","2016-03-11T09:28:00Z","5003" +"*/.clone.dll*",".{0,1000}\/\.clone\.dll.{0,1000}","offensive_tool_keyword","Koppeling","Adaptive DLL hijacking / dynamic export forwarding","T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/monoxgas/Koppeling","1","1","N/A","N/A","8","8","748","128","2020-07-06T14:47:57Z","2020-02-18T21:08:16Z","5009" +"*/.link/3rdparty/SharpCollection*",".{0,1000}\/\.link\/3rdparty\/SharpCollection.{0,1000}","offensive_tool_keyword","link","link is a command and control framework written in rust","T1071 - T1094 - T1132 - T1008 - T1024","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/postrequest/link","1","1","N/A","N/A","10","10","575","90","2021-08-18T11:53:55Z","2021-02-02T11:15:43Z","5018" +"*/.msf4/*",".{0,1000}\/\.msf4\/.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5026" +"*/.sliver/logs*",".{0,1000}\/\.sliver\/logs.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","5032" +"*/.ssh/RAI.pub*",".{0,1000}\/\.ssh\/RAI\.pub.{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","5039" +"*//Lh0St/InJ3C*",".{0,1000}\/\/Lh0St\/InJ3C.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","5056" +"*//localhost:1337*",".{0,1000}\/\/localhost\:1337.{0,1000}","offensive_tool_keyword","empire","Starkiller is a Frontend for Powershell Empire. It is a web application written in VueJS","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Starkiller","1","1","N/A","N/A","10","10","1461","206","2025-03-25T03:30:16Z","2020-03-09T05:48:58Z","5057" +"*//RRh0St/InJ3C*",".{0,1000}\/\/RRh0St\/InJ3C.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","5059" +"*//shuck.sh*",".{0,1000}\/\/shuck\.sh.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","5060" +"*//StaticSyscallsDump/*",".{0,1000}\/\/StaticSyscallsDump\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","5061" +"*/_distutils_hack.zip*",".{0,1000}\/_distutils_hack\.zip.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","5062" +"*/_sish/api/clients*",".{0,1000}\/_sish\/api\/clients.{0,1000}","offensive_tool_keyword","sish","An open source serveo/ngrok alternative. HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH","T1572 - T1090.002","TA0010 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antoniomika/sish","1","1","N/A","N/A","10","10","4203","325","2025-04-10T20:04:08Z","2019-02-15T15:36:23Z","5063" +"*/_sish/console*",".{0,1000}\/_sish\/console.{0,1000}","offensive_tool_keyword","sish","An open source serveo/ngrok alternative. HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH","T1572 - T1090.002","TA0010 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antoniomika/sish","1","1","N/A","N/A","10","10","4203","325","2025-04-10T20:04:08Z","2019-02-15T15:36:23Z","5064" +"*/0d1n.c*",".{0,1000}\/0d1n\.c.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5066" +"*/0d1n_view*",".{0,1000}\/0d1n_view.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","5067" +"*/0nly1 RAT*/Client.exe*",".{0,1000}\/0nly1\sRAT\s.{0,1000}\/Client\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5068" +"*/0nly1 RAT*/Server.exe *",".{0,1000}\/0nly1\sRAT\s.{0,1000}\/Server\.exe\s.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5069" +"*/0tt7/CVE-2022-23131*",".{0,1000}\/0tt7\/CVE\-2022\-23131.{0,1000}","offensive_tool_keyword","POC","POC exploitaiton of zabbix saml bypass exp vulnerability cve-2022-23131 (Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML)","T1548 - T1190","TA0004","N/A","N/A","Exploitation tool","https://github.com/0tt7/CVE-2022-23131","1","1","N/A","N/A","N/A","1","N/A","N/A","N/A","N/A","5070" +"*/0xdarkvortex-*",".{0,1000}\/0xdarkvortex\-.{0,1000}","offensive_tool_keyword","prometheus","malware C2","T1071 - T1071.001 - T1105 - T1105.002 - T1106 - T1574.002","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/paranoidninja/0xdarkvortex-MalwareDevelopment","1","1","N/A","N/A","10","10","193","66","2020-07-21T06:14:44Z","2018-09-04T15:38:53Z","5071" +"*/0xIronGoat/dirty-pipe*",".{0,1000}\/0xIronGoat\/dirty\-pipe.{0,1000}","offensive_tool_keyword","dirty-pipe","POC exploitation for dirty pipe vulnerability","T1068 - T1055 - T1003 - T1015","TA0001 - TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/0xIronGoat/dirty-pipe","1","1","N/A","N/A","N/A","1","10","9","2022-03-08T15:47:53Z","2022-03-08T15:30:45Z","5072" +"*/0xthirteen/*",".{0,1000}\/0xthirteen\/.{0,1000}","offensive_tool_keyword","SharpStay","SharpStay - .NET Persistence","T1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123","TA0003","N/A","N/A","Persistence","https://github.com/0xthirteen/SharpStay","1","1","N/A","N/A","10","5","475","97","2024-06-26T15:54:52Z","2020-01-24T22:22:07Z","5073" +"*/0xthirteen/StayKit*",".{0,1000}\/0xthirteen\/StayKit.{0,1000}","offensive_tool_keyword","StayKit","StayKit - Cobalt Strike persistence kit - StayKit is an extension for Cobalt Strike persistence by leveraging the execute_assembly function with the SharpStay .NET assembly. The aggressor script handles payload creation by reading the template files for a specific execution type.","T1059 - T1053 - T1124","TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/0xthirteen/StayKit","1","1","N/A","N/A","N/A","10","475","73","2020-01-27T14:53:31Z","2020-01-24T22:20:20Z","5074" +"*/1$a$$.exe*",".{0,1000}\/1\$a\$\$\.exe.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","1","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","5075" +"*/1.6-C2.git*",".{0,1000}\/1\.6\-C2\.git.{0,1000}","offensive_tool_keyword","1.6-C2","Using the Counter Strike 1.6 RCON protocol as a C2 Channel","T1071 - T1095 - T1572","TA0011 - TA0010","N/A","N/A","C2","https://github.com/eversinc33/1.6-C2","1","1","N/A","N/A","6","10","78","5","2025-02-19T15:34:37Z","2024-01-23T18:30:00Z","5076" +"*/1/all_in_one.7z.torrent*",".{0,1000}\/1\/all_in_one\.7z\.torrent.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","5077" +"*/1/all_in_one_p.7z*",".{0,1000}\/1\/all_in_one_p\.7z.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","5078" +"*/1/all_in_one_w.7z*",".{0,1000}\/1\/all_in_one_w\.7z.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","5079" +"*/11_Credentials.py*",".{0,1000}\/11_Credentials\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","5081" +"*/13_NoseyParker.py*",".{0,1000}\/13_NoseyParker\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","5082" +"*/17_Custom_Cracklist.py*",".{0,1000}\/17_Custom_Cracklist\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","5083" +"*/1mxml/CVE-2022-23131*",".{0,1000}\/1mxml\/CVE\-2022\-23131.{0,1000}","offensive_tool_keyword","POC","POC exploitaiton of zabbix saml bypass exp vulnerability cve-2022-23131 (Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML)","T1190 - T1550 - T1078","TA0001 - TA0003","N/A","N/A","Exploitation tool","https://github.com/1mxml/CVE-2022-23131","1","1","N/A","N/A","N/A","1","3","0","2022-02-19T03:14:47Z","2022-02-18T14:48:53Z","5084" +"*/1n73ction.php*",".{0,1000}\/1n73ction\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5085" +"*/365-Stealer.git*",".{0,1000}\/365\-Stealer\.git.{0,1000}","offensive_tool_keyword","365-Stealer","365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack","T1111 - T1566.001 - T1078.004","TA0004 - TA0001 - TA0040","N/A","N/A","Phishing","https://github.com/AlteredSecurity/365-Stealer","1","1","N/A","N/A","10","5","488","89","2024-06-08T21:03:50Z","2020-09-20T18:22:36Z","5086" +"*/3DESEncryptor.go*",".{0,1000}\/3DESEncryptor\.go.{0,1000}","offensive_tool_keyword","Augustus","Augustus is a Golang loader that execute shellcode utilizing the process hollowing technique with anti-sandbox and anti-analysis measures. The shellcode is encrypted with the Triple DES (3DES) encryption algorithm.","T1055.012 - T1027.002 - T1136.001 - T1562.001","TA0005 - TA0002 - TA0003","N/A","N/A","Exploitation tool","https://github.com/TunnelGRE/Augustus","1","1","N/A","N/A","6","2","131","26","2024-07-27T14:47:45Z","2023-08-21T15:08:40Z","5087" +"*/3snake.git*",".{0,1000}\/3snake\.git.{0,1000}","offensive_tool_keyword","3snake","Tool for extracting information from newly spawned processes","T1003 - T1110 - T1552 - T1505","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/blendin/3snake","1","1","N/A","N/A","7","8","752","109","2022-02-14T17:42:10Z","2018-02-07T21:03:15Z","5094" +"*/4luc4rdr5290/CVE-2022-0847*",".{0,1000}\/4luc4rdr5290\/CVE\-2022\-0847.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1204 - T1055 - T1003 - T1015 - T1068 - T1059 - T1047","TA0001 - TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/4luc4rdr5290/CVE-2022-0847","1","1","N/A","N/A","N/A","1","4","2","2022-03-08T20:41:15Z","2022-03-08T20:18:28Z","5095" +"*/78dc91f1A716DBBAA9E4E12C884C1CB1C27FFF2BEEED7DF1*",".{0,1000}\/78dc91f1A716DBBAA9E4E12C884C1CB1C27FFF2BEEED7DF1.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","5096" +"*/78dc91f1A716DBBAA9E4E12C884C1CB1C27FFF2BEEED7DF1*",".{0,1000}\/78dc91f1A716DBBAA9E4E12C884C1CB1C27FFF2BEEED7DF1.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","5097" +"*/888 RAT Private .exe*",".{0,1000}\/888\sRAT\sPrivate\s\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5098" +"*/9_DPAPI.py*",".{0,1000}\/9_DPAPI\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","5099" +"*/A7m3d Rat V.*.exe*",".{0,1000}\/A7m3d\sRat\sV\..{0,1000}\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5101" +"*/AbandonedCOMKeys/*",".{0,1000}\/AbandonedCOMKeys\/.{0,1000}","offensive_tool_keyword","AbandonedCOMKeys","Enumerates abandoned COM keys (specifically InprocServer32). Useful for persistence","T1547.011 - T1049 - T1087.002","TA0005 - TA0007 - TA0003","N/A","N/A","Persistence","https://github.com/matterpreter/OffensiveCSharp/tree/master/AbandonedCOMKeys","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","5103" +"*/ABPTTS.git*",".{0,1000}\/ABPTTS\.git.{0,1000}","offensive_tool_keyword","ABPTTS","TCP tunneling over HTTP/HTTPS for web application servers","T1071.001 - T1573","TA0003 - TA0011","N/A","N/A","Persistence","https://github.com/nccgroup/ABPTTS","1","1","N/A","N/A","9","8","735","151","2016-08-12T19:36:24Z","2016-07-29T21:45:57Z","5104" +"*/acarsd-info.nse*",".{0,1000}\/acarsd\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5105" +"*/Accomplice.git*",".{0,1000}\/Accomplice\.git.{0,1000}","offensive_tool_keyword","Accomplice","Tools for discovery and abuse of COM hijacks","T1120 - T1174","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/nccgroup/Accomplice","1","1","N/A","N/A","7","4","303","47","2019-10-15T21:54:09Z","2019-09-04T23:32:09Z","5106" +"*/Ace RAT v*/Server.exe*",".{0,1000}\/Ace\sRAT\sv.{0,1000}\/Server\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5107" +"*/ACE_Get-KerberosTicketCache.ps1*",".{0,1000}\/ACE_Get\-KerberosTicketCache\.ps1.{0,1000}","offensive_tool_keyword","S4UTomato","Escalate Service Account To LocalSystem via Kerberos","T1558 - T1558.002 - T1548.002 - T1078 - T1078.004","TA0006 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/wh0amitz/S4UTomato","1","1","N/A","N/A","10","4","394","76","2023-09-14T08:53:19Z","2023-07-30T11:51:57Z","5108" +"*/AceLdr.cna*",".{0,1000}\/AceLdr\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike UDRL for memory scanner evasion.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/kyleavery/AceLdr","1","1","N/A","N/A","10","10","925","164","2024-06-04T16:45:42Z","2022-08-11T00:06:09Z","5109" +"*/AceRAT-Client.exe*",".{0,1000}\/AceRAT\-Client\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5110" +"*/ACEshark.git*",".{0,1000}\/ACEshark\.git.{0,1000}","offensive_tool_keyword","ACEshark","uncover potential privilege escalation vectors by analyzing windows service configurations and Access Control Entries","T1058 - T1548","TA0004","N/A","N/A","Privilege Escalation","https://github.com/t3l3machus/ACEshark","1","1","N/A","N/A","6","2","109","19","2025-01-15T07:01:48Z","2024-12-28T10:42:29Z","5111" +"*/ACEshark.py*",".{0,1000}\/ACEshark\.py.{0,1000}","offensive_tool_keyword","ACEshark","uncover potential privilege escalation vectors by analyzing windows service configurations and Access Control Entries","T1058 - T1548","TA0004","N/A","N/A","Privilege Escalation","https://github.com/t3l3machus/ACEshark","1","1","N/A","N/A","6","2","109","19","2025-01-15T07:01:48Z","2024-12-28T10:42:29Z","5112" +"*/acheron.git*",".{0,1000}\/acheron\.git.{0,1000}","offensive_tool_keyword","acheron","indirect syscalls for AV/EDR evasion in Go assembly","T1055.012 - T1059.001 - T1059.003","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/f1zm0/acheron","1","1","N/A","N/A","N/A","4","326","39","2023-06-13T19:20:33Z","2023-04-07T10:40:33Z","5113" +"*/acheron.go*",".{0,1000}\/acheron\.go.{0,1000}","offensive_tool_keyword","acheron","indirect syscalls for AV/EDR evasion in Go assembly","T1055.012 - T1059.001 - T1059.003","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/f1zm0/acheron","1","1","N/A","N/A","N/A","4","326","39","2023-06-13T19:20:33Z","2023-04-07T10:40:33Z","5114" +"*/ACLight.git*",".{0,1000}\/ACLight\.git.{0,1000}","offensive_tool_keyword","ACLight","A tool for advanced discovery of Privileged Accounts - including Shadow Admins.","T1087 - T1003 - T1208","TA0001 - TA0006 - TA0008","N/A","N/A","Discovery","https://github.com/cyberark/ACLight","1","1","N/A","AD Enumeration","7","9","801","146","2019-09-09T06:48:45Z","2017-05-17T09:29:41Z","5115" +"*/ACLight/*",".{0,1000}\/ACLight\/.{0,1000}","offensive_tool_keyword","ACLight","A tool for advanced discovery of Privileged Accounts - including Shadow Admins.","T1087 - T1003 - T1208","TA0001 - TA0006 - TA0008","N/A","N/A","Discovery","https://github.com/cyberark/ACLight","1","1","N/A","N/A","N/A","9","801","146","2019-09-09T06:48:45Z","2017-05-17T09:29:41Z","5116" +"*/acltoolkit*",".{0,1000}\/acltoolkit.{0,1000}","offensive_tool_keyword","acltoolkit","acltoolkit is an ACL abuse swiss-army knife. It implements multiple ACL abuses","T1222.001 - T1222.002 - T1046","TA0007 - TA0040","N/A","N/A","Exploitation tool","https://github.com/zblurx/acltoolkit","1","1","N/A","N/A","N/A","2","120","12","2023-02-03T10:27:45Z","2022-01-12T22:45:49Z","5117" +"*/ActiveScanPlusPlus*",".{0,1000}\/ActiveScanPlusPlus.{0,1000}","offensive_tool_keyword","ActiveScanPlusPlus","ActiveScan++ extends Burp Suite's active and passive scanning capabilities. Designed to add minimal network overhead. it identifies application behaviour that may be of interest to advanced testers","T1583 - T1595 - T1190","TA0001 - TA0002 - TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/albinowax/ActiveScanPlusPlus","1","1","N/A","network exploitation tool","N/A","7","630","195","2025-04-17T10:47:54Z","2014-06-23T10:04:13Z","5124" +"*/AD_Enumeration_Hunt*",".{0,1000}\/AD_Enumeration_Hunt.{0,1000}","offensive_tool_keyword","AD_Enumeration_Hunt","This repository contains a collection of PowerShell scripts and commands that can be used for Active Directory (AD) penetration testing and security assessment","T1018 - T1003 - T1033 - T1087 - T1069 - T1046 - T1069.002 - T1047 - T1083","TA0001 - TA0007 - TA0005 - TA0002 - TA0003","N/A","N/A","Discovery","https://github.com/alperenugurlu/AD_Enumeration_Hunt","1","1","N/A","AD Enumeration","7","1","93","18","2023-08-05T06:10:26Z","2023-08-05T05:16:57Z","5125" +"*/AD_Miner.git*",".{0,1000}\/AD_Miner\.git.{0,1000}","offensive_tool_keyword","AD_Miner","AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses","T1087.002 - T1069 - T1018 - T1595","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/Mazars-Tech/AD_Miner","1","1","N/A","AD Enumeration","7","10","1290","131","2025-03-12T10:53:09Z","2023-09-26T12:36:59Z","5126" +"*/ADACLScanner.git*",".{0,1000}\/ADACLScanner\.git.{0,1000}","offensive_tool_keyword","ADACLScanner","A tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory .","T1222 - T1069 - T1018","TA0002 - TA0007 - TA0043","N/A","N/A","Discovery","https://github.com/canix1/ADACLScanner","1","1","N/A","AD Enumeration","7","10","1015","173","2025-04-11T14:35:08Z","2017-04-06T12:28:37Z","5129" +"*/adalanche/modules/*",".{0,1000}\/adalanche\/modules\/.{0,1000}","offensive_tool_keyword","adalanche","Active Directory ACL Visualizer and Explorer - who's really Domain Admin?","T1484 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/lkarlslund/Adalanche","1","1","N/A","AD Enumeration","10","10","1908","184","2025-03-25T13:01:45Z","2020-10-07T10:07:22Z","5130" +"*/Adamantium-Thief.git*",".{0,1000}\/Adamantium\-Thief\.git.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","1","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","5131" +"*/ADAPE.ps1*",".{0,1000}\/ADAPE\.ps1.{0,1000}","offensive_tool_keyword","ADAPE-Script","Active Directory Assessment and Privilege Escalation Script","T1178 - T1087 - T1482","TA0002 - TA0004 - TA0007","N/A","Black Basta","Privilege Escalation","https://github.com/cjoan75/ADAPE-Script","1","1","N/A","N/A","8","1","0","0","2020-07-11T00:53:24Z","2020-08-09T16:52:35Z","5132" +"*/ADAPE-Script.git*",".{0,1000}\/ADAPE\-Script\.git.{0,1000}","offensive_tool_keyword","ADAPE-Script","Active Directory Assessment and Privilege Escalation Script","T1178 - T1087 - T1482","TA0002 - TA0004 - TA0007","N/A","Black Basta","Privilege Escalation","https://github.com/cjoan75/ADAPE-Script","1","1","N/A","N/A","8","1","0","0","2020-07-11T00:53:24Z","2020-08-09T16:52:35Z","5133" +"*/AdapticClient.exe*",".{0,1000}\/AdapticClient\.exe.{0,1000}","offensive_tool_keyword","AdaptixC2","C2- Adaptix is an extensible post-exploitation and adversarial emulation framework made for penetration testers","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/Adaptix-Framework/AdaptixC2","1","1","N/A","N/A","10","10","547","114","2025-04-21T06:03:46Z","2024-08-21T18:07:05Z","5134" +"*/adaptiveC2.py*",".{0,1000}\/adaptiveC2\.py.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5135" +"*/AdaptixC2.git*",".{0,1000}\/AdaptixC2\.git.{0,1000}","offensive_tool_keyword","AdaptixC2","C2- Adaptix is an extensible post-exploitation and adversarial emulation framework made for penetration testers","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/Adaptix-Framework/AdaptixC2","1","1","N/A","N/A","10","10","547","114","2025-04-21T06:03:46Z","2024-08-21T18:07:05Z","5136" +"*/adaudit.git*",".{0,1000}\/adaudit\.git.{0,1000}","offensive_tool_keyword","adaudit","Powershell script to do domain auditing automation","T1087 - T1069 - T1046 - T1057 - T1114 - T1018","TA0007 - TA0003 - TA0004 - TA0006","N/A","N/A","Discovery","https://github.com/phillips321/adaudit","1","1","N/A","N/A","5","4","389","106","2025-04-08T06:17:54Z","2018-04-20T11:29:06Z","5137" +"*/ADAudit.ps1*",".{0,1000}\/ADAudit\.ps1.{0,1000}","offensive_tool_keyword","adaudit","Powershell script to do domain auditing automation","T1087 - T1069 - T1046 - T1057 - T1114 - T1018","TA0007 - TA0003 - TA0004 - TA0006","N/A","N/A","Discovery","https://github.com/phillips321/adaudit","1","1","N/A","N/A","5","4","389","106","2025-04-08T06:17:54Z","2018-04-20T11:29:06Z","5139" +"*/ADcheck.git*",".{0,1000}\/ADcheck\.git.{0,1000}","offensive_tool_keyword","Adcheck","Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle","T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009","N/A","N/A","Discovery","https://github.com/CobblePot59/Adcheck","1","1","N/A","N/A","10","4","315","35","2025-04-18T15:17:46Z","2024-05-10T13:54:45Z","5141" +"*/ADcheck.py*",".{0,1000}\/ADcheck\.py.{0,1000}","offensive_tool_keyword","Adcheck","Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle","T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009","N/A","N/A","Discovery","https://github.com/CobblePot59/Adcheck","1","1","N/A","N/A","10","4","315","35","2025-04-18T15:17:46Z","2024-05-10T13:54:45Z","5142" +"*/ADCollector.exe*",".{0,1000}\/ADCollector\.exe.{0,1000}","offensive_tool_keyword","ADCollector","ADCollector is a lightweight tool that enumerates the Active Directory environment","T1087 - T1018 - T1069 - T1482","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/dev-2null/ADCollector","1","1","N/A","N/A","7","7","629","81","2022-07-30T05:27:15Z","2019-05-15T06:42:20Z","5143" +"*/ADCollector.exe*",".{0,1000}\/ADCollector\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","5144" +"*/ADCollector.exe*",".{0,1000}\/ADCollector\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","5145" +"*/ADCollector.git*",".{0,1000}\/ADCollector\.git.{0,1000}","offensive_tool_keyword","ADCollector","ADCollector is a lightweight tool that enumerates the Active Directory environment","T1087 - T1018 - T1069 - T1482","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/dev-2null/ADCollector","1","1","N/A","N/A","7","7","629","81","2022-07-30T05:27:15Z","2019-05-15T06:42:20Z","5146" +"*/adconnectdump.git*",".{0,1000}\/adconnectdump\.git.{0,1000}","offensive_tool_keyword","adconnectdump","Dump Azure AD Connect credentials for Azure AD and Active Directory","T1003.004 - T1059.001 - T1082","TA0006 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/fox-it/adconnectdump","1","1","N/A","N/A","10","7","668","88","2024-11-10T22:00:16Z","2019-04-09T07:41:42Z","5148" +"*/ADCS.ps1*",".{0,1000}\/ADCS\.ps1.{0,1000}","offensive_tool_keyword","PoshADCS","attack vectors against Active Directory by abusing Active Directory Certificate Services (ADCS)","T1213.003 - T1213 - T1098.003 - T1098 - T1484.001","TA0002 - TA0003 - TA0040","N/A","N/A","Persistence","https://github.com/cfalta/PoshADCS","1","1","N/A","N/A","7","2","186","17","2021-07-07T16:47:07Z","2019-10-15T15:54:03Z","5149" +"*/adcs_enum/*",".{0,1000}\/adcs_enum\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","5151" +"*/adcs_request/adcs_request.*",".{0,1000}\/adcs_request\/adcs_request\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","5152" +"*/adcs_request/CertCli.*",".{0,1000}\/adcs_request\/CertCli\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","5153" +"*/adcs_request/certenroll.*",".{0,1000}\/adcs_request\/certenroll\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","5154" +"*/adcs_request/CertPol.*",".{0,1000}\/adcs_request\/CertPol\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","5155" +"*/ADCSCoercePotato.git*",".{0,1000}\/ADCSCoercePotato\.git.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","1","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","5156" +"*/ADCSCoercePotato/*",".{0,1000}\/ADCSCoercePotato\/.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","1","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","5157" +"*/adcs-enum.py*",".{0,1000}\/adcs\-enum\.py.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5158" +"*/adcshunter.git*",".{0,1000}\/adcshunter\.git.{0,1000}","offensive_tool_keyword","adcshunter","Uses rpcdump to locate the ADCS server and identify if ESC8 is vulnerable from unauthenticated perspective.","T1018 - T1087 - T1046 - T1201 - T1595","TA0007 - TA0043","N/A","N/A","Discovery","https://github.com/danti1988/adcshunter","1","1","N/A","N/A","7","1","80","7","2024-09-13T12:50:50Z","2023-12-14T14:31:05Z","5159" +"*/ADCSKiller*",".{0,1000}\/ADCSKiller.{0,1000}","offensive_tool_keyword","ADCSKiller","ADCSKiller is a Python-based tool designed to automate the process of discovering and exploiting Active Directory Certificate Services (ADCS) vulnerabilities. It leverages features of Certipy and Coercer to simplify the process of attacking ADCS infrastructure","T1552.004 - T1003.003 - T1114.002 - T1649","TA0006 - TA0003 - TA0005","N/A","N/A","Exploitation tool","https://github.com/grimlockx/ADCSKiller","1","1","N/A","N/A","N/A","8","710","70","2023-05-19T17:36:37Z","2023-05-19T06:51:41Z","5160" +"*/ADCSPwn.exe*",".{0,1000}\/ADCSPwn\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","5161" +"*/ADCSPwn.exe*",".{0,1000}\/ADCSPwn\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","5162" +"*/ADCSPwn.git*",".{0,1000}\/ADCSPwn\.git.{0,1000}","offensive_tool_keyword","ADCSPwn","A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service","T1550.002 - T1078.003 - T1110.003 - T1649","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/bats3c/ADCSPwn","1","1","N/A","N/A","10","9","838","127","2023-03-20T20:30:40Z","2021-07-30T15:04:41Z","5163" +"*/adcsync.git*",".{0,1000}\/adcsync\.git.{0,1000}","offensive_tool_keyword","adcsync","Use ESC1 to perform a makeshift DCSync and dump hashes","T1003.006 - T1021","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/JPG0mez/ADCSync","1","1","N/A","N/A","9","3","205","22","2023-11-02T21:41:08Z","2023-10-04T01:56:50Z","5164" +"*/adcsync.py*",".{0,1000}\/adcsync\.py.{0,1000}","offensive_tool_keyword","adcsync","Use ESC1 to perform a makeshift DCSync and dump hashes","T1003.006 - T1021","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/JPG0mez/ADCSync","1","1","N/A","N/A","9","3","205","22","2023-11-02T21:41:08Z","2023-10-04T01:56:50Z","5165" +"*/add_groupmember.py*",".{0,1000}\/add_groupmember\.py.{0,1000}","offensive_tool_keyword","acltoolkit","acltoolkit is an ACL abuse swiss-army knife. It implements multiple ACL abuses","T1222.001 - T1222.002 - T1046","TA0007 - TA0040","N/A","N/A","Exploitation tool","https://github.com/zblurx/acltoolkit","1","1","N/A","N/A","N/A","2","120","12","2023-02-03T10:27:45Z","2022-01-12T22:45:49Z","5167" +"*/add-admin.exe*",".{0,1000}\/add\-admin\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","5168" +"*/addcomputer.py*",".{0,1000}\/addcomputer\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","5169" +"*/addcomputer_LDAP_spn.py*",".{0,1000}\/addcomputer_LDAP_spn\.py.{0,1000}","offensive_tool_keyword","Ouned","The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning","T1484 - T1210","TA0001 - TA0004 - TA0005 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/synacktiv/Ouned","1","1","N/A","N/A","10","2","112","14","2025-03-29T14:20:38Z","2024-04-17T10:18:04Z","5170" +"*/addcomputer_with_spns.py*",".{0,1000}\/addcomputer_with_spns\.py.{0,1000}","offensive_tool_keyword","Ouned","The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning","T1484 - T1210","TA0001 - TA0004 - TA0005 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/synacktiv/Ouned","1","1","N/A","N/A","10","2","112","14","2025-03-29T14:20:38Z","2024-04-17T10:18:04Z","5171" +"*/Add-KeeThiefLurker.ps1*",".{0,1000}\/Add\-KeeThiefLurker\.ps1.{0,1000}","offensive_tool_keyword","Powerlurk","PowerLurk is a PowerShell toolset for building malicious WMI Event Subsriptions","T1084 - T1059.001 - T1546.003 - T1053.005","TA0003 - TA0005 - TA0002 - TA0006","N/A","N/A","Persistence","https://github.com/Sw4mpf0x/PowerLurk","1","1","N/A","N/A","10","4","384","72","2016-07-25T22:19:22Z","2016-07-13T20:07:25Z","5172" +"*/AddNewAdminUser.ahk*",".{0,1000}\/AddNewAdminUser\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","5173" +"*/Add-RemoteRegBackdoor.ps1*",".{0,1000}\/Add\-RemoteRegBackdoor\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","5174" +"*/address-info.nse*",".{0,1000}\/address\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5175" +"*/AddScriptToRegistry.ahk*",".{0,1000}\/AddScriptToRegistry\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","5176" +"*/AddTrustedDomain.py*",".{0,1000}\/AddTrustedDomain\.py.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","5177" +"*/AddTrustedDomain.vba*",".{0,1000}\/AddTrustedDomain\.vba.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","5178" +"*/AddUser-Bof.*",".{0,1000}\/AddUser\-Bof\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF that Add an admin user","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/0x3rhy/AddUser-Bof","1","1","N/A","N/A","10","10","71","14","2022-10-11T06:51:27Z","2021-08-30T10:09:20Z","5179" +"*/AddUser-Bof/*",".{0,1000}\/AddUser\-Bof\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF that Add an admin user","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/0x3rhy/AddUser-Bof","1","1","N/A","N/A","10","10","71","14","2022-10-11T06:51:27Z","2021-08-30T10:09:20Z","5180" +"*/ADeleg.exe*",".{0,1000}\/ADeleg\.exe.{0,1000}","offensive_tool_keyword","adeleg","an Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest","T1595 - T1087.002 - T1069.002","TA0007 - TA0004","N/A","N/A","Discovery","https://github.com/mtth-bfft/adeleg","1","1","N/A","N/A","8","3","294","31","2023-06-07T15:08:53Z","2022-02-09T19:47:04Z","5181" +"*/ADeleg.exe*",".{0,1000}\/ADeleg\.exe.{0,1000}","offensive_tool_keyword","Adeleginator","tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory","T1087 - T1136 - T1069","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/techspence/Adeleginator","1","1","N/A","N/A","6","2","179","18","2024-09-18T20:21:42Z","2024-03-04T03:44:52Z","5182" +"*/adeleg.git*",".{0,1000}\/adeleg\.git.{0,1000}","offensive_tool_keyword","adeleg","an Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest","T1595 - T1087.002 - T1069.002","TA0007 - TA0004","N/A","N/A","Discovery","https://github.com/mtth-bfft/adeleg","1","1","N/A","N/A","8","3","294","31","2023-06-07T15:08:53Z","2022-02-09T19:47:04Z","5183" +"*/adeleg.pdb*",".{0,1000}\/adeleg\.pdb.{0,1000}","offensive_tool_keyword","adeleg","an Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest","T1595 - T1087.002 - T1069.002","TA0007 - TA0004","N/A","N/A","Discovery","https://github.com/mtth-bfft/adeleg","1","1","N/A","N/A","8","3","294","31","2023-06-07T15:08:53Z","2022-02-09T19:47:04Z","5184" +"*/ADeleginator.git*",".{0,1000}\/ADeleginator\.git.{0,1000}","offensive_tool_keyword","Adeleginator","tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory","T1087 - T1136 - T1069","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/techspence/Adeleginator","1","1","N/A","N/A","6","2","179","18","2024-09-18T20:21:42Z","2024-03-04T03:44:52Z","5185" +"*/adfsbrute.git*",".{0,1000}\/adfsbrute\.git.{0,1000}","offensive_tool_keyword","adfsbrute","test credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacks","T1110.003 - T1110.001 - T1110","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/ricardojoserf/adfsbrute","1","1","N/A","N/A","8","2","172","33","2021-04-23T16:43:59Z","2020-10-02T16:28:35Z","5187" +"*/adfsbrute.py*",".{0,1000}\/adfsbrute\.py.{0,1000}","offensive_tool_keyword","adfsbrute","test credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacks","T1110.003 - T1110.001 - T1110","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/ricardojoserf/adfsbrute","1","1","N/A","N/A","8","2","172","33","2021-04-23T16:43:59Z","2020-10-02T16:28:35Z","5188" +"*/ADFSDump.exe*",".{0,1000}\/ADFSDump\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","5189" +"*/ADFSDump.exe*",".{0,1000}\/ADFSDump\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","5190" +"*/ADFSDump.git*",".{0,1000}\/ADFSDump\.git.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","1","N/A","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","5191" +"*/ADFSDump-PS.git*",".{0,1000}\/ADFSDump\-PS\.git.{0,1000}","offensive_tool_keyword","ADFSDump-PS","ADFSDump to assist with GoldenSAML","T1078 - T1552.004 - T1558.004","TA0006 ","N/A","N/A","Credential Access","https://github.com/ZephrFish/ADFSDump-PS","1","1","N/A","N/A","10","1","31","8","2024-05-20T00:00:19Z","2024-05-19T00:46:28Z","5192" +"*/ADFSpoof.py*",".{0,1000}\/ADFSpoof\.py.{0,1000}","offensive_tool_keyword","ADFSpoof","A python tool to forge AD FS security tokens.","T1550.004 - T1071 - T1606","TA0006 - TA0011 - TA0008","N/A","N/A","Sniffing & Spoofing","https://github.com/mandiant/ADFSpoof","1","1","N/A","N/A","10","4","391","62","2024-08-12T08:13:42Z","2019-03-20T22:30:58Z","5193" +"*/ADFSpray*",".{0,1000}\/ADFSpray.{0,1000}","offensive_tool_keyword","adfspray","Python3 tool to perform password spraying against Microsoft Online service using various methods","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/xFreed0m/ADFSpray","1","1","N/A","N/A","N/A","1","87","14","2023-03-12T00:21:34Z","2020-04-23T08:56:51Z","5194" +"*/ADFSRelay.git*",".{0,1000}\/ADFSRelay\.git.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","1","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","5195" +"*/ADFSRelay.go*",".{0,1000}\/ADFSRelay\.go.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","1","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","5196" +"*/adfs-spray.py*",".{0,1000}\/adfs\-spray\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","5197" +"*/ADHunt.git*",".{0,1000}\/ADHunt\.git.{0,1000}","offensive_tool_keyword","adhunt","Tool for exploiting Active Directory Enviroments - enumeration","T1018 - T1087 - T1087.002 - T1069 - T1069.002","TA0007 - TA0003 - TA0001","N/A","N/A","Discovery","https://github.com/karendm/ADHunt","1","1","N/A","AD Enumeration","7","1","46","10","2023-08-10T18:55:39Z","2023-06-20T13:24:10Z","5199" +"*/adhunt.py*","\/adhunt\.py","offensive_tool_keyword","adhunt","Tool for exploiting Active Directory Enviroments - enumeration","T1018 - T1087 - T1087.002 - T1069 - T1069.002","TA0007 - TA0003 - TA0001","N/A","N/A","Discovery","https://github.com/karendm/ADHunt","1","1","N/A","AD Enumeration","7","1","46","10","2023-08-10T18:55:39Z","2023-06-20T13:24:10Z","5200" +"*/adidnsdump.git*",".{0,1000}\/adidnsdump\.git.{0,1000}","offensive_tool_keyword","adidnsdump","By default any user in Active Directory can enumerate all DNS records in the Domain or Forest DNS zones. similar to a zone transfer. This tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks.","T1018 - T1087 - T1201 - T1056 - T1039","TA0005 - TA0009","N/A","N/A","Discovery","https://github.com/dirkjanm/adidnsdump","1","1","N/A","N/A","N/A","10","997","118","2025-04-04T09:28:20Z","2019-04-24T17:18:46Z","5201" +"*/ad-ldap-enum.git*",".{0,1000}\/ad\-ldap\-enum\.git.{0,1000}","offensive_tool_keyword","ad-ldap-enum","An LDAP based Active Directory user and group enumeration tool","T1087 - T1087.001 - T1018 - T1069 - T1069.002","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/CroweCybersecurity/ad-ldap-enum","1","1","N/A","AD Enumeration","6","4","308","66","2023-02-10T19:07:34Z","2015-08-25T19:38:39Z","5202" +"*/adlogin.ps1*",".{0,1000}\/adlogin\.ps1.{0,1000}","offensive_tool_keyword","Minimalistic-offensive","A repository of tools for pentesting of restricted and isolated environments.","T1110 - T1046 - T1021 - T1203 - T1485","TA0006 - TA0007 - TA0008","N/A","Dispossessor","Discovery","https://github.com/InfosecMatter/Minimalistic-offensive-security-tools","1","1","N/A","N/A","7","6","562","121","2021-10-26T11:04:46Z","2020-05-10T17:40:31Z","5203" +"*/adm2sys.py*",".{0,1000}\/adm2sys\.py.{0,1000}","offensive_tool_keyword","PyExec","This is a very simple privilege escalation technique from admin to System. This is the same technique PSExec uses.","T1134 - T1055 - T1548.002","TA0004 - TA0005 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/OlivierLaflamme/PyExec","1","1","N/A","N/A","9","1","11","7","2019-09-11T13:56:04Z","2019-09-11T13:54:15Z","5204" +"*/admin/smb/ms17_010_command*",".{0,1000}\/admin\/smb\/ms17_010_command.{0,1000}","offensive_tool_keyword","metasploit","exploit used by Dispossessor ransomware group","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","5205" +"*/admin_persistence_winlogon.c*",".{0,1000}\/admin_persistence_winlogon\.c.{0,1000}","offensive_tool_keyword","OffensiveCpp","C/C++ snippets that can be handy in specific offensive scenarios","T1055 - T1047 - T1105 - T1117 - T1129 - T1135 - T1203","TA0002 - TA0003 - TA0006 - TA0007 - TA0009","N/A","N/A","Exploitation tool","https://github.com/lsecqt/OffensiveCpp","1","1","N/A","N/A","10","8","700","83","2025-01-26T08:05:48Z","2023-04-05T09:39:33Z","5206" +"*/Admin2Sys.git*",".{0,1000}\/Admin2Sys\.git.{0,1000}","offensive_tool_keyword","Admin2Sys","Admin2Sys it's a C++ malware to escalate privileges from Administrator account to NT AUTORITY SYSTEM","T1055.002 - T1078.003 - T1068","TA0002 - TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/S12cybersecurity/Admin2Sys","1","1","N/A","N/A","10","1","54","19","2023-05-01T19:32:41Z","2023-05-01T18:50:51Z","5207" +"*/admin-panels.txt*",".{0,1000}\/admin\-panels\.txt.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","5208" +"*/adPEAS.git*",".{0,1000}\/adPEAS\.git.{0,1000}","offensive_tool_keyword","adPEAS","adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others","T1016 - T1087.002 - T1482 - T1207 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/61106960/adPEAS","1","1","N/A","N/A","8","10","1095","132","2025-04-01T16:16:15Z","2020-12-23T08:10:19Z","5209" +"*/adPEAS.ps1*",".{0,1000}\/adPEAS\.ps1.{0,1000}","offensive_tool_keyword","adPEAS","adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others","T1016 - T1087.002 - T1482 - T1207 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/61106960/adPEAS","1","1","N/A","N/A","8","10","1095","132","2025-04-01T16:16:15Z","2020-12-23T08:10:19Z","5210" +"*/adPEAS-Light.ps1*",".{0,1000}\/adPEAS\-Light\.ps1.{0,1000}","offensive_tool_keyword","adPEAS","adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others","T1016 - T1087.002 - T1482 - T1207 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/61106960/adPEAS","1","1","N/A","N/A","8","10","1095","132","2025-04-01T16:16:15Z","2020-12-23T08:10:19Z","5211" +"*/ADSearch.exe*",".{0,1000}\/ADSearch\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","5215" +"*/ADSearch.exe*",".{0,1000}\/ADSearch\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","5216" +"*/ADSearch.git*",".{0,1000}\/ADSearch\.git.{0,1000}","offensive_tool_keyword","adsearch","A tool to help query AD via the LDAP protocol","T1087 - T1069.002 - T1018","TA0003 - TA0002 - TA0007","N/A","N/A","Reconnaissance","https://github.com/tomcarver16/ADSearch","1","1","N/A","N/A","N/A","6","536","57","2024-09-25T16:13:13Z","2020-06-17T22:21:41Z","5217" +"*/afp-brute.nse*",".{0,1000}\/afp\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5221" +"*/afp-ls.nse*",".{0,1000}\/afp\-ls\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5222" +"*/afp-path-vuln.nse*",".{0,1000}\/afp\-path\-vuln\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5223" +"*/afp-serverinfo.nse*",".{0,1000}\/afp\-serverinfo\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5224" +"*/afp-showmount.nse*",".{0,1000}\/afp\-showmount\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5225" +"*/afrog-pocs/*",".{0,1000}\/afrog\-pocs\/.{0,1000}","offensive_tool_keyword","afrog","A tool for finding vulnerabilities","T1083 - T1065 - T1204 - T1046","TA0007 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/zan8in/afrog","1","1","N/A","N/A","N/A","10","3791","414","2025-04-22T07:32:19Z","2022-02-24T06:00:32Z","5226" +"*/agent.ps1.oct*",".{0,1000}\/agent\.ps1\.oct.{0,1000}","offensive_tool_keyword","octopus","Octopus is an open source. pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S.","T1059.001 - T1105 - T1071.001 - T1219 - T1573","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/mhaskar/Octopus","1","1","N/A","N/A","10","10","750","156","2021-07-06T23:52:37Z","2019-08-30T21:09:07Z","5228" +"*/agent/C/src/*",".{0,1000}\/agent\/C\/src\/.{0,1000}","offensive_tool_keyword","Striker","Striker is a simple Command and Control (C2) program.","T1071 - T1071.001 - T1071.004 - T1071.005 - T1071.006 - T1071.007 - T1071.008 - T1071.009 - T1071.010 - T1071.012 - T1071.013 - T1071.014 - T1071.015 - T1071.016 - T1071.018 - T1105 - T1105.002 - T1573 - T1573.002 - T1573.003 - T1573.004 - T1573.005","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/4g3nt47/Striker","1","1","N/A","N/A","10","10","301","42","2023-05-04T18:00:05Z","2022-09-07T10:09:41Z","5230" +"*/agent/stagers/dropbox.py*",".{0,1000}\/agent\/stagers\/dropbox\.py.{0,1000}","offensive_tool_keyword","EmbedInHTML","What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.","T1027 - T1566.001","TA0005 - TA0002","N/A","N/A","Phishing","https://github.com/Arno0x/EmbedInHTML","1","1","N/A","N/A","10","5","485","119","2017-09-27T13:16:06Z","2017-09-11T07:17:20Z","5234" +"*/agent_code/Apollo/*",".{0,1000}\/agent_code\/Apollo\/.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","5235" +"*/agent_code/Athena*",".{0,1000}\/agent_code\/Athena.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5236" +"*/agent_code/cmd_executor*",".{0,1000}\/agent_code\/cmd_executor.{0,1000}","offensive_tool_keyword","mythic","mythic C2 agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/freyja/","1","1","N/A","N/A","10","10","54","13","2024-10-29T17:32:07Z","2022-09-28T17:20:04Z","5237" +"*/agent_code/dll.go*",".{0,1000}\/agent_code\/dll\.go.{0,1000}","offensive_tool_keyword","mythic","Cross-platform post-exploitation HTTP Command & Control agent written in golang","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/merlin","1","1","N/A","N/A","10","10","94","16","2025-04-16T13:05:47Z","2021-01-25T12:36:46Z","5238" +"*/agent_code/merlin.*",".{0,1000}\/agent_code\/merlin\..{0,1000}","offensive_tool_keyword","mythic","Cross-platform post-exploitation HTTP Command & Control agent written in golang","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/merlin","1","1","N/A","N/A","10","10","94","16","2025-04-16T13:05:47Z","2021-01-25T12:36:46Z","5239" +"*/agent_code/powershell_executor*",".{0,1000}\/agent_code\/powershell_executor.{0,1000}","offensive_tool_keyword","mythic","mythic C2 agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/freyja/","1","1","N/A","N/A","10","10","54","13","2024-10-29T17:32:07Z","2022-09-28T17:20:04Z","5240" +"*/agent_code/sh_executor*",".{0,1000}\/agent_code\/sh_executor.{0,1000}","offensive_tool_keyword","mythic","mythic C2 agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/freyja/","1","1","N/A","N/A","10","10","54","13","2024-10-29T17:32:07Z","2022-09-28T17:20:04Z","5241" +"*/agent_code/zsh_executor*",".{0,1000}\/agent_code\/zsh_executor.{0,1000}","offensive_tool_keyword","mythic","mythic C2 agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/freyja/","1","1","N/A","N/A","10","10","54","13","2024-10-29T17:32:07Z","2022-09-28T17:20:04Z","5242" +"*/agent_functions/*.py*",".{0,1000}\/agent_functions\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5243" +"*/agent_icons/athena.svg*",".{0,1000}\/agent_icons\/athena\.svg.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5244" +"*/agents/thanatos/commands/*",".{0,1000}\/agents\/thanatos\/commands\/.{0,1000}","offensive_tool_keyword","mythic","Thanatos is a Windows and Linux C2 agent written in rust.","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/thanatos","1","1","N/A","N/A","10","10","333","49","2024-12-19T19:07:03Z","2022-03-07T20:35:33Z","5245" +"*/AggressiveClean.cna*",".{0,1000}\/AggressiveClean\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","New UAC bypass for Silent Cleanup for CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EncodeGroup/UAC-SilentClean","1","1","N/A","N/A","10","10","192","31","2021-07-14T13:51:02Z","2020-10-07T13:25:21Z","5246" +"*/aggressor/*.java*",".{0,1000}\/aggressor\/.{0,1000}\.java.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","5247" +"*/aggressor/spoolsystem.cna*",".{0,1000}\/aggressor\/spoolsystem\.cna.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","5248" +"*/aggressor-powerview*",".{0,1000}\/aggressor\-powerview.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","5249" +"*/AggressorScripts*",".{0,1000}\/AggressorScripts.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5250" +"*/AggressorScripts*",".{0,1000}\/AggressorScripts.{0,1000}","offensive_tool_keyword","cobaltstrike","Aggressor scripts for use with Cobalt Strike 3.0+","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/C0axx/AggressorScripts","1","1","N/A","N/A","10","10","39","12","2019-10-08T12:00:53Z","2019-01-11T15:48:18Z","5251" +"*/AggressorScripts*",".{0,1000}\/AggressorScripts.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike toolkit","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/1135/1135-CobaltStrike-ToolKit","1","1","N/A","N/A","10","10","150","35","2023-12-01T03:18:35Z","2019-02-22T09:36:44Z","5252" +"*/ahmedkhlief/Ninja/*",".{0,1000}\/ahmedkhlief\/Ninja\/.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1024 - T1071 - T1029 - T1569","TA0002 - TA0003 - TA0040","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","5261" +"*/ahrixia/CVE_2022_0847*",".{0,1000}\/ahrixia\/CVE_2022_0847.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1204 - T1055 - T1003 - T1015 - T1068 - T1059 - T1047","TA0001 - TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/ahrixia/CVE_2022_0847","1","1","N/A","N/A","N/A","1","21","15","2022-03-08T13:15:35Z","2022-03-08T12:43:43Z","5262" +"*/ajp-auth.nse*",".{0,1000}\/ajp\-auth\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5263" +"*/ajp-brute.nse*",".{0,1000}\/ajp\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5264" +"*/ajp-headers.nse*",".{0,1000}\/ajp\-headers\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5265" +"*/ajp-methods.nse*",".{0,1000}\/ajp\-methods\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5266" +"*/ajp-request.nse*",".{0,1000}\/ajp\-request\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5267" +"*/AKID-RATV04.exe*",".{0,1000}\/AKID\-RATV04\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5268" +"*/alan.log*",".{0,1000}\/alan\.log.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","#logfile #linux","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","5269" +"*/Alan.v*.zip*",".{0,1000}\/Alan\.v.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","5270" +"*/Alaris.sln*",".{0,1000}\/Alaris\.sln.{0,1000}","offensive_tool_keyword","cobaltstrike","A protective and Low Level Shellcode Loader that defeats modern EDR systems.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/cribdragg3r/Alaris","1","1","N/A","N/A","10","10","903","142","2024-03-20T15:50:57Z","2020-02-22T15:42:37Z","5271" +"*/Alcatraz.exe*",".{0,1000}\/Alcatraz\.exe.{0,1000}","offensive_tool_keyword","Alcatraz","x64 binary obfuscator","T1027 - T1140","TA0004 - TA0042","N/A","N/A","Defense Evasion","https://github.com/weak1337/Alcatraz","1","1","N/A","N/A","10","10","1808","267","2023-07-14T14:19:01Z","2022-12-21T17:27:56Z","5272" +"*/Alcatraz.git*",".{0,1000}\/Alcatraz\.git.{0,1000}","offensive_tool_keyword","Alcatraz","x64 binary obfuscator","T1027 - T1140","TA0004 - TA0042","N/A","N/A","Defense Evasion","https://github.com/weak1337/Alcatraz","1","1","N/A","N/A","10","10","1808","267","2023-07-14T14:19:01Z","2022-12-21T17:27:56Z","5273" +"*/Alcatraz/files/*/Alcatraz.zip*",".{0,1000}\/Alcatraz\/files\/.{0,1000}\/Alcatraz\.zip.{0,1000}","offensive_tool_keyword","Alcatraz","x64 binary obfuscator","T1027 - T1140","TA0004 - TA0042","N/A","N/A","Defense Evasion","https://github.com/weak1337/Alcatraz","1","1","N/A","N/A","10","10","1808","267","2023-07-14T14:19:01Z","2022-12-21T17:27:56Z","5274" +"*/Alcatraz/x64*",".{0,1000}\/Alcatraz\/x64.{0,1000}","offensive_tool_keyword","Alcatraz","x64 binary obfuscator","T1027 - T1140","TA0004 - TA0042","N/A","N/A","Defense Evasion","https://github.com/weak1337/Alcatraz","1","1","N/A","N/A","10","10","1808","267","2023-07-14T14:19:01Z","2022-12-21T17:27:56Z","5275" +"*/Alcatraz-gui*",".{0,1000}\/Alcatraz\-gui.{0,1000}","offensive_tool_keyword","Alcatraz","x64 binary obfuscator","T1027 - T1140","TA0004 - TA0042","N/A","N/A","Defense Evasion","https://github.com/weak1337/Alcatraz","1","1","N/A","N/A","10","10","1808","267","2023-07-14T14:19:01Z","2022-12-21T17:27:56Z","5276" +"*/all/pupyutils/*.py*",".{0,1000}\/all\/pupyutils\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","5277" +"*/All_attack.txt*",".{0,1000}\/All_attack\.txt.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","5278" +"*/all_in_one_enum.ps1*",".{0,1000}\/all_in_one_enum\.ps1.{0,1000}","offensive_tool_keyword","Powershell-Scripts-for-Hackers-and-Pentesters","","T1059.001 - T1119 - T1027 - T1016 - T1056.001","TA0002 - TA0009 - TA0005 - TA0007 - TA0010","N/A","N/A","Collection","https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters","1","1","N/A","N/A","10","5","415","49","2025-02-23T09:05:44Z","2023-02-27T14:27:32Z","5279" +"*/allseeingeye-info.nse*",".{0,1000}\/allseeingeye\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5280" +"*/amass/releases/download/*",".{0,1000}\/amass\/releases\/download\/.{0,1000}","offensive_tool_keyword","Amass","The OWASP Amass Project performs network mapping of attack surfaces and external asset discovery using open source information gathering and active reconnaissance techniques.","T1595 - T1596 - T1018 - T1482","TA0007 - TA0043 - ","N/A","EMBER BEAR","Reconnaissance","https://github.com/caffix/amass","1","1","#linux","N/A","5","","N/A","","","","5285" +"*/amass/wordlists*",".{0,1000}\/amass\/wordlists.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5286" +"*/Amnesiac.git*",".{0,1000}\/Amnesiac\.git.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","5289" +"*/Amnesiac.ps1*",".{0,1000}\/Amnesiac\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","5290" +"*/amqp-info.nse*",".{0,1000}\/amqp\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5294" +"*/amsi.py*",".{0,1000}\/amsi\.py.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5295" +"*/Amsi_Bypass_In_2023*",".{0,1000}\/Amsi_Bypass_In_2023.{0,1000}","offensive_tool_keyword","Amsi_Bypass","Amsi Bypass payload that works on Windwos 11","T1055 - T1055.012 - T1562 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/senzee1984/Amsi_Bypass_In_2023","1","1","N/A","N/A","8","4","377","67","2023-07-30T19:17:23Z","2023-07-30T16:14:19Z","5296" +"*/AMSI_patch.git*",".{0,1000}\/AMSI_patch\.git.{0,1000}","offensive_tool_keyword","AMSI_patch","Patching AmsiOpenSession by forcing an error branching","T1055 - T1055.001 - T1112","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/AMSI_patch","1","1","N/A","N/A","8","2","145","29","2023-08-02T02:27:00Z","2023-02-03T18:11:37Z","5297" +"*/AmsiBypass.*",".{0,1000}\/AmsiBypass\..{0,1000}","offensive_tool_keyword","AmsiBypass","bypassing Anti-Malware Scanning Interface (AMSI) features","T1548.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/S3cur3Th1sSh1t/Amsi-Bypass-Powershell","1","1","N/A","N/A","10","10","1890","311","2024-11-28T10:31:15Z","2019-05-14T06:09:25Z","5298" +"*/Amsi-Bypass-Powershell.git*",".{0,1000}\/Amsi\-Bypass\-Powershell\.git.{0,1000}","offensive_tool_keyword","AmsiBypass","bypassing Anti-Malware Scanning Interface (AMSI) features","T1548.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/S3cur3Th1sSh1t/Amsi-Bypass-Powershell","1","1","N/A","N/A","10","10","1890","311","2024-11-28T10:31:15Z","2019-05-14T06:09:25Z","5299" +"*/Amsi-Killer.git*",".{0,1000}\/Amsi\-Killer\.git.{0,1000}","offensive_tool_keyword","Amsi-Killer","Lifetime AMSI bypass","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/ZeroMemoryEx/Amsi-Killer","1","1","N/A","N/A","10","7","624","90","2023-09-26T00:49:22Z","2023-02-26T19:05:14Z","5300" +"*/amsikiller.py*",".{0,1000}\/amsikiller\.py.{0,1000}","offensive_tool_keyword","SharpShooter","Payload Generation Framework","T1027 - T1059","TA0042","N/A","N/A","Resource Development","https://github.com/mdsecactivebreach/SharpShooter","1","1","N/A","N/A","10","10","1859","361","2024-08-21T12:09:54Z","2018-03-06T20:04:20Z","5301" +"*/AmsiOpenSession.exe*",".{0,1000}\/AmsiOpenSession\.exe.{0,1000}","offensive_tool_keyword","AMSI_patch","Patching AmsiOpenSession by forcing an error branching","T1055 - T1055.001 - T1112","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/AMSI_patch","1","1","N/A","N/A","8","2","145","29","2023-08-02T02:27:00Z","2023-02-03T18:11:37Z","5302" +"*/AMSI-Provider.git*",".{0,1000}\/AMSI\-Provider\.git.{0,1000}","offensive_tool_keyword","AMSI-Provider","A fake AMSI Provider which can be used for persistence","T1546.013 - T1574.012","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/netbiosX/AMSI-Provider","1","1","N/A","N/A","10","2","150","16","2021-05-16T16:56:15Z","2021-05-15T16:18:47Z","5303" +"*/AMSITrigger.git*",".{0,1000}\/AMSITrigger\.git.{0,1000}","offensive_tool_keyword","AMSITrigger","AMSITrigger will identify all of the malicious strings in a powershell file by repeatedly making calls to AMSI using AMSIScanBuffer - line by line. On receiving an AMSI_RESULT_DETECTED response code the line will then be scrutinised to identify the individual triggers","T1059.001 - T1218.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/RythmStick/AMSITrigger","1","1","N/A","https://www.rythmstick.net/posts/amsitrigger/","10","10","1195","166","2022-08-21T22:37:23Z","2020-05-27T09:17:19Z","5305" +"*/amsiwala.exe*",".{0,1000}\/amsiwala\.exe.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","5306" +"*/Analyzer-Session.log*",".{0,1000}\/Analyzer\-Session\.log.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","#logfile #linux","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","5307" +"*/AndrewSpecial.git*",".{0,1000}\/AndrewSpecial\.git.{0,1000}","offensive_tool_keyword","AndrewSpecial","AndrewSpecial - dumping lsass memory stealthily","T1003.001 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/hoangprod/AndrewSpecial","1","1","N/A","N/A","10","4","386","98","2019-06-02T02:49:28Z","2019-01-18T19:12:09Z","5308" +"*/android/pupydroid/*",".{0,1000}\/android\/pupydroid\/.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","5309" +"*/AndroRat Binder.exe*",".{0,1000}\/AndroRat\sBinder\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","QUILTED TIGER","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5310" +"*/ANGRYPUPPY.cna*",".{0,1000}\/ANGRYPUPPY\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Bloodhound Attack Path Automation in CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/vysecurity/ANGRYPUPPY","1","1","N/A","N/A","10","10","316","87","2020-04-26T17:35:31Z","2017-07-11T14:18:07Z","5311" +"*/Ani-Shell.php*",".{0,1000}\/Ani\-Shell\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5312" +"*/Annoying1.exe*",".{0,1000}\/Annoying1\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5313" +"*/anonymous rat v1.0.exe*",".{0,1000}\/anonymous\srat\sv1\.0\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5314" +"*/Ant Attack.exe*",".{0,1000}\/Ant\sAttack\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5315" +"*/antak.aspx*",".{0,1000}\/antak\.aspx.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","5316" +"*/anthemtotheego/CredBandit*",".{0,1000}\/anthemtotheego\/CredBandit.{0,1000}","offensive_tool_keyword","cobaltstrike","Proof of concept Beacon Object File (BOF) that uses static x64 syscalls to perform a complete in memory dump of a process and send that back through your already existing Beacon communication channel","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/xforcered/CredBandit","1","1","N/A","N/A","10","10","240","26","2021-07-14T17:42:41Z","2021-03-17T15:19:33Z","5317" +"*/anti_analysis.exe*",".{0,1000}\/anti_analysis\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","5318" +"*/anti_debug.exe*",".{0,1000}\/anti_debug\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","5319" +"*/anti_methods/antivm.ps1*",".{0,1000}\/anti_methods\/antivm\.ps1.{0,1000}","offensive_tool_keyword","SomalifuscatorV2","windows batch obfuscator","T1027 - T1497 - T1057","TA0005","N/A","N/A","Defense Evasion","https://github.com/KDot227/SomalifuscatorV2","1","1","N/A","N/A","10","4","315","42","2025-01-19T04:30:49Z","2022-09-23T00:46:51Z","5320" +"*/Antichat Shell v1.3.php*",".{0,1000}\/Antichat\sShell\sv1\.3\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5321" +"*/AntiSandbox.go*",".{0,1000}\/AntiSandbox\.go.{0,1000}","offensive_tool_keyword","goMatrixC2","C2 leveraging Matrix/Element Messaging Platform as Backend to control Implants in goLang.","T1090 - T1027 - T1071","TA0011 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/n1k7l4i/goMatrixC2","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5322" +"*/AntiSandbox.go*",".{0,1000}\/AntiSandbox\.go.{0,1000}","offensive_tool_keyword","goZulipC2","C2 leveraging Zulip Messaging Platform as Backend.","T1090 - T1090.003 - T1071 - T1071.001","TA0011 - TA0009","N/A","N/A","C2","https://github.com/n1k7l4i/goZulipC2","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5323" +"*/AntiTamper.exe*",".{0,1000}\/AntiTamper\.exe.{0,1000}","offensive_tool_keyword","ConfuserEx","ConfuserEx is a widely used open source obfuscator often found in malware","T1027 - T1045","TA0005 ","N/A","N/A","Defense Evasion","https://github.com/yck1509/ConfuserEx","1","1","N/A","N/A","6","10","3629","1661","2019-05-14T14:23:56Z","2014-03-28T07:00:26Z","5324" +"*/antSword.git*",".{0,1000}\/antSword\.git.{0,1000}","offensive_tool_keyword","antSword","cross-platform website management toolkit - abused by attackers - supports the use of web shells","T1505.003 - T1059 - T1100 - T1027 - T1219 - T1071","TA0002 - TA0003 - TA0005 - TA0011","antSword webshell","APT41 - APT15","C2","https://github.com/AntSwordProject/antSword","1","1","N/A","N/A","10","10","4010","616","2025-01-20T12:48:42Z","2016-03-11T09:28:00Z","5325" +"*/antsword.tar.gz*",".{0,1000}\/antsword\.tar\.gz.{0,1000}","offensive_tool_keyword","antSword","cross-platform website management toolkit - abused by attackers - supports the use of web shells","T1505.003 - T1059 - T1100 - T1027 - T1219 - T1071","TA0002 - TA0003 - TA0005 - TA0011","antSword webshell","APT41 - APT15","C2","https://github.com/AntSwordProject/antSword","1","1","N/A","N/A","10","10","4010","616","2025-01-20T12:48:42Z","2016-03-11T09:28:00Z","5327" +"*/AntSword/archive/master.tar*",".{0,1000}\/AntSword\/archive\/master\.tar.{0,1000}","offensive_tool_keyword","antSword","cross-platform website management toolkit - abused by attackers - supports the use of web shells","T1505.003 - T1059 - T1100 - T1027 - T1219 - T1071","TA0002 - TA0003 - TA0005 - TA0011","antSword webshell","APT41 - APT15","C2","https://github.com/AntSwordProject/antSword","1","1","N/A","N/A","10","10","4010","616","2025-01-20T12:48:42Z","2016-03-11T09:28:00Z","5328" +"*/antSword/releases/tag/2*",".{0,1000}\/antSword\/releases\/tag\/2.{0,1000}","offensive_tool_keyword","antSword","cross-platform website management toolkit - abused by attackers - supports the use of web shells","T1505.003 - T1059 - T1100 - T1027 - T1219 - T1071","TA0002 - TA0003 - TA0005 - TA0011","antSword webshell","APT41 - APT15","C2","https://github.com/AntSwordProject/antSword","1","1","N/A","N/A","10","10","4010","616","2025-01-20T12:48:42Z","2016-03-11T09:28:00Z","5329" +"*/AntSword_*.php*",".{0,1000}\/AntSword_.{0,1000}\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5330" +"*/antSword-master.zip*",".{0,1000}\/antSword\-master\.zip.{0,1000}","offensive_tool_keyword","antSword","cross-platform website management toolkit - abused by attackers - supports the use of web shells","T1505.003 - T1059 - T1100 - T1027 - T1219 - T1071","TA0002 - TA0003 - TA0005 - TA0011","antSword webshell","APT41 - APT15","C2","https://github.com/AntSwordProject/antSword","1","1","N/A","N/A","10","10","4010","616","2025-01-20T12:48:42Z","2016-03-11T09:28:00Z","5331" +"*/antx-code/CVE-2022-0847*",".{0,1000}\/antx\-code\/CVE\-2022\-0847.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","t1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/antx-code/CVE-2022-0847","1","1","N/A","N/A","N/A","1","58","21","2022-03-08T09:14:25Z","2022-03-08T09:10:51Z","5332" +"*/AoratosWin/*",".{0,1000}\/AoratosWin\/.{0,1000}","offensive_tool_keyword","AoratosWin","A tool that removes traces of executed applications on Windows OS.","T1070 - T1564","TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/PinoyWH1Z/AoratosWin","1","1","N/A","N/A","N/A","2","120","16","2022-09-04T09:15:35Z","2022-09-04T09:04:35Z","5337" +"*/APC_Injection.cpp*",".{0,1000}\/APC_Injection\.cpp.{0,1000}","offensive_tool_keyword","GlllPowerloader","Sample to bypass AV/EDR and upload to transfer.sh","T1059.001 - T1202 - T1105 - T1027 - T1036 - T1070 - T1031 - T1071 - T1048","TA0005 - TA0004 - TA0002 - TA0011 - TA0010","N/A","N/A","Defense Evasion","https://github.com/INotGreen/GlllPowerloader","1","1","N/A","N/A","10","5","451","105","2024-04-12T07:28:24Z","2022-04-26T12:10:58Z","5339" +"*/apc_injection.exe*",".{0,1000}\/apc_injection\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","5340" +"*/APCLdr.*",".{0,1000}\/APCLdr\..{0,1000}","offensive_tool_keyword","APCLdr","APCLdr: Payload Loader With Evasion Features","T1027 - T1055 - T1055.002 - T1055.003 - T1070 - T1070.004 - T1071 - T1106 - T1574.001","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/NUL0x4C/APCLdr","1","1","N/A","N/A","N/A","4","316","54","2023-01-22T04:24:33Z","2023-01-21T18:09:36Z","5341" +"*/api/admin/shutdown?token=*",".{0,1000}\/api\/admin\/shutdown\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5343" +"*/api/agents/*/kill?token=*",".{0,1000}\/api\/agents\/.{0,1000}\/kill\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5344" +"*/api/agents/all/kill?token=*",".{0,1000}\/api\/agents\/all\/kill\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5345" +"*/api/agents/all/shell?token=*",".{0,1000}\/api\/agents\/all\/shell\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5346" +"*/api/agents/CXPLDTZCKFNT3SLT/shell?*",".{0,1000}\/api\/agents\/CXPLDTZCKFNT3SLT\/shell\?.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5347" +"*/api/agents/stale?token=*",".{0,1000}\/api\/agents\/stale\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5348" +"*/api/agents/XMY2H2ZPFWNPGEAP?token=*",".{0,1000}\/api\/agents\/XMY2H2ZPFWNPGEAP\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5349" +"*/api/listeners/all?token=*",".{0,1000}\/api\/listeners\/all\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5351" +"*/api/modules/collection/*?token=*",".{0,1000}\/api\/modules\/collection\/.{0,1000}\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5352" +"*/api/modules/credentials*?token=*",".{0,1000}\/api\/modules\/credentials.{0,1000}\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5353" +"*/api/reporting/agent/initial?token=*",".{0,1000}\/api\/reporting\/agent\/initial\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5354" +"*/api/reporting/msg/*?token=*",".{0,1000}\/api\/reporting\/msg\/.{0,1000}\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5355" +"*/api/reporting/type/checkin?token=*",".{0,1000}\/api\/reporting\/type\/checkin\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5356" +"*/api/sites/1/devices/1/crocconfig*",".{0,1000}\/api\/sites\/1\/devices\/1\/crocconfig.{0,1000}","offensive_tool_keyword","hak5 cloudc2","Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud","T1021 - T1102 - T1213","TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://shop.hak5.org/products/c2?","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","5357" +"*/api/sites/1/devices/1/deviceloot*",".{0,1000}\/api\/sites\/1\/devices\/1\/deviceloot.{0,1000}","offensive_tool_keyword","hak5 cloudc2","Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud","T1021 - T1102 - T1213","TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://shop.hak5.org/products/c2?","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","5358" +"*/api/sites/1/devices/1/keystrokes/*",".{0,1000}\/api\/sites\/1\/devices\/1\/keystrokes\/.{0,1000}","offensive_tool_keyword","hak5 cloudc2","Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud","T1021 - T1102 - T1213","TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://shop.hak5.org/products/c2?","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","5359" +"*/api/sites/1/devices/1/matchpayloads*",".{0,1000}\/api\/sites\/1\/devices\/1\/matchpayloads.{0,1000}","offensive_tool_keyword","hak5 cloudc2","Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud","T1021 - T1102 - T1213","TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://shop.hak5.org/products/c2?","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","5360" +"*/api/stagers/dll?token=*",".{0,1000}\/api\/stagers\/dll\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5361" +"*/api/stagers?token=*",".{0,1000}\/api\/stagers\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5362" +"*/api/users/1/disable?token=*",".{0,1000}\/api\/users\/1\/disable\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5363" +"*/api/v1/campaign/*/implants/*",".{0,1000}\/api\/v1\/campaign\/.{0,1000}\/implants\/.{0,1000}","offensive_tool_keyword","FudgeC2","FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.","T1021.002 - T1105 - T1059.001 - T1059.003","TA0008 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/Ziconius/FudgeC2","1","1","N/A","N/A","10","10","253","54","2023-05-01T21:13:56Z","2018-09-09T21:05:21Z","5364" +"*/api/v1/implants/*/execute*",".{0,1000}\/api\/v1\/implants\/.{0,1000}\/execute.{0,1000}","offensive_tool_keyword","FudgeC2","FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.","T1021.002 - T1105 - T1059.001 - T1059.003","TA0008 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/Ziconius/FudgeC2","1","1","N/A","N/A","10","10","253","54","2023-05-01T21:13:56Z","2018-09-09T21:05:21Z","5366" +"*/api/v1/implants/*/responses*",".{0,1000}\/api\/v1\/implants\/.{0,1000}\/responses.{0,1000}","offensive_tool_keyword","FudgeC2","FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.","T1021.002 - T1105 - T1059.001 - T1059.003","TA0008 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/Ziconius/FudgeC2","1","1","N/A","N/A","10","10","253","54","2023-05-01T21:13:56Z","2018-09-09T21:05:21Z","5367" +"*/api/v2/starkiller*",".{0,1000}\/api\/v2\/starkiller.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","5368" +"*/api_hooking.exe*",".{0,1000}\/api_hooking\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","5369" +"*/api0cradle/CVE-*",".{0,1000}\/api0cradle\/CVE\-.{0,1000}","offensive_tool_keyword","POC","CVE-2023-23397 POC Powershell exploit","T1068 - T1557.001 - T1187 - T1212 -T1003.001 - T1550","TA0003 - TA0002 - TA0004","N/A","N/A","Exploitation tool","https://github.com/api0cradle/CVE-2023-23397-POC-Powershell","1","1","N/A","N/A","N/A","4","344","63","2023-03-17T07:47:40Z","2023-03-16T19:43:39Z","5370" +"*/Apollo.exe*",".{0,1000}\/Apollo\.exe.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","5371" +"*/Apollo.git*",".{0,1000}\/Apollo\.git.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","5372" +"*/Apollo/Agent/*",".{0,1000}\/Apollo\/Agent\/.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","5373" +"*/ApolloInterop.*",".{0,1000}\/ApolloInterop\..{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","5374" +"*/ApolloInterop/*",".{0,1000}\/ApolloInterop\/.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","5375" +"*/apollon-all-x64*",".{0,1000}\/apollon\-all\-x64.{0,1000}","offensive_tool_keyword","apollon","evade auditd by writing /proc/PID/mem","T1054.001 - T1055.001 - T1012","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/codewhitesec/apollon","1","1","N/A","N/A","8","1","21","7","2023-08-21T05:43:36Z","2023-07-31T11:55:43Z","5376" +"*/apollon-main.zip*",".{0,1000}\/apollon\-main\.zip.{0,1000}","offensive_tool_keyword","apollon","evade auditd by writing /proc/PID/mem","T1054.001 - T1055.001 - T1012","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/codewhitesec/apollon","1","1","N/A","N/A","8","1","21","7","2023-08-21T05:43:36Z","2023-07-31T11:55:43Z","5377" +"*/apollon-selective-x64*",".{0,1000}\/apollon\-selective\-x64.{0,1000}","offensive_tool_keyword","apollon","evade auditd by writing /proc/PID/mem","T1054.001 - T1055.001 - T1012","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/codewhitesec/apollon","1","1","N/A","N/A","8","1","21","7","2023-08-21T05:43:36Z","2023-07-31T11:55:43Z","5378" +"*/ApolloTest.exe",".{0,1000}\/ApolloTest\.exe","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","5379" +"*/AppProxyC2.git*",".{0,1000}\/AppProxyC2\.git.{0,1000}","offensive_tool_keyword","AppProxyC2","simple POC to show how to tunnel traffic through Azure Application Proxy","T1090 - T1572 - T1071","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/xpn/AppProxyC2","1","1","N/A","N/A","9","10","69","18","2021-04-21T13:02:15Z","2021-04-21T10:46:16Z","5387" +"*/apps/zxtm/wizard.fcgi?error=1§ion=Access+Management%3ALocalUsers*",".{0,1000}\/apps\/zxtm\/wizard\.fcgi\?error\=1\§ion\=Access\+Management\%3ALocalUsers.{0,1000}","offensive_tool_keyword","POC","Ivanti Authent Bypass CVE-2024-7593 - Successful exploitation could lead to authentication bypass and creation of an administrator user","T1078 - T1136 - T1078.001","TA0006 - TA0004 - TA0005","N/A","N/A","Credential Access","https://x.com/mthcht/status/1823463842459848906","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5388" +"*/Aqua Server Editor.exe*",".{0,1000}\/Aqua\sServer\sEditor\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5389" +"*/aquasecurity/cloudsploit*",".{0,1000}\/aquasecurity\/cloudsploit.{0,1000}","offensive_tool_keyword","cloudsploit","CloudSploit by Aqua - Cloud Security Scans","T1526 - T1534 - T1547 - T1078 - T1046","TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/aquasecurity/cloudsploit","1","1","N/A","N/A","N/A","10","3498","702","2025-03-20T12:01:19Z","2015-06-29T15:33:40Z","5390" +"*/AquaServer.exe*",".{0,1000}\/AquaServer\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5391" +"*/Aquates Rat.exe*",".{0,1000}\/Aquates\sRat\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5392" +"*/arabicspy.php*",".{0,1000}\/arabicspy\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5393" +"*/Arbitrium-RAT.git*",".{0,1000}\/Arbitrium\-RAT\.git.{0,1000}","offensive_tool_keyword","Arbitrium-RAT","cross-platform fully undetectable remote access trojan to control Android Windows and Linux","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","N/A","Malware","https://github.com/im-hanzou/Arbitrium-RAT","1","1","N/A","N/A","10","4","355","309","2021-01-15T23:21:13Z","2021-01-16T03:03:11Z","5394" +"*/Ares.git",".{0,1000}\/Ares\.git","offensive_tool_keyword","Ares","Python C2 botnet and backdoor ","T1105 - T1102 - T1055","TA0003 - TA0002 - TA0007","N/A","N/A","C2","https://github.com/sweetsoftware/Ares","1","1","N/A","N/A","10","10","1588","477","2023-03-02T12:43:09Z","2015-10-18T12:26:27Z","5395" +"*/ArgFuscator.zip*",".{0,1000}\/ArgFuscator\.zip.{0,1000}","offensive_tool_keyword","Invoke-ArgFuscator","generate obfuscated command-lines for common system-native executables","T1027 - T1059 - T1202","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/wietze/Invoke-ArgFuscator","1","1","N/A","N/A","10","2","161","28","2025-04-14T21:24:29Z","2022-11-20T17:59:23Z","5397" +"*/args_spoofing-rs.exe*",".{0,1000}\/args_spoofing\-rs\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","5398" +"*/armitage.git*",".{0,1000}\/armitage\.git.{0,1000}","offensive_tool_keyword","armitage","Armitage is a graphical cyber attack management tool for Metasploit that visualizes your targets. recommends exploits and exposes the advanced capabilities of the framework ","T1210 - T1059.003 - T1547.001 - T1057 - T1046 - T1562.001 - T1071.001 - T1060 - T1573.002","TA0002 - TA0008 - TA0005 - TA0007 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/r00t0v3rr1d3/armitage","1","1","N/A","N/A","N/A","2","129","32","2022-12-06T00:17:23Z","2022-01-23T17:32:01Z","5399" +"*/arp_scanner.*",".{0,1000}\/arp_scanner\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","5400" +"*/arp_spoof/*",".{0,1000}\/arp_spoof\/.{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","5401" +"*/arsenal.git*",".{0,1000}\/arsenal\.git.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","5402" +"*/arsenal-1.1.0.zip*",".{0,1000}\/arsenal\-1\.1\.0\.zip.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","5403" +"*/arsenal-1.2.0.zip*",".{0,1000}\/arsenal\-1\.2\.0\.zip.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","5404" +"*/arsenal-1.2.1.zip*",".{0,1000}\/arsenal\-1\.2\.1\.zip.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","5405" +"*/arsenal-master.zip*",".{0,1000}\/arsenal\-master\.zip.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","5406" +"*/artifactor.py*",".{0,1000}\/artifactor\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","5407" +"*/ase_docker/*",".{0,1000}\/ase_docker\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","5408" +"*/Ask4Creds.git*",".{0,1000}\/Ask4Creds\.git.{0,1000}","offensive_tool_keyword","Ask4Creds","Prompt User for credentials","T1056 - T1071","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Leo4j/Ask4Creds","1","1","N/A","N/A","8","1","1","0","2024-03-20T17:09:21Z","2023-11-12T15:21:40Z","5409" +"*/Ask4Creds.ps1*",".{0,1000}\/Ask4Creds\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","5410" +"*/Ask4Creds.ps1*",".{0,1000}\/Ask4Creds\.ps1.{0,1000}","offensive_tool_keyword","Ask4Creds","Prompt User for credentials","T1056 - T1071","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Leo4j/Ask4Creds","1","1","N/A","N/A","8","1","1","0","2024-03-20T17:09:21Z","2023-11-12T15:21:40Z","5411" +"*/asleap.exe*",".{0,1000}\/asleap\.exe.{0,1000}","offensive_tool_keyword","asleap","Exploiting a serious deficiency in proprietary Cisco LEAP networks","T1078 - T1557 - T1040","TA0006 - TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/joswr1ght/asleap","1","1","N/A","N/A","10","1","88","20","2021-06-21T00:13:17Z","2016-08-30T13:00:21Z","5412" +"*/asn-query.nse*",".{0,1000}\/asn\-query\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5413" +"*/ASP.NET Web BackDoor.aspx*",".{0,1000}\/ASP\.NET\sWeb\sBackDoor\.aspx.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5414" +"*/ASPJinjaObfuscator.git*",".{0,1000}\/ASPJinjaObfuscator\.git.{0,1000}","offensive_tool_keyword","ASPJinjaObfuscator","Heavily obfuscated ASP web shell generation tool.","T1100 - T1027","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/fin3ss3g0d/ASPJinjaObfuscator","1","1","N/A","N/A","8","2","160","21","2024-04-26T01:27:42Z","2024-04-23T01:01:53Z","5415" +"*/asprox.profile*",".{0,1000}\/asprox\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","5416" +"*/asprox.profile*",".{0,1000}\/asprox\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","5417" +"*/ASPXspy2.aspx*",".{0,1000}\/ASPXspy2\.aspx.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5418" +"*/AspxSpy2014Final.aspx*",".{0,1000}\/AspxSpy2014Final\.aspx.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5419" +"*/ASRenum.cpp*",".{0,1000}\/ASRenum\.cpp.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF that identifies Attack Surface Reduction (ASR) rules. actions. and exclusion locations","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mlcsec/ASRenum-BOF","1","1","N/A","N/A","10","10","153","17","2024-03-01T14:03:44Z","2022-12-28T14:41:02Z","5420" +"*/ASRenum.cs*",".{0,1000}\/ASRenum\.cs.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF that identifies Attack Surface Reduction (ASR) rules. actions. and exclusion locations","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mlcsec/ASRenum-BOF","1","1","N/A","N/A","10","10","153","17","2024-03-01T14:03:44Z","2022-12-28T14:41:02Z","5421" +"*/ASRenum-BOF*",".{0,1000}\/ASRenum\-BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF that identifies Attack Surface Reduction (ASR) rules. actions. and exclusion locations","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mlcsec/ASRenum-BOF","1","1","N/A","N/A","10","10","153","17","2024-03-01T14:03:44Z","2022-12-28T14:41:02Z","5422" +"*/ASREPRoast*",".{0,1000}\/ASREPRoast.{0,1000}","offensive_tool_keyword","ASREPRoast","Project that retrieves crackable hashes from KRB5 AS-REP responses for users without kerberoast preauthentication enabled. ","T1558.003","TA0006","N/A","N/A","Credential Access","https://github.com/HarmJ0y/ASREPRoast","1","1","N/A","N/A","N/A","3","202","58","2018-09-25T03:26:00Z","2017-01-14T21:07:57Z","5423" +"*/asreproast_hashes_*.txt*",".{0,1000}\/asreproast_hashes_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","5424" +"*/assets/bin2uuids_file.py*",".{0,1000}\/assets\/bin2uuids_file\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Shellcode Generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RCStep/CSSG","1","1","N/A","N/A","10","10","654","112","2025-01-08T23:11:49Z","2021-01-12T14:39:06Z","5426" +"*/assets/wraith-scripts/*",".{0,1000}\/assets\/wraith\-scripts\/.{0,1000}","offensive_tool_keyword","wraith","A free and open-source, modular Remote Administration Tool (RAT) / Payload Dropper written in Go(lang) with a flexible command and control (C2) system.","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/wraith-labs/wraith","1","1","N/A","N/A","10","10","223","49","2023-12-03T22:16:27Z","2020-01-23T17:09:23Z","5427" +"*/AsStrongAsFuck.exe*",".{0,1000}\/AsStrongAsFuck\.exe.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","packer bundled","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","5430" +"*/asstrongasfuck.py*",".{0,1000}\/asstrongasfuck\.py.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","packer bundled","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","5431" +"*/AsyncRAT-C%23*",".{0,1000}\/AsyncRAT\-C\%23.{0,1000}","offensive_tool_keyword","AsyncRAT-C-Sharp","Open-Source Remote Administration Tool For Windows C# (RAT)","T1021.002 - T1056.001 - T1113 - T1133 - T1041 - T1555 - T1129 - T1564.001","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009","N/A","TA2541 - APT-C-36 - Earth Berberoka - Operation Comando - TA558","C2","https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp","1","1","N/A","N/A","10","10","2484","754","2023-10-16T21:41:12Z","2019-01-19T04:02:26Z","5432" +"*/AsyncRAT-C-Sharp*",".{0,1000}\/AsyncRAT\-C\-Sharp.{0,1000}","offensive_tool_keyword","AsyncRAT-C-Sharp","Open-Source Remote Administration Tool For Windows C# (RAT)","T1021.002 - T1056.001 - T1113 - T1133 - T1041 - T1555 - T1129 - T1564.001","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009","N/A","TA2541 - APT-C-36 - Earth Berberoka - Operation Comando - TA558","C2","https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp","1","1","N/A","N/A","10","10","2484","754","2023-10-16T21:41:12Z","2019-01-19T04:02:26Z","5433" +"*/asyncssh_server.py*",".{0,1000}\/asyncssh_server\.py.{0,1000}","offensive_tool_keyword","MaccaroniC2","A proof-of-concept Command & Control framework that utilizes the powerful AsyncSSH Python library which provides an asynchronous client and server implementation of the SSHv2 protocol and use PyNgrok wrapper for ngrok integration.","T1090 - T1059.003","TA0011 - TA0002","N/A","N/A","C2","https://github.com/CalfCrusher/MaccaroniC2","1","1","N/A","N/A","10","10","76","16","2023-06-27T17:43:59Z","2023-05-21T13:33:48Z","5434" +"*/atexec.py*",".{0,1000}\/atexec\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","5435" +"*/atexec.py*",".{0,1000}\/atexec\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","5436" +"*/atexec-pro.git*",".{0,1000}\/atexec\-pro\.git.{0,1000}","offensive_tool_keyword","atexec-pro","Fileless atexec for lateral movement","T1021.002 - T1105","TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/Ridter/atexec-pro","1","1","N/A","N/A","10","4","366","45","2024-03-28T03:36:50Z","2024-03-27T09:15:00Z","5437" +"*/atexec-pro.py*",".{0,1000}\/atexec\-pro\.py.{0,1000}","offensive_tool_keyword","atexec-pro","Fileless atexec for lateral movement","T1021.002 - T1105","TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/Ridter/atexec-pro","1","1","N/A","N/A","10","4","366","45","2024-03-28T03:36:50Z","2024-03-27T09:15:00Z","5438" +"*/Athena-*.zip*",".{0,1000}\/Athena\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5439" +"*/Athena.csproj*",".{0,1000}\/Athena\.csproj.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5440" +"*/Athena.exe*",".{0,1000}\/Athena\.exe.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5441" +"*/Athena.Profiles.*.cs*",".{0,1000}\/Athena\.Profiles\..{0,1000}\.cs.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5442" +"*/Athena.Profiles.*.exe*",".{0,1000}\/Athena\.Profiles\..{0,1000}\.exe.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5443" +"*/Athena.Profiles.*.py*",".{0,1000}\/Athena\.Profiles\..{0,1000}\.py.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5444" +"*/Athena.sln*",".{0,1000}\/Athena\.sln.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5445" +"*/Athena/Assembly/*.*",".{0,1000}\/Athena\/Assembly\/.{0,1000}\..{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5446" +"*/Athena/Commands/*.*",".{0,1000}\/Athena\/Commands\/.{0,1000}\..{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5447" +"*/athena/mythic*",".{0,1000}\/athena\/mythic.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5448" +"*/athena_utils/*.py*",".{0,1000}\/athena_utils\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5449" +"*/AthenaPlugins/bin/*",".{0,1000}\/AthenaPlugins\/bin\/.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","#linux","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5450" +"*/AthenaSMB/*",".{0,1000}\/AthenaSMB\/.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5451" +"*/AthenaTests/*.*",".{0,1000}\/AthenaTests\/.{0,1000}\..{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5452" +"*/AtlasReaper.git*",".{0,1000}\/AtlasReaper\.git.{0,1000}","offensive_tool_keyword","AtlasReaper","A command-line tool for reconnaissance and targeted write operations on Confluence and Jira instances.","T1210.002 - T1078.003 - T1046 ","TA0001 - TA0007 - TA0040","N/A","N/A","Reconnaissance","https://github.com/werdhaihai/AtlasReaper","1","1","N/A","N/A","3","3","255","28","2023-09-14T23:50:33Z","2023-06-24T00:18:41Z","5453" +"*/AtomLdr.git*",".{0,1000}\/AtomLdr\.git.{0,1000}","offensive_tool_keyword","AtomLdr","A DLL loader with advanced evasive features","T1071.004 - T1574.001 - T1574.002 - T1071.001 - T1055.003 - T1059.003 - T1546.003 - T1574.003 - T1574.004 - T1059.001 - T1569.002","TA0011 - TA0006 - TA0002 - TA0008 - TA0007","N/A","N/A","Exploitation tool","https://github.com/NUL0x4C/AtomLdr","1","1","N/A","N/A","N/A","8","712","91","2023-02-26T19:57:09Z","2023-02-26T17:59:26Z","5457" +"*/ATPMiniDump.exe*",".{0,1000}\/ATPMiniDump\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","5459" +"*/ATPMiniDump.git*",".{0,1000}\/ATPMiniDump\.git.{0,1000}","offensive_tool_keyword","ATPMiniDump","Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis","T1003 - T1005 - T1055 - T1218","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/b4rtik/ATPMiniDump","1","1","N/A","N/A","N/A","3","255","46","2019-12-02T15:01:22Z","2019-11-29T19:49:54Z","5460" +"*/attackercan/*",".{0,1000}\/attackercan\/.{0,1000}","offensive_tool_keyword","Github Username","github Penetration tester repo hosting malicious code","T1583 - T1595 - T1190","TA0001 - TA0002 - TA0008 - TA0011","N/A","N/A","Exploitation tool","https://github.com/attackercan/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5461" +"*/AttackerMITM.py*",".{0,1000}\/AttackerMITM\.py.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","#linux","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","5462" +"*/attacks/*.py",".{0,1000}\/attacks\/.{0,1000}\.py","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","5463" +"*/AttackServers/*",".{0,1000}\/AttackServers\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","5464" +"*/AttackSurfaceMapper.git*",".{0,1000}\/AttackSurfaceMapper\.git.{0,1000}","offensive_tool_keyword","AttackSurfaceMapper","AttackSurfaceMapper (ASM) is a reconnaissance tool that uses a mixture of open source intelligence and active techniques to expand the attack surface of your target","T1595 - T1596","TA0043","N/A","N/A","Reconnaissance","https://github.com/superhedgy/AttackSurfaceMapper","1","1","N/A","N/A","6","10","1355","197","2024-04-08T16:13:24Z","2019-08-07T14:32:53Z","5465" +"*/AtYourService.exe*",".{0,1000}\/AtYourService\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","5467" +"*/audio/exfiltrator.py*",".{0,1000}\/audio\/exfiltrator\.py.{0,1000}","offensive_tool_keyword","PyExfil","A Python Package for Data Exfiltration","T1041 - T1567 - T1027","TA0011 - TA0009 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/ytisf/PyExfil","1","1","N/A","N/A","10","8","782","141","2024-05-07T07:58:02Z","2014-11-27T19:06:24Z","5468" +"*/Augustus.git*",".{0,1000}\/Augustus\.git.{0,1000}","offensive_tool_keyword","Augustus","Augustus is a Golang loader that execute shellcode utilizing the process hollowing technique with anti-sandbox and anti-analysis measures. The shellcode is encrypted with the Triple DES (3DES) encryption algorithm.","T1055.012 - T1027.002 - T1136.001 - T1562.001","TA0005 - TA0002 - TA0003","N/A","N/A","Exploitation tool","https://github.com/TunnelGRE/Augustus","1","1","N/A","N/A","6","2","131","26","2024-07-27T14:47:45Z","2023-08-21T15:08:40Z","5469" +"*/auth/cc2_auth.*",".{0,1000}\/auth\/cc2_auth\..{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","5470" +"*/auth-owners.nse*",".{0,1000}\/auth\-owners\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5471" +"*/auth-spoof.nse*",".{0,1000}\/auth\-spoof\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5472" +"*/autobloody.git*",".{0,1000}\/autobloody\.git.{0,1000}","offensive_tool_keyword","autobloody","Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound","T1078 - T1078.003 - T1021 - T1021.006 - T1076.001","TA0005 - TA0001 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/CravateRouge/autobloody","1","1","#linux","N/A","10","6","545","54","2024-11-14T13:07:54Z","2022-09-07T13:34:30Z","5473" +"*/autobloody/archive*",".{0,1000}\/autobloody\/archive.{0,1000}","offensive_tool_keyword","autobloody","Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound","T1078 - T1078.003 - T1021 - T1021.006 - T1076.001","TA0005 - TA0001 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/CravateRouge/autobloody","1","1","#linux","N/A","10","6","545","54","2024-11-14T13:07:54Z","2022-09-07T13:34:30Z","5474" +"*/AutoBlue-MS17-010.git*",".{0,1000}\/AutoBlue\-MS17\-010\.git.{0,1000}","offensive_tool_keyword","AutoBlue-MS17-010","automated exploit code for MS17-010","T1210 - T1040 - T1059.001","TA0001 - TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/3ndG4me/AutoBlue-MS17-010","1","1","N/A","N/A","6","10","1240","317","2023-12-24T19:22:26Z","2017-11-25T09:03:38Z","5475" +"*/AutoBypass.ps1*",".{0,1000}\/AutoBypass\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","5476" +"*/AutoCrypt.ahk*",".{0,1000}\/AutoCrypt\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","5477" +"*/autoNTDS.git*",".{0,1000}\/autoNTDS\.git.{0,1000}","offensive_tool_keyword","autoNTDS","autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat","T1003 - T1059 - T1021.002 - T1213","TA0006 - TA0008 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/hmaverickadams/autoNTDS","1","1","N/A","N/A","10","2","109","14","2023-10-31T22:03:58Z","2023-10-30T23:10:58Z","5486" +"*/autoNTDS.py*",".{0,1000}\/autoNTDS\.py.{0,1000}","offensive_tool_keyword","autoNTDS","autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat","T1003 - T1059 - T1021.002 - T1213","TA0006 - TA0008 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/hmaverickadams/autoNTDS","1","1","N/A","N/A","10","2","109","14","2023-10-31T22:03:58Z","2023-10-30T23:10:58Z","5487" +"*/AutoPwnKey.git*",".{0,1000}\/AutoPwnKey\.git.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","5488" +"*/autordpwn.php*",".{0,1000}\/autordpwn\.php.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","5489" +"*/AutoRDPwn/master/*",".{0,1000}\/AutoRDPwn\/master\/.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","5490" +"*/AutoRecon.git*",".{0,1000}\/AutoRecon\.git.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","5491" +"*/AutoSmuggle.git*",".{0,1000}\/AutoSmuggle\.git.{0,1000}","offensive_tool_keyword","AutoSmuggle","Utility to craft HTML or SVG smuggled files for Red Team engagements","T1027.006 - T1598","TA0005 - TA0043","N/A","N/A","Defense Evasion","https://github.com/surajpkhetani/AutoSmuggle","1","1","N/A","N/A","9","3","240","26","2024-03-19T09:26:49Z","2022-03-20T19:02:06Z","5492" +"*/AutoSUID.git*",".{0,1000}\/AutoSUID\.git.{0,1000}","offensive_tool_keyword","AutoSUID","automate harvesting the SUID executable files and to find a way for further escalating the privileges","T1548.003 - T1069.001 - T1068","TA0004 - TA0003 - TA0005","N/A","N/A","Discovery","https://github.com/IvanGlinkin/AutoSUID","1","1","N/A","N/A","7","4","375","77","2024-04-29T12:30:35Z","2021-11-28T19:44:18Z","5493" +"*/auxiliary/scanner/*",".{0,1000}\/auxiliary\/scanner\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","5494" +"*/AV_Evasion_Tool.git*",".{0,1000}\/AV_Evasion_Tool\.git.{0,1000}","offensive_tool_keyword","AV_Evasion_Tool","Undetectable Payload Generator Tool","T1027 - T1036 - T1059 - T1107","TA0005","N/A","N/A","Defense Evasion","https://github.com/1y0n/AV_Evasion_Tool","1","1","N/A","N/A","10","10","2680","406","2023-12-08T07:38:06Z","2020-04-24T01:11:09Z","5495" +"*/avet.git*",".{0,1000}\/avet\.git.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","5496" +"*/avet_fabric.py*",".{0,1000}\/avet_fabric\.py.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","5497" +"*/avet_script_config.sh*",".{0,1000}\/avet_script_config\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","5498" +"*/AVKiller.git*",".{0,1000}\/AVKiller\.git.{0,1000}","offensive_tool_keyword","AVKiller","forcibly close some anti-virus processes through process injection (taking 360 Security Guard and 360 Anti-Virus as examples)","T1055.011 - T1089","TA0005 ","N/A","N/A","Defense Evasion","https://github.com/1y0n/AVKiller","1","1","N/A","N/A","10","2","127","18","2023-12-26T05:47:55Z","2023-12-19T00:55:23Z","5499" +"*/avoid_badchars.py*",".{0,1000}\/avoid_badchars\.py.{0,1000}","offensive_tool_keyword","Exrop","Exrop is automatic ROP chains generator tool which can build gadget chain automatically from given binary and constraints","T1554","TA0003","N/A","N/A","Exploitation tool","https://github.com/d4em0n/exrop","1","1","N/A","N/A","N/A","3","285","22","2020-02-21T08:01:06Z","2020-01-19T05:09:00Z","5500" +"*/avred.git*",".{0,1000}\/avred\.git.{0,1000}","offensive_tool_keyword","avred","Avred is being used to identify which parts of a file are identified by a Antivirus and tries to show as much possible information and context about each match.","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/dobin/avred","1","1","N/A","N/A","9","5","465","55","2025-02-26T08:12:03Z","2022-05-19T12:12:34Z","5501" +"*/avred.py*",".{0,1000}\/avred\.py.{0,1000}","offensive_tool_keyword","avred","Avred is being used to identify which parts of a file are identified by a Antivirus and tries to show as much possible information and context about each match.","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/dobin/avred","1","1","N/A","N/A","9","5","465","55","2025-02-26T08:12:03Z","2022-05-19T12:12:34Z","5502" +"*/awesome-burp-extensions/*",".{0,1000}\/awesome\-burp\-extensions\/.{0,1000}","offensive_tool_keyword","burpsuite","Collection of burpsuite plugins","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","network exploitation tool","9","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","5507" +"*/awesome-pentest*",".{0,1000}\/awesome\-pentest.{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","5508" +"*/AWS-Loot*",".{0,1000}\/AWS\-Loot.{0,1000}","offensive_tool_keyword","AWS-Loot","Searches an AWS environment looking for secrets. by enumerating environment variables and source code. This tool allows quick enumeration over large sets of AWS instances and services.","T1552","TA0002","N/A","N/A","Exploitation tool","https://github.com/sebastian-mora/AWS-Loot","1","1","N/A","N/A","N/A","1","70","25","2020-02-02T00:51:56Z","2020-02-02T00:25:46Z","5511" +"*/Azure-AccessPermissions.git*",".{0,1000}\/Azure\-AccessPermissions\.git.{0,1000}","offensive_tool_keyword","Azure-AccessPermissions","Easy to use PowerShell script to enumerate access permissions in an Azure Active Directory environment.","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/csandker/Azure-AccessPermissions","1","1","N/A","AD Enumeration","6","2","108","18","2023-02-21T06:46:24Z","2022-10-19T10:33:24Z","5512" +"*/AzureC2Relay*",".{0,1000}\/AzureC2Relay.{0,1000}","offensive_tool_keyword","AzureC2Relay","AzureC2Relay is an Azure Function that validates and relays Cobalt Strike beacon traffic by verifying the incoming requests based on a Cobalt Strike Malleable C2 profile.","T1090 - T1090.003 - T1027 - T1027.005 - T1071 - T1071.001","TA0042 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/Flangvik/AzureC2Relay","1","1","N/A","N/A","10","10","220","49","2021-02-15T18:06:38Z","2021-02-14T00:03:52Z","5513" +"*/AzureHound.ps1*",".{0,1000}\/AzureHound\.ps1.{0,1000}","offensive_tool_keyword","BloodHound","Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors","1","1","N/A","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","5514" +"*/AzureHound.ps1*",".{0,1000}\/AzureHound\.ps1.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","5515" +"*/B0-K RAT Majdi SaaD.exe*",".{0,1000}\/B0\-K\sRAT\sMajdi\sSaaD\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5516" +"*/BabelStrike.git*",".{0,1000}\/BabelStrike\.git.{0,1000}","offensive_tool_keyword","BabelStrike","The purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin)","T1078 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/t3l3machus/BabelStrike","1","1","N/A","N/A","1","2","132","23","2024-07-19T07:02:42Z","2023-01-10T07:59:00Z","5518" +"*/BabelStrike.py*",".{0,1000}\/BabelStrike\.py.{0,1000}","offensive_tool_keyword","BabelStrike","The purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin)","T1078 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/t3l3machus/BabelStrike","1","1","N/A","N/A","1","2","132","23","2024-07-19T07:02:42Z","2023-01-10T07:59:00Z","5519" +"*/Babylon RAT.exe*",".{0,1000}\/Babylon\sRAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5520" +"*/Babylon RAT.exe*",".{0,1000}\/Babylon\sRAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5521" +"*/Babylon RAT.exe*",".{0,1000}\/Babylon\sRAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5522" +"*/BabyShark.git*",".{0,1000}\/BabyShark\.git.{0,1000}","offensive_tool_keyword","BabyShark","This is a basic C2 generic server written in Python and Flask.","T1547.001 - T1059.003 - T1132.001 - T1140 - T1083 - T1070.004 - T1105 - T1056.001 - T1057 - T1012 - T1053.005 - T1218.005 - T1082 - T1016 - T1033","TA0006 - TA0011 - TA0040","N/A","Kimsuky","C2","https://github.com/UnkL4b/BabyShark","1","1","N/A","N/A","10","10","189","30","2021-07-03T00:18:18Z","2020-06-02T12:27:20Z","5523" +"*/backdoor.bat*",".{0,1000}\/backdoor\.bat.{0,1000}","offensive_tool_keyword","logon_backdoor","automated sticky keys backdoor","T1174 - T1078 - T1546.013","TA0003","N/A","N/A","Persistence","https://github.com/szymon1118/logon_backdoor","1","1","N/A","N/A","6","1","10","4","2016-02-12T11:42:59Z","2016-02-10T22:38:46Z","5525" +"*/backdoor.exe*",".{0,1000}\/backdoor\.exe.{0,1000}","offensive_tool_keyword","logon_backdoor","automated sticky keys backdoor","T1174 - T1078 - T1546.013","TA0003","N/A","N/A","Persistence","https://github.com/szymon1118/logon_backdoor","1","1","N/A","N/A","6","1","10","4","2016-02-12T11:42:59Z","2016-02-10T22:38:46Z","5526" +"*/Backdoor.PHP.Agent.php*",".{0,1000}\/Backdoor\.PHP\.Agent\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5527" +"*/backdoor_all_users.py*",".{0,1000}\/backdoor_all_users\.py.{0,1000}","offensive_tool_keyword","pacu","The AWS exploitation framework designed for testing the security of Amazon Web Services environments.","T1136.003 - T1190 - T1078.004","TA0006 - TA0001","N/A","Scattered Spider*","Framework","https://github.com/RhinoSecurityLabs/pacu","1","1","N/A","N/A","9","10","4651","731","2025-03-20T21:08:57Z","2018-06-13T21:58:59Z","5529" +"*/backdoored-script.ps1*",".{0,1000}\/backdoored\-script\.ps1.{0,1000}","offensive_tool_keyword","Graphpython","Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit","T1078.004 - T1114.002","TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010","N/A","N/A","Discovery","https://github.com/mlcsec/Graphpython","1","1","N/A","N/A","7","2","145","13","2024-12-07T21:54:00Z","2024-07-10T00:04:48Z","5531" +"*/BackgroundShell.exe*",".{0,1000}\/BackgroundShell\.exe.{0,1000}","offensive_tool_keyword","PrivFu","SeTcbPrivilege exploitation","T1134 - T1134.001 - T1078 - T1059 - T1075","TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu/","1","1","N/A","PrivFu\PowerOfTcb","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","5532" +"*/BackHAck.git*",".{0,1000}\/BackHAck\.git.{0,1000}","offensive_tool_keyword","BackHAck","Backdoor Generator with C2 server - Linux & Windows - FUD AV .py .exe","T1090 - T1095 - T1008","TA0011","N/A","N/A","C2","https://github.com/AngelSecurityTeam/BackHAck","1","1","#linux","N/A","10","10","108","34","2020-03-25T21:30:47Z","2020-03-14T19:00:36Z","5533" +"*/backhack.py*",".{0,1000}\/backhack\.py.{0,1000}","offensive_tool_keyword","BackHAck","Backdoor Generator with C2 server - Linux & Windows - FUD AV .py .exe","T1090 - T1095 - T1008","TA0011","N/A","N/A","C2","https://github.com/AngelSecurityTeam/BackHAck","1","1","#linux","N/A","10","10","108","34","2020-03-25T21:30:47Z","2020-03-14T19:00:36Z","5534" +"*/backoff.profile*",".{0,1000}\/backoff\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","5535" +"*/backorifice-brute.nse*",".{0,1000}\/backorifice\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5536" +"*/backorifice-info.nse*",".{0,1000}\/backorifice\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5537" +"*/Backstab.git",".{0,1000}\/Backstab\.git","offensive_tool_keyword","Backstab","A tool to kill antimalware protected processes","T1562.001 - T1569 - T1059","TA0005 - TA0040 - TA0002","N/A","Black Basta - LockBit","Defense Evasion","https://github.com/Yaxser/Backstab","1","1","N/A","N/A","10","10","1435","244","2021-06-19T20:01:52Z","2021-06-15T16:02:11Z","5538" +"*/Backstab/Backstab*",".{0,1000}\/Backstab\/Backstab.{0,1000}","offensive_tool_keyword","Backstab","A tool to kill antimalware protected processes","T1562.001 - T1569 - T1059","TA0005 - TA0040 - TA0002","N/A","Black Basta - LockBit","Defense Evasion","https://github.com/Yaxser/Backstab","1","1","N/A","N/A","10","10","1435","244","2021-06-19T20:01:52Z","2021-06-15T16:02:11Z","5539" +"*/backstab_src/*",".{0,1000}\/backstab_src\/.{0,1000}","offensive_tool_keyword","cobaltstrike","BOF combination of KillDefender and Backstab","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Octoberfest7/KDStab","1","1","N/A","N/A","10","10","167","37","2023-03-23T02:22:50Z","2022-03-10T06:09:52Z","5540" +"*/Backstab64.exe*",".{0,1000}\/Backstab64\.exe.{0,1000}","offensive_tool_keyword","Backstab","A tool to kill antimalware protected processes","T1562.001 - T1569 - T1059","TA0005 - TA0040 - TA0002","N/A","Black Basta - LockBit","Defense Evasion","https://github.com/Yaxser/Backstab","1","1","N/A","N/A","10","10","1435","244","2021-06-19T20:01:52Z","2021-06-15T16:02:11Z","5541" +"*/backupcreds.exe*",".{0,1000}\/backupcreds\.exe.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","1","N/A","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","5542" +"*/BackupCreds.git*",".{0,1000}\/BackupCreds\.git.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","1","N/A","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","5543" +"*/BackupOperatorToDA.git*",".{0,1000}\/BackupOperatorToDA\.git.{0,1000}","offensive_tool_keyword","BackupOperatorToDA","From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller","T1078 - T1078.003 - T1021 - T1021.006 - T1112 - T1003.003","TA0005 - TA0001 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/mpgn/BackupOperatorToDA","1","1","N/A","N/A","10","5","421","53","2025-01-04T14:16:46Z","2022-02-15T20:51:46Z","5544" +"*/BackupPrivSam/*",".{0,1000}\/BackupPrivSam\/.{0,1000}","offensive_tool_keyword","cobaltstrike","A basic implementation of abusing the SeBackupPrivilege via Remote Registry dumping to dump the remote SAM SECURITY AND SYSTEM hives.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/m57/cobaltstrike_bofs","1","1","N/A","N/A","10","10","164","25","2022-07-23T20:37:52Z","2020-07-30T22:36:51Z","5545" +"*/bacnet-info.nse*",".{0,1000}\/bacnet\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5546" +"*/BadPotato.dll*",".{0,1000}\/BadPotato\.dll.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","5550" +"*/BadPotato.exe*",".{0,1000}\/BadPotato\.exe.{0,1000}","offensive_tool_keyword","BadPotato","Windows Privilege Escalation Exploit BadPotato","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","Ghost Ransomware","Earth Lusca","Privilege Escalation","https://github.com/BeichenDream/BadPotato","1","1","N/A","N/A","10","9","836","136","2020-05-10T15:42:21Z","2020-05-10T10:01:20Z","5551" +"*/BadPotato.git*",".{0,1000}\/BadPotato\.git.{0,1000}","offensive_tool_keyword","BadPotato","Windows Privilege Escalation Exploit BadPotato","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","Ghost Ransomware","Earth Lusca","Privilege Escalation","https://github.com/BeichenDream/BadPotato","1","1","N/A","N/A","10","9","836","136","2020-05-10T15:42:21Z","2020-05-10T10:01:20Z","5552" +"*/BadRat 1.6/client.exe*",".{0,1000}\/BadRat\s1\.6\/client\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5553" +"*/badrat.ps1*",".{0,1000}\/badrat\.ps1.{0,1000}","offensive_tool_keyword","badrats","control tool (C2) using Python server - Jscript - Powershell and C# implants and communicates via HTTP(S) and SMB","T1059 - T1027 - T1573 - T1071 - T1105","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://gitlab.com/KevinJClark/badrats","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","5554" +"*/badrat_cs.exe*",".{0,1000}\/badrat_cs\.exe.{0,1000}","offensive_tool_keyword","badrats","control tool (C2) using Python server - Jscript - Powershell and C# implants and communicates via HTTP(S) and SMB","T1059 - T1027 - T1573 - T1071 - T1105","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://gitlab.com/KevinJClark/badrats","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","5555" +"*/badrat_server.py*",".{0,1000}\/badrat_server\.py.{0,1000}","offensive_tool_keyword","badrats","control tool (C2) using Python server - Jscript - Powershell and C# implants and communicates via HTTP(S) and SMB","T1059 - T1027 - T1573 - T1071 - T1105","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://gitlab.com/KevinJClark/badrats","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","5556" +"*/badrats.git*",".{0,1000}\/badrats\.git.{0,1000}","offensive_tool_keyword","badrats","control tool (C2) using Python server - Jscript - Powershell and C# implants and communicates via HTTP(S) and SMB","T1059 - T1027 - T1573 - T1071 - T1105","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://gitlab.com/KevinJClark/badrats","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","5557" +"*/BadRentdrv2.git*",".{0,1000}\/BadRentdrv2\.git.{0,1000}","offensive_tool_keyword","BadRentdrv2","A vulnerable driver (BYOVD) capable of terminating several EDRs and antivirus software","T1562 - T1068 - T1210 - T1489 - T1496","TA0005 - TA0004 - TA0040","N/A","Agrius","Defense Evasion","https://github.com/keowu/BadRentdrv2","1","1","N/A","N/A","10","1","95","20","2024-12-26T13:43:18Z","2023-10-01T18:24:38Z","5558" +"*/BadWindowsService.exe*",".{0,1000}\/BadWindowsService\.exe.{0,1000}","offensive_tool_keyword","BadWindowsService","An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities","T1068 - T1211 - T1050","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/eladshamir/BadWindowsService","1","1","N/A","N/A","10","1","58","10","2022-08-25T14:22:25Z","2022-08-19T15:38:05Z","5559" +"*/BadWindowsService.git*",".{0,1000}\/BadWindowsService\.git.{0,1000}","offensive_tool_keyword","BadWindowsService","An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities","T1068 - T1211 - T1050","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/eladshamir/BadWindowsService","1","1","N/A","N/A","10","1","58","10","2022-08-25T14:22:25Z","2022-08-19T15:38:05Z","5560" +"*/BadZure.git*",".{0,1000}\/BadZure\.git.{0,1000}","offensive_tool_keyword","badazure","BadZure orchestrates the setup of Azure Active Directory tenants populating them with diverse entities while also introducing common security misconfigurations to create vulnerable tenants with multiple attack paths","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Exploitation tool","https://github.com/mvelazc0/BadZure/","1","1","N/A","N/A","5","5","451","26","2025-04-10T03:20:03Z","2023-05-05T04:52:21Z","5561" +"*/BadZure/*",".{0,1000}\/BadZure\/.{0,1000}","offensive_tool_keyword","badazure","BadZure orchestrates the setup of Azure Active Directory tenants populating them with diverse entities while also introducing common security misconfigurations to create vulnerable tenants with multiple attack paths","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Exploitation tool","https://github.com/mvelazc0/BadZure/","1","1","N/A","N/A","5","5","451","26","2025-04-10T03:20:03Z","2023-05-05T04:52:21Z","5562" +"*/banner.nse*",".{0,1000}\/banner\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5563" +"*/Base64ToBin.py*",".{0,1000}\/Base64ToBin\.py.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","5564" +"*/BaseNEncoder.cs*",".{0,1000}\/BaseNEncoder\.cs.{0,1000}","offensive_tool_keyword","Macrome","An Excel Macro Document Reader/Writer for Red Teamers & Analysts. Blog posts describing what this tool actually does can be found https://malware.pizza/2020/05/12/evading-av-with-excel-macros-and-biff8-xls/ and https://malware.pizza/2020/06/19/further-evasion-in-the-forgotten-corners-of-ms-xls/","T1140","TA0005","N/A","N/A","Exploitation tool","https://github.com/michaelweber/Macrome","1","1","N/A","N/A","N/A","6","520","79","2022-02-01T16:26:13Z","2020-05-07T22:44:11Z","5565" +"*/bash_executor/*.go",".{0,1000}\/bash_executor\/.{0,1000}\.go","offensive_tool_keyword","mythic","mythic C2 agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/freyja/","1","1","#linux","N/A","10","10","54","13","2024-10-29T17:32:07Z","2022-09-28T17:20:04Z","5567" +"*/bashexplode/boko*",".{0,1000}\/bashexplode\/boko.{0,1000}","offensive_tool_keyword","boko","boko.py is an application scanner for macOS that searches for and identifies potential dylib hijacking and weak dylib vulnerabilities for application executables as well as scripts an application may use that have the potential to be backdoored","T1195 - T1078 - T1079 - T1574","TA0006 - TA0008","N/A","N/A","Exploitation tool","https://github.com/bashexplode/boko","1","1","#linux","N/A","N/A","1","71","13","2021-09-28T22:36:01Z","2020-05-22T21:46:33Z","5568" +"*/Bashfuscator*",".{0,1000}\/Bashfuscator.{0,1000}","offensive_tool_keyword","Bashfuscator","A fully configurable and extendable Bash obfuscation framework","T1027 - T1027.004 - T1059 - T1059.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Bashfuscator/Bashfuscator","1","1","#linux","N/A","10","10","1752","185","2023-09-05T10:40:25Z","2018-08-03T21:25:22Z","5569" +"*/bat_b4tm4n.php*",".{0,1000}\/bat_b4tm4n\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5570" +"*/batch_cme_smb.sh*",".{0,1000}\/batch_cme_smb\.sh.{0,1000}","offensive_tool_keyword","crackmapexec","crack mapexec script used by Dispossessor ransomware group","T1486 - T1490 - T1059 - T1213 - T1078","TA0040 - TA0043 - TA0001 - TA0009","N/A","Dispossessor - APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Lateral Movement","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5571" +"*/Bates.csproj*",".{0,1000}\/Bates\.csproj.{0,1000}","offensive_tool_keyword","Dendrobate","Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code","T1055.012 - T1059.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Dendrobate","1","1","N/A","N/A","10","2","131","27","2021-11-19T12:18:50Z","2021-02-15T11:15:51Z","5572" +"*/batik_svg*",".{0,1000}\/batik_svg.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","5573" +"*/Bat-Potato.bat*",".{0,1000}\/Bat\-Potato\.bat.{0,1000}","offensive_tool_keyword","Bat-Potato","Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers","T1055.012 - T1068 - T1548.002 - T1505.003","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/0x4xel/Bat-Potato","1","1","N/A","N/A","10","1","42","11","2022-12-13T20:19:51Z","2022-12-12T20:50:22Z","5574" +"*/Bat-Potato.git*",".{0,1000}\/Bat\-Potato\.git.{0,1000}","offensive_tool_keyword","Bat-Potato","Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers","T1055.012 - T1068 - T1548.002 - T1505.003","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/0x4xel/Bat-Potato","1","1","N/A","N/A","10","1","42","11","2022-12-13T20:19:51Z","2022-12-12T20:50:22Z","5575" +"*/bazarloader.profile*",".{0,1000}\/bazarloader\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","5576" +"*/bbaranoff/CVE-2022-0847/*",".{0,1000}\/bbaranoff\/CVE\-2022\-0847\/.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","t1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/bbaranoff/CVE-2022-0847","1","1","N/A","N/A","N/A","1","49","25","2022-03-07T15:52:23Z","2022-03-07T15:50:18Z","5577" +"*/beacon_202_no_acl.log*",".{0,1000}\/beacon_202_no_acl\.log.{0,1000}","offensive_tool_keyword","bofhound","Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel","T1046 - T1087 - T1003","TA0007 - TA0009 - TA0001","N/A","N/A","Discovery","https://github.com/fortalice/bofhound","1","1","#logfile #linux","N/A","5","4","328","56","2024-02-23T15:36:24Z","2022-05-10T17:41:53Z","5578" +"*/beacon_compatibility*",".{0,1000}\/beacon_compatibility.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a ELF object in memory loader/runner. The goal is to create a single elf loader that can be used to run follow on capabilities across all x86_64 and x86 nix operating systems.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/ELFLoader","1","1","N/A","N/A","10","10","268","45","2022-05-16T17:48:40Z","2022-04-26T19:18:20Z","5580" +"*/beacon_compatibility.*",".{0,1000}\/beacon_compatibility\..{0,1000}","offensive_tool_keyword","cobaltstrike","This is a quick and dirty COFF loader (AKA Beacon Object Files). Currently can run un-modified BOF's so it can be used for testing without a CS agent running it","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/COFFLoader","1","1","N/A","N/A","10","10","520","78","2025-04-03T14:57:10Z","2021-02-19T19:14:43Z","5581" +"*/beacon_funcs/*",".{0,1000}\/beacon_funcs\/.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool to run object files mainly beacon object files (BOF) in .Net.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nettitude/RunOF","1","1","N/A","N/A","10","10","145","21","2023-01-06T15:30:05Z","2022-02-21T13:53:39Z","5582" +"*/beacon_generate.py*",".{0,1000}\/beacon_generate\.py.{0,1000}","offensive_tool_keyword","Shoggoth","Shoggoth: Asmjit Based Polymorphic Encryptor","T1027 - T1045","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/frkngksl/Shoggoth","1","1","N/A","N/A","8","8","724","92","2024-04-10T03:04:04Z","2021-12-03T11:55:22Z","5583" +"*/beacon_health_check/*",".{0,1000}\/beacon_health_check\/.{0,1000}","offensive_tool_keyword","cobaltstrike","This aggressor script uses a beacon's note field to indicate the health status of a beacon.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/beacon_health_check","1","1","N/A","N/A","10","10","142","21","2021-09-29T20:20:52Z","2021-07-08T13:28:11Z","5584" +"*/beacon_http/*",".{0,1000}\/beacon_http\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5585" +"*/beacon_notify.cna*",".{0,1000}\/beacon_notify\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","5586" +"*/BeaconChannel.cs*",".{0,1000}\/BeaconChannel\.cs.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","5587" +"*/beaconhealth.cna*",".{0,1000}\/beaconhealth\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","This aggressor script uses a beacon's note field to indicate the health status of a beacon.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/beacon_health_check","1","1","N/A","N/A","10","10","142","21","2021-09-29T20:20:52Z","2021-07-08T13:28:11Z","5588" +"*/beacon-injection/*",".{0,1000}\/beacon\-injection\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Manual Map DLL injection implemented with Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tomcarver16/BOF-DLL-Inject","1","1","N/A","N/A","10","10","151","23","2020-09-03T23:24:31Z","2020-09-03T23:04:30Z","5589" +"*/beacon-object-file*",".{0,1000}\/beacon\-object\-file.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike beacon object files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/realoriginal/beacon-object-file","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5590" +"*/BeaconTool.java*",".{0,1000}\/BeaconTool\.java.{0,1000}","offensive_tool_keyword","cobaltstrike","Practice Go programming and implement CobaltStrike's Beacon in Go","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/darkr4y/geacon","1","1","N/A","N/A","10","10","1189","206","2020-10-02T10:34:37Z","2020-02-14T14:01:29Z","5591" +"*/beef.git*",".{0,1000}\/beef\.git.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","5592" +"*/beef/extensions/*.rb*",".{0,1000}\/beef\/extensions\/.{0,1000}\.rb.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","5593" +"*/beef_bind_shell/*",".{0,1000}\/beef_bind_shell\/.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","5594" +"*/beef_common.js*",".{0,1000}\/beef_common\.js.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","5595" +"*/beefbind/*",".{0,1000}\/beefbind\/.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","5596" +"*/beefproject/*",".{0,1000}\/beefproject\/.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","5597" +"*/Ben0xA/*",".{0,1000}\/Ben0xA\/.{0,1000}","offensive_tool_keyword","Github Username","Github username of known powershell offensive modules and scripts","T1059 - T1027 - T1064 - T1086 - T1191 - T1202","TA0002 - TA0003 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Ben0xA","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5598" +"*/beRoot.exe*",".{0,1000}\/beRoot\.exe.{0,1000}","offensive_tool_keyword","BeRoot","Privilege Escalation Project - Windows / Linux / Mac ","T1068 - T1055 - T1078 - T1548 - T1003","TA0004","N/A","N/A","Privilege Escalation","https://github.com/AlessandroZ/BeRoot","1","1","#linux","N/A","10","10","2523","459","2024-10-04T11:54:01Z","2017-04-14T12:47:31Z","5599" +"*/BeRoot.git*",".{0,1000}\/BeRoot\.git.{0,1000}","offensive_tool_keyword","BeRoot","Privilege Escalation Project - Windows / Linux / Mac ","T1053.005 - T1069.002 - T1069.001 - T1053.003 - T1087.001 - T1087.002 - T1082 - T1135 - T1049 - T1007","TA0004","N/A","N/A","Privilege Escalation","https://github.com/AlessandroZ/BeRoot","1","1","#linux","N/A","10","10","2523","459","2024-10-04T11:54:01Z","2017-04-14T12:47:31Z","5600" +"*/beRoot.py*",".{0,1000}\/beRoot\.py.{0,1000}","offensive_tool_keyword","BeRoot","Privilege Escalation Project - Windows / Linux / Mac ","T1053.005 - T1069.002 - T1069.001 - T1053.003 - T1087.001 - T1087.002 - T1082 - T1135 - T1049 - T1007","TA0004","N/A","N/A","Privilege Escalation","https://github.com/AlessandroZ/BeRoot","1","1","#linux","N/A","10","10","2523","459","2024-10-04T11:54:01Z","2017-04-14T12:47:31Z","5601" +"*/beroot.py*",".{0,1000}\/beroot\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","5602" +"*/beroot/modules/*.py*",".{0,1000}\/beroot\/modules\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","BeRoot","BeRoot Project is a post exploitation tool to check common misconfigurations to find a way to escalate our privilege.","T1068 - T1055 - T1078 - T1548 - T1003","TA0004","N/A","N/A","Exploitation tool","https://github.com/AlessandroZ/BeRoot","1","1","N/A","N/A","10","10","2523","459","2024-10-04T11:54:01Z","2017-04-14T12:47:31Z","5605" +"*/BesoToken.cpp*",".{0,1000}\/BesoToken\.cpp.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","1","N/A","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","5606" +"*/BesoToken.exe*",".{0,1000}\/BesoToken\.exe.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","1","N/A","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","5607" +"*/BesoToken.git*",".{0,1000}\/BesoToken\.git.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","1","N/A","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","5608" +"*/bettercap*",".{0,1000}\/bettercap.{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","5609" +"*/BetterSafetyKatz.exe*",".{0,1000}\/BetterSafetyKatz\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","5610" +"*/BetterSafetyKatz.exe*",".{0,1000}\/BetterSafetyKatz\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","5611" +"*/bgp_exfil.py*",".{0,1000}\/bgp_exfil\.py.{0,1000}","offensive_tool_keyword","PyExfil","A Python Package for Data Exfiltration","T1041 - T1567 - T1027","TA0011 - TA0009 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/ytisf/PyExfil","1","1","N/A","N/A","10","8","782","141","2024-05-07T07:58:02Z","2014-11-27T19:06:24Z","5612" +"*/bh_owned.py*",".{0,1000}\/bh_owned\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","5613" +"*/BHF Rat v * beta.exe*",".{0,1000}\/BHF\sRat\sv\s.{0,1000}\sbeta\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5614" +"*/BIFFRecordEncryption.cs*",".{0,1000}\/BIFFRecordEncryption\.cs.{0,1000}","offensive_tool_keyword","Macrome","An Excel Macro Document Reader/Writer for Red Teamers & Analysts. Blog posts describing what this tool actually does can be found https://malware.pizza/2020/05/12/evading-av-with-excel-macros-and-biff8-xls/ and https://malware.pizza/2020/06/19/further-evasion-in-the-forgotten-corners-of-ms-xls/","T1140","TA0005","N/A","N/A","Exploitation tool","https://github.com/michaelweber/Macrome","1","1","N/A","N/A","N/A","6","520","79","2022-02-01T16:26:13Z","2020-05-07T22:44:11Z","5616" +"*/Bifrost RAT Of Evil.exe*",".{0,1000}\/Bifrost\sRAT\sOf\sEvil\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5617" +"*/big_shell_pwd.7z*",".{0,1000}\/big_shell_pwd\.7z.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","1","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","5618" +"*/bin/0d1n*",".{0,1000}\/bin\/0d1n.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","#linux","N/A","7","","N/A","","","","5619" +"*/bin/AceLdr*",".{0,1000}\/bin\/AceLdr.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike UDRL for memory scanner evasion.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/kyleavery/AceLdr","1","1","#linux","N/A","10","10","925","164","2024-06-04T16:45:42Z","2022-08-11T00:06:09Z","5620" +"*/bin/gs-netcat*",".{0,1000}\/bin\/gs\-netcat.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","5631" +"*/bin/proxy_cli.py*",".{0,1000}\/bin\/proxy_cli\.py.{0,1000}","offensive_tool_keyword","sshimpanzee","SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS - ICMP - HTTP Encapsulation - HTTP/Socks Proxies - UDP","T1572 - T1095 - T1090 - T1043","TA0010 - TA0011 - TA0005","N/A","Scattered Spider*","C2","https://github.com/lexfo/sshimpanzee","1","1","#linux","N/A","10","10","263","27","2025-03-05T08:32:56Z","2023-04-03T10:11:27Z","5641" +"*/bin/pupysh*",".{0,1000}\/bin\/pupysh.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","#linux","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","5643" +"*/bin/read_i.php?a1=step2-down-b&a2=*",".{0,1000}\/bin\/read_i\.php\?a1\=step2\-down\-b\&a2\=.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","5644" +"*/bin/read_i.php?a1=step2-down-c&a2=*",".{0,1000}\/bin\/read_i\.php\?a1\=step2\-down\-c\&a2\=.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","5645" +"*/bin/read_i.php?a1=step2-down-j&a2=*",".{0,1000}\/bin\/read_i\.php\?a1\=step2\-down\-j\&a2\=.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","5646" +"*/bin/read_i.php?a1=step2-down-k&a2=*",".{0,1000}\/bin\/read_i\.php\?a1\=step2\-down\-k\&a2\=.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","5647" +"*/bin/read_i.php?a1=step2-down-r&a2=*",".{0,1000}\/bin\/read_i\.php\?a1\=step2\-down\-r\&a2\=.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","5648" +"*/bin/read_i.php?a1=step2-down-u&a2=*",".{0,1000}\/bin\/read_i\.php\?a1\=step2\-down\-u\&a2\=.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","5649" +"*/bin/Sleeper.o*",".{0,1000}\/bin\/Sleeper\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files (BOF) for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/crypt0p3g/bof-collection","1","1","#linux","N/A","10","10","175","27","2022-12-05T04:49:33Z","2021-01-20T06:07:38Z","5655" +"*/bin/wapiti*",".{0,1000}\/bin\/wapiti.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","#linux","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","5664" +"*/bin2hex.lua*",".{0,1000}\/bin2hex\.lua.{0,1000}","offensive_tool_keyword","OffensiveLua","Offensive Lua is a collection of offensive security scripts written in Lua with FFI","T1059 - T1218.011 - T1105 - T1021.002 - T1564.001 - T1112 - T1113 - T1204.002 - T1547.002","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hackerhouse-opensource/OffensiveLua","1","1","N/A","N/A","8","2","184","25","2023-11-17T00:35:10Z","2023-10-25T17:21:13Z","5667" +"*/bind_powershell.rb*",".{0,1000}\/bind_powershell\.rb.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","5668" +"*/bindshell.lua*",".{0,1000}\/bindshell\.lua.{0,1000}","offensive_tool_keyword","OffensiveLua","Offensive Lua is a collection of offensive security scripts written in Lua with FFI","T1059 - T1218.011 - T1105 - T1021.002 - T1564.001 - T1112 - T1113 - T1204.002 - T1547.002","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hackerhouse-opensource/OffensiveLua","1","1","N/A","N/A","8","2","184","25","2023-11-17T00:35:10Z","2023-10-25T17:21:13Z","5669" +"*/bin-sploits/*.zip*",".{0,1000}\/bin\-sploits\/.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","5670" +"*/BITB.git*",".{0,1000}\/BITB\.git.{0,1000}","offensive_tool_keyword","bitb","Browser templates for Browser In The Browser (BITB) attack","T1056.001 - T1134 - T1090","TA0005 - TA0006 - TA0003","N/A","N/A","Sniffing & Spoofing","https://github.com/mrd0x/BITB","1","1","N/A","N/A","10","10","2823","474","2024-01-26T05:20:18Z","2022-03-15T16:51:39Z","5671" +"*/bitcoin-getaddr.nse*",".{0,1000}\/bitcoin\-getaddr\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5673" +"*/bitcoin-info.nse*",".{0,1000}\/bitcoin\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5674" +"*/bitcoinrpc-info.nse*",".{0,1000}\/bitcoinrpc\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5675" +"*/bitsadmin/bitsadmin.cmd*",".{0,1000}\/bitsadmin\/bitsadmin\.cmd.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","5677" +"*/BitsArbitraryFileMove*",".{0,1000}\/BitsArbitraryFileMove.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","5678" +"*/BITSInject.git*",".{0,1000}\/BITSInject\.git.{0,1000}","offensive_tool_keyword","BITSInject","A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM account","T1197","TA0004","N/A","N/A","Privilege Escalation","https://github.com/SafeBreach-Labs/BITSInject","1","1","N/A","N/A","8","1","99","18","2019-08-24T22:02:12Z","2017-07-03T12:39:38Z","5679" +"*/BITSInject.py*",".{0,1000}\/BITSInject\.py.{0,1000}","offensive_tool_keyword","BITSInject","A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM account","T1197","TA0004","N/A","N/A","Privilege Escalation","https://github.com/SafeBreach-Labs/BITSInject","1","1","N/A","N/A","8","1","99","18","2019-08-24T22:02:12Z","2017-07-03T12:39:38Z","5680" +"*/BITSJobPayloads.py*",".{0,1000}\/BITSJobPayloads\.py.{0,1000}","offensive_tool_keyword","BITSInject","A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM account","T1197","TA0004","N/A","N/A","Privilege Escalation","https://github.com/SafeBreach-Labs/BITSInject","1","1","N/A","N/A","8","1","99","18","2019-08-24T22:02:12Z","2017-07-03T12:39:38Z","5681" +"*/bittorrent-discovery.nse*",".{0,1000}\/bittorrent\-discovery\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5682" +"*/bjnp-discover.nse*",".{0,1000}\/bjnp\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5683" +"*/Black-key Spoofer.exe*",".{0,1000}\/Black\-key\sSpoofer\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5684" +"*/Blackout.cpp*",".{0,1000}\/Blackout\.cpp.{0,1000}","offensive_tool_keyword","Blackout","kill anti-malware protected processes using BYOVD","T1055 - T1562.001","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/ZeroMemoryEx/Blackout","1","1","N/A","N/A","N/A","10","935","137","2023-07-21T17:35:09Z","2023-05-25T23:54:21Z","5685" +"*/Blackout.exe*",".{0,1000}\/Blackout\.exe.{0,1000}","offensive_tool_keyword","Blackout","kill anti-malware protected processes using BYOVD","T1055 - T1562.001","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/ZeroMemoryEx/Blackout","1","1","N/A","N/A","N/A","10","935","137","2023-07-21T17:35:09Z","2023-05-25T23:54:21Z","5686" +"*/Blackout.git*",".{0,1000}\/Blackout\.git.{0,1000}","offensive_tool_keyword","Blackout","kill anti-malware protected processes using BYOVD","T1055 - T1562.001","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/ZeroMemoryEx/Blackout","1","1","N/A","N/A","N/A","10","935","137","2023-07-21T17:35:09Z","2023-05-25T23:54:21Z","5687" +"*/Blackout.sln*",".{0,1000}\/Blackout\.sln.{0,1000}","offensive_tool_keyword","Blackout","kill anti-malware protected processes using BYOVD","T1055 - T1562.001","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/ZeroMemoryEx/Blackout","1","1","N/A","N/A","N/A","10","935","137","2023-07-21T17:35:09Z","2023-05-25T23:54:21Z","5688" +"*/Blackout.sys*",".{0,1000}\/Blackout\.sys.{0,1000}","offensive_tool_keyword","Blackout","kill anti-malware protected processes using BYOVD","T1055 - T1562.001","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/ZeroMemoryEx/Blackout","1","1","N/A","N/A","N/A","10","935","137","2023-07-21T17:35:09Z","2023-05-25T23:54:21Z","5689" +"*/blackvision.git*",".{0,1000}\/blackvision\.git.{0,1000}","offensive_tool_keyword","blackvision","Command line Remote Access tool (RAT) for Windows.","T1090 - T1095 - T1008","TA0011","N/A","N/A","Malware","https://github.com/quantumcore/blackvision","1","1","N/A","N/A","10","1","14","10","2019-09-16T18:32:51Z","2019-07-04T17:32:35Z","5690" +"*/Blank%20Grabber/Extras/hash*",".{0,1000}\/Blank\%20Grabber\/Extras\/hash.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","1","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","5692" +"*/Blank.Grabber.zip*",".{0,1000}\/Blank\.Grabber\.zip.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","1","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","5693" +"*/Blank-Grabber#download*",".{0,1000}\/Blank\-Grabber\#download.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","1","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","5694" +"*/Blank-Grabber.git*",".{0,1000}\/Blank\-Grabber\.git.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","1","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","5695" +"*/BlankOBF.git*",".{0,1000}\/BlankOBF\.git.{0,1000}","offensive_tool_keyword","BlankOBF","BlankOBF is a Python obfuscation tool designed to make Python programs harder to understand","T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/Blank-c/BlankOBF","1","1","N/A","N/A","9","2","114","22","2024-12-23T02:53:41Z","2022-01-24T13:52:00Z","5696" +"*/BlankOBF.py*",".{0,1000}\/BlankOBF\.py.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","1","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","5697" +"*/BlankOBFv2.py*",".{0,1000}\/BlankOBFv2\.py.{0,1000}","offensive_tool_keyword","BlankOBF","BlankOBF is a Python obfuscation tool designed to make Python programs harder to understand","T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/Blank-c/BlankOBF","1","1","N/A","N/A","9","2","114","22","2024-12-23T02:53:41Z","2022-01-24T13:52:00Z","5698" +"*/blindeventlog.exe*",".{0,1000}\/blindeventlog\.exe.{0,1000}","offensive_tool_keyword","DarkWidow","Indirect Dynamic Syscall SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a sacrificial Process as target process + (ACG+BlockDll) mitigation policy on spawned process + PPID spoofing (Emotet method) + Api resolving from TIB + API hashing","T1055 - T1055.012 - T1055.002 - T1098 - T1027 - T1027.001 - T1070.004 - T1036 - T1134 - T1140","TA0005 - TA0003 - TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/reveng007/DarkWidow","1","1","N/A","N/A","10","7","671","91","2025-03-12T21:58:25Z","2023-07-24T13:59:16Z","5699" +"*/blindsight.exe*",".{0,1000}\/blindsight\.exe.{0,1000}","offensive_tool_keyword","blindsight","Red teaming tool to dump LSASS memory, bypassing basic countermeasures","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/0xdea/blindsight","1","1","N/A","N/A","10","3","225","26","2024-12-31T15:28:15Z","2024-07-18T07:35:43Z","5700" +"*/blindsight.git*",".{0,1000}\/blindsight\.git.{0,1000}","offensive_tool_keyword","blindsight","Red teaming tool to dump LSASS memory, bypassing basic countermeasures","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/0xdea/blindsight","1","1","N/A","N/A","10","3","225","26","2024-12-31T15:28:15Z","2024-07-18T07:35:43Z","5701" +"*/Blizzard-RAT lite.exe*",".{0,1000}\/Blizzard\-RAT\slite\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5702" +"*/blob/main/write_anything.c*",".{0,1000}\/blob\/main\/write_anything\.c.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0008","N/A","N/A","Exploitation tool","https://github.com/gyaansastra/CVE-2022-0847","1","1","N/A","N/A","N/A","1","2","2","2022-03-20T15:46:04Z","2022-03-09T15:44:58Z","5703" +"*/block_dll_policy.exe*",".{0,1000}\/block_dll_policy\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","5704" +"*/blocketw.bin*",".{0,1000}\/blocketw\.bin.{0,1000}","offensive_tool_keyword","BlockEtw",".Net Assembly to block ETW telemetry in current process","T1055.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/Soledge/BlockEtw","1","1","N/A","N/A","10","1","78","19","2020-05-14T19:24:49Z","2020-05-14T02:40:50Z","5705" +"*/blocketw.exe*",".{0,1000}\/blocketw\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","5706" +"*/blocketw.exe*",".{0,1000}\/blocketw\.exe.{0,1000}","offensive_tool_keyword","BlockEtw",".Net Assembly to block ETW telemetry in current process","T1055.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/Soledge/BlockEtw","1","1","N/A","N/A","10","1","78","19","2020-05-14T19:24:49Z","2020-05-14T02:40:50Z","5707" +"*/BlockEtw.git*",".{0,1000}\/BlockEtw\.git.{0,1000}","offensive_tool_keyword","BlockEtw",".Net Assembly to block ETW telemetry in current process","T1055.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/Soledge/BlockEtw","1","1","N/A","N/A","10","1","78","19","2020-05-14T19:24:49Z","2020-05-14T02:40:50Z","5708" +"*/BlockEtw/tarball/*",".{0,1000}\/BlockEtw\/tarball\/.{0,1000}","offensive_tool_keyword","BlockEtw",".Net Assembly to block ETW telemetry in current process","T1055.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/Soledge/BlockEtw","1","1","N/A","N/A","10","1","78","19","2020-05-14T19:24:49Z","2020-05-14T02:40:50Z","5709" +"*/BlockEtw/zipball/*",".{0,1000}\/BlockEtw\/zipball\/.{0,1000}","offensive_tool_keyword","BlockEtw",".Net Assembly to block ETW telemetry in current process","T1055.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/Soledge/BlockEtw","1","1","N/A","N/A","10","1","78","19","2020-05-14T19:24:49Z","2020-05-14T02:40:50Z","5710" +"*/BlockOpenHandle.git*",".{0,1000}\/BlockOpenHandle\.git.{0,1000}","offensive_tool_keyword","BlockOpenHandle","Block any Process to open HANDLE to your process - only SYTEM is allowed to open handle to your process - with that you can avoid remote memory scanners","T1050.005 - T1480","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/BlockOpenHandle","1","1","N/A","N/A","9","2","167","25","2023-04-27T05:42:51Z","2023-04-27T05:40:47Z","5711" +"*/BloodHound.exe*",".{0,1000}\/BloodHound\.exe.{0,1000}","offensive_tool_keyword","BloodHound","Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors","1","1","N/A","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","5712" +"*/BloodHound.git*",".{0,1000}\/BloodHound\.git.{0,1000}","offensive_tool_keyword","BloodHound","Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors","1","1","N/A","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","5713" +"*/bloodhound.md*",".{0,1000}\/bloodhound\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","5714" +"*/bloodhound.py*",".{0,1000}\/bloodhound\.py.{0,1000}","offensive_tool_keyword","crackmapexec","bloodhound integration with crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks ","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","5715" +"*/bloodhound/enumeration*",".{0,1000}\/bloodhound\/enumeration.{0,1000}","offensive_tool_keyword","BloodHound","A Python based ingestor for BloodHound","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/fox-it/BloodHound.py","1","1","N/A","N/A","10","10","2088","343","2025-03-28T11:19:13Z","2018-02-26T14:44:20Z","5716" +"*/bloodhound_domain.py*",".{0,1000}\/bloodhound_domain\.py.{0,1000}","offensive_tool_keyword","bofhound","Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel","T1046 - T1087 - T1003","TA0007 - TA0009 - TA0001","N/A","N/A","Discovery","https://github.com/fortalice/bofhound","1","1","N/A","N/A","5","4","328","56","2024-02-23T15:36:24Z","2022-05-10T17:41:53Z","5717" +"*/bloodhound_domaintrust.py*",".{0,1000}\/bloodhound_domaintrust\.py.{0,1000}","offensive_tool_keyword","bofhound","Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel","T1046 - T1087 - T1003","TA0007 - TA0009 - TA0001","N/A","N/A","Discovery","https://github.com/fortalice/bofhound","1","1","N/A","N/A","5","4","328","56","2024-02-23T15:36:24Z","2022-05-10T17:41:53Z","5718" +"*/bloodhound_gpo.py*",".{0,1000}\/bloodhound_gpo\.py.{0,1000}","offensive_tool_keyword","bofhound","Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel","T1046 - T1087 - T1003","TA0007 - TA0009 - TA0001","N/A","N/A","Discovery","https://github.com/fortalice/bofhound","1","1","N/A","N/A","5","4","328","56","2024-02-23T15:36:24Z","2022-05-10T17:41:53Z","5719" +"*/bloodhound_object.py*",".{0,1000}\/bloodhound_object\.py.{0,1000}","offensive_tool_keyword","bofhound","Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel","T1046 - T1087 - T1003","TA0007 - TA0009 - TA0001","N/A","N/A","Discovery","https://github.com/fortalice/bofhound","1","1","N/A","N/A","5","4","328","56","2024-02-23T15:36:24Z","2022-05-10T17:41:53Z","5720" +"*/bloodhound_ou.py*",".{0,1000}\/bloodhound_ou\.py.{0,1000}","offensive_tool_keyword","bofhound","Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel","T1046 - T1087 - T1003","TA0007 - TA0009 - TA0001","N/A","N/A","Discovery","https://github.com/fortalice/bofhound","1","1","N/A","N/A","5","4","328","56","2024-02-23T15:36:24Z","2022-05-10T17:41:53Z","5721" +"*/bloodhound_schema.py*",".{0,1000}\/bloodhound_schema\.py.{0,1000}","offensive_tool_keyword","bofhound","Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel","T1046 - T1087 - T1003","TA0007 - TA0009 - TA0001","N/A","N/A","Discovery","https://github.com/fortalice/bofhound","1","1","N/A","N/A","5","4","328","56","2024-02-23T15:36:24Z","2022-05-10T17:41:53Z","5722" +"*/bloodhound-data*",".{0,1000}\/bloodhound\-data.{0,1000}","offensive_tool_keyword","BloodHound","A Python based ingestor for BloodHound","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/fox-it/BloodHound.py","1","1","N/A","N/A","10","10","2088","343","2025-03-28T11:19:13Z","2018-02-26T14:44:20Z","5723" +"*/bloodhound-quickwin.git*",".{0,1000}\/bloodhound\-quickwin\.git.{0,1000}","offensive_tool_keyword","bloodhound-quickwin","Simple script to extract useful informations from the combo BloodHound + Neo4j","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/kaluche/bloodhound-quickwin","1","1","N/A","AD Enumeration","6","3","239","26","2025-04-04T05:11:46Z","2021-02-16T16:04:16Z","5724" +"*/bloodhoundsync.py*",".{0,1000}\/bloodhoundsync\.py.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","1","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","5725" +"*/bloodyAD.git*",".{0,1000}\/bloodyAD\.git.{0,1000}","offensive_tool_keyword","bloodyAD","BloodyAD is an Active Directory Privilege Escalation Framework","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/CravateRouge/bloodyAD","1","1","N/A","N/A","10","10","1590","145","2025-04-10T10:47:16Z","2021-10-11T15:07:26Z","5726" +"*/BluePalmRAT.exe*",".{0,1000}\/BluePalmRAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5727" +"*/bluscreenofjeff/*",".{0,1000}\/bluscreenofjeff\/.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","5728" +"*/BobTheSmuggler.git*",".{0,1000}\/BobTheSmuggler\.git.{0,1000}","offensive_tool_keyword","BobTheSmuggler","HTML SMUGGLING TOOL 6 allows you to create HTML files with embedded 7z/zip archives. The tool would compress your binary (EXE/DLL) into 7z/zip file format then XOR encrypt the archive and then hides inside PNG/GIF image file format (Image Polyglots)","T1027 - T1204.002 - T1140","TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/TheCyb3rAlpha/BobTheSmuggler","1","1","N/A","N/A","10","6","534","62","2025-03-10T07:32:22Z","2024-01-10T08:04:57Z","5729" +"*/BOF.NET/*",".{0,1000}\/BOF\.NET\/.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","5732" +"*/bof.nim",".{0,1000}\/bof\.nim","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF Files with Nim!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/byt3bl33d3r/BOF-Nim","1","1","N/A","N/A","10","10","84","13","2022-07-10T22:12:10Z","2021-01-12T18:58:23Z","5733" +"*/bof.x64.o*",".{0,1000}\/bof\.x64\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","5734" +"*/bof.x64.o*",".{0,1000}\/bof\.x64\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Spectrum Attack Simulation beacons","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas/","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","5735" +"*/bof.x86.o*",".{0,1000}\/bof\.x86\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","5736" +"*/bof.x86.o*",".{0,1000}\/bof\.x86\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Spectrum Attack Simulation beacons","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas/","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","5737" +"*/bof/bof.c",".{0,1000}\/bof\/bof\.c","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","5738" +"*/bof/bof.vcxproj*",".{0,1000}\/bof\/bof\.vcxproj.{0,1000}","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","5739" +"*/bof/IABOF*",".{0,1000}\/bof\/IABOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Inject .NET assemblies into an existing process","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/kyleavery/inject-assembly","1","1","N/A","N/A","10","10","494","74","2022-01-19T19:15:11Z","2022-01-03T15:38:10Z","5740" +"*/bof/IAStart.asm*",".{0,1000}\/bof\/IAStart\.asm.{0,1000}","offensive_tool_keyword","cobaltstrike","Inject .NET assemblies into an existing process","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/kyleavery/inject-assembly","1","1","N/A","N/A","10","10","494","74","2022-01-19T19:15:11Z","2022-01-03T15:38:10Z","5741" +"*/bof_reg_collect_parser.py*",".{0,1000}\/bof_reg_collect_parser\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","5742" +"*/BOF-Builder*",".{0,1000}\/BOF\-Builder.{0,1000}","offensive_tool_keyword","cobaltstrike","C# .Net 5.0 project to build BOF (Beacon Object Files) in mass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ceramicskate0/BOF-Builder","1","1","N/A","N/A","10","10","28","4","2023-07-25T22:19:27Z","2021-09-07T01:28:11Z","5743" +"*/bof-collection/*",".{0,1000}\/bof\-collection\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files (BOF) for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/crypt0p3g/bof-collection","1","1","N/A","N/A","10","10","175","27","2022-12-05T04:49:33Z","2021-01-20T06:07:38Z","5744" +"*/bofhound.git*",".{0,1000}\/bofhound\.git.{0,1000}","offensive_tool_keyword","bofhound","Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel","T1046 - T1087 - T1003","TA0007 - TA0009 - TA0001","N/A","N/A","Discovery","https://github.com/fortalice/bofhound","1","1","N/A","N/A","5","4","328","56","2024-02-23T15:36:24Z","2022-05-10T17:41:53Z","5745" +"*/bofhound.py*",".{0,1000}\/bofhound\.py.{0,1000}","offensive_tool_keyword","ShadowHound","set of PowerShell scripts for Active Directory enumeration","T1087 - T1018 - T1482 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/Friends-Security/ShadowHound","1","1","N/A","N/A","8","4","345","36","2024-12-01T08:06:02Z","2024-11-21T15:01:14Z","5746" +"*/BOFMask.git*",".{0,1000}\/BOFMask\.git.{0,1000}","offensive_tool_keyword","BOFMask","BOFMask is a proof-of-concept for masking Cobalt Strike's Beacon payload while executing a Beacon Object File (BOF)","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/passthehashbrowns/BOFMask","1","1","N/A","N/A","10","2","120","27","2023-06-28T14:35:32Z","2023-06-27T21:19:22Z","5747" +"*/bofmask.h*",".{0,1000}\/bofmask\.h.{0,1000}","offensive_tool_keyword","BOFMask","BOFMask is a proof-of-concept for masking Cobalt Strike's Beacon payload while executing a Beacon Object File (BOF)","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/passthehashbrowns/BOFMask","1","1","N/A","N/A","10","2","120","27","2023-06-28T14:35:32Z","2023-06-27T21:19:22Z","5748" +"*/BOFNETExamples/*",".{0,1000}\/BOFNETExamples\/.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","5749" +"*/BOF-RegSave*",".{0,1000}\/BOF\-RegSave.{0,1000}","offensive_tool_keyword","cobaltstrike","Dumping SAM / SECURITY / SYSTEM registry hives with a Beacon Object File","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EncodeGroup/BOF-RegSave","1","1","N/A","N/A","10","10","198","32","2020-10-08T17:29:02Z","2020-10-07T13:46:03Z","5750" +"*/BofRunner.cs*",".{0,1000}\/BofRunner\.cs.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool to run object files mainly beacon object files (BOF) in .Net.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nettitude/RunOF","1","1","N/A","N/A","10","10","145","21","2023-01-06T15:30:05Z","2022-02-21T13:53:39Z","5751" +"*/BOFs.git*",".{0,1000}\/BOFs\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files (BOFs) for shells and lols","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RiccardoAncarani/BOFs","1","1","N/A","N/A","10","10","118","13","2021-09-14T09:03:58Z","2021-08-27T10:04:12Z","5752" +"*/bof-vs-template/*",".{0,1000}\/bof\-vs\-template\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","5753" +"*/bof-vs-template/*",".{0,1000}\/bof\-vs\-template\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Spectrum Attack Simulation beacons","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas/","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","5754" +"*/boko.py*",".{0,1000}\/boko\.py.{0,1000}","offensive_tool_keyword","boko","boko.py is an application scanner for macOS that searches for and identifies potential dylib hijacking and weak dylib vulnerabilities for application executables as well as scripts an application may use that have the potential to be backdoored","T1195 - T1078 - T1079 - T1574","TA0006 - TA0008","N/A","N/A","Exploitation tool","https://github.com/bashexplode/boko","1","1","N/A","N/A","N/A","1","71","13","2021-09-28T22:36:01Z","2020-05-22T21:46:33Z","5755" +"*/boku7/spawn*",".{0,1000}\/boku7\/spawn.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF that spawns a sacrificial process. injects it with shellcode. and executes payload. Built to evade EDR/UserLand hooks by spawning sacrificial process with Arbitrary Code Guard (ACG). BlockDll. and PPID spoofing.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/spawn","1","1","N/A","N/A","10","10","455","73","2023-03-08T15:53:44Z","2021-07-17T16:35:59Z","5756" +"*/boku7/whereami/*",".{0,1000}\/boku7\/whereami\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object File (BOF) that uses handwritten shellcode to return the process Environment strings without touching any DLL's.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/whereami","1","1","N/A","N/A","10","10","172","27","2023-03-13T15:56:38Z","2021-08-19T22:32:34Z","5757" +"*/BokuLoader.c*",".{0,1000}\/BokuLoader\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","5758" +"*/BokuLoader.h*",".{0,1000}\/BokuLoader\.h.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","5759" +"*/BokuLoader/*",".{0,1000}\/BokuLoader\/.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","5760" +"*/BooExecutor.cs*",".{0,1000}\/BooExecutor\.cs.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","5765" +"*/bootkit-rs*",".{0,1000}\/bootkit\-rs.{0,1000}","offensive_tool_keyword","bootkit-rs","Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus)","T1542.004 - T1067.002 - T1012 - T1053.005 - T1057","TA0002 - TA0040 - TA0003 - TA0001","N/A","N/A","Defense Evasion","https://github.com/memN0ps/bootkit-rs","1","1","N/A","N/A","N/A","6","528","67","2023-09-12T07:23:15Z","2023-04-11T03:53:15Z","5766" +"*/boxreflect.dll*",".{0,1000}\/boxreflect\.dll.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5771" +"*/bpf-keylogger.git*",".{0,1000}\/bpf\-keylogger\.git.{0,1000}","offensive_tool_keyword","bpf-keylogger","Keylogger written in BPF","T1056.001 - T1053.005","TA0006 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/SkyperTHC/bpf-keylogger","1","1","N/A","N/A","10","1","4","1","2024-01-29T18:08:01Z","2024-01-29T09:34:47Z","5772" +"*/bpf-keylogger/*",".{0,1000}\/bpf\-keylogger\/.{0,1000}","offensive_tool_keyword","bpf-keylogger","Keylogger written in BPF","T1056.001 - T1053.005","TA0006 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/SkyperTHC/bpf-keylogger","1","1","N/A","N/A","10","1","4","1","2024-01-29T18:08:01Z","2024-01-29T09:34:47Z","5773" +"*/bq1iFEP2/assert/dll/*",".{0,1000}\/bq1iFEP2\/assert\/dll\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Chinese clone of cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/YDHCUI/manjusaka","1","1","N/A","N/A","10","10","818","150","2023-05-09T03:31:53Z","2022-03-18T08:16:04Z","5774" +"*/bq1iFEP2/assert/exe/*",".{0,1000}\/bq1iFEP2\/assert\/exe\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Chinese clone of cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/YDHCUI/manjusaka","1","1","N/A","N/A","10","10","818","150","2023-05-09T03:31:53Z","2022-03-18T08:16:04Z","5775" +"*/brc-1.2.2.git*",".{0,1000}\/brc\-1\.2\.2\.git.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5776" +"*/BRC4_rar",".{0,1000}\/BRC4_rar","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5777" +"*/breg.x64.o*",".{0,1000}\/breg\.x64\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike beacon object file that allows you to query and make changes to the Windows Registry","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ausecwa/bof-registry","1","1","N/A","N/A","10","10","27","8","2021-02-11T04:38:28Z","2021-01-29T05:07:47Z","5778" +"*/breg.x86.o*",".{0,1000}\/breg\.x86\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike beacon object file that allows you to query and make changes to the Windows Registry","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ausecwa/bof-registry","1","1","N/A","N/A","10","10","27","8","2021-02-11T04:38:28Z","2021-01-29T05:07:47Z","5779" +"*/broadcast-ataoe-discover.nse*",".{0,1000}\/broadcast\-ataoe\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5780" +"*/broadcast-avahi-dos.nse*",".{0,1000}\/broadcast\-avahi\-dos\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5781" +"*/broadcast-bjnp-discover.nse*",".{0,1000}\/broadcast\-bjnp\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5782" +"*/broadcast-db2-discover.nse*",".{0,1000}\/broadcast\-db2\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5783" +"*/broadcast-dhcp6-discover.nse*",".{0,1000}\/broadcast\-dhcp6\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5784" +"*/broadcast-dhcp-discover.nse*",".{0,1000}\/broadcast\-dhcp\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5785" +"*/broadcast-dns-service-discovery.nse*",".{0,1000}\/broadcast\-dns\-service\-discovery\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5786" +"*/broadcast-dropbox-listener.nse*",".{0,1000}\/broadcast\-dropbox\-listener\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5787" +"*/broadcast-eigrp-discovery.nse*",".{0,1000}\/broadcast\-eigrp\-discovery\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5788" +"*/broadcast-hid-discoveryd.nse*",".{0,1000}\/broadcast\-hid\-discoveryd\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5789" +"*/broadcast-igmp-discovery.nse*",".{0,1000}\/broadcast\-igmp\-discovery\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5790" +"*/broadcast-jenkins-discover.nse*",".{0,1000}\/broadcast\-jenkins\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5791" +"*/broadcast-listener.nse*",".{0,1000}\/broadcast\-listener\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5792" +"*/broadcast-ms-sql-discover.nse*",".{0,1000}\/broadcast\-ms\-sql\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5793" +"*/broadcast-netbios-master-browser.nse*",".{0,1000}\/broadcast\-netbios\-master\-browser\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5794" +"*/broadcast-networker-discover.nse*",".{0,1000}\/broadcast\-networker\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5795" +"*/broadcast-novell-locate.nse*",".{0,1000}\/broadcast\-novell\-locate\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5796" +"*/broadcast-ospf2-discover.nse*",".{0,1000}\/broadcast\-ospf2\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5797" +"*/broadcast-pc-anywhere.nse*",".{0,1000}\/broadcast\-pc\-anywhere\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5798" +"*/broadcast-pc-duo.nse*",".{0,1000}\/broadcast\-pc\-duo\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5799" +"*/broadcast-pim-discovery.nse*",".{0,1000}\/broadcast\-pim\-discovery\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5800" +"*/broadcast-ping.nse*",".{0,1000}\/broadcast\-ping\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5801" +"*/broadcast-pppoe-discover.nse*",".{0,1000}\/broadcast\-pppoe\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5802" +"*/broadcast-rip-discover.nse*",".{0,1000}\/broadcast\-rip\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5803" +"*/broadcast-ripng-discover.nse*",".{0,1000}\/broadcast\-ripng\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5804" +"*/broadcast-sonicwall-discover.nse*",".{0,1000}\/broadcast\-sonicwall\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5805" +"*/broadcast-sybase-asa-discover.nse*",".{0,1000}\/broadcast\-sybase\-asa\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5806" +"*/broadcast-tellstick-discover.nse*",".{0,1000}\/broadcast\-tellstick\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5807" +"*/broadcast-upnp-info.nse*",".{0,1000}\/broadcast\-upnp\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5808" +"*/broadcast-versant-locate.nse*",".{0,1000}\/broadcast\-versant\-locate\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5809" +"*/broadcast-wake-on-lan.nse*",".{0,1000}\/broadcast\-wake\-on\-lan\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5810" +"*/broadcast-wpad-discover.nse*",".{0,1000}\/broadcast\-wpad\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5811" +"*/broadcast-wsdd-discover.nse*",".{0,1000}\/broadcast\-wsdd\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5812" +"*/broadcast-xdmcp-discover.nse*",".{0,1000}\/broadcast\-xdmcp\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5813" +"*/Bropper.git*",".{0,1000}\/Bropper\.git.{0,1000}","offensive_tool_keyword","bropper","An automatic Blind ROP exploitation tool ","T1068 - T1059.003 - T1140","TA0002 - TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/Hakumarachi/Bropper","1","1","N/A","N/A","7","3","201","19","2023-06-09T12:40:05Z","2023-01-20T14:09:19Z","5814" +"*/bropper.py*",".{0,1000}\/bropper\.py.{0,1000}","offensive_tool_keyword","bropper","An automatic Blind ROP exploitation tool ","T1068 - T1059.003 - T1140","TA0002 - TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/Hakumarachi/Bropper","1","1","N/A","N/A","7","3","201","19","2023-06-09T12:40:05Z","2023-01-20T14:09:19Z","5815" +"*/Browser-C2*",".{0,1000}\/Browser\-C2.{0,1000}","offensive_tool_keyword","Browser-C2","Post Exploitation agent which uses a browser to do C2 operations.","T1105 - T1102","TA0003 - TA0005 - TA0008","N/A","N/A","C2","https://github.com/0x09AL/Browser-C2","1","1","N/A","N/A","10","10","102","28","2018-05-25T15:12:21Z","2018-05-22T14:33:24Z","5816" +"*/BrowserDataGrabber.git*",".{0,1000}\/BrowserDataGrabber\.git.{0,1000}","offensive_tool_keyword","Browser Data Grabber","credential access tool used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://github.com/n37sn4k3/BrowserDataGrabber","1","1","N/A","N/A","10","1","7","4","2018-05-28T15:49:03Z","2018-05-04T12:33:32Z","5817" +"*/BrowserGhost.exe*",".{0,1000}\/BrowserGhost\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","5818" +"*/BrowserGhost.git*",".{0,1000}\/BrowserGhost\.git.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","1","N/A","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","5819" +"*/BrowserGhost/releases/download/*",".{0,1000}\/BrowserGhost\/releases\/download\/.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","1","N/A","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","5820" +"*/BrowserGhost/tarball/*",".{0,1000}\/BrowserGhost\/tarball\/.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","1","N/A","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","5821" +"*/BrowserGhost/zipball/*",".{0,1000}\/BrowserGhost\/zipball\/.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","1","N/A","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","5822" +"*/browserhistory.csv*",".{0,1000}\/browserhistory\.csv.{0,1000}","offensive_tool_keyword","WinPirate","automated sticky keys backdoor + credentials harvesting","T1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003","TA0003 - TA0005 - TA0006","N/A","N/A","Persistence","https://github.com/l3m0n/WinPirate","1","1","N/A","N/A","9","1","13","32","2016-07-17T20:02:07Z","2016-07-18T03:40:13Z","5823" +"*/BrowserSnatch.git*",".{0,1000}\/BrowserSnatch\.git.{0,1000}","offensive_tool_keyword","BrowserSnatch","steals important data from all chromium and gecko browsers installed in the system and gather the data in a stealer db to be exfiltrated out. A powerful Browser Stealer","T1081 - T1074 - T1114 - T1005 - T1041 - T1027","TA0006 - TA0009 - TA0010","N/A","N/A","Data Exfiltration","https://github.com/shaddy43/BrowserSnatch","1","1","N/A","N/A","10","3","246","39","2025-03-31T21:04:30Z","2024-08-26T18:38:42Z","5824" +"*/BrowserSnatch/releases/download*",".{0,1000}\/BrowserSnatch\/releases\/download.{0,1000}","offensive_tool_keyword","BrowserSnatch","steals important data from all chromium and gecko browsers installed in the system and gather the data in a stealer db to be exfiltrated out. A powerful Browser Stealer","T1081 - T1074 - T1114 - T1005 - T1041 - T1027","TA0006 - TA0009 - TA0010","N/A","N/A","Data Exfiltration","https://github.com/shaddy43/BrowserSnatch","1","1","N/A","N/A","10","3","246","39","2025-03-31T21:04:30Z","2024-08-26T18:38:42Z","5825" +"*/BrowserSnatch-master*",".{0,1000}\/BrowserSnatch\-master.{0,1000}","offensive_tool_keyword","BrowserSnatch","steals important data from all chromium and gecko browsers installed in the system and gather the data in a stealer db to be exfiltrated out. A powerful Browser Stealer","T1081 - T1074 - T1114 - T1005 - T1041 - T1027","TA0006 - TA0009 - TA0010","N/A","N/A","Data Exfiltration","https://github.com/shaddy43/BrowserSnatch","1","1","N/A","N/A","10","3","246","39","2025-03-31T21:04:30Z","2024-08-26T18:38:42Z","5826" +"*/BrtoVenomRenames.sh*",".{0,1000}\/BrtoVenomRenames\.sh.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","5827" +"*/brute force.cna*",".{0,1000}\/brute\sforce\.cna.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","5828" +"*/Brute/BruteStager*",".{0,1000}\/Brute\/BruteStager.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","5829" +"*/bruteforce.py*",".{0,1000}\/bruteforce\.py.{0,1000}","offensive_tool_keyword","Vajra","Vajra is a UI based tool with multiple techniques for attacking and enumerating in target's Azure environment","T1087 - T1098 - T1583 - T1078 - T1110 - T1566 - T1537 - T1020 - T1526 - T1482","TA0003 - TA0006 - TA0007 - TA0008 - TA0009","N/A","N/A","Exploitation tool","https://github.com/TROUBLE-1/Vajra","1","1","N/A","N/A","N/A","4","391","61","2025-02-21T16:40:23Z","2022-03-01T14:31:27Z","5830" +"*/bruteforce-ftp.py*",".{0,1000}\/bruteforce\-ftp\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","5831" +"*/bruteforce-http.py*",".{0,1000}\/bruteforce\-http\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","5832" +"*/Bruteforcer.*",".{0,1000}\/Bruteforcer\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","5833" +"*/bruteforce-rdp.py*",".{0,1000}\/bruteforce\-rdp\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","5834" +"*/bruteforce-smb.py*",".{0,1000}\/bruteforce\-smb\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","5835" +"*/bruteforce-ssh.py*",".{0,1000}\/bruteforce\-ssh\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","5836" +"*/bruteratel*",".{0,1000}\/bruteratel.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5837" +"*/brute-ratel-armx64*",".{0,1000}\/brute\-ratel\-armx64.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5838" +"*/brute-ratel-linx64*",".{0,1000}\/brute\-ratel\-linx64.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5839" +"*/brutereflect.dll*",".{0,1000}\/brutereflect\.dll.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5840" +"*/BruteSploit*",".{0,1000}\/BruteSploit.{0,1000}","offensive_tool_keyword","BruteSploit","BruteSploit is a collection of method for automated Generate. Bruteforce and Manipulation wordlist with interactive shell. That can be used during a penetration test to enumerate and maybe can be used in CTF for manipulation.combine.transform and permutation some words or file text","T1110","N/A","N/A","N/A","Exploitation tool","https://github.com/screetsec/BruteSploit","1","1","N/A","N/A","N/A","8","741","263","2020-04-05T00:29:26Z","2017-05-31T17:00:51Z","5841" +"*/brutespray.git*",".{0,1000}\/brutespray\.git.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","1","N/A","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","5842" +"*/brutespray/*",".{0,1000}\/brutespray\/.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","1","N/A","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","5843" +"*/brutespray/*",".{0,1000}\/brutespray\/.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5844" +"*/brutespray_*",".{0,1000}\/brutespray_.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","1","N/A","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","5845" +"*/BruteStager.cs*",".{0,1000}\/BruteStager\.cs.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","5846" +"*/BucketLoot.git*",".{0,1000}\/BucketLoot\.git.{0,1000}","offensive_tool_keyword","BucketLoot","BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets- flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain-text","T1562.007 - T1119 - T1530","TA0006 - TA0010","N/A","N/A","Discovery","https://github.com/redhuntlabs/BucketLoot","1","1","N/A","N/A","7","5","409","58","2025-01-22T10:48:27Z","2023-07-17T09:06:14Z","5849" +"*/build/encrypted_shellcode*",".{0,1000}\/build\/encrypted_shellcode.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Shellcode Generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RCStep/CSSG","1","1","N/A","N/A","10","10","654","112","2025-01-08T23:11:49Z","2021-01-12T14:39:06Z","5850" +"*/build/formatted_shellcode*",".{0,1000}\/build\/formatted_shellcode.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Shellcode Generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RCStep/CSSG","1","1","N/A","N/A","10","10","654","112","2025-01-08T23:11:49Z","2021-01-12T14:39:06Z","5851" +"*/build/shellcode*",".{0,1000}\/build\/shellcode.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Shellcode Generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RCStep/CSSG","1","1","N/A","N/A","10","10","654","112","2025-01-08T23:11:49Z","2021-01-12T14:39:06Z","5852" +"*/build_arsenal_kit.sh*",".{0,1000}\/build_arsenal_kit\.sh.{0,1000}","offensive_tool_keyword","ElusiveMice","Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind","T1620 - T1055.012 - T1202","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/mgeeky/ElusiveMice","1","1","N/A","N/A","10","5","449","78","2023-07-12T17:54:07Z","2021-08-27T19:22:20Z","5853" +"*/BuildBOFs/*",".{0,1000}\/BuildBOFs\/.{0,1000}","offensive_tool_keyword","cobaltstrike","C# .Net 5.0 project to build BOF (Beacon Object Files) in mass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ceramicskate0/BOF-Builder","1","1","N/A","N/A","10","10","28","4","2023-07-25T22:19:27Z","2021-09-07T01:28:11Z","5854" +"*/burp/releases/community/latest*",".{0,1000}\/burp\/releases\/community\/latest.{0,1000}","offensive_tool_keyword","burpsuite","The class-leading vulnerability scanning. penetration testing. and web app security platform","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://portswigger.net/burp","1","1","N/A","network exploitation tool","N/A","N/A","N/A","N/A","N/A","N/A","5855" +"*/burp-api/*",".{0,1000}\/burp\-api\/.{0,1000}","offensive_tool_keyword","burpsuite","CO2 is a project for lightweight and useful enhancements to Portswigger popular Burp Suite web penetration tool through the standard Extender API","T1583 - T1595 - T1190","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/JGillam/burp-co2","1","1","N/A","network exploitation tool","N/A","2","152","34","2024-02-21T02:23:00Z","2015-04-19T03:38:34Z","5856" +"*/burp-Dirbuster*",".{0,1000}\/burp\-Dirbuster.{0,1000}","offensive_tool_keyword","dirbuster","Dirbuster plugin for Burp Suite","T1583 - T1595 - T1190","TA0011 - TA0009","N/A","N/A","Reconnaissance","https://github.com/vulnersCom/burp-Dirbuster","1","1","#linux","N/A","N/A","1","70","28","2017-02-22T08:31:32Z","2017-02-22T08:24:05Z","5857" +"*/burpee.py*",".{0,1000}\/burpee\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CodeXTF2/Burp2Malleable","1","1","N/A","N/A","10","10","385","34","2023-04-06T15:24:12Z","2022-08-14T18:05:39Z","5858" +"*/BurpExtender.java*",".{0,1000}\/BurpExtender\.java.{0,1000}","offensive_tool_keyword","burpsuite","CO2 is a project for lightweight and useful enhancements to Portswigger popular Burp Suite web penetration tool through the standard Extender API","T1583 - T1595 - T1190","TA0010 - TA0007 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/JGillam/burp-co2","1","1","N/A","network exploitation tool","N/A","2","152","34","2024-02-21T02:23:00Z","2015-04-19T03:38:34Z","5859" +"*/burp-proxy*",".{0,1000}\/burp\-proxy.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","5860" +"*/BurpSuite-collections*",".{0,1000}\/BurpSuite\-collections.{0,1000}","offensive_tool_keyword","burpsuite","Collection of burpsuite plugins","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","network exploitation tool","N/A","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","5861" +"*/BUYTHEAPTDETECTORNOW*",".{0,1000}\/BUYTHEAPTDETECTORNOW.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","5862" +"*/BX RAT V*.exe*",".{0,1000}\/BX\sRAT\sV.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5863" +"*/BX RAT.exe*",".{0,1000}\/BX\sRAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","5864" +"*/byakugan.cpp*",".{0,1000}\/byakugan\.cpp.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","5865" +"*/byakugan.dll*",".{0,1000}\/byakugan\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","5866" +"*/bypass.vbs*",".{0,1000}\/bypass\.vbs.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","5867" +"*/Bypass/payloads*",".{0,1000}\/Bypass\/payloads.{0,1000}","offensive_tool_keyword","GreatSCT","The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This tool is intended for BOTH red and blue team.","T1055 - T1112 - T1189 - T1205","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/GreatSCT/GreatSCT","1","1","N/A","N/A","N/A","10","1127","202","2021-02-10T22:05:27Z","2017-05-12T03:30:41Z","5868" +"*/bypass_mod/loader*",".{0,1000}\/bypass_mod\/loader.{0,1000}","offensive_tool_keyword","C2 related tools","An anti-virus platform written in the Golang-Gin framework with built-in BypassAV methods such as separation and bundling.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Ed1s0nZ/cool","1","1","N/A","N/A","10","10","686","112","2023-07-13T07:04:30Z","2021-11-10T14:32:34Z","5869" +"*/BypassAddUser.exe*",".{0,1000}\/BypassAddUser\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","5870" +"*/BypassAddUser.exe*",".{0,1000}\/BypassAddUser\.exe.{0,1000}","offensive_tool_keyword","BypassAddUser","Bypass antivirus software to add users","T1562.001 - T1078.002 - T1136.001","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TryA9ain/BypassAddUser","1","1","N/A","N/A","6","1","46","8","2020-12-12T05:11:35Z","2020-12-12T04:15:06Z","5871" +"*/BypassAddUser.git*",".{0,1000}\/BypassAddUser\.git.{0,1000}","offensive_tool_keyword","BypassAddUser","Bypass antivirus software to add users","T1562.001 - T1078.002 - T1136.001","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TryA9ain/BypassAddUser","1","1","N/A","N/A","6","1","46","8","2020-12-12T05:11:35Z","2020-12-12T04:15:06Z","5872" +"*/BypassAddUser/releases/download/*",".{0,1000}\/BypassAddUser\/releases\/download\/.{0,1000}","offensive_tool_keyword","BypassAddUser","Bypass antivirus software to add users","T1562.001 - T1078.002 - T1136.001","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TryA9ain/BypassAddUser","1","1","N/A","N/A","6","1","46","8","2020-12-12T05:11:35Z","2020-12-12T04:15:06Z","5873" +"*/BypassAddUser/tarball/*",".{0,1000}\/BypassAddUser\/tarball\/.{0,1000}","offensive_tool_keyword","BypassAddUser","Bypass antivirus software to add users","T1562.001 - T1078.002 - T1136.001","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TryA9ain/BypassAddUser","1","1","N/A","N/A","6","1","46","8","2020-12-12T05:11:35Z","2020-12-12T04:15:06Z","5874" +"*/BypassAddUser/zipball/*",".{0,1000}\/BypassAddUser\/zipball\/.{0,1000}","offensive_tool_keyword","BypassAddUser","Bypass antivirus software to add users","T1562.001 - T1078.002 - T1136.001","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TryA9ain/BypassAddUser","1","1","N/A","N/A","6","1","46","8","2020-12-12T05:11:35Z","2020-12-12T04:15:06Z","5875" +"*/BypassAV/*",".{0,1000}\/BypassAV\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike plugin for quickly generating anti-kill executable files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/hack2fun/BypassAV","1","1","N/A","N/A","10","10","908","125","2020-07-19T15:46:54Z","2020-02-17T02:33:14Z","5876" +"*/bypassAV-1/*",".{0,1000}\/bypassAV\-1\/.{0,1000}","offensive_tool_keyword","cobaltstrike","bypassAV cobaltstrike shellcode","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/jas502n/bypassAV-1","1","1","N/A","N/A","10","10","17","9","2021-03-04T01:51:14Z","2021-03-03T11:33:38Z","5877" +"*/bypass-clm.exe*",".{0,1000}\/bypass\-clm\.exe.{0,1000}","offensive_tool_keyword","bypass-clm","PowerShell Constrained Language Mode Bypass","T1059.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/calebstewart/bypass-clm","1","1","N/A","N/A","8","3","261","38","2021-01-31T19:13:55Z","2021-01-29T04:46:23Z","5878" +"*/bypass-clm.git*",".{0,1000}\/bypass\-clm\.git.{0,1000}","offensive_tool_keyword","bypass-clm","PowerShell Constrained Language Mode Bypass","T1059.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/calebstewart/bypass-clm","1","1","N/A","N/A","8","3","261","38","2021-01-31T19:13:55Z","2021-01-29T04:46:23Z","5879" +"*/BypassCredGuard.cpp*",".{0,1000}\/BypassCredGuard\.cpp.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","1","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","5880" +"*/BypassCredGuard.exe*",".{0,1000}\/BypassCredGuard\.exe.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","1","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","5881" +"*/BypassCredGuard.git*",".{0,1000}\/BypassCredGuard\.git.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","1","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","5882" +"*/BypassFramework.py*",".{0,1000}\/BypassFramework\.py.{0,1000}","offensive_tool_keyword","FourEye","AV Evasion Tool","T1059 - T1059.001 - T1059.005 - T1027 - T1027.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/lengjibo/FourEye","1","1","N/A","N/A","10","8","758","152","2021-12-08T11:55:15Z","2020-12-11T01:29:58Z","5883" +"*/bypass-iisuser-p.asp*",".{0,1000}\/bypass\-iisuser\-p\.asp.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5884" +"*/bypassuac/*",".{0,1000}\/bypassuac\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","5885" +"*/bypass-waf.asp*",".{0,1000}\/bypass\-waf\.asp.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5886" +"*/bypass-with-base32.php*",".{0,1000}\/bypass\-with\-base32\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5887" +"*/C2/Beacon/*.cs*",".{0,1000}\/C2\/Beacon\/.{0,1000}\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","5891" +"*/c2/c2.go*",".{0,1000}\/c2\/c2\.go.{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","5892" +"*/C2/c2.go*",".{0,1000}\/C2\/c2\.go.{0,1000}","offensive_tool_keyword","GC2-sheet","GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet and exfiltrate data using Google Drive.","T1071.002 - T1560 - T1105","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/looCiprian/GC2-sheet","1","1","N/A","N/A","10","10","578","111","2025-03-28T19:48:36Z","2021-09-15T19:06:12Z","5893" +"*/C2/Http/*.cs*",".{0,1000}\/C2\/Http\/.{0,1000}\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","5894" +"*/C2/server.py*",".{0,1000}\/C2\/server\.py.{0,1000}","offensive_tool_keyword","primusC2","another C2 framework","T1090 - T1071","TA0011 - TA0002","N/A","N/A","C2","https://github.com/Primusinterp/PrimusC2","1","1","N/A","N/A","10","10","55","4","2024-11-01T00:20:02Z","2023-04-19T10:59:30Z","5895" +"*/C2/SmbListener.*",".{0,1000}\/C2\/SmbListener\..{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","5896" +"*/c2/tcp-stager.*",".{0,1000}\/c2\/tcp\-stager\..{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","5897" +"*/c2_code/*.html",".{0,1000}\/c2_code\/.{0,1000}\.html","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","5899" +"*/c2_code/server*",".{0,1000}\/c2_code\/server.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","5900" +"*/C2_Profiles/*",".{0,1000}\/C2_Profiles\/.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","5901" +"*/C2_Server.git*",".{0,1000}\/C2_Server\.git.{0,1000}","offensive_tool_keyword","C2_Server","C2 server to connect to a victim machine via reverse shell","T1090 - T1090.001 - T1071 - T1071.001","TA0011 ","N/A","N/A","C2","https://github.com/reveng007/C2_Server","1","1","N/A","N/A","10","10","54","18","2022-02-27T02:00:02Z","2021-03-05T12:35:45Z","5902" +"*/c2_server.py*",".{0,1000}\/c2_server\.py.{0,1000}","offensive_tool_keyword","Commander","A command and control (C2) server","T1021 - T1027 - T1059","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/voukatas/Commander","1","1","N/A","N/A","10","10","56","16","2024-07-05T11:05:30Z","2023-02-03T16:46:33Z","5903" +"*/c2_server/resources*",".{0,1000}\/c2_server\/resources.{0,1000}","offensive_tool_keyword","FudgeC2","FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.","T1021.002 - T1105 - T1059.001 - T1059.003","TA0008 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/Ziconius/FudgeC2","1","1","N/A","N/A","10","10","253","54","2023-05-01T21:13:56Z","2018-09-09T21:05:21Z","5904" +"*/c2_test.go*",".{0,1000}\/c2_test\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","5905" +"*/c2-3.4.0.zip*",".{0,1000}\/c2\-3\.4\.0\.zip.{0,1000}","offensive_tool_keyword","hak5 cloudc2","Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud","T1021 - T1102 - T1213","TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://shop.hak5.org/products/c2?","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","5906" +"*/c2-3.4.0_amd64_windows.exe*",".{0,1000}\/c2\-3\.4\.0_amd64_windows\.exe.{0,1000}","offensive_tool_keyword","hak5 cloudc2","Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud","T1021 - T1102 - T1213","TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://shop.hak5.org/products/c2?","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","5908" +"*/c2-3.4.0_arm64_darwin*",".{0,1000}\/c2\-3\.4\.0_arm64_darwin.{0,1000}","offensive_tool_keyword","hak5 cloudc2","Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud","T1021 - T1102 - T1213","TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://shop.hak5.org/products/c2?","1","1","#linux","N/A","10","9","N/A","N/A","N/A","N/A","5909" +"*/c2-3.4.0_i386_windows.exe*",".{0,1000}\/c2\-3\.4\.0_i386_windows\.exe.{0,1000}","offensive_tool_keyword","hak5 cloudc2","Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud","T1021 - T1102 - T1213","TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://shop.hak5.org/products/c2?","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","5910" +"*/c2-3.4.0_i386_windows.exe*",".{0,1000}\/c2\-3\.4\.0_i386_windows\.exe.{0,1000}","offensive_tool_keyword","hak5 cloudc2","Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud","T1021 - T1102 - T1213","TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://shop.hak5.org/products/c2?","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","5911" +"*/C2concealer*",".{0,1000}\/C2concealer.{0,1000}","offensive_tool_keyword","C2concealer","C2concealer is a command line tool that generates randomized C2 malleable profiles for use in Cobalt Strike.","T1090 - T1090.003 - T1027 - T1027.005 - T1071 - T1071.001","TA0042 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/RedSiege/C2concealer","1","1","N/A","N/A","10","10","1053","172","2024-06-25T11:10:54Z","2020-03-23T14:13:16Z","5912" +"*/C2concealer*",".{0,1000}\/C2concealer.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5913" +"*/c2endpoint.php*",".{0,1000}\/c2endpoint\.php.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","N/A","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","5914" +"*/C2Frame.*",".{0,1000}\/C2Frame\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","5915" +"*/C2Manager.cs*",".{0,1000}\/C2Manager\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","5916" +"*/c2profile.*",".{0,1000}\/c2profile\..{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","5917" +"*/c2profile.go*",".{0,1000}\/c2profile\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","Practice Go programming and implement CobaltStrike's Beacon in Go","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/darkr4y/geacon","1","1","N/A","N/A","10","10","1189","206","2020-10-02T10:34:37Z","2020-02-14T14:01:29Z","5918" +"*/c2profiles.zip*",".{0,1000}\/c2profiles\.zip.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","5919" +"*/C2Profiles/*",".{0,1000}\/C2Profiles\/.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","5920" +"*/C2ReverseProxy.git*",".{0,1000}\/C2ReverseProxy\.git.{0,1000}","offensive_tool_keyword","C2ReverseProxy","ReverseProxy C2 - Bring CS online without going offline","T1090 - T1090.002 - T1573 - T1573.001 - T1573.002","TA0011","N/A","N/A","C2","https://github.com/Daybr4ak/C2ReverseProxy","1","1","N/A","N/A","10","10","486","56","2023-04-26T13:16:26Z","2020-01-16T05:43:35Z","5921" +"*/C2ReverseProxy/*",".{0,1000}\/C2ReverseProxy\/.{0,1000}","offensive_tool_keyword","C2ReverseProxy","ReverseProxy C2 - Bring CS online without going offline","T1090 - T1090.002 - T1573 - T1573.001 - T1573.002","TA0011","N/A","N/A","C2","https://github.com/Daybr4ak/C2ReverseProxy","1","1","N/A","N/A","10","10","486","56","2023-04-26T13:16:26Z","2020-01-16T05:43:35Z","5922" +"*/C2ReverseProxy/tarball*",".{0,1000}\/C2ReverseProxy\/tarball.{0,1000}","offensive_tool_keyword","C2ReverseProxy","ReverseProxy C2 - Bring CS online without going offline","T1090 - T1090.002 - T1573 - T1573.001 - T1573.002","TA0011","N/A","N/A","C2","https://github.com/Daybr4ak/C2ReverseProxy","1","1","N/A","N/A","10","10","486","56","2023-04-26T13:16:26Z","2020-01-16T05:43:35Z","5923" +"*/C2ReverseProxy/zipball*",".{0,1000}\/C2ReverseProxy\/zipball.{0,1000}","offensive_tool_keyword","C2ReverseProxy","ReverseProxy C2 - Bring CS online without going offline","T1090 - T1090.002 - T1573 - T1573.001 - T1573.002","TA0011","N/A","N/A","C2","https://github.com/Daybr4ak/C2ReverseProxy","1","1","N/A","N/A","10","10","486","56","2023-04-26T13:16:26Z","2020-01-16T05:43:35Z","5924" +"*/C2ReverseServer*",".{0,1000}\/C2ReverseServer.{0,1000}","offensive_tool_keyword","C2ReverseProxy","ReverseProxy C2 - Bring CS online without going offline","T1090 - T1090.002 - T1573 - T1573.001 - T1573.002","TA0011","N/A","N/A","C2","https://github.com/Daybr4ak/C2ReverseProxy","1","1","N/A","N/A","10","10","486","56","2023-04-26T13:16:26Z","2020-01-16T05:43:35Z","5925" +"*/C2script/*",".{0,1000}\/C2script\/.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool that can perform reverse proxy and cs online without going online","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Daybr4ak/C2ReverseProxy","1","1","N/A","N/A","10","10","486","56","2023-04-26T13:16:26Z","2020-01-16T05:43:35Z","5926" +"*/C2Server.py*",".{0,1000}\/C2Server\.py.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","5927" +"*/C2-Tool-Collection/*",".{0,1000}\/C2\-Tool\-Collection\/.{0,1000}","offensive_tool_keyword","C2-Tool-Collection","A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques","T1055 - T1218 - T1059 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","C2","https://github.com/outflanknl/C2-Tool-Collection","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","5928" +"*/C3/releases/download/*/C3-*",".{0,1000}\/C3\/releases\/download\/.{0,1000}\/C3\-.{0,1000}","offensive_tool_keyword","C3","Framework designed for red teams to create and manage custom C2 (Command and Control) channels. Unlike traditional C2 frameworks that rely on typical communication methods like HTTP/S DNS or TCP - C3 allows for the creation of non-traditional and esoteric C2 channels using platforms like Slack Dropbox GitHub OneDrive and more.","T1071 - T1102 - T1090 - T1573 - T1048","TA0011 - TA0002 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/WithSecureLabs/C3","1","1","N/A","N/A","9","10","1602","276","2023-03-04T20:32:13Z","2019-08-30T11:21:04Z","5929" +"*/C3WebController.dll*",".{0,1000}\/C3WebController\.dll.{0,1000}","offensive_tool_keyword","C3","Framework designed for red teams to create and manage custom C2 (Command and Control) channels. Unlike traditional C2 frameworks that rely on typical communication methods like HTTP/S DNS or TCP - C3 allows for the creation of non-traditional and esoteric C2 channels using platforms like Slack Dropbox GitHub OneDrive and more.","T1071 - T1102 - T1090 - T1573 - T1048","TA0011 - TA0002 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/WithSecureLabs/C3","1","1","N/A","N/A","9","10","1602","276","2023-03-04T20:32:13Z","2019-08-30T11:21:04Z","5930" +"*/c99_locus7s.php*",".{0,1000}\/c99_locus7s\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5931" +"*/c99_PSych0.php*",".{0,1000}\/c99_PSych0\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5932" +"*/c99_w4cking.php*",".{0,1000}\/c99_w4cking\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5933" +"*/c99madshell.php*",".{0,1000}\/c99madshell\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5934" +"*/c99shell.php*",".{0,1000}\/c99shell\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5935" +"*/cachedump.py*",".{0,1000}\/cachedump\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","5937" +"*/CACTUSTORCH.git*",".{0,1000}\/CACTUSTORCH\.git.{0,1000}","offensive_tool_keyword","CACTUSTORCH","A JavaScript and VBScript shellcode launcher. This will spawn a 32 bit version of the binary specified and inject shellcode into it.","T1055.011 - T1059.005 - T1059.007","TA0002 - TA0005","N/A","APT32","Exploitation tool","https://github.com/mdsecactivebreach/CACTUSTORCH","1","1","N/A","N/A","8","10","1006","227","2018-07-03T06:47:36Z","2017-07-04T10:20:34Z","5938" +"*/CaiDao-Webshell-Password-LandGrey.jsp*",".{0,1000}\/CaiDao\-Webshell\-Password\-LandGrey\.jsp.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","5939" +"*/cain.html*",".{0,1000}\/cain\.html.{0,1000}","offensive_tool_keyword","Cain&Abel","Cain & Able exploitation tool file ","T1075 - T1110 - T1071 - T1003 - T1555","TA0003 - TA0008","N/A","FIN7 - Night Dragon","Credential Access","https://github.com/undergroundwires/CEH-in-bullet-points/blob/master/chapters/08-sniffing/sniffing-tools.md","1","1","N/A","N/A","N/A","10","1067","310","2024-08-13T04:35:50Z","2021-05-11T12:38:17Z","5940" +"*/CamHacker-*.png*",".{0,1000}\/CamHacker\-.{0,1000}\.png.{0,1000}","offensive_tool_keyword","CamHacker","Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!","T1598 - T1204 - T1566.001","TA0009 - TA0010 - TA0043","N/A","N/A","Phishing","https://github.com/KasRoudra/CamHacker","1","1","N/A","N/A","10","","N/A","","","","5941" +"*/CamHacker.git*",".{0,1000}\/CamHacker\.git.{0,1000}","offensive_tool_keyword","CamHacker","Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!","T1598 - T1204 - T1566.001","TA0009 - TA0010 - TA0043","N/A","N/A","Phishing","https://github.com/KasRoudra/CamHacker","1","1","N/A","N/A","10","","N/A","","","","5942" +"*/Cam-Hackers.git*",".{0,1000}\/Cam\-Hackers\.git.{0,1000}","offensive_tool_keyword","Cam-Hackers","Hack Cameras CCTV FREE","T1125","TA0007","N/A","N/A","Discovery","https://github.com/AngelSecurityTeam/Cam-Hackers","1","1","N/A","N/A","6","10","2025","512","2024-08-06T18:49:02Z","2019-11-16T18:49:35Z","5943" +"*/campaign/*/implant/get_all*",".{0,1000}\/campaign\/.{0,1000}\/implant\/get_all.{0,1000}","offensive_tool_keyword","FudgeC2","FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.","T1021.002 - T1105 - T1059.001 - T1059.003","TA0008 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/Ziconius/FudgeC2","1","1","N/A","N/A","10","10","253","54","2023-05-01T21:13:56Z","2018-09-09T21:05:21Z","5944" +"*/canary.go",".{0,1000}\/canary\.go","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","5945" +"*/CandyPotato.cpp*",".{0,1000}\/CandyPotato\.cpp.{0,1000}","offensive_tool_keyword","CandyPotato","CandyPotato - Pure C++ weaponized fully automated implementation of RottenPotatoNG. This tool has been made on top of the original JuicyPotato with the main focus on improving and adding some functionalities which was lacking","T1547.004","TA0002","N/A","Volatile Cedar","Exploitation tool","https://github.com/klezVirus/CandyPotato","1","1","N/A","N/A","N/A","4","306","67","2021-09-16T17:08:52Z","2020-08-21T17:14:30Z","5946" +"*/CandyPotato.sdf*",".{0,1000}\/CandyPotato\.sdf.{0,1000}","offensive_tool_keyword","CandyPotato","CandyPotato - Pure C++ weaponized fully automated implementation of RottenPotatoNG. This tool has been made on top of the original JuicyPotato with the main focus on improving and adding some functionalities which was lacking","T1547.004","TA0002","N/A","Volatile Cedar","Exploitation tool","https://github.com/klezVirus/CandyPotato","1","1","N/A","N/A","N/A","4","306","67","2021-09-16T17:08:52Z","2020-08-21T17:14:30Z","5947" +"*/CandyPotato.sln*",".{0,1000}\/CandyPotato\.sln.{0,1000}","offensive_tool_keyword","CandyPotato","CandyPotato - Pure C++ weaponized fully automated implementation of RottenPotatoNG. This tool has been made on top of the original JuicyPotato with the main focus on improving and adding some functionalities which was lacking","T1547.004","TA0002","N/A","Volatile Cedar","Exploitation tool","https://github.com/klezVirus/CandyPotato","1","1","N/A","N/A","N/A","4","306","67","2021-09-16T17:08:52Z","2020-08-21T17:14:30Z","5948" +"*/CandyPotato.vcxproj*",".{0,1000}\/CandyPotato\.vcxproj.{0,1000}","offensive_tool_keyword","CandyPotato","CandyPotato - Pure C++ weaponized fully automated implementation of RottenPotatoNG. This tool has been made on top of the original JuicyPotato with the main focus on improving and adding some functionalities which was lacking","T1547.004","TA0002","N/A","Volatile Cedar","Exploitation tool","https://github.com/klezVirus/CandyPotato","1","1","N/A","N/A","N/A","4","306","67","2021-09-16T17:08:52Z","2020-08-21T17:14:30Z","5949" +"*/canisrufus.git*",".{0,1000}\/canisrufus\.git.{0,1000}","offensive_tool_keyword","canisrufus","A stealthy Python based Windows backdoor that uses Github as a command and control server","T1105 - T1071 - T1027","TA0003 - TA0011 - TA0005 - TA0010","N/A","Black Basta","C2","https://github.com/maldevel/canisrufus","1","1","N/A","N/A","10","10","263","78","2017-08-15T15:46:20Z","2017-08-12T06:49:40Z","5950" +"*/canisrufus.py*",".{0,1000}\/canisrufus\.py.{0,1000}","offensive_tool_keyword","canisrufus","A stealthy Python based Windows backdoor that uses Github as a command and control server","T1105 - T1071 - T1027","TA0003 - TA0011 - TA0005 - TA0010","N/A","Black Basta","C2","https://github.com/maldevel/canisrufus","1","1","N/A","N/A","10","10","263","78","2017-08-15T15:46:20Z","2017-08-12T06:49:40Z","5951" +"*/capture_netntlmv2.py*",".{0,1000}\/capture_netntlmv2\.py.{0,1000}","offensive_tool_keyword","specula","Specula is a C2 framework that allows for interactive operations of an implant that runs purely in the context of outlook","T1071.001 - T1105 - T1204 - T1548.002 - T1071 - T1562","TA0011 - TA0002 - TA0003 - TA0006 - TA0008 - TA0007 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/trustedsec/specula","1","1","N/A","N/A","10","10","191","21","2024-09-23T09:25:33Z","2023-12-07T15:59:52Z","5953" +"*/carlosevieira/Dirty-Pipe*",".{0,1000}\/carlosevieira\/Dirty\-Pipe.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","t1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/carlosevieira/Dirty-Pipe","1","1","N/A","N/A","N/A","1","9","6","2022-03-07T21:01:15Z","2022-03-07T20:57:34Z","5954" +"*/Carseat.git*",".{0,1000}\/Carseat\.git.{0,1000}","offensive_tool_keyword","Carseat","Python implementation of GhostPack Seatbelt situational awareness tool","T1012 - T1082 - T1087 - T1124 - T1217","TA0006 - TA0007 - TA0009","N/A","N/A","Collection","https://github.com/0xthirteen/Carseat","1","1","N/A","N/A","8","3","257","21","2024-11-12T19:37:38Z","2024-11-08T02:08:53Z","5955" +"*/cassandra-brute.nse*",".{0,1000}\/cassandra\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5957" +"*/cassandra-info.nse*",".{0,1000}\/cassandra\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5958" +"*/catspin.git*",".{0,1000}\/catspin\.git.{0,1000}","offensive_tool_keyword","catspin","Catspin rotates the IP address of HTTP requests making IP based blocks or slowdown measures ineffective. It is based on AWS API Gateway and deployed via AWS Cloudformation.","T1027 - T1071 - T1047 - T1090","TA0042 - TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/rootcathacking/catspin","1","1","N/A","N/A","9","3","261","32","2024-03-01T09:25:02Z","2022-07-26T08:08:33Z","5959" +"*/catspin-main/*",".{0,1000}\/catspin\-main\/.{0,1000}","offensive_tool_keyword","catspin","Catspin rotates the IP address of HTTP requests making IP based blocks or slowdown measures ineffective. It is based on AWS API Gateway and deployed via AWS Cloudformation.","T1027 - T1071 - T1047 - T1090","TA0042 - TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/rootcathacking/catspin","1","1","N/A","N/A","9","3","261","32","2024-03-01T09:25:02Z","2022-07-26T08:08:33Z","5960" +"*/cc2_frp.*",".{0,1000}\/cc2_frp\..{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","5961" +"*/cccam-version.nse*",".{0,1000}\/cccam\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5962" +"*/ccmpwn.git*",".{0,1000}\/ccmpwn\.git.{0,1000}","offensive_tool_keyword","ccmpwn","Lateral Movement script that leverages the CcmExec service to remotely hijack user sessions","T1021.005","TA0008","N/A","N/A","Lateral Movement","https://github.com/mandiant/ccmpwn","1","1","N/A","N/A","10","3","201","25","2024-03-26T20:51:27Z","2024-03-14T18:43:24Z","5963" +"*/ccmpwn.py*",".{0,1000}\/ccmpwn\.py.{0,1000}","offensive_tool_keyword","ccmpwn","Lateral Movement script that leverages the CcmExec service to remotely hijack user sessions","T1021.005","TA0008","N/A","N/A","Lateral Movement","https://github.com/mandiant/ccmpwn","1","1","N/A","N/A","10","3","201","25","2024-03-26T20:51:27Z","2024-03-14T18:43:24Z","5964" +"*/CCob/Volumiser*",".{0,1000}\/CCob\/Volumiser.{0,1000}","offensive_tool_keyword","Volumiser","Volumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats.","T1560.001 - T1059 - T1114 - T1005","TA0005 - TA0009","N/A","N/A","Collection","https://github.com/CCob/Volumiser","1","1","N/A","N/A","7","4","379","42","2025-04-22T15:47:53Z","2022-11-08T21:38:56Z","5965" +"*/CelestialSpark.git*",".{0,1000}\/CelestialSpark\.git.{0,1000}","offensive_tool_keyword","CelestialSpark","A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders Stardust","T1572 - T1048 - T1041 - T1105","TA0005 - TA0011 - TA0010","N/A","N/A","C2","https://github.com/Karkas66/CelestialSpark","1","1","N/A","N/A","10","10","103","10","2025-03-27T12:47:34Z","2024-04-11T12:17:22Z","5971" +"*/cerbrutus*",".{0,1000}\/cerbrutus.{0,1000}","offensive_tool_keyword","cerbrutus","Network brute force tool. written in Python. Faster than other existing solutions (including the main leader in the network brute force market).","T1110 - T1040 - T1496","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/Cerbrutus-BruteForcer/cerbrutus","1","1","N/A","N/A","N/A","4","385","57","2021-08-22T19:05:45Z","2021-07-07T19:11:40Z","5972" +"*/Certify.exe*",".{0,1000}\/Certify\.exe.{0,1000}","offensive_tool_keyword","Certify","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","Certify","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","5973" +"*/Certify.exe*",".{0,1000}\/Certify\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","Certify","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","5974" +"*/Certipy.exe*",".{0,1000}\/Certipy\.exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","5975" +"*/Certipy.git*",".{0,1000}\/Certipy\.git.{0,1000}","offensive_tool_keyword","Certipy","Tool for Active Directory Certificate Services enumeration and abuse","T1552.003 - T1110.003 - T1550.004 - T1649","TA0006 - TA0008 - TA0003","N/A","Dispossessor","Exploitation tool","https://github.com/ly4k/Certipy","1","1","N/A","N/A","10","10","2704","380","2024-08-19T17:33:04Z","2021-10-06T23:02:40Z","5976" +"*/Certipy/*",".{0,1000}\/Certipy\/.{0,1000}","offensive_tool_keyword","Certipy","Tool for Active Directory Certificate Services enumeration and abuse","T1552.003 - T1110.003 - T1550.004 - T1649","TA0006 - TA0008 - TA0003","N/A","Dispossessor","Exploitation tool","https://github.com/ly4k/Certipy","1","1","N/A","N/A","10","10","2704","380","2024-08-19T17:33:04Z","2021-10-06T23:02:40Z","5977" +"*/certipy64.exe*",".{0,1000}\/certipy64\.exe.{0,1000}","offensive_tool_keyword","Certipy","Tool for Active Directory Certificate Services enumeration and abuse","T1552.003 - T1110.003 - T1550.004 - T1649","TA0006 - TA0008 - TA0003","N/A","Dispossessor","Exploitation tool","https://github.com/ly4k/Certipy","1","1","N/A","N/A","10","10","2704","380","2024-08-19T17:33:04Z","2021-10-06T23:02:40Z","5978" +"*/CertStealer*",".{0,1000}\/CertStealer.{0,1000}","offensive_tool_keyword","CertStealer","A .NET tool for exporting and importing certificates without touching disk.","T1552.001 - T1140 - T1005 - T1649","TA0006 - TA0005","N/A","N/A","Exploitation tool","https://github.com/TheWover/CertStealer","1","1","N/A","N/A","10","5","487","68","2021-10-08T20:48:34Z","2021-04-21T14:20:56Z","5981" +"*/certsync.git*",".{0,1000}\/certsync\.git.{0,1000}","offensive_tool_keyword","certsync","Dump NTDS with golden certificates and UnPAC the hash","T1553.002 - T1003.001 - T1145 - T1649","TA0002 - TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/zblurx/certsync","1","1","N/A","N/A","10","7","633","66","2024-03-20T10:58:15Z","2023-01-31T15:37:12Z","5982" +"*/ChaiLdr.exe*",".{0,1000}\/ChaiLdr\.exe.{0,1000}","offensive_tool_keyword","ChaiLdr","Indirect syscalls AV bypass","T1055.011 - T1569 - T1564 - T1213","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Cipher7/ChaiLdr","1","1","N/A","N/A","9","3","220","35","2024-05-17T13:58:04Z","2024-03-29T09:19:10Z","5984" +"*/ChaiLdr.git*",".{0,1000}\/ChaiLdr\.git.{0,1000}","offensive_tool_keyword","ChaiLdr","Indirect syscalls AV bypass","T1055.011 - T1569 - T1564 - T1213","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Cipher7/ChaiLdr","1","1","N/A","N/A","9","3","220","35","2024-05-17T13:58:04Z","2024-03-29T09:19:10Z","5985" +"*/ChainBuilder.py*",".{0,1000}\/ChainBuilder\.py.{0,1000}","offensive_tool_keyword","Exrop","Exrop is automatic ROP chains generator tool which can build gadget chain automatically from given binary and constraints","T1554","TA0003","N/A","N/A","Exploitation tool","https://github.com/d4em0n/exrop","1","1","N/A","N/A","N/A","3","285","22","2020-02-21T08:01:06Z","2020-01-19T05:09:00Z","5986" +"*/Chakra.dll*",".{0,1000}\/Chakra\.dll.{0,1000}","offensive_tool_keyword","dropper","Generates Malicious Office Macro Enabled Dropper for DLL SideLoading and Embed it in Lnk file to bypass MOTW","T1059 - T1574.002 - T1218 - T1559.003","TA0002 - TA0005 - TA0009","N/A","N/A","Resource Development","https://github.com/SaadAhla/dropper","1","1","N/A","N/A","10","3","N/A","N/A","N/A","N/A","5987" +"*/changepasswd.py*",".{0,1000}\/changepasswd\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","#linux","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","5988" +"*/ChannelLinter.exe*",".{0,1000}\/ChannelLinter\.exe.{0,1000}","offensive_tool_keyword","C3","Framework designed for red teams to create and manage custom C2 (Command and Control) channels. Unlike traditional C2 frameworks that rely on typical communication methods like HTTP/S DNS or TCP - C3 allows for the creation of non-traditional and esoteric C2 channels using platforms like Slack Dropbox GitHub OneDrive and more.","T1071 - T1102 - T1090 - T1573 - T1048","TA0011 - TA0002 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/WithSecureLabs/C3","1","1","N/A","N/A","9","10","1602","276","2023-03-04T20:32:13Z","2019-08-30T11:21:04Z","5989" +"*/ChannelLinter_d64.exe*",".{0,1000}\/ChannelLinter_d64\.exe.{0,1000}","offensive_tool_keyword","C3","Framework designed for red teams to create and manage custom C2 (Command and Control) channels. Unlike traditional C2 frameworks that rely on typical communication methods like HTTP/S DNS or TCP - C3 allows for the creation of non-traditional and esoteric C2 channels using platforms like Slack Dropbox GitHub OneDrive and more.","T1071 - T1102 - T1090 - T1573 - T1048","TA0011 - TA0002 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/WithSecureLabs/C3","1","1","N/A","N/A","9","10","1602","276","2023-03-04T20:32:13Z","2019-08-30T11:21:04Z","5990" +"*/CHAOS.git*",".{0,1000}\/CHAOS\.git.{0,1000}","offensive_tool_keyword","chaos","CHAOS is a free and open-source Remote Administration Tool that allow generate binaries to control remote operating systems","T1105 - T1059 - T1021 - T1041 - T1569.002 - T1573","TA0002 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/tiagorlampert/CHAOS","1","1","N/A","N/A","10","10","2483","541","2024-10-26T18:02:45Z","2017-07-11T06:54:56Z","5991" +"*/CHAOS-5.0.1.zip*",".{0,1000}\/CHAOS\-5\.0\.1\.zip.{0,1000}","offensive_tool_keyword","chaos","CHAOS is a free and open-source Remote Administration Tool that allow generate binaries to control remote operating systems","T1105 - T1059 - T1021 - T1041 - T1569.002 - T1573","TA0002 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/tiagorlampert/CHAOS","1","1","N/A","N/A","10","10","2483","541","2024-10-26T18:02:45Z","2017-07-11T06:54:56Z","5992" +"*/chaos-container:/database/*",".{0,1000}\/chaos\-container\:\/database\/.{0,1000}","offensive_tool_keyword","chaos","CHAOS is a free and open-source Remote Administration Tool that allow generate binaries to control remote operating systems","T1105 - T1059 - T1021 - T1041 - T1569.002 - T1573","TA0002 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/tiagorlampert/CHAOS","1","1","N/A","N/A","10","10","2483","541","2024-10-26T18:02:45Z","2017-07-11T06:54:56Z","5993" +"*/charlotte.cpp*",".{0,1000}\/charlotte\.cpp.{0,1000}","offensive_tool_keyword","charlotte","c++ fully undetected shellcode launcher","T1055.012 - T1059.003 - T1027.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/9emin1/charlotte","1","1","N/A","N/A","10","10","976","211","2021-06-11T04:44:18Z","2021-05-13T07:32:03Z","5994" +"*/charlotte.py*",".{0,1000}\/charlotte\.py.{0,1000}","offensive_tool_keyword","charlotte","c++ fully undetected shellcode launcher","T1055.012 - T1059.003 - T1027.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/9emin1/charlotte","1","1","N/A","N/A","10","10","976","211","2021-06-11T04:44:18Z","2021-05-13T07:32:03Z","5995" +"*/chashell.git*",".{0,1000}\/chashell\.git.{0,1000}","offensive_tool_keyword","chashell","Chashell is a Go reverse shell that communicates over DNS. It can be used to bypass firewalls or tightly restricted networks","T1071.004 - T1572 - T1071 - T1027","TA0011 - TA0005 - TA0008","N/A","PYSA","C2","https://github.com/sysdream/chashell","1","1","N/A","N/A","10","10","1068","135","2022-04-05T17:22:14Z","2019-02-15T14:54:48Z","5996" +"*/CheckPort.exe*",".{0,1000}\/CheckPort\.exe.{0,1000}","offensive_tool_keyword","CheckPort","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","CheckPort","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","5997" +"*/CheckPort.exe*",".{0,1000}\/CheckPort\.exe.{0,1000}","offensive_tool_keyword","KrbRelay","Relaying 3-headed dogs. More details at https://googleprojectzero.blogspot.com/2021/10/windows-exploitation-tricks-relaying.html and https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html","T1212 - T1558 - T1550","TA0001 - TA0004 -TA0006","N/A","Dispossessor","Exploitation tool","https://github.com/cube0x0/KrbRelay","1","1","N/A","N/A","N/A","10","907","125","2022-05-29T09:45:03Z","2022-02-14T08:21:57Z","5998" +"*/CheckPort.exe*",".{0,1000}\/CheckPort\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","CheckPort","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","5999" +"*/CheckSMBSigning.git*",".{0,1000}\/CheckSMBSigning\.git.{0,1000}","offensive_tool_keyword","CheckSMBSigning","Checks for SMB signing disabled on all hosts in the network","T1018 - T1550","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/Leo4j/CheckSMBSigning","1","1","N/A","N/A","6","1","8","1","2023-10-13T11:55:33Z","2023-05-17T11:47:52Z","6001" +"*/CheckSMBSigning.ps1*",".{0,1000}\/CheckSMBSigning\.ps1.{0,1000}","offensive_tool_keyword","CheckSMBSigning","Checks for SMB signing disabled on all hosts in the network","T1018 - T1550","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/Leo4j/CheckSMBSigning","1","1","N/A","N/A","6","1","8","1","2023-10-13T11:55:33Z","2023-05-17T11:47:52Z","6002" +"*/CheeseTools.git*",".{0,1000}\/CheeseTools\.git.{0,1000}","offensive_tool_keyword","CheeseTools","tools for Lateral Movement/Code Execution","T1021.006 - T1059.003 - T1105","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/klezVirus/CheeseTools","1","1","N/A","N/A","10","8","706","143","2021-08-17T20:22:56Z","2020-08-24T01:28:12Z","6003" +"*/cheetah.git*",".{0,1000}\/cheetah\.git.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","1","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","6004" +"*/Chimera.git*",".{0,1000}\/Chimera\.git.{0,1000}","offensive_tool_keyword","chimera","Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.","T1027.002 - T1059.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/tokyoneon/Chimera/","1","1","N/A","N/A","10","10","1493","252","2021-11-09T12:39:59Z","2020-09-01T07:42:22Z","6006" +"*/chimera.sh*",".{0,1000}\/chimera\.sh.{0,1000}","offensive_tool_keyword","chimera","Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.","T1027.002 - T1059.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/tokyoneon/Chimera/","1","1","N/A","N/A","10","10","1493","252","2021-11-09T12:39:59Z","2020-09-01T07:42:22Z","6008" +"*/chisel.exe*",".{0,1000}\/chisel\.exe.{0,1000}","offensive_tool_keyword","chisel","A fast TCP/UDP tunnel over HTTP","T1090 - T1090.003 - T1572 - T1572.001","TA0042 - TA0011","N/A","BlackSuit - Royal - AvosLocker - Cactus - Yanluowang - Sandworm - KNOTWEED","C2","https://github.com/jpillora/chisel","1","1","N/A","N/A","10","10","14432","1466","2024-09-28T23:35:13Z","2015-02-25T11:42:50Z","6009" +"*/chisel.git*",".{0,1000}\/chisel\.git.{0,1000}","offensive_tool_keyword","chisel","A fast TCP/UDP tunnel over HTTP","T1090 - T1090.003 - T1572 - T1572.001","TA0042 - TA0011","N/A","BlackSuit - Royal - AvosLocker - Cactus - Yanluowang - Sandworm - KNOTWEED","C2","https://github.com/jpillora/chisel","1","1","N/A","N/A","10","10","14432","1466","2024-09-28T23:35:13Z","2015-02-25T11:42:50Z","6010" +"*/chisel_x32*",".{0,1000}\/chisel_x32.{0,1000}","offensive_tool_keyword","D3m0n1z3dShell","Demonized Shell is an Advanced Tool for persistence in linux","T1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037","TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Persistence","https://github.com/MatheuZSecurity/D3m0n1z3dShell","1","1","#linux","N/A","10","4","373","54","2025-01-05T13:56:51Z","2023-05-30T02:30:47Z","6014" +"*/chisel_x64*",".{0,1000}\/chisel_x64.{0,1000}","offensive_tool_keyword","D3m0n1z3dShell","Demonized Shell is an Advanced Tool for persistence in linux","T1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037","TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Persistence","https://github.com/MatheuZSecurity/D3m0n1z3dShell","1","1","#linux","N/A","10","4","373","54","2025-01-05T13:56:51Z","2023-05-30T02:30:47Z","6015" +"*/chisel-darwin_amd64*",".{0,1000}\/chisel\-darwin_amd64.{0,1000}","offensive_tool_keyword","chisel","A fast TCP/UDP tunnel over HTTP","T1090 - T1090.003 - T1572 - T1572.001","TA0042 - TA0011","N/A","BlackSuit - Royal - AvosLocker - Cactus - Yanluowang - Sandworm - KNOTWEED","C2","https://github.com/jpillora/chisel","1","1","#linux","N/A","10","10","14432","1466","2024-09-28T23:35:13Z","2015-02-25T11:42:50Z","6016" +"*/chisel-freebsd*",".{0,1000}\/chisel\-freebsd.{0,1000}","offensive_tool_keyword","chisel","A fast TCP/UDP tunnel over HTTP","T1090 - T1090.003 - T1572 - T1572.001","TA0042 - TA0011","N/A","BlackSuit - Royal - AvosLocker - Cactus - Yanluowang - Sandworm - KNOTWEED","C2","https://github.com/jpillora/chisel","1","1","N/A","N/A","10","10","14432","1466","2024-09-28T23:35:13Z","2015-02-25T11:42:50Z","6017" +"*/chisel-linux_*",".{0,1000}\/chisel\-linux_.{0,1000}","offensive_tool_keyword","chisel","A fast TCP/UDP tunnel over HTTP","T1090 - T1090.003 - T1572 - T1572.001","TA0042 - TA0011","N/A","BlackSuit - Royal - AvosLocker - Cactus - Yanluowang - Sandworm - KNOTWEED","C2","https://github.com/jpillora/chisel","1","1","#linux","N/A","10","10","14432","1466","2024-09-28T23:35:13Z","2015-02-25T11:42:50Z","6018" +"*/chisel-master*",".{0,1000}\/chisel\-master.{0,1000}","offensive_tool_keyword","chisel","A fast TCP/UDP tunnel over HTTP","T1090 - T1090.003 - T1572 - T1572.001","TA0042 - TA0011","N/A","BlackSuit - Royal - AvosLocker - Cactus - Yanluowang - Sandworm - KNOTWEED","C2","https://github.com/jpillora/chisel","1","1","N/A","N/A","10","10","14432","1466","2024-09-28T23:35:13Z","2015-02-25T11:42:50Z","6019" +"*/chisel-windows_amd6*",".{0,1000}\/chisel\-windows_amd6.{0,1000}","offensive_tool_keyword","chisel","A fast TCP/UDP tunnel over HTTP","T1090 - T1090.003 - T1572 - T1572.001","TA0042 - TA0011","N/A","BlackSuit - Royal - AvosLocker - Cactus - Yanluowang - Sandworm - KNOTWEED","C2","https://github.com/jpillora/chisel","1","1","N/A","N/A","10","10","14432","1466","2024-09-28T23:35:13Z","2015-02-25T11:42:50Z","6020" +"*/chntpw-140201*",".{0,1000}\/chntpw\-140201.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","6022" +"*/chrome_decrypt.exe*",".{0,1000}\/chrome_decrypt\.exe.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","1","N/A","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","6025" +"*/chrome_decrypt.py*",".{0,1000}\/chrome_decrypt\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","6026" +"*/Chrome-App-Bound-Encryption-Decryption.git*",".{0,1000}\/Chrome\-App\-Bound\-Encryption\-Decryption\.git.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","1","N/A","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","6029" +"*/ChromeDump.ahk*",".{0,1000}\/ChromeDump\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","6030" +"*/ChromeDump/*",".{0,1000}\/ChromeDump\/.{0,1000}","offensive_tool_keyword","chromedump","ChromeDump is a small tool to dump all JavaScript and other ressources going through the browser","T1059.007 - T1114.001 - T1518.001 - T1552.002","TA0005 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/g4l4drim/ChromeDump","1","1","N/A","N/A","N/A","1","55","1","2024-10-12T14:07:36Z","2023-01-26T20:44:06Z","6031" +"*/ChromeKatz.git*",".{0,1000}\/ChromeKatz\.git.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","6032" +"*/chromepasswordlist.csv*",".{0,1000}\/chromepasswordlist\.csv.{0,1000}","offensive_tool_keyword","WinPirate","automated sticky keys backdoor + credentials harvesting","T1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003","TA0003 - TA0005 - TA0006","N/A","N/A","Persistence","https://github.com/l3m0n/WinPirate","1","1","N/A","N/A","9","1","13","32","2016-07-17T20:02:07Z","2016-07-18T03:40:13Z","6033" +"*/chromepasswords.py*",".{0,1000}\/chromepasswords\.py.{0,1000}","offensive_tool_keyword","WinPirate","automated sticky keys backdoor + credentials harvesting","T1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003","TA0003 - TA0005 - TA0006","N/A","N/A","Persistence","https://github.com/l3m0n/WinPirate","1","1","N/A","N/A","9","1","13","32","2016-07-17T20:02:07Z","2016-07-18T03:40:13Z","6034" +"*/ChromeStealer.git*",".{0,1000}\/ChromeStealer\.git.{0,1000}","offensive_tool_keyword","ChromeStealer","extract and decrypt stored passwords from Google Chrome","T1555.003 - T1003.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/BernKing/ChromeStealer","1","1","N/A","N/A","8","2","145","18","2024-07-25T08:27:10Z","2024-07-14T13:27:30Z","6035" +"*/chromium_based_browsers.py*",".{0,1000}\/chromium_based_browsers\.py.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","1","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","6036" +"*/chromium_history.py*",".{0,1000}\/chromium_history\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","6037" +"*/chromium_logins.py*",".{0,1000}\/chromium_logins\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","6038" +"*/Chunk-Proxy.git*",".{0,1000}\/Chunk\-Proxy\.git.{0,1000}","offensive_tool_keyword","chunk-Proxy","A backdoor installed on a web server that allows for the execution of commands and facilitates persistent access.","T1505.003 - T1059 - T1105 - T1071","TA0011 - TA0002 - TA0003","Ghost Ransomware","N/A","C2","https://github.com/BeichenDream/Chunk-Proxy","1","1","N/A","N/A","10","10","283","40","2022-05-07T04:24:50Z","2021-10-28T18:45:21Z","6039" +"*/cics-enum.nse*",".{0,1000}\/cics\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6041" +"*/cics-info.nse*",".{0,1000}\/cics\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6042" +"*/cics-user-brute.nse*",".{0,1000}\/cics\-user\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6043" +"*/cics-user-enum.nse*",".{0,1000}\/cics\-user\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6044" +"*/CIMplant.exe*",".{0,1000}\/CIMplant\.exe.{0,1000}","offensive_tool_keyword","CIMplant","C# port of WMImplant which uses either CIM or WMI to query remote systems","T1047 - T1059.001 - T1021.006","TA0002 - TA0007 - TA0008","N/A","Scattered Spider*","Lateral Movement","https://github.com/RedSiege/CIMplant","1","1","N/A","N/A","10","2","199","29","2021-07-14T18:18:42Z","2021-01-29T21:41:58Z","6045" +"*/CIMplant.git*",".{0,1000}\/CIMplant\.git.{0,1000}","offensive_tool_keyword","CIMplant","C# port of WMImplant which uses either CIM or WMI to query remote systems","T1047 - T1059.001 - T1021.006","TA0002 - TA0007 - TA0008","N/A","Scattered Spider*","Lateral Movement","https://github.com/RedSiege/CIMplant","1","1","N/A","N/A","10","2","199","29","2021-07-14T18:18:42Z","2021-01-29T21:41:58Z","6046" +"*/CIMplant/Commander.cs*",".{0,1000}\/CIMplant\/Commander\.cs.{0,1000}","offensive_tool_keyword","CIMplant","C# port of WMImplant which uses either CIM or WMI to query remote systems","T1047 - T1059.001 - T1021.006","TA0002 - TA0007 - TA0008","N/A","Scattered Spider*","Lateral Movement","https://github.com/RedSiege/CIMplant","1","1","N/A","N/A","10","2","199","29","2021-07-14T18:18:42Z","2021-01-29T21:41:58Z","6047" +"*/citrix-brute-xml.nse*",".{0,1000}\/citrix\-brute\-xml\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6048" +"*/citrix-enum-apps.nse*",".{0,1000}\/citrix\-enum\-apps\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6049" +"*/citrix-enum-apps-xml.nse*",".{0,1000}\/citrix\-enum\-apps\-xml\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6050" +"*/citrix-enum-servers.nse*",".{0,1000}\/citrix\-enum\-servers\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6051" +"*/citrix-enum-servers-xml.nse*",".{0,1000}\/citrix\-enum\-servers\-xml\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6052" +"*/clamav-exec.nse*",".{0,1000}\/clamav\-exec\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6053" +"*/cleantracks.ps1",".{0,1000}\/cleantracks\.ps1","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","6055" +"*/ClearnEventRecordID.ps1*",".{0,1000}\/ClearnEventRecordID\.ps1.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6057" +"*/ClearnIpAddress.ps1*",".{0,1000}\/ClearnIpAddress\.ps1.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6058" +"*/ClearnTempLog.ps1*",".{0,1000}\/ClearnTempLog\.ps1.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6059" +"*/clfs_eop.exe*",".{0,1000}\/clfs_eop\.exe.{0,1000}","offensive_tool_keyword","POC","CVE-2024-6768: Improper validation of specified quantity in input produces an unrecoverable state in CLFS.sys causing a BSoD","T1499 - T1485","TA0043 - TA0042 - TA0005","N/A","N/A","Impact","https://github.com/fortra/CVE-2024-6768","1","1","N/A","N/A","10","1","16","4","2024-08-12T20:48:52Z","2024-07-18T07:52:46Z","6060" +"*/ClickJack.exe",".{0,1000}\/ClickJack\.exe","offensive_tool_keyword","clickjack","automate abuse of clickonce applications","T1210 - T1204 - T1071.001","TA0001 - TA0002 - TA0005","N/A","N/A","Phishing","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","6061" +"*/clickme.docx*",".{0,1000}\/clickme\.docx.{0,1000}","offensive_tool_keyword","POC","CVE-2022-30190 Follina POC","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/onecloudemoji/CVE-2022-30190","1","1","N/A","N/A","N/A","2","104","27","2022-05-31T09:35:37Z","2022-05-31T06:45:25Z","6062" +"*/client/beef.js*",".{0,1000}\/client\/beef\.js.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","6063" +"*/client/bof/*.asm*",".{0,1000}\/client\/bof\/.{0,1000}\.asm.{0,1000}","offensive_tool_keyword","cobaltstrike","Hidden Desktop (often referred to as HVNC) is a tool that allows operators to interact with a remote desktop session without the user knowing. The VNC protocol is not involved but the result is a similar experience. This Cobalt Strike BOF implementation was created as an alternative to TinyNuke/forks that are written in C++","T1021.001 - T1133","TA0005 - TA0002","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/WKL-Sec/HiddenDesktop","1","1","N/A","N/A","10","10","1213","187","2023-12-07T17:15:48Z","2023-05-21T00:57:43Z","6064" +"*/Client/Commands/Enumeration.yaml*",".{0,1000}\/Client\/Commands\/Enumeration\.yaml.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","6065" +"*/Client/Commands/Execution.yaml*",".{0,1000}\/Client\/Commands\/Execution\.yaml.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","6066" +"*/Client/Commands/Injection.yaml*",".{0,1000}\/Client\/Commands\/Injection\.yaml.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","6067" +"*/Client/Commands/Lateral.yaml*",".{0,1000}\/Client\/Commands\/Lateral\.yaml.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","6068" +"*/Client/Commands/Tokens.yaml*",".{0,1000}\/Client\/Commands\/Tokens\.yaml.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","6069" +"*/client/generated-stagers/*",".{0,1000}\/client\/generated\-stagers\/.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","6070" +"*/Client/Pages/Drones.razor*",".{0,1000}\/Client\/Pages\/Drones\.razor.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","6071" +"*/Client/Pages/Payloads.razor*",".{0,1000}\/Client\/Pages\/Payloads\.razor.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","6072" +"*/Client/Pages/Pivots.razor*",".{0,1000}\/Client\/Pages\/Pivots\.razor.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","6073" +"*/clipboardinject.*",".{0,1000}\/clipboardinject\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","6074" +"*/clipboardinject/*",".{0,1000}\/clipboardinject\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","6075" +"*/ClipboardMITM.py*",".{0,1000}\/ClipboardMITM\.py.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","#linux","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","6076" +"*/clipmon/clipmon.sln*",".{0,1000}\/clipmon\/clipmon\.sln.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike addons to interact with clipboard","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DallasFR/Cobalt-Clip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","6077" +"*/clipmon/dll/*",".{0,1000}\/clipmon\/dll\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike addons to interact with clipboard","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DallasFR/Cobalt-Clip","1","1","N/A","N/A","10","","N/A","","","","6078" +"*/cliws.exe*",".{0,1000}\/cliws\.exe.{0,1000}","offensive_tool_keyword","cliws","Cross platform interactive bind/reverse PTY shell","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","Dispossessor","C2","https://github.com/b23r0/cliws","1","1","N/A","N/A","10","10","159","29","2023-11-06T02:19:16Z","2021-10-24T04:10:07Z","6082" +"*/cliws.git*",".{0,1000}\/cliws\.git.{0,1000}","offensive_tool_keyword","cliws","Cross platform interactive bind/reverse PTY shell","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","Dispossessor","C2","https://github.com/b23r0/cliws","1","1","N/A","N/A","10","10","159","29","2023-11-06T02:19:16Z","2021-10-24T04:10:07Z","6083" +"*/CloakNDaggerC2*",".{0,1000}\/CloakNDaggerC2.{0,1000}","offensive_tool_keyword","CloakNDaggerC2","A C2 framework designed around the use of public/private RSA key pairs to sign and authenticate commands being executed. This prevents MiTM interception of calls and ensures opsec during delicate operations.","T1090 - T1090.003 - T1071 - T1071.001 - T1553 - T1553.002","TA0011 - TA0042 - TA0003","N/A","N/A","C2","https://github.com/matt-culbert/CloakNDaggerC2","1","1","N/A","N/A","10","10","17","3","2024-10-09T15:36:46Z","2023-04-28T01:58:18Z","6084" +"*/clock-skew.nse*",".{0,1000}\/clock\-skew\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6085" +"*/cloud_enum.git*",".{0,1000}\/cloud_enum\.git.{0,1000}","offensive_tool_keyword","cloud_enum","Multi-cloud OSINT tool. Enumerate public resources in AWS Azure and Google Cloud.","T1596","TA0043","N/A","N/A","Reconnaissance","https://github.com/initstring/cloud_enum","1","1","N/A","N/A","6","10","1794","271","2024-10-10T08:16:59Z","2019-05-31T09:14:05Z","6087" +"*/cloud_enum.py*",".{0,1000}\/cloud_enum\.py.{0,1000}","offensive_tool_keyword","cloud_enum","Multi-cloud OSINT tool. Enumerate public resources in AWS Azure and Google Cloud.","T1596","TA0043","N/A","N/A","Reconnaissance","https://github.com/initstring/cloud_enum","1","1","N/A","N/A","6","10","1794","271","2024-10-10T08:16:59Z","2019-05-31T09:14:05Z","6088" +"*/cloudbrute.yaml*",".{0,1000}\/cloudbrute\.yaml.{0,1000}","offensive_tool_keyword","Osmedeus","Osmedeus - A Workflow Engine for Offensive Security","T1595","TA0043","N/A","N/A","Exploitation tool","https://github.com/j3ssie/osmedeus","1","1","N/A","N/A","N/A","10","5566","907","2025-04-22T14:57:07Z","2018-11-10T04:17:18Z","6090" +"*/cloudsploit.git*",".{0,1000}\/cloudsploit\.git.{0,1000}","offensive_tool_keyword","cloudsploit","CloudSploit by Aqua is an open-source project designed to allow detection of security risks in cloud infrastructure accounts including: Amazon Web Services (AWS) - Microsoft Azure - Google Cloud Platform (GCP) - Oracle Cloud Infrastructure (OCI) and GitHub. These scripts are designed to return a series of potential misconfigurations and security risks.","T1526 - T1534 - T1547 - T1078 - T1046","TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/aquasecurity/cloudsploit","1","1","N/A","N/A","N/A","10","3498","702","2025-03-20T12:01:19Z","2015-06-29T15:33:40Z","6095" +"*/CLR-Injection.git*",".{0,1000}\/CLR\-Injection\.git.{0,1000}","offensive_tool_keyword","CLR-Injection","Use CLR to inject all the .NET apps","T1055.009","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/3gstudent/CLR-Injection","1","1","N/A","N/A","8","2","183","45","2021-04-17T01:39:32Z","2017-07-27T03:00:04Z","6097" +"*/CLR-Injection_x64.bat*",".{0,1000}\/CLR\-Injection_x64\.bat.{0,1000}","offensive_tool_keyword","CLR-Injection","Use CLR to inject all the .NET apps","T1055.009","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/3gstudent/CLR-Injection","1","1","N/A","N/A","8","2","183","45","2021-04-17T01:39:32Z","2017-07-27T03:00:04Z","6098" +"*/CLR-Injection_x86.bat*",".{0,1000}\/CLR\-Injection_x86\.bat.{0,1000}","offensive_tool_keyword","CLR-Injection","Use CLR to inject all the .NET apps","T1055.009","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/3gstudent/CLR-Injection","1","1","N/A","N/A","8","2","183","45","2021-04-17T01:39:32Z","2017-07-27T03:00:04Z","6099" +"*/cmd/c2.go*",".{0,1000}\/cmd\/c2\.go.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071 - T1001 - T1008 - T1070 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","N/A","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","6100" +"*/cmd/hades/*",".{0,1000}\/cmd\/hades\/.{0,1000}","offensive_tool_keyword","hades","Go shellcode loader that combines multiple evasion techniques","T1055 - T1027 - T1218 - T1027.001 - T1036","TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/f1zm0/hades","1","1","N/A","N/A","N/A","4","364","47","2023-06-21T19:22:57Z","2022-10-11T08:16:24Z","6101" +"*/cmd/sish.go*",".{0,1000}\/cmd\/sish\.go.{0,1000}","offensive_tool_keyword","sish","An open source serveo/ngrok alternative. HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH","T1572 - T1090.002","TA0010 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antoniomika/sish","1","1","N/A","N/A","10","10","4203","325","2025-04-10T20:04:08Z","2019-02-15T15:36:23Z","6104" +"*/cmd_executor/*.go*",".{0,1000}\/cmd_executor\/.{0,1000}\.go.{0,1000}","offensive_tool_keyword","mythic","mythic C2 agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/freyja/","1","1","N/A","N/A","10","10","54","13","2024-10-29T17:32:07Z","2022-09-28T17:20:04Z","6106" +"*/cmd_stager*",".{0,1000}\/cmd_stager.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6108" +"*/CmdLineSpoofer.git*",".{0,1000}\/CmdLineSpoofer\.git.{0,1000}","offensive_tool_keyword","CmdLineSpoofer","How to spoof the command line when spawning a new process from C#","T1055 - T1027 - T1036","TA0002 - TA0004 - TA0010","N/A","N/A","Defense Evasion","https://github.com/plackyhacker/CmdLineSpoofer","1","1","N/A","N/A","9","2","106","17","2021-12-28T18:56:25Z","2021-12-27T09:23:45Z","6109" +"*/CmdLineSpoofer/*.cs*",".{0,1000}\/CmdLineSpoofer\/.{0,1000}\.cs.{0,1000}","offensive_tool_keyword","CmdLineSpoofer","How to spoof the command line when spawning a new process from C#","T1055 - T1027 - T1036","TA0002 - TA0004 - TA0010","N/A","N/A","Defense Evasion","https://github.com/plackyhacker/CmdLineSpoofer","1","1","N/A","N/A","9","2","106","17","2021-12-28T18:56:25Z","2021-12-27T09:23:45Z","6110" +"*/cmdstager/*",".{0,1000}\/cmdstager\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6111" +"*/cme_adcs_output_*.txt*",".{0,1000}\/cme_adcs_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","6114" +"*/cme_shares_output_*",".{0,1000}\/cme_shares_output_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","6115" +"*/cme_spooler_output_*",".{0,1000}\/cme_spooler_output_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","6116" +"*/cmedb",".{0,1000}\/cmedb","offensive_tool_keyword","crackmapexec","windows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct lateral move","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","6117" +"*/CMLoot.git*",".{0,1000}\/CMLoot\.git.{0,1000}","offensive_tool_keyword","CMLoot","Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares","T1083 - T1039","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/1njected/CMLoot","1","1","N/A","N/A","8","2","175","22","2023-02-05T00:24:31Z","2022-06-02T10:59:21Z","6118" +"*/CMLoot.ps1*",".{0,1000}\/CMLoot\.ps1.{0,1000}","offensive_tool_keyword","CMLoot","Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares","T1083 - T1039","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/1njected/CMLoot","1","1","N/A","N/A","8","2","175","22","2023-02-05T00:24:31Z","2022-06-02T10:59:21Z","6119" +"*/cmstp_uac.ahk*",".{0,1000}\/cmstp_uac\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","6121" +"*/cna/pipetest.cna*",".{0,1000}\/cna\/pipetest\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Example code for using named pipe output with beacon ReflectiveDLLs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rxwx/cs-rdll-ipc-example","1","1","N/A","N/A","10","10","116","23","2020-06-24T19:47:35Z","2020-06-24T19:43:56Z","6123" +"*/co2-cewler/*",".{0,1000}\/co2\-cewler\/.{0,1000}","offensive_tool_keyword","burpsuite","CO2 is a project for lightweight and useful enhancements to Portswigger popular Burp Suite web penetration tool through the standard Extender API","T1583 - T1595 - T1190","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/JGillam/burp-co2","1","1","N/A","network exploitation tool","N/A","2","152","34","2024-02-21T02:23:00Z","2015-04-19T03:38:34Z","6124" +"*/co2-core/*",".{0,1000}\/co2\-core\/.{0,1000}","offensive_tool_keyword","burpsuite","CO2 is a project for lightweight and useful enhancements to Portswigger popular Burp Suite web penetration tool through the standard Extender API","T1583 - T1595 - T1190","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/JGillam/burp-co2","1","1","N/A","network exploitation tool","N/A","2","152","34","2024-02-21T02:23:00Z","2015-04-19T03:38:34Z","6125" +"*/co2-laudanum/*",".{0,1000}\/co2\-laudanum\/.{0,1000}","offensive_tool_keyword","burpsuite","CO2 is a project for lightweight and useful enhancements to Portswigger popular Burp Suite web penetration tool through the standard Extender API","T1583 - T1595 - T1190","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/JGillam/burp-co2","1","1","N/A","network exploitation tool","N/A","2","152","34","2024-02-21T02:23:00Z","2015-04-19T03:38:34Z","6126" +"*/co2-sqlmapper/*",".{0,1000}\/co2\-sqlmapper\/.{0,1000}","offensive_tool_keyword","burpsuite","CO2 is a project for lightweight and useful enhancements to Portswigger popular Burp Suite web penetration tool through the standard Extender API","T1583 - T1595 - T1190","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/JGillam/burp-co2","1","1","N/A","network exploitation tool","N/A","2","152","34","2024-02-21T02:23:00Z","2015-04-19T03:38:34Z","6127" +"*/coap-resources.nse*",".{0,1000}\/coap\-resources\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6128" +"*/cobaltclip.c*",".{0,1000}\/cobaltclip\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike addons to interact with clipboard","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DallasFR/Cobalt-Clip","1","1","N/A","N/A","10","","N/A","","","","6129" +"*/cobaltclip.o*",".{0,1000}\/cobaltclip\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike addons to interact with clipboard","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DallasFR/Cobalt-Clip","1","1","N/A","N/A","10","","N/A","","","","6130" +"*/Cobalt-Clip/*",".{0,1000}\/Cobalt\-Clip\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike addons to interact with clipboard","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DallasFR/Cobalt-Clip","1","1","N/A","N/A","10","","N/A","","","","6131" +"*/cobaltstrike*",".{0,1000}\/cobaltstrike.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","6132" +"*/cobalt-strike*",".{0,1000}\/cobalt\-strike.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","6133" +"*/CobaltStrike_OpenBeacon.git*",".{0,1000}\/CobaltStrike_OpenBeacon\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","alternative to the Cobalt Strike Beacon","T1071.001 - T1041 - T1219 - T1105","TA0011","N/A","N/A","C2","https://github.com/ElJaviLuki/CobaltStrike_OpenBeacon","1","1","N/A","N/A","10","10","225","40","2024-03-13T04:32:57Z","2023-12-27T18:37:46Z","6135" +"*/cobaltstrike-nemesis-connector/*",".{0,1000}\/cobaltstrike\-nemesis\-connector\/.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","6136" +"*/code_exec.ps1*",".{0,1000}\/code_exec\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","6137" +"*/CodeBuildLooter.py*",".{0,1000}\/CodeBuildLooter\.py.{0,1000}","offensive_tool_keyword","AWS-Loot","Searches an AWS environment looking for secrets. by enumerating environment variables and source code. This tool allows quick enumeration over large sets of AWS instances and services.","T1552","TA0002","N/A","N/A","Exploitation tool","https://github.com/sebastian-mora/AWS-Loot","1","1","N/A","N/A","N/A","1","70","25","2020-02-02T00:51:56Z","2020-02-02T00:25:46Z","6138" +"*/CoercedPotato.cpp*",".{0,1000}\/CoercedPotato\.cpp.{0,1000}","offensive_tool_keyword","CoercedPotatoRDLL","Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege","T1055 - T1134 - T1548","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/sokaRepo/CoercedPotatoRDLL","1","1","N/A","N/A","10","3","204","31","2023-11-23T18:58:41Z","2023-11-23T13:22:38Z","6139" +"*/CoercedPotato.git*",".{0,1000}\/CoercedPotato\.git.{0,1000}","offensive_tool_keyword","CoercedPotato","CoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022.","T1548.002 - T1134.002","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/Prepouce/CoercedPotato","1","1","N/A","N/A","10","4","366","66","2024-08-26T08:09:00Z","2023-09-11T19:04:29Z","6140" +"*/CoercedPotatoRDLL.git*",".{0,1000}\/CoercedPotatoRDLL\.git.{0,1000}","offensive_tool_keyword","CoercedPotatoRDLL","Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege","T1055 - T1134 - T1548","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/sokaRepo/CoercedPotatoRDLL","1","1","N/A","N/A","10","3","204","31","2023-11-23T18:58:41Z","2023-11-23T13:22:38Z","6141" +"*/coercer.egg-info*",".{0,1000}\/coercer\.egg\-info.{0,1000}","offensive_tool_keyword","Coercer","A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through many methods.","T1110 - T1021 - T1020","TA0006 - TA0010","N/A","N/A","Exploitation tool","https://github.com/p0dalirius/Coercer","1","1","N/A","N/A","10","10","1945","195","2025-03-21T07:42:42Z","2022-06-30T16:52:33Z","6142" +"*/Coercer.git*",".{0,1000}\/Coercer\.git.{0,1000}","offensive_tool_keyword","Coercer","A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through many methods.","T1110 - T1021 - T1020","TA0006 - TA0010","N/A","N/A","Exploitation tool","https://github.com/p0dalirius/Coercer","1","1","N/A","N/A","10","10","1945","195","2025-03-21T07:42:42Z","2022-06-30T16:52:33Z","6143" +"*/Coercer.py*",".{0,1000}\/Coercer\.py.{0,1000}","offensive_tool_keyword","Coercer","A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through many methods.","T1110 - T1021 - T1020","TA0006 - TA0010","N/A","N/A","Exploitation tool","https://github.com/p0dalirius/Coercer","1","1","N/A","N/A","10","10","1945","195","2025-03-21T07:42:42Z","2022-06-30T16:52:33Z","6144" +"*/Coercer/*.py",".{0,1000}\/Coercer\/.{0,1000}\.py","offensive_tool_keyword","Coercer","A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through many methods.","T1110 - T1021 - T1020","TA0006 - TA0010","N/A","N/A","Exploitation tool","https://github.com/p0dalirius/Coercer","1","1","N/A","N/A","10","10","1945","195","2025-03-21T07:42:42Z","2022-06-30T16:52:33Z","6145" +"*/coercer_output_*.txt*",".{0,1000}\/coercer_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","6146" +"*/CoffeeLdr.c*",".{0,1000}\/CoffeeLdr\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File Loader","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cracked5pider/CoffeeLdr","1","1","N/A","N/A","10","10","286","38","2023-12-03T18:09:34Z","2022-07-18T15:21:11Z","6147" +"*/CoffeeLdr/*",".{0,1000}\/CoffeeLdr\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File Loader","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cracked5pider/CoffeeLdr","1","1","N/A","N/A","10","10","286","38","2023-12-03T18:09:34Z","2022-07-18T15:21:11Z","6148" +"*/COFFLoader*",".{0,1000}\/COFFLoader.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a quick and dirty COFF loader (AKA Beacon Object Files). Currently can run un-modified BOF's so it can be used for testing without a CS agent running it","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/COFFLoader","1","1","N/A","N/A","10","10","520","78","2025-04-03T14:57:10Z","2021-02-19T19:14:43Z","6149" +"*/COFFLoader.exe*",".{0,1000}\/COFFLoader\.exe.{0,1000}","offensive_tool_keyword","Shoggoth","Shoggoth: Asmjit Based Polymorphic Encryptor","T1027 - T1045","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/frkngksl/Shoggoth","1","1","N/A","N/A","8","8","724","92","2024-04-10T03:04:04Z","2021-12-03T11:55:22Z","6150" +"*/COFFLoader2/*",".{0,1000}\/COFFLoader2\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Load and execute COFF files and Cobalt Strike BOFs in-memory","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Yaxser/COFFLoader2","1","1","N/A","N/A","10","10","215","44","2022-09-13T14:58:30Z","2021-12-14T07:49:17Z","6151" +"*/collection/screengrab*",".{0,1000}\/collection\/screengrab.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","6152" +"*/com/blackh4t/*",".{0,1000}\/com\/blackh4t\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Practice Go programming and implement CobaltStrike's Beacon in Go","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/darkr4y/geacon","1","1","N/A","N/A","10","10","1189","206","2020-10-02T10:34:37Z","2020-02-14T14:01:29Z","6155" +"*/combine_harvester.git*",".{0,1000}\/combine_harvester\.git.{0,1000}","offensive_tool_keyword","combine_harvester","Rust in-memory dumper","T1055 - T1055.001 - T1055.012","TA0005 - TA0006","N/A","N/A","Defense Evasion","https://github.com/m3f157O/combine_harvester","1","1","N/A","N/A","10","2","108","17","2023-07-26T07:16:00Z","2023-07-20T07:37:51Z","6156" +"*/comfoo.profile*",".{0,1000}\/comfoo\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","6157" +"*/COMHijackToolkit.ps1*",".{0,1000}\/COMHijackToolkit\.ps1.{0,1000}","offensive_tool_keyword","Accomplice","Tools for discovery and abuse of COM hijacks","T1120 - T1174","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/nccgroup/Accomplice","1","1","N/A","N/A","7","4","303","47","2019-10-15T21:54:09Z","2019-09-04T23:32:09Z","6158" +"*/COM-Hunter.csproj*",".{0,1000}\/COM\-Hunter\.csproj.{0,1000}","offensive_tool_keyword","COM-Hunter","COM-hunter is a COM Hijacking persistnce tool written in C#","T1122 - T1055.012","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/nickvourd/COM-Hunter","1","1","N/A","N/A","10","3","289","48","2025-03-11T04:49:55Z","2022-05-26T19:34:59Z","6159" +"*/COM-Hunter.exe*",".{0,1000}\/COM\-Hunter\.exe.{0,1000}","offensive_tool_keyword","COM-Hunter","COM-hunter is a COM Hijacking persistnce tool written in C#","T1122 - T1055.012","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/nickvourd/COM-Hunter","1","1","N/A","N/A","10","3","289","48","2025-03-11T04:49:55Z","2022-05-26T19:34:59Z","6160" +"*/COM-Hunter.git*",".{0,1000}\/COM\-Hunter\.git.{0,1000}","offensive_tool_keyword","COM-Hunter","COM-hunter is a COM Hijacking persistnce tool written in C#","T1122 - T1055.012","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/nickvourd/COM-Hunter","1","1","N/A","N/A","10","3","289","48","2025-03-11T04:49:55Z","2022-05-26T19:34:59Z","6161" +"*/COM-Hunter.sln*",".{0,1000}\/COM\-Hunter\.sln.{0,1000}","offensive_tool_keyword","COM-Hunter","COM-hunter is a COM Hijacking persistnce tool written in C#","T1122 - T1055.012","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/nickvourd/COM-Hunter","1","1","N/A","N/A","10","3","289","48","2025-03-11T04:49:55Z","2022-05-26T19:34:59Z","6162" +"*/COMInjectTarget.dll*",".{0,1000}\/COMInjectTarget\.dll.{0,1000}","offensive_tool_keyword","Accomplice","Tools for discovery and abuse of COM hijacks","T1120 - T1174","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/nccgroup/Accomplice","1","1","N/A","N/A","7","4","303","47","2019-10-15T21:54:09Z","2019-09-04T23:32:09Z","6163" +"*/Command Reciever.exe*",".{0,1000}\/Command\sReciever\.exe.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","6164" +"*/Command%20Reciever.exe*",".{0,1000}\/Command\%20Reciever\.exe.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","6165" +"*/command/exec/sideload.go*",".{0,1000}\/command\/exec\/sideload\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","6166" +"*/command/exec/spawndll.go*",".{0,1000}\/command\/exec\/spawndll\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","6167" +"*/command_exec.exe*",".{0,1000}\/command_exec\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","6168" +"*/commandcontrol/malware*.py*",".{0,1000}\/commandcontrol\/malware.{0,1000}\.py.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","6169" +"*/commando-vm*",".{0,1000}\/commando\-vm.{0,1000}","offensive_tool_keyword","commando-vm","CommandoVM - a fully customizable Windows-based security distribution for penetration testing and red teaming.","T1059 - T1053 - T1055 - T1070","TA0002 - TA0004 - TA0008","N/A","N/A","Exploitation OS","https://github.com/mandiant/commando-vm","1","1","N/A","N/A","N/A","10","7168","1313","2024-09-24T19:14:18Z","2019-03-26T22:36:32Z","6171" +"*/commix.git",".{0,1000}\/commix\.git","offensive_tool_keyword","commix","Automated All-in-One OS command injection and exploitation tool.","T1059 - T1053 - T1503","TA0002 - TA0003 - TA0040","N/A","N/A","Exploitation tool","https://github.com/commixproject/commix","1","1","N/A","N/A","N/A","10","5245","872","2025-04-13T08:55:27Z","2015-03-20T08:38:26Z","6172" +"*/commix.py*",".{0,1000}\/commix\.py.{0,1000}","offensive_tool_keyword","commix","Automated All-in-One OS command injection and exploitation tool.","T1059 - T1053 - T1503","TA0002 - TA0003 - TA0040","N/A","N/A","Exploitation tool","https://github.com/commixproject/commix","1","1","N/A","N/A","N/A","10","5245","872","2025-04-13T08:55:27Z","2015-03-20T08:38:26Z","6173" +"*/common/beacon.go*",".{0,1000}\/common\/beacon\.go.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","6174" +"*/COM-Object-hijacking.git*",".{0,1000}\/COM\-Object\-hijacking\.git.{0,1000}","offensive_tool_keyword","COM-Object-hijacking","use COM Object hijacking to maintain persistence.(Hijack CAccPropServicesClass and MMDeviceEnumerator)","T1546.015","TA0003","N/A","N/A","Persistence","https://github.com/3gstudent/COM-Object-hijacking","1","1","N/A","N/A","8","1","58","30","2017-08-04T09:19:40Z","2017-08-04T08:15:36Z","6175" +"*/comsvcs_stealth.py*",".{0,1000}\/comsvcs_stealth\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","6177" +"*/ComunicationC2.cpp*",".{0,1000}\/ComunicationC2\.cpp.{0,1000}","offensive_tool_keyword","DocPlz","Documents Exfiltration and C2 project","T1105 - T1567 - T1071","TA0011 - TA0010 - TA0009","N/A","N/A","Data Exfiltration","https://github.com/TheD1rkMtr/DocPlz","1","1","N/A","N/A","10","2","145","30","2023-10-10T19:01:42Z","2023-10-02T20:49:22Z","6178" +"*/CONCRETE_STEEL.exe""*",".{0,1000}\/CONCRETE_STEEL\.exe\"".{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","6179" +"*/config/doNmapScanWin.bat *",".{0,1000}\/config\/doNmapScanWin\.bat\s.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoCs - 23 kinds of application password crack - 7000+Web fingerprints - 146 protocols and 90000+ rules Port scanning - Fuzz - HW - awesome BugBounty","T1046 - T1210.001 - T1059 - T1082 - T1110","TA0007 - TA0001 - TA0009 - TA0002 - TA0004 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","6182" +"*/configdhcpserver.sh*",".{0,1000}\/configdhcpserver\.sh.{0,1000}","offensive_tool_keyword","TunnelVision","TunnelVision uses DHCP option 121 to manipulate routing tables and decloak VPN traffic","T1557 - T1498.003","TA0009 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/leviathansecurity/TunnelVision","1","1","N/A","N/A","9","2","132","17","2024-05-08T19:40:13Z","2024-03-11T22:24:56Z","6183" +"*/Configure-Victim.ps1*",".{0,1000}\/Configure\-Victim\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","6184" +"*/ConfuserEx.exe*",".{0,1000}\/ConfuserEx\.exe.{0,1000}","offensive_tool_keyword","ConfuserEx","ConfuserEx is a widely used open source obfuscator often found in malware","T1027 - T1045","TA0005 ","N/A","N/A","Defense Evasion","https://github.com/yck1509/ConfuserEx","1","1","N/A","N/A","6","10","3629","1661","2019-05-14T14:23:56Z","2014-03-28T07:00:26Z","6185" +"*/ConfuserEx.git*",".{0,1000}\/ConfuserEx\.git.{0,1000}","offensive_tool_keyword","ConfuserEx","ConfuserEx is a widely used open source obfuscator often found in malware","T1027 - T1045","TA0005 ","N/A","N/A","Defense Evasion","https://github.com/yck1509/ConfuserEx","1","1","N/A","N/A","6","10","3629","1661","2019-05-14T14:23:56Z","2014-03-28T07:00:26Z","6186" +"*/confuserex.py*",".{0,1000}\/confuserex\.py.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","packer bundled","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","6187" +"*/ConfuserEx_bin.zip*",".{0,1000}\/ConfuserEx_bin\.zip.{0,1000}","offensive_tool_keyword","ConfuserEx","ConfuserEx is a widely used open source obfuscator often found in malware","T1027 - T1045","TA0005 ","N/A","N/A","Defense Evasion","https://github.com/yck1509/ConfuserEx","1","1","N/A","N/A","6","10","3629","1661","2019-05-14T14:23:56Z","2014-03-28T07:00:26Z","6188" +"*/ConPtyShell/*",".{0,1000}\/ConPtyShell\/.{0,1000}","offensive_tool_keyword","ConPtyShell","ConPtyShell - Fully Interactive Reverse Shell for Windows","T1059.001 - T1021.004 - T1056.003","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/ConPtyShell","1","1","N/A","N/A","10","10","1102","171","2023-01-20T10:52:52Z","2019-09-13T22:11:18Z","6191" +"*/ContainYourself.git*",".{0,1000}\/ContainYourself\.git.{0,1000}","offensive_tool_keyword","ContainYourself","Abuses the Windows containers framework to bypass EDRs.","T1562 - T1562.004 - T1212 - T1212.002 - T1055 - T1055.015","TA0005","N/A","N/A","Defense Evasion","https://github.com/deepinstinct/ContainYourself","1","1","N/A","N/A","10","4","310","39","2023-08-31T07:26:22Z","2023-07-12T14:47:24Z","6192" +"*/ConvertToShellcode.py*",".{0,1000}\/ConvertToShellcode\.py.{0,1000}","offensive_tool_keyword","NamelessC2","A C2 with all its components written in Rust","T1102 - T1573.001 - T1027 - T1219 - T1205","TA0011 - TA0003 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/trickster0/NamelessC2","1","1","N/A","N/A","10","10","266","33","2024-09-26T21:21:20Z","2024-09-26T21:06:37Z","6193" +"*/CookieProcessor.cs*",".{0,1000}\/CookieProcessor\.cs.{0,1000}","offensive_tool_keyword","cobaltstrike","C or BOF file to extract WebKit master key to decrypt user cookie. The C code can be used to compile an executable or a bof script for Cobalt Strike.","T1552.002 - T1027.001 - T1059.003 - T1003.001","TA0006 - TA0005 - TA0002 - TA0003","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/Cookie-Graber-BOF","1","1","N/A","N/A","10","10","194","23","2024-04-29T19:08:52Z","2023-05-28T18:30:02Z","6194" +"*/Coolvibes.exe*",".{0,1000}\/Coolvibes\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6195" +"*/Cooolis-ms/*",".{0,1000}\/Cooolis\-ms\/.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","6196" +"*/Cordyceps.git*",".{0,1000}\/Cordyceps\.git.{0,1000}","offensive_tool_keyword","Cordyceps","C++ self-Injecting dropper based on various EDR evasion techniques","T1055 - T1055.001 - T1070.004 - T1564.001","TA0005 - TA0002 ","N/A","N/A","Defense Evasion","https://github.com/pard0p/Cordyceps","1","1","N/A","N/A","10","3","N/A","N/A","N/A","N/A","6197" +"*/core/browser_darwin.go*",".{0,1000}\/core\/browser_darwin\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","reflective module for HackBrowserData","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/idiotc4t/Reflective-HackBrowserData","1","1","#linux","N/A","10","10","175","25","2021-03-13T08:42:18Z","2021-03-13T08:35:01Z","6198" +"*/core/browser_linux.go*",".{0,1000}\/core\/browser_linux\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","reflective module for HackBrowserData","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/idiotc4t/Reflective-HackBrowserData","1","1","#linux","N/A","10","10","175","25","2021-03-13T08:42:18Z","2021-03-13T08:35:01Z","6199" +"*/core/browser_windows.go*",".{0,1000}\/core\/browser_windows\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","reflective module for HackBrowserData","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/idiotc4t/Reflective-HackBrowserData","1","1","N/A","N/A","10","10","175","25","2021-03-13T08:42:18Z","2021-03-13T08:35:01Z","6200" +"*/Coringa-RAT 0.1.exe*",".{0,1000}\/Coringa\-RAT\s0\.1\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6201" +"*/CORINGA-RAT.exe*",".{0,1000}\/CORINGA\-RAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6202" +"*/Corrupt_AMSI.py*",".{0,1000}\/Corrupt_AMSI\.py.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","6203" +"*/Corrupt_AMSI.vba*",".{0,1000}\/Corrupt_AMSI\.vba.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","6204" +"*/couchdb-databases.nse*",".{0,1000}\/couchdb\-databases\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6205" +"*/couchdb-stats.nse*",".{0,1000}\/couchdb\-stats\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6206" +"*/Covenant*.cs*",".{0,1000}\/Covenant.{0,1000}\.cs.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","6207" +"*/Covenant.git*",".{0,1000}\/Covenant\.git.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","6208" +"*/Covenant/*",".{0,1000}\/Covenant\/.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","6209" +"*/CovenantUsers/*",".{0,1000}\/CovenantUsers\/.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","6210" +"*/CppWSManWinRM.exe*",".{0,1000}\/CppWSManWinRM\.exe.{0,1000}","offensive_tool_keyword","WSMan-WinRM","remote commands over WinRM using the WSMan.Automation COM object","T1021.004 - T1059.001","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/bohops/WSMan-WinRM","1","1","N/A","N/A","10","3","236","40","2020-05-12T16:49:01Z","2020-05-12T01:30:42Z","6211" +"*/crack.sh/get-cracking/*",".{0,1000}\/\/crack\.sh\/get\-cracking\/.{0,1000}","offensive_tool_keyword","crack.sh","crack.sh THE WORLD???S FASTEST DES CRACKER. Used by attackers to submit passwords to crack","T1110.002 - T1021.002","TA0006 - TA0008","N/A","N/A","Credential Access","https://crack.sh/get-cracking/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6212" +"*/crack_list/client_wordlists.py*",".{0,1000}\/crack_list\/client_wordlists\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","6213" +"*/crack_list/cracklist_api.py*",".{0,1000}\/crack_list\/cracklist_api\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","6214" +"*/crack_list/dictionary.py*",".{0,1000}\/crack_list\/dictionary\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","6215" +"*/crack_list/wordlist.py*",".{0,1000}\/crack_list\/wordlist\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","6216" +"*/Cracked5pider/*",".{0,1000}\/Cracked5pider\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File Loader","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cracked5pider/CoffeeLdr","1","1","N/A","N/A","10","10","286","38","2023-12-03T18:09:34Z","2022-07-18T15:21:11Z","6217" +"*/Cracked5pider/*",".{0,1000}\/Cracked5pider\/.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","6218" +"*/cracklord.git*",".{0,1000}\/cracklord\.git.{0,1000}","offensive_tool_keyword","cracklord","Queue and resource system for cracking passwords","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/jmmcatee/cracklord","1","1","N/A","N/A","10","4","388","70","2022-09-22T09:30:14Z","2013-12-09T23:10:54Z","6220" +"*/cracklord/cmd/*",".{0,1000}\/cracklord\/cmd\/.{0,1000}","offensive_tool_keyword","cracklord","Queue and resource system for cracking passwords","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/jmmcatee/cracklord","1","1","N/A","N/A","10","4","388","70","2022-09-22T09:30:14Z","2013-12-09T23:10:54Z","6221" +"*/CrackMapExec.git",".{0,1000}\/CrackMapExec\.git","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","6222" +"*/cradle.ps1*",".{0,1000}\/cradle\.ps1.{0,1000}","offensive_tool_keyword","Dinjector","Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL","T1055 - T1055.012 - T1055.001 - T1027.002","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Metro-Holografix/DInjector","1","1","N/A","private github repo","10","1","N/A","N/A","N/A","N/A","6224" +"*/cradle.ps1*",".{0,1000}\/cradle\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","6225" +"*/Crassus.git*",".{0,1000}\/Crassus\.git.{0,1000}","offensive_tool_keyword","Crassus","Crassus Windows privilege escalation discovery tool","T1068 - T1003 - T1003.003 - T1046","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/vu-ls/Crassus","1","1","N/A","N/A","10","6","571","59","2024-11-08T14:11:39Z","2023-01-12T21:01:52Z","6226" +"*/Crassus-main*",".{0,1000}\/Crassus\-main.{0,1000}","offensive_tool_keyword","Crassus","Crassus Windows privilege escalation discovery tool","T1068 - T1003 - T1003.003 - T1046","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/vu-ls/Crassus","1","1","N/A","N/A","10","6","571","59","2024-11-08T14:11:39Z","2023-01-12T21:01:52Z","6227" +"*/create_webshell_with_py.py*",".{0,1000}\/create_webshell_with_py\.py.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","6230" +"*/createforestcache.py*",".{0,1000}\/createforestcache\.py.{0,1000}","offensive_tool_keyword","BloodHound","BloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/fox-it/BloodHound.py","1","1","N/A","N/A","10","10","2088","343","2025-03-28T11:19:13Z","2018-02-26T14:44:20Z","6231" +"*/Create-HotKeyLNK.ps1*",".{0,1000}\/Create\-HotKeyLNK\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","6232" +"*/createproxydll.sh*",".{0,1000}\/createproxydll\.sh.{0,1000}","offensive_tool_keyword","nimproxydll","A Docker container for byt3bl33d3r/NimDllSideload - DLL sideloading/proxying","T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/cyllective/nimproxydll","1","1","N/A","N/A","9","1","10","0","2024-05-26T17:34:01Z","2024-03-15T15:15:45Z","6233" +"*/createstager.py*",".{0,1000}\/createstager\.py.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","6234" +"*/Cred_Dump.sh*",".{0,1000}\/Cred_Dump\.sh.{0,1000}","offensive_tool_keyword","AutoC2","AutoC2 is a bash script written to install all of the red team tools that you know and love","T1059.004 - T1129 - T1486","TA0005 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/assume-breach/Home-Grown-Red-Team/tree/main/AutoC2","1","1","N/A","N/A","10","8","707","112","2024-03-22T12:32:22Z","2022-03-23T15:52:41Z","6236" +"*/credBandit/*",".{0,1000}\/credBandit\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Proof of concept Beacon Object File (BOF) that uses static x64 syscalls to perform a complete in memory dump of a process and send that back through your already existing Beacon communication channel","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/xforcered/CredBandit","1","1","N/A","N/A","10","10","240","26","2021-07-14T17:42:41Z","2021-03-17T15:19:33Z","6237" +"*/creddump.py*",".{0,1000}\/creddump\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","6238" +"*/creddump7*.py*",".{0,1000}\/creddump7.{0,1000}\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","6239" +"*/creddump7.git*",".{0,1000}\/creddump7\.git.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","6240" +"*/creddump7.git*",".{0,1000}\/creddump7\.git.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","6241" +"*/creddump7/*",".{0,1000}\/creddump7\/.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","6242" +"*/creddump7/*",".{0,1000}\/creddump7\/.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","6243" +"*/creddump7/releases/*",".{0,1000}\/creddump7\/releases\/.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","6244" +"*/credential access.cna*",".{0,1000}\/credential\saccess\.cna.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6245" +"*/Credentials/*.ccache*",".{0,1000}\/Credentials\/.{0,1000}\.ccache.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","6246" +"*/Credentials/firefox_*.txt*",".{0,1000}\/Credentials\/firefox_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","6249" +"*/Credentials/msol_*.txt*",".{0,1000}\/Credentials\/msol_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","6250" +"*/credentials/SudoSnatch*",".{0,1000}\/credentials\/SudoSnatch.{0,1000}","offensive_tool_keyword","sudoSnatch","sudoSnatch payload grabs sudo password in plain text and imediately after target uses sudo command and sends it back to attacker remotely/locally.","T1552.001 - T1056.001 - T1071.001","TA0006 - TA0004 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/SudoSnatch","1","1","#linux","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","6251" +"*/credentials/wifigrabber*",".{0,1000}\/credentials\/wifigrabber.{0,1000}","offensive_tool_keyword","wifigrabber","grab wifi password and exfiltrate to a given site","T1056.005 - T1552.001 - T1119 - T1071.001","TA0004 - TA0006 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/wifigrabber","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","6252" +"*/CredEnum.c*",".{0,1000}\/CredEnum\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/guervild/BOFs","1","1","N/A","N/A","10","10","161","27","2022-05-02T16:59:24Z","2021-03-15T23:30:22Z","6253" +"*/CredEnum.cna*",".{0,1000}\/CredEnum\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/guervild/BOFs","1","1","N/A","N/A","10","10","161","27","2022-05-02T16:59:24Z","2021-03-15T23:30:22Z","6254" +"*/CredEnum.h*",".{0,1000}\/CredEnum\.h.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/guervild/BOFs","1","1","N/A","N/A","10","10","161","27","2022-05-02T16:59:24Z","2021-03-15T23:30:22Z","6255" +"*/creditcards.py*",".{0,1000}\/creditcards\.py.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","6256" +"*/CredMaster.git*",".{0,1000}\/CredMaster\.git.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","6257" +"*/credmaster.py*",".{0,1000}\/credmaster\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","6258" +"*/CredMaster-master.zip*",".{0,1000}\/CredMaster\-master\.zip.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","6260" +"*/CredPhisher.exe*",".{0,1000}\/CredPhisher\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6263" +"*/CredPhisher.exe*",".{0,1000}\/CredPhisher\.exe.{0,1000}","offensive_tool_keyword","Credphisher","prompt a user for credentials using a Windows credential dialog","T1056.002 - T1003 ","TA0006","N/A","N/A","Credential Access","https://github.com/ryanmrestivo/red-team/blob/1e53b7aa77717a22c9bd54facc64155a9a4c49fc/Exploitation-Tools/OffensiveCSharp/CredPhisher","1","1","N/A","N/A","7","2","136","34","2024-10-18T12:12:38Z","2021-04-12T00:00:03Z","6264" +"*/CredPhisher/*",".{0,1000}\/CredPhisher\/.{0,1000}","offensive_tool_keyword","CredPhisher","Prompts the current user for their credentials using the CredUIPromptForWindowsCredentials WinAPI function","T1056.002 - T1111","TA0004 ","N/A","N/A","Phishing","https://github.com/matterpreter/OffensiveCSharp/tree/master/CredPhisher","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","6265" +"*/CredPrompt.exe*",".{0,1000}\/CredPrompt\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/guervild/BOFs","1","1","N/A","N/A","10","10","161","27","2022-05-02T16:59:24Z","2021-03-15T23:30:22Z","6266" +"*/CredPrompt/credprompt.c*",".{0,1000}\/CredPrompt\/credprompt\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/guervild/BOFs","1","1","N/A","N/A","10","10","161","27","2022-05-02T16:59:24Z","2021-03-15T23:30:22Z","6267" +"*/creds-*/creds.zip*",".{0,1000}\/creds\-.{0,1000}\/creds\.zip.{0,1000}","offensive_tool_keyword","DefaultCreds-cheat-sheet","One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password","T1110.001 - T1110.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/ihebski/DefaultCreds-cheat-sheet","1","1","N/A","N/A","N/A","10","6048","726","2025-04-15T13:13:19Z","2021-01-01T19:02:36Z","6268" +"*/creds-summary.nse*",".{0,1000}\/creds\-summary\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6269" +"*/crlfinjection.txt*",".{0,1000}\/crlfinjection\.txt.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","6270" +"*/Cronos-Rootkit*",".{0,1000}\/Cronos\-Rootkit.{0,1000}","offensive_tool_keyword","Cronos-Rootkit","Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.","T1055 - T1078 - T1134 - T1562.001","TA0001 - TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/XaFF-XaFF/Cronos-Rootkit","1","1","N/A","N/A","N/A","9","899","186","2022-03-29T08:26:03Z","2021-08-25T08:54:45Z","6276" +"*/Cronos-Rootkit/*",".{0,1000}\/Cronos\-Rootkit\/.{0,1000}","offensive_tool_keyword","Cronos-Rootkit","Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.","T1055 - T1078 - T1134 - T1562.001","TA0001 - TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/XaFF-XaFF/Cronos-Rootkit","1","1","N/A","N/A","N/A","9","899","186","2022-03-29T08:26:03Z","2021-08-25T08:54:45Z","6277" +"*/Cronos-x64.zip*",".{0,1000}\/Cronos\-x64\.zip.{0,1000}","offensive_tool_keyword","Cronos-Rootkit","Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.","T1055 - T1078 - T1134 - T1562.001","TA0001 - TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/XaFF-XaFF/Cronos-Rootkit","1","1","N/A","N/A","N/A","9","899","186","2022-03-29T08:26:03Z","2021-08-25T08:54:45Z","6278" +"*/CrossC2.*",".{0,1000}\/CrossC2\..{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","6279" +"*/CrossC2/*",".{0,1000}\/CrossC2\/.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","6280" +"*/CrossC2Kit*",".{0,1000}\/CrossC2Kit.{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","6281" +"*/CrossC2Kit/*",".{0,1000}\/CrossC2Kit\/.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","6282" +"*/CrossC2-test*",".{0,1000}\/CrossC2\-test.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","6283" +"*/CrossNet-Beta/*",".{0,1000}\/CrossNet\-Beta\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike payload generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dr0op/CrossNet-Beta","1","1","N/A","N/A","10","10","362","58","2024-06-19T07:02:22Z","2021-02-08T10:52:39Z","6284" +"*/crunch-wordlist/*",".{0,1000}\/crunch\-wordlist\/.{0,1000}","offensive_tool_keyword","crunch","Generate a dictionary file containing words with a minimum and maximum length","T1596 - T1596.001","TA0043","N/A","N/A","Credential Access","https://sourceforge.net/projects/crunch-wordlist/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6298" +"*/crypt0p3g/*",".{0,1000}\/crypt0p3g\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files (BOF) for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/crypt0p3g/bof-collection","1","1","N/A","N/A","10","10","175","27","2022-12-05T04:49:33Z","2021-01-20T06:07:38Z","6299" +"*/cryptomining.git*",".{0,1000}\/cryptomining\.git.{0,1000}","offensive_tool_keyword","cryptomining","A Linux Cyptomining malware","T1496","TA0009","N/A","N/A","Cryptomining","https://github.com/tarcisio-marinho/cryptomining","1","1","#linux","N/A","7","1","36","15","2023-05-05T02:42:59Z","2018-04-07T03:59:52Z","6300" +"*/cs2modrewrite/*",".{0,1000}\/cs2modrewrite\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Convert Cobalt Strike profiles to modrewrite scripts","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/cs2modrewrite","1","1","N/A","N/A","10","10","599","117","2023-01-30T17:47:51Z","2017-06-06T14:53:57Z","6302" +"*/CS-BOFs/*",".{0,1000}\/CS\-BOFs\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of CobaltStrike beacon object files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/pwn1sher/CS-BOFs","1","1","N/A","N/A","10","10","103","22","2022-02-14T09:47:30Z","2021-01-18T08:54:48Z","6303" +"*/csexec.exe*",".{0,1000}\/csexec\.exe.{0,1000}","offensive_tool_keyword","csexec","An implementation of PSExec in C#","T1021.002 - T1059.004 - T1077","TA0008 - TA0009 - TA0011","N/A","N/A","Lateral Movement","https://github.com/malcomvetter/CSExec","1","1","N/A","N/A","10","4","325","62","2020-12-01T14:52:01Z","2018-08-08T21:09:07Z","6304" +"*/CSExec.git*",".{0,1000}\/CSExec\.git.{0,1000}","offensive_tool_keyword","csexec","An implementation of PSExec in C#","T1021.002 - T1059.004 - T1077","TA0008 - TA0009 - TA0011","N/A","N/A","Lateral Movement","https://github.com/malcomvetter/CSExec","1","1","N/A","N/A","10","4","325","62","2020-12-01T14:52:01Z","2018-08-08T21:09:07Z","6305" +"*/CSExec.py*",".{0,1000}\/CSExec\.py.{0,1000}","offensive_tool_keyword","CSExec","An alternative to *exec.py from impacket with some builtin tricks","T1059.001 - T1059.005 - T1071.001","TA0002","N/A","N/A","Lateral Movement","https://github.com/Metro-Holografix/CSExec.py","1","1","N/A","private github repo","10","","N/A","","","","6306" +"*/CSExec.py.git*",".{0,1000}\/CSExec\.py\.git.{0,1000}","offensive_tool_keyword","CSExec","An alternative to *exec.py from impacket with some builtin tricks","T1059.001 - T1059.005 - T1071.001","TA0002","N/A","N/A","Lateral Movement","https://github.com/Metro-Holografix/CSExec.py","1","1","N/A","private github repo","10","","N/A","","","","6307" +"*/csexecsvc.exe*",".{0,1000}\/csexecsvc\.exe.{0,1000}","offensive_tool_keyword","csexec","An implementation of PSExec in C#","T1021.002 - T1059.004 - T1077","TA0008 - TA0009 - TA0011","N/A","N/A","Lateral Movement","https://github.com/malcomvetter/CSExec","1","1","N/A","N/A","10","4","325","62","2020-12-01T14:52:01Z","2018-08-08T21:09:07Z","6308" +"*/csexecsvc-net35.exe*",".{0,1000}\/csexecsvc\-net35\.exe.{0,1000}","offensive_tool_keyword","csexec","An implementation of PSExec in C#","T1021.002 - T1059.004 - T1077","TA0008 - TA0009 - TA0011","N/A","N/A","Lateral Movement","https://github.com/malcomvetter/CSExec","1","1","N/A","N/A","10","4","325","62","2020-12-01T14:52:01Z","2018-08-08T21:09:07Z","6309" +"*/csexecsvc-net40.exe*",".{0,1000}\/csexecsvc\-net40\.exe.{0,1000}","offensive_tool_keyword","csexec","An implementation of PSExec in C#","T1021.002 - T1059.004 - T1077","TA0008 - TA0009 - TA0011","N/A","N/A","Lateral Movement","https://github.com/malcomvetter/CSExec","1","1","N/A","N/A","10","4","325","62","2020-12-01T14:52:01Z","2018-08-08T21:09:07Z","6310" +"*/csexecsvc-net45.exe*",".{0,1000}\/csexecsvc\-net45\.exe.{0,1000}","offensive_tool_keyword","csexec","An implementation of PSExec in C#","T1021.002 - T1059.004 - T1077","TA0008 - TA0009 - TA0011","N/A","N/A","Lateral Movement","https://github.com/malcomvetter/CSExec","1","1","N/A","N/A","10","4","325","62","2020-12-01T14:52:01Z","2018-08-08T21:09:07Z","6311" +"*/csharp/process_injection/*",".{0,1000}\/csharp\/process_injection\/.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1027 - T1055 - T1070 - T1112 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","6312" +"*/CSharpWinRM*",".{0,1000}\/CSharpWinRM.{0,1000}","offensive_tool_keyword","cobaltstrike","C++ WinRM API via Reflective DLL","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mez-0/winrmdll","1","1","N/A","N/A","10","10","144","28","2021-09-11T13:44:16Z","2021-09-11T13:40:22Z","6313" +"*/C--Shellcode*",".{0,1000}\/C\-\-Shellcode.{0,1000}","offensive_tool_keyword","cobaltstrike","python ShellCode Loader (Cobaltstrike&Metasploit)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OneHone/C--Shellcode","1","1","N/A","N/A","10","10","20","2","2019-11-28T01:53:55Z","2019-11-05T09:48:14Z","6314" +"*/CS-Loader.go*",".{0,1000}\/CS\-Loader\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","CS anti-killing including python version and C version","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Gality369/CS-Loader","1","1","N/A","N/A","10","10","829","141","2025-04-02T09:37:10Z","2020-08-17T21:33:06Z","6315" +"*/CS-Loader/*",".{0,1000}\/CS\-Loader\/.{0,1000}","offensive_tool_keyword","cobaltstrike","CS anti-killing including python version and C version","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Gality369/CS-Loader","1","1","N/A","N/A","10","10","829","141","2025-04-02T09:37:10Z","2020-08-17T21:33:06Z","6316" +"*/CsOnTheFly.ps1*",".{0,1000}\/CsOnTheFly\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","6317" +"*/csOnvps/*",".{0,1000}\/csOnvps\/.{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike4.4 one-click deployment script Randomly generate passwords. keys. port numbers. certificates. etc.. to solve the problem that cs4.x cannot run on Linux and report errors","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/AlphabugX/csOnvps","1","1","N/A","N/A","10","10","286","63","2022-03-19T00:10:03Z","2021-12-02T02:10:42Z","6318" +"*/csOnvps/*",".{0,1000}\/csOnvps\/.{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike4.4 one-click deployment script Randomly generate passwords. keys. port numbers. certificates. etc.. to solve the problem that cs4.x cannot run on Linux and report errors Gray often ginkgo design","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/AlphabugX/csOnvps","1","1","N/A","N/A","10","10","286","63","2022-03-19T00:10:03Z","2021-12-02T02:10:42Z","6319" +"*/cs-rdll-ipc-example/*",".{0,1000}\/cs\-rdll\-ipc\-example\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Example code for using named pipe output with beacon ReflectiveDLLs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rxwx/cs-rdll-ipc-example","1","1","N/A","N/A","10","10","116","23","2020-06-24T19:47:35Z","2020-06-24T19:43:56Z","6320" +"*/CS-Remote-OPs-BOF*",".{0,1000}\/CS\-Remote\-OPs\-BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","6321" +"*/cstealer.git*",".{0,1000}\/cstealer\.git.{0,1000}","offensive_tool_keyword","cstealer","stealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python.","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/can-kat/cstealer","1","1","N/A","N/A","10","","N/A","","","","6322" +"*/cstealer.py*",".{0,1000}\/cstealer\.py.{0,1000}","offensive_tool_keyword","cstealer","stealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python.","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/can-kat/cstealer","1","1","N/A","N/A","10","","N/A","","","","6323" +"*/cs-token-vault/*",".{0,1000}\/cs\-token\-vault\/.{0,1000}","offensive_tool_keyword","cobaltstrike","In-memory token vault BOF for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Henkru/cs-token-vault","1","1","N/A","N/A","10","10","142","25","2022-08-18T11:02:42Z","2022-07-29T17:50:10Z","6324" +"*/Cstrike Rat.exe*",".{0,1000}\/Cstrike\sRat\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6325" +"*/cube0x0/noPac*",".{0,1000}\/cube0x0\/noPac.{0,1000}","offensive_tool_keyword","POC","POC exploitation for CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user","T1548 - T1134 - T1078 - T1078.002","TA0003 - TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/cube0x0/noPac","1","1","N/A","N/A","N/A","10","1365","323","2021-12-16T09:50:15Z","2021-12-11T19:27:30Z","6328" +"*/cuddlephish.git*",".{0,1000}\/cuddlephish\.git.{0,1000}","offensive_tool_keyword","cuddlephish","Weaponized Browser-in-the-Middle (BitM) for Penetration Testers","T1185 - T1185.002 - T1071 - T1071.001 - T1556 - T1556.001","TA0009 - TA0006","N/A","N/A","Sniffing & Spoofing","https://github.com/fkasler/cuddlephish","1","1","N/A","N/A","10","5","487","51","2024-11-21T17:36:55Z","2023-08-02T14:30:41Z","6329" +"*/cuddlephish.html*",".{0,1000}\/cuddlephish\.html.{0,1000}","offensive_tool_keyword","cuddlephish","Weaponized Browser-in-the-Middle (BitM) for Penetration Testers","T1185 - T1185.002 - T1071 - T1071.001 - T1556 - T1556.001","TA0009 - TA0006","N/A","N/A","Sniffing & Spoofing","https://github.com/fkasler/cuddlephish","1","1","N/A","N/A","10","5","487","51","2024-11-21T17:36:55Z","2023-08-02T14:30:41Z","6330" +"*/cups-info.nse*",".{0,1000}\/cups\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6331" +"*/cups-queue-info.nse*",".{0,1000}\/cups\-queue\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6332" +"*/curl.cna",".{0,1000}\/curl\.cna","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","6333" +"*/curl.x64.o",".{0,1000}\/curl\.x64\.o","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","6334" +"*/curl.x86.o",".{0,1000}\/curl\.x86\.o","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","6335" +"*/curlshell.git*",".{0,1000}\/curlshell\.git.{0,1000}","offensive_tool_keyword","curlshell","reverse shell using curl","T1105 - T1059.004 - T1140","TA0011 - TA0002 - TA0007","N/A","N/A","C2","https://github.com/irsl/curlshell","1","1","N/A","N/A","10","10","454","73","2024-04-20T15:23:11Z","2023-07-13T19:38:34Z","6336" +"*/curlshell.git*",".{0,1000}\/curlshell\.git.{0,1000}","offensive_tool_keyword","curlshell","reverse shell using curl","T1572","TA0002 - TA0011","N/A","N/A","C2","https://github.com/irsl/curlshell","1","1","N/A","N/A","10","10","454","73","2024-04-20T15:23:11Z","2023-07-13T19:38:34Z","6337" +"*/curlshell.py*",".{0,1000}\/curlshell\.py.{0,1000}","offensive_tool_keyword","curlshell","reverse shell using curl","T1572","TA0002 - TA0011","N/A","N/A","C2","https://github.com/irsl/curlshell","1","1","N/A","N/A","10","10","454","73","2024-04-20T15:23:11Z","2023-07-13T19:38:34Z","6338" +"*/curlshell-main.*",".{0,1000}\/curlshell\-main\..{0,1000}","offensive_tool_keyword","curlshell","reverse shell using curl","T1572","TA0002 - TA0011","N/A","N/A","C2","https://github.com/irsl/curlshell","1","1","N/A","N/A","10","10","454","73","2024-04-20T15:23:11Z","2023-07-13T19:38:34Z","6339" +"*/CursedChrome.git*",".{0,1000}\/CursedChrome\.git.{0,1000}","offensive_tool_keyword","CursedChrome","Chrome-extension implant that turns victim Chrome browsers into fully-functional HTTP proxies allowing you to browse sites as your victims","T1176 - T1219 - T1090","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/mandatoryprogrammer/CursedChrome","1","1","N/A","N/A","10","10","1533","226","2024-10-26T19:06:54Z","2020-04-26T20:55:05Z","6341" +"*/cursorinit.vbs*",".{0,1000}\/cursorinit\.vbs.{0,1000}","offensive_tool_keyword","Fentanyl","Stealer Malware - Steal Discord Tokens (+ Much More Info) - Steal Passwords/Cookies/History/Credit Cards/Phone Numbers and Addresses from all Browsers (Profile Support) - Steal PC Info - Steal Video Game Accounts (Adding more games + wallets and VPN's) - Low Detections - Anti VM - Sort of Fast - Startup - IP Logger","T1547.001 - T1552.001 - T1552.005 - T1110.001 - T1082 - T1562.001 - T1574.002 - T1529 - T1497.001 - T1543.003 - T1592.001","TA0005 - TA0006 - TA0040 - TA0003 - TA0009","N/A","N/A","Malware","https://github.com/dekrypted/Fentanyl","1","1","N/A","N/A","10","","N/A","","","","6342" +"*/custom_crack_list.txt*",".{0,1000}\/custom_crack_list\.txt.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","6343" +"*/custom_payload_generator/*",".{0,1000}\/custom_payload_generator\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Various Aggressor Scripts I've Created.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/offsecginger/AggressorScripts","1","1","N/A","N/A","10","10","149","30","2022-01-01T19:04:27Z","2018-11-30T03:14:45Z","6344" +"*/customPayload/*",".{0,1000}\/customPayload\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6345" +"*/CVE-*.bin",".{0,1000}\/CVE\-.{0,1000}\.bin","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6347" +"*/CVE-*.jar",".{0,1000}\/CVE\-.{0,1000}\.jar","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6348" +"*/CVE-*_EXPLOIT_0DAY/*",".{0,1000}\/CVE\-.{0,1000}_EXPLOIT_0DAY\/.{0,1000}","offensive_tool_keyword","poc","Exploit for the CVE-2023-23399","T1068 - T1557.001 - T1187 - T1212 -T1003.001 - T1550","TA0003 - TA0002 - TA0004","N/A","N/A","Exploitation tool","https://github.com/sqrtZeroKnowledge/CVE-2023-23397_EXPLOIT_0DAY","1","1","N/A","N/A","N/A","2","161","41","2023-03-15T17:53:53Z","2023-03-15T17:03:38Z","6350" +"*/CVE-*x64.exe",".{0,1000}\/CVE\-.{0,1000}x64\.exe","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6351" +"*/CVE-*x86.exe",".{0,1000}\/CVE\-.{0,1000}x86\.exe","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6352" +"*/CVE-2009-2698/katon.c*",".{0,1000}\/CVE\-2009\-2698\/katon\.c.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","6353" +"*/cve-2014-4113.x64.dll*",".{0,1000}\/cve\-2014\-4113\.x64\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6354" +"*/cve-2014-4113.x86.dll*",".{0,1000}\/cve\-2014\-4113\.x86\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6355" +"*/cve-2015-1701.x64.dll*",".{0,1000}\/cve\-2015\-1701\.x64\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6356" +"*/cve-2015-1701.x86.dll*",".{0,1000}\/cve\-2015\-1701\.x86\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6357" +"*/cve-2016-0051.x86.dll*",".{0,1000}\/cve\-2016\-0051\.x86\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6358" +"*/CVE-2020-0796.x64.dll*",".{0,1000}\/CVE\-2020\-0796\.x64\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6359" +"*/CVE-2021-1675.git*",".{0,1000}\/CVE\-2021\-1675\.git.{0,1000}","offensive_tool_keyword","PrintNightmare","PrintNightmare exploitation","T1210 - T1059.001 - T1548.002","TA0001 - TA0002 - TA0004","N/A","Dispossessor","Privilege Escalation","https://github.com/cube0x0/CVE-2021-1675","1","1","N/A","N/A","10","10","1879","582","2021-07-20T15:28:13Z","2021-06-29T17:24:14Z","6360" +"*/CVE-2021-1675.x64.dll*",".{0,1000}\/CVE\-2021\-1675\.x64\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6361" +"*/CVE-2021-21972.git*",".{0,1000}\/CVE\-2021\-21972\.git.{0,1000}","offensive_tool_keyword","POC","CVE-2021-21972 POC exploitation","T1190 - T1059.001 - T1040","TA0001 - TA0003 - TA0009","N/A","Dispossessor","Exploitation tool","https://github.com/NS-Sp4ce/CVE-2021-21972","1","1","N/A","N/A","7","5","491","146","2023-06-08T04:01:33Z","2021-02-24T11:14:58Z","6362" +"*/CVE-2021-21985_PoC.git*",".{0,1000}\/CVE\-2021\-21985_PoC\.git.{0,1000}","offensive_tool_keyword","POC","CVE-2021-21985 POC exploitation","T1190 - T1059.001 - T1040","TA0001 - TA0003 - TA0009","N/A","Dispossessor","Exploitation tool","https://github.com/sknux/CVE-2021-21985_PoC","1","1","N/A","N/A","7","1","3","1","2021-11-09T19:14:55Z","2021-11-09T19:06:29Z","6363" +"*/CVE-2022-*.git*",".{0,1000}\/CVE\-2022\-.{0,1000}\.git.{0,1000}","offensive_tool_keyword","POC","POC exploit pattern from github","T1203 - T1218 - T1059 - T1064 - T1204","TA0001 - TA0002","N/A","N/A","Exploitation tool","N/A","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6364" +"*/CVE-2022-0847.c*",".{0,1000}\/CVE\-2022\-0847\.c.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1204 - T1055 - T1003 - T1015 - T1068 - T1059 - T1047","TA0001 - TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/4luc4rdr5290/CVE-2022-0847","1","1","N/A","N/A","N/A","1","4","2","2022-03-08T20:41:15Z","2022-03-08T20:18:28Z","6366" +"*/CVE-2022-0847/write_anything.c*",".{0,1000}\/CVE\-2022\-0847\/write_anything\.c.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0008","N/A","N/A","Exploitation tool","https://github.com/gyaansastra/CVE-2022-0847","1","1","N/A","N/A","N/A","1","2","2","2022-03-20T15:46:04Z","2022-03-09T15:44:58Z","6367" +"*/CVE-2022-0847-dirty-pipe-checker*",".{0,1000}\/CVE\-2022\-0847\-dirty\-pipe\-checker.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","t1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/basharkey/CVE-2022-0847-dirty-pipe-checker","1","1","N/A","N/A","N/A","1","67","29","2023-06-14T23:25:46Z","2022-03-08T17:13:24Z","6368" +"*/CVE-2022-0847-DirtyPipe-Exploit*",".{0,1000}\/CVE\-2022\-0847\-DirtyPipe\-Exploit.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","t1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/Arinerron/CVE-2022-0847-DirtyPipe-Exploit","1","1","N/A","N/A","N/A","10","1099","221","2022-03-08T06:20:05Z","2022-03-07T18:55:20Z","6369" +"*/CVE-2022-0847-dirty-pipe-exploit*",".{0,1000}\/CVE\-2022\-0847\-dirty\-pipe\-exploit.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/cspshivam/CVE-2022-0847-dirty-pipe-exploit","1","1","N/A","N/A","N/A","1","1","3","2022-03-08T11:15:00Z","2022-03-08T10:40:07Z","6370" +"*/CVE-2022-0847-Docker*",".{0,1000}\/CVE\-2022\-0847\-Docker.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/mrchucu1/CVE-2022-0847-Docker","1","1","N/A","N/A","N/A","1","0","1","2022-03-08T17:05:01Z","2022-03-08T17:02:40Z","6371" +"*/cve-2022-23131-exp/blob/main/zabbix.py*",".{0,1000}\/cve\-2022\-23131\-exp\/blob\/main\/zabbix\.py.{0,1000}","offensive_tool_keyword","POC","POC exploitaiton of zabbix saml bypass exp vulnerability cve-2022-23131 (Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML)","T1548 - T1190","TA0003 - TA0002","N/A","N/A","Exploitation tool","https://github.com/random-robbie/cve-2022-23131-exp","1","1","N/A","N/A","N/A","1","8","7","2022-02-23T16:37:13Z","2022-02-23T16:34:03Z","6372" +"*/CVE-2022-26809-RCE*",".{0,1000}\/CVE\-2022\-26809\-RCE.{0,1000}","offensive_tool_keyword","POC","Remote Code Execution Exploit in the RPC Library CVE-2022-26809","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/websecnl/CVE-2022-26809","1","1","N/A","N/A","N/A","1","26","3","2022-04-19T17:04:04Z","2022-04-14T08:12:24Z","6373" +"*/CVE-2023-*.git*",".{0,1000}\/CVE\-2023\-.{0,1000}\.git.{0,1000}","offensive_tool_keyword","POC","POC exploit pattern from github","T1203 - T1218 - T1059 - T1064 - T1204","TA0001 - TA0002","N/A","N/A","Exploitation tool","N/A","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6374" +"*/CVE-2023-34362.git*",".{0,1000}\/CVE\-2023\-34362\.git.{0,1000}","offensive_tool_keyword","POC","CVE-2023-34362: MOVEit Transfer Unauthenticated RCE","T1190.001 - T1210.002 - T1068 - T1059.001 - T1059.003","TA0005 - TA0001 - TA0002 - TA0043","N/A","N/A","Exploitation tool","https://github.com/sfewer-r7/CVE-2023-34362","1","1","N/A","N/A","N/A","1","64","23","2024-03-24T00:46:38Z","2023-06-12T12:56:12Z","6375" +"*/CVE-2023-38831-RaRCE*",".{0,1000}\/CVE\-2023\-38831\-RaRCE.{0,1000}","offensive_tool_keyword","RaRCE","An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831 - WinRAR RCE before versions 6.23","T1068 - T1203 - T1059.003","TA0001 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/ignis-sec/CVE-2023-38831-RaRCE","1","1","N/A","N/A","9","2","115","18","2023-08-27T22:17:56Z","2023-08-27T21:49:37Z","6376" +"*/CVE-2024-1086.git*",".{0,1000}\/CVE\-2024\-1086\.git.{0,1000}","offensive_tool_keyword","POC","local privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6","T1068 - T1548.002","TA0004","N/A","N/A","Privilege Escalation","https://github.com/Notselwyn/CVE-2024-1086","1","1","#linux","CVE-2024-1086 POC","10","10","2357","314","2024-04-17T16:09:54Z","2024-03-20T21:16:41Z","6377" +"*/CVE-2024-21338.git*",".{0,1000}\/CVE\-2024\-21338\.git.{0,1000}","offensive_tool_keyword","POC","Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.","T1055.011 - T1548.002","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/hakaioffsec/CVE-2024-21338","1","1","N/A","N/A","9","3","292","60","2024-04-16T21:00:14Z","2024-04-13T05:53:02Z","6378" +"*/CVE-2024-22274-RCE.git*",".{0,1000}\/CVE\-2024\-22274\-RCE\.git.{0,1000}","offensive_tool_keyword","POC","PoC - Authenticated Remote Code Execution in VMware vCenter Server (CVE-2024-22274 Exploit)","T1213 - T1059 - T1056 - T1078 - T1578","TA0001 - TA0002 - TA0008 - TA0009","N/A","N/A","Lateral Movement","https://github.com/l0n3m4n/CVE-2024-22274-RCE","1","1","N/A","N/A","10","1","42","8","2024-07-16T23:22:14Z","2024-07-15T07:26:59Z","6379" +"*/CVE-2024-49138-POC.git*",".{0,1000}\/CVE\-2024\-49138\-POC\.git.{0,1000}","offensive_tool_keyword","POC","Windows Privilege escalation POC exploitation for CVE-2024-49138","T1068 - T1058 - T1203","TA0004","N/A","N/A","Privilege Escalation","https://github.com/emdnaia/CVE-2024-49138-POC","1","1","N/A","N/A","9","1","1","0","2025-01-15T01:01:21Z","2025-01-15T02:11:49Z","6380" +"*/cvs-brute.nse*",".{0,1000}\/cvs\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6381" +"*/cvs-brute-repository.nse*",".{0,1000}\/cvs\-brute\-repository\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6382" +"*/CWoNaJLBo/VTNeWw11212/*",".{0,1000}\/CWoNaJLBo\/VTNeWw11212\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","6383" +"*/CWoNaJLBo/VTNeWw11213/*",".{0,1000}\/CWoNaJLBo\/VTNeWw11213\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","6384" +"*/Cyber Shell (v 1.0).php*",".{0,1000}\/Cyber\sShell\s\(v\s1\.0\)\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","6385" +"*/CyberSpy5.Asp*",".{0,1000}\/CyberSpy5\.Asp.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","6386" +"*/d00r_py3.py*",".{0,1000}\/d00r_py3\.py.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","6387" +"*/D1rkInject.git*",".{0,1000}\/D1rkInject\.git.{0,1000}","offensive_tool_keyword","D1rkInject","Threadless injection that loads a module into the target process and stomps it and reverting back memory protections and original memory state","T1055 - T1055.012 - T1055.002 - T1574.002","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/D1rkInject","1","1","N/A","N/A","9","2","177","32","2023-08-02T02:45:46Z","2023-08-02T02:13:55Z","6388" +"*/D3m0n1z3dShell.git*",".{0,1000}\/D3m0n1z3dShell\.git.{0,1000}","offensive_tool_keyword","D3m0n1z3dShell","Demonized Shell is an Advanced Tool for persistence in linux","T1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037","TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Persistence","https://github.com/MatheuZSecurity/D3m0n1z3dShell","1","1","#linux","N/A","10","4","373","54","2025-01-05T13:56:51Z","2023-05-30T02:30:47Z","6389" +"*/D3m0n1z3dShell/archive/*",".{0,1000}\/D3m0n1z3dShell\/archive\/.{0,1000}","offensive_tool_keyword","D3m0n1z3dShell","Demonized Shell is an Advanced Tool for persistence in linux","T1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037","TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Persistence","https://github.com/MatheuZSecurity/D3m0n1z3dShell","1","1","#linux","N/A","10","4","373","54","2025-01-05T13:56:51Z","2023-05-30T02:30:47Z","6390" +"*/d4em0n/exrop*",".{0,1000}\/d4em0n\/exrop.{0,1000}","offensive_tool_keyword","Exrop","Exrop is automatic ROP chains generator tool which can build gadget chain automatically from given binary and constraints","T1554","TA0003","N/A","N/A","Exploitation tool","https://github.com/d4em0n/exrop","1","1","N/A","N/A","N/A","3","285","22","2020-02-21T08:01:06Z","2020-01-19T05:09:00Z","6391" +"*/daap-get-library.nse*",".{0,1000}\/daap\-get\-library\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6392" +"*/dacledit.py*",".{0,1000}\/dacledit\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","6393" +"*/dacledit.py*",".{0,1000}\/dacledit\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","6394" +"*/daclread.py*",".{0,1000}\/daclread\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","6395" +"*/dafthack/MSOLSpray*",".{0,1000}\/dafthack\/MSOLSpray.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","6396" +"*/DAMP.git*",".{0,1000}\/DAMP\.git.{0,1000}","offensive_tool_keyword","DAMP","The Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification.","T1222 - T1222.002 - T1548 - T1548.002","TA0005 ","N/A","N/A","Persistence","https://github.com/HarmJ0y/DAMP","1","1","N/A","N/A","10","4","378","79","2019-07-25T21:18:37Z","2018-04-06T22:13:58Z","6398" +"*/Dandelion_RAT.exe*",".{0,1000}\/Dandelion_RAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6399" +"*/daphne.git*",".{0,1000}\/daphne\.git.{0,1000}","offensive_tool_keyword","daphne","evade auditd by tampering via ptrace","T1054.004 - T1012 - T1057","TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/codewhitesec/daphne","1","1","N/A","N/A","8","1","17","3","2023-08-03T08:31:40Z","2023-07-31T11:57:29Z","6401" +"*/daphne-x64*",".{0,1000}\/daphne\-x64.{0,1000}","offensive_tool_keyword","daphne","evade auditd by tampering via ptrace","T1054.004 - T1012 - T1057","TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/codewhitesec/daphne","1","1","N/A","N/A","8","1","17","3","2023-08-03T08:31:40Z","2023-07-31T11:57:29Z","6402" +"*/Dark Comet Stub Crypter.exe*",".{0,1000}\/Dark\sComet\sStub\sCrypter\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","Transparent Tribe - SilverTerrier - APT38 ","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6403" +"*/darkarmour.git*",".{0,1000}\/darkarmour\.git.{0,1000}","offensive_tool_keyword","darkarmour","Store and execute an encrypted windows binary from inside memorywithout a single bit touching disk.","T1055.012 - T1027 - T1564.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/bats3c/darkarmour","1","1","N/A","N/A","10","8","773","122","2020-04-13T10:56:23Z","2020-04-06T20:48:20Z","6404" +"*/DarkCoderSc.exe*",".{0,1000}\/DarkCoderSc\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6405" +"*/DarkCoderSc/*",".{0,1000}\/DarkCoderSc\/.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","1","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","6406" +"*/DarkComet.exe*",".{0,1000}\/DarkComet\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","Transparent Tribe - SilverTerrier - APT38 ","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6407" +"*/DarkComet.exe*",".{0,1000}\/DarkComet\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","Transparent Tribe - SilverTerrier - APT38 ","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6408" +"*/DarkComet_Full_setup.exe*",".{0,1000}\/DarkComet_Full_setup\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","Transparent Tribe - SilverTerrier - APT38 ","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6409" +"*/DarkComet_Module_setup.exe*",".{0,1000}\/DarkComet_Module_setup\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","Transparent Tribe - SilverTerrier - APT38 ","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6410" +"*/darkexe.py*",".{0,1000}\/darkexe\.py.{0,1000}","offensive_tool_keyword","FourEye","AV Evasion Tool","T1059 - T1059.001 - T1059.005 - T1027 - T1027.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/lengjibo/FourEye","1","1","N/A","N/A","10","8","758","152","2021-12-08T11:55:15Z","2020-12-11T01:29:58Z","6411" +"*/darkfire.bat*",".{0,1000}\/darkfire\.bat.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","6412" +"*/darkhotel.py*",".{0,1000}\/darkhotel\.py.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","6413" +"*/DarkLoadLibrary.git*",".{0,1000}\/DarkLoadLibrary\.git.{0,1000}","offensive_tool_keyword","DarkLoadLibrary","LoadLibrary for offensive operations","T1071.001 - T1055.002 - T1055.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bats3c/DarkLoadLibrary","1","1","N/A","N/A","10","10","1133","207","2021-10-22T07:27:58Z","2021-06-17T08:33:47Z","6414" +"*/Darkside.exe*",".{0,1000}\/Darkside\.exe.{0,1000}","offensive_tool_keyword","Darkside","C# AV/EDR Killer using less-known driver (BYOVD)","T1547.006 - T1055 - T1562.001","TA0005 - TA0003 - TA0004 ","N/A","N/A","Defense Evasion","https://github.com/ph4nt0mbyt3/Darkside","1","1","N/A","N/A","10","2","175","34","2023-11-10T16:01:21Z","2023-11-10T15:34:20Z","6415" +"*/Darkside.git*",".{0,1000}\/Darkside\.git.{0,1000}","offensive_tool_keyword","Darkside","C# AV/EDR Killer using less-known driver (BYOVD)","T1547.006 - T1055 - T1562.001","TA0005 - TA0003 - TA0004 ","N/A","N/A","Defense Evasion","https://github.com/ph4nt0mbyt3/Darkside","1","1","N/A","N/A","10","2","175","34","2023-11-10T16:01:21Z","2023-11-10T15:34:20Z","6416" +"*/Dark-Virus.exe*",".{0,1000}\/Dark\-Virus\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6418" +"*/Dark-Virus.exe*",".{0,1000}\/Dark\-Virus\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6419" +"*/DarkWidow.git*",".{0,1000}\/DarkWidow\.git.{0,1000}","offensive_tool_keyword","DarkWidow","Indirect Dynamic Syscall SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a sacrificial Process as target process + (ACG+BlockDll) mitigation policy on spawned process + PPID spoofing (Emotet method) + Api resolving from TIB + API hashing","T1055 - T1055.012 - T1055.002 - T1098 - T1027 - T1027.001 - T1070.004 - T1036 - T1134 - T1140","TA0005 - TA0003 - TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/reveng007/DarkWidow","1","1","N/A","N/A","10","7","671","91","2025-03-12T21:58:25Z","2023-07-24T13:59:16Z","6421" +"*/data/attacks/*.txt*",".{0,1000}\/data\/attacks\/.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","6425" +"*/data/auxiliary/gather*",".{0,1000}\/data\/auxiliary\/gather.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6426" +"*/data/empire.db*",".{0,1000}\/data\/empire\.db.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","6429" +"*/data/exploits/*",".{0,1000}\/data\/exploits\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6431" +"*/data/shellcode*",".{0,1000}\/data\/shellcode.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6434" +"*/DataBouncing.git*",".{0,1000}\/DataBouncing\.git.{0,1000}","offensive_tool_keyword","DataBouncing","Data Bouncing is a technique for transmitting data between two endpoints using DNS lookups and HTTP header manipulation","T1048 - T1041","TA0010","N/A","N/A","Data Exfiltration","https://github.com/Unit-259/DataBouncing","1","1","N/A","N/A","9","1","15","0","2025-03-12T07:34:04Z","2025-03-12T06:58:51Z","6435" +"*/DavRelayUp.git*",".{0,1000}\/DavRelayUp\.git.{0,1000}","offensive_tool_keyword","DavRelayUp","DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced","T1078 - T1078.004 - T1068","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/ShorSec/DavRelayUp","1","1","N/A","N/A","9","6","542","81","2023-06-05T09:17:06Z","2023-06-05T07:49:39Z","6441" +"*/DavRelayUp/*",".{0,1000}\/DavRelayUp\/.{0,1000}","offensive_tool_keyword","DavRelayUp","DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced","T1078 - T1078.004 - T1068","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/ShorSec/DavRelayUp","1","1","N/A","N/A","9","6","542","81","2023-06-05T09:17:06Z","2023-06-05T07:49:39Z","6442" +"*/daytime.nse*",".{0,1000}\/daytime\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6443" +"*/dazzleUP.git*",".{0,1000}\/dazzleUP\.git.{0,1000}","offensive_tool_keyword","dazzleUP","A tool that detects the privilege escalation vulnerabilities caused by misconfigurations and missing updates in the Windows operating systems.","T1068 - T1088 - T1210 - T1210.002","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/hlldz/dazzleUP","1","1","N/A","N/A","9","5","490","69","2020-07-23T08:48:43Z","2020-07-21T21:06:46Z","6444" +"*/dazzleUP_Reflective_DLL.x64.dll*",".{0,1000}\/dazzleUP_Reflective_DLL\.x64\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6445" +"*/db2_default_userpass.txt*",".{0,1000}\/db2_default_userpass\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6447" +"*/db2-das-info.nse*",".{0,1000}\/db2\-das\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6448" +"*/dbc2Loader*",".{0,1000}\/dbc2Loader.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","6449" +"*/DBC-Server.py*",".{0,1000}\/DBC\-Server\.py.{0,1000}","offensive_tool_keyword","dns-black-cat","Multi platform toolkit for an interactive DNS shell commands exfiltration - by using DNS-Cat you will be able to execute system commands in shell mode over DNS protocol","T1140 - T1048.003 - T1071.004","TA0011 - TA0040 - TA0001","N/A","N/A","C2","https://github.com/lawrenceamer/dns-black-cat","1","1","N/A","N/A","10","10","114","20","2022-09-15T18:07:05Z","2021-02-13T11:31:22Z","6450" +"*/DCOM Lateral Movement/*",".{0,1000}\/DCOM\sLateral\sMovement\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of beacon BOF written to learn windows and cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Yaxser/CobaltStrike-BOF","1","1","N/A","N/A","10","10","347","57","2023-02-24T13:12:14Z","2020-10-08T01:12:41Z","6453" +"*/dcomexec.exe*",".{0,1000}\/dcomexec\.exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","6454" +"*/dcomexec.py*",".{0,1000}\/dcomexec\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","6455" +"*/dcomhijack.cna*",".{0,1000}\/dcomhijack\.cna.{0,1000}","offensive_tool_keyword","dcomhijack","Lateral Movement Using DCOM with impacket and DLL Hijacking","T1570 - T1021.003 - T1574.001 - T1574.002","TA0008 - TA0003 - TA0005","N/A","N/A","Lateral Movement","https://github.com/WKL-Sec/dcomhijack","1","1","N/A","N/A","7","3","290","24","2023-06-18T20:34:03Z","2023-06-17T20:23:24Z","6456" +"*/dcomhijack.git*",".{0,1000}\/dcomhijack\.git.{0,1000}","offensive_tool_keyword","dcomhijack","Lateral Movement Using DCOM and DLL Hijacking","T1021 - T1021.003 - T1574 - T1574.007 - T1574.002","TA0008 - TA0005 - TA0002","N/A","N/A","Lateral Movement","https://github.com/WKL-Sec/dcomhijack","1","1","N/A","N/A","10","3","290","24","2023-06-18T20:34:03Z","2023-06-17T20:23:24Z","6457" +"*/dcomhijack.git*",".{0,1000}\/dcomhijack\.git.{0,1000}","offensive_tool_keyword","dcomhijack","Lateral Movement Using DCOM with impacket and DLL Hijacking","T1570 - T1021.003 - T1574.001 - T1574.002","TA0008 - TA0003 - TA0005","N/A","N/A","Lateral Movement","https://github.com/WKL-Sec/dcomhijack","1","1","N/A","N/A","7","3","290","24","2023-06-18T20:34:03Z","2023-06-17T20:23:24Z","6458" +"*/dcomhijack.py*",".{0,1000}\/dcomhijack\.py.{0,1000}","offensive_tool_keyword","dcomhijack","Lateral Movement Using DCOM with impacket and DLL Hijacking","T1570 - T1021.003 - T1574.001 - T1574.002","TA0008 - TA0003 - TA0005","N/A","N/A","Lateral Movement","https://github.com/WKL-Sec/dcomhijack","1","1","N/A","N/A","7","3","290","24","2023-06-18T20:34:03Z","2023-06-17T20:23:24Z","6459" +"*/DCOMPotato.git*",".{0,1000}\/DCOMPotato\.git.{0,1000}","offensive_tool_keyword","DCOMPotato","Service DCOM Object and SeImpersonatePrivilege abuse.","T1548.002 - T1134.002","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/zcgonvh/DCOMPotato","1","1","N/A","N/A","10","4","356","48","2022-12-09T01:57:53Z","2022-12-08T14:56:13Z","6460" +"*/DCOMUploadExec.exe*",".{0,1000}\/DCOMUploadExec\.exe.{0,1000}","offensive_tool_keyword","DCOMUploadExec","DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely","T1021.003 - T1570 - T1105 - T1569.002","TA0008 - TA0011 - TA0002","N/A","N/A","Lateral Movement","https://github.com/deepinstinct/DCOMUploadExec","1","1","N/A","N/A","9","4","357","52","2024-12-13T14:03:12Z","2024-11-13T16:05:29Z","6461" +"*/DCOMUploadExec.git*",".{0,1000}\/DCOMUploadExec\.git.{0,1000}","offensive_tool_keyword","DCOMUploadExec","DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely","T1021.003 - T1570 - T1105 - T1569.002","TA0008 - TA0011 - TA0002","N/A","N/A","Lateral Movement","https://github.com/deepinstinct/DCOMUploadExec","1","1","N/A","N/A","9","4","357","52","2024-12-13T14:03:12Z","2024-11-13T16:05:29Z","6462" +"*/dControl.exe*",".{0,1000}\/dControl\.exe.{0,1000}","offensive_tool_keyword","defender-control","disable windows defender permanently","T1562.001 - T1562.004 - T1089","TA0005 - TA0002","N/A","LockBit","Defense Evasion","https://www.sordum.org/9480/defender-control-v2-1/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","6463" +"*/dControl.rar*",".{0,1000}\/dControl\.rar.{0,1000}","offensive_tool_keyword","defender-control","disable windows defender permanently","T1562.001 - T1562.004 - T1089","TA0005 - TA0002","N/A","LockBit","Defense Evasion","https://www.sordum.org/9480/defender-control-v2-1/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","6464" +"*/DcRat.git*",".{0,1000}\/DcRat\.git.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","6465" +"*/DcRat.sln*",".{0,1000}\/DcRat\.sln.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","6466" +"*/DcRat/releases/download/*",".{0,1000}\/DcRat\/releases\/download\/.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","6467" +"*/dcrypt.exe*",".{0,1000}\/dcrypt\.exe.{0,1000}","offensive_tool_keyword","DiskCryptor","DiskCryptor is an open source encryption solution that offers encryption of all disk partitions including system partitions","T1486 ","TA0040","N/A","N/A","Ransomware","https://github.com/DavidXanatos/DiskCryptor","1","1","N/A","N/A","10","5","499","108","2024-07-03T10:05:01Z","2019-04-20T14:51:18Z","6468" +"*/dcrypt_setup.exe*",".{0,1000}\/dcrypt_setup\.exe.{0,1000}","offensive_tool_keyword","DiskCryptor","DiskCryptor is an open source encryption solution that offers encryption of all disk partitions including system partitions","T1486 ","TA0040","N/A","N/A","Ransomware","https://github.com/DavidXanatos/DiskCryptor","1","1","N/A","N/A","10","5","499","108","2024-07-03T10:05:01Z","2019-04-20T14:51:18Z","6469" +"*/dcshadow.html*",".{0,1000}\/dcshadow\.html.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","6470" +"*/dcsync_*.txt",".{0,1000}\/dcsync_.{0,1000}\.txt","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","6471" +"*/DCSyncer.git*",".{0,1000}\/DCSyncer\.git.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","1","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","6472" +"*/DCSyncer/releases/download/*",".{0,1000}\/DCSyncer\/releases\/download\/.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","1","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","6473" +"*/DCSyncer/tarball/*",".{0,1000}\/DCSyncer\/tarball\/.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","1","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","6474" +"*/DCSyncer/zipball/*",".{0,1000}\/DCSyncer\/zipball\/.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","1","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","6475" +"*/DDexec.git*",".{0,1000}\/DDexec\.git.{0,1000}","offensive_tool_keyword","Ddexec","A technique to run binaries filelessly and stealthily on Linux by ""overwriting"" the shell's process with another.","T1055.008 - T1106 - T1059.004","TA0002 - TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/arget13/DDexec","1","1","#linux","N/A","9","9","830","88","2025-03-21T17:51:04Z","2022-01-27T12:52:10Z","6476" +"*/DDSpoof.git*",".{0,1000}\/DDSpoof\.git.{0,1000}","offensive_tool_keyword","DDSpoof","DDSpoof is a tool that enables DHCP DNS Dynamic Update attacks against Microsoft DHCP servers in AD environments.","T1557 - T1584 - T1203","TA0005 - TA0003 TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/akamai/DDSpoof","1","1","N/A","N/A","9","2","122","13","2024-04-12T22:06:02Z","2023-12-14T06:47:45Z","6479" +"*/ddspoof.py*",".{0,1000}\/ddspoof\.py.{0,1000}","offensive_tool_keyword","DDSpoof","DDSpoof is a tool that enables DHCP DNS Dynamic Update attacks against Microsoft DHCP servers in AD environments.","T1557 - T1584 - T1203","TA0005 - TA0003 TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/akamai/DDSpoof","1","1","N/A","N/A","9","2","122","13","2024-04-12T22:06:02Z","2023-12-14T06:47:45Z","6480" +"*/deadPool.ps1*",".{0,1000}\/deadPool\.ps1.{0,1000}","offensive_tool_keyword","DataBouncing","Data Bouncing is a technique for transmitting data between two endpoints using DNS lookups and HTTP header manipulation","T1048 - T1041","TA0010","N/A","N/A","Data Exfiltration","https://github.com/Unit-259/DataBouncing","1","1","N/A","N/A","9","1","15","0","2025-03-12T07:34:04Z","2025-03-12T06:58:51Z","6481" +"*/DeadPotato.git*",".{0,1000}\/DeadPotato\.git.{0,1000}","offensive_tool_keyword","DeadPotato","DeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privileges","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","N/A","N/A","Privilege Escalation","https://github.com/lypd0/DeadPotato","1","1","N/A","N/A","10","4","382","45","2024-08-17T06:08:29Z","2024-07-31T01:08:30Z","6482" +"*/Deamond RAT 1.2/*",".{0,1000}\/Deamond\sRAT\s1\.2\/.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6483" +"*/deb.parrot.sh/*",".{0,1000}\/deb\.parrot\.sh\/.{0,1000}","offensive_tool_keyword","parrot os","Parrot OS is a Debian-based. security-oriented Linux distribution that is designed for ethical hacking. penetration testing and digital forensics.","T1590 - T1200 - T1027 - T1578 - T1003 - T1001 - T1046 - T1570 - T1114 - T1105","TA0043 - TA0002 - TA0003 - TA0004 - TA0006 - TA0005 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation OS","https://www.parrotsec.org/download/","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6485" +"*/DebugAmsi.git*",".{0,1000}\/DebugAmsi\.git.{0,1000}","offensive_tool_keyword","DebugAmsi","DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.","T1562.001 - T1050.005","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/MzHmO/DebugAmsi","1","1","N/A","N/A","10","1","97","22","2023-09-18T17:17:26Z","2023-08-28T07:32:54Z","6487" +"*/decipher_mremoteng.iml*",".{0,1000}\/decipher_mremoteng\.iml.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","1","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","6488" +"*/DecryptAutoLogon.exe*",".{0,1000}\/DecryptAutoLogon\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6489" +"*/DecryptAutoLogon.exe*",".{0,1000}\/DecryptAutoLogon\.exe.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","1","N/A","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","6490" +"*/DecryptAutoLogon.git*",".{0,1000}\/DecryptAutoLogon\.git.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","1","N/A","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","6491" +"*/decrypt-chrome-passwords*",".{0,1000}\/decrypt\-chrome\-passwords.{0,1000}","offensive_tool_keyword","decrypt-chrome-passwords","A simple program to decrypt chrome password saved on your machine.","T1555.003 - T1112 - T1056.001","TA0006 - TA0009 - TA0040","N/A","N/A","Credential Access","https://github.com/ohyicong/decrypt-chrome-passwords","1","1","N/A","N/A","10","10","966","211","2024-07-31T14:08:55Z","2020-12-28T15:11:12Z","6492" +"*/decrypting-lsa-secrets.html*",".{0,1000}\/decrypting\-lsa\-secrets\.html.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","1","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","6494" +"*/decrypting-lsa-secrets.html*",".{0,1000}\/decrypting\-lsa\-secrets\.html.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","6495" +"*/Decrypt-RDCMan.ps1*",".{0,1000}\/Decrypt\-RDCMan\.ps1.{0,1000}","offensive_tool_keyword","Decrypt-RDCMan","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/vmamuaya/Powershell/blob/master/Decrypt-RDCMan.ps1","1","1","N/A","N/A","9","1","1","1","2016-12-01T14:06:24Z","2017-11-22T23:18:39Z","6497" +"*/DecryptRDCManager.git*",".{0,1000}\/DecryptRDCManager\.git.{0,1000}","offensive_tool_keyword","DecryptRDCManager","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/mez-0/DecryptRDCManager","1","1","N/A","N/A","8","1","73","7","2020-09-29T10:12:58Z","2020-09-29T08:53:46Z","6498" +"*/DecryptTeamViewer.exe*",".{0,1000}\/DecryptTeamViewer\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6499" +"*/DecryptTeamViewer.exe*",".{0,1000}\/DecryptTeamViewer\.exe.{0,1000}","offensive_tool_keyword","DecryptTeamViewer","Enumerate and decrypt TeamViewer credentials from Windows registry","T1552.001 - T1003 - T1119 - T1012","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/V1V1/DecryptTeamViewer","1","1","N/A","N/A","7","3","241","62","2021-12-05T09:19:56Z","2020-02-07T07:50:47Z","6500" +"*/DecryptTeamViewer.git*",".{0,1000}\/DecryptTeamViewer\.git.{0,1000}","offensive_tool_keyword","DecryptTeamViewer","Enumerate and decrypt TeamViewer credentials from Windows registry","T1552.001 - T1003 - T1119 - T1012","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/V1V1/DecryptTeamViewer","1","1","N/A","N/A","7","3","241","62","2021-12-05T09:19:56Z","2020-02-07T07:50:47Z","6501" +"*/DEDSEC-RANSOMWARE.git*",".{0,1000}\/DEDSEC\-RANSOMWARE\.git.{0,1000}","offensive_tool_keyword","DEDSEC-RANSOMWARE","dedsec ransomware","T1486 - T1489 - T1490 - T1495 - T1488 - T1482","TA0040 - TA0043 - TA0042 - TA0009 - TA0010","N/A","N/A","Ransomware","https://github.com/xelroth/DEDSEC-RANSOMWARE","1","1","N/A","N/A","10","1","7","1","2024-05-17T11:12:23Z","2024-05-17T10:34:03Z","6502" +"*/deepce.sh*",".{0,1000}\/deepce\.sh.{0,1000}","offensive_tool_keyword","D3m0n1z3dShell","Demonized Shell is an Advanced Tool for persistence in linux","T1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037","TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Persistence","https://github.com/MatheuZSecurity/D3m0n1z3dShell","1","1","#linux","N/A","10","4","373","54","2025-01-05T13:56:51Z","2023-05-30T02:30:47Z","6504" +"*/DefaultCreds_db.json*",".{0,1000}\/DefaultCreds_db\.json.{0,1000}","offensive_tool_keyword","DefaultCreds-cheat-sheet","One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password","T1110.001 - T1110.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/ihebski/DefaultCreds-cheat-sheet","1","1","N/A","N/A","N/A","10","6048","726","2025-04-15T13:13:19Z","2021-01-01T19:02:36Z","6508" +"*/Defeat-Defender-V1.2.0.git*",".{0,1000}\/Defeat\-Defender\-V1\.2\.0\.git.{0,1000}","offensive_tool_keyword","Defeat-Defender","script to dismantle complete windows defender protection and even bypass tamper protection - Disable Windows-Defender Permanently.","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/swagkarna/Defeat-Defender-V1.2.0","1","1","N/A","N/A","10","10","1530","316","2023-10-20T17:55:09Z","2020-12-10T07:22:06Z","6509" +"*/Defender Control.zip*",".{0,1000}\/Defender\sControl\.zip.{0,1000}","offensive_tool_keyword","defender-control","disable windows defender permanently","T1562.001 - T1562.004 - T1089","TA0005 - TA0002","N/A","LockBit","Defense Evasion","https://www.sordum.org/9480/defender-control-v2-1/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","6510" +"*/defender-control.git*",".{0,1000}\/defender\-control\.git.{0,1000}","offensive_tool_keyword","defender-control","An open-source windows defender manager. Now you can disable windows defender permanently","T1562.001 - T1562.004 - T1089","TA0005 - TA0002","N/A","LockBit","Defense Evasion","https://github.com/pgkt04/defender-control","1","1","N/A","N/A","10","10","1614","128","2023-09-09T14:57:56Z","2021-05-15T10:09:17Z","6511" +"*/defendercontrol.zip*",".{0,1000}\/defendercontrol\.zip.{0,1000}","offensive_tool_keyword","defender-control","disable windows defender permanently","T1562.001 - T1562.004 - T1089","TA0005 - TA0002","N/A","LockBit","Defense Evasion","https://www.sordum.org/9480/defender-control-v2-1/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","6512" +"*/defender-exclusions.ps1*",".{0,1000}\/defender\-exclusions\.ps1.{0,1000}","offensive_tool_keyword","Kematian Stealer","Fake WinRar site distributes malware (+stealer +miner +hvnc +ransomware) from GitHub","T1195 - T1566 - T1569 - T1106 - T1486 - T1113","TA0001 - TA0002 - TA0005 - TA0006 - TA0007 - TA0009 - TA0010 - TA0011 - TA0040 - TA0043","N/A","N/A","Malware","https://github[.]com/sap3r-encrypthub/encrypthub","1","1","N/A","N/A","10","7","N/A","N/A","N/A","N/A","6513" +"*/defender-exclusions/*defender*",".{0,1000}\/defender\-exclusions\/.{0,1000}defender.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of CobaltStrike beacon object files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/pwn1sher/CS-BOFs","1","1","N/A","N/A","10","10","103","22","2022-02-14T09:47:30Z","2021-01-18T08:54:48Z","6514" +"*/defender-exclusions/*exclusion*",".{0,1000}\/defender\-exclusions\/.{0,1000}exclusion.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of CobaltStrike beacon object files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/pwn1sher/CS-BOFs","1","1","N/A","N/A","10","10","103","22","2022-02-14T09:47:30Z","2021-01-18T08:54:48Z","6515" +"*/defenderOff.rar*",".{0,1000}\/defenderOff\.rar.{0,1000}","offensive_tool_keyword","defender-control","disable windows defender permanently","T1562.001 - T1562.004 - T1089","TA0005 - TA0002","N/A","LockBit","Defense Evasion","https://www.sordum.org/9480/defender-control-v2-1/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","6516" +"*/DefenderRemover.exe*",".{0,1000}\/DefenderRemover\.exe.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","6517" +"*/DefenderRemover-x86.exe*",".{0,1000}\/DefenderRemover\-x86\.exe.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","6518" +"*/DelegationBOF/*",".{0,1000}\/DelegationBOF\/.{0,1000}","offensive_tool_keyword","cobaltstrike","This tool uses LDAP to check a domain for known abusable Kerberos delegation settings","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/IcebreakerSecurity/DelegationBOF","1","1","N/A","N/A","10","10","141","23","2022-05-04T14:00:36Z","2022-03-28T20:14:24Z","6520" +"*/DelegationBOF/*",".{0,1000}\/DelegationBOF\/.{0,1000}","offensive_tool_keyword","DelegationBOF","This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently. it supports RBCD. Constrained. Constrained w/Protocol Transition. and Unconstrained Delegation checks.","T1098 - T1214 - T1552","TA0006","N/A","N/A","Credential Access","https://github.com/IcebreakerSecurity/DelegationBOF","1","1","N/A","N/A","N/A","10","141","23","2022-05-04T14:00:36Z","2022-03-28T20:14:24Z","6521" +"*/DeleteonReboot.exe*",".{0,1000}\/DeleteonReboot\.exe.{0,1000}","offensive_tool_keyword","RedTeam_Tools_n_Stuff","Schedules a file to be deleted on next Windows host reboot","T1070.004 - T1222 - T1070.003 - T1003.005 - T1057","TA0005 - TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/samkenxstream/SAMkenXCCorePHdLAwiN8SoLr77","1","1","N/A","N/A","7","1","1","1","2023-10-13T06:31:42Z","2023-10-04T13:43:37Z","6522" +"*/DeleteWD.dll*",".{0,1000}\/DeleteWD\.dll.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","6523" +"*/deluge-rpc-brute.nse*",".{0,1000}\/deluge\-rpc\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6524" +"*/dementor.py*",".{0,1000}\/dementor\.py.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","1","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","6525" +"*/demiguise.py*",".{0,1000}\/demiguise\.py.{0,1000}","offensive_tool_keyword","demiguise","The aim of this project is to generate .html files that contain an encrypted HTA file. The idea is that when your target visits the page. the key is fetched and the HTA is decrypted dynamically within the browser and pushed directly to the user. This is an evasion technique to get round content / file-type inspection implemented by some security-appliances. This tool is not designed to create awesome HTA content. There are many other tools/techniques that can help you with that. What it might help you with is getting your HTA into an environment in the first place. and (if you use environmental keying) to avoid it being sandboxed.","T1564 - T1071.001 - T1071.004 - T1059 - T1070","TA0002 - TA0011 - TA0008","N/A","N/A","Defense Evasion","https://github.com/nccgroup/demiguise","1","1","N/A","N/A","9","10","1389","257","2022-11-09T08:12:25Z","2017-07-26T08:56:15Z","6526" +"*/demo.specula.com/*",".{0,1000}\/demo\.specula\.com\/.{0,1000}","offensive_tool_keyword","specula","Specula is a C2 framework that allows for interactive operations of an implant that runs purely in the context of outlook","T1071.001 - T1105 - T1204 - T1548.002 - T1071 - T1562","TA0011 - TA0002 - TA0003 - TA0006 - TA0008 - TA0007 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/trustedsec/specula","1","1","N/A","N/A","10","10","191","21","2024-09-23T09:25:33Z","2023-12-07T15:59:52Z","6527" +"*/demo_bof.c*",".{0,1000}\/demo_bof\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool to run object files mainly beacon object files (BOF) in .Net.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nettitude/RunOF","1","1","N/A","N/A","10","10","145","21","2023-01-06T15:30:05Z","2022-02-21T13:53:39Z","6528" +"*/demon.x64.bin*",".{0,1000}\/demon\.x64\.bin.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","6529" +"*/demon.x64.exe*",".{0,1000}\/demon\.x64\.exe.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","6530" +"*/demon1.dll*",".{0,1000}\/demon1\.dll.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","6531" +"*/demosyscalls.exe*",".{0,1000}\/demosyscalls\.exe.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","6532" +"*/Dendrobate.git*",".{0,1000}\/Dendrobate\.git.{0,1000}","offensive_tool_keyword","Dendrobate","Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code","T1055.012 - T1059.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Dendrobate","1","1","N/A","N/A","10","2","131","27","2021-11-19T12:18:50Z","2021-02-15T11:15:51Z","6533" +"*/Dendron.bin*",".{0,1000}\/Dendron\.bin.{0,1000}","offensive_tool_keyword","Dendrobate","Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code","T1055.012 - T1059.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Dendrobate","1","1","N/A","N/A","10","2","131","27","2021-11-19T12:18:50Z","2021-02-15T11:15:51Z","6534" +"*/Dendron.csproj*",".{0,1000}\/Dendron\.csproj.{0,1000}","offensive_tool_keyword","Dendrobate","Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code","T1055.012 - T1059.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Dendrobate","1","1","N/A","N/A","10","2","131","27","2021-11-19T12:18:50Z","2021-02-15T11:15:51Z","6535" +"*/Dendron.exe*",".{0,1000}\/Dendron\.exe.{0,1000}","offensive_tool_keyword","Dendrobate","Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code","T1055.012 - T1059.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Dendrobate","1","1","N/A","N/A","10","2","131","27","2021-11-19T12:18:50Z","2021-02-15T11:15:51Z","6536" +"*/Dendron.sln*",".{0,1000}\/Dendron\.sln.{0,1000}","offensive_tool_keyword","Dendrobate","Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code","T1055.012 - T1059.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Dendrobate","1","1","N/A","N/A","10","2","131","27","2021-11-19T12:18:50Z","2021-02-15T11:15:51Z","6537" +"*/DeNiSe.git*",".{0,1000}\/DeNiSe\.git.{0,1000}","offensive_tool_keyword","DeNiSe","DeNiSe is a proof of concept for tunneling TCP over DNS in Python","T1071.004 - T1048.003","TA0011 - TA0010 - TA0001","N/A","N/A","C2","https://github.com/mdornseif/DeNiSe","1","1","N/A","N/A","10","10","28","13","2021-12-17T18:03:33Z","2010-01-15T07:43:14Z","6538" +"*/Dent/*/Loader/Loader.go*",".{0,1000}\/Dent\/.{0,1000}\/Loader\/Loader\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/optiv/Dent","1","1","N/A","N/A","10","10","296","46","2023-08-18T17:28:54Z","2021-05-03T14:00:29Z","6539" +"*/Dent/Dent.go*",".{0,1000}\/Dent\/Dent\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/optiv/Dent","1","1","N/A","N/A","10","10","296","46","2023-08-18T17:28:54Z","2021-05-03T14:00:29Z","6540" +"*/Dent/Loader*",".{0,1000}\/Dent\/Loader.{0,1000}","offensive_tool_keyword","cobaltstrike","A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/optiv/Dent","1","1","N/A","N/A","10","10","296","46","2023-08-18T17:28:54Z","2021-05-03T14:00:29Z","6541" +"*/DenyOutboundFirewall.ahk*",".{0,1000}\/DenyOutboundFirewall\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","6542" +"*/DeployPrinterNightmare.exe*",".{0,1000}\/DeployPrinterNightmare\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","6543" +"*/DeployPrinterNightmare.exe*",".{0,1000}\/DeployPrinterNightmare\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","6544" +"*/DesckVB Rat.exe*",".{0,1000}\/DesckVB\sRat\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6545" +"*/describeTicket.py*",".{0,1000}\/describeTicket\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","6546" +"*/DesertFox/archive/*.zip*",".{0,1000}\/DesertFox\/archive\/.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","cobaltstrike","Implement load Cobalt Strike & Metasploit&Sliver shellcode with golang","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/zha0gongz1/DesertFox","1","1","N/A","N/A","10","10","125","26","2023-02-02T07:02:12Z","2021-02-04T09:04:13Z","6547" +"*/DesktopShell.exe*",".{0,1000}\/DesktopShell\.exe.{0,1000}","offensive_tool_keyword","PrivFu","SeTcbPrivilege exploitation","T1134 - T1134.001 - T1078 - T1059 - T1075","TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu/","1","1","N/A","PrivFu\PowerOfTcb","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","6548" +"*/detail/kali-linux/*",".{0,1000}\/detail\/kali\-linux\/.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","6549" +"*/detect_antivirus/*.js*",".{0,1000}\/detect_antivirus\/.{0,1000}\.js.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","6550" +"*/detect_antivirus/*.rb*",".{0,1000}\/detect_antivirus\/.{0,1000}\.rb.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","6551" +"*/detect-hooks.c*",".{0,1000}\/detect\-hooks\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Proof of concept Beacon Object File (BOF) that attempts to detect userland hooks in place by AV/EDR","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/anthemtotheego/Detect-Hooks","1","1","N/A","N/A","10","10","158","30","2021-07-22T20:13:16Z","2021-07-22T18:58:23Z","6552" +"*/detect-hooks.cna*",".{0,1000}\/detect\-hooks\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Proof of concept Beacon Object File (BOF) that attempts to detect userland hooks in place by AV/EDR","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/anthemtotheego/Detect-Hooks","1","1","N/A","N/A","10","10","158","30","2021-07-22T20:13:16Z","2021-07-22T18:58:23Z","6553" +"*/detect-hooks.h*",".{0,1000}\/detect\-hooks\.h.{0,1000}","offensive_tool_keyword","cobaltstrike","Proof of concept Beacon Object File (BOF) that attempts to detect userland hooks in place by AV/EDR","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/anthemtotheego/Detect-Hooks","1","1","N/A","N/A","10","10","158","30","2021-07-22T20:13:16Z","2021-07-22T18:58:23Z","6554" +"*/Detect-Hooks/*",".{0,1000}\/Detect\-Hooks\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Proof of concept Beacon Object File (BOF) that attempts to detect userland hooks in place by AV/EDR","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/anthemtotheego/Detect-Hooks","1","1","N/A","N/A","10","10","158","30","2021-07-22T20:13:16Z","2021-07-22T18:58:23Z","6555" +"*/Devils-Rat *.exe*",".{0,1000}\/Devils\-Rat\s.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6556" +"*/Devils-Rat 8.0.exe*",".{0,1000}\/Devils\-Rat\s8\.0\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6557" +"*/devilzShell.asp*",".{0,1000}\/devilzShell\.asp.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","6558" +"*/devilzShell.cgi*",".{0,1000}\/devilzShell\.cgi.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","6559" +"*/devilzShell.jsp*",".{0,1000}\/devilzShell\.jsp.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","6560" +"*/devilzShell.php*",".{0,1000}\/devilzShell\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","6561" +"*/DFSCoerce.exe*",".{0,1000}\/DFSCoerce\.exe.{0,1000}","offensive_tool_keyword","KrbRelay-SMBServer","acts as an SMB server (instead of DCOM) to relay Kerberos AP-REQ to CIFS or HTTP","T1557 - T1021 - T1205 - T1071","TA0006 - TA0008 - TA0010","N/A","Black Basta","Lateral Movement","https://github.com/decoder-it/KrbRelay-SMBServer","1","1","N/A","N/A","9","3","215","26","2024-10-08T14:55:59Z","2024-10-05T12:28:55Z","6562" +"*/DFSCoerce.git*",".{0,1000}\/DFSCoerce\.git.{0,1000}","offensive_tool_keyword","DFSCoerce","PoC for MS-DFSNM coerce authentication using NetrDfsRemoveStdRoot and NetrDfsAddStdRoot?","T1550.001 - T1078.003 - T1046","TA0002 - TA0007 - TA0040","N/A","Dispossessor","Exploitation tool","https://github.com/Wh04m1001/DFSCoerce","1","1","N/A","N/A","10","8","769","98","2022-09-09T17:45:41Z","2022-06-18T12:38:37Z","6563" +"*/dfscoerce.py*",".{0,1000}\/dfscoerce\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","6564" +"*/DGPOEdit.zip*",".{0,1000}\/DGPOEdit\.zip.{0,1000}","offensive_tool_keyword","DRSAT","Disconnected RSAT is a launcher for the official Group Policy Manager - Certificate Authority and Certificate Templates snap-in to bypass the domain joined requirement that is needed when using the official MMC snap-in. The tool works by injecting a C# library into MMC that will hook the various API calls to trick MMC into believing that the logged on user is a domain user. attackers can abuse Disconnected RSAT to interact with Active Directory (AD) environments from non-domain-joined machines","T1559.001 - T1112 - T1078 - T1134.002 - T1055.001","TA0002 - TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/CCob/DRSAT","1","1","N/A","N/A","6","3","233","25","2024-12-27T11:44:18Z","2024-09-04T16:35:02Z","6565" +"*/dhcp-discover.nse*",".{0,1000}\/dhcp\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6566" +"*/Dialogs/Payload.hpp*",".{0,1000}\/Dialogs\/Payload\.hpp.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","6568" +"*/Diamond RAT Cracked.exe*",".{0,1000}\/Diamond\sRAT\sCracked\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6569" +"*/Diamorphine.git*",".{0,1000}\/Diamorphine\.git.{0,1000}","offensive_tool_keyword","Diamorphine","LKM rootkit for Linux Kernels","T1547.006 - T1548.002 - T1562.001 - T1027","TA0003 - TA0004 - TA0005 - TA0006 - TA0007","N/A","N/A","Persistence","https://github.com/m0nad/Diamorphine","1","1","#linux","N/A","10","10","1986","451","2023-09-20T10:56:06Z","2013-11-06T22:38:47Z","6570" +"*/dicassassin.7z*",".{0,1000}\/dicassassin\.7z.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","6571" +"*/dicom-brute.nse*",".{0,1000}\/dicom\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6572" +"*/dicom-ping.nse*",".{0,1000}\/dicom\-ping\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6573" +"*/dict-info.nse*",".{0,1000}\/dict\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6574" +"*/dicts/ftp_default.txt*",".{0,1000}\/dicts\/ftp_default\.txt.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoCs - 23 kinds of application password crack - 7000+Web fingerprints - 146 protocols and 90000+ rules Port scanning - Fuzz - HW - awesome BugBounty","T1046 - T1210.001 - T1059 - T1082 - T1110","TA0007 - TA0001 - TA0009 - TA0002 - TA0004 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","6575" +"*/DigitalOceanProxyTab.java*",".{0,1000}\/DigitalOceanProxyTab\.java.{0,1000}","offensive_tool_keyword","burpsuite","A BurpSuite extension to deploy an OpenVPN config file to DigitalOcean and set up a SOCKS proxy to route traffic through it","T1592 - T1021 - T1573 - T1090 - T1071","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/honoki/burp-digitalocean-openvpn-socks","1","1","N/A","N/A","10","1","49","9","2024-02-26T13:59:20Z","2024-02-26T13:59:17Z","6576" +"*/DInjector.git*",".{0,1000}\/DInjector\.git.{0,1000}","offensive_tool_keyword","Dinjector","Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL","T1055 - T1055.012 - T1055.001 - T1027.002","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Metro-Holografix/DInjector","1","1","N/A","private github repo","8","","N/A","","","","6577" +"*/DInvoke/*",".{0,1000}\/DInvoke\/.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","6578" +"*/DInvokeResolver/*",".{0,1000}\/DInvokeResolver\/.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","6579" +"*/dir_brute.txt*",".{0,1000}\/dir_brute\.txt.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","6580" +"*/dirbuster*",".{0,1000}\/dirbuster.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6581" +"*/dirbuster.py*",".{0,1000}\/dirbuster\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","6582" +"*/dirbuster/*",".{0,1000}\/dirbuster\/.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6583" +"*/DirCreate2System.git*",".{0,1000}\/DirCreate2System\.git.{0,1000}","offensive_tool_keyword","DirCreate2System","Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting","T1068 - T1059.001 - T1070.004","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/binderlabs/DirCreate2System","1","1","N/A","N/A","8","4","357","38","2022-12-19T17:00:43Z","2022-12-15T03:49:55Z","6584" +"*/DirCreate2System.git*",".{0,1000}\/DirCreate2System\.git.{0,1000}","offensive_tool_keyword","DirCreate2System","Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting","T1068 - T1059.001 - T1070.004","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/binderlabs/DirCreate2System","1","1","N/A","N/A","8","4","357","38","2022-12-19T17:00:43Z","2022-12-15T03:49:55Z","6585" +"*/dirdevil.git*",".{0,1000}\/dirdevil\.git.{0,1000}","offensive_tool_keyword","dirdevil","PowerShell to hide data in directory structures","T1027 - T1083 - T1158 - T1059.001 - T1036","TA0005","N/A","N/A","Defense Evasion","https://github.com/nyxgeek/dirdevil","1","1","N/A","N/A","6","1","44","6","2024-07-11T16:09:02Z","2024-06-25T07:26:30Z","6586" +"*/dirdevil.ps1*",".{0,1000}\/dirdevil\.ps1.{0,1000}","offensive_tool_keyword","dirdevil","PowerShell to hide data in directory structures","T1027 - T1083 - T1158 - T1059.001 - T1036","TA0005","N/A","N/A","Defense Evasion","https://github.com/nyxgeek/dirdevil","1","1","N/A","N/A","6","1","44","6","2024-07-11T16:09:02Z","2024-06-25T07:26:30Z","6587" +"*/dirdevil_decoder_mini.ps1*",".{0,1000}\/dirdevil_decoder_mini\.ps1.{0,1000}","offensive_tool_keyword","dirdevil","PowerShell to hide data in directory structures","T1027 - T1083 - T1158 - T1059.001 - T1036","TA0005","N/A","N/A","Defense Evasion","https://github.com/nyxgeek/dirdevil","1","1","N/A","N/A","6","1","44","6","2024-07-11T16:09:02Z","2024-06-25T07:26:30Z","6588" +"*/dirdevil_decoder_only.ps1*",".{0,1000}\/dirdevil_decoder_only\.ps1.{0,1000}","offensive_tool_keyword","dirdevil","PowerShell to hide data in directory structures","T1027 - T1083 - T1158 - T1059.001 - T1036","TA0005","N/A","N/A","Defense Evasion","https://github.com/nyxgeek/dirdevil","1","1","N/A","N/A","6","1","44","6","2024-07-11T16:09:02Z","2024-06-25T07:26:30Z","6589" +"*/direct_syscall_amd64.s*",".{0,1000}\/direct_syscall_amd64\.s.{0,1000}","offensive_tool_keyword","acheron","indirect syscalls for AV/EDR evasion in Go assembly","T1055.012 - T1059.001 - T1059.003","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/f1zm0/acheron","1","1","N/A","N/A","N/A","4","326","39","2023-06-13T19:20:33Z","2023-04-07T10:40:33Z","6590" +"*/dirsearch.py*",".{0,1000}\/dirsearch\.py.{0,1000}","offensive_tool_keyword","BruteSploit","BruteSploit is a collection of method for automated Generate. Bruteforce and Manipulation wordlist with interactive shell. That can be used during a penetration test to enumerate and maybe can be used in CTF for manipulation.combine.transform and permutation some words or file text","T1110","N/A","N/A","N/A","Exploitation tool","https://github.com/screetsec/BruteSploit","1","1","N/A","N/A","N/A","8","741","263","2020-04-05T00:29:26Z","2017-05-31T17:00:51Z","6591" +"*/DirtyCLR.git*",".{0,1000}\/DirtyCLR\.git.{0,1000}","offensive_tool_keyword","DirtyCLR","An App Domain Manager Injection DLL PoC","T1055.001 - T1546.016 - T1055.013","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/ipSlav/DirtyCLR","1","1","N/A","N/A","7","2","170","19","2023-12-14T21:22:12Z","2023-12-11T11:29:36Z","6592" +"*/Dirty-Pipe.sh*",".{0,1000}\/Dirty\-Pipe\.sh.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/imfiver/CVE-2022-0847","1","1","N/A","N/A","N/A","3","280","78","2023-02-02T02:17:30Z","2022-03-07T18:36:50Z","6593" +"*/Dirty-Pipe.sh*",".{0,1000}\/Dirty\-Pipe\.sh.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/puckiestyle/CVE-2022-0847","1","1","N/A","N/A","N/A","1","2","1","2022-03-10T08:10:40Z","2022-03-08T14:46:21Z","6594" +"*/Dirty-Pipe/main/exploit-static*",".{0,1000}\/Dirty\-Pipe\/main\/exploit\-static.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","t1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/carlosevieira/Dirty-Pipe","1","1","N/A","N/A","N/A","1","9","6","2022-03-07T21:01:15Z","2022-03-07T20:57:34Z","6595" +"*/dirtypipez.c*",".{0,1000}\/dirtypipez\.c.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","6596" +"*/dirtypipez.c*",".{0,1000}\/dirtypipez\.c.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1533","TA0003","N/A","N/A","Exploitation tool","https://github.com/febinrev/dirtypipez-exploit","1","1","N/A","N/A","N/A","1","51","22","2022-03-08T11:52:22Z","2022-03-08T11:49:40Z","6597" +"*/dirtypipez.c*",".{0,1000}\/dirtypipez\.c.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/puckiestyle/CVE-2022-0847","1","1","N/A","N/A","N/A","1","2","1","2022-03-10T08:10:40Z","2022-03-08T14:46:21Z","6598" +"*/dirtypipez.c*",".{0,1000}\/dirtypipez\.c.{0,1000}","offensive_tool_keyword","POC","exploit the Linux Dirty Pipe vulnerability","T1068 - T1078.003 - T1071.004 - T1072 - T1105","TA0004 - TA0006?","N/A","N/A","Privilege Escalation","https://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits","1","1","#linux","N/A","10","6","595","148","2023-05-20T05:55:45Z","2022-03-12T20:57:24Z","6599" +"*/dirtypipez-exploit/*",".{0,1000}\/dirtypipez\-exploit\/.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1533","TA0003","N/A","N/A","Exploitation tool","https://github.com/febinrev/dirtypipez-exploit","1","1","N/A","N/A","N/A","1","51","22","2022-03-08T11:52:22Z","2022-03-08T11:49:40Z","6600" +"*/Dirty-Vanity.git*",".{0,1000}\/Dirty\-Vanity\.git.{0,1000}","offensive_tool_keyword","Dirty-Vanity","injection technique abusing windows fork API to evade EDRs","T1055 - T1562 - T1070 - T1027","TA0005 - TA0006","N/A","N/A","Defense Evasion","https://github.com/deepinstinct/Dirty-Vanity","1","1","N/A","N/A","10","7","633","86","2022-12-23T10:54:10Z","2022-11-24T10:54:00Z","6601" +"*/dis_defender.exe*",".{0,1000}\/dis_defender\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6602" +"*/Disable_defender.py*",".{0,1000}\/Disable_defender\.py.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","6603" +"*/disable-defender.exe*",".{0,1000}\/disable\-defender\.exe.{0,1000}","offensive_tool_keyword","defender-control","An open-source windows defender manager. Now you can disable windows defender permanently","T1562.001 - T1562.004 - T1089","TA0005 - TA0002","N/A","LockBit","Defense Evasion","https://github.com/pgkt04/defender-control","1","1","N/A","N/A","10","10","1614","128","2023-09-09T14:57:56Z","2021-05-15T10:09:17Z","6604" +"*/Disable-TamperProtection.git*",".{0,1000}\/Disable\-TamperProtection\.git.{0,1000}","offensive_tool_keyword","Disable-TamperProtection","disable TamperProtection and other Defender / MDE components","T1562.001 - T1562.007","TA0005","N/A","N/A","Defense Evasion","https://github.com/AlteredSecurity/Disable-TamperProtection","1","1","N/A","N/A","10","3","208","35","2024-06-06T14:44:59Z","2024-06-05T12:48:56Z","6605" +"*/DisableWD.dll,*",".{0,1000}\/DisableWD\.dll,.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","6606" +"*/Discord rat.exe*",".{0,1000}\/Discord\srat\.exe.{0,1000}","offensive_tool_keyword","Discord-RAT-2.0","Discord Remote Administration Tool fully written in c#, stub size of ~75kb with over 40 post exploitations modules","T1059.005 - T1105 - T1569.002 - T1027.001","TA0011 - TA0003 - TA0006 - TA0009 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/moom825/Discord-RAT-2.0","1","1","N/A","N/A","10","10","512","115","2023-11-03T01:15:38Z","2022-07-15T20:09:56Z","6607" +"*/DiscordBot.py*",".{0,1000}\/DiscordBot\.py.{0,1000}","offensive_tool_keyword","mail-in-the-middle","This script sits in the middle between a legitimate sender of an email and the legitimate recipient of that email. This means that we (the attackers) are receiving sensitive information not originally destined to us","T1557 - T1598.002 - T1566.002 - T1192 - T1204.002 - T1539 - T1593","TA0001 - TA0006 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/sensepost/mail-in-the-middle","1","1","N/A","N/A","8","2","108","9","2024-11-07T10:41:00Z","2024-02-21T07:25:37Z","6608" +"*/discord-c2.git*",".{0,1000}\/discord\-c2\.git.{0,1000}","offensive_tool_keyword","discord-c2","C2 communication with discord","T1102.003 - T1071.001 - T1027.010 - T1105 - T1090.002","TA0011 - TA0010","N/A","N/A","C2","https://github.com/bmdyy/discord-c2","1","1","N/A","N/A","10","10","60","6","2022-12-29T03:05:05Z","2022-12-08T19:10:23Z","6609" +"*/Discord-RAT-2.0*",".{0,1000}\/Discord\-RAT\-2\.0.{0,1000}","offensive_tool_keyword","Discord-RAT-2.0","Discord Remote Administration Tool fully written in c#, stub size of ~75kb with over 40 post exploitations modules","T1059.005 - T1105 - T1569.002 - T1027.001","TA0011 - TA0003 - TA0006 - TA0009 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/moom825/Discord-RAT-2.0","1","1","N/A","N/A","10","10","512","115","2023-11-03T01:15:38Z","2022-07-15T20:09:56Z","6610" +"*/Discord-RAT-2.0.git*",".{0,1000}\/Discord\-RAT\-2\.0\.git.{0,1000}","offensive_tool_keyword","Discord-RAT-2.0","Discord Remote Administration Tool fully written in c#, stub size of ~75kb with over 40 post exploitations modules","T1059.005 - T1105 - T1569.002 - T1027.001","TA0011 - TA0003 - TA0006 - TA0009 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/moom825/Discord-RAT-2.0","1","1","N/A","N/A","10","10","512","115","2023-11-03T01:15:38Z","2022-07-15T20:09:56Z","6611" +"*/disctopia.py*",".{0,1000}\/disctopia\.py.{0,1000}","offensive_tool_keyword","disctopia-c2","Windows Remote Administration Tool that uses Discord Telegram and GitHub as C2s","T1105 - T1102","TA0003 - TA0008 - TA0002","N/A","N/A","C2","https://github.com/3ct0s/disctopia-c2","1","1","N/A","N/A","10","10","609","139","2024-07-18T10:16:19Z","2022-01-02T22:03:10Z","6612" +"*/disctopia-c2*",".{0,1000}\/disctopia\-c2.{0,1000}","offensive_tool_keyword","disctopia-c2","Windows Remote Administration Tool that uses Discord Telegram and GitHub as C2s","T1105 - T1102","TA0003 - TA0008 - TA0002","N/A","N/A","C2","https://github.com/3ct0s/disctopia-c2","1","1","N/A","N/A","10","10","609","139","2024-07-18T10:16:19Z","2022-01-02T22:03:10Z","6613" +"*/DiskCryptor.git*",".{0,1000}\/DiskCryptor\.git.{0,1000}","offensive_tool_keyword","DiskCryptor","DiskCryptor is an open source encryption solution that offers encryption of all disk partitions including system partitions","T1486 ","TA0040","N/A","N/A","Ransomware","https://github.com/DavidXanatos/DiskCryptor","1","1","N/A","N/A","10","5","499","108","2024-07-03T10:05:01Z","2019-04-20T14:51:18Z","6614" +"*/dist/fw_walk.*",".{0,1000}\/dist\/fw_walk\..{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to interact with COM objects associated with the Windows software firewall.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/Firewall_Walker_BOF","1","1","N/A","N/A","10","10","103","15","2021-10-10T03:28:27Z","2021-10-09T05:17:10Z","6615" +"*/distcc-cve2004-2687.nse*",".{0,1000}\/distcc\-cve2004\-2687\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6617" +"*/DitExplorer.git*",".{0,1000}\/DitExplorer\.git.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","1","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","6619" +"*/DitExplorer/releases/download/*",".{0,1000}\/DitExplorer\/releases\/download\/.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","1","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","6620" +"*/DitExplorer/releases/tag/v*",".{0,1000}\/DitExplorer\/releases\/tag\/v.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","1","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","6621" +"*/DitExplorer/tarball/*",".{0,1000}\/DitExplorer\/tarball\/.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","1","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","6622" +"*/DitExplorer/zipball/*",".{0,1000}\/DitExplorer\/zipball\/.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","1","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","6623" +"*/Dive Shell 1.0 - Emperor Hacking Team.php*",".{0,1000}\/Dive\sShell\s1\.0\s\-\sEmperor\sHacking\sTeam\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","6624" +"*/DKMC.git*",".{0,1000}\/DKMC\.git.{0,1000}","offensive_tool_keyword","DKMC","Malicious payload evasion tool","T1027 - T1055.012","TA0005 - TA0040","N/A","Molerats","Defense Evasion","https://github.com/Mr-Un1k0d3r/DKMC","1","1","N/A","N/A","10","10","1392","290","2020-07-20T03:36:56Z","2016-12-05T03:44:07Z","6625" +"*/dkmc.py*",".{0,1000}\/dkmc\.py.{0,1000}","offensive_tool_keyword","DKMC","Malicious payload evasion tool","T1027 - T1055.012","TA0005 - TA0040","N/A","Molerats","Defense Evasion","https://github.com/Mr-Un1k0d3r/DKMC","1","1","N/A","N/A","10","10","1392","290","2020-07-20T03:36:56Z","2016-12-05T03:44:07Z","6626" +"*/DLHell.git*",".{0,1000}\/DLHell\.git.{0,1000}","offensive_tool_keyword","DLHell","Local & remote Windows DLL Proxying","T1574.002 - T1055","TA0005 - TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/synacktiv/DLHell","1","1","N/A","N/A","9","2","163","24","2024-06-17T16:20:10Z","2024-04-17T13:00:12Z","6627" +"*/DLHell.py*",".{0,1000}\/DLHell\.py.{0,1000}","offensive_tool_keyword","DLHell","Local & remote Windows DLL Proxying","T1574.002 - T1055","TA0005 - TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/synacktiv/DLHell","1","1","N/A","N/A","9","2","163","24","2024-06-17T16:20:10Z","2024-04-17T13:00:12Z","6628" +"*/dll/inject/*",".{0,1000}\/dll\/inject\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6629" +"*/dll_inject.exe*",".{0,1000}\/dll_inject\.exe.{0,1000}","offensive_tool_keyword","Rust-for-Malware-Development","malware development using Rust","T1055.001 - T1027 - T1204 - T1518 - T1056 - T1021 - T1587/001","TA0005 - TA0003 - TA0007 - TA0009 - TA0004 - TA0008 - TA0042","N/A","N/A","Exploitation tool","https://github.com/Whitecat18/Rust-for-Malware-Development","1","1","N/A","N/A","8","10","2123","53","2025-04-22T18:09:57Z","2024-02-12T16:55:06Z","6630" +"*/DLLEnc.ps1*",".{0,1000}\/DLLEnc\.ps1.{0,1000}","offensive_tool_keyword","Powerpick","allowing the execution of Powershell functionality without the use of Powershell.exe","T1059.001 - T1059.003 - T1086 - T1027.001","TA0005 - TA0002","N/A","Black Basta - Dispossessor","Defense Evasion","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","6631" +"*/dllexploit.cpp*",".{0,1000}\/dllexploit\.cpp.{0,1000}","offensive_tool_keyword","RunAsWinTcb","RunAsWinTcb uses an userland exploit to run a DLL with a protection level of WinTcb-Light.","T1073.002 - T1055.001 - T1055.002","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/tastypepperoni/RunAsWinTcb","1","1","N/A","N/A","10","2","132","17","2022-08-02T16:35:50Z","2022-07-29T16:36:06Z","6632" +"*/dllexploit.exe*",".{0,1000}\/dllexploit\.exe.{0,1000}","offensive_tool_keyword","RunAsWinTcb","RunAsWinTcb uses an userland exploit to run a DLL with a protection level of WinTcb-Light.","T1073.002 - T1055.001 - T1055.002","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/tastypepperoni/RunAsWinTcb","1","1","N/A","N/A","10","2","132","17","2022-08-02T16:35:50Z","2022-07-29T16:36:06Z","6633" +"*/DllExport.bat*",".{0,1000}\/DllExport\.bat.{0,1000}","offensive_tool_keyword","C2 related tools","PowerShell rebuilt in C# for Red Teaming purposes","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","6634" +"*/DLL-Hijack*",".{0,1000}\/DLL\-Hijack.{0,1000}","offensive_tool_keyword","cobaltstrike","DLL Hijack Search Order Enumeration BOF","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/DLL-Hijack-Search-Order-BOF","1","1","N/A","N/A","10","10","147","21","2021-11-03T17:39:32Z","2021-11-02T03:47:31Z","6635" +"*/dll-hijack-by-proxying.git*",".{0,1000}\/dll\-hijack\-by\-proxying\.git.{0,1000}","offensive_tool_keyword","dll-hijack-by-proxying","Exploiting DLL Hijacking by DLL Proxying Super Easily","T1174 - T1574.007","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tothi/dll-hijack-by-proxying","1","1","N/A","N/A","7","5","498","103","2023-07-09T22:11:34Z","2020-07-08T18:11:17Z","6636" +"*/DLLHijackTest.git*",".{0,1000}\/DLLHijackTest\.git.{0,1000}","offensive_tool_keyword","DLLHijackTest","DLL and PowerShell script to assist with finding DLL hijacks","T1574.002 - T1055.001 - T1059.001 - T1036.005","TA0005 - TA0004 - TA0002","N/A","N/A","Defense Evasion","https://github.com/slyd0g/DLLHijackTest","1","1","N/A","N/A","9","4","335","62","2020-10-01T22:37:36Z","2020-06-20T04:33:01Z","6637" +"*/DLLHound.git*",".{0,1000}\/DLLHound\.git.{0,1000}","offensive_tool_keyword","DLLHound","Find potential DLL Sideloads on your windows computer","T1574.001 - T1574.002","TA0004 - TA0007","N/A","N/A","Discovery","https://github.com/ajm4n/DLLHound","1","1","N/A","N/A","7","3","201","22","2025-01-12T02:28:22Z","2024-12-20T02:26:16Z","6638" +"*/DLLHound.ps1*",".{0,1000}\/DLLHound\.ps1.{0,1000}","offensive_tool_keyword","DLLHound","Find potential DLL Sideloads on your windows computer","T1574.001 - T1574.002","TA0004 - TA0007","N/A","N/A","Discovery","https://github.com/ajm4n/DLLHound","1","1","N/A","N/A","7","3","201","22","2025-01-12T02:28:22Z","2024-12-20T02:26:16Z","6639" +"*/dllinject.py*",".{0,1000}\/dllinject\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","6640" +"*/dllinjection_rs.exe*",".{0,1000}\/dllinjection_rs\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","6641" +"*/dll-installer.ps1*",".{0,1000}\/dll\-installer\.ps1.{0,1000}","offensive_tool_keyword","Powershell-Scripts-for-Hackers-and-Pentesters","","T1059.001 - T1119 - T1027 - T1016 - T1056.001","TA0002 - TA0009 - TA0005 - TA0007 - TA0010","N/A","N/A","Collection","https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters","1","1","N/A","N/A","10","5","415","49","2025-02-23T09:05:44Z","2023-02-27T14:27:32Z","6642" +"*/DllNotificationInjection.git*",".{0,1000}\/DllNotificationInjection\.git.{0,1000}","offensive_tool_keyword","DllNotificationInjection","A POC of a new threadless process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote processes.","T1055.011 - T1055.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/ShorSec/DllNotificationInjection","1","1","N/A","N/A","10","1","23","3","2023-08-23T13:50:27Z","2023-12-01T12:47:43Z","6643" +"*/DllProxy.git*",".{0,1000}\/DllProxy\.git.{0,1000}","offensive_tool_keyword","DllProxy","Proxy your dll exports and add some spicy content at the same time","T1574.002 - T1036.005","TA0005 - TA0004","N/A","N/A","Exploitation tool","https://github.com/Iansus/DllProxy/","1","1","N/A","N/A","N/A","1","17","5","2023-06-28T14:19:36Z","2021-05-04T19:38:42Z","6644" +"*/dllproxy.nim*",".{0,1000}\/dllproxy\.nim.{0,1000}","offensive_tool_keyword","NimDllSideload","DLL sideloading/proxying","T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/byt3bl33d3r/NimDllSideload","1","1","N/A","N/A","9","2","167","17","2022-12-04T21:52:49Z","2022-12-03T03:25:57Z","6645" +"*/DLL-Spoofer.git*",".{0,1000}\/DLL\-Spoofer\.git.{0,1000}","offensive_tool_keyword","DLL-Spoofer","POC for a DLL spoofer to determine DLL Hijacking","T1574.002","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/MitchHS/DLL-Spoofer","1","1","N/A","N/A","9","1","60","7","2025-03-04T14:14:15Z","2023-10-18T14:34:38Z","6646" +"*/dns_grabber.*",".{0,1000}\/dns_grabber\..{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","6647" +"*/dns_spoof*",".{0,1000}\/dns_spoof.{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","6648" +"*/dns2tcp.git*",".{0,1000}\/dns2tcp\.git.{0,1000}","offensive_tool_keyword","dns2tcp","Dns2tcp is a tool for relaying TCP connections over DNS","T1071.004 - T1048.003","TA0011 - TA0001","N/A","N/A","C2","https://github.com/alex-sector/dns2tcp","1","1","N/A","N/A","10","10","191","60","2024-06-08T09:40:52Z","2017-11-23T11:19:53Z","6649" +"*/dns-black-cat.git*",".{0,1000}\/dns\-black\-cat\.git.{0,1000}","offensive_tool_keyword","dns-black-cat","Multi platform toolkit for an interactive DNS shell commands exfiltration - by using DNS-Cat you will be able to execute system commands in shell mode over DNS protocol","T1140 - T1048.003 - T1071.004","TA0011 - TA0040 - TA0001","N/A","N/A","C2","https://github.com/lawrenceamer/dns-black-cat","1","1","N/A","N/A","10","10","114","20","2022-09-15T18:07:05Z","2021-02-13T11:31:22Z","6653" +"*/dns-blacklist.nse*",".{0,1000}\/dns\-blacklist\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6654" +"*/dns-brute.nse*",".{0,1000}\/dns\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6655" +"*/dns-cache-snoop.nse*",".{0,1000}\/dns\-cache\-snoop\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6656" +"*/dnscan.git*",".{0,1000}\/dnscan\.git.{0,1000}","offensive_tool_keyword","dnscan","dnscan is a python wordlist-based DNS subdomain scanner.","T1595 - T1595.002 - T1018 - T1046","TA0007 - TA0043","N/A","N/A","Reconnaissance","https://github.com/rbsec/dnscan","1","1","N/A","N/A","6","10","1193","410","2024-12-17T15:29:50Z","2013-03-13T10:42:07Z","6657" +"*/dnscan.py*",".{0,1000}\/dnscan\.py.{0,1000}","offensive_tool_keyword","dnscan","dnscan is a python wordlist-based DNS subdomain scanner.","T1595 - T1595.002 - T1018 - T1046","TA0007 - TA0043","N/A","N/A","Reconnaissance","https://github.com/rbsec/dnscan","1","1","#linux","N/A","6","10","1193","410","2024-12-17T15:29:50Z","2013-03-13T10:42:07Z","6658" +"*/dnscat.c*",".{0,1000}\/dnscat\.c.{0,1000}","offensive_tool_keyword","dnscat","This tool is designed to create an encrypted command-and-control (C&C) channel over the DNS protocol","T1071.004 - T1102 - T1071.001","TA0002 - TA0003 - TA0008","N/A","EMBER BEAR","C2","https://github.com/iagox86/dnscat2","1","1","#linux","N/A","10","10","3566","618","2024-03-14T11:17:49Z","2013-01-04T23:15:55Z","6659" +"*/dnscat2.git*",".{0,1000}\/dnscat2\.git.{0,1000}","offensive_tool_keyword","dnscat","This tool is designed to create an encrypted command-and-control (C&C) channel over the DNS protocol","T1071.004 - T1102 - T1071.001","TA0002 - TA0003 - TA0008","N/A","EMBER BEAR","C2","https://github.com/iagox86/dnscat2","1","1","N/A","N/A","10","10","3566","618","2024-03-14T11:17:49Z","2013-01-04T23:15:55Z","6661" +"*/dns-check-zone.nse*",".{0,1000}\/dns\-check\-zone\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6662" +"*/dnschef.exe*",".{0,1000}\/dnschef\.exe.{0,1000}","offensive_tool_keyword","dnschef-ng","DNSChef is a highly configurable DNS proxy for Penetration Testers and Malware Analysts. A DNS proxy (aka ""Fake DNS"") is a tool used for application network traffic analysis among other uses. For example - a DNS proxy can be used to fake requests for ""badguy.com"" to point to a local machine for termination or interception instead of a real host somewhere on the Internet.","T1568 - T1583 - T1071","TA0001 - TA0042 - TA0005","N/A","N/A","Sniffing & Spoofing","https://github.com/byt3bl33d3r/dnschef-ng","1","1","N/A","N/A","8","2","153","14","2023-11-26T06:57:04Z","2021-12-24T21:07:29Z","6663" +"*/dnschef.log*",".{0,1000}\/dnschef\.log.{0,1000}","offensive_tool_keyword","dnschef-ng","DNSChef is a highly configurable DNS proxy for Penetration Testers and Malware Analysts. A DNS proxy (aka ""Fake DNS"") is a tool used for application network traffic analysis among other uses. For example - a DNS proxy can be used to fake requests for ""badguy.com"" to point to a local machine for termination or interception instead of a real host somewhere on the Internet.","T1568 - T1583 - T1071","TA0001 - TA0042 - TA0005","N/A","N/A","Sniffing & Spoofing","https://github.com/byt3bl33d3r/dnschef-ng","1","1","#logfile #linux","N/A","8","2","153","14","2023-11-26T06:57:04Z","2021-12-24T21:07:29Z","6665" +"*/dnschef.py*",".{0,1000}\/dnschef\.py.{0,1000}","offensive_tool_keyword","dnschef-ng","DNSChef is a highly configurable DNS proxy for Penetration Testers and Malware Analysts. A DNS proxy (aka ""Fake DNS"") is a tool used for application network traffic analysis among other uses. For example - a DNS proxy can be used to fake requests for ""badguy.com"" to point to a local machine for termination or interception instead of a real host somewhere on the Internet.","T1568 - T1583 - T1071","TA0001 - TA0042 - TA0005","N/A","N/A","Sniffing & Spoofing","https://github.com/byt3bl33d3r/dnschef-ng","1","1","N/A","N/A","8","2","153","14","2023-11-26T06:57:04Z","2021-12-24T21:07:29Z","6666" +"*/dnschef-ng.git*",".{0,1000}\/dnschef\-ng\.git.{0,1000}","offensive_tool_keyword","dnschef-ng","DNSChef is a highly configurable DNS proxy for Penetration Testers and Malware Analysts. A DNS proxy (aka ""Fake DNS"") is a tool used for application network traffic analysis among other uses. For example - a DNS proxy can be used to fake requests for ""badguy.com"" to point to a local machine for termination or interception instead of a real host somewhere on the Internet.","T1568 - T1583 - T1071","TA0001 - TA0042 - TA0005","N/A","N/A","Sniffing & Spoofing","https://github.com/byt3bl33d3r/dnschef-ng","1","1","N/A","N/A","8","2","153","14","2023-11-26T06:57:04Z","2021-12-24T21:07:29Z","6667" +"*/dnschef-ng/*",".{0,1000}\/dnschef\-ng\/.{0,1000}","offensive_tool_keyword","dnschef-ng","DNSChef is a highly configurable DNS proxy for Penetration Testers and Malware Analysts. A DNS proxy (aka ""Fake DNS"") is a tool used for application network traffic analysis among other uses. For example - a DNS proxy can be used to fake requests for ""badguy.com"" to point to a local machine for termination or interception instead of a real host somewhere on the Internet.","T1568 - T1583 - T1071","TA0001 - TA0042 - TA0005","N/A","N/A","Sniffing & Spoofing","https://github.com/byt3bl33d3r/dnschef-ng","1","1","N/A","N/A","8","2","153","14","2023-11-26T06:57:04Z","2021-12-24T21:07:29Z","6668" +"*/dns-client-subnet-scan.nse*",".{0,1000}\/dns\-client\-subnet\-scan\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6669" +"*/dnscnc.py*",".{0,1000}\/dnscnc\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","6670" +"*/dnscrypt-proxy.git*",".{0,1000}\/dnscrypt\-proxy\.git.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","6672" +"*/dnsdump.py*",".{0,1000}\/dnsdump\.py.{0,1000}","offensive_tool_keyword","adidnsdump","By default any user in Active Directory can enumerate all DNS records in the Domain or Forest DNS zones. similar to a zone transfer. This tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks.","T1018 - T1087 - T1201 - T1056 - T1039","TA0005 - TA0009","N/A","N/A","Discovery","https://github.com/dirkjanm/adidnsdump","1","1","#linux","N/A","N/A","10","997","118","2025-04-04T09:28:20Z","2019-04-24T17:18:46Z","6673" +"*/DNSExfiltrator*",".{0,1000}\/DNSExfiltrator.{0,1000}","offensive_tool_keyword","DNSExfiltrator","DNSExfiltrator allows for transfering (exfiltrate) a file over a DNS request covert channel. This is basically a data leak testing tool allowing to exfiltrate data over a covert channel.","T1041 - T1048","TA0010 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/Arno0x/DNSExfiltrator","1","1","N/A","N/A","10","9","867","188","2024-04-29T20:20:43Z","2017-12-20T13:58:09Z","6674" +"*/dnsExfiltrator.dll*",".{0,1000}\/dnsExfiltrator\.dll.{0,1000}","offensive_tool_keyword","DNSExfiltrator","DNSExfiltrator allows for transfering (exfiltrate) a file over a DNS request covert channel. This is basically a data leak testing tool allowing to exfiltrate data over a covert channel.","T1041 - T1048","TA0010 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/Arno0x/DNSExfiltrator","1","1","N/A","N/A","10","9","867","188","2024-04-29T20:20:43Z","2017-12-20T13:58:09Z","6675" +"*/DNSExfiltrator.git*",".{0,1000}\/DNSExfiltrator\.git.{0,1000}","offensive_tool_keyword","DNSExfiltrator","DNSExfiltrator allows for transfering (exfiltrate) a file over a DNS request covert channel. This is basically a data leak testing tool allowing to exfiltrate data over a covert channel.","T1041 - T1048","TA0010 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/Arno0x/DNSExfiltrator","1","1","N/A","N/A","10","9","867","188","2024-04-29T20:20:43Z","2017-12-20T13:58:09Z","6676" +"*/dnsexfiltrator.py*",".{0,1000}\/dnsexfiltrator\.py.{0,1000}","offensive_tool_keyword","DNSExfiltrator","DNSExfiltrator allows for transfering (exfiltrate) a file over a DNS request covert channel. This is basically a data leak testing tool allowing to exfiltrate data over a covert channel.","T1041 - T1048","TA0010 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/Arno0x/DNSExfiltrator","1","1","N/A","N/A","10","9","867","188","2024-04-29T20:20:43Z","2017-12-20T13:58:09Z","6677" +"*/dns-fuzz.nse*",".{0,1000}\/dns\-fuzz\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6678" +"*/DNS-Hijacking.git*",".{0,1000}\/DNS\-Hijacking\.git.{0,1000}","offensive_tool_keyword","DNS-Hijacking","DNS Hijacking in UNIX/Linux System by using raw socket and pcap","T1496 - T1040 - T1071.004 - T1090","TA0040 - TA0002 - TA0009","N/A","Sea Turtle","Sniffing & Spoofing","https://github.com/DyeKuu/DNS-Hijacking","1","1","#linux","N/A","9","1","5","2","2020-05-31T23:03:34Z","2020-05-02T08:49:22Z","6679" +"*/dns-ip6-arpa-scan.nse*",".{0,1000}\/dns\-ip6\-arpa\-scan\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6680" +"*/dnskire.git*",".{0,1000}\/dnskire\.git.{0,1000}","offensive_tool_keyword","dnskire","A tool for file infiltration over DNS","T1071.004 - T1071.001 - T1048","TA0010 - TA0005 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/0xtosh/dnskire","1","1","N/A","N/A","7","1","17","0","2023-12-07T21:42:34Z","2022-09-10T17:56:30Z","6681" +"*/dnskire.js*",".{0,1000}\/dnskire\.js.{0,1000}","offensive_tool_keyword","dnskire","A tool for file infiltration over DNS","T1071.004 - T1071.001 - T1048","TA0010 - TA0005 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/0xtosh/dnskire","1","1","N/A","N/A","7","1","17","0","2023-12-07T21:42:34Z","2022-09-10T17:56:30Z","6682" +"*/dns-nsec3-enum.nse*",".{0,1000}\/dns\-nsec3\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6685" +"*/dns-nsec-enum.nse*",".{0,1000}\/dns\-nsec\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6686" +"*/dns-nsid.nse*",".{0,1000}\/dns\-nsid\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6687" +"*/DNS-Persist/*",".{0,1000}\/DNS\-Persist\/.{0,1000}","offensive_tool_keyword","DNS-Persist","DNS-Persist is a post-exploitation agent which uses DNS for command and control.","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/0x09AL/DNS-Persist","1","1","N/A","N/A","10","10","211","65","2017-11-20T08:53:25Z","2017-11-10T15:23:49Z","6688" +"*/dnspot.git*",".{0,1000}\/dnspot\.git.{0,1000}","offensive_tool_keyword","dnspot","End-to-end Encrypted DNS Tunnelling and C2 framework","T1071.004 - T1090.002 - T1573.002","TA0011 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/mosajjal/dnspot","1","1","N/A","N/A","10","10","73","16","2025-02-01T08:13:29Z","2021-09-25T08:49:43Z","6689" +"*/dns-random-srcport.nse*",".{0,1000}\/dns\-random\-srcport\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6690" +"*/dns-random-txid.nse*",".{0,1000}\/dns\-random\-txid\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6691" +"*/dnsrecon.py*",".{0,1000}\/dnsrecon\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","6692" +"*/dnsrecon-subdomain-bruteforce.py*",".{0,1000}\/dnsrecon\-subdomain\-bruteforce\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","6693" +"*/dns-recursion.nse*",".{0,1000}\/dns\-recursion\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6694" +"*/dns-service-discovery.nse*",".{0,1000}\/dns\-service\-discovery\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6695" +"*/dns-srv-enum.nse*",".{0,1000}\/dns\-srv\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6697" +"*/DNSStager.git*",".{0,1000}\/DNSStager\.git.{0,1000}","offensive_tool_keyword","DNSStager","DNSStager is an open-source project based on Python used to hide and transfer your payload using DNS.","T1071.004 - T1568.002 - T1102","TA0002 - TA0005 - TA0009 - TA0010","N/A","N/A","Defense Evasion","https://github.com/mhaskar/DNSStager","1","1","N/A","N/A","10","7","613","133","2023-05-03T12:25:07Z","2021-04-18T21:58:21Z","6698" +"*/dnsstager.py*",".{0,1000}\/dnsstager\.py.{0,1000}","offensive_tool_keyword","DNSStager","DNSStager is an open-source project based on Python used to hide and transfer your payload using DNS.","T1071.004 - T1568.002 - T1102","TA0002 - TA0005 - TA0009 - TA0010","N/A","N/A","Defense Evasion","https://github.com/mhaskar/DNSStager","1","1","N/A","N/A","10","7","613","133","2023-05-03T12:25:07Z","2021-04-18T21:58:21Z","6699" +"*/dnsteal*",".{0,1000}\/dnsteal.{0,1000}","offensive_tool_keyword","dnsteal","This is a fake DNS server that allows you to stealthily extract files from a victim machine through DNS requests.","T1048.003 - T1568.002 - T1573.002","TA0010 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/m57/dnsteal","1","1","N/A","N/A","N/A","10","1694","231","2022-02-03T11:04:49Z","2015-08-11T17:02:58Z","6700" +"*/dnstool.py*",".{0,1000}\/dnstool\.py.{0,1000}","offensive_tool_keyword","krbrelayx","Kerberos unconstrained delegation abuse toolkit","T1558.003 - T1098","TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/dirkjanm/krbrelayx","1","1","N/A","N/A","N/A","10","1281","181","2025-01-27T09:22:54Z","2019-01-08T18:42:07Z","6701" +"*/dns-update.nse*",".{0,1000}\/dns\-update\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6702" +"*/dns-zeustracker.nse*",".{0,1000}\/dns\-zeustracker\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6703" +"*/dns-zone-transfer.nse*",".{0,1000}\/dns\-zone\-transfer\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6704" +"*/dns-zone-transfer.py*",".{0,1000}\/dns\-zone\-transfer\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","6705" +"*/dobin/avred*",".{0,1000}\/dobin\/avred.{0,1000}","offensive_tool_keyword","avred","Avred is being used to identify which parts of a file are identified by a Antivirus and tries to show as much possible information and context about each match.","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/dobin/avred","1","1","N/A","N/A","9","5","465","55","2025-02-26T08:12:03Z","2022-05-19T12:12:34Z","6706" +"*/DockerPwn.py*",".{0,1000}\/DockerPwn\.py.{0,1000}","offensive_tool_keyword","CDK","CDK is an open-sourced container penetration toolkit","T1610 - T1611 - T1203 - T1059.004 - T1564.004","TA0001 - TA0002 - TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/cdk-team/CDK","1","1","#linux","N/A","9","10","4164","566","2025-03-08T14:00:06Z","2020-11-05T09:18:51Z","6708" +"*/docker-version.nse*",".{0,1000}\/docker\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6709" +"*/DocPlz.git*",".{0,1000}\/DocPlz\.git.{0,1000}","offensive_tool_keyword","DocPlz","Documents Exfiltration and C2 project","T1105 - T1567 - T1071","TA0011 - TA0010 - TA0009","N/A","N/A","Data Exfiltration","https://github.com/TheD1rkMtr/DocPlz","1","1","N/A","N/A","10","2","145","30","2023-10-10T19:01:42Z","2023-10-02T20:49:22Z","6710" +"*/DocsPLZ.cpp*",".{0,1000}\/DocsPLZ\.cpp.{0,1000}","offensive_tool_keyword","DocPlz","Documents Exfiltration and C2 project","T1105 - T1567 - T1071","TA0011 - TA0010 - TA0009","N/A","N/A","Data Exfiltration","https://github.com/TheD1rkMtr/DocPlz","1","1","N/A","N/A","10","2","145","30","2023-10-10T19:01:42Z","2023-10-02T20:49:22Z","6711" +"*/DocsPLZ.exe*",".{0,1000}\/DocsPLZ\.exe.{0,1000}","offensive_tool_keyword","DocPlz","Documents Exfiltration and C2 project","T1105 - T1567 - T1071","TA0011 - TA0010 - TA0009","N/A","N/A","Data Exfiltration","https://github.com/TheD1rkMtr/DocPlz","1","1","N/A","N/A","10","2","145","30","2023-10-10T19:01:42Z","2023-10-02T20:49:22Z","6712" +"*/documentation-c2/*",".{0,1000}\/documentation\-c2\/.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","6713" +"*/documentation-payload/*",".{0,1000}\/documentation\-payload\/.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","6714" +"*/Do-Exfiltration.ps1*",".{0,1000}\/Do\-Exfiltration\.ps1.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","6715" +"*/Doge-Loader/*",".{0,1000}\/Doge\-Loader\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Shellcode Loader by Golang","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/timwhitez/Doge-Loader","1","1","N/A","N/A","10","10","280","57","2021-04-22T08:24:59Z","2020-10-09T04:47:54Z","6716" +"*/DoHC2.cs*",".{0,1000}\/DoHC2\.cs.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","6717" +"*/DoHC2.git*",".{0,1000}\/DoHC2\.git.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","6718" +"*/DoHC2/*",".{0,1000}\/DoHC2\/.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","6719" +"*/domain_analyzer.git*",".{0,1000}\/domain_analyzer\.git.{0,1000}","offensive_tool_keyword","domain_analyzer","Analyze the security of any domain by finding all the information possible","T1560 - T1590 - T1200 - T1213 - T1057","TA0002 - TA0009","N/A","N/A","Reconnaissance","https://github.com/eldraco/domain_analyzer","1","1","N/A","N/A","6","10","1858","241","2022-12-29T10:57:33Z","2017-08-08T18:52:34Z","6721" +"*/domainhunter*",".{0,1000}\/domainhunter.{0,1000}","offensive_tool_keyword","domainhunter","Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names ","T1583.002 - T1568.002","TA0011 - TA0009","N/A","N/A","Phishing","https://github.com/threatexpress/domainhunter","1","1","N/A","N/A","N/A","10","1587","292","2024-06-06T21:01:21Z","2017-03-01T11:16:26Z","6723" +"*/DomainPasswordSpray.git*",".{0,1000}\/DomainPasswordSpray\.git.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","1","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","6724" +"*/DomainRecon/*.txt*",".{0,1000}\/DomainRecon\/.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","6725" +"*/DomainTrustRecon.ahk*",".{0,1000}\/DomainTrustRecon\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","6726" +"*/domcachedump.py*",".{0,1000}\/domcachedump\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","6727" +"*/domcachedump.py*",".{0,1000}\/domcachedump\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","6728" +"*/domcon-brute.nse*",".{0,1000}\/domcon\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6729" +"*/domcon-cmd.nse*",".{0,1000}\/domcon\-cmd\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6730" +"*/Dome.git*",".{0,1000}\/Dome\.git.{0,1000}","offensive_tool_keyword","DOME","DOME - A subdomain enumeration tool","T1583 - T1595 - T1190","TA0011 - TA0009","N/A","N/A","Reconnaissance","https://github.com/v4d1/Dome","1","1","N/A","N/A","5","6","531","74","2024-02-07T09:12:17Z","2022-02-20T15:09:40Z","6731" +"*/domino-enum-users.nse*",".{0,1000}\/domino\-enum\-users\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6732" +"*/dompdf-rce*",".{0,1000}\/dompdf\-rce.{0,1000}","offensive_tool_keyword","POC","This repository contains a vulnerable demo application using dompdf 1.2.0 and an exploit that achieves remote code execution via a ttf+php polyglot file.","T1203 - T1204","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/positive-security/dompdf-rce","1","1","N/A","N/A","N/A","2","176","66","2022-03-17T18:05:07Z","2022-03-14T19:51:06Z","6733" +"*/DonPAPI.git*",".{0,1000}\/DonPAPI\.git.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","6734" +"*/DonPAPI.py*",".{0,1000}\/DonPAPI\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","6735" +"*/DonPAPI.zip*",".{0,1000}\/DonPAPI\.zip.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","6736" +"*/donut.exe*",".{0,1000}\/donut\.exe.{0,1000}","offensive_tool_keyword","donut","Donut is a position-independent code that enables in-memory execution of VBScript. JScript. EXE. DLL files and dotNET assemblies. A module created by Donut can either be staged from a HTTP server or embedded directly in the loader itself","T1071.001 - T1059 - T1059.001 - T1059.005 - T1059.006 - T1059.007 - T1562.001 - T1070 - T1105 - T1106 - T1027 - T1027.002 - T1057 - T1055 - T1620","TA0011 - TA0002 - TA0005 - TA0008 - TA0004 - TA0007 - TA0003 - TA0006 - TA0010","N/A","Indrik Spider","Exploitation tool","https://github.com/TheWover/donut","1","1","N/A","N/A","N/A","10","3882","667","2024-10-23T12:19:13Z","2019-03-27T23:24:44Z","6738" +"*/donut.git",".{0,1000}\/donut\.git","offensive_tool_keyword","donut","Donut is a position-independent code that enables in-memory execution of VBScript. JScript. EXE. DLL files and dotNET assemblies. A module created by Donut can either be staged from a HTTP server or embedded directly in the loader itself","T1071.001 - T1059 - T1059.001 - T1059.005 - T1059.006 - T1059.007 - T1562.001 - T1070 - T1105 - T1106 - T1027 - T1027.002 - T1057 - T1055 - T1620","TA0011 - TA0002 - TA0005 - TA0008 - TA0004 - TA0007 - TA0003 - TA0006 - TA0010","N/A","Indrik Spider","Exploitation tool","https://github.com/TheWover/donut","1","1","N/A","N/A","N/A","10","3882","667","2024-10-23T12:19:13Z","2019-03-27T23:24:44Z","6739" +"*/DonutCS/Donut.cs*",".{0,1000}\/DonutCS\/Donut\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","6742" +"*/donutmodule.c*",".{0,1000}\/donutmodule\.c.{0,1000}","offensive_tool_keyword","donut","Donut is a position-independent code that enables in-memory execution of VBScript. JScript. EXE. DLL files and dotNET assemblies. A module created by Donut can either be staged from a HTTP server or embedded directly in the loader itself","T1071.001 - T1059 - T1059.001 - T1059.005 - T1059.006 - T1059.007 - T1562.001 - T1070 - T1105 - T1106 - T1027 - T1027.002 - T1057 - T1055 - T1620","TA0011 - TA0002 - TA0005 - TA0008 - TA0004 - TA0007 - TA0003 - TA0006 - TA0010","N/A","Indrik Spider","Exploitation tool","https://github.com/TheWover/donut","1","1","N/A","N/A","N/A","10","3882","667","2024-10-23T12:19:13Z","2019-03-27T23:24:44Z","6743" +"*/donut-packer.py*",".{0,1000}\/donut\-packer\.py.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","packer bundled","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","6744" +"*/DonutTest/*",".{0,1000}\/DonutTest\/.{0,1000}","offensive_tool_keyword","donut","Donut is a position-independent code that enables in-memory execution of VBScript. JScript. EXE. DLL files and dotNET assemblies. A module created by Donut can either be staged from a HTTP server or embedded directly in the loader itself","T1071.001 - T1059 - T1059.001 - T1059.005 - T1059.006 - T1059.007 - T1562.001 - T1070 - T1105 - T1106 - T1027 - T1027.002 - T1057 - T1055 - T1620","TA0011 - TA0002 - TA0005 - TA0008 - TA0004 - TA0007 - TA0003 - TA0006 - TA0010","N/A","Indrik Spider","Exploitation tool","https://github.com/TheWover/donut","1","1","N/A","N/A","N/A","10","3882","667","2024-10-23T12:19:13Z","2019-03-27T23:24:44Z","6745" +"*/DotNet/SigFlip*",".{0,1000}\/DotNet\/SigFlip.{0,1000}","offensive_tool_keyword","cobaltstrike","SigFlip is a tool for patching authenticode signed PE files (exe. dll. sys ..etc) without invalidating or breaking the existing signature.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/med0x2e/SigFlip","1","1","N/A","N/A","10","10","1139","197","2023-08-27T18:27:50Z","2021-08-08T15:59:19Z","6746" +"*/DoubleDrive.git*",".{0,1000}\/DoubleDrive\.git.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","6747" +"*/DoubleDrive-main.zip*",".{0,1000}\/DoubleDrive\-main\.zip.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","6748" +"*/DoUCMe.git*",".{0,1000}\/DoUCMe\.git.{0,1000}","offensive_tool_keyword","doucme","leverages the NetUserAdd Win32 API to create a new computer account","T1136 - T1098 - T1078","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/Ben0xA/DoUCMe","1","1","N/A","N/A","9","1","69","18","2021-05-01T03:15:59Z","2021-04-29T15:41:28Z","6749" +"*/download/linpeas.sh*",".{0,1000}\/download\/linpeas\.sh.{0,1000}","offensive_tool_keyword","PEASS-ng","PEASS-ng - Privilege Escalation Awesome Scripts suite","T1098","TA0004 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/peass-ng/PEASS-ng","1","1","N/A","N/A","10","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","6752" +"*/download/LsassDumping/*",".{0,1000}\/download\/LsassDumping\/.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","1","N/A","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","6753" +"*/download/v*/sliver-client_linux*",".{0,1000}\/download\/v.{0,1000}\/sliver\-client_linux.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","#linux","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","6755" +"*/download/v*/sliver-client_macos*",".{0,1000}\/download\/v.{0,1000}\/sliver\-client_macos.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","6756" +"*/download/v*/sliver-client_macos*",".{0,1000}\/download\/v.{0,1000}\/sliver\-client_macos.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","6757" +"*/download/v1.1.0/pspy32*",".{0,1000}\/download\/v1\.1\.0\/pspy32.{0,1000}","offensive_tool_keyword","pspy","Monitor linux processes without root permissions","T1057 - T1082 - T1518.001","TA0007","N/A","N/A","Discovery","https://github.com/DominicBreuker/pspy","1","1","#linux","N/A","8","10","5370","538","2023-01-17T21:09:22Z","2018-02-08T21:41:37Z","6759" +"*/download/v1.1.0/pspy64*",".{0,1000}\/download\/v1\.1\.0\/pspy64.{0,1000}","offensive_tool_keyword","pspy","Monitor linux processes without root permissions","T1057 - T1082 - T1518.001","TA0007","N/A","N/A","Discovery","https://github.com/DominicBreuker/pspy","1","1","#linux","N/A","8","10","5370","538","2023-01-17T21:09:22Z","2018-02-08T21:41:37Z","6760" +"*/download/v1.2.0/pspy32*",".{0,1000}\/download\/v1\.2\.0\/pspy32.{0,1000}","offensive_tool_keyword","pspy","Monitor linux processes without root permissions","T1057 - T1082 - T1518.001","TA0007","N/A","N/A","Discovery","https://github.com/DominicBreuker/pspy","1","1","#linux","N/A","8","10","5370","538","2023-01-17T21:09:22Z","2018-02-08T21:41:37Z","6761" +"*/download/v1.2.1/pspy32*",".{0,1000}\/download\/v1\.2\.1\/pspy32.{0,1000}","offensive_tool_keyword","pspy","Monitor linux processes without root permissions","T1057 - T1082 - T1518.001","TA0007","N/A","N/A","Discovery","https://github.com/DominicBreuker/pspy","1","1","#linux","N/A","8","10","5370","538","2023-01-17T21:09:22Z","2018-02-08T21:41:37Z","6762" +"*/download/v1.2.1/pspy64*",".{0,1000}\/download\/v1\.2\.1\/pspy64.{0,1000}","offensive_tool_keyword","pspy","Monitor linux processes without root permissions","T1057 - T1082 - T1518.001","TA0007","N/A","N/A","Discovery","https://github.com/DominicBreuker/pspy","1","1","#linux","N/A","8","10","5370","538","2023-01-17T21:09:22Z","2018-02-08T21:41:37Z","6763" +"*/Download:Cradle.js*",".{0,1000}\/Download\:Cradle\.js.{0,1000}","offensive_tool_keyword","Payload-Download-Cradles","download cradles to bypass AV/EPP/EDR in context of download cradle detections","T1105 - T1027 - T1203 - T1071","TA0005 - TA0009 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Payload-Download-Cradles","1","1","N/A","N/A","10","3","256","51","2022-07-07T07:20:36Z","2021-05-14T08:56:54Z","6764" +"*/Download_Cradles.hta*",".{0,1000}\/Download_Cradles\.hta.{0,1000}","offensive_tool_keyword","Payload-Download-Cradles","download cradles to bypass AV/EPP/EDR in context of download cradle detections","T1105 - T1027 - T1203 - T1071","TA0005 - TA0009 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Payload-Download-Cradles","1","1","N/A","N/A","10","3","256","51","2022-07-07T07:20:36Z","2021-05-14T08:56:54Z","6765" +"*/Download_Cradles.ps1*",".{0,1000}\/Download_Cradles\.ps1.{0,1000}","offensive_tool_keyword","Payload-Download-Cradles","download cradles to bypass AV/EPP/EDR in context of download cradle detections","T1105 - T1027 - T1203 - T1071","TA0005 - TA0009 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Payload-Download-Cradles","1","1","N/A","N/A","10","3","256","51","2022-07-07T07:20:36Z","2021-05-14T08:56:54Z","6766" +"*/Download-Cradles.cmd*",".{0,1000}\/Download\-Cradles\.cmd.{0,1000}","offensive_tool_keyword","Payload-Download-Cradles","download cradles to bypass AV/EPP/EDR in context of download cradle detections","T1105 - T1027 - T1203 - T1071","TA0005 - TA0009 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Payload-Download-Cradles","1","1","N/A","N/A","10","3","256","51","2022-07-07T07:20:36Z","2021-05-14T08:56:54Z","6767" +"*/downloadexec.lua*",".{0,1000}\/downloadexec\.lua.{0,1000}","offensive_tool_keyword","OffensiveLua","Offensive Lua is a collection of offensive security scripts written in Lua with FFI","T1059 - T1218.011 - T1105 - T1021.002 - T1564.001 - T1112 - T1113 - T1204.002 - T1547.002","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hackerhouse-opensource/OffensiveLua","1","1","N/A","N/A","8","2","184","25","2023-11-17T00:35:10Z","2023-10-25T17:21:13Z","6768" +"*/download-stager.js*",".{0,1000}\/download\-stager\.js.{0,1000}","offensive_tool_keyword","empire","Starkiller is a Frontend for Powershell Empire. It is a web application written in VueJS","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Starkiller","1","1","N/A","N/A","10","10","1461","206","2025-03-25T03:30:16Z","2020-03-09T05:48:58Z","6772" +"*/dpap-brute.nse*",".{0,1000}\/dpap\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6773" +"*/Dpapi.ps1*",".{0,1000}\/Dpapi\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","6774" +"*/dpapi.py*",".{0,1000}\/dpapi\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","6775" +"*/dpapi_domain_backupkey.py*",".{0,1000}\/dpapi_domain_backupkey\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","6776" +"*/dpapi_masterkey.py*",".{0,1000}\/dpapi_masterkey\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","6777" +"*/DPAPImk2john.py*",".{0,1000}\/DPAPImk2john\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","6778" +"*/dpipe.sh*",".{0,1000}\/dpipe\.sh.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","t1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/basharkey/CVE-2022-0847-dirty-pipe-checker","1","1","N/A","N/A","N/A","1","67","29","2023-06-14T23:25:46Z","2022-03-08T17:13:24Z","6780" +"*/dploot.git*",".{0,1000}\/dploot\.git.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","6782" +"*/DragonCastle.git*",".{0,1000}\/DragonCastle\.git.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","1","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","6783" +"*/DragonCastle.pdb*",".{0,1000}\/DragonCastle\.pdb.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","1","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","6784" +"*/dragoncastle.py*",".{0,1000}\/dragoncastle\.py.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","1","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","6785" +"*/D-RAT.exe*",".{0,1000}\/D\-RAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6786" +"*/drda-brute.nse*",".{0,1000}\/drda\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6787" +"*/drda-info.nse*",".{0,1000}\/drda\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6788" +"*/DReverseProxy.git*",".{0,1000}\/DReverseProxy\.git.{0,1000}","offensive_tool_keyword","C2ReverseProxy","ReverseProxy C2 - Bring CS online without going offline","T1090 - T1090.002 - T1573 - T1573.001 - T1573.002","TA0011","N/A","N/A","C2","https://github.com/Daybr4ak/C2ReverseProxy","1","1","N/A","N/A","10","10","486","56","2023-04-26T13:16:26Z","2020-01-16T05:43:35Z","6789" +"*/DriverDump.exe*",".{0,1000}\/DriverDump\.exe.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","6790" +"*/Drones/SleepDialogue.razor*",".{0,1000}\/Drones\/SleepDialogue\.razor.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","6791" +"*/DRSAT.exe*",".{0,1000}\/DRSAT\.exe.{0,1000}","offensive_tool_keyword","DRSAT","Disconnected RSAT is a launcher for the official Group Policy Manager - Certificate Authority and Certificate Templates snap-in to bypass the domain joined requirement that is needed when using the official MMC snap-in. The tool works by injecting a C# library into MMC that will hook the various API calls to trick MMC into believing that the logged on user is a domain user. attackers can abuse Disconnected RSAT to interact with Active Directory (AD) environments from non-domain-joined machines","T1559.001 - T1112 - T1078 - T1134.002 - T1055.001","TA0002 - TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/CCob/DRSAT","1","1","N/A","N/A","6","3","233","25","2024-12-27T11:44:18Z","2024-09-04T16:35:02Z","6800" +"*/DRSAT.git*",".{0,1000}\/DRSAT\.git.{0,1000}","offensive_tool_keyword","DRSAT","Disconnected RSAT is a launcher for the official Group Policy Manager - Certificate Authority and Certificate Templates snap-in to bypass the domain joined requirement that is needed when using the official MMC snap-in. The tool works by injecting a C# library into MMC that will hook the various API calls to trick MMC into believing that the logged on user is a domain user. attackers can abuse Disconnected RSAT to interact with Active Directory (AD) environments from non-domain-joined machines","T1559.001 - T1112 - T1078 - T1134.002 - T1055.001","TA0002 - TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/CCob/DRSAT","1","1","N/A","N/A","6","3","233","25","2024-12-27T11:44:18Z","2024-09-04T16:35:02Z","6801" +"*/DRSAT-0.2.zip*",".{0,1000}\/DRSAT\-0\.2\.zip.{0,1000}","offensive_tool_keyword","DRSAT","Disconnected RSAT is a launcher for the official Group Policy Manager - Certificate Authority and Certificate Templates snap-in to bypass the domain joined requirement that is needed when using the official MMC snap-in. The tool works by injecting a C# library into MMC that will hook the various API calls to trick MMC into believing that the logged on user is a domain user. attackers can abuse Disconnected RSAT to interact with Active Directory (AD) environments from non-domain-joined machines","T1559.001 - T1112 - T1078 - T1134.002 - T1055.001","TA0002 - TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/CCob/DRSAT","1","1","N/A","N/A","6","3","233","25","2024-12-27T11:44:18Z","2024-09-04T16:35:02Z","6802" +"*/drunkpotato*",".{0,1000}\/drunkpotato.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6803" +"*/DSInternals.psd1*",".{0,1000}\/DSInternals\.psd1.{0,1000}","offensive_tool_keyword","DSInternals","Directory Services Internals (DSInternals) PowerShell Module and Framework - abused by attackers","T1003 - T1087 - T1018 - T1110 - T1558","TA0003 - TA0006 - TA0007","N/A","COZY BEAR","Discovery","https://github.com/MichaelGrafnetter/DSInternals","1","1","N/A","AD Enumeration","10","10","1760","265","2025-04-16T18:12:55Z","2015-12-25T13:23:05Z","6805" +"*/DUBrute.git*",".{0,1000}\/DUBrute\.git.{0,1000}","offensive_tool_keyword","DUBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/ch0sys/DUBrute","1","1","N/A","N/A","10","1","37","28","2018-02-19T13:03:14Z","2017-06-15T08:55:46Z","6808" +"*/DuckDuckC2.git*",".{0,1000}\/DuckDuckC2\.git.{0,1000}","offensive_tool_keyword","DuckDuckC2","A proof-of-concept C2 channel through DuckDuckGo's image proxy service","T1071.001 - T1090.003","TA0011 - TA0042","N/A","N/A","C2","https://github.com/nopcorn/DuckDuckC2","1","1","N/A","N/A","10","10","74","6","2023-11-12T10:24:59Z","2023-09-23T20:00:09Z","6815" +"*/ducky.py",".{0,1000}\/ducky\.py","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1101","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","6816" +"*/DueDLLigence.git*",".{0,1000}\/DueDLLigence\.git.{0,1000}","offensive_tool_keyword","DueDLLigence","Shellcode runner framework for application whitelisting bypasses and DLL side-loading","T1055.012 - T1218.011","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/mandiant/DueDLLigence","1","1","N/A","N/A","10","5","469","89","2023-06-02T14:24:43Z","2019-10-04T18:34:27Z","6817" +"*/dukes_apt29.profile*",".{0,1000}\/dukes_apt29\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","6818" +"*/dump.ps1*",".{0,1000}\/dump\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","6820" +"*/dump_lsass.*",".{0,1000}\/dump_lsass\..{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of CobaltStrike beacon object files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/pwn1sher/CS-BOFs","1","1","N/A","N/A","10","10","103","22","2022-02-14T09:47:30Z","2021-01-18T08:54:48Z","6821" +"*/DumpAADSyncCreds.git*",".{0,1000}\/DumpAADSyncCreds\.git.{0,1000}","offensive_tool_keyword","DumpAADSyncCreds","C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.","T1555 - T1110","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Hagrid29/DumpAADSyncCreds","1","1","N/A","N/A","10","1","39","3","2023-06-24T16:17:36Z","2022-03-27T18:43:44Z","6822" +"*/DumpCerts*",".{0,1000}\/DumpCerts.{0,1000}","offensive_tool_keyword","mimikatz","Invoke-Mimikatz.ps1 script argument","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Invoke-Mimikatz.ps1","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","6823" +"*/DumpCreds*",".{0,1000}\/DumpCreds.{0,1000}","offensive_tool_keyword","mimikatz","Invoke-Mimikatz.ps1 script argument","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Invoke-Mimikatz.ps1","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","6824" +"*/dumpCredStore.ps1*",".{0,1000}\/dumpCredStore\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","6825" +"*/dumper.ps1*",".{0,1000}\/dumper\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","6826" +"*/dumper2020.git*",".{0,1000}\/dumper2020\.git.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","1","N/A","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","6827" +"*/dumper2020_exe*",".{0,1000}\/dumper2020_exe.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","1","N/A","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","6828" +"*/dumpert.c*",".{0,1000}\/dumpert\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","LSASS memory dumper using direct system calls and API unhooking.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Dumpert/tree/master/Dumpert-Aggressor","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","6829" +"*/dumpert.py*",".{0,1000}\/dumpert\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","6830" +"*/Dumpert/*",".{0,1000}\/Dumpert\/.{0,1000}","offensive_tool_keyword","cobaltstrike","LSASS memory dumper using direct system calls and API unhooking.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Dumpert/tree/master/Dumpert-Aggressor","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","6831" +"*/DumpIt.exe*",".{0,1000}\/DumpIt\.exe.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","1","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","6832" +"*/DumpLSASS.git*",".{0,1000}\/DumpLSASS\.git.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","1","N/A","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","6833" +"*/Dump-Lsass.git*",".{0,1000}\/Dump\-Lsass\.git.{0,1000}","offensive_tool_keyword","impacket","Dump-lsass script using impacket - Automates the manual process of using wmiexec and procdump to dump Lsass and plaintext creds or hashes across a large number of systems.","T1021 - T1047 - T1055.011 - T1003","TA0002 - TA0005 - TA0006","N/A","Dispossessor - Black Basta","Credential Access","https://github.com/kaluche/Dump-Lsass","1","1","N/A","N/A","10","1","1","0","2019-11-14T18:15:26Z","2019-11-20T20:26:27Z","6834" +"*/DumpLsass.ps1*",".{0,1000}\/DumpLsass\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","6835" +"*/dump-lsass.py*",".{0,1000}\/dump\-lsass\.py.{0,1000}","offensive_tool_keyword","impacket","Dump-lsass script using impacket - Automates the manual process of using wmiexec and procdump to dump Lsass and plaintext creds or hashes across a large number of systems.","T1021 - T1047 - T1055.011 - T1003","TA0002 - TA0005 - TA0006","N/A","Dispossessor - Black Basta","Credential Access","https://github.com/kaluche/Dump-Lsass","1","1","N/A","N/A","10","1","1","0","2019-11-14T18:15:26Z","2019-11-20T20:26:27Z","6836" +"*/dumpmethod/*.py",".{0,1000}\/dumpmethod\/.{0,1000}\.py","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","6837" +"*/DumpNParse.exe*",".{0,1000}\/DumpNParse\.exe.{0,1000}","offensive_tool_keyword","DumpNParse","A Combination LSASS Dumper and LSASS Parser","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/icyguider/DumpNParse","1","1","N/A","N/A","10","2","150","24","2021-11-21T14:25:24Z","2021-11-21T14:18:42Z","6838" +"*/DumpNParse.git*",".{0,1000}\/DumpNParse\.git.{0,1000}","offensive_tool_keyword","DumpNParse","A Combination LSASS Dumper and LSASS Parser","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/icyguider/DumpNParse","1","1","N/A","N/A","10","2","150","24","2021-11-21T14:25:24Z","2021-11-21T14:18:42Z","6839" +"*/DumpNTLMInfo.py*",".{0,1000}\/DumpNTLMInfo\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","6840" +"*/dumpSecrets.go*",".{0,1000}\/dumpSecrets\.go.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","6842" +"*/dumpsecrets_test.go*",".{0,1000}\/dumpsecrets_test\.go.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","6843" +"*/DumpShellcode/*",".{0,1000}\/DumpShellcode\/.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","6844" +"*/DumpSvc.exe*",".{0,1000}\/DumpSvc\.exe.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","1","N/A","N/A","10","8","N/A","N/A","N/A","N/A","6846" +"*/DumpThatLSASS.*",".{0,1000}\/DumpThatLSASS\..{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","1","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","6847" +"*/DumpThatLSASS.git*",".{0,1000}\/DumpThatLSASS\.git.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","1","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","6848" +"*/DumpThatLSASS/*",".{0,1000}\/DumpThatLSASS\/.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","1","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","6849" +"*/dumpweb.log*",".{0,1000}\/dumpweb\.log.{0,1000}","offensive_tool_keyword","chromedump","ChromeDump is a small tool to dump all JavaScript and other ressources going through the browser","T1059.007 - T1114.001 - T1518.001 - T1552.002","TA0005 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/g4l4drim/ChromeDump","1","1","#logfile #linux","N/A","N/A","1","55","1","2024-10-12T14:07:36Z","2023-01-26T20:44:06Z","6850" +"*/dumpXor.exe*",".{0,1000}\/dumpXor\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","dump lsass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/seventeenman/CallBackDump","1","1","N/A","N/A","10","10","549","76","2023-07-20T09:03:33Z","2022-09-25T08:29:14Z","6851" +"*/dumpXor/dumpXor*",".{0,1000}\/dumpXor\/dumpXor.{0,1000}","offensive_tool_keyword","cobaltstrike","dump lsass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/seventeenman/CallBackDump","1","1","N/A","N/A","10","10","549","76","2023-07-20T09:03:33Z","2022-09-25T08:29:14Z","6852" +"*/dumpy.exe*",".{0,1000}\/dumpy\.exe.{0,1000}","offensive_tool_keyword","Dumpy","Reuse open handles to dynamically dump LSASS","T1003.001 - T1055.001 - T1083","TA0006","N/A","N/A","Credential Access","https://github.com/Kudaes/Dumpy","1","1","N/A","N/A","10","3","243","24","2024-04-04T07:42:26Z","2021-10-13T21:54:59Z","6853" +"*/Dumpy.git*",".{0,1000}\/Dumpy\.git.{0,1000}","offensive_tool_keyword","Dumpy","Reuse open handles to dynamically dump LSASS","T1003.001 - T1055.001 - T1083","TA0006","N/A","N/A","Credential Access","https://github.com/Kudaes/Dumpy","1","1","N/A","N/A","10","3","243","24","2024-04-04T07:42:26Z","2021-10-13T21:54:59Z","6854" +"*/dunderhay/CVE-202*",".{0,1000}\/dunderhay\/CVE\-202.{0,1000}","offensive_tool_keyword","POC","exploit code for F5-Big-IP (CVE-2020-5902)","T1210","TA0008","N/A","N/A","Exploitation tool","https://github.com/dunderhay/CVE-2020-5902","1","1","N/A","N/A","N/A","1","37","8","2024-03-19T01:21:06Z","2020-07-06T04:03:58Z","6855" +"*/duplicates.nse*",".{0,1000}\/duplicates\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6856" +"*/DynastyPersist.git*",".{0,1000}\/DynastyPersist\.git.{0,1000}","offensive_tool_keyword","DynastyPersist","Linux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd Service","T1055 - T1037 - T1078 - T1547 - T1546 - T1556","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/Trevohack/DynastyPersist","1","1","#linux","N/A","9","2","153","17","2024-05-16T05:19:48Z","2023-08-13T15:05:42Z","6864" +"*/DynastyPersist/src/*.sh*",".{0,1000}\/DynastyPersist\/src\/.{0,1000}\.sh.{0,1000}","offensive_tool_keyword","DynastyPersist","Linux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd Service","T1055 - T1037 - T1078 - T1547 - T1546 - T1556","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/Trevohack/DynastyPersist","1","1","#linux","N/A","9","2","153","17","2024-05-16T05:19:48Z","2023-08-13T15:05:42Z","6865" +"*/e2e_test.py*",".{0,1000}\/e2e_test\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","6867" +"*/Eagle RAT.exe*",".{0,1000}\/Eagle\sRAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","6868" +"*/eap-info.nse*",".{0,1000}\/eap\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6869" +"*/earthworm.exe*",".{0,1000}\/earthworm\.exe.{0,1000}","offensive_tool_keyword","EarthWorm","SOCKS v5 proxy service used for data forwarding in complex network environments","T1090.002 - T1573.001 - T1095","TA0010 - TA0008 - TA0011","N/A","APT27 - APT15 - Calypso - Earth Lusca - Worok","C2","https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4","1","1","N/A","N/A","10","10","156","177","2021-01-26T23:16:49Z","2019-01-03T05:01:20Z","6870" +"*/EASSniper.git*",".{0,1000}\/EASSniper\.git.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","1","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","6871" +"*/EASSniper.ps1*",".{0,1000}\/EASSniper\.ps1.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","1","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","6872" +"*/EASSniper.ps1*",".{0,1000}\/EASSniper\.ps1.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","6873" +"*/ebapc_injection.exe*",".{0,1000}\/ebapc_injection\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","6875" +"*/Ebowla.git*",".{0,1000}\/Ebowla\.git.{0,1000}","offensive_tool_keyword","Ebowla","Framework for Making Environmental Keyed Payloads","T1027.002 - T1059.003 - T1140","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/Genetic-Malware/Ebowla","1","1","N/A","N/A","10","8","748","171","2019-01-28T10:45:15Z","2016-04-07T22:29:58Z","6876" +"*/ebowla.py*",".{0,1000}\/ebowla\.py.{0,1000}","offensive_tool_keyword","Ebowla","Framework for Making Environmental Keyed Payloads","T1027.002 - T1059.003 - T1140","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/Genetic-Malware/Ebowla","1","1","N/A","N/A","10","8","748","171","2019-01-28T10:45:15Z","2016-04-07T22:29:58Z","6877" +"*/ec2__backdoor_ec2_sec_groups*",".{0,1000}\/ec2__backdoor_ec2_sec_groups.{0,1000}","offensive_tool_keyword","pacu","The AWS exploitation framework designed for testing the security of Amazon Web Services environments.","T1136.003 - T1190 - T1078.004","TA0006 - TA0001","N/A","Scattered Spider*","Framework","https://github.com/RhinoSecurityLabs/pacu","1","1","N/A","N/A","9","10","4651","731","2025-03-20T21:08:57Z","2018-06-13T21:58:59Z","6878" +"*/EC2Looter.py*",".{0,1000}\/EC2Looter\.py.{0,1000}","offensive_tool_keyword","AWS-Loot","Searches an AWS environment looking for secrets. by enumerating environment variables and source code. This tool allows quick enumeration over large sets of AWS instances and services.","T1552","TA0002","N/A","N/A","Exploitation tool","https://github.com/sebastian-mora/AWS-Loot","1","1","N/A","N/A","N/A","1","70","25","2020-02-02T00:51:56Z","2020-02-02T00:25:46Z","6882" +"*/echoac-poc.git*",".{0,1000}\/echoac\-poc\.git.{0,1000}","offensive_tool_keyword","echoac-poc","poc stealing the Kernel's KPROCESS/EPROCESS block and writing it to a newly spawned shell to elevate its privileges to the highest possible - nt authority\system","T1068 - T1203 - T1059.003","TA0002 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/kite03/echoac-poc","1","1","N/A","N/A","8","2","138","25","2024-01-09T16:44:00Z","2023-06-28T00:52:22Z","6883" +"*/ecrprivenum.py*",".{0,1000}\/ecrprivenum\.py.{0,1000}","offensive_tool_keyword","quiet-riot","Unauthenticated enumeration of AWS - Azure and GCP Principals","T1087 - T1083 - T1210","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/righteousgambit/quiet-riot","1","1","N/A","N/A","6","3","224","30","2024-11-13T19:41:26Z","2021-10-28T15:12:27Z","6884" +"*/ecrpubenum.py*",".{0,1000}\/ecrpubenum\.py.{0,1000}","offensive_tool_keyword","quiet-riot","Unauthenticated enumeration of AWS - Azure and GCP Principals","T1087 - T1083 - T1210","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/righteousgambit/quiet-riot","1","1","N/A","N/A","6","3","224","30","2024-11-13T19:41:26Z","2021-10-28T15:12:27Z","6885" +"*/edb-35948/*",".{0,1000}\/edb\-35948\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6886" +"*/EdgeDump.ahk*",".{0,1000}\/EdgeDump\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","6887" +"*/EDR_Detector.git*",".{0,1000}\/EDR_Detector\.git.{0,1000}","offensive_tool_keyword","EDR_Detector","detect EDR agents on a machine","T1518.001 - T1063","TA0007 - TA0009","N/A","N/A","Collection","https://github.com/trickster0/EDR_Detector","1","1","N/A","N/A","7","1","93","14","2021-11-05T08:10:05Z","2019-08-24T20:50:09Z","6888" +"*/EDR_Detector.rs*",".{0,1000}\/EDR_Detector\.rs.{0,1000}","offensive_tool_keyword","EDR_Detector","detect EDR agents on a machine","T1518.001 - T1063","TA0007 - TA0009","N/A","N/A","Collection","https://github.com/trickster0/EDR_Detector","1","1","N/A","N/A","7","1","93","14","2021-11-05T08:10:05Z","2019-08-24T20:50:09Z","6889" +"*/EDRaser.git*",".{0,1000}\/EDRaser\.git.{0,1000}","offensive_tool_keyword","EDRaser","EDRaser is a powerful tool for remotely deleting access logs & Windows event logs & databases and other files on remote machines.","T1070.004 - T1027 - T1564.001","TA0005 - TA0040 - TA0003","N/A","N/A","Defense Evasion","https://github.com/SafeBreach-Labs/EDRaser","1","1","N/A","N/A","10","4","363","49","2024-04-06T17:42:40Z","2023-08-10T04:30:45Z","6890" +"*/edraser.py*",".{0,1000}\/edraser\.py.{0,1000}","offensive_tool_keyword","EDRaser","EDRaser is a powerful tool for remotely deleting access logs & Windows event logs & databases and other files on remote machines.","T1070.004 - T1027 - T1564.001","TA0005 - TA0040 - TA0003","N/A","N/A","Defense Evasion","https://github.com/SafeBreach-Labs/EDRaser","1","1","N/A","N/A","10","4","363","49","2024-04-06T17:42:40Z","2023-08-10T04:30:45Z","6891" +"*/EDRPrison.git*",".{0,1000}\/EDRPrison\.git.{0,1000}","offensive_tool_keyword","EDRPrison","Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry","T1562 - T1027","TA0005 - TA0007","N/A","N/A","Defense Evasion","https://github.com/senzee1984/EDRPrison","1","1","N/A","N/A","10","5","401","37","2024-08-02T18:10:02Z","2024-06-30T01:17:04Z","6893" +"*/EDRSandblast.git*",".{0,1000}\/EDRSandblast\.git.{0,1000}","offensive_tool_keyword","EDRSandBlast","EDRSandBlast is a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/wavestone-cdt/EDRSandblast","1","1","N/A","N/A","10","10","1633","292","2024-08-30T20:30:31Z","2021-11-02T15:02:42Z","6894" +"*/EDRSilencer.c*",".{0,1000}\/EDRSilencer\.c.{0,1000}","offensive_tool_keyword","EDRSilencer","A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server","T1562.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/netero1010/EDRSilencer","1","1","N/A","N/A","10","10","1645","209","2024-11-03T16:05:14Z","2023-12-26T04:15:39Z","6896" +"*/EDRSilencer.git*",".{0,1000}\/EDRSilencer\.git.{0,1000}","offensive_tool_keyword","EDRSilencer","A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server","T1562.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/netero1010/EDRSilencer","1","1","N/A","N/A","10","10","1645","209","2024-11-03T16:05:14Z","2023-12-26T04:15:39Z","6897" +"*/EfiDSEFix.cpp*",".{0,1000}\/EfiDSEFix\.cpp.{0,1000}","offensive_tool_keyword","EfiGuard","EfiGuard is a portable x64 UEFI bootkit that patches the Windows boot manager - boot loader and kernel at boot time in order to disable PatchGuard and Driver Signature Enforcement (DSE).","T1542.002 - T1542.003 - T1542.004","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Mattiwatti/EfiGuard","1","1","N/A","N/A","10","10","1977","354","2025-02-24T11:57:36Z","2019-03-25T19:47:39Z","6898" +"*/EfiDSEFix.exe*",".{0,1000}\/EfiDSEFix\.exe.{0,1000}","offensive_tool_keyword","EfiGuard","EfiGuard is a portable x64 UEFI bootkit that patches the Windows boot manager - boot loader and kernel at boot time in order to disable PatchGuard and Driver Signature Enforcement (DSE).","T1542.002 - T1542.003 - T1542.004","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Mattiwatti/EfiGuard","1","1","N/A","N/A","10","10","1977","354","2025-02-24T11:57:36Z","2019-03-25T19:47:39Z","6899" +"*/EfiGuard.sln*",".{0,1000}\/EfiGuard\.sln.{0,1000}","offensive_tool_keyword","EfiGuard","EfiGuard is a portable x64 UEFI bootkit that patches the Windows boot manager - boot loader and kernel at boot time in order to disable PatchGuard and Driver Signature Enforcement (DSE).","T1542.002 - T1542.003 - T1542.004","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Mattiwatti/EfiGuard","1","1","N/A","N/A","10","10","1977","354","2025-02-24T11:57:36Z","2019-03-25T19:47:39Z","6900" +"*/EfiGuardDxe.c*",".{0,1000}\/EfiGuardDxe\.c.{0,1000}","offensive_tool_keyword","EfiGuard","EfiGuard is a portable x64 UEFI bootkit that patches the Windows boot manager - boot loader and kernel at boot time in order to disable PatchGuard and Driver Signature Enforcement (DSE).","T1542.002 - T1542.003 - T1542.004","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Mattiwatti/EfiGuard","1","1","N/A","N/A","10","10","1977","354","2025-02-24T11:57:36Z","2019-03-25T19:47:39Z","6901" +"*/EfsPotato.exe*",".{0,1000}\/EfsPotato\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6902" +"*/EfsPotato.git*",".{0,1000}\/EfsPotato\.git.{0,1000}","offensive_tool_keyword","EfsPotato","Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability)","T1068 - T1055.002 - T1070.004","TA0003 - TA0005 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/zcgonvh/EfsPotato","1","1","N/A","N/A","10","8","771","125","2023-12-14T14:30:15Z","2021-07-26T21:36:16Z","6903" +"*/egghunter.rb*",".{0,1000}\/egghunter\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6904" +"*/Egress-Assess*",".{0,1000}\/Egress\-Assess.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","6905" +"*/elevate_handle_inheritance.py*",".{0,1000}\/elevate_handle_inheritance\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","6907" +"*/elevate_mofcomp.py*",".{0,1000}\/elevate_mofcomp\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","6908" +"*/elevate_named_pipe_impersonation.py*",".{0,1000}\/elevate_named_pipe_impersonation\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","6909" +"*/elevate_schtasks.py*",".{0,1000}\/elevate_schtasks\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","6910" +"*/elevate_token_impersonation.py*",".{0,1000}\/elevate_token_impersonation\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","6911" +"*/elevate_wmic.py*",".{0,1000}\/elevate_wmic\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","6912" +"*/elevateit.bat*",".{0,1000}\/elevateit\.bat.{0,1000}","offensive_tool_keyword","elevationstation","elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","6913" +"*/ElevateKit/elevate.*",".{0,1000}\/ElevateKit\/elevate\..{0,1000}","offensive_tool_keyword","cobaltstrike","The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/ElevateKit","1","1","N/A","N/A","10","10","912","203","2020-06-22T21:12:24Z","2016-12-08T03:51:09Z","6914" +"*/Elevator.git*",".{0,1000}\/Elevator\.git.{0,1000}","offensive_tool_keyword","Elevator","UAC bypass by abusing RPC and debug objects.","T1548.002","TA0004","N/A","N/A","Privilege Escalation","https://github.com/Kudaes/Elevator","1","1","N/A","N/A","10","7","614","69","2023-10-19T08:51:09Z","2022-08-25T21:39:28Z","6915" +"*/ELFLoader/*",".{0,1000}\/ELFLoader\/.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a ELF object in memory loader/runner. The goal is to create a single elf loader that can be used to run follow on capabilities across all x86_64 and x86 nix operating systems.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/ELFLoader","1","1","N/A","N/A","10","10","268","45","2022-05-16T17:48:40Z","2022-04-26T19:18:20Z","6918" +"*/ELMALISEKER Backd00r.asp*",".{0,1000}\/ELMALISEKER\sBackd00r\.asp.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","6919" +"*/ElusiveMice.git*",".{0,1000}\/ElusiveMice\.git.{0,1000}","offensive_tool_keyword","ElusiveMice","Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind","T1620 - T1055.012 - T1202","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/mgeeky/ElusiveMice","1","1","N/A","N/A","10","5","449","78","2023-07-12T17:54:07Z","2021-08-27T19:22:20Z","6920" +"*/EmailAll.git*",".{0,1000}\/EmailAll\.git.{0,1000}","offensive_tool_keyword","EmailAll","EmailAll is a powerful Email Collect tool","T1114.001 - T1113 - T1087.003","TA0009 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Taonn/EmailAll","1","1","N/A","N/A","6","8","715","117","2022-03-04T10:36:41Z","2022-02-14T06:55:30Z","6922" +"*/emailall.py*",".{0,1000}\/emailall\.py.{0,1000}","offensive_tool_keyword","EmailAll","EmailAll is a powerful Email Collect tool","T1114.001 - T1113 - T1087.003","TA0009 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Taonn/EmailAll","1","1","N/A","N/A","6","8","715","117","2022-03-04T10:36:41Z","2022-02-14T06:55:30Z","6923" +"*/embedded/framework/msfdb-kali*",".{0,1000}\/embedded\/framework\/msfdb\-kali.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-omnibus","1","1","N/A","N/A","10","3","268","213","2025-04-18T13:17:56Z","2015-02-26T18:42:09Z","6924" +"*/EmbedInHTML.git*",".{0,1000}\/EmbedInHTML\.git.{0,1000}","offensive_tool_keyword","EmbedInHTML","What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.","T1027 - T1566.001","TA0005 - TA0002","N/A","N/A","Phishing","https://github.com/Arno0x/EmbedInHTML","1","1","N/A","N/A","10","5","485","119","2017-09-27T13:16:06Z","2017-09-11T07:17:20Z","6925" +"*/EmbedInHTML/*",".{0,1000}\/EmbedInHTML\/.{0,1000}","offensive_tool_keyword","EmbedInHTML","What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.","T1027 - T1566.001","TA0005 - TA0002","N/A","N/A","Phishing","https://github.com/Arno0x/EmbedInHTML","1","1","N/A","N/A","N/A","5","485","119","2017-09-27T13:16:06Z","2017-09-11T07:17:20Z","6926" +"*/emotet.profile*",".{0,1000}\/emotet\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","6927" +"*/Empire.git",".{0,1000}\/Empire\.git","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","6928" +"*/empire/client/*",".{0,1000}\/empire\/client\/.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","6929" +"*/empire:latest*",".{0,1000}\/empire\:latest.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","6930" +"*/empire_exec.py*",".{0,1000}\/empire_exec\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","6931" +"*/EmpireProject*",".{0,1000}\/EmpireProject.{0,1000}","offensive_tool_keyword","empire","The Empire Multiuser GUI is a graphical interface to the Empire post-exploitation Framework","T1059.003 - T1071.001 - T1543.003 - T1041 - T1562.001","TA0002 - TA0010 - TA0011 ","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire-GUI","1","1","N/A","N/A","10","5","495","146","2022-03-10T11:34:46Z","2018-04-20T21:59:52Z","6933" +"*/enable_all_tokens.exe*",".{0,1000}\/enable_all_tokens\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","6934" +"*/EnableAllMacros_AMSI.py*",".{0,1000}\/EnableAllMacros_AMSI\.py.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","6935" +"*/EnableAllMacros_AMSI.vba*",".{0,1000}\/EnableAllMacros_AMSI\.vba.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","6936" +"*/EnableAllTokenPrivs.exe*",".{0,1000}\/EnableAllTokenPrivs\.exe.{0,1000}","offensive_tool_keyword","EnableAllTokenPrivs","Enable or Disable TokenPrivilege(s)","T1134 - T1055","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/xvt-void/EnableAllTokenPrivs","1","1","N/A","N/A","7","1","13","5","2024-05-17T12:43:43Z","2024-02-17T15:39:25Z","6937" +"*/EnableAllTokenPrivs.git*",".{0,1000}\/EnableAllTokenPrivs\.git.{0,1000}","offensive_tool_keyword","EnableAllTokenPrivs","Enable or Disable TokenPrivilege(s)","T1134 - T1055","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/xvt-void/EnableAllTokenPrivs","1","1","N/A","N/A","7","1","13","5","2024-05-17T12:43:43Z","2024-02-17T15:39:25Z","6938" +"*/EnableAllTokenPrivs.ps1*",".{0,1000}\/EnableAllTokenPrivs\.ps1.{0,1000}","offensive_tool_keyword","EnableAllTokenPrivs","Enable or Disable TokenPrivilege(s)","T1134 - T1055","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/xvt-void/EnableAllTokenPrivs","1","1","N/A","N/A","7","1","13","5","2024-05-17T12:43:43Z","2024-02-17T15:39:25Z","6939" +"*/enable-defender.exe*",".{0,1000}\/enable\-defender\.exe.{0,1000}","offensive_tool_keyword","defender-control","An open-source windows defender manager. Now you can disable windows defender permanently","T1562.001 - T1562.004 - T1089","TA0005 - TA0002","N/A","LockBit","Defense Evasion","https://github.com/pgkt04/defender-control","1","1","N/A","N/A","10","10","1614","128","2023-09-09T14:57:56Z","2021-05-15T10:09:17Z","6940" +"*/enable-user.py*",".{0,1000}\/enable\-user\.py.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","6941" +"*/enableuser/enableuser.x64.*",".{0,1000}\/enableuser\/enableuser\.x64\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","6942" +"*/enableuser/enableuser.x86.*",".{0,1000}\/enableuser\/enableuser\.x86\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","6943" +"*/enc_shellcode.bin*",".{0,1000}\/enc_shellcode\.bin.{0,1000}","offensive_tool_keyword","ReflectiveNtdll","A Dropper POC with a focus on aiding in EDR evasion - NTDLL Unhooking followed by loading ntdll in-memory which is present as shellcode","T1059 - T1059.003 - T1218.011 - T1027 - T1027.005 - T1070 - T1070.004","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/reveng007/ReflectiveNtdll","1","1","N/A","N/A","10","2","170","24","2023-02-10T05:30:28Z","2023-01-30T08:43:16Z","6944" +"*/enc_shellcode.h*",".{0,1000}\/enc_shellcode\.h.{0,1000}","offensive_tool_keyword","ReflectiveNtdll","A Dropper POC with a focus on aiding in EDR evasion - NTDLL Unhooking followed by loading ntdll in-memory which is present as shellcode","T1059 - T1059.003 - T1218.011 - T1027 - T1027.005 - T1070 - T1070.004","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/reveng007/ReflectiveNtdll","1","1","N/A","N/A","10","2","170","24","2023-02-10T05:30:28Z","2023-01-30T08:43:16Z","6945" +"*/Encrypor-X.exe*",".{0,1000}\/Encrypor\-X\.exe.{0,1000}","offensive_tool_keyword","Rust-Malware-Samples","open source ransomware Encryfer in rust","T1486 - T1489 - T1485","TA0040 - TA0043 - TA0042","N/A","N/A","Ransomware","https://github.com/Whitecat18/Rust-for-Malware-Development/tree/main/Malware-Samples","1","1","N/A","N/A","10","10","2123","53","2025-04-22T18:09:57Z","2024-02-12T16:55:06Z","6947" +"*/EncryptedZIP.exe*",".{0,1000}\/EncryptedZIP\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","6948" +"*/encryption_aes.exe*",".{0,1000}\/encryption_aes\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","6949" +"*/encryption_rc4.exe*",".{0,1000}\/encryption_rc4\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","6950" +"*/endpoint_takeover.py*",".{0,1000}\/endpoint_takeover\.py.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","6951" +"*/enip-info.nse*",".{0,1000}\/enip\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6952" +"*/enum__secrets/*.py*",".{0,1000}\/enum__secrets\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","pacu","The AWS exploitation framework designed for testing the security of Amazon Web Services environments.","T1136.003 - T1190 - T1078.004","TA0006 - TA0001","N/A","Scattered Spider*","Framework","https://github.com/RhinoSecurityLabs/pacu","1","1","N/A","N/A","9","10","4651","731","2025-03-20T21:08:57Z","2018-06-13T21:58:59Z","6953" +"*/enum_av.md*",".{0,1000}\/enum_av\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6954" +"*/enum_av.py*",".{0,1000}\/enum_av\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","6955" +"*/enum_av.py*",".{0,1000}\/enum_av\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","6956" +"*/enum_cisco.md*",".{0,1000}\/enum_cisco\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6957" +"*/enum_dns.py*",".{0,1000}\/enum_dns\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","6958" +"*/enum_domain_info*",".{0,1000}\/enum_domain_info.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","6959" +"*/enum_f5.md*",".{0,1000}\/enum_f5\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6960" +"*/enum_juniper.md*",".{0,1000}\/enum_juniper\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6961" +"*/enum_osx.md*",".{0,1000}\/enum_osx\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6962" +"*/enum_proxy.md*",".{0,1000}\/enum_proxy\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6963" +"*/enum_services.md*",".{0,1000}\/enum_services\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6964" +"*/enum_shares.*",".{0,1000}\/enum_shares\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6965" +"*/enum_snmp.md*",".{0,1000}\/enum_snmp\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","6966" +"*/enum4linux.py*",".{0,1000}\/enum4linux\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","#linux","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","6967" +"*/EnumCLR.c*",".{0,1000}\/EnumCLR\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF to identify processes with the CLR loaded with a goal of identifying SpawnTo / injection candidates.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://gist.github.com/G0ldenGunSec/8ca0e853dd5637af2881697f8de6aecc","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","6968" +"*/enumerate.cna*",".{0,1000}\/enumerate\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script function and alias to perform some rudimentary Windows host enumeration with Beacon built-in commands","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/red-team-scripts","1","1","N/A","N/A","10","10","1122","195","2024-11-19T19:39:01Z","2017-05-01T13:53:05Z","6969" +"*/EnumerateDCs.ahk*",".{0,1000}\/EnumerateDCs\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","6971" +"*/enumeration/azureAd.py*",".{0,1000}\/enumeration\/azureAd\.py.{0,1000}","offensive_tool_keyword","Vajra","Vajra is a UI based tool with multiple techniques for attacking and enumerating in target's Azure environment","T1087 - T1098 - T1583 - T1078 - T1110 - T1566 - T1537 - T1020 - T1526 - T1482","TA0003 - TA0006 - TA0007 - TA0008 - TA0009","N/A","N/A","Exploitation tool","https://github.com/TROUBLE-1/Vajra","1","1","N/A","N/A","N/A","4","391","61","2025-02-21T16:40:23Z","2022-03-01T14:31:27Z","6972" +"*/enumeration/azureAzService.py*",".{0,1000}\/enumeration\/azureAzService\.py.{0,1000}","offensive_tool_keyword","Vajra","Vajra is a UI based tool with multiple techniques for attacking and enumerating in target's Azure environment","T1087 - T1098 - T1583 - T1078 - T1110 - T1566 - T1537 - T1020 - T1526 - T1482","TA0003 - TA0006 - TA0007 - TA0008 - TA0009","N/A","N/A","Exploitation tool","https://github.com/TROUBLE-1/Vajra","1","1","N/A","N/A","N/A","4","391","61","2025-02-21T16:40:23Z","2022-03-01T14:31:27Z","6973" +"*/enumeration/subdomain.py*",".{0,1000}\/enumeration\/subdomain\.py.{0,1000}","offensive_tool_keyword","Vajra","Vajra is a UI based tool with multiple techniques for attacking and enumerating in target's Azure environment","T1087 - T1098 - T1583 - T1078 - T1110 - T1566 - T1537 - T1020 - T1526 - T1482","TA0003 - TA0006 - TA0007 - TA0008 - TA0009","N/A","N/A","Exploitation tool","https://github.com/TROUBLE-1/Vajra","1","1","N/A","N/A","N/A","4","391","61","2025-02-21T16:40:23Z","2022-03-01T14:31:27Z","6974" +"*/enumeration/userenum.py*",".{0,1000}\/enumeration\/userenum\.py.{0,1000}","offensive_tool_keyword","Vajra","Vajra is a UI based tool with multiple techniques for attacking and enumerating in target's Azure environment","T1087 - T1098 - T1583 - T1078 - T1110 - T1566 - T1537 - T1020 - T1526 - T1482","TA0003 - TA0006 - TA0007 - TA0008 - TA0009","N/A","N/A","Exploitation tool","https://github.com/TROUBLE-1/Vajra","1","1","N/A","N/A","N/A","4","391","61","2025-02-21T16:40:23Z","2022-03-01T14:31:27Z","6975" +"*/enumeration_process.exe*",".{0,1000}\/enumeration_process\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","6976" +"*/epmd-info.nse*",".{0,1000}\/epmd\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6977" +"*/eppc-enum-processes.nse*",".{0,1000}\/eppc\-enum\-processes\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6978" +"*/Erebus/*.dll*",".{0,1000}\/Erebus\/.{0,1000}\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Erebus CobaltStrike post penetration testing plugin","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DeEpinGh0st/Erebus","1","1","N/A","N/A","10","10","1518","221","2021-10-28T06:20:51Z","2019-09-26T09:32:00Z","6985" +"*/Erebus/*.exe*",".{0,1000}\/Erebus\/.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Erebus CobaltStrike post penetration testing plugin","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DeEpinGh0st/Erebus","1","1","N/A","N/A","10","10","1518","221","2021-10-28T06:20:51Z","2019-09-26T09:32:00Z","6986" +"*/Erebus-email.*",".{0,1000}\/Erebus\-email\..{0,1000}","offensive_tool_keyword","cobaltstrike","Erebus CobaltStrike post penetration testing plugin","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DeEpinGh0st/Erebus","1","1","N/A","N/A","10","10","1518","221","2021-10-28T06:20:51Z","2019-09-26T09:32:00Z","6987" +"*/esentutl.py*",".{0,1000}\/esentutl\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","6988" +"*/EternalHushCore.dll*",".{0,1000}\/EternalHushCore\.dll.{0,1000}","offensive_tool_keyword","EternalHushFramework","EternalHush Framework is a new open source project that is an advanced C&C framework. Designed specifically for Windows operating systems","T1071.001 - T1132.001 - T1059.003 - T1547.001","TA0011 - TA0005 - TA0010 - TA0002","N/A","Equation Group","C2","https://github.com/APT64/EternalHushFramework","1","1","N/A","N/A","10","10","11","1","2023-10-28T13:08:06Z","2023-07-09T09:13:21Z","7038" +"*/EternalHushFramework.git*",".{0,1000}\/EternalHushFramework\.git.{0,1000}","offensive_tool_keyword","EternalHushFramework","EternalHush Framework is a new open source project that is an advanced C&C framework. Designed specifically for Windows operating systems","T1071.001 - T1132.001 - T1059.003 - T1547.001","TA0011 - TA0005 - TA0010 - TA0002","N/A","Equation Group","C2","https://github.com/APT64/EternalHushFramework","1","1","N/A","N/A","10","10","11","1","2023-10-28T13:08:06Z","2023-07-09T09:13:21Z","7039" +"*/etumbot.profile*",".{0,1000}\/etumbot\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","7040" +"*/etw.cna",".{0,1000}\/etw\.cna","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","7041" +"*/etw.x64.*",".{0,1000}\/etw\.x64\..{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","7042" +"*/etw.x86.*",".{0,1000}\/etw\.x86\..{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","7043" +"*/etw-fuck.cpp*",".{0,1000}\/etw\-fuck\.cpp.{0,1000}","offensive_tool_keyword","Fuck-Etw","Bypass the Event Trace Windows(ETW) and unhook ntdll.","T1070.004 - T1055.001","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/unkvolism/Fuck-Etw","1","1","N/A","N/A","10","2","102","13","2023-09-29T21:19:10Z","2023-09-25T18:59:10Z","7044" +"*/etw-fuck.exe*",".{0,1000}\/etw\-fuck\.exe.{0,1000}","offensive_tool_keyword","Fuck-Etw","Bypass the Event Trace Windows(ETW) and unhook ntdll.","T1070.004 - T1055.001","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/unkvolism/Fuck-Etw","1","1","N/A","N/A","10","2","102","13","2023-09-29T21:19:10Z","2023-09-25T18:59:10Z","7045" +"*/ETWHash/*",".{0,1000}\/ETWHash\/.{0,1000}","offensive_tool_keyword","ETWHash","C# POC to extract NetNTLMv1/v2 hashes from ETW provider","T1556.001","TA0009 ","N/A","N/A","Credential Access","https://github.com/nettitude/ETWHash","1","1","N/A","N/A","N/A","3","256","29","2023-05-10T06:45:06Z","2023-04-26T15:53:01Z","7046" +"*/etwunhook.cpp*",".{0,1000}\/etwunhook\.cpp.{0,1000}","offensive_tool_keyword","etwunhook","Simple ETW unhook PoC. Overwrites NtTraceEvent opcode to disable ETW at Nt-function level.","T1055 - T1562.001","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/Meowmycks/etwunhook","1","1","N/A","N/A","9","1","47","11","2024-02-29T10:07:52Z","2024-01-22T22:21:09Z","7047" +"*/etwunhook.exe*",".{0,1000}\/etwunhook\.exe.{0,1000}","offensive_tool_keyword","etwunhook","Simple ETW unhook PoC. Overwrites NtTraceEvent opcode to disable ETW at Nt-function level.","T1055 - T1562.001","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/Meowmycks/etwunhook","1","1","N/A","N/A","9","1","47","11","2024-02-29T10:07:52Z","2024-01-22T22:21:09Z","7048" +"*/etwunhook.git*",".{0,1000}\/etwunhook\.git.{0,1000}","offensive_tool_keyword","etwunhook","Simple ETW unhook PoC. Overwrites NtTraceEvent opcode to disable ETW at Nt-function level.","T1055 - T1562.001","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/Meowmycks/etwunhook","1","1","N/A","N/A","9","1","47","11","2024-02-29T10:07:52Z","2024-01-22T22:21:09Z","7049" +"*/evasion/evasion.go",".{0,1000}\/evasion\/evasion\.go","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","7050" +"*/evasion_linux.go*",".{0,1000}\/evasion_linux\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","#linux","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","7052" +"*/evasion_windows.go*",".{0,1000}\/evasion_windows\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","7053" +"*/EventCleaner.cpp*",".{0,1000}\/EventCleaner\.cpp.{0,1000}","offensive_tool_keyword","EventCleaner","erase specified records from Windows event logs","T1070.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/QAX-A-Team/EventCleaner","1","1","N/A","N/A","10","6","599","148","2018-09-07T11:02:01Z","2018-07-27T07:37:32Z","7054" +"*/EventCleaner.exe*",".{0,1000}\/EventCleaner\.exe.{0,1000}","offensive_tool_keyword","EventCleaner","erase specified records from Windows event logs","T1070.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/QAX-A-Team/EventCleaner","1","1","N/A","N/A","10","6","599","148","2018-09-07T11:02:01Z","2018-07-27T07:37:32Z","7055" +"*/EventCleaner.git*",".{0,1000}\/EventCleaner\.git.{0,1000}","offensive_tool_keyword","EventCleaner","erase specified records from Windows event logs","T1070.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/QAX-A-Team/EventCleaner","1","1","N/A","N/A","10","6","599","148","2018-09-07T11:02:01Z","2018-07-27T07:37:32Z","7056" +"*/EventLogCrasher.git*",".{0,1000}\/EventLogCrasher\.git.{0,1000}","offensive_tool_keyword","EventLogCrasher","crash the Windows Event Log service of any other Windows 10/Windows Server 2022 machine on the same domain","T1562.002 - T1489","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/floesen/EventLogCrasher","1","1","N/A","N/A","10","2","186","34","2024-01-23T14:04:23Z","2024-01-23T09:27:27Z","7057" +"*/EventLogCredentials.ps1*",".{0,1000}\/EventLogCredentials\.ps1.{0,1000}","offensive_tool_keyword","EventLogMaster","Cobalt Strike Plugin - RDP Log Forensics & Clearing","T1070.001 - T1070.003 - T1070.004 - T1563.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/QAX-A-Team/EventLogMaster","1","1","N/A","N/A","6","4","361","73","2019-12-23T10:31:35Z","2019-12-17T05:07:09Z","7058" +"*/Eventlogedit-evt--General.git*",".{0,1000}\/Eventlogedit\-evt\-\-General\.git.{0,1000}","offensive_tool_keyword","Eventlogedit-evt--General","Remove individual lines from Windows Event Viewer Log (EVT) files","T1070.001 - T1564.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/3gstudent/Eventlogedit-evt--General","1","1","N/A","N/A","9","1","44","9","2021-04-17T01:36:42Z","2018-07-23T01:19:03Z","7059" +"*/Eventlogedit-evtx--Evolution.git*",".{0,1000}\/Eventlogedit\-evtx\-\-Evolution\.git.{0,1000}","offensive_tool_keyword","Eventlogedit-evtx--Evolution","","T1070.001 - T1564.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/3gstudent/Eventlogedit-evtx--Evolution","1","1","N/A","N/A","9","3","267","62","2021-04-17T01:28:00Z","2018-06-05T01:21:20Z","7060" +"*/EventLogMaster.git*",".{0,1000}\/EventLogMaster\.git.{0,1000}","offensive_tool_keyword","EventLogMaster","Cobalt Strike Plugin - RDP Log Forensics & Clearing","T1070.001 - T1070.003 - T1070.004 - T1563.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/QAX-A-Team/EventLogMaster","1","1","N/A","N/A","6","4","361","73","2019-12-23T10:31:35Z","2019-12-17T05:07:09Z","7061" +"*/EventViewerUAC/*",".{0,1000}\/EventViewerUAC\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File implementation of Event Viewer deserialization UAC bypass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/TrustedPath-UACBypass-BOF","1","1","N/A","N/A","10","10","133","40","2021-08-16T07:49:55Z","2021-08-07T03:40:33Z","7062" +"*/EventViewerUAC/*",".{0,1000}\/EventViewerUAC\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File implementation of Event Viewer deserialization UAC bypass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Octoberfest7/EventViewerUAC_BOF","1","1","N/A","N/A","10","10","131","31","2022-05-06T17:43:05Z","2022-05-02T02:08:52Z","7063" +"*/EventViewer-UACBypass*",".{0,1000}\/EventViewer\-UACBypass.{0,1000}","offensive_tool_keyword","EventViewer-UACBypass","RCE through Unsafe .Net Deserialization in Windows Event Viewer which leads to UAC bypass","T1078.004 - T1216 - T1068","TA0004 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/CsEnox/EventViewer-UACBypass","1","1","N/A","N/A","10","2","184","21","2022-04-29T09:42:37Z","2022-04-27T12:56:59Z","7064" +"*/evi1m0.bat*",".{0,1000}\/evi1m0\.bat.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","7065" +"*/evil.cpp*",".{0,1000}\/evil\.cpp.{0,1000}","offensive_tool_keyword","cobaltstrike","CS anti-killing including python version and C version","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Gality369/CS-Loader","1","1","N/A","N/A","10","10","829","141","2025-04-02T09:37:10Z","2020-08-17T21:33:06Z","7066" +"*/evil.ps1*",".{0,1000}\/evil\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","7068" +"*/evil_pdf/*",".{0,1000}\/evil_pdf\/.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","7069" +"*/evil_script.py*",".{0,1000}\/evil_script\.py.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","7071" +"*/EvilClippy*",".{0,1000}\/EvilClippy.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","7072" +"*/EvilClippy-*.zip*",".{0,1000}\/EvilClippy\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","EvilClippy","A cross-platform assistant for creating malicious MS Office documents","T1566.001 - T1059.001 - T1204.002","TA0004 - TA0002","N/A","N/A","Phishing","https://github.com/outflanknl/EvilClippy","1","1","N/A","N/A","10","10","2165","402","2023-12-27T12:37:47Z","2019-03-26T12:14:03Z","7073" +"*/evilclippy.cs*",".{0,1000}\/evilclippy\.cs.{0,1000}","offensive_tool_keyword","EvilClippy","A cross-platform assistant for creating malicious MS Office documents","T1566.001 - T1059.001 - T1204.002","TA0004 - TA0002","N/A","N/A","Phishing","https://github.com/outflanknl/EvilClippy","1","1","N/A","N/A","10","10","2165","402","2023-12-27T12:37:47Z","2019-03-26T12:14:03Z","7074" +"*/EvilClippy.git*",".{0,1000}\/EvilClippy\.git.{0,1000}","offensive_tool_keyword","EvilClippy","A cross-platform assistant for creating malicious MS Office documents","T1566.001 - T1059.001 - T1204.002","TA0004 - TA0002","N/A","N/A","Phishing","https://github.com/outflanknl/EvilClippy","1","1","N/A","N/A","10","10","2165","402","2023-12-27T12:37:47Z","2019-03-26T12:14:03Z","7075" +"*/evilginx*",".{0,1000}\/evilginx.{0,1000}","offensive_tool_keyword","gophish","Combination of evilginx2 and GoPhish","T1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113","TA0002 - TA0003","N/A","Black Basta","Phishing","https://github.com/fin3ss3g0d/evilgophish","1","1","N/A","N/A","10","10","1762","340","2024-06-15T17:48:11Z","2022-09-07T02:47:43Z","7076" +"*/evilginx2.git*",".{0,1000}\/evilginx2\.git.{0,1000}","offensive_tool_keyword","evilginx2","Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication","T1557.002 - T1114 - T1539","TA0001","N/A","BlackCat - COLDRIVER","Phishing","https://github.com/kgretzky/evilginx2","1","1","N/A","N/A","10","10","12879","2234","2025-01-21T15:16:19Z","2018-07-10T09:59:52Z","7077" +"*/evilginx2/*",".{0,1000}\/evilginx2\/.{0,1000}","offensive_tool_keyword","evilginx2","Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication","T1557.002 - T1114 - T1539","TA0001","N/A","BlackCat - COLDRIVER","Phishing","https://github.com/kgretzky/evilginx2","1","1","#linux","N/A","10","10","12879","2234","2025-01-21T15:16:19Z","2018-07-10T09:59:52Z","7078" +"*/evilhost:*",".{0,1000}\/evilhost\:.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-JBoss.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","7079" +"*/EvilLsassTwin*",".{0,1000}\/EvilLsassTwin.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","7080" +"*/EvilLsassTwin/*",".{0,1000}\/EvilLsassTwin\/.{0,1000}","offensive_tool_keyword","EvilLsassTwin","attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.","T1003.001 - T1055 - T1093","TA0006 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","9","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","7081" +"*/EvilnoVNC.git*",".{0,1000}\/EvilnoVNC\.git.{0,1000}","offensive_tool_keyword","EvilnoVNC","EvilnoVNC is a Ready to go Phishing Platform","T1566 - T1110 - T1555 - T1204 - T1592","TA0001 - TA0006 - TA0009","N/A","N/A","Phishing","https://github.com/JoelGMSec/EvilnoVNC","1","1","N/A","N/A","9","10","960","169","2025-03-04T15:59:27Z","2022-09-04T10:48:49Z","7082" +"*/evil-proxy.git*",".{0,1000}\/evil\-proxy\.git.{0,1000}","offensive_tool_keyword","evil-proxy","A ruby http/https proxy to do EVIL things","T1557 - T1110.001 - T1563.001","TA0006 - TA0001 - TA0009 - TA0040","N/A","N/A","Phishing","https://github.com/bbtfr/evil-proxy","1","1","N/A","N/A","9","2","172","96","2023-10-30T07:49:40Z","2015-07-30T01:54:40Z","7083" +"*/evil-proxy.rb*",".{0,1000}\/evil\-proxy\.rb.{0,1000}","offensive_tool_keyword","evil-proxy","A ruby http/https proxy to do EVIL things","T1557 - T1110.001 - T1563.001","TA0006 - TA0001 - TA0009 - TA0040","N/A","N/A","Phishing","https://github.com/bbtfr/evil-proxy","1","1","N/A","N/A","9","2","172","96","2023-10-30T07:49:40Z","2015-07-30T01:54:40Z","7084" +"*/evilqr.git*",".{0,1000}\/evilqr\.git.{0,1000}","offensive_tool_keyword","evilqr","Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice","T1566.002 - T1204.001 - T1192","TA0001 - TA0005","N/A","N/A","Phishing","https://github.com/kgretzky/evilqr","1","1","N/A","N/A","N/A","3","292","45","2024-06-18T11:27:23Z","2023-06-20T12:58:09Z","7086" +"*/evilrdp.git*",".{0,1000}\/evilrdp\.git.{0,1000}","offensive_tool_keyword","evilrdp","Th evil twin of aardwolfgui using the aardwolf RDP client library that gives you extended control over the target and additional scripting capabilities from the command line.","T1021.001 - T1056.001 - T1113 - T1078.002 - T1105 - T1090.002 - T1059.001","TA0008 - TA0002 - TA0005 - TA0001 - TA0009 - TA0010 - TA0011","N/A","Black Basta","C2","https://github.com/skelsec/evilrdp","1","1","N/A","N/A","10","10","299","31","2025-03-15T13:37:21Z","2023-11-29T13:44:58Z","7087" +"*/evilrdp/*",".{0,1000}\/evilrdp\/.{0,1000}","offensive_tool_keyword","evilrdp","Th evil twin of aardwolfgui using the aardwolf RDP client library that gives you extended control over the target and additional scripting capabilities from the command line.","T1021.001 - T1056.001 - T1113 - T1078.002 - T1105 - T1090.002 - T1059.001","TA0008 - TA0002 - TA0005 - TA0001 - TA0009 - TA0010 - TA0011","N/A","Black Basta","C2","https://github.com/skelsec/evilrdp","1","1","N/A","N/A","10","10","299","31","2025-03-15T13:37:21Z","2023-11-29T13:44:58Z","7088" +"*/evilscript.ps1*",".{0,1000}\/evilscript\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","7089" +"*/evilscript.ps1*",".{0,1000}\/evilscript\.ps1.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","7090" +"*/evilSignatures.db*",".{0,1000}\/evilSignatures\.db.{0,1000}","offensive_tool_keyword","EDRaser","EDRaser is a powerful tool for remotely deleting access logs & Windows event logs & databases and other files on remote machines.","T1070.004 - T1027 - T1564.001","TA0005 - TA0040 - TA0003","N/A","N/A","Defense Evasion","https://github.com/SafeBreach-Labs/EDRaser","1","1","N/A","N/A","10","4","363","49","2024-04-06T17:42:40Z","2023-08-10T04:30:45Z","7091" +"*/EvilSln.git*",".{0,1000}\/EvilSln\.git.{0,1000}","offensive_tool_keyword","EvilSln","A New Exploitation Technique for Visual Studio Projects","T1564.001 - T1204.002","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/cjm00n/EvilSln","1","1","N/A","N/A","10","5","N/A","N/A","N/A","N/A","7092" +"*/EvilSln/*.suo*",".{0,1000}\/EvilSln\/.{0,1000}\.suo.{0,1000}","offensive_tool_keyword","EvilSln","A New Exploitation Technique for Visual Studio Projects","T1564.001 - T1204.002","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/cjm00n/EvilSln","1","1","N/A","N/A","10","","N/A","","","","7093" +"*/EvilTwinServer*",".{0,1000}\/EvilTwinServer.{0,1000}","offensive_tool_keyword","EvilLsassTwin","attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.","T1003.001 - T1055 - T1093","TA0006 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","9","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","7094" +"*/EvtMute.git*",".{0,1000}\/EvtMute\.git.{0,1000}","offensive_tool_keyword","EvtMute","This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging - mute the event log","T1562.004 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/bats3c/EvtMute","1","1","N/A","N/A","10","3","261","51","2021-04-24T19:23:39Z","2020-08-29T00:13:20Z","7095" +"*/Example_C2_Profile*",".{0,1000}\/Example_C2_Profile.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","7101" +"*/Example_Payload_Type/*",".{0,1000}\/Example_Payload_Type\/.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","7102" +"*/ExcelDocWriter.cs*",".{0,1000}\/ExcelDocWriter\.cs.{0,1000}","offensive_tool_keyword","Macrome","An Excel Macro Document Reader/Writer for Red Teamers & Analysts. Blog posts describing what this tool actually does can be found https://malware.pizza/2020/05/12/evading-av-with-excel-macros-and-biff8-xls/ and https://malware.pizza/2020/06/19/further-evasion-in-the-forgotten-corners-of-ms-xls/","T1140","TA0005","N/A","N/A","Exploitation tool","https://github.com/michaelweber/Macrome","1","1","N/A","N/A","N/A","6","520","79","2022-02-01T16:26:13Z","2020-05-07T22:44:11Z","7103" +"*/exchanger.py*",".{0,1000}\/exchanger\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7105" +"*/exe_to_dll.git*",".{0,1000}\/exe_to_dll\.git.{0,1000}","offensive_tool_keyword","exe_to_dll","Converts a EXE into DLL","T1027.004 - T1059.001","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/hasherezade/exe_to_dll","1","1","N/A","N/A","5","10","1297","197","2023-07-26T11:41:27Z","2020-04-16T16:27:00Z","7106" +"*/exe_to_dll.git*",".{0,1000}\/exe_to_dll\.git.{0,1000}","offensive_tool_keyword","exe_to_dll","Converts an EXE so that it can be loaded like a DLL.","T1055.002 - T1073.001 - T1027","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/hasherezade/exe_to_dll","1","1","N/A","N/A","8","10","1297","197","2023-07-26T11:41:27Z","2020-04-16T16:27:00Z","7107" +"*/exe2powershell*",".{0,1000}\/exe2powershell.{0,1000}","offensive_tool_keyword","exe2powershell","exe2powershell is used to convert any binary file to a bat/powershell file","T1059.001 - T1027.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/yanncam/exe2powershell","1","1","N/A","N/A","6","2","172","44","2020-10-15T08:22:30Z","2016-03-02T11:23:32Z","7108" +"*/exec_bin.c*",".{0,1000}\/exec_bin\.c.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","7109" +"*/exec_diskshadow.py*",".{0,1000}\/exec_diskshadow\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","7110" +"*/exec_dll.c*",".{0,1000}\/exec_dll\.c.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","7111" +"*/exec_ftp.py*",".{0,1000}\/exec_ftp\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","7112" +"*/exec_pcalua.py*",".{0,1000}\/exec_pcalua\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","7113" +"*/exec_psexec*",".{0,1000}\/exec_psexec.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","7114" +"*/exec_psh.c*",".{0,1000}\/exec_psh\.c.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","7115" +"*/exec_shdocvw.py*",".{0,1000}\/exec_shdocvw\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","7116" +"*/exec_wmi*",".{0,1000}\/exec_wmi.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","7117" +"*/exec0.py*",".{0,1000}\/exec0\.py.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","7118" +"*/Executable_Files.git*",".{0,1000}\/Executable_Files\.git.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","7119" +"*/execute_shellcode.exe*",".{0,1000}\/execute_shellcode\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","7120" +"*/execute-api.eu-central-1.amazonaws.com/catspin_deployed*",".{0,1000}\/execute\-api\.eu\-central\-1\.amazonaws\.com\/catspin_deployed.{0,1000}","offensive_tool_keyword","catspin","Catspin rotates the IP address of HTTP requests making IP based blocks or slowdown measures ineffective. It is based on AWS API Gateway and deployed via AWS Cloudformation.","T1027 - T1071 - T1047 - T1090","TA0042 - TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/rootcathacking/catspin","1","1","N/A","N/A","9","3","261","32","2024-03-01T09:25:02Z","2022-07-26T08:08:33Z","7121" +"*/ExecuteCommand_x64_Release.exe*",".{0,1000}\/ExecuteCommand_x64_Release\.exe.{0,1000}","offensive_tool_keyword","Tsunami","another C2 framework","T1573 - T1027 - T1059 - T1071 ","TA0011 - TA0009 - TA0003 - TA0007 - TA0008","N/A","N/A","C2","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","7122" +"*/Exegol-images-*.zip*",".{0,1000}\/Exegol\-images\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","7128" +"*/Exegol-images.git*",".{0,1000}\/Exegol\-images\.git.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","7129" +"*/ExeStager/*",".{0,1000}\/ExeStager\/.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","7130" +"*/exetotext.ps1*",".{0,1000}\/exetotext\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","7131" +"*/exfilGui.ps1*",".{0,1000}\/exfilGui\.ps1.{0,1000}","offensive_tool_keyword","DataBouncing","Data Bouncing is a technique for transmitting data between two endpoints using DNS lookups and HTTP header manipulation","T1048 - T1041","TA0010","N/A","N/A","Data Exfiltration","https://github.com/Unit-259/DataBouncing","1","1","N/A","N/A","9","1","15","0","2025-03-12T07:34:04Z","2025-03-12T06:58:51Z","7132" +"*/exocet.elf*",".{0,1000}\/exocet\.elf.{0,1000}","offensive_tool_keyword","EXOCET-AV-Evasion","EXOCET - AV-evading undetectable payload delivery tool","T1055 - T1218.011 - T1027.009 - T1027 - T1105 - T1102.001","TA0005 - TA0001 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/tanc7/EXOCET-AV-Evasion","1","1","N/A","N/A","10","9","840","147","2022-08-16T02:58:39Z","2020-07-15T06:55:13Z","7134" +"*/exocet.exe*",".{0,1000}\/exocet\.exe.{0,1000}","offensive_tool_keyword","EXOCET-AV-Evasion","EXOCET - AV-evading undetectable payload delivery tool","T1055 - T1218.011 - T1027.009 - T1027 - T1105 - T1102.001","TA0005 - TA0001 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/tanc7/EXOCET-AV-Evasion","1","1","N/A","N/A","10","9","840","147","2022-08-16T02:58:39Z","2020-07-15T06:55:13Z","7135" +"*/EXOCET-AV-Evasion.git*",".{0,1000}\/EXOCET\-AV\-Evasion\.git.{0,1000}","offensive_tool_keyword","EXOCET-AV-Evasion","EXOCET - AV-evading undetectable payload delivery tool","T1055 - T1218.011 - T1027.009 - T1027 - T1105 - T1102.001","TA0005 - TA0001 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/tanc7/EXOCET-AV-Evasion","1","1","N/A","N/A","10","9","840","147","2022-08-16T02:58:39Z","2020-07-15T06:55:13Z","7136" +"*/expl/expl.go*",".{0,1000}\/expl\/expl\.go.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirtycow vulnerability","T1533","TA0003","N/A","N/A","Exploitation tool","https://github.com/gbonacini/CVE-2016-5195","1","1","N/A","N/A","N/A","4","326","121","2017-03-21T16:46:38Z","2016-10-23T00:16:33Z","7137" +"*/exploit.cron.sh*",".{0,1000}\/exploit\.cron\.sh.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","7138" +"*/exploit.dll*",".{0,1000}\/exploit\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","7139" +"*/exploit.exe*",".{0,1000}\/exploit\.exe.{0,1000}","offensive_tool_keyword","shad0w","A post exploitation framework designed to operate covertly on heavily monitored environments","T1071 - T1090 - T1105 - T1571 - T1001","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/bats3c/shad0w","1","1","N/A","N/A","N/A","10","2090","332","2021-09-29T00:15:36Z","2020-04-28T16:42:07Z","7140" +"*/exploit.ldpreload.sh*",".{0,1000}\/exploit\.ldpreload\.sh.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","7141" +"*/exploit.pbj*",".{0,1000}\/exploit\.pbj.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","7142" +"*/exploit/linux/*",".{0,1000}\/exploit\/linux\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","#linux","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","7143" +"*/exploit/nc.exe*",".{0,1000}\/exploit\/nc\.exe.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","7144" +"*/exploit/remote/*",".{0,1000}\/exploit\/remote\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","7145" +"*/exploit/windows/*",".{0,1000}\/exploit\/windows\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","7146" +"*/exploit_orw.py*",".{0,1000}\/exploit_orw\.py.{0,1000}","offensive_tool_keyword","Exrop","Exrop is automatic ROP chains generator tool which can build gadget chain automatically from given binary and constraints","T1554","TA0003","N/A","N/A","Exploitation tool","https://github.com/d4em0n/exrop","1","1","N/A","N/A","N/A","3","285","22","2020-02-21T08:01:06Z","2020-01-19T05:09:00Z","7147" +"*/exploit_suggester.py*",".{0,1000}\/exploit_suggester\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","7148" +"*/exports_function_hid.txt*",".{0,1000}\/exports_function_hid\.txt.{0,1000}","offensive_tool_keyword","cobaltstrike","New Lateral Movement technique by abusing Windows Perception Simulation Service to achieve DLL hijacking code execution.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/ServiceMove-BOF","1","1","N/A","N/A","10","10","291","48","2022-02-23T07:17:38Z","2021-08-16T07:16:31Z","7150" +"*/extension_injection.sh*",".{0,1000}\/extension_injection\.sh.{0,1000}","offensive_tool_keyword","CursedChrome","Chrome-extension implant that turns victim Chrome browsers into fully-functional HTTP proxies allowing you to browse sites as your victims","T1176 - T1219 - T1090","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/mandatoryprogrammer/CursedChrome","1","1","N/A","on forked repo","10","10","1533","226","2024-10-26T19:06:54Z","2020-04-26T20:55:05Z","7153" +"*/ExtensionSpoof.exe*",".{0,1000}\/ExtensionSpoof\.exe.{0,1000}","offensive_tool_keyword","ExtensionSpoofer","Spoof file icons and extensions in Windows","T1036 - T1027.005 - T1218","TA0005 - TA0040","N/A","N/A","Phishing","https://github.com/henriksb/ExtensionSpoofer","1","1","N/A","N/A","9","2","179","65","2024-12-12T18:05:28Z","2017-11-11T16:02:17Z","7155" +"*/ExtensionSpoofer.git*",".{0,1000}\/ExtensionSpoofer\.git.{0,1000}","offensive_tool_keyword","ExtensionSpoofer","Spoof file icons and extensions in Windows","T1036 - T1027.005 - T1218","TA0005 - TA0040","N/A","N/A","Phishing","https://github.com/henriksb/ExtensionSpoofer","1","1","N/A","N/A","9","2","179","65","2024-12-12T18:05:28Z","2017-11-11T16:02:17Z","7156" +"*/ExternalC2/*",".{0,1000}\/ExternalC2\/.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","7157" +"*/ExternalC2/*",".{0,1000}\/ExternalC2\/.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","7158" +"*/extpassword.zip*",".{0,1000}\/extpassword\.zip.{0,1000}","offensive_tool_keyword","ExtPassword.exe","Nirsoft tool for Windows that allows you to recover passwords stored on external drive plugged to your computer","T1081 - T1003 - T1212","TA0006 - TA0009","N/A","LockBit","Credential Access","https://www.nirsoft.net/utils/external_drive_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","7159" +"*/extract_wifi.exe*",".{0,1000}\/extract_wifi\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","7160" +"*/ExtractBitlockerKeys.git*",".{0,1000}\/ExtractBitlockerKeys\.git.{0,1000}","offensive_tool_keyword","ExtractBitlockerKeys","A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.","T1003.002 - T1039 - T1087.002","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/p0dalirius/ExtractBitlockerKeys","1","1","N/A","N/A","10","4","368","54","2025-01-31T09:39:55Z","2023-09-19T07:28:11Z","7161" +"*/Exymna RAT.exe*",".{0,1000}\/Exymna\sRAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","7162" +"*/Fa1c0n35/zabbix-cve-2022-23131*",".{0,1000}\/Fa1c0n35\/zabbix\-cve\-2022\-23131.{0,1000}","offensive_tool_keyword","POC","POC exploitaiton of zabbix saml bypass exp vulnerability cve-2022-23131 (Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML)","T1548 - T1190","TA0006 - TA0008","N/A","N/A","Exploitation tool","https://github.com/trganda/CVE-2022-23131","1","1","N/A","N/A","N/A","1","1","1","2022-02-24T11:50:28Z","2022-02-24T08:10:46Z","7164" +"*/Fake Error Message RAT.exe*",".{0,1000}\/Fake\sError\sMessage\sRAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","7165" +"*/fake.html",".{0,1000}\/fake\.html","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","7166" +"*/FakeCmdLine*",".{0,1000}\/FakeCmdLine.{0,1000}","offensive_tool_keyword","FakeCmdLine","Simple demonstration (C source code and compiled .exe) of a less-known (but documented) behavior of CreateProcess() function. Effectively you can put any string into the child process Command Line field.","T1059 - T1036","TA0003","N/A","N/A","Defense Evasion","https://github.com/gtworek/PSBits/tree/master/FakeCmdLine","1","1","N/A","N/A","N/A","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","7167" +"*/FakeLogonScreen.exe*",".{0,1000}\/FakeLogonScreen\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","7168" +"*/fakelogonscreen.exe*",".{0,1000}\/fakelogonscreen.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","7169" +"*/fakelogonscreen.git*",".{0,1000}\/fakelogonscreen\.git.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","7170" +"*/fakelogonscreen/releases/download/*",".{0,1000}\/fakelogonscreen\/releases\/download\/.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","7171" +"*/fakelogonscreen/tarball/*",".{0,1000}\/fakelogonscreen\/tarball\/.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","7172" +"*/fakelogonscreen/zipball/*",".{0,1000}\/fakelogonscreen\/zipball\/.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","7173" +"*/fake-sms.git*",".{0,1000}\/fake\-sms\.git.{0,1000}","offensive_tool_keyword","fake-sms","A simple command line tool using which you can skip phone number based SMS verification by using a temporary phone number that acts like a proxy.","T1598.003 - T1514","TA0003 - TA0009","N/A","N/A","Defense Evasion","https://github.com/Narasimha1997/fake-sms","1","1","N/A","N/A","8","10","2745","176","2023-08-01T15:34:41Z","2021-02-18T15:18:50Z","7174" +"*/fakewarning.dll*",".{0,1000}\/fakewarning\.dll.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","7175" +"*/Farmer.git*",".{0,1000}\/Farmer\.git.{0,1000}","offensive_tool_keyword","Farmer","Farmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.","T1557.001 - T1056.004 - T1078.003","TA0006 - TA0004 - TA0001","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/Farmer","1","1","N/A","N/A","10","4","379","61","2021-04-28T15:27:24Z","2021-02-22T14:32:29Z","7176" +"*/fastfuz-chrome-ext*",".{0,1000}\/fastfuz\-chrome\-ext.{0,1000}","offensive_tool_keyword","fastfuzz","Fast fuzzing websites with chrome extension","T1110","TA0006","N/A","N/A","Vulnerability Scanner","https://github.com/tismayil/fastfuz-chrome-ext","1","1","N/A","N/A","N/A","1","25","5","2022-02-04T02:15:51Z","2022-02-04T00:22:51Z","7177" +"*/FastPathMITM.py*",".{0,1000}\/FastPathMITM\.py.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","#linux","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","7178" +"*/fb_firstlast.7z*",".{0,1000}\/fb_firstlast\.7z.{0,1000}","offensive_tool_keyword","wordlists","Various wordlists FR & EN - Cracking French passwords","T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/clem9669/wordlists","1","1","N/A","N/A","N/A","3","280","45","2025-04-22T14:34:10Z","2020-10-21T14:37:53Z","7179" +"*/fb-brute.pl*",".{0,1000}\/fb\-brute\.pl.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://raw.githubusercontent.com/Sup3r-Us3r/scripts/master/fb-brute.pl","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","7180" +"*/fcrdns.nse*",".{0,1000}\/fcrdns\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7181" +"*/febinrev/dirtypipez-exploit*",".{0,1000}\/febinrev\/dirtypipez\-exploit.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1533","TA0003","N/A","N/A","Exploitation tool","https://github.com/febinrev/dirtypipez-exploit","1","1","N/A","N/A","N/A","1","51","22","2022-03-08T11:52:22Z","2022-03-08T11:49:40Z","7182" +"*/Fentanyl.git*",".{0,1000}\/Fentanyl\.git.{0,1000}","offensive_tool_keyword","Fentanyl","Stealer Malware - Steal Discord Tokens (+ Much More Info) - Steal Passwords/Cookies/History/Credit Cards/Phone Numbers and Addresses from all Browsers (Profile Support) - Steal PC Info - Steal Video Game Accounts (Adding more games + wallets and VPN's) - Low Detections - Anti VM - Sort of Fast - Startup - IP Logger","T1547.001 - T1552.001 - T1552.005 - T1110.001 - T1082 - T1562.001 - T1574.002 - T1529 - T1497.001 - T1543.003 - T1592.001","TA0005 - TA0006 - TA0040 - TA0003 - TA0009","N/A","N/A","Malware","https://github.com/dekrypted/Fentanyl","1","1","N/A","N/A","10","","N/A","","","","7183" +"*/fern-wifi-cracker/*",".{0,1000}\/fern\-wifi\-cracker\/.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7184" +"*/Ferrari.ps1*",".{0,1000}\/Ferrari\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","7185" +"*/fetch-some-proxies.git*",".{0,1000}\/fetch\-some\-proxies\.git.{0,1000}","offensive_tool_keyword","fetch-some-proxies","Simple Python script for fetching ""some"" (usable) proxies","T1090 - T1071 - T1070","TA0002 - TA0005 - TA0010","N/A","N/A","Defense Evasion","https://github.com/stamparm/fetch-some-proxies","1","1","N/A","N/A","9","6","585","138","2023-03-15T09:14:25Z","2016-10-09T22:39:56Z","7186" +"*/ffuf.git*",".{0,1000}\/ffuf\.git.{0,1000}","offensive_tool_keyword","ffuf","Fast web fuzzer written in Go","T1110 - T1550","TA0006 - TA0008","N/A","N/A","Reconnaissance","https://github.com/ffuf/ffuf","1","1","#linux","N/A","N/A","10","13818","1373","2025-04-05T17:35:17Z","2018-11-08T09:25:49Z","7187" +"*/ffuf/ffufrc*",".{0,1000}\/ffuf\/ffufrc.{0,1000}","offensive_tool_keyword","ffuf","Fast web fuzzer written in Go","T1110 - T1550","TA0006 - TA0008","N/A","N/A","Reconnaissance","https://github.com/ffuf/ffuf","1","1","#linux","N/A","N/A","10","13818","1373","2025-04-05T17:35:17Z","2018-11-08T09:25:49Z","7188" +"*/fgdump.git*",".{0,1000}\/fgdump\.git.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","1","N/A","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","7189" +"*/fiesta.profile*",".{0,1000}\/fiesta\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","7191" +"*/fiesta2.profile*",".{0,1000}\/fiesta2\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","7192" +"*/File Encrypter Reverse Bytes.exe*",".{0,1000}\/File\sEncrypter\sReverse\sBytes\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","7193" +"*/FileBasic_x64_Release.exe*",".{0,1000}\/FileBasic_x64_Release\.exe.{0,1000}","offensive_tool_keyword","Tsunami","another C2 framework","T1573 - T1027 - T1059 - T1071 ","TA0011 - TA0009 - TA0003 - TA0007 - TA0008","N/A","N/A","C2","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","7194" +"*/FileCrawlerMITM.py*",".{0,1000}\/FileCrawlerMITM\.py.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","#linux","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","7195" +"*/FilelessPELoader*",".{0,1000}\/FilelessPELoader.{0,1000}","offensive_tool_keyword","FilelessPELoader","Loading Remote AES Encrypted PE in memory - Decrypted it and run it","T1027.001 - T1059.001 - T1071","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/FilelessPELoader","1","1","N/A","N/A","10","10","933","196","2023-08-29T21:46:11Z","2023-02-08T16:59:33Z","7196" +"*/File-Server.ps1*",".{0,1000}\/File\-Server\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","7197" +"*/File-Tunnel.git*",".{0,1000}\/File\-Tunnel\.git.{0,1000}","offensive_tool_keyword","File-Tunnel","Tunnel TCP connections through a file","T1071 - T1105 - T1090","TA0005 - TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/fiddyschmitt/File-Tunnel","1","1","N/A","N/A","10","10","925","82","2025-04-19T15:06:09Z","2023-02-05T12:57:45Z","7198" +"*/final_shellcode_size.txt*",".{0,1000}\/final_shellcode_size\.txt.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Shellcode Generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RCStep/CSSG","1","1","N/A","N/A","10","10","654","112","2025-01-08T23:11:49Z","2021-01-12T14:39:06Z","7201" +"*/find_domain.sh*",".{0,1000}\/find_domain\.sh.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","7202" +"*/findDelegation.py*",".{0,1000}\/findDelegation\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7204" +"*/FindModule.c*",".{0,1000}\/FindModule\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or process handles.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/FindObjects-BOF","1","1","N/A","N/A","10","10","268","47","2023-05-03T19:52:08Z","2021-01-11T09:38:52Z","7205" +"*/FindObjects.cna*",".{0,1000}\/FindObjects\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or process handles.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/FindObjects-BOF","1","1","N/A","N/A","10","10","268","47","2023-05-03T19:52:08Z","2021-01-11T09:38:52Z","7206" +"*/FindSQLSrv.py*",".{0,1000}\/FindSQLSrv\.py.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","N/A","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","7207" +"*/finger.nse*",".{0,1000}\/finger\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7208" +"*/fingerprint-strings.nse*",".{0,1000}\/fingerprint\-strings\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7209" +"*/firefox_decrypt.git*",".{0,1000}\/firefox_decrypt\.git.{0,1000}","offensive_tool_keyword","firefox_decrypt","Firefox Decrypt is a tool to extract passwords from Mozilla","T1555.003 - T1112 - T1056.001","TA0006 - TA0009 - TA0040","N/A","N/A","Credential Access","https://github.com/unode/firefox_decrypt","1","1","N/A","N/A","10","10","2172","317","2024-11-08T13:52:34Z","2014-01-17T13:25:02Z","7210" +"*/firefox_decrypt.py*",".{0,1000}\/firefox_decrypt\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","7211" +"*/firewalk.nse*",".{0,1000}\/firewalk\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7212" +"*/firewall-bypass.nse*",".{0,1000}\/firewall\-bypass\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7213" +"*/flask:5000/supershell/*",".{0,1000}\/flask\:5000\/supershell\/.{0,1000}","offensive_tool_keyword","supershell","Supershell is a C2 remote control platform accessed through WEB services. By establishing a reverse SSH tunnel it obtains a fully interactive Shell and supports multi-platform architecture Payload","T1090 - T1059 - T1021","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/tdragon6/Supershell","1","1","N/A","N/A","10","10","1561","196","2023-09-26T13:53:55Z","2023-03-25T15:02:43Z","7214" +"*/flatten-macho.m*",".{0,1000}\/flatten\-macho\.m.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","7215" +"*/flume-master-info.nse*",".{0,1000}\/flume\-master\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7220" +"*/Fodetect-hooksx64*",".{0,1000}\/Fodetect\-hooksx64.{0,1000}","offensive_tool_keyword","cobaltstrike","Proof of concept Beacon Object File (BOF) that attempts to detect userland hooks in place by AV/EDR","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/anthemtotheego/Detect-Hooks","1","1","N/A","N/A","10","10","158","30","2021-07-22T20:13:16Z","2021-07-22T18:58:23Z","7221" +"*/follina.py*",".{0,1000}\/follina\.py.{0,1000}","offensive_tool_keyword","POC","Just another PoC for the new MSDT-Exploit","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/ItsNee/Follina-CVE-2022-30190-POC","1","1","N/A","N/A","N/A","1","5","0","2022-07-04T13:27:13Z","2022-06-05T13:54:04Z","7222" +"*/follow_attacker_commands.py*",".{0,1000}\/follow_attacker_commands\.py.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","7223" +"*/Forensia.exe*",".{0,1000}\/Forensia\.exe.{0,1000}","offensive_tool_keyword","Forensia","Anti Forensics Tool For Red Teamers - Used For Erasing Some Footprints In The Post Exploitation Phase","T1070.001 - T1070.002 - T1070.004 - T1070.006 - T1070.009 - T1564.004 - T1553.002 - T1027","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/PaulNorman01/Forensia","1","1","N/A","N/A","10","8","755","75","2023-06-23T23:23:22Z","2022-12-07T14:45:52Z","7224" +"*/Forensia.git*",".{0,1000}\/Forensia\.git.{0,1000}","offensive_tool_keyword","Forensia","Anti Forensics Tool For Red Teamers - Used For Erasing Some Footprints In The Post Exploitation Phase","T1070.001 - T1070.002 - T1070.004 - T1070.006 - T1070.009 - T1564.004 - T1553.002 - T1027","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/PaulNorman01/Forensia","1","1","N/A","N/A","10","8","755","75","2023-06-23T23:23:22Z","2022-12-07T14:45:52Z","7225" +"*/forensia.pdb*",".{0,1000}\/forensia\.pdb.{0,1000}","offensive_tool_keyword","Forensia","Anti Forensics Tool For Red Teamers - Used For Erasing Some Footprints In The Post Exploitation Phase","T1070.001 - T1070.002 - T1070.004 - T1070.006 - T1070.009 - T1564.004 - T1553.002 - T1027","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/PaulNorman01/Forensia","1","1","N/A","N/A","10","8","755","75","2023-06-23T23:23:22Z","2022-12-07T14:45:52Z","7226" +"*/Forensia/releases/download/ReleaseX64/*",".{0,1000}\/Forensia\/releases\/download\/ReleaseX64\/.{0,1000}","offensive_tool_keyword","Forensia","Anti Forensics Tool For Red Teamers - Used For Erasing Some Footprints In The Post Exploitation Phase","T1070.001 - T1070.002 - T1070.004 - T1070.006 - T1070.009 - T1564.004 - T1553.002 - T1027","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/PaulNorman01/Forensia","1","1","N/A","N/A","10","8","755","75","2023-06-23T23:23:22Z","2022-12-07T14:45:52Z","7227" +"*/Forensike.git*",".{0,1000}\/Forensike\.git.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","1","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","7228" +"*/Forensike.ps1*",".{0,1000}\/Forensike\.ps1.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","1","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","7229" +"*/ForgeCert.exe*",".{0,1000}\/ForgeCert\.exe.{0,1000}","offensive_tool_keyword","ForgeCert","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","ForgeCert","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","7230" +"*/ForgeCert.exe*",".{0,1000}\/ForgeCert\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","7231" +"*/ForgeCert.exe*",".{0,1000}\/ForgeCert\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","ForgeCert","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","7232" +"*/ForgeCert.exe*",".{0,1000}\/ForgeCert\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","7233" +"*/ForgeCert.git*",".{0,1000}\/ForgeCert\.git.{0,1000}","offensive_tool_keyword","ForgeCert","ForgeCert uses the BouncyCastle C# API and a stolen Certificate Authority (CA) certificate + private key to forge certificates for arbitrary users capable of authentication to Active Directory.","T1553.002 - T1136.003 - T1059.001 - T1649","TA0006 - TA0002","N/A","N/A","Defense Evasion","https://github.com/GhostPack/ForgeCert","1","1","N/A","N/A","10","7","671","109","2024-08-17T16:40:07Z","2021-06-09T22:04:18Z","7234" +"*/forkatz.filters*",".{0,1000}\/forkatz\.filters.{0,1000}","offensive_tool_keyword","forkatz","credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege","T1003.002 - T1558.002 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/Barbarisch/forkatz","1","1","N/A","N/A","10","2","124","16","2021-05-22T00:23:04Z","2021-05-21T18:42:22Z","7235" +"*/forkatz.git*",".{0,1000}\/forkatz\.git.{0,1000}","offensive_tool_keyword","forkatz","credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege","T1003.002 - T1558.002 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/Barbarisch/forkatz","1","1","N/A","N/A","10","2","124","16","2021-05-22T00:23:04Z","2021-05-21T18:42:22Z","7236" +"*/ForkDump.cpp*",".{0,1000}\/ForkDump\.cpp.{0,1000}","offensive_tool_keyword","ForkPlayground","proof-of-concept of Process Forking.","T1055 - T1003","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/D4stiny/ForkPlayground","1","1","N/A","N/A","7","3","226","33","2021-11-29T21:42:43Z","2021-11-26T04:21:46Z","7237" +"*/ForkLib.cpp*",".{0,1000}\/ForkLib\.cpp.{0,1000}","offensive_tool_keyword","ForkPlayground","proof-of-concept of Process Forking.","T1055 - T1003","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/D4stiny/ForkPlayground","1","1","N/A","N/A","7","3","226","33","2021-11-29T21:42:43Z","2021-11-26T04:21:46Z","7238" +"*/ForkPlayground.git*",".{0,1000}\/ForkPlayground\.git.{0,1000}","offensive_tool_keyword","ForkPlayground","proof-of-concept of Process Forking.","T1055 - T1003","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/D4stiny/ForkPlayground","1","1","N/A","N/A","7","3","226","33","2021-11-29T21:42:43Z","2021-11-26T04:21:46Z","7239" +"*/FormThief.git*",".{0,1000}\/FormThief\.git.{0,1000}","offensive_tool_keyword","FormThief","Spoofing desktop login applications with WinForms and WPF","T1204.002 - T1056.004 - T1071.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/mlcsec/FormThief","1","1","N/A","N/A","8","2","173","31","2024-02-19T22:40:09Z","2024-02-19T22:34:07Z","7241" +"*/FourEye.git*",".{0,1000}\/FourEye\.git.{0,1000}","offensive_tool_keyword","FourEye","AV Evasion Tool","T1059 - T1059.001 - T1059.005 - T1027 - T1027.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/lengjibo/FourEye","1","1","N/A","N/A","10","8","758","152","2021-12-08T11:55:15Z","2020-12-11T01:29:58Z","7243" +"*/fox-info.nse*",".{0,1000}\/fox\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7244" +"*/fox-it/BloodHound*",".{0,1000}\/fox\-it\/BloodHound.{0,1000}","offensive_tool_keyword","BloodHound","BloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/fox-it/BloodHound.py","1","1","N/A","N/A","10","10","2088","343","2025-03-28T11:19:13Z","2018-02-26T14:44:20Z","7245" +"*/Free porn.exe*",".{0,1000}\/Free\sporn\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","7246" +"*/freelancer-info.nse*",".{0,1000}\/freelancer\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7253" +"*/Freeze.rs*",".{0,1000}\/Freeze\.rs.{0,1000}","offensive_tool_keyword","Freeze.rs","Freeze.rs is a payload toolkit for bypassing EDRs using suspended processes. direct syscalls written in RUST","T1548.004","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/optiv/Freeze.rs","1","1","N/A","N/A","N/A","8","716","84","2023-08-18T17:26:44Z","2023-05-03T16:04:47Z","7254" +"*/freyja.go*",".{0,1000}\/freyja\.go.{0,1000}","offensive_tool_keyword","mythic","mythic C2 agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/freyja/","1","1","N/A","N/A","10","10","54","13","2024-10-29T17:32:07Z","2022-09-28T17:20:04Z","7255" +"*/freyja_tcp/*",".{0,1000}\/freyja_tcp\/.{0,1000}","offensive_tool_keyword","mythic","mythic C2 agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/freyja/","1","1","N/A","N/A","10","10","54","13","2024-10-29T17:32:07Z","2022-09-28T17:20:04Z","7256" +"*/fritzone/obfy*",".{0,1000}\/fritzone\/obfy.{0,1000}","offensive_tool_keyword","obfy","A tiny C++ obfuscation framework","T1027.002 - T1059.003 - T1140","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/fritzone/obfy","1","1","N/A","N/A","N/A","7","678","97","2020-06-10T13:28:32Z","2015-11-13T13:28:23Z","7257" +"*/frpc.exe*",".{0,1000}\/frpc\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","7269" +"*/FruityC2.git*",".{0,1000}\/FruityC2\.git.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","7274" +"*/FruityC2/archive/master.zip*",".{0,1000}\/FruityC2\/archive\/master\.zip.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","7277" +"*/FruityC2/releases/*",".{0,1000}\/FruityC2\/releases\/.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","7278" +"*/FruityC2-Client*",".{0,1000}\/FruityC2\-Client.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","7279" +"*/fscan.exe*",".{0,1000}\/fscan\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","7280" +"*/fscan.exe*",".{0,1000}\/fscan\.exe.{0,1000}","offensive_tool_keyword","fscan","Vulnerability scanner","T1595","TA0042 - TA0007","N/A","Earth Lusca","Reconnaissance","https://github.com/shadow1ng/fscan","1","1","N/A","N/A","8","10","11931","1725","2025-04-20T11:30:29Z","2020-11-13T16:35:20Z","7281" +"*/fscan.git*",".{0,1000}\/fscan\.git.{0,1000}","offensive_tool_keyword","fscan","Vulnerability scanner","T1595","TA0042 - TA0007","N/A","Earth Lusca","Reconnaissance","https://github.com/shadow1ng/fscan","1","1","N/A","N/A","8","10","11931","1725","2025-04-20T11:30:29Z","2020-11-13T16:35:20Z","7282" +"*/fscan/releases/download/*",".{0,1000}\/fscan\/releases\/download\/.{0,1000}","offensive_tool_keyword","fscan","Vulnerability scanner","T1595","TA0042 - TA0007","N/A","Earth Lusca","Reconnaissance","https://github.com/shadow1ng/fscan","1","1","N/A","N/A","8","10","11931","1725","2025-04-20T11:30:29Z","2020-11-13T16:35:20Z","7283" +"*/fscan32.exe*",".{0,1000}\/fscan32\.exe.{0,1000}","offensive_tool_keyword","fscan","Vulnerability scanner","T1595","TA0042 - TA0007","N/A","Earth Lusca","Reconnaissance","https://github.com/shadow1ng/fscan","1","1","N/A","N/A","8","10","11931","1725","2025-04-20T11:30:29Z","2020-11-13T16:35:20Z","7287" +"*/fscan64.exe*",".{0,1000}\/fscan64\.exe.{0,1000}","offensive_tool_keyword","fscan","Vulnerability scanner","T1595","TA0042 - TA0007","N/A","Earth Lusca","Reconnaissance","https://github.com/shadow1ng/fscan","1","1","N/A","N/A","8","10","11931","1725","2025-04-20T11:30:29Z","2020-11-13T16:35:20Z","7289" +"*/fscanarm64.exe*",".{0,1000}\/fscanarm64\.exe.{0,1000}","offensive_tool_keyword","fscan","Vulnerability scanner","T1595","TA0042 - TA0007","N/A","Earth Lusca","Reconnaissance","https://github.com/shadow1ng/fscan","1","1","N/A","N/A","8","10","11931","1725","2025-04-20T11:30:29Z","2020-11-13T16:35:20Z","7291" +"*/fscanarmv6.exe*",".{0,1000}\/fscanarmv6\.exe.{0,1000}","offensive_tool_keyword","fscan","Vulnerability scanner","T1595","TA0042 - TA0007","N/A","Earth Lusca","Reconnaissance","https://github.com/shadow1ng/fscan","1","1","N/A","N/A","8","10","11931","1725","2025-04-20T11:30:29Z","2020-11-13T16:35:20Z","7292" +"*/fscanarmv7.exe*",".{0,1000}\/fscanarmv7\.exe.{0,1000}","offensive_tool_keyword","fscan","Vulnerability scanner","T1595","TA0042 - TA0007","N/A","Earth Lusca","Reconnaissance","https://github.com/shadow1ng/fscan","1","1","N/A","N/A","8","10","11931","1725","2025-04-20T11:30:29Z","2020-11-13T16:35:20Z","7293" +"*/ftp-anon.nse*",".{0,1000}\/ftp\-anon\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7295" +"*/ftp-bounce.nse*",".{0,1000}\/ftp\-bounce\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7296" +"*/ftp-brute.nse*",".{0,1000}\/ftp\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7297" +"*/FtpC2/*",".{0,1000}\/FtpC2\/.{0,1000}","offensive_tool_keyword","SharpFtpC2","A Streamlined FTP-Driven Command and Control Conduit for Interconnecting Remote Systems.","T1572 - T1041 - T1105","TA0011 - TA0002 - TA0040","N/A","N/A","C2","https://github.com/DarkCoderSc/SharpFtpC2","1","1","N/A","N/A","10","10","88","15","2023-11-09T10:37:20Z","2023-06-09T12:41:28Z","7298" +"*/ftp-libopie.nse*",".{0,1000}\/ftp\-libopie\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7299" +"*/ftp-proftpd-backdoor.nse*",".{0,1000}\/ftp\-proftpd\-backdoor\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7300" +"*/ftp-syst.nse*",".{0,1000}\/ftp\-syst\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7301" +"*/ftp-vsftpd-backdoor.nse*",".{0,1000}\/ftp\-vsftpd\-backdoor\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7302" +"*/ftp-vuln-cve2010-4221.nse*",".{0,1000}\/ftp\-vuln\-cve2010\-4221\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7303" +"*/fuck.php*",".{0,1000}\/fuck\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","7304" +"*/Fuck-Etw.git*",".{0,1000}\/Fuck\-Etw\.git.{0,1000}","offensive_tool_keyword","Fuck-Etw","Bypass the Event Trace Windows(ETW) and unhook ntdll.","T1070.004 - T1055.001","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/unkvolism/Fuck-Etw","1","1","N/A","N/A","10","2","102","13","2023-09-29T21:19:10Z","2023-09-25T18:59:10Z","7305" +"*/FuckThatPacker*",".{0,1000}\/FuckThatPacker.{0,1000}","offensive_tool_keyword","cobaltstrike","A simple python packer to easily bypass Windows Defender","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Unknow101/FuckThatPacker","1","1","N/A","N/A","10","10","637","84","2022-04-03T18:20:01Z","2020-08-13T07:26:07Z","7306" +"*/FudgeC2*",".{0,1000}\/FudgeC2.{0,1000}","offensive_tool_keyword","FudgeC2","FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.","T1021.002 - T1105 - T1059.001 - T1059.003","TA0008 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/Ziconius/FudgeC2","1","1","N/A","N/A","10","10","253","54","2023-05-01T21:13:56Z","2018-09-09T21:05:21Z","7308" +"*/fuegoshell.git*",".{0,1000}\/fuegoshell\.git.{0,1000}","offensive_tool_keyword","fuegoshell","Fuegoshell is a powershell oneliner generator for Windows remote shell re-using TCP 445","T1059.001 - T1203","TA0002 - TA0011 - TA0008","N/A","N/A","Lateral Movement","https://github.com/v1k1ngfr/fuegoshell","1","1","N/A","N/A","10","1","44","7","2024-04-27T09:03:28Z","2024-04-27T08:06:03Z","7309" +"*/FullPowers.dll*",".{0,1000}\/FullPowers\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","7312" +"*/FunctionalC2/*",".{0,1000}\/FunctionalC2\/.{0,1000}","offensive_tool_keyword","FunctionalC2","A small POC of using Azure Functions to relay communications","T1021.006 - T1132.002 - T1071.001","TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/FortyNorthSecurity/FunctionalC2","1","1","N/A","N/A","10","10","74","17","2023-03-30T20:27:38Z","2020-03-12T17:54:50Z","7313" +"*/fuzz.txt*",".{0,1000}\/fuzz\.txt.{0,1000}","offensive_tool_keyword","fuzz.txt","list of sensible files for fuzzing in system","T1210 - T1190 - T1203 - T1114","TA0002 - TA0003 - TA0007 - TA0040","N/A","N/A","Exploitation tool","https://github.com/Bo0oM/fuzz.txt/blob/master/fuzz.txt","1","1","N/A","N/A","N/A","10","3134","514","2025-03-27T08:34:43Z","2016-01-19T13:35:44Z","7314" +"*/fuzz_wordlist.txt*",".{0,1000}\/fuzz_wordlist\.txt.{0,1000}","offensive_tool_keyword","reconftw","reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities","T1595 - T1590 - T1592 - T1596 - T1598 - T1046 - T1599 - T1213 - T1597","TA0043 - TA0042 - TA0007 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/six2dez/reconftw","1","1","#linux","N/A","7","10","6202","982","2025-04-22T13:01:31Z","2020-12-30T23:52:52Z","7315" +"*/fuzzers/dns*",".{0,1000}\/fuzzers\/dns.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","7316" +"*/fuzzers/ftp*",".{0,1000}\/fuzzers\/ftp.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","7317" +"*/fuzzers/http*",".{0,1000}\/fuzzers\/http.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","7318" +"*/fuzzers/ntp*",".{0,1000}\/fuzzers\/ntp.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","7319" +"*/fuzzers/smb*",".{0,1000}\/fuzzers\/smb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","7320" +"*/fuzzers/smtp*",".{0,1000}\/fuzzers\/smtp.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","7321" +"*/fuzzers/ssh*",".{0,1000}\/fuzzers\/ssh.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","7322" +"*/FWUprank.ps1",".{0,1000}\/FWUprank\.ps1","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","7323" +"*/g00nv13.php*",".{0,1000}\/g00nv13\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","7324" +"*/G0ldenGunSec/*",".{0,1000}\/G0ldenGunSec\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF to identify processes with the CLR loaded with a goal of identifying SpawnTo / injection candidates.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://gist.github.com/G0ldenGunSec/8ca0e853dd5637af2881697f8de6aecc","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","7325" +"*/GadgetToJScript.git*",".{0,1000}\/GadgetToJScript\.git.{0,1000}","offensive_tool_keyword","GadgetToJScript","A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.","T1059.001 - T1078 - T1059.005","TA0002 - TA0004 - TA0001","N/A","N/A","Exploitation tool","https://github.com/med0x2e/GadgetToJScript","1","1","N/A","N/A","10","10","942","168","2021-07-26T17:35:40Z","2019-10-05T12:27:19Z","7326" +"*/gandcrab.profile*",".{0,1000}\/gandcrab\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","7327" +"*/ganglia-info.nse*",".{0,1000}\/ganglia\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7328" +"*/GatewayConsoleExe_d64.exe*",".{0,1000}\/GatewayConsoleExe_d64\.exe.{0,1000}","offensive_tool_keyword","C3","Framework designed for red teams to create and manage custom C2 (Command and Control) channels. Unlike traditional C2 frameworks that rely on typical communication methods like HTTP/S DNS or TCP - C3 allows for the creation of non-traditional and esoteric C2 channels using platforms like Slack Dropbox GitHub OneDrive and more.","T1071 - T1102 - T1090 - T1573 - T1048","TA0011 - TA0002 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/WithSecureLabs/C3","1","1","N/A","N/A","9","10","1602","276","2023-03-04T20:32:13Z","2019-08-30T11:21:04Z","7329" +"*/gather/credentials*",".{0,1000}\/gather\/credentials.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","7330" +"*/gather/forensics*",".{0,1000}\/gather\/forensics.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","7331" +"*/gato/*attack.py*",".{0,1000}\/gato\/.{0,1000}attack\.py.{0,1000}","offensive_tool_keyword","gato","GitHub Self-Hosted Runner Enumeration and Attack Tool","T1083 - T1087 - T1081","TA0006 - TA0007","N/A","N/A","Reconnaissance","https://github.com/praetorian-inc/gato","1","1","N/A","N/A","N/A","7","630","55","2025-04-10T23:25:04Z","2023-01-06T15:43:27Z","7333" +"*/gato_x-0.5.2.tar.gz*",".{0,1000}\/gato_x\-0\.5\.2\.tar\.gz.{0,1000}","offensive_tool_keyword","Gato-X","automate advanced enumeration and exploitation techniques against GitHub repositories and organizations","T1190 - T1083 - T1588 - T1587","TA0001 - TA0007 - TA0005","N/A","N/A","Reconnaissance","https://github.com/adnanekhan/Gato-X","1","1","N/A","N/A","7","3","270","35","2025-04-21T17:57:09Z","2024-01-27T18:55:16Z","7334" +"*/gato_x-0.5.3.tar.gz*",".{0,1000}\/gato_x\-0\.5\.3\.tar\.gz.{0,1000}","offensive_tool_keyword","Gato-X","automate advanced enumeration and exploitation techniques against GitHub repositories and organizations","T1190 - T1083 - T1588 - T1587","TA0001 - TA0007 - TA0005","N/A","N/A","Reconnaissance","https://github.com/adnanekhan/Gato-X","1","1","N/A","N/A","7","3","270","35","2025-04-21T17:57:09Z","2024-01-27T18:55:16Z","7335" +"*/Gato-X.git*",".{0,1000}\/Gato\-X\.git.{0,1000}","offensive_tool_keyword","Gato-X","automate advanced enumeration and exploitation techniques against GitHub repositories and organizations","T1190 - T1083 - T1588 - T1587","TA0001 - TA0007 - TA0005","N/A","N/A","Reconnaissance","https://github.com/adnanekhan/Gato-X","1","1","N/A","N/A","7","3","270","35","2025-04-21T17:57:09Z","2024-01-27T18:55:16Z","7336" +"*/Gay Porn Mailer.exe*",".{0,1000}\/Gay\sPorn\sMailer\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","7337" +"*/GC2-sheet/*",".{0,1000}\/GC2\-sheet\/.{0,1000}","offensive_tool_keyword","GC2-sheet","GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet and exfiltrate data using Google Drive.","T1071.002 - T1560 - T1105","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/looCiprian/GC2-sheet","1","1","N/A","N/A","10","10","578","111","2025-03-28T19:48:36Z","2021-09-15T19:06:12Z","7338" +"*/gcat.git*",".{0,1000}\/gcat\.git.{0,1000}","offensive_tool_keyword","gcat","A PoC backdoor that uses Gmail as a C&C server","T1071.001 - T1094 - T1102.002","TA0011 - TA0010 - TA0008","N/A","Sandworm","C2","https://github.com/byt3bl33d3r/gcat","1","1","N/A","N/A","10","10","1332","425","2018-11-16T13:43:15Z","2015-06-03T01:28:00Z","7339" +"*/gcat.py",".{0,1000}\/gcat\.py","offensive_tool_keyword","gcat","A PoC backdoor that uses Gmail as a C&C server","T1071.001 - T1094 - T1102.002","TA0011 - TA0010 - TA0008","N/A","Sandworm","C2","https://github.com/byt3bl33d3r/gcat","1","1","N/A","N/A","10","10","1332","425","2018-11-16T13:43:15Z","2015-06-03T01:28:00Z","7340" +"*/geacon/*beacon*",".{0,1000}\/geacon\/.{0,1000}beacon.{0,1000}","offensive_tool_keyword","cobaltstrike","Practice Go programming and implement CobaltStrike's Beacon in Go","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/darkr4y/geacon","1","1","N/A","N/A","10","10","1189","206","2020-10-02T10:34:37Z","2020-02-14T14:01:29Z","7342" +"*/geacon_pro*",".{0,1000}\/geacon_pro.{0,1000}","offensive_tool_keyword","cobaltstrike","Practice Go programming and implement CobaltStrike's Beacon in Go","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/darkr4y/geacon","1","1","N/A","N/A","10","10","1189","206","2020-10-02T10:34:37Z","2020-02-14T14:01:29Z","7343" +"*/gecko-new.php*",".{0,1000}\/gecko\-new\.php.{0,1000}","offensive_tool_keyword","Gecko","Gecko Backdoor is a web php backdoor","T1100 - T1059 - T1105 - T1203","TA0011 - TA0003","N/A","N/A","C2","https://github.com/MadExploits/Gecko","1","1","N/A","N/A","10","10","118","56","2025-02-08T17:50:28Z","2022-07-15T05:51:04Z","7344" +"*/gecko-old.php*",".{0,1000}\/gecko\-old\.php.{0,1000}","offensive_tool_keyword","Gecko","Gecko Backdoor is a web php backdoor","T1100 - T1059 - T1105 - T1203","TA0011 - TA0003","N/A","N/A","C2","https://github.com/MadExploits/Gecko","1","1","N/A","N/A","10","10","118","56","2025-02-08T17:50:28Z","2022-07-15T05:51:04Z","7345" +"*/Gemail-Hack.git*",".{0,1000}\/Gemail\-Hack\.git.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/Ha3MrX/Gemail-Hack","1","1","N/A","N/A","7","10","1062","400","2024-01-17T15:12:44Z","2018-04-19T13:48:41Z","7346" +"*/generate_bind_fuegoshell.ps1*",".{0,1000}\/generate_bind_fuegoshell\.ps1.{0,1000}","offensive_tool_keyword","fuegoshell","Fuegoshell is a powershell oneliner generator for Windows remote shell re-using TCP 445","T1059.001 - T1203","TA0002 - TA0011 - TA0008","N/A","N/A","Lateral Movement","https://github.com/v1k1ngfr/fuegoshell","1","1","N/A","N/A","10","1","44","7","2024-04-27T09:03:28Z","2024-04-27T08:06:03Z","7348" +"*/generate_reverse_fuegoshell.ps1*",".{0,1000}\/generate_reverse_fuegoshell\.ps1.{0,1000}","offensive_tool_keyword","fuegoshell","Fuegoshell is a powershell oneliner generator for Windows remote shell re-using TCP 445","T1059.001 - T1203","TA0002 - TA0011 - TA0008","N/A","N/A","Lateral Movement","https://github.com/v1k1ngfr/fuegoshell","1","1","N/A","N/A","10","1","44","7","2024-04-27T09:03:28Z","2024-04-27T08:06:03Z","7349" +"*/GetADComputers.py*",".{0,1000}\/GetADComputers\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7351" +"*/GetADUsers.py*",".{0,1000}\/GetADUsers\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7352" +"*/getArch.py*",".{0,1000}\/getArch\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7354" +"*/GetBrowsers.ps1*",".{0,1000}\/GetBrowsers\.ps1.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","7355" +"*/getChatAdministrators?chat_id=1002168553106*",".{0,1000}\/getChatAdministrators\?chat_id\=1002168553106.{0,1000}","offensive_tool_keyword","Kematian Stealer","Fake WinRar site distributes malware (+stealer +miner +hvnc +ransomware) from GitHub","T1195 - T1566 - T1569 - T1106 - T1486 - T1113","TA0001 - TA0002 - TA0005 - TA0006 - TA0007 - TA0009 - TA0010 - TA0011 - TA0040 - TA0043","N/A","N/A","Malware","https://github[.]com/sap3r-encrypthub/encrypthub","1","1","N/A","N/A","10","7","N/A","N/A","N/A","N/A","7356" +"*/get-clipboard.py*",".{0,1000}\/get\-clipboard\.py.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","7357" +"*/Get-GPPPassword.ps1*",".{0,1000}\/Get\-GPPPassword\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","7359" +"*/Get-GPPPassword.py*",".{0,1000}\/Get\-GPPPassword\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7360" +"*/Get-InfectedThread.ps1*",".{0,1000}\/Get\-InfectedThread\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","7361" +"*/Get-InjectedThread.ps1*",".{0,1000}\/Get\-InjectedThread\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","7362" +"*/GetLAPSPassword.py*",".{0,1000}\/GetLAPSPassword\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7363" +"*/getLegit/cdnl*",".{0,1000}\/getLegit\/cdnl.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","7364" +"*/getLegit/grkg*",".{0,1000}\/getLegit\/grkg.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","7365" +"*/getLegit/prvw*",".{0,1000}\/getLegit\/prvw.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","7366" +"*/getLegit/qhwl*",".{0,1000}\/getLegit\/qhwl.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","7367" +"*/getLegit/tsom*",".{0,1000}\/getLegit\/tsom.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","7368" +"*/getLegit/zijz*",".{0,1000}\/getLegit\/zijz.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","7369" +"*/get-loggedon/*.c*",".{0,1000}\/get\-loggedon\/.{0,1000}\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of CobaltStrike beacon object files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/pwn1sher/CS-BOFs","1","1","N/A","N/A","10","10","103","22","2022-02-14T09:47:30Z","2021-01-18T08:54:48Z","7370" +"*/Get-LsaSecret.*",".{0,1000}\/Get\-LsaSecret\..{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","7371" +"*/getlsasrvaddr.exe*",".{0,1000}\/getlsasrvaddr\.exe.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","1","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","7372" +"*/Get-NetNTLM.git*",".{0,1000}\/Get\-NetNTLM\.git.{0,1000}","offensive_tool_keyword","Get-NetNTLM","Powershell module to get the NetNTLMv2 hash of the current user","T1110.003 - T1557.001 - T1040","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/elnerd/Get-NetNTLM","1","1","N/A","N/A","7","1","93","18","2022-07-05T20:55:33Z","2019-02-11T23:09:54Z","7373" +"*/Get-NetNTLM.ps1*",".{0,1000}\/Get\-NetNTLM\.ps1.{0,1000}","offensive_tool_keyword","Get-NetNTLM","Powershell module to get the NetNTLMv2 hash of the current user","T1110.003 - T1557.001 - T1040","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/elnerd/Get-NetNTLM","1","1","N/A","N/A","7","1","93","18","2022-07-05T20:55:33Z","2019-02-11T23:09:54Z","7374" +"*/GetNPUsers.exe*",".{0,1000}\/GetNPUsers\.exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7375" +"*/GetNPUsers.py*",".{0,1000}\/GetNPUsers\.py.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","7376" +"*/GetNPUsers.py*",".{0,1000}\/GetNPUsers\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7377" +"*/getOSandSMBproperties.exe*",".{0,1000}\/getOSandSMBproperties\.exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7378" +"*/Get-OSTokenInformation.ps1*",".{0,1000}\/Get\-OSTokenInformation\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","7379" +"*/getPac.exe*",".{0,1000}\/getPac\.exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7380" +"*/getPac.py*",".{0,1000}\/getPac\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7381" +"*/GetPasswords.ps1*",".{0,1000}\/GetPasswords\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","7382" +"*/Get-ScheduledTaskComHandler.ps1*",".{0,1000}\/Get\-ScheduledTaskComHandler\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","7383" +"*/get-shucking.php*",".{0,1000}\/get\-shucking\.php.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","7384" +"*/Get-SMBSigning.ps1*",".{0,1000}\/Get\-SMBSigning\.ps1.{0,1000}","offensive_tool_keyword","CheckSMBSigning","Checks for SMB signing disabled on all hosts in the network","T1018 - T1550","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/Leo4j/CheckSMBSigning","1","1","N/A","N/A","6","1","8","1","2023-10-13T11:55:33Z","2023-05-17T11:47:52Z","7385" +"*/getST.py*",".{0,1000}\/getST\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7386" +"*/getST2.py*",".{0,1000}\/getST\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7387" +"*/get-system/getsystem.c*",".{0,1000}\/get\-system\/getsystem\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of CobaltStrike beacon object files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/pwn1sher/CS-BOFs","1","1","N/A","N/A","10","10","103","22","2022-02-14T09:47:30Z","2021-01-18T08:54:48Z","7388" +"*/Get-TGSCipher.ps1*",".{0,1000}\/Get\-TGSCipher\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","7389" +"*/getTGT.py*",".{0,1000}\/getTGT\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7390" +"*/GetUserSPNs.py*",".{0,1000}\/GetUserSPNs\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7391" +"*/GetWebDAVStatus_BOF/*",".{0,1000}\/GetWebDAVStatus_BOF\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Determine if the WebClient Service (WebDAV) is running on a remote system","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/G0ldenGunSec/GetWebDAVStatus","1","1","N/A","N/A","10","10","133","27","2024-03-09T22:49:45Z","2021-09-29T17:31:21Z","7392" +"*/Get-WLAN-Keys.ps1*",".{0,1000}\/Get\-WLAN\-Keys\.ps1.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","7393" +"*/gh0st.exe*",".{0,1000}\/gh0st\.exe.{0,1000}","offensive_tool_keyword","gh0st","Malware RAT with keylogger - dll injection - C2 - Remote control","T1204.002 - T1071.001 - T1027 - T1036.005 - T1055.001 - T1005 - T1056.001 - T1074.001 - T1105 - T1562.001 - T1543.003 - T1547.001 - T1571 - T1573.001 - T1106 - T1219","TA0002 - TA0003 - TA0004 - TA0008 - TA0009 - TA0010 - TA0011","GhostRAT","N/A","Malware","https://github.com/sin5678/gh0st","1","1","N/A","N/A","10","6","508","274","2013-05-08T21:17:26Z","2012-10-05T06:25:36Z","7394" +"*/gh0st.git*",".{0,1000}\/gh0st\.git.{0,1000}","offensive_tool_keyword","gh0st","Malware RAT with keylogger - dll injection - C2 - Remote control","T1204.002 - T1071.001 - T1027 - T1036.005 - T1055.001 - T1005 - T1056.001 - T1074.001 - T1105 - T1562.001 - T1543.003 - T1547.001 - T1571 - T1573.001 - T1106 - T1219","TA0002 - TA0003 - TA0004 - TA0008 - TA0009 - TA0010 - TA0011","GhostRAT","N/A","Malware","https://github.com/sin5678/gh0st","1","1","N/A","N/A","10","6","508","274","2013-05-08T21:17:26Z","2012-10-05T06:25:36Z","7395" +"*/ghauri.git*",".{0,1000}\/ghauri\.git.{0,1000}","offensive_tool_keyword","ghauri","A cross-platform python based advanced sql injections detection & exploitation tool","T1190 - T1210 - T1095","TA0001 - TA0002 - TA0009","N/A","N/A","Vulnerability Scanner","https://github.com/r0oth3x49/ghauri","1","1","N/A","N/A","8","10","3483","361","2025-02-25T19:09:50Z","2022-10-01T11:21:50Z","7396" +"*/ghauri.py*",".{0,1000}\/ghauri\.py.{0,1000}","offensive_tool_keyword","ghauri","A cross-platform python based advanced sql injections detection & exploitation tool","T1190 - T1210 - T1095","TA0001 - TA0002 - TA0009","N/A","N/A","Vulnerability Scanner","https://github.com/r0oth3x49/ghauri","1","1","N/A","N/A","8","10","3483","361","2025-02-25T19:09:50Z","2022-10-01T11:21:50Z","7397" +"*/GhostDriver.exe*",".{0,1000}\/GhostDriver\.exe.{0,1000}","offensive_tool_keyword","GhostDriver","GhostDriver is a Rust-built AV killer tool using BYOVD","T1562.001 - T1211 - T1055.001","TA0005 - TA0002","N/A","Black Basta","Defense Evasion","https://github.com/BlackSnufkin/GhostDriver","1","1","N/A","N/A","9","3","270","38","2023-12-12T13:52:32Z","2023-12-02T23:56:13Z","7400" +"*/GhostDriver.git*",".{0,1000}\/GhostDriver\.git.{0,1000}","offensive_tool_keyword","GhostDriver","GhostDriver is a Rust-built AV killer tool using BYOVD","T1562.001 - T1211 - T1055.001","TA0005 - TA0002","N/A","Black Basta","Defense Evasion","https://github.com/BlackSnufkin/GhostDriver","1","1","N/A","N/A","9","3","270","38","2023-12-12T13:52:32Z","2023-12-02T23:56:13Z","7401" +"*/ghostdriver.sys*",".{0,1000}\/ghostdriver\.sys.{0,1000}","offensive_tool_keyword","GhostDriver","GhostDriver is a Rust-built AV killer tool using BYOVD","T1562.001 - T1211 - T1055.001","TA0005 - TA0002","N/A","Black Basta","Defense Evasion","https://github.com/BlackSnufkin/GhostDriver","1","1","N/A","N/A","9","3","270","38","2023-12-12T13:52:32Z","2023-12-02T23:56:13Z","7402" +"*/ghostfile.aspx*",".{0,1000}\/ghostfile\.aspx.{0,1000}","offensive_tool_keyword","ysoserial.net","Deserialization payload generator for a variety of .NET formatters","T1059.007 - T1027.002 - T1059.001","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/pwntester/ysoserial.net","1","1","N/A","N/A","10","10","3385","493","2024-12-23T20:59:47Z","2017-09-18T17:48:08Z","7403" +"*/GhostInTheNet.git*",".{0,1000}\/GhostInTheNet\.git.{0,1000}","offensive_tool_keyword","GhostInTheNet","Ultimate Network Stealther that makes Linux a Ghost In The Net and protects from MITM/DOS/scan","T1574 - T1565 - T1055","TA0007 - TA0040 - TA0043","N/A","N/A","Sniffing & Spoofing","https://github.com/cryptolok/GhostInTheNet","1","1","#linux","N/A","7","4","372","79","2023-04-27T07:07:29Z","2017-04-22T01:53:16Z","7404" +"*/GhostInTheNet.sh*",".{0,1000}\/GhostInTheNet\.sh.{0,1000}","offensive_tool_keyword","GhostInTheNet","Ultimate Network Stealther that makes Linux a Ghost In The Net and protects from MITM/DOS/scan","T1574 - T1565 - T1055","TA0007 - TA0040 - TA0043","N/A","N/A","Sniffing & Spoofing","https://github.com/cryptolok/GhostInTheNet","1","1","#linux","N/A","7","4","372","79","2023-04-27T07:07:29Z","2017-04-22T01:53:16Z","7405" +"*/GhostInTheNet-master*",".{0,1000}\/GhostInTheNet\-master.{0,1000}","offensive_tool_keyword","GhostInTheNet","Ultimate Network Stealther that makes Linux a Ghost In The Net and protects from MITM/DOS/scan","T1574 - T1565 - T1055","TA0007 - TA0040 - TA0043","N/A","N/A","Sniffing & Spoofing","https://github.com/cryptolok/GhostInTheNet","1","1","#linux","N/A","7","4","372","79","2023-04-27T07:07:29Z","2017-04-22T01:53:16Z","7406" +"*/GhostMapper.git*",".{0,1000}\/GhostMapper\.git.{0,1000}","offensive_tool_keyword","GhostMapper","GhostMapper involves modifying Windows system ""dump_"" prefix drivers to exploit crash handling mechanisms for malicious purposes.","T1014 - T1070.004 - T1055.011","TA0003 - TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/Oliver-1-1/GhostMapper","1","1","N/A","N/A","8","3","279","62","2025-04-12T19:17:46Z","2023-10-31T11:26:33Z","7407" +"*/GhostMapper.sln*",".{0,1000}\/GhostMapper\.sln.{0,1000}","offensive_tool_keyword","GhostMapper","GhostMapper involves modifying Windows system ""dump_"" prefix drivers to exploit crash handling mechanisms for malicious purposes.","T1014 - T1070.004 - T1055.011","TA0003 - TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/Oliver-1-1/GhostMapper","1","1","N/A","N/A","8","3","279","62","2025-04-12T19:17:46Z","2023-10-31T11:26:33Z","7408" +"*/GhostMouse.exe*",".{0,1000}\/GhostMouse\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","7409" +"*/ghostsocks.git*",".{0,1000}\/ghostsocks\.git.{0,1000}","offensive_tool_keyword","ghostsocks","SOCKS5 proxy based on lightsocks","T1090.002 - T1090","TA0005 - TA0008","Lumma Stealer","N/A","Defense Evasion","https://github.com/LemonSaaS/ghostsocks","1","1","N/A","N/A","7","1","2","1","2017-11-14T16:56:05Z","2017-11-13T03:38:57Z","7410" +"*/GhostTask.git*",".{0,1000}\/GhostTask\.git.{0,1000}","offensive_tool_keyword","GhostTask","Creates scheduled tasks with a restrictive security descriptor - making them invisible to all users. - Establishes scheduled tasks directly via the registry - bypassing the generation of standard Windows event logs. - Provides support to modify existing scheduled tasks without generating Windows event logs. - Supports remote scheduled task creation (by using specially crafted Silver Ticket). - Supports to run in C2 with in-memory PE execution module (e.g. - BruteRatel's memexec)","T1053.005 - T1112 - T1078","TA0003 - TA0005 - TA0007","N/A","N/A","Defense Evasion","https://github.com/netero1010/GhostTask","1","1","N/A","N/A","10","6","549","63","2025-01-02T15:26:01Z","2023-10-23T13:05:00Z","7411" +"*/gimmeSH.sh*",".{0,1000}\/gimmeSH\.sh.{0,1000}","offensive_tool_keyword","gimmeSH","gimmeSH. is a tool that generates a custom cheatsheet for Reverse Shell. File Transfer and Msfvenom within your terminal. you just need to provide the platform. your Internet protocol address and your port number.","T1059 - T1505","TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/A3h1nt/gimmeSH","1","1","N/A","N/A","N/A","2","183","28","2021-08-27T03:12:15Z","2021-08-02T07:22:15Z","7412" +"*/giop-info.nse*",".{0,1000}\/giop\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7413" +"*/GithubC2.git*",".{0,1000}\/GithubC2\.git.{0,1000}","offensive_tool_keyword","GithubC2","Github as C2","T1095 - T1071.001","TA0011","N/A","N/A","C2","https://github.com/TheD1rkMtr/GithubC2","1","1","N/A","N/A","10","10","136","37","2023-08-02T02:26:05Z","2023-02-15T00:50:59Z","7519" +"*/gkrellm-info.nse*",".{0,1000}\/gkrellm\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7520" +"*/glit.git*",".{0,1000}\/glit\.git.{0,1000}","offensive_tool_keyword","glit","Retrieve all mails of users related to a git repository a git user or a git organization","T1583 - T1059.001 - T1059.003","TA0002 - TA0003","N/A","N/A","Reconnaissance","https://github.com/shadawck/glit","1","1","N/A","N/A","8","1","49","7","2024-05-01T15:07:51Z","2022-11-14T11:25:10Z","7521" +"*/GlllPowerloader.git*",".{0,1000}\/GlllPowerloader\.git.{0,1000}","offensive_tool_keyword","GlllPowerloader","Sample to bypass AV/EDR and upload to transfer.sh","T1059.001 - T1202 - T1105 - T1027 - T1036 - T1070 - T1031 - T1071 - T1048","TA0005 - TA0004 - TA0002 - TA0011 - TA0010","N/A","N/A","Defense Evasion","https://github.com/INotGreen/GlllPowerloader","1","1","N/A","N/A","10","5","451","105","2024-04-12T07:28:24Z","2022-04-26T12:10:58Z","7524" +"*/GlllPowerLoader.py*",".{0,1000}\/GlllPowerLoader\.py.{0,1000}","offensive_tool_keyword","GlllPowerloader","Sample to bypass AV/EDR and upload to transfer.sh","T1059.001 - T1202 - T1105 - T1027 - T1036 - T1070 - T1031 - T1071 - T1048","TA0005 - TA0004 - TA0002 - TA0011 - TA0010","N/A","N/A","Defense Evasion","https://github.com/INotGreen/GlllPowerloader","1","1","N/A","N/A","10","5","451","105","2024-04-12T07:28:24Z","2022-04-26T12:10:58Z","7525" +"*/GlobalUnProtect.git*",".{0,1000}\/GlobalUnProtect\.git.{0,1000}","offensive_tool_keyword","GlobalUnProtect","Decrypt GlobalProtect configuration and cookie files.","T1552 - T1003 - T1555","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rotarydrone/GlobalUnProtect","1","1","N/A","N/A","9","2","147","19","2024-09-10T20:19:24Z","2024-09-04T15:31:52Z","7526" +"*/globeimposter.profile*",".{0,1000}\/globeimposter\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","7527" +"*/gmailC2.exe*",".{0,1000}\/gmailC2\.exe.{0,1000}","offensive_tool_keyword","SharpGmailC2","Gmail will act as Server and implant will exfiltrate data via smtp and will read commands from C2 (Gmail) via imap protocol","T1071 - T1071.004 - T1568 - T1568.002 - T1114 - T1114.001","TA0011 - TA0040 - TA0001","N/A","N/A","C2","https://github.com/reveng007/SharpGmailC2","1","1","N/A","N/A","10","10","260","47","2022-12-27T01:45:46Z","2022-11-10T06:48:15Z","7528" +"*/gmer.exe*",".{0,1000}\/gmer\.exe.{0,1000}","offensive_tool_keyword","gmer","rootkit detector abused by attackers to disable security software","T1014 - T1562.001","TA0005","N/A","BlackSuit - Royal - PLAY - LockBit - Bassterlord* - Conti - 8BASE - TargetCompany - Hive - Avaddon","Defense Evasion","gmer.net","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","7529" +"*/gMSA_dump_*.txt*",".{0,1000}\/gMSA_dump_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","7531" +"*/gMSADumper*",".{0,1000}\/gMSADumper.{0,1000}","offensive_tool_keyword","gMSADumper","Lists who can read any gMSA password blobs and parses them if the current user has access.","T1552.001 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/micahvandeusen/gMSADumper","1","1","N/A","N/A","N/A","3","274","51","2024-02-12T02:15:32Z","2021-04-10T00:15:24Z","7532" +"*/GMSAPasswordReader.*",".{0,1000}\/GMSAPasswordReader\..{0,1000}","offensive_tool_keyword","GMSAPasswordReader","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","GMSAPasswordReader","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","7533" +"*/GMSAPasswordReader.*",".{0,1000}\/GMSAPasswordReader\..{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","GMSAPasswordReader","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","7534" +"*/GMSAPasswordReader.exe*",".{0,1000}\/GMSAPasswordReader\.exe.{0,1000}","offensive_tool_keyword","BloodHound","Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors","1","1","N/A","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","7535" +"*/GMSAPasswordReader.exe*",".{0,1000}\/GMSAPasswordReader\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","7536" +"*/GMSAPasswordReader.git*",".{0,1000}\/GMSAPasswordReader\.git.{0,1000}","offensive_tool_keyword","GMSAPasswordReader","Reads the password blob from a GMSA account using LDAP and parses the values into hashes for re-use.","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/rvazarkar/GMSAPasswordReader","1","1","N/A","N/A","7","3","219","34","2023-02-17T14:37:40Z","2020-01-19T19:06:20Z","7537" +"*/GoAWSConsoleSpray.git*",".{0,1000}\/GoAWSConsoleSpray\.git.{0,1000}","offensive_tool_keyword","GoAWSConsoleSpray","brute-force AWS IAM Console credentials to discover valid logins for user accounts","T1078 - T1110 - T1187 - T1110.001","TA0006 - TA0007 - TA0003 - TA0001","N/A","N/A","Credential Access","https://github.com/WhiteOakSecurity/GoAWSConsoleSpray","1","1","N/A","N/A","9","1","29","5","2022-06-15T18:16:21Z","2022-06-15T18:11:39Z","7538" +"*/gobuster.git*",".{0,1000}\/gobuster\.git.{0,1000}","offensive_tool_keyword","gobuster","Directory/File DNS and VHost busting tool written in Go","T1046 - T1590.002 - T1590.005","TA0007 - TA0043 - TA0006","N/A","Volatile Cedar","Reconnaissance","https://github.com/OJ/gobuster","1","1","#linux","network exploitation tool","N/A","10","11434","1338","2025-04-17T06:41:43Z","2014-11-14T13:18:35Z","7539" +"*/gobuster/*",".{0,1000}\/gobuster\/.{0,1000}","offensive_tool_keyword","gobuster","Directory/File DNS and VHost busting tool written in Go","T1046 - T1590.002 - T1590.005","TA0007 - TA0043 - TA0006","N/A","Volatile Cedar","Reconnaissance","https://github.com/OJ/gobuster","1","1","#linux","network exploitation tool","N/A","10","11434","1338","2025-04-17T06:41:43Z","2014-11-14T13:18:35Z","7540" +"*/gobusterdir/*",".{0,1000}\/gobusterdir\/.{0,1000}","offensive_tool_keyword","gobuster","Directory/File DNS and VHost busting tool written in Go","T1046 - T1590.002 - T1590.005","TA0007 - TA0043 - TA0006","N/A","Volatile Cedar","Reconnaissance","https://github.com/OJ/gobuster","1","1","#linux","network exploitation tool","N/A","10","11434","1338","2025-04-17T06:41:43Z","2014-11-14T13:18:35Z","7541" +"*/gobusterdns/*",".{0,1000}\/gobusterdns\/.{0,1000}","offensive_tool_keyword","gobuster","Directory/File DNS and VHost busting tool written in Go","T1046 - T1590.002 - T1590.005","TA0007 - TA0043 - TA0006","N/A","Volatile Cedar","Reconnaissance","https://github.com/OJ/gobuster","1","1","#linux","network exploitation tool","N/A","10","11434","1338","2025-04-17T06:41:43Z","2014-11-14T13:18:35Z","7542" +"*/gobustergcs/*",".{0,1000}\/gobustergcs\/.{0,1000}","offensive_tool_keyword","gobuster","Directory/File DNS and VHost busting tool written in Go","T1046 - T1590.002 - T1590.005","TA0007 - TA0043 - TA0006","N/A","Volatile Cedar","Reconnaissance","https://github.com/OJ/gobuster","1","1","#linux","network exploitation tool","N/A","10","11434","1338","2025-04-17T06:41:43Z","2014-11-14T13:18:35Z","7543" +"*/gocrack.git*",".{0,1000}\/gocrack\.git.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","1","N/A","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","7544" +"*/goDoH.git*",".{0,1000}\/goDoH\.git.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071 - T1001 - T1008 - T1070 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","N/A","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","7550" +"*/godoh.git*",".{0,1000}\/godoh\.git.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071.004 - T1568.002 - T1105 ","TA0011 - TA0005","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","N/A","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","7551" +"*/godoh/*",".{0,1000}\/godoh\/.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071 - T1001 - T1008 - T1070 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","N/A","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","7552" +"*/goDoH/releases*",".{0,1000}\/goDoH\/releases.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071.004 - T1568.002 - T1105 ","TA0011 - TA0005","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","N/A","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","7553" +"*/godoh-master.zip*",".{0,1000}\/godoh\-master\.zip.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071.004 - T1568.002 - T1105 ","TA0011 - TA0005","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","N/A","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","7554" +"*/GodPotato.exe*",".{0,1000}\/GodPotato\.exe.{0,1000}","offensive_tool_keyword","GodPotato","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","GodPotato","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","7555" +"*/GodPotato.exe*",".{0,1000}\/GodPotato\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","GodPotato","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","7556" +"*/GodPotato.git*",".{0,1000}\/GodPotato\.git.{0,1000}","offensive_tool_keyword","godpotato","GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","Ghost Ransomware","N/A","Privilege Escalation","https://github.com/BeichenDream/GodPotato","1","1","N/A","N/A","10","10","1938","236","2023-11-24T19:22:31Z","2022-12-23T14:37:00Z","7557" +"*/Godzilla.java*",".{0,1000}\/Godzilla\.java.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","7558" +"*/Godzilla-BypassOpenRasp.jar*",".{0,1000}\/Godzilla\-BypassOpenRasp\.jar.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","7559" +"*/GodzillaSource.git*",".{0,1000}\/GodzillaSource\.git.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","7560" +"*/gofetch.exe*",".{0,1000}\/gofetch\.exe.{0,1000}","offensive_tool_keyword","GoFetch","GoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application.","T1078 - T1078.003 - T1021 - T1021.006 - T1076.001","TA0005 - TA0001 - TA0003","N/A","Dispossessor","Discovery","https://github.com/GoFetchAD/GoFetch","1","1","N/A","N/A","10","7","633","99","2017-06-20T14:15:10Z","2017-04-11T10:45:23Z","7561" +"*/GoFetch.git*",".{0,1000}\/GoFetch\.git.{0,1000}","offensive_tool_keyword","GoFetch","GoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application.","T1078 - T1078.003 - T1021 - T1021.006 - T1076.001","TA0005 - TA0001 - TA0003","N/A","Dispossessor","Discovery","https://github.com/GoFetchAD/GoFetch","1","1","N/A","N/A","10","7","633","99","2017-06-20T14:15:10Z","2017-04-11T10:45:23Z","7562" +"*/golang_c2.git*",".{0,1000}\/golang_c2\.git.{0,1000}","offensive_tool_keyword","golang_c2","C2 written in Go for red teams aka gorfice2k","T1071 - T1021 - T1090","TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/m00zh33/golang_c2","1","1","N/A","N/A","10","10","6","8","2019-03-18T00:46:41Z","2019-03-19T02:39:59Z","7566" +"*/GoldenGMSA.git*",".{0,1000}\/GoldenGMSA\.git.{0,1000}","offensive_tool_keyword","GoldenGMSA","GolenGMSA tool for working with GMSA passwords","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/Semperis/GoldenGMSA","1","1","N/A","N/A","7","2","144","22","2024-04-11T07:51:57Z","2022-02-03T10:32:05Z","7567" +"*/goldenPac.py*",".{0,1000}\/goldenPac\.py.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","7568" +"*/goldenPac.py*",".{0,1000}\/goldenPac\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","7569" +"*/go-lsass.exe*",".{0,1000}\/go\-lsass\.exe.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","1","N/A","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","7571" +"*/go-lsass.git*",".{0,1000}\/go\-lsass\.git.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","1","N/A","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","7572" +"*/go-lsass/releases*",".{0,1000}\/go\-lsass\/releases.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","1","N/A","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","7573" +"*/go-lsass-master.zip*",".{0,1000}\/go\-lsass\-master\.zip.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","1","N/A","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","7574" +"*/goMatrixC2.git*",".{0,1000}\/goMatrixC2\.git.{0,1000}","offensive_tool_keyword","goMatrixC2","C2 leveraging Matrix/Element Messaging Platform as Backend to control Implants in goLang.","T1090 - T1027 - T1071","TA0011 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/n1k7l4i/goMatrixC2","1","1","N/A","N/A","10","","N/A","","","","7575" +"*/go-mimikatz*",".{0,1000}\/go\-mimikatz.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/vyrus001/go-mimikatz","1","1","N/A","N/A","10","7","619","105","2022-09-08T18:14:20Z","2015-10-22T08:43:38Z","7576" +"*/GONET-Scanner/*",".{0,1000}\/GONET\-Scanner\/.{0,1000}","offensive_tool_keyword","GONET-Scanner","port scanner and arp discover in go","T1595","TA0001","N/A","N/A","Discovery","https://github.com/luijait/GONET-Scanner","1","1","N/A","network exploitation tool","N/A","1","82","21","2022-03-10T04:35:58Z","2022-02-02T19:39:09Z","7577" +"*/GonnaCry.git*",".{0,1000}\/GonnaCry\.git.{0,1000}","offensive_tool_keyword","GonnaCry","a linux ransomware","T1486 - T1059 - T1020 - T1083 - T1070","TA0040 - TA0005 - TA0009 - TA0010","N/A","N/A","Ransomware","https://github.com/tarcisio-marinho/GonnaCry","1","1","N/A","N/A","10","8","717","402","2025-01-24T13:39:57Z","2017-05-12T23:46:28Z","7578" +"*/google_drive_doubledrive.py*",".{0,1000}\/google_drive_doubledrive\.py.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","7580" +"*/goPassGen.git*",".{0,1000}\/goPassGen\.git.{0,1000}","offensive_tool_keyword","goPassGen","Easily-guessable Password Generator for Password Spray Attack","T1110 - T1110.003","TA0006 ","N/A","N/A","Exploitation tool","https://github.com/bigb0sss/goPassGen","1","1","N/A","N/A","8","1","21","1","2020-06-04T23:13:44Z","2020-06-04T22:33:37Z","7581" +"*/Gopher.exe*",".{0,1000}\/Gopher\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","7582" +"*/gopher-ls.nse*",".{0,1000}\/gopher\-ls\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7583" +"*/gophish.db*",".{0,1000}\/gophish\.db.{0,1000}","offensive_tool_keyword","gophish","Open-Source Phishing Toolkit","T1566-001 - T1566-002 - T1566-003 - T1056-001 - T1113 - T1567-001","TA0002 - TA0003","N/A","Black Basta","Phishing","https://github.com/gophish/gophish","1","1","N/A","N/A","10","10","12483","2528","2024-09-23T04:24:43Z","2013-11-18T23:26:43Z","7585" +"*/gophish/*",".{0,1000}\/gophish\/.{0,1000}","offensive_tool_keyword","gophish","Open-Source Phishing Toolkit","T1566-001 - T1566-002 - T1566-003 - T1056-001 - T1113 - T1567-001","TA0002 - TA0003","N/A","Black Basta","Phishing","https://github.com/gophish/gophish","1","1","N/A","N/A","10","10","12483","2528","2024-09-23T04:24:43Z","2013-11-18T23:26:43Z","7586" +"*/gorsair.go*",".{0,1000}\/gorsair\.go.{0,1000}","offensive_tool_keyword","Gorsair","Gorsair hacks its way into remote docker containers that expose their APIs","T1552","TA0006","N/A","N/A","Exploitation tool","https://github.com/Ullaakut/Gorsair","1","1","N/A","N/A","N/A","9","851","70","2023-12-19T18:44:32Z","2018-08-02T16:49:14Z","7589" +"*/go-secdump.git*",".{0,1000}\/go\-secdump\.git.{0,1000}","offensive_tool_keyword","go-secdump","Tool to remotely dump secrets from the Windows registry","T1003.002 - T1012 - T1059.003","TA0006 - TA0003 - TA0002","N/A","N/A","Credential Access","https://github.com/jfjallid/go-secdump","1","1","N/A","N/A","10","5","457","51","2025-02-21T19:16:11Z","2023-02-23T17:02:50Z","7590" +"*/gosecretsdump*",".{0,1000}\/gosecretsdump.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","7591" +"*/gosecretsdump.*",".{0,1000}\/gosecretsdump\..{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","7592" +"*/gosecretsdump/*",".{0,1000}\/gosecretsdump\/.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","7593" +"*/gosecretsdump_linux*",".{0,1000}\/gosecretsdump_linux.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","#linux","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","7594" +"*/gosecretsdump_mac*",".{0,1000}\/gosecretsdump_mac.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","7595" +"*/gosecretsdump_win*",".{0,1000}\/gosecretsdump_win.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","7596" +"*/GoStompy.go*",".{0,1000}\/GoStompy\.go.{0,1000}","offensive_tool_keyword","Stompy","Timestomp Tool to flatten MAC times with a specific timestamp","T1070.006","TA0005","N/A","N/A","Defense Evasion","https://github.com/ZephrFish/Stompy","1","1","N/A","N/A","10","1","46","6","2023-10-15T17:38:23Z","2023-10-14T23:40:32Z","7600" +"*/Gotato.git*",".{0,1000}\/Gotato\.git.{0,1000}","offensive_tool_keyword","Gotato","Generic impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported.","T1003.003 - T1056.002 - T1550.001 - T1090","TA0005 - TA0004 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/iammaguire/Gotato","1","1","N/A","N/A","9","2","112","16","2021-06-07T21:19:58Z","2021-06-05T22:32:48Z","7601" +"*/gotato.go*",".{0,1000}\/gotato\.go.{0,1000}","offensive_tool_keyword","Gotato","Generic impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported.","T1003.003 - T1056.002 - T1550.001 - T1090","TA0005 - TA0004 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/iammaguire/Gotato","1","1","N/A","N/A","9","2","112","16","2021-06-07T21:19:58Z","2021-06-05T22:32:48Z","7602" +"*/goWMIExec.git*",".{0,1000}\/goWMIExec\.git.{0,1000}","offensive_tool_keyword","goWMIExec","re-implementation of invoke-wmiexec (Lateral Movement)","T1021.005","TA0008","N/A","N/A","Lateral Movement","https://github.com/C-Sto/goWMIExec","1","1","N/A","N/A","10","3","214","42","2023-02-25T01:41:41Z","2019-10-14T22:32:11Z","7604" +"*/goWMIExec_linux_*",".{0,1000}\/goWMIExec_linux_.{0,1000}","offensive_tool_keyword","goWMIExec","re-implementation of invoke-wmiexec (Lateral Movement)","T1021.005","TA0008","N/A","N/A","Lateral Movement","https://github.com/C-Sto/goWMIExec","1","1","#linux","N/A","10","3","214","42","2023-02-25T01:41:41Z","2019-10-14T22:32:11Z","7605" +"*/goWMIExec_mac_*",".{0,1000}\/goWMIExec_mac_.{0,1000}","offensive_tool_keyword","goWMIExec","re-implementation of invoke-wmiexec (Lateral Movement)","T1021.005","TA0008","N/A","N/A","Lateral Movement","https://github.com/C-Sto/goWMIExec","1","1","N/A","N/A","10","3","214","42","2023-02-25T01:41:41Z","2019-10-14T22:32:11Z","7606" +"*/goWMIExec_win_*",".{0,1000}\/goWMIExec_win_.{0,1000}","offensive_tool_keyword","goWMIExec","re-implementation of invoke-wmiexec (Lateral Movement)","T1021.005","TA0008","N/A","N/A","Lateral Movement","https://github.com/C-Sto/goWMIExec","1","1","N/A","N/A","10","3","214","42","2023-02-25T01:41:41Z","2019-10-14T22:32:11Z","7607" +"*/goZulipC2.git*",".{0,1000}\/goZulipC2\.git.{0,1000}","offensive_tool_keyword","goZulipC2","C2 leveraging Zulip Messaging Platform as Backend.","T1090 - T1090.003 - T1071 - T1071.001","TA0011 - TA0009","N/A","N/A","C2","https://github.com/n1k7l4i/goZulipC2","1","1","N/A","N/A","10","","N/A","","","","7608" +"*/GPOBrowser.py*",".{0,1000}\/GPOBrowser\.py.{0,1000}","offensive_tool_keyword","Adcheck","Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle","T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009","N/A","N/A","Discovery","https://github.com/CobblePot59/Adcheck","1","1","N/A","N/A","10","4","315","35","2025-04-18T15:17:46Z","2024-05-10T13:54:45Z","7609" +"*/GPOddity.git*",".{0,1000}\/GPOddity\.git.{0,1000}","offensive_tool_keyword","GPOddity","GPO attack vectors through NTLM relaying","T1558.001 - T1552.001","TA0003 - TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/synacktiv/GPOddity","1","1","N/A","N/A","9","3","297","26","2024-11-08T15:14:06Z","2023-09-01T08:13:25Z","7610" +"*/GPOddity/*",".{0,1000}\/GPOddity\/.{0,1000}","offensive_tool_keyword","GPOddity","GPO attack vectors through NTLM relaying","T1558.001 - T1552.001","TA0003 - TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/synacktiv/GPOddity","1","1","N/A","N/A","9","3","297","26","2024-11-08T15:14:06Z","2023-09-01T08:13:25Z","7611" +"*/gpp_autologin.py*",".{0,1000}\/gpp_autologin\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","7612" +"*/gpp_password.py*",".{0,1000}\/gpp_password\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","7613" +"*/gpp-decrypt*",".{0,1000}\/gpp\-decrypt.{0,1000}","offensive_tool_keyword","gpp-decrypt","Decrypt the given Group Policy Preferences","T1552.002 - T1212","TA0009 - TA0006","N/A","N/A","Credential Access","https://gitlab.com/kalilinux/packages/gpp-decrypt","1","1","N/A","N/A","6","10","N/A","N/A","N/A","N/A","7614" +"*/gpsd-info.nse*",".{0,1000}\/gpsd\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7615" +"*/grabchrome.exe*",".{0,1000}\/grabchrome\.exe.{0,1000}","offensive_tool_keyword","GrabChrome","HelloKitty Grabber used by Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","7616" +"*/Graphpython.git*",".{0,1000}\/Graphpython\.git.{0,1000}","offensive_tool_keyword","Graphpython","Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit","T1078.004 - T1114.002","TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010","N/A","N/A","Discovery","https://github.com/mlcsec/Graphpython","1","1","N/A","N/A","7","2","145","13","2024-12-07T21:54:00Z","2024-07-10T00:04:48Z","7617" +"*/Graphpython.py*",".{0,1000}\/Graphpython\.py.{0,1000}","offensive_tool_keyword","Graphpython","Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit","T1078.004 - T1114.002","TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010","N/A","N/A","Discovery","https://github.com/mlcsec/Graphpython","1","1","N/A","N/A","7","2","145","13","2024-12-07T21:54:00Z","2024-07-10T00:04:48Z","7618" +"*/GraphRunner.git*",".{0,1000}\/GraphRunner\.git.{0,1000}","offensive_tool_keyword","GraphRunner","A Post-exploitation Toolset for Interacting with the Microsoft Graph API","T1059.007 - T1087.001 - T1078.001 - T1585.001 - T1071.001","TA0002 - TA0003 - TA0008 - TA0011","N/A","N/A","Exploitation tool","https://github.com/dafthack/GraphRunner","1","1","N/A","N/A","10","10","1082","127","2024-11-07T04:40:34Z","2023-08-15T17:19:11Z","7619" +"*/GraphRunner.ps1*",".{0,1000}\/GraphRunner\.ps1.{0,1000}","offensive_tool_keyword","GraphRunner","A Post-exploitation Toolset for Interacting with the Microsoft Graph API","T1059.007 - T1087.001 - T1078.001 - T1585.001 - T1071.001","TA0002 - TA0003 - TA0008 - TA0011","N/A","N/A","Exploitation tool","https://github.com/dafthack/GraphRunner","1","1","N/A","N/A","10","10","1082","127","2024-11-07T04:40:34Z","2023-08-15T17:19:11Z","7620" +"*/GraphRunner-main*",".{0,1000}\/GraphRunner\-main.{0,1000}","offensive_tool_keyword","GraphRunner","A Post-exploitation Toolset for Interacting with the Microsoft Graph API","T1059.007 - T1087.001 - T1078.001 - T1585.001 - T1071.001","TA0002 - TA0003 - TA0008 - TA0011","N/A","N/A","Exploitation tool","https://github.com/dafthack/GraphRunner","1","1","N/A","N/A","10","10","1082","127","2024-11-07T04:40:34Z","2023-08-15T17:19:11Z","7621" +"*/GraphSpy.git*",".{0,1000}\/GraphSpy\.git.{0,1000}","offensive_tool_keyword","GraphSpy","Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI","T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656","TA0001 - TA0006 - TA0003 - TA0005 - TA0008","N/A","N/A","Collection","https://github.com/RedByte1337/GraphSpy","1","1","N/A","N/A","10","7","680","72","2025-04-15T21:07:15Z","2024-02-07T19:47:15Z","7622" +"*/GraphSpy.py*",".{0,1000}\/GraphSpy\.py.{0,1000}","offensive_tool_keyword","GraphSpy","Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI","T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656","TA0001 - TA0006 - TA0003 - TA0005 - TA0008","N/A","N/A","Collection","https://github.com/RedByte1337/GraphSpy","1","1","N/A","N/A","10","7","680","72","2025-04-15T21:07:15Z","2024-02-07T19:47:15Z","7623" +"*/GraphStrike.cna*",".{0,1000}\/GraphStrike\.cna.{0,1000}","offensive_tool_keyword","GraphStrike","Cobalt Strike HTTPS beaconing over Microsoft Graph API","T1102 - T1071.001 ","TA0002 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/RedSiege/GraphStrike","1","1","N/A","N/A","10","10","585","95","2024-06-25T11:18:19Z","2024-01-02T00:18:44Z","7624" +"*/GraphStrike.git*",".{0,1000}\/GraphStrike\.git.{0,1000}","offensive_tool_keyword","GraphStrike","Cobalt Strike HTTPS beaconing over Microsoft Graph API","T1102 - T1071.001 ","TA0002 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/RedSiege/GraphStrike","1","1","N/A","N/A","10","10","585","95","2024-06-25T11:18:19Z","2024-01-02T00:18:44Z","7625" +"*/graphstrike.profile*",".{0,1000}\/graphstrike\.profile.{0,1000}","offensive_tool_keyword","GraphStrike","Cobalt Strike HTTPS beaconing over Microsoft Graph API","T1102 - T1071.001 ","TA0002 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/RedSiege/GraphStrike","1","1","N/A","N/A","10","10","585","95","2024-06-25T11:18:19Z","2024-01-02T00:18:44Z","7626" +"*/GraphStrike.py*",".{0,1000}\/GraphStrike\.py.{0,1000}","offensive_tool_keyword","GraphStrike","Cobalt Strike HTTPS beaconing over Microsoft Graph API","T1102 - T1071.001 ","TA0002 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/RedSiege/GraphStrike","1","1","N/A","N/A","10","10","585","95","2024-06-25T11:18:19Z","2024-01-02T00:18:44Z","7627" +"*/GreameRAT.exe*",".{0,1000}\/GreameRAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","7629" +"*/GreatSCT/*",".{0,1000}\/GreatSCT\/.{0,1000}","offensive_tool_keyword","GreatSCT","The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This tool is intended for BOTH red and blue team.","T1055 - T1112 - T1189 - T1205","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/GreatSCT/GreatSCT","1","1","N/A","N/A","N/A","10","1127","202","2021-02-10T22:05:27Z","2017-05-12T03:30:41Z","7630" +"*/greatsct-output*",".{0,1000}\/greatsct\-output.{0,1000}","offensive_tool_keyword","GreatSCT","The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This tool is intended for BOTH red and blue team.","T1055 - T1112 - T1189 - T1205","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/GreatSCT/GreatSCT","1","1","N/A","N/A","N/A","10","1127","202","2021-02-10T22:05:27Z","2017-05-12T03:30:41Z","7632" +"*/Group3r.exe*",".{0,1000}\/Group3r\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","7633" +"*/Group3r.exe*",".{0,1000}\/Group3r\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","7634" +"*/Group3r.exe*",".{0,1000}\/Group3r\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","7635" +"*/Group3r.git*",".{0,1000}\/Group3r\.git.{0,1000}","offensive_tool_keyword","Group3r","Find vulnerabilities in AD Group Policy","T1484.002 - T1069.002 - T1087.002","TA0007 - TA0040","N/A","KNOTWEED","Discovery","https://github.com/Group3r/Group3r","1","1","N/A","AD Enumeration","7","8","781","68","2025-04-08T05:03:34Z","2021-07-05T05:05:42Z","7636" +"*/Group3r/releases/download/*",".{0,1000}\/Group3r\/releases\/download\/.{0,1000}","offensive_tool_keyword","Group3r","Find vulnerabilities in AD Group Policy","T1484.002 - T1069.002 - T1087.002","TA0007 - TA0040","N/A","KNOTWEED","Discovery","https://github.com/Group3r/Group3r","1","1","N/A","AD Enumeration","7","8","781","68","2025-04-08T05:03:34Z","2021-07-05T05:05:42Z","7637" +"*/Grouper2.exe*",".{0,1000}\/Grouper2\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","7638" +"*/Grouper2.exe*",".{0,1000}\/Grouper2\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","7639" +"*/GruntHTTP.exe*",".{0,1000}\/GruntHTTP\.exe.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","7640" +"*/gsecdump-*.exe*",".{0,1000}\/gsecdump\-.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","7641" +"*/gsecdump.exe*",".{0,1000}\/gsecdump\.exe.{0,1000}","offensive_tool_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","7642" +"*/gsocket-*.tar.gz*",".{0,1000}\/gsocket\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7644" +"*/gsocket.git*",".{0,1000}\/gsocket\.git.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7646" +"*/gsocket/releases/latest*",".{0,1000}\/gsocket\/releases\/latest.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7647" +"*/gsocket_*_all.deb*",".{0,1000}\/gsocket_.{0,1000}_all\.deb.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7648" +"*/gsocket_*_x86_64.deb*",".{0,1000}\/gsocket_.{0,1000}_x86_64\.deb.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7649" +"*/gsocket_*aarch64.deb*",".{0,1000}\/gsocket_.{0,1000}aarch64\.deb.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7650" +"*/gsocket_*arm.deb*",".{0,1000}\/gsocket_.{0,1000}arm\.deb.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7651" +"*/gsocket_*armv6.deb*",".{0,1000}\/gsocket_.{0,1000}armv6\.deb.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7652" +"*/gsocket_*armv7l.deb*",".{0,1000}\/gsocket_.{0,1000}armv7l\.deb.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7653" +"*/gsocket_*i686.deb*",".{0,1000}\/gsocket_.{0,1000}i686\.deb.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7654" +"*/gsocket_*mips32.deb*",".{0,1000}\/gsocket_.{0,1000}mips32\.deb.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7655" +"*/gsocket_*mips64.deb*",".{0,1000}\/gsocket_.{0,1000}mips64\.deb.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7656" +"*/gsocket_*mipsel.deb*",".{0,1000}\/gsocket_.{0,1000}mipsel\.deb.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7657" +"*/gsocket_dso.so.*",".{0,1000}\/gsocket_dso\.so\..{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7658" +"*/gsocket_latest_all.deb*",".{0,1000}\/gsocket_latest_all\.deb.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7659" +"*/gsocket-build*",".{0,1000}\/gsocket\-build.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7660" +"*/gsocket-deb*",".{0,1000}\/gsocket\-deb.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7661" +"*/gsocket-pkg/*",".{0,1000}\/gsocket\-pkg\/.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7662" +"*/gsocket-src*",".{0,1000}\/gsocket\-src.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7663" +"*/gsocket-tor*",".{0,1000}\/gsocket\-tor.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7665" +"*/gsocket-tor*",".{0,1000}\/gsocket\-tor.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7666" +"*/gs-portforward.service*",".{0,1000}\/gs\-portforward\.service.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7668" +"*/gs-root-shell.service*",".{0,1000}\/gs\-root\-shell\.service.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","7669" +"*/gtfobin_update.py*",".{0,1000}\/gtfobin_update\.py.{0,1000}","offensive_tool_keyword","GTFONow","Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.","T1548.003 - T1548.002 - T1548.001","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/Frissi0n/GTFONow","1","1","N/A","N/A","6","6","566","73","2024-11-10T08:38:30Z","2021-01-18T21:16:40Z","7672" +"*/gtfobins.py*",".{0,1000}\/gtfobins\.py.{0,1000}","offensive_tool_keyword","BeRoot","Privilege Escalation Project - Windows / Linux / Mac ","T1053.005 - T1069.002 - T1069.001 - T1053.003 - T1087.001 - T1087.002 - T1082 - T1135 - T1049 - T1007","TA0004","N/A","N/A","Privilege Escalation","https://github.com/AlessandroZ/BeRoot","1","1","#linux","N/A","10","10","2523","459","2024-10-04T11:54:01Z","2017-04-14T12:47:31Z","7674" +"*/gtfonow.py*",".{0,1000}\/gtfonow\.py.{0,1000}","offensive_tool_keyword","GTFONow","Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.","T1548.003 - T1548.002 - T1548.001","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/Frissi0n/GTFONow","1","1","N/A","N/A","6","6","566","73","2024-11-10T08:38:30Z","2021-01-18T21:16:40Z","7675" +"*/gTunnel.git*",".{0,1000}\/gTunnel\.git.{0,1000}","offensive_tool_keyword","gTunnel","tunelling solution written in golang","T1573.002 - T1071 - T1090 - T1105 - T1020","TA0005 - TA0010 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hotnops/gTunnel","1","1","N/A","N/A","10","10","266","49","2023-05-17T05:24:58Z","2020-03-09T02:52:48Z","7676" +"*/gTunnel/gtuncli*",".{0,1000}\/gTunnel\/gtuncli.{0,1000}","offensive_tool_keyword","gTunnel","tunelling solution written in golang","T1573.002 - T1071 - T1090 - T1105 - T1020","TA0005 - TA0010 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hotnops/gTunnel","1","1","N/A","N/A","10","10","266","49","2023-05-17T05:24:58Z","2020-03-09T02:52:48Z","7677" +"*/gtunnel/releases/*",".{0,1000}\/gtunnel\/releases\/.{0,1000}","offensive_tool_keyword","gTunnel","tunelling solution written in golang","T1573.002 - T1071 - T1090 - T1105 - T1020","TA0005 - TA0010 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hotnops/gTunnel","1","1","N/A","N/A","10","10","266","49","2023-05-17T05:24:58Z","2020-03-09T02:52:48Z","7678" +"*/gtunnel/tarball/*",".{0,1000}\/gtunnel\/tarball\/.{0,1000}","offensive_tool_keyword","gTunnel","tunelling solution written in golang","T1573.002 - T1071 - T1090 - T1105 - T1020","TA0005 - TA0010 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hotnops/gTunnel","1","1","N/A","N/A","10","10","266","49","2023-05-17T05:24:58Z","2020-03-09T02:52:48Z","7679" +"*/gtunnel/zipball/*",".{0,1000}\/gtunnel\/zipball\/.{0,1000}","offensive_tool_keyword","gTunnel","tunelling solution written in golang","T1573.002 - T1071 - T1090 - T1105 - T1020","TA0005 - TA0010 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hotnops/gTunnel","1","1","N/A","N/A","10","10","266","49","2023-05-17T05:24:58Z","2020-03-09T02:52:48Z","7680" +"*/guervild/BOFs*",".{0,1000}\/guervild\/BOFs.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/guervild/BOFs","1","1","N/A","N/A","10","10","161","27","2022-05-02T16:59:24Z","2021-03-15T23:30:22Z","7683" +"*/gyaansastra/CVE-2022-0847*",".{0,1000}\/gyaansastra\/CVE\-2022\-0847.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0008","N/A","N/A","Exploitation tool","https://github.com/gyaansastra/CVE-2022-0847","1","1","N/A","N/A","N/A","1","2","2","2022-03-20T15:46:04Z","2022-03-09T15:44:58Z","7685" +"*/GzipB64.exe*",".{0,1000}\/GzipB64\.exe.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","7686" +"*/H Remote Admin Tools.exe*",".{0,1000}\/H\sRemote\sAdmin\sTools\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","7687" +"*/h4ntu shell [powered by tsoi].php*",".{0,1000}\/h4ntu\sshell\s\[powered\sby\stsoi\]\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","7688" +"*/h8mail/*",".{0,1000}\/h8mail\/.{0,1000}","offensive_tool_keyword","h8mail","Powerful and user-friendly password hunting tool.","T1581.002 - T1591 - T1590 - T1596 - T1592 - T1217.001","TA0010","N/A","N/A","Reconnaissance","https://github.com/opencubicles/h8mail","1","1","N/A","N/A","N/A","1","11","4","2019-08-19T09:46:33Z","2019-08-19T09:45:32Z","7689" +"*/HackBrowserData*",".{0,1000}\/HackBrowserData.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555 - T1189 - T1217 - T1185","TA0002 - TA0009 - TA0001 - TA0010","N/A","N/A","Exploitation tool","https://github.com/moonD4rk/HackBrowserData","1","1","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7690" +"*/hack-browser-data.exe*",".{0,1000}\/hack\-browser\-data\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","7691" +"*/HackBrowserData.git*",".{0,1000}\/HackBrowserData\.git.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7692" +"*/hack-browser-data-linux-386.zip*",".{0,1000}\/hack\-browser\-data\-linux\-386\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","#linux","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7693" +"*/hack-browser-data-linux-amd64.zip*",".{0,1000}\/hack\-browser\-data\-linux\-amd64\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","#linux","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7694" +"*/hack-browser-data-linux-arm.zip*",".{0,1000}\/hack\-browser\-data\-linux\-arm\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","#linux","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7695" +"*/hack-browser-data-linux-arm64.zip*",".{0,1000}\/hack\-browser\-data\-linux\-arm64\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","#linux","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7696" +"*/hack-browser-data-osx-64bit.zip*",".{0,1000}\/hack\-browser\-data\-osx\-64bit\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7697" +"*/hack-browser-data-windows-32bit.zip*",".{0,1000}\/hack\-browser\-data\-windows\-32bit\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7698" +"*/hack-browser-data-windows-64bit.zip*",".{0,1000}\/hack\-browser\-data\-windows\-64bit\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7699" +"*/hackerid.py*",".{0,1000}\/hackerid\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","7700" +"*/hackingtool.git*",".{0,1000}\/hackingtool\.git.{0,1000}","offensive_tool_keyword","hackingtool","ALL IN ONE Hacking Tool For Hackers","T1059 - T1078 - T1105 - T1110 - T1566","TA0002 - TA0008 - TA0009 - TA0005 - TA0007","N/A","N/A","Exploitation tool","https://github.com/Z4nzu/hackingtool","1","1","N/A","N/A","N/A","10","52217","5629","2025-03-03T15:17:19Z","2020-04-11T09:21:31Z","7701" +"*/hackshell.sh*",".{0,1000}\/hackshell\.sh.{0,1000}","offensive_tool_keyword","hackshell","Make BASH stealthy and hacker friendly with lots of bash functions","T1070.003 - T1059.004 - T1564.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/hackerschoice/hackshell","1","1","N/A","N/A","9","3","251","28","2025-04-21T11:23:41Z","2024-07-16T15:56:11Z","7702" +"*/Hack-Tools.git*",".{0,1000}\/Hack\-Tools\.git.{0,1000}","offensive_tool_keyword","hack-tools","The all-in-one Red Team browser extension for Web Pentester","T1059.007 - T1505 - T1068 - T1216 - T1547.009","TA0002 - TA0001 - TA0009","N/A","N/A","Vulnerability Scanner","https://github.com/LasCC/Hack-Tools","1","1","N/A","N/A","9","10","6045","678","2025-01-05T23:10:49Z","2020-06-22T21:42:16Z","7703" +"*/hades.git*",".{0,1000}\/hades\.git.{0,1000}","offensive_tool_keyword","hades","Go shellcode loader that combines multiple evasion techniques","T1055 - T1027 - T1218 - T1027.001 - T1036","TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/f1zm0/hades","1","1","N/A","N/A","N/A","4","364","47","2023-06-21T19:22:57Z","2022-10-11T08:16:24Z","7705" +"*/HadesLdr.git*",".{0,1000}\/HadesLdr\.git.{0,1000}","offensive_tool_keyword","HadesLdr","Shellcode Loader Implementing Indirect Dynamic Syscall - API Hashing - Fileless Shellcode retrieving using Winsock2","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CognisysGroup/HadesLdr","1","1","N/A","N/A","10","3","292","47","2023-07-15T21:23:49Z","2023-07-12T11:44:07Z","7706" +"*/hades-main.zip*",".{0,1000}\/hades\-main\.zip.{0,1000}","offensive_tool_keyword","hades","Go shellcode loader that combines multiple evasion techniques","T1055 - T1027 - T1218 - T1027.001 - T1036","TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/f1zm0/hades","1","1","N/A","N/A","N/A","4","364","47","2023-06-21T19:22:57Z","2022-10-11T08:16:24Z","7707" +"*/hadoop-datanode-info.nse*",".{0,1000}\/hadoop\-datanode\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7708" +"*/hadoop-jobtracker-info.nse*",".{0,1000}\/hadoop\-jobtracker\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7709" +"*/hadoop-namenode-info.nse*",".{0,1000}\/hadoop\-namenode\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7710" +"*/hadoop-secondary-namenode-info.nse*",".{0,1000}\/hadoop\-secondary\-namenode\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7711" +"*/hadoop-tasktracker-info.nse*",".{0,1000}\/hadoop\-tasktracker\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7712" +"*/HAKOPS Binder.exe*",".{0,1000}\/HAKOPS\sBinder\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","7715" +"*/HAKOPS RAT.exe*",".{0,1000}\/HAKOPS\sRAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","7716" +"*/hakrawler.git*",".{0,1000}\/hakrawler\.git.{0,1000}","offensive_tool_keyword","hakrawler","Simple fast web crawler designed for easy and quick discovery of endpoints and assets within a web application","T1190 - T1212 - T1087.001","TA0007 - TA0003 - TA0009","N/A","N/A","Vulnerability Scanner","https://github.com/hakluke/hakrawler","1","1","#linux","N/A","6","10","4683","520","2024-12-21T20:40:03Z","2019-12-15T13:54:43Z","7717" +"*/hancitor.profile*",".{0,1000}\/hancitor\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","7718" +"*/HandleHijacker.cpp*",".{0,1000}\/HandleHijacker\.cpp.{0,1000}","offensive_tool_keyword","PoolParty","A set of fully-undetectable process injection techniques abusing Windows Thread Pools","T1055","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/SafeBreach-Labs/PoolParty","1","1","N/A","N/A","9","10","1088","143","2023-12-11T10:52:05Z","2023-05-21T16:13:32Z","7719" +"*/HandleHijacker.hpp*",".{0,1000}\/HandleHijacker\.hpp.{0,1000}","offensive_tool_keyword","PoolParty","A set of fully-undetectable process injection techniques abusing Windows Thread Pools","T1055","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/SafeBreach-Labs/PoolParty","1","1","N/A","N/A","9","10","1088","143","2023-12-11T10:52:05Z","2023-05-21T16:13:32Z","7720" +"*/handlekatz.py*",".{0,1000}\/handlekatz\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","7721" +"*/HandleKatz_BOF*",".{0,1000}\/HandleKatz_BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF port of the research of @thefLinkk and @codewhitesec","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/HandleKatz_BOF","1","1","N/A","N/A","10","10","96","18","2021-10-12T21:38:02Z","2021-10-12T18:45:06Z","7722" +"*/Harmmy Rat v1.*.exe*",".{0,1000}\/Harmmy\sRat\sv1\..{0,1000}\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","7723" +"*/HaryyUser.exe*",".{0,1000}\/HaryyUser\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","7724" +"*/hashcat-rule.git*",".{0,1000}\/hashcat\-rule\.git.{0,1000}","offensive_tool_keyword","hashcat-rule","Rule for hashcat or john. Aiming to crack how people generate their password","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/clem9669/hashcat-rule","1","1","#linux","N/A","10","5","435","47","2024-09-02T20:14:15Z","2020-03-06T17:20:40Z","7727" +"*/hashcrack_com.rb*",".{0,1000}\/hashcrack_com\.rb.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","7728" +"*/hashcracking.rb*",".{0,1000}\/hashcracking\.rb.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","7729" +"*/hashdump_dc*",".{0,1000}\/hashdump_dc.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","7730" +"*/hashesorg2019.gz*",".{0,1000}\/hashesorg2019\.gz.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","7731" +"*/Hashi0x/*",".{0,1000}\/Hashi0x\/.{0,1000}","offensive_tool_keyword","poc","Windows Message Queuing vulnerability exploitation with custom payloads","T1192 - T1507","TA0002","N/A","N/A","Exploitation tool","https://github.com/Hashi0x/PoC-CVE-2023-21554","1","1","N/A","network exploitation tool","N/A","","N/A","","","","7732" +"*/hashview.py*",".{0,1000}\/hashview\.py.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","7733" +"*/havex.profile*",".{0,1000}\/havex\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","7734" +"*/Havoc.cpp*",".{0,1000}\/Havoc\.cpp.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","7735" +"*/Havoc.qss*",".{0,1000}\/Havoc\.qss.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","7736" +"*/Havoc.rc*",".{0,1000}\/Havoc\.rc.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","7737" +"*/Havoc/data/*",".{0,1000}\/Havoc\/data\/.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","7738" +"*/Havoc/main/*",".{0,1000}\/Havoc\/main\/.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","7739" +"*/havoc_bof.py*",".{0,1000}\/havoc_bof\.py.{0,1000}","offensive_tool_keyword","PoolPartyBof","A beacon object file implementation of PoolParty Process Injection Technique","T1055.011 - T1055 - T1620","TA0005","N/A","Black Basta","Privilege Escalation","https://github.com/0xEr3bus/PoolPartyBof","1","1","N/A","N/A","10","4","380","44","2023-12-21T19:00:20Z","2023-12-11T19:28:20Z","7740" +"*/HavocFramework/*",".{0,1000}\/HavocFramework\/.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","7741" +"*/HavocImages/*",".{0,1000}\/HavocImages\/.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","7742" +"*/havoc-py/*",".{0,1000}\/havoc\-py\/.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","7743" +"*/HavRat.exe*",".{0,1000}\/HavRat\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","7744" +"*/hbase-master-info.nse*",".{0,1000}\/hbase\-master\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7745" +"*/hbase-region-info.nse*",".{0,1000}\/hbase\-region\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7746" +"*/hddtemp-info.nse*",".{0,1000}\/hddtemp\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7747" +"*/hDendron.cs*",".{0,1000}\/hDendron\.cs.{0,1000}","offensive_tool_keyword","Dendrobate","Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code","T1055.012 - T1059.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Dendrobate","1","1","N/A","N/A","10","2","131","27","2021-11-19T12:18:50Z","2021-02-15T11:15:51Z","7748" +"*/HeapCrypt.git*",".{0,1000}\/HeapCrypt\.git.{0,1000}","offensive_tool_keyword","HeapCrypt","Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap","T1055.001 - T1027 - T1146","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/HeapCrypt","1","1","N/A","N/A","9","3","239","44","2023-08-02T02:24:42Z","2023-03-25T05:19:52Z","7749" +"*/HellHall.git*",".{0,1000}\/HellHall\.git.{0,1000}","offensive_tool_keyword","HellsHall","Performing Indirect Clean Syscalls","T1106","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Maldev-Academy/HellHall","1","1","N/A","N/A","8","6","535","71","2023-04-19T06:10:47Z","2023-01-03T04:43:05Z","7750" +"*/HellsGate.git*",".{0,1000}\/HellsGate\.git.{0,1000}","offensive_tool_keyword","HellsGate","The Hell's Gate technique is a method employed by malware to hide its malicious behavior and avoid detection. This technique involves executing system calls directly thus bypassing the Windows API (Application Programming Interface) which is typically monitored by EDRs","T1055 - T1548.002 - T1129","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/am0nsec/HellsGate","1","1","N/A","N/A","N/A","10","1028","121","2021-06-28T15:42:36Z","2020-06-02T17:10:21Z","7751" +"*/HellsHall.exe*",".{0,1000}\/HellsHall\.exe.{0,1000}","offensive_tool_keyword","HellsHall","Performing Indirect Clean Syscalls","T1106","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Maldev-Academy/HellHall","1","1","N/A","N/A","8","6","535","71","2023-04-19T06:10:47Z","2023-01-03T04:43:05Z","7752" +"*/Heroinn.git*",".{0,1000}\/Heroinn\.git.{0,1000}","offensive_tool_keyword","Heroinn","A cross platform C2/post-exploitation framework implementation by Rust.","T1059 - T1547 - T1068 - T1562 - T1110 - T1083 - T1021 - T1071","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/b23r0/Heroinn","1","1","N/A","N/A","10","10","672","215","2022-10-08T07:27:38Z","2015-05-16T14:54:19Z","7761" +"*/Heroinn/*",".{0,1000}\/Heroinn\/.{0,1000}","offensive_tool_keyword","Heroinn","A cross platform C2/post-exploitation framework implementation by Rust.","T1059 - T1547 - T1068 - T1562 - T1110 - T1083 - T1021 - T1071","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/b23r0/Heroinn","1","1","N/A","N/A","10","10","672","215","2022-10-08T07:27:38Z","2015-05-16T14:54:19Z","7762" +"*/hid_inject.*",".{0,1000}\/hid_inject\..{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","7764" +"*/hid_sniff.*",".{0,1000}\/hid_sniff\..{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","7765" +"*/HiddenDesktop.git*",".{0,1000}\/HiddenDesktop\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","Hidden Desktop (often referred to as HVNC) is a tool that allows operators to interact with a remote desktop session without the user knowing. The VNC protocol is not involved but the result is a similar experience. This Cobalt Strike BOF implementation was created as an alternative to TinyNuke/forks that are written in C++","T1021.001 - T1133","TA0005 - TA0002","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/WKL-Sec/HiddenDesktop","1","1","N/A","N/A","10","10","1213","187","2023-12-07T17:15:48Z","2023-05-21T00:57:43Z","7766" +"*/hidden-tear.exe*",".{0,1000}\/hidden\-tear\.exe.{0,1000}","offensive_tool_keyword","hidden-tear","open source ransomware - many variant in the wild","T1486 - T1059 - T1485 - T1489 - T1070 - T1488","TA0005 - TA0009 - TA0040 - TA0042","N/A","N/A","Ransomware","https://github.com/goliate/hidden-tear","1","1","N/A","N/A","10","8","765","394","2020-07-08T22:34:01Z","2015-08-19T09:06:51Z","7767" +"*/hidden-tear.git*",".{0,1000}\/hidden\-tear\.git.{0,1000}","offensive_tool_keyword","hidden-tear","open source ransomware - many variant in the wild","T1486 - T1059 - T1485 - T1489 - T1070 - T1488","TA0005 - TA0009 - TA0040 - TA0042","N/A","N/A","Ransomware","https://github.com/goliate/hidden-tear","1","1","N/A","N/A","10","8","765","394","2020-07-08T22:34:01Z","2015-08-19T09:06:51Z","7768" +"*/HiddenTear.zip*",".{0,1000}\/HiddenTear\.zip.{0,1000}","offensive_tool_keyword","hidden-tear","open source ransomware - many variant in the wild","T1486 - T1059 - T1485 - T1489 - T1070 - T1488","TA0005 - TA0009 - TA0040 - TA0042","N/A","N/A","Ransomware","https://github.com/goliate/hidden-tear","1","1","N/A","N/A","10","8","765","394","2020-07-08T22:34:01Z","2015-08-19T09:06:51Z","7769" +"*/hidden-tear/write.php?info=*",".{0,1000}\/hidden\-tear\/write\.php\?info\=.{0,1000}","offensive_tool_keyword","hidden-tear","open source ransomware - many variant in the wild","T1486 - T1059 - T1485 - T1489 - T1070 - T1488","TA0005 - TA0009 - TA0040 - TA0042","N/A","N/A","Ransomware","https://github.com/goliate/hidden-tear","1","1","N/A","N/A","10","8","765","394","2020-07-08T22:34:01Z","2015-08-19T09:06:51Z","7770" +"*/hidden-tear-remake.git*",".{0,1000}\/hidden\-tear\-remake\.git.{0,1000}","offensive_tool_keyword","hidden-tear","open source ransomware - many variant in the wild","T1486 - T1059 - T1485 - T1489 - T1070 - T1488","TA0005 - TA0009 - TA0040 - TA0042","N/A","N/A","Ransomware","https://github.com/goliate/hidden-tear","1","1","N/A","N/A","10","8","765","394","2020-07-08T22:34:01Z","2015-08-19T09:06:51Z","7771" +"*/hijack_opener/*.js*",".{0,1000}\/hijack_opener\/.{0,1000}\.js.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","7772" +"*/hijack_opener/*.rb*",".{0,1000}\/hijack_opener\/.{0,1000}\.rb.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","7773" +"*/HijackDLL-CreateRemoteThread.cpp*",".{0,1000}\/HijackDLL\-CreateRemoteThread\.cpp.{0,1000}","offensive_tool_keyword","Accomplice","Tools for discovery and abuse of COM hijacks","T1120 - T1174","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/nccgroup/Accomplice","1","1","N/A","N/A","7","4","303","47","2019-10-15T21:54:09Z","2019-09-04T23:32:09Z","7774" +"*/HijackDll-Process.cpp*",".{0,1000}\/HijackDll\-Process\.cpp.{0,1000}","offensive_tool_keyword","Accomplice","Tools for discovery and abuse of COM hijacks","T1120 - T1174","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/nccgroup/Accomplice","1","1","N/A","N/A","7","4","303","47","2019-10-15T21:54:09Z","2019-09-04T23:32:09Z","7775" +"*/HijackDLL-Threads.*",".{0,1000}\/HijackDLL\-Threads\..{0,1000}","offensive_tool_keyword","Accomplice","Tools for discovery and abuse of COM hijacks","T1120 - T1174","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/nccgroup/Accomplice","1","1","N/A","N/A","7","4","303","47","2019-10-15T21:54:09Z","2019-09-04T23:32:09Z","7776" +"*/HijackHunter/*",".{0,1000}\/HijackHunter\/.{0,1000}","offensive_tool_keyword","HijackHunter","Parses a target's PE header in order to find lined DLLs vulnerable to hijacking. Provides reasoning and abuse techniques for each detected hijack opportunity","T1574.002 - T1059.003 - T1078.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/matterpreter/OffensiveCSharp/tree/master/HijackHunter","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","7777" +"*/HInvoke.cs*",".{0,1000}\/HInvoke\.cs.{0,1000}","offensive_tool_keyword","NixImports","A .NET malware loader using API-Hashing to evade static analysis","T1055.012 - T1562.001 - T1140","TA0005 - TA0003 - TA0040","N/A","N/A","Defense Evasion","https://github.com/dr4k0nia/NixImports","1","1","N/A","N/A","N/A","3","207","23","2023-05-30T14:14:21Z","2023-05-22T18:32:01Z","7778" +"*/hiphp.git*",".{0,1000}\/hiphp\.git.{0,1000}","offensive_tool_keyword","hiphp","The BackDoor of HIPHP gives you the power to control websites based on PHP using HTTP/HTTPS protocol. By sending files - tokens and commands through port 80s POST/GET method - users can access a range of activities such as downloading and editing files. It also allows for connecting to Tor networks with password protection for extra security.","T1105 - T1071.001 - T1132 - T1505 - T1608 - T1560 ","TA0011 - TA0001 - TA0002 - TA0009","N/A","N/A","C2","https://github.com/yasserbdj96/hiphp","1","1","N/A","N/A","10","10","217","33","2025-04-19T07:05:12Z","2021-04-05T20:29:57Z","7779" +"*/hiphp-cli.sh*",".{0,1000}\/hiphp\-cli\.sh.{0,1000}","offensive_tool_keyword","hiphp","The BackDoor of HIPHP gives you the power to control websites based on PHP using HTTP/HTTPS protocol. By sending files - tokens and commands through port 80s POST/GET method - users can access a range of activities such as downloading and editing files. It also allows for connecting to Tor networks with password protection for extra security.","T1105 - T1071.001 - T1132 - T1505 - T1608 - T1560 ","TA0011 - TA0001 - TA0002 - TA0009","N/A","N/A","C2","https://github.com/yasserbdj96/hiphp","1","1","N/A","N/A","10","10","217","33","2025-04-19T07:05:12Z","2021-04-05T20:29:57Z","7780" +"*/hiphp-desktop.sh*",".{0,1000}\/hiphp\-desktop\.sh.{0,1000}","offensive_tool_keyword","hiphp","The BackDoor of HIPHP gives you the power to control websites based on PHP using HTTP/HTTPS protocol. By sending files - tokens and commands through port 80s POST/GET method - users can access a range of activities such as downloading and editing files. It also allows for connecting to Tor networks with password protection for extra security.","T1105 - T1071.001 - T1132 - T1505 - T1608 - T1560 ","TA0011 - TA0001 - TA0002 - TA0009","N/A","N/A","C2","https://github.com/yasserbdj96/hiphp","1","1","N/A","N/A","10","10","217","33","2025-04-19T07:05:12Z","2021-04-05T20:29:57Z","7781" +"*/hiphp-main*",".{0,1000}\/hiphp\-main.{0,1000}","offensive_tool_keyword","hiphp","The BackDoor of HIPHP gives you the power to control websites based on PHP using HTTP/HTTPS protocol. By sending files - tokens and commands through port 80s POST/GET method - users can access a range of activities such as downloading and editing files. It also allows for connecting to Tor networks with password protection for extra security.","T1105 - T1071.001 - T1132 - T1505 - T1608 - T1560 ","TA0011 - TA0001 - TA0002 - TA0009","N/A","N/A","C2","https://github.com/yasserbdj96/hiphp","1","1","N/A","N/A","10","10","217","33","2025-04-19T07:05:12Z","2021-04-05T20:29:57Z","7782" +"*/HiveDump.ps1*",".{0,1000}\/HiveDump\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","7783" +"*/hnap-info.nse*",".{0,1000}\/hnap\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7785" +"*/hoaxshell.git*",".{0,1000}\/hoaxshell\.git.{0,1000}","offensive_tool_keyword","hoaxshell","An unconventional Windows reverse shell. currently undetected by Microsoft Defender and various other AV solutions. solely based on http(s) traffic","T1059 - T1071 - T1071.001 - T1203","TA0002 - TA0011","N/A","N/A","C2","https://github.com/t3l3machus/hoaxshell","1","1","N/A","N/A","N/A","10","3212","499","2025-01-19T12:29:35Z","2022-07-10T15:36:24Z","7786" +"*/hoaxshell/*.py*",".{0,1000}\/hoaxshell\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","7787" +"*/holehe.git*",".{0,1000}\/holehe\.git.{0,1000}","offensive_tool_keyword","holehe","holehe allows you to check if the mail is used on different sites like twitter instagram and will retrieve information on sites with the forgotten password function.","T1598.004 - T1592.002 - T1598.001","TA0003 - TA0009","N/A","N/A","Reconnaissance","https://github.com/megadose/holehe","1","1","#linux","N/A","6","10","8656","981","2024-09-10T20:24:32Z","2020-06-25T23:03:02Z","7788" +"*/hollow.x64.*",".{0,1000}\/hollow\.x64\..{0,1000}","offensive_tool_keyword","cobaltstrike","EarlyBird process hollowing technique (BOF) - Spawns a process in a suspended state. inject shellcode. hijack main thread with APC and execute shellcode","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/HOLLOW","1","1","N/A","N/A","10","10","280","60","2023-03-08T15:51:19Z","2021-07-21T15:58:18Z","7789" +"*/hookchain_finder64.exe*",".{0,1000}\/hookchain_finder64\.exe.{0,1000}","offensive_tool_keyword","hookchain","Bypassing EDR Solutions","T1055.011 - T1564.001 - T1070.004 - T1562.001 - T1222","TA0005","N/A","N/A","Defense Evasion","https://github.com/helviojunior/hookchain","1","1","N/A","N/A","9","6","513","85","2025-01-05T22:00:17Z","2024-03-22T13:18:02Z","7802" +"*/HookChain_msg.exe*",".{0,1000}\/HookChain_msg\.exe.{0,1000}","offensive_tool_keyword","hookchain","Bypassing EDR Solutions","T1055.011 - T1564.001 - T1070.004 - T1562.001 - T1222","TA0005","N/A","N/A","Defense Evasion","https://github.com/helviojunior/hookchain","1","1","N/A","N/A","9","6","513","85","2025-01-05T22:00:17Z","2024-03-22T13:18:02Z","7803" +"*/HookDetector.exe*",".{0,1000}\/HookDetector\.exe.{0,1000}","offensive_tool_keyword","HookDetector","Detects hooked Native API functions in the current process indicating the presence of EDR","T1055.012 - T1082 - T1057","TA0007 - TA0003","N/A","N/A","Defense Evasion","https://github.com/matterpreter/OffensiveCSharp/tree/master/HookDetector","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","7804" +"*/hooks/spoof.c*",".{0,1000}\/hooks\/spoof\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike UDRL for memory scanner evasion.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/kyleavery/AceLdr","1","1","N/A","N/A","10","10","925","164","2024-06-04T16:45:42Z","2022-08-11T00:06:09Z","7805" +"*/HookSentry.exe*",".{0,1000}\/HookSentry\.exe.{0,1000}","offensive_tool_keyword","HookSentry","tool for inspecting system DLLs loaded into processes - looking for functions hooked from AV/EDR.","T1055.001 - T1055 - T1057","TA0007 - TA0005","N/A","N/A","Defense Evasion","https://github.com/UmaRex01/HookSentry","0","1","N/A","N/A","6","1","27","2","2025-04-02T12:30:58Z","2024-11-20T18:09:39Z","7806" +"*/HookSentry.git*",".{0,1000}\/HookSentry\.git.{0,1000}","offensive_tool_keyword","HookSentry","tool for inspecting system DLLs loaded into processes - looking for functions hooked from AV/EDR.","T1055.001 - T1055 - T1057","TA0007 - TA0005","N/A","N/A","Defense Evasion","https://github.com/UmaRex01/HookSentry","1","1","N/A","N/A","6","1","27","2","2025-04-02T12:30:58Z","2024-11-20T18:09:39Z","7807" +"*/horizon3ai/*",".{0,1000}\/horizon3ai\/.{0,1000}","offensive_tool_keyword","vRealizeLogInsightRCE","POC for VMSA-2023-0001 affecting VMware vRealize Log Insight which includes the following CVEs: VMware vRealize Log Insight Directory Traversal Vulnerability (CVE-2022-31706) VMware vRealize Log Insight broken access control Vulnerability (CVE-2022-31704) VMware vRealize Log Insight contains an Information Disclosure Vulnerability (CVE-2022-31711)","T1190 - T1071 - T1003 - T1069 - T1110 - T1222","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007","N/A","Black Basta","Exploitation tool","https://github.com/horizon3ai/vRealizeLogInsightRCE","1","1","N/A","Added to cover the POC exploitation used in massive ransomware campagne that exploit public facing Vmware ESXI product ","4","2","149","22","2023-01-31T11:41:08Z","2023-01-30T22:01:08Z","7809" +"*/HostEnum.ps1*",".{0,1000}\/HostEnum\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","7811" +"*/hostenum.py*",".{0,1000}\/hostenum\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script function and alias to perform some rudimentary Windows host enumeration with Beacon built-in commands","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/red-team-scripts","1","1","N/A","N/A","10","10","1122","195","2024-11-19T19:39:01Z","2017-05-01T13:53:05Z","7812" +"*/hostmap-bfk.nse*",".{0,1000}\/hostmap\-bfk\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7813" +"*/hostmap-crtsh.nse*",".{0,1000}\/hostmap\-crtsh\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7814" +"*/hostmap-robtex.nse*",".{0,1000}\/hostmap\-robtex\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7815" +"*/Hotkeyz.exe*",".{0,1000}\/Hotkeyz\.exe.{0,1000}","offensive_tool_keyword","hotkeyz","Hotkey-based keylogger for Windows","T1056.001","TA0006 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/yo-yo-yo-jbo/hotkeyz","1","1","N/A","N/A","9","1","21","1","2024-10-17T17:50:19Z","2024-06-03T21:23:16Z","7817" +"*/hotkeyz.git*",".{0,1000}\/hotkeyz\.git.{0,1000}","offensive_tool_keyword","hotkeyz","Hotkey-based keylogger for Windows","T1056.001","TA0006 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/yo-yo-yo-jbo/hotkeyz","1","1","N/A","N/A","9","1","21","1","2024-10-17T17:50:19Z","2024-06-03T21:23:16Z","7818" +"*/HouQing/*/Loader.go",".{0,1000}\/HouQing\/.{0,1000}\/Loader\.go","offensive_tool_keyword","cobaltstrike","Hou Qing-Advanced AV Evasion Tool For Red Team Ops","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Hangingsword/HouQing","1","1","N/A","N/A","10","10","205","60","2021-01-14T08:38:12Z","2021-01-14T07:13:21Z","7819" +"*/HRShell.git*",".{0,1000}\/HRShell\.git.{0,1000}","offensive_tool_keyword","HRShell","HRShell is an HTTPS/HTTP reverse shell built with flask. It is an advanced C2 server with many features & capabilities.","T1021.002 - T1105 - T1059.001 - T1059.003 - T1064","TA0008 - TA0011 - TA0002","N/A","Black Basta","C2","https://github.com/chrispetrou/HRShell","1","1","N/A","N/A","10","10","247","70","2021-09-09T08:26:32Z","2019-08-20T15:24:46Z","7820" +"*/HRShell/*",".{0,1000}\/HRShell\/.{0,1000}","offensive_tool_keyword","HRShell","HRShell is an HTTPS/HTTP reverse shell built with flask. It is an advanced C2 server with many features & capabilities.","T1021.002 - T1105 - T1059.001 - T1059.003 - T1064","TA0008 - TA0011 - TA0002","N/A","Black Basta","C2","https://github.com/chrispetrou/HRShell","1","1","N/A","N/A","10","10","247","70","2021-09-09T08:26:32Z","2019-08-20T15:24:46Z","7821" +"*/hta_attack/*",".{0,1000}\/hta_attack\/.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","7822" +"*/hta_gen.py*",".{0,1000}\/hta_gen\.py.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","7823" +"*/HTMLSmuggler.git*",".{0,1000}\/HTMLSmuggler\.git.{0,1000}","offensive_tool_keyword","HTMLSmuggler","HTML Smuggling generator&obfuscator for your Red Team operations","T1564.001 - T1027 - T1566","TA0005","N/A","N/A","Phishing","https://github.com/D00Movenok/HTMLSmuggler","1","1","N/A","N/A","10","2","162","19","2024-02-27T23:03:55Z","2023-07-02T08:10:59Z","7824" +"*/HTMLSmuggler/*",".{0,1000}\/HTMLSmuggler\/.{0,1000}","offensive_tool_keyword","HTMLSmuggler","HTML Smuggling generator&obfuscator for your Red Team operations","T1564.001 - T1027 - T1566","TA0005","N/A","N/A","Phishing","https://github.com/D00Movenok/HTMLSmuggler","1","1","N/A","N/A","10","2","162","19","2024-02-27T23:03:55Z","2023-07-02T08:10:59Z","7825" +"*/htran.exe*",".{0,1000}\/htran\.exe.{0,1000}","offensive_tool_keyword","htran","proxies connections through intermediate hops and aids users in disguising their true geographical location. It can be used by adversaries to hide their location when interacting with the victim networks","T1055 - T1090 - T1014","TA0003 - TA0005 - TA0011","N/A","GALLIUM - APT10 - APT12 - Deep Panda - MenuPass","C2","https://github.com/HiwinCN/Htran","1","1","N/A","N/A","9","10","256","88","2021-04-25T09:57:46Z","2015-12-03T04:54:53Z","7826" +"*/HTran.git*",".{0,1000}\/HTran\.git.{0,1000}","offensive_tool_keyword","htran","proxies connections through intermediate hops and aids users in disguising their true geographical location. It can be used by adversaries to hide their location when interacting with the victim networks","T1055 - T1090 - T1014","TA0003 - TA0005 - TA0011","N/A","GALLIUM - APT10 - APT12 - Deep Panda - MenuPass","C2","https://github.com/HiwinCN/Htran","1","1","N/A","N/A","9","10","256","88","2021-04-25T09:57:46Z","2015-12-03T04:54:53Z","7827" +"*/Htran-master.zip*",".{0,1000}\/Htran\-master\.zip.{0,1000}","offensive_tool_keyword","htran","proxies connections through intermediate hops and aids users in disguising their true geographical location. It can be used by adversaries to hide their location when interacting with the victim networks","T1055 - T1090 - T1014","TA0003 - TA0005 - TA0011","N/A","GALLIUM - APT10 - APT12 - Deep Panda - MenuPass","C2","https://github.com/HiwinCN/Htran","1","1","N/A","N/A","9","10","256","88","2021-04-25T09:57:46Z","2015-12-03T04:54:53Z","7828" +"*/htshells.git*",".{0,1000}\/htshells\.git.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","7829" +"*/http_exfiltration.py*",".{0,1000}\/http_exfiltration\.py.{0,1000}","offensive_tool_keyword","PyExfil","A Python Package for Data Exfiltration","T1041 - T1567 - T1027","TA0011 - TA0009 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/ytisf/PyExfil","1","1","N/A","N/A","10","8","782","141","2024-05-07T07:58:02Z","2014-11-27T19:06:24Z","7830" +"*/http_payload.ps1*",".{0,1000}\/http_payload\.ps1.{0,1000}","offensive_tool_keyword","hoaxshell","An unconventional Windows reverse shell. currently undetected by Microsoft Defender and various other AV solutions. solely based on http(s) traffic","T1059 - T1071 - T1071.001 - T1203","TA0002 - TA0011","N/A","N/A","C2","https://github.com/t3l3machus/hoaxshell","1","1","N/A","N/A","N/A","10","3212","499","2025-01-19T12:29:35Z","2022-07-10T15:36:24Z","7831" +"*/http-adobe-coldfusion-apsa1301.nse*",".{0,1000}\/http\-adobe\-coldfusion\-apsa1301\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7832" +"*/http-affiliate-id.nse*",".{0,1000}\/http\-affiliate\-id\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7833" +"*/http-apache-negotiation.nse*",".{0,1000}\/http\-apache\-negotiation\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7834" +"*/http-apache-server-status.nse*",".{0,1000}\/http\-apache\-server\-status\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7835" +"*/http-aspnet-debug.nse*",".{0,1000}\/http\-aspnet\-debug\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7836" +"*/httpattack.py*",".{0,1000}\/httpattack\.py.{0,1000}","offensive_tool_keyword","PKINITtools","Tools for Kerberos PKINIT and relaying to AD CS","T1550.003 - T1557.002 - T1552.004 - T1212 - T1550","TA0009 - TA0008","N/A","N/A","Lateral Movement","https://github.com/dirkjanm/PKINITtools","1","1","N/A","N/A","N/A","8","737","82","2025-01-03T14:25:52Z","2021-07-27T19:06:09Z","7837" +"*/http-auth.nse*",".{0,1000}\/http\-auth\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7838" +"*/http-auth-finder.nse*",".{0,1000}\/http\-auth\-finder\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7839" +"*/http-avaya-ipoffice-users.nse*",".{0,1000}\/http\-avaya\-ipoffice\-users\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7840" +"*/http-awstatstotals-exec.nse*",".{0,1000}\/http\-awstatstotals\-exec\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7841" +"*/http-axis2-dir-traversal.nse*",".{0,1000}\/http\-axis2\-dir\-traversal\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7842" +"*/http-backup-finder.nse*",".{0,1000}\/http\-backup\-finder\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7843" +"*/http-barracuda-dir-traversal.nse*",".{0,1000}\/http\-barracuda\-dir\-traversal\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7844" +"*/http-bigip-cookie.nse*",".{0,1000}\/http\-bigip\-cookie\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7845" +"*/http-brute.nse*",".{0,1000}\/http\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7846" +"*/http-c2.go*",".{0,1000}\/http\-c2\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","7847" +"*/http-cakephp-version.nse*",".{0,1000}\/http\-cakephp\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7848" +"*/http-chrono.nse*",".{0,1000}\/http\-chrono\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7849" +"*/http-cisco-anyconnect.nse*",".{0,1000}\/http\-cisco\-anyconnect\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7850" +"*/http-coldfusion-subzero.nse*",".{0,1000}\/http\-coldfusion\-subzero\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7852" +"*/http-comments-displayer.nse*",".{0,1000}\/http\-comments\-displayer\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7853" +"*/http-config-backup.nse*",".{0,1000}\/http\-config\-backup\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7854" +"*/http-cookie-flags.nse*",".{0,1000}\/http\-cookie\-flags\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7855" +"*/http-cors.nse*",".{0,1000}\/http\-cors\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7856" +"*/http-cross-domain-policy.nse*",".{0,1000}\/http\-cross\-domain\-policy\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7857" +"*/http-csrf.nse*",".{0,1000}\/http\-csrf\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7858" +"*/http-date.nse*",".{0,1000}\/http\-date\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7859" +"*/http-default-accounts.nse*",".{0,1000}\/http\-default\-accounts\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7860" +"*/http-devframework.nse*",".{0,1000}\/http\-devframework\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7861" +"*/http-dlink-backdoor.nse*",".{0,1000}\/http\-dlink\-backdoor\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7862" +"*/http-dombased-xss.nse*",".{0,1000}\/http\-dombased\-xss\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7863" +"*/http-domino-enum-passwords.nse*",".{0,1000}\/http\-domino\-enum\-passwords\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7864" +"*/http-drupal-enum.nse*",".{0,1000}\/http\-drupal\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7865" +"*/http-drupal-enum-users.nse*",".{0,1000}\/http\-drupal\-enum\-users\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7866" +"*/http-enum.nse*",".{0,1000}\/http\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7867" +"*/http-errors.nse*",".{0,1000}\/http\-errors\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7868" +"*/http-exif-spider.nse*",".{0,1000}\/http\-exif\-spider\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7869" +"*/http-favicon.nse*",".{0,1000}\/http\-favicon\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7870" +"*/http-feed.nse*",".{0,1000}\/http\-feed\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7871" +"*/http-fetch.nse*",".{0,1000}\/http\-fetch\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7872" +"*/http-fileupload-exploiter.nse*",".{0,1000}\/http\-fileupload\-exploiter\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7873" +"*/http-form-brute.nse*",".{0,1000}\/http\-form\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7874" +"*/http-form-fuzzer.nse*",".{0,1000}\/http\-form\-fuzzer\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7875" +"*/http-frontpage-login.nse*",".{0,1000}\/http\-frontpage\-login\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7876" +"*/http-generator.nse*",".{0,1000}\/http\-generator\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7877" +"*/http-git.nse*",".{0,1000}\/http\-git\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7878" +"*/http-gitweb-projects-enum.nse*",".{0,1000}\/http\-gitweb\-projects\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7879" +"*/http-google-malware.nse*",".{0,1000}\/http\-google\-malware\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7880" +"*/http-grep.nse*",".{0,1000}\/http\-grep\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7881" +"*/http-headers.nse*",".{0,1000}\/http\-headers\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7882" +"*/http-hp-ilo-info.nse*",".{0,1000}\/http\-hp\-ilo\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7883" +"*/http-huawei-hg5xx-vuln.nse*",".{0,1000}\/http\-huawei\-hg5xx\-vuln\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7884" +"*/http-icloud-findmyiphone.nse*",".{0,1000}\/http\-icloud\-findmyiphone\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7885" +"*/http-icloud-sendmsg.nse*",".{0,1000}\/http\-icloud\-sendmsg\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7886" +"*/http-iis-short-name-brute.nse*",".{0,1000}\/http\-iis\-short\-name\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7887" +"*/http-iis-webdav-vuln.nse*",".{0,1000}\/http\-iis\-webdav\-vuln\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7888" +"*/http-internal-ip-disclosure.nse*",".{0,1000}\/http\-internal\-ip\-disclosure\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7889" +"*/http-joomla-brute.nse*",".{0,1000}\/http\-joomla\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7890" +"*/http-jsonp-detection.nse*",".{0,1000}\/http\-jsonp\-detection\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7891" +"*/http-lexmark-version.nse*",".{0,1000}\/http\-lexmark\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://github.com/nccgroup/nmap-nse-vulnerability-scripts","1","1","N/A","N/A","N/A","7","627","59","2022-03-04T09:08:55Z","2021-05-18T15:20:30Z","7892" +"*/http-lfi.nse*",".{0,1000}\/http\-lfi\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://github.com/cldrn/nmap-nse-scripts/tree/master/scripts","1","1","N/A","N/A","N/A","10","968","369","2022-01-22T18:40:30Z","2011-05-31T05:41:49Z","7893" +"*/http-litespeed-sourcecode-download.nse*",".{0,1000}\/http\-litespeed\-sourcecode\-download\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7894" +"*/HTTP-Login.ps1*",".{0,1000}\/HTTP\-Login\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1109","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","7895" +"*/http-ls.nse*",".{0,1000}\/http\-ls\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7896" +"*/http-majordomo2-dir-traversal.nse*",".{0,1000}\/http\-majordomo2\-dir\-traversal\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7897" +"*/http-malware-host.nse*",".{0,1000}\/http\-malware\-host\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7898" +"*/http-mcmp.nse*",".{0,1000}\/http\-mcmp\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7899" +"*/http-methods.nse*",".{0,1000}\/http\-methods\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7900" +"*/http-method-tamper.nse*",".{0,1000}\/http\-method\-tamper\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7901" +"*/http-mobileversion-checker.nse*",".{0,1000}\/http\-mobileversion\-checker\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7902" +"*/http-nikto-scan.nse*",".{0,1000}\/http\-nikto\-scan\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://github.com/cldrn/nmap-nse-scripts/tree/master/scripts","1","1","N/A","N/A","N/A","10","968","369","2022-01-22T18:40:30Z","2011-05-31T05:41:49Z","7903" +"*/http-ntlm/ntlmtransport*",".{0,1000}\/http\-ntlm\/ntlmtransport.{0,1000}","offensive_tool_keyword","ruler","A tool to abuse Exchange services","T1087 - T1110 - T1133 - T1064 - T1204","TA0007 - TA0006 - TA0003 - TA0002 - TA0005","N/A","APT33","Persistence","https://github.com/sensepost/ruler","1","1","N/A","N/A","10","10","2222","362","2024-06-10T11:03:07Z","2016-08-18T15:05:13Z","7904" +"*/http-ntlm-info.nse*",".{0,1000}\/http\-ntlm\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7905" +"*/http-open-proxy.nse*",".{0,1000}\/http\-open\-proxy\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7906" +"*/http-open-redirect.nse*",".{0,1000}\/http\-open\-redirect\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7907" +"*/http-passwd.nse*",".{0,1000}\/http\-passwd\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7908" +"*/http-phpmyadmin-dir-traversal.nse*",".{0,1000}\/http\-phpmyadmin\-dir\-traversal\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7909" +"*/http-phpself-xss.nse*",".{0,1000}\/http\-phpself\-xss\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7910" +"*/http-php-version.nse*",".{0,1000}\/http\-php\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7911" +"*/http-proxy-brute.nse*",".{0,1000}\/http\-proxy\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7912" +"*/http-put.nse*",".{0,1000}\/http\-put\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7913" +"*/http-qnap-nas-info.nse*",".{0,1000}\/http\-qnap\-nas\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7915" +"*/http-referer-checker.nse*",".{0,1000}\/http\-referer\-checker\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7916" +"*/httprelayserver.py*",".{0,1000}\/httprelayserver\.py.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","1","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","7917" +"*/http-rfi-spider.nse*",".{0,1000}\/http\-rfi\-spider\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7919" +"*/http-robots.txt.nse*",".{0,1000}\/http\-robots\.txt\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7920" +"*/http-robtex-reverse-ip.nse*",".{0,1000}\/http\-robtex\-reverse\-ip\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7921" +"*/http-robtex-shared-ns.nse*",".{0,1000}\/http\-robtex\-shared\-ns\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7922" +"*/https_payload.ps1*",".{0,1000}\/https_payload\.ps1.{0,1000}","offensive_tool_keyword","hoaxshell","An unconventional Windows reverse shell. currently undetected by Microsoft Defender and various other AV solutions. solely based on http(s) traffic","T1059 - T1071 - T1071.001 - T1203","TA0002 - TA0011","N/A","N/A","C2","https://github.com/t3l3machus/hoaxshell","1","1","N/A","N/A","N/A","10","3212","499","2025-01-19T12:29:35Z","2022-07-10T15:36:24Z","7923" +"*/http-sap-netweaver-leak.nse*",".{0,1000}\/http\-sap\-netweaver\-leak\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7924" +"*/http-security-headers.nse*",".{0,1000}\/http\-security\-headers\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7925" +"*/http-server-header.nse*",".{0,1000}\/http\-server\-header\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7926" +"*/HTTP-Shell.git*",".{0,1000}\/HTTP\-Shell\.git.{0,1000}","offensive_tool_keyword","HTTP-Shell","MultiPlatform HTTP Reverse Shell","T1573.001 - T1104 - T1205 - T1110","TA0005 - TA0011","N/A","N/A","C2","https://github.com/JoelGMSec/HTTP-Shell","1","1","N/A","N/A","10","10","231","33","2024-09-27T10:23:14Z","2023-09-05T12:01:17Z","7927" +"*/http-shellshock.nse*",".{0,1000}\/http\-shellshock\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7928" +"*/http-sitemap-generator.nse*",".{0,1000}\/http\-sitemap\-generator\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7929" +"*/http-slowloris.nse*",".{0,1000}\/http\-slowloris\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7930" +"*/http-slowloris-check.nse*",".{0,1000}\/http\-slowloris\-check\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7931" +"*/http-sql-injection.nse*",".{0,1000}\/http\-sql\-injection\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7932" +"*/https-redirect.nse*",".{0,1000}\/https\-redirect\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7933" +"*/http-stored-xss.nse*",".{0,1000}\/http\-stored\-xss\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7934" +"*/http-svn-enum.nse*",".{0,1000}\/http\-svn\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7935" +"*/http-svn-info.nse*",".{0,1000}\/http\-svn\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7936" +"*/http-tenda-enum.nse*",".{0,1000}\/http\-tenda\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://github.com/cldrn/nmap-nse-scripts/tree/master/scripts","1","1","N/A","N/A","N/A","10","968","369","2022-01-22T18:40:30Z","2011-05-31T05:41:49Z","7937" +"*/http-title.nse*",".{0,1000}\/http\-title\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7938" +"*/http-tplink-dir-traversal.nse*",".{0,1000}\/http\-tplink\-dir\-traversal\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7939" +"*/http-trace.nse*",".{0,1000}\/http\-trace\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7940" +"*/http-traceroute.nse*",".{0,1000}\/http\-traceroute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7941" +"*/http-trane-info.nse*",".{0,1000}\/http\-trane\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7942" +"*/http-unsafe-output-escaping.nse*",".{0,1000}\/http\-unsafe\-output\-escaping\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7943" +"*/http-useragent-tester.nse*",".{0,1000}\/http\-useragent\-tester\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7944" +"*/http-userdir-enum.nse*",".{0,1000}\/http\-userdir\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7945" +"*/http-vhosts.nse*",".{0,1000}\/http\-vhosts\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7946" +"*/http-virustotal.nse*",".{0,1000}\/http\-virustotal\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7947" +"*/http-vlcstreamer-ls.nse*",".{0,1000}\/http\-vlcstreamer\-ls\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7948" +"*/http-vmware-path-vuln.nse*",".{0,1000}\/http\-vmware\-path\-vuln\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7949" +"*/http-vuln-cve2006-3392.nse*",".{0,1000}\/http\-vuln\-cve2006\-3392\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7950" +"*/http-vuln-cve2009-3960.nse*",".{0,1000}\/http\-vuln\-cve2009\-3960\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7951" +"*/http-vuln-cve2010-0738.nse*",".{0,1000}\/http\-vuln\-cve2010\-0738\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7952" +"*/http-vuln-cve2010-2861.nse*",".{0,1000}\/http\-vuln\-cve2010\-2861\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7953" +"*/http-vuln-cve2011-3192.nse*",".{0,1000}\/http\-vuln\-cve2011\-3192\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7954" +"*/http-vuln-cve2011-3368.nse*",".{0,1000}\/http\-vuln\-cve2011\-3368\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7955" +"*/http-vuln-cve2012-1823.nse*",".{0,1000}\/http\-vuln\-cve2012\-1823\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7956" +"*/http-vuln-cve2013-0156.nse*",".{0,1000}\/http\-vuln\-cve2013\-0156\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7957" +"*/http-vuln-cve2013-6786.nse*",".{0,1000}\/http\-vuln\-cve2013\-6786\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7958" +"*/http-vuln-cve2013-7091.nse*",".{0,1000}\/http\-vuln\-cve2013\-7091\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7959" +"*/http-vuln-cve2014-2126.nse*",".{0,1000}\/http\-vuln\-cve2014\-2126\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7960" +"*/http-vuln-cve2014-2127.nse*",".{0,1000}\/http\-vuln\-cve2014\-2127\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7961" +"*/http-vuln-cve2014-2128.nse*",".{0,1000}\/http\-vuln\-cve2014\-2128\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7962" +"*/http-vuln-cve2014-2129.nse*",".{0,1000}\/http\-vuln\-cve2014\-2129\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7963" +"*/http-vuln-cve2014-3704.nse*",".{0,1000}\/http\-vuln\-cve2014\-3704\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7964" +"*/http-vuln-cve2014-8877.nse*",".{0,1000}\/http\-vuln\-cve2014\-8877\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7965" +"*/http-vuln-cve2015-1427.nse*",".{0,1000}\/http\-vuln\-cve2015\-1427\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7966" +"*/http-vuln-cve2015-1635.nse*",".{0,1000}\/http\-vuln\-cve2015\-1635\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7967" +"*/http-vuln-cve2017-1001000.nse*",".{0,1000}\/http\-vuln\-cve2017\-1001000\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7968" +"*/http-vuln-cve2017-5638.nse*",".{0,1000}\/http\-vuln\-cve2017\-5638\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7969" +"*/http-vuln-cve2017-5689.nse*",".{0,1000}\/http\-vuln\-cve2017\-5689\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7970" +"*/http-vuln-cve2017-8917.nse*",".{0,1000}\/http\-vuln\-cve2017\-8917\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7971" +"*/http-vulners-regex.nse*",".{0,1000}\/http\-vulners\-regex\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://github.com/vulnersCom/nmap-vulners","1","1","N/A","N/A","N/A","10","3297","553","2024-04-03T11:53:29Z","2017-12-19T21:21:28Z","7972" +"*/http-vuln-misfortune-cookie.nse*",".{0,1000}\/http\-vuln\-misfortune\-cookie\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7973" +"*/http-vuln-wnr1000-creds.nse*",".{0,1000}\/http\-vuln\-wnr1000\-creds\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7974" +"*/http-waf-detect.nse*",".{0,1000}\/http\-waf\-detect\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7975" +"*/http-waf-fingerprint.nse*",".{0,1000}\/http\-waf\-fingerprint\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7976" +"*/http-webdav-scan.nse*",".{0,1000}\/http\-webdav\-scan\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7977" +"*/http-wordpress-brute.nse*",".{0,1000}\/http\-wordpress\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7978" +"*/http-wordpress-enum.nse*",".{0,1000}\/http\-wordpress\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7979" +"*/http-wordpress-users.nse*",".{0,1000}\/http\-wordpress\-users\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7980" +"*/http-xssed.nse*",".{0,1000}\/http\-xssed\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7981" +"*/HuanLoader/*",".{0,1000}\/HuanLoader\/.{0,1000}","offensive_tool_keyword","Huan","Huan is an encrypted PE Loader Generator that I developed for learning PE file structure and PE loading processes. It encrypts the PE file to be run with different keys each time and embeds it in a new section of the loader binary. Currently. it works on 64 bit PE files.","T1027 - T1036 - T1564 - T1003 - T1056 - T1204 - T1588 - T1620","TA0002 - TA0008 - ","N/A","N/A","Exploitation tool","https://github.com/frkngksl/Huan","1","1","N/A","N/A","N/A","6","540","107","2021-08-13T10:48:26Z","2021-05-21T08:55:02Z","7983" +"*/HVNC.git*",".{0,1000}\/HVNC\.git.{0,1000}","offensive_tool_keyword","HVNC","Standalone HVNC Client & Server Coded in C++ (Modified Tinynuke)","T1021.005 - T1071 - T1563.002 - T1219","TA0001 - TA0002 - TA0008","N/A","N/A","RMM","https://github.com/Meltedd/HVNC","1","1","N/A","N/A","10","5","445","133","2025-03-27T21:20:10Z","2021-09-03T17:34:44Z","7984" +"*/hvnc/ngrok.zip*",".{0,1000}\/hvnc\/ngrok\.zip.{0,1000}","offensive_tool_keyword","Kematian Stealer","Fake WinRar site distributes malware (+stealer +miner +hvnc +ransomware) from GitHub","T1195 - T1566 - T1569 - T1106 - T1486 - T1113","TA0001 - TA0002 - TA0005 - TA0006 - TA0007 - TA0009 - TA0010 - TA0011 - TA0040 - TA0043","N/A","N/A","Malware","https://github[.]com/sap3r-encrypthub/encrypthub","1","1","N/A","N/A","10","7","N/A","N/A","N/A","N/A","7985" +"*/HVNC-Server.exe*",".{0,1000}\/HVNC\-Server\.exe.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","7986" +"*/HWSyscalls.cpp*",".{0,1000}\/HWSyscalls\.cpp.{0,1000}","offensive_tool_keyword","NtRemoteLoad","Remote Shellcode Injector","T1055 - T1027 - T1218.010","TA0002 - TA0005 - TA0010","N/A","N/A","Exploitation tool","https://github.com/florylsk/NtRemoteLoad","1","1","N/A","N/A","10","3","213","37","2023-08-27T17:14:44Z","2023-08-27T16:52:31Z","7987" +"*/hXOR.exe*",".{0,1000}\/hXOR\.exe.{0,1000}","offensive_tool_keyword","hXOR-Packer","hXOR Packer is a PE (Portable Executable) packer with Huffman Compression and Xor encryption.","T1027 - T1048.003 - T1140 - T1205.001","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/akuafif/hXOR-Packer","1","1","N/A","N/A","9","1","57","14","2021-09-11T13:00:34Z","2020-11-19T14:57:03Z","7988" +"*/hXOR-Packer.git*",".{0,1000}\/hXOR\-Packer\.git.{0,1000}","offensive_tool_keyword","hXOR-Packer","hXOR Packer is a PE (Portable Executable) packer with Huffman Compression and Xor encryption.","T1027 - T1048.003 - T1140 - T1205.001","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/akuafif/hXOR-Packer","1","1","N/A","N/A","9","1","57","14","2021-09-11T13:00:34Z","2020-11-19T14:57:03Z","7989" +"*/hyperion.exe*",".{0,1000}\/hyperion\.exe.{0,1000}","offensive_tool_keyword","hyperion","A runtime PE-Crypter - The crypter is started via the command line and encrypts an input executable with AES-128. The encrypted file decrypts itself on startup (bruteforcing the AES key which may take a few seconds)","T1027.002 - T1059.001 - T1116","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://www.kali.org/tools/hyperion/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","7991" +"*/Hypnos.git*",".{0,1000}\/Hypnos\.git.{0,1000}","offensive_tool_keyword","Hypnos","indirect syscalls - the Win API functions are not hooked by AV/EDR - bypass EDR detections","T1055.012 - T1136.001 - T1070.004 - T1055.001","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/CaptainNox/Hypnos","1","1","N/A","N/A","10","1","49","6","2024-02-12T17:51:24Z","2023-07-11T09:07:10Z","7995" +"*/hypobrychium.git*",".{0,1000}\/hypobrychium\.git.{0,1000}","offensive_tool_keyword","hypobrychium","hypobrychium AV/EDR Bypass","T1562.001 - T1070.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/foxlox/hypobrychium","1","1","N/A","N/A","8","1","72","21","2023-07-21T21:13:20Z","2023-07-18T09:55:07Z","7996" +"*/iam__backdoor_users_password*",".{0,1000}\/iam__backdoor_users_password.{0,1000}","offensive_tool_keyword","pacu","The AWS exploitation framework designed for testing the security of Amazon Web Services environments.","T1136.003 - T1190 - T1078.004","TA0006 - TA0001","N/A","Scattered Spider*","Framework","https://github.com/RhinoSecurityLabs/pacu","1","1","N/A","N/A","9","10","4651","731","2025-03-20T21:08:57Z","2018-06-13T21:58:59Z","7997" +"*/iam__bruteforce_permissions/*",".{0,1000}\/iam__bruteforce_permissions\/.{0,1000}","offensive_tool_keyword","pacu","The AWS exploitation framework designed for testing the security of Amazon Web Services environments.","T1136.003 - T1190 - T1078.004","TA0006 - TA0001","N/A","Scattered Spider*","Framework","https://github.com/RhinoSecurityLabs/pacu","1","1","N/A","N/A","9","10","4651","731","2025-03-20T21:08:57Z","2018-06-13T21:58:59Z","7998" +"*/iamassumeroleenum.py*",".{0,1000}\/iamassumeroleenum\.py.{0,1000}","offensive_tool_keyword","quiet-riot","Unauthenticated enumeration of AWS - Azure and GCP Principals","T1087 - T1083 - T1210","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/righteousgambit/quiet-riot","1","1","N/A","N/A","6","3","224","30","2024-11-13T19:41:26Z","2021-10-28T15:12:27Z","8000" +"*/iat_obfuscation.exe*",".{0,1000}\/iat_obfuscation\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","8001" +"*/iax2-brute.nse*",".{0,1000}\/iax2\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8002" +"*/iax2-version.nse*",".{0,1000}\/iax2\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8003" +"*/icap-info.nse*",".{0,1000}\/icap\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8004" +"*/icebreaker.git*",".{0,1000}\/icebreaker\.git.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","8005" +"*/icebreaker.py*",".{0,1000}\/icebreaker\.py.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","8006" +"*/IceRat v 1.0.exe*",".{0,1000}\/IceRat\sv\s1\.0\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","8007" +"*/id_reverse-ssh.pub*",".{0,1000}\/id_reverse\-ssh\.pub.{0,1000}","offensive_tool_keyword","reverse-ssh","Statically-linked ssh server with reverse shell functionality for CTFs and such","T1105 - T1572 - T1569.002 - T1090","TA0001 - TA0002 - TA0003 - TA0010 - TA0011 - TA0005 ","N/A","N/A","C2","https://github.com/Fahrj/reverse-ssh","1","1","N/A","N/A","10","10","961","141","2023-02-15T00:16:25Z","2021-07-12T18:26:29Z","8009" +"*/IdentifyDomainAdmins.ahk*",".{0,1000}\/IdentifyDomainAdmins\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","8010" +"*/IdentifyGroupMembershipActiveUser.ahk*",".{0,1000}\/IdentifyGroupMembershipActiveUser\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","8011" +"*/IDiagnosticProfileUAC*",".{0,1000}\/IDiagnosticProfileUAC.{0,1000}","offensive_tool_keyword","IDiagnosticProfileUAC","UAC bypass using auto-elevated COM object Virtual Factory for DiagCpl","T1548.002 - T1059.003 - T1027.002","TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/Wh04m1001/IDiagnosticProfileUAC","1","1","N/A","N/A","10","2","182","32","2022-07-02T20:31:47Z","2022-07-02T19:55:42Z","8012" +"*/iec-identify.nse*",".{0,1000}\/iec\-identify\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8013" +"*/ielocalserver.dll*",".{0,1000}\/ielocalserver\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8014" +"*/iepv.exe*",".{0,1000}\/iepv\.exe.{0,1000}","offensive_tool_keyword","IEPassView","IE PassView scans all Internet Explorer passwords in your system and display them on the main window.","T1555 - T1212","TA0006","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/internet_explorer_password.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","8015" +"*/ieshell32.dll*",".{0,1000}\/ieshell32\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8016" +"*/Ignis RAT V1_YKW.exe*",".{0,1000}\/Ignis\sRAT\sV1_YKW\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","8017" +"*/IHxExec.exe*",".{0,1000}\/IHxExec\.exe.{0,1000}","offensive_tool_keyword","IHxExec","Process injection technique","T1055.001 - T1055","TA0005 - TA0004 - TA0003","N/A","N/A","Defense Evasion","https://github.com/CICADA8-Research/IHxExec","1","1","N/A","N/A","8","4","325","46","2024-09-06T07:58:41Z","2024-07-11T09:18:42Z","8018" +"*/IHxExec.git*",".{0,1000}\/IHxExec\.git.{0,1000}","offensive_tool_keyword","IHxExec","Process injection technique","T1055.001 - T1055","TA0005 - TA0004 - TA0003","N/A","N/A","Defense Evasion","https://github.com/CICADA8-Research/IHxExec","1","1","N/A","N/A","8","4","325","46","2024-09-06T07:58:41Z","2024-07-11T09:18:42Z","8019" +"*/IHxExec-main.zip*",".{0,1000}\/IHxExec\-main\.zip.{0,1000}","offensive_tool_keyword","IHxExec","Process injection technique","T1055.001 - T1055","TA0005 - TA0004 - TA0003","N/A","N/A","Defense Evasion","https://github.com/CICADA8-Research/IHxExec","1","1","N/A","N/A","8","4","325","46","2024-09-06T07:58:41Z","2024-07-11T09:18:42Z","8020" +"*/iis_controller.py*",".{0,1000}\/iis_controller\.py.{0,1000}","offensive_tool_keyword","IIS-Raid","A native backdoor module for Microsoft IIS","T1505.003 - T1059.001 - T1071.001","TA0002 - TA0011","N/A","N/A","C2","https://github.com/0x09AL/IIS-Raid","1","1","N/A","N/A","10","10","541","124","2020-07-03T13:31:42Z","2020-02-17T16:28:10Z","8021" +"*/IIS-Raid.git*",".{0,1000}\/IIS\-Raid\.git.{0,1000}","offensive_tool_keyword","IIS-Raid","A native backdoor module for Microsoft IIS","T1505.003 - T1059.001 - T1071.001","TA0002 - TA0011","N/A","N/A","C2","https://github.com/0x09AL/IIS-Raid","1","1","N/A","N/A","10","10","541","124","2020-07-03T13:31:42Z","2020-02-17T16:28:10Z","8022" +"*/ike-crack.*",".{0,1000}\/ike\-crack\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","8023" +"*/Ikeext-Privesc.git*",".{0,1000}\/Ikeext\-Privesc\.git.{0,1000}","offensive_tool_keyword","Ikeext-Privesc","Windows IKEEXT DLL Hijacking Exploit Tool","T1546.011 - T1574.009 - T1036.004","TA0003 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/securycore/Ikeext-Privesc","1","1","N/A","N/A","10","1","33","52","2018-02-25T13:45:15Z","2018-02-27T11:18:56Z","8024" +"*/ike-version.nse*",".{0,1000}\/ike\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8026" +"*/imap-brute.nse*",".{0,1000}\/imap\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8027" +"*/imap-capabilities.nse*",".{0,1000}\/imap\-capabilities\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8028" +"*/imap-ntlm-info.nse*",".{0,1000}\/imap\-ntlm\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8029" +"*/IMDSpoof.git*",".{0,1000}\/IMDSpoof\.git.{0,1000}","offensive_tool_keyword","IMDSpoof","IMDSPOOF is a cyber deception tool that spoofs the AWS IMDS service to return HoneyTokens that can be alerted on.","T1584 - T1204 - T1078 - T1558","TA0007 - TA0001 - TA0002 - TA0004","N/A","N/A","Sniffing & Spoofing","https://github.com/grahamhelton/IMDSpoof","1","1","N/A","N/A","8","2","101","3","2023-11-24T23:42:48Z","2023-11-24T23:21:21Z","8030" +"*/imfiver/CVE-2022-0847*",".{0,1000}\/imfiver\/CVE\-2022\-0847.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/imfiver/CVE-2022-0847","1","1","N/A","N/A","N/A","3","280","78","2023-02-02T02:17:30Z","2022-03-07T18:36:50Z","8031" +"*/Imminent Monitor 3.9.exe*",".{0,1000}\/Imminent\sMonitor\s3\.9\.exe.{0,1000}","offensive_tool_keyword","Imminent-Monitor","used for malicious activities such as keylogging - screen capture and remote control of infected systems.","T1012 - T1059 - T1105 - T1071 - T1124 - T1041","TA0005 - TA0003 - TA0011 - TA0009","Imminent RAT","PROMETHIUM","Malware","https://github.com/Indestructible7/Imminent-Monitor-v3.9","1","1","N/A","N/A","8","1","4","2","2022-11-04T18:48:14Z","2022-11-04T18:15:20Z","8032" +"*/ImminentMonitor.exe*",".{0,1000}\/ImminentMonitor\.exe.{0,1000}","offensive_tool_keyword","Imminent-Monitor","used for malicious activities such as keylogging - screen capture and remote control of infected systems.","T1012 - T1059 - T1105 - T1071 - T1124 - T1041","TA0005 - TA0003 - TA0011 - TA0009","Imminent RAT","PROMETHIUM","Malware","https://github.com/Indestructible7/Imminent-Monitor-v3.9","1","1","N/A","N/A","8","1","4","2","2022-11-04T18:48:14Z","2022-11-04T18:15:20Z","8033" +"*/impacket.*",".{0,1000}\/impacket\..{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","8034" +"*/impacket.git*",".{0,1000}\/impacket\.git.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","8035" +"*/impacket.zip*",".{0,1000}\/impacket\.zip.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","8036" +"*/impacket/*",".{0,1000}\/impacket\/.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","8037" +"*/impacketfile.py*",".{0,1000}\/impacketfile\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","8038" +"*/Impersonate.exe*",".{0,1000}\/Impersonate\.exe.{0,1000}","offensive_tool_keyword","impersonate","A windows token impersonation tool","T1134 - T1550","TA0004 - TA0003","N/A","N/A","Lateral Movement","https://github.com/sensepost/impersonate","1","1","N/A","N/A","10","4","301","38","2023-04-19T12:53:50Z","2022-10-28T06:30:02Z","8039" +"*/impersonate.git*",".{0,1000}\/impersonate\.git.{0,1000}","offensive_tool_keyword","impersonate","A windows token impersonation tool","T1134 - T1550","TA0004 - TA0003","N/A","N/A","Lateral Movement","https://github.com/sensepost/impersonate","1","1","N/A","N/A","10","4","301","38","2023-04-19T12:53:50Z","2022-10-28T06:30:02Z","8040" +"*/impersonate.py*",".{0,1000}\/impersonate\.py.{0,1000}","offensive_tool_keyword","impersonate","A windows token impersonation tool","T1134 - T1550","TA0004 - TA0003","N/A","N/A","Lateral Movement","https://github.com/sensepost/impersonate","1","1","N/A","N/A","10","4","301","38","2023-04-19T12:53:50Z","2022-10-28T06:30:02Z","8041" +"*/impersonate-rs*",".{0,1000}\/impersonate\-rs.{0,1000}","offensive_tool_keyword","impersonate-rs","Reimplementation of Defte Impersonate in plain Rust allow you to impersonate any user on the target computer as long as you have administrator privileges (No NT SYSTEM needed) and is usable with and without GUI","T1134 - T1003 - T1008 - T1071","TA0004 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/zblurx/impersonate-rs","1","1","N/A","N/A","N/A","1","95","12","2023-06-15T15:33:49Z","2023-01-30T17:11:14Z","8043" +"*/Imperva_gzip_WAF_Bypass*",".{0,1000}\/Imperva_gzip_WAF_Bypass.{0,1000}","offensive_tool_keyword","Imperva_gzip_WAF_Bypass","Imperva Cloud WAF was vulnerable to a bypass that allows attackers to evade WAF rules when sending malicious HTTP POST payloads. such as log4j exploits. SQL injection. command execution. directory traversal. XXE. etc.","T1190 - T1210 - T1506 - T1061 - T1071 - T1100 - T1220","TA0001 - TA0002 - TA0003 - TA0040","N/A","N/A","Defense Evasion","https://github.com/BishopFox/Imperva_gzip_WAF_Bypass","1","1","N/A","network exploitation tool","N/A","2","157","29","2022-01-07T17:39:29Z","2022-01-07T17:38:33Z","8045" +"*/implant/callback*",".{0,1000}\/implant\/callback.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","8046" +"*/implant/elevate/*",".{0,1000}\/implant\/elevate\/.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","8047" +"*/implant/register_cmd*",".{0,1000}\/implant\/register_cmd.{0,1000}","offensive_tool_keyword","FudgeC2","FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.","T1021.002 - T1105 - T1059.001 - T1059.003","TA0008 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/Ziconius/FudgeC2","1","1","N/A","N/A","10","10","253","54","2023-05-01T21:13:56Z","2018-09-09T21:05:21Z","8048" +"*/implants/*/Syscalls.*",".{0,1000}\/implants\/.{0,1000}\/Syscalls\..{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","8049" +"*/ImplantSSP.exe*",".{0,1000}\/ImplantSSP\.exe.{0,1000}","offensive_tool_keyword","ImplantSSP","Installs a user-supplied Security Support Provider (SSP) DLL on the system which will be loaded by LSA on system start","T1547.008 - T1073.001 - T1055.001","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/matterpreter/OffensiveCSharp/tree/master/ImplantSSP","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","8050" +"*/impress-remote-discover.nse*",".{0,1000}\/impress\-remote\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8051" +"*/inceptor.git*",".{0,1000}\/inceptor\.git.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1027 - T1055 - T1070 - T1112 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","8052" +"*/inceptor.git*",".{0,1000}\/inceptor\.git.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","8053" +"*/include/KaynStrike.h*",".{0,1000}\/include\/KaynStrike\.h.{0,1000}","offensive_tool_keyword","KaynStrike","A User Defined Reflective Loader for Cobalt Strike Beacon that spoofs the thread start address and frees itself after entry point was executed.","T1055 - T1036 - T1070 - T1055.012 - T1055.001","TA0002 - TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/KaynStrike","1","1","N/A","N/A","9","5","422","66","2023-12-03T18:05:11Z","2022-05-30T04:22:59Z","8054" +"*/infection_monkey/*",".{0,1000}\/infection_monkey\/.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","8055" +"*/InflativeLoading.git*",".{0,1000}\/InflativeLoading\.git.{0,1000}","offensive_tool_keyword","InflativeLoading","Dynamically convert a native EXE to PIC shellcode by prepending a shellcode stub","T1027 - T1055 - T1140","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/senzee1984/InflativeLoading","1","1","N/A","N/A","10","4","309","64","2024-04-12T17:14:07Z","2024-01-05T03:59:33Z","8056" +"*/InflativeLoading.py*",".{0,1000}\/InflativeLoading\.py.{0,1000}","offensive_tool_keyword","InflativeLoading","Dynamically convert a native EXE to PIC shellcode by prepending a shellcode stub","T1027 - T1055 - T1140","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/senzee1984/InflativeLoading","1","1","N/A","N/A","10","4","309","64","2024-04-12T17:14:07Z","2024-01-05T03:59:33Z","8057" +"*/InflativeLoading-main.zip*",".{0,1000}\/InflativeLoading\-main\.zip.{0,1000}","offensive_tool_keyword","InflativeLoading","Dynamically convert a native EXE to PIC shellcode by prepending a shellcode stub","T1027 - T1055 - T1140","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/senzee1984/InflativeLoading","1","1","N/A","N/A","10","4","309","64","2024-04-12T17:14:07Z","2024-01-05T03:59:33Z","8058" +"*/informix-brute.nse*",".{0,1000}\/informix\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8060" +"*/informix-query.nse*",".{0,1000}\/informix\-query\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8061" +"*/informix-tables.nse*",".{0,1000}\/informix\-tables\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8062" +"*/inject.cpp*",".{0,1000}\/inject\.cpp.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","8063" +"*/Inject/Dll/LoadDll*",".{0,1000}\/Inject\/Dll\/LoadDll.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","8064" +"*/Inject/PE/*.cs*",".{0,1000}\/Inject\/PE\/.{0,1000}\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","8065" +"*/Inject/ShellCode/*.cs*",".{0,1000}\/Inject\/ShellCode\/.{0,1000}\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","8066" +"*/injectAmsiBypass/*",".{0,1000}\/injectAmsiBypass\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF - Bypass AMSI in a remote process with code injection.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/injectAmsiBypass","1","1","N/A","N/A","10","10","378","69","2023-03-08T15:54:57Z","2021-07-19T00:08:21Z","8067" +"*/inject-assembly/*",".{0,1000}\/inject\-assembly\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Inject .NET assemblies into an existing process","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/kyleavery/inject-assembly","1","1","N/A","N/A","10","10","494","74","2022-01-19T19:15:11Z","2022-01-03T15:38:10Z","8068" +"*/injectEtw.*",".{0,1000}\/injectEtw\..{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike BOF - Inject ETW Bypass into Remote Process via Syscalls (HellsGate|HalosGate)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/injectEtwBypass","1","1","N/A","N/A","10","10","279","55","2021-09-28T19:09:38Z","2021-09-21T23:06:42Z","8069" +"*/Injection/clipboard/*",".{0,1000}\/Injection\/clipboard\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","8070" +"*/Injection/conhost/*",".{0,1000}\/Injection\/conhost\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","8071" +"*/Injection/createremotethread/*",".{0,1000}\/Injection\/createremotethread\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","8072" +"*/Injection/ctray/*",".{0,1000}\/Injection\/ctray\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","8073" +"*/Injection/dde/*",".{0,1000}\/Injection\/dde\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","8074" +"*/Injection/Injection.cna*",".{0,1000}\/Injection\/Injection\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","8075" +"*/Injection/kernelcallbacktable*",".{0,1000}\/Injection\/kernelcallbacktable.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","8076" +"*/Injection/ntcreatethread*",".{0,1000}\/Injection\/ntcreatethread.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","8077" +"*/Injection/ntcreatethread/*",".{0,1000}\/Injection\/ntcreatethread\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","8078" +"*/Injection/ntqueueapcthread*",".{0,1000}\/Injection\/ntqueueapcthread.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","8079" +"*/Injection/setthreadcontext*",".{0,1000}\/Injection\/setthreadcontext.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","8080" +"*/Injection/svcctrl/*",".{0,1000}\/Injection\/svcctrl\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","8081" +"*/Injection/tooltip/*",".{0,1000}\/Injection\/tooltip\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","8082" +"*/Injection/uxsubclassinfo*",".{0,1000}\/Injection\/uxsubclassinfo.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","8083" +"*/Injections/SQL.txt*",".{0,1000}\/Injections\/SQL\.txt.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","8085" +"*/injectsu.exp*",".{0,1000}\/injectsu\.exp.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8086" +"*/injectsu.lib*",".{0,1000}\/injectsu\.lib.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8087" +"*/injectsu.pdb*",".{0,1000}\/injectsu\.pdb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8088" +"*/injectsu/*",".{0,1000}\/injectsu\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8089" +"*/inline_syscall.git*",".{0,1000}\/inline_syscall\.git.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","8090" +"*/inline_syscall/include/in_memory_init.hpp*",".{0,1000}\/inline_syscall\/include\/in_memory_init\.hpp.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","8091" +"*/inline-exec/*.exe",".{0,1000}\/inline\-exec\/.{0,1000}\.exe","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","8092" +"*/InlineWhispers*",".{0,1000}\/InlineWhispers.{0,1000}","offensive_tool_keyword","cobaltstrike","Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/InlineWhispers","1","1","N/A","N/A","10","10","315","42","2021-11-09T15:39:27Z","2020-12-25T16:52:50Z","8093" +"*/insta-bf.git*",".{0,1000}\/insta\-bf\.git.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/insta-bf","1","1","N/A","N/A","7","1","59","13","2024-04-23T02:47:28Z","2020-11-20T22:22:48Z","8094" +"*/instabf.py*",".{0,1000}\/instabf\.py.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/insta-bf","1","1","N/A","N/A","7","1","59","13","2024-04-23T02:47:28Z","2020-11-20T22:22:48Z","8095" +"*/instabrute.py*",".{0,1000}\/instabrute\.py.{0,1000}","offensive_tool_keyword","BruteSploit","BruteSploit is a collection of method for automated Generate. Bruteforce and Manipulation wordlist with interactive shell. That can be used during a penetration test to enumerate and maybe can be used in CTF for manipulation.combine.transform and permutation some words or file text","T1110","N/A","N/A","N/A","Exploitation tool","https://github.com/screetsec/BruteSploit","1","1","N/A","N/A","N/A","8","741","263","2020-04-05T00:29:26Z","2017-05-31T17:00:51Z","8096" +"*/instainsane.git*",".{0,1000}\/instainsane\.git.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/umeshshinde19/instainsane","1","1","N/A","N/A","7","7","655","371","2024-02-11T10:29:05Z","2018-12-02T22:48:11Z","8097" +"*/instainsane.sh*",".{0,1000}\/instainsane\.sh.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/umeshshinde19/instainsane","1","1","N/A","N/A","7","7","655","371","2024-02-11T10:29:05Z","2018-12-02T22:48:11Z","8098" +"*/install_elevated.py*",".{0,1000}\/install_elevated\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","8099" +"*/install_locutus.sh*",".{0,1000}\/install_locutus\.sh.{0,1000}","offensive_tool_keyword","D3m0n1z3dShell","Demonized Shell is an Advanced Tool for persistence in linux","T1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037","TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Persistence","https://github.com/MatheuZSecurity/D3m0n1z3dShell","1","1","#linux","N/A","10","4","373","54","2025-01-05T13:56:51Z","2023-05-30T02:30:47Z","8100" +"*/install-sb.sh*",".{0,1000}\/install\-sb\.sh.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/SocialBox-Termux","1","1","N/A","N/A","7","10","3581","391","2024-09-02T19:15:22Z","2019-03-28T18:07:05Z","8102" +"*/InstallStager.exe*",".{0,1000}\/InstallStager\.exe.{0,1000}","offensive_tool_keyword","Discord-RAT-2.0","Discord Remote Administration Tool fully written in c#, stub size of ~75kb with over 40 post exploitations modules","T1059.005 - T1105 - T1569.002 - T1027.001","TA0011 - TA0003 - TA0006 - TA0009 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/moom825/Discord-RAT-2.0","1","1","N/A","N/A","10","10","512","115","2023-11-03T01:15:38Z","2022-07-15T20:09:56Z","8103" +"*/insTof.py*",".{0,1000}\/insTof\.py.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/insta-bf","1","1","N/A","N/A","7","1","59","13","2024-04-23T02:47:28Z","2020-11-20T22:22:48Z","8104" +"*/interactive_shell.py*",".{0,1000}\/interactive_shell\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","8105" +"*/Intercepter-NG*.apk*",".{0,1000}\/Intercepter\-NG.{0,1000}\.apk.{0,1000}","offensive_tool_keyword","Intercepter-NG","android wifi sniffer","T1433","TA0006","N/A","N/A","Sniffing & Spoofing","https://github.com/intercepter-ng","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8110" +"*/internal/C2/*.go*",".{0,1000}\/internal\/C2\/.{0,1000}\.go.{0,1000}","offensive_tool_keyword","GC2-sheet","GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet and exfiltrate data using Google Drive.","T1071.002 - T1560 - T1105","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/looCiprian/GC2-sheet","1","1","N/A","N/A","10","10","578","111","2025-03-28T19:48:36Z","2021-09-15T19:06:12Z","8112" +"*/InternalMonologue.exe*",".{0,1000}\/InternalMonologue\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8113" +"*/Internals/Coff.cs*",".{0,1000}\/Internals\/Coff\.cs.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool to run object files mainly beacon object files (BOF) in .Net.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nettitude/RunOF","1","1","N/A","N/A","10","10","145","21","2023-01-06T15:30:05Z","2022-02-21T13:53:39Z","8114" +"*/InternetConnect_x64_Release.exe*",".{0,1000}\/InternetConnect_x64_Release\.exe.{0,1000}","offensive_tool_keyword","Tsunami","another C2 framework","T1573 - T1027 - T1059 - T1071 ","TA0011 - TA0009 - TA0003 - TA0007 - TA0008","N/A","N/A","C2","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","8115" +"*/Intranet penetration.cna*",".{0,1000}\/Intranet\spenetration\.cna.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8116" +"*/Inveigh.exe*",".{0,1000}\/Inveigh\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","8117" +"*/Inveigh.git*",".{0,1000}\/Inveigh\.git.{0,1000}","offensive_tool_keyword","Inveigh",".NET IPv4/IPv6 machine-in-the-middle tool for penetration testers","T1550.002 - T1059.001 - T1071.001","TA0002","N/A","ALLANITE - ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/Kevin-Robertson/Inveigh","1","1","N/A","N/A","10","10","2685","462","2024-08-06T01:47:27Z","2015-04-02T18:04:41Z","8118" +"*/Inveigh.ps1*",".{0,1000}\/Inveigh\.ps1.{0,1000}","offensive_tool_keyword","ADAPE-Script","Active Directory Assessment and Privilege Escalation Script","T1178 - T1087 - T1482","TA0002 - TA0004 - TA0007","N/A","Black Basta","Privilege Escalation","https://github.com/cjoan75/ADAPE-Script","1","1","N/A","N/A","8","1","0","0","2020-07-11T00:53:24Z","2020-08-09T16:52:35Z","8119" +"*/Inveigh.ps1*",".{0,1000}\/Inveigh\.ps1.{0,1000}","offensive_tool_keyword","Inveigh","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","Inveigh","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","8120" +"*/Inveigh.ps1*",".{0,1000}\/Inveigh\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","8121" +"*/Inveigh.ps1*",".{0,1000}\/Inveigh\.ps1.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","Inveigh","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","8122" +"*/Inveigh.txt*",".{0,1000}\/Inveigh\.txt.{0,1000}","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","8123" +"*/Invisi-Shell.git*",".{0,1000}\/Invisi\-Shell\.git.{0,1000}","offensive_tool_keyword","Invisi-Shell","Hide your powershell script in plain sight! Invisi-Shell bypasses all of Powershell security features (ScriptBlock logging. Module logging. Transcription. AMSI) by hooking .Net assemblies. The hook is performed via CLR Profiler API.","T1027 - T1059.001 - T1562","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/OmerYa/Invisi-Shell","1","1","N/A","N/A","10","10","1167","166","2019-08-19T19:55:19Z","2018-10-14T23:32:56Z","8135" +"*/Invoke-Adeleginator*",".{0,1000}\/Invoke\-Adeleginator.{0,1000}","offensive_tool_keyword","Adeleginator","tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory","T1087 - T1136 - T1069","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/techspence/Adeleginator","1","1","N/A","N/A","6","2","179","18","2024-09-18T20:21:42Z","2024-03-04T03:44:52Z","8137" +"*/Invoke-ADEnum.git*",".{0,1000}\/Invoke\-ADEnum\.git.{0,1000}","offensive_tool_keyword","Invoke-ADEnum","Automate Active Directory Enumeration","T1016 - T1482","TA0007","N/A","N/A","Discovery","https://github.com/Leo4j/Invoke-ADEnum","1","1","N/A","N/A","7","5","448","50","2025-04-09T10:13:47Z","2023-04-18T11:19:42Z","8138" +"*/Invoke-ADSBackdoor.ps1*",".{0,1000}\/Invoke\-ADSBackdoor\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","8139" +"*/Invoke-ArgFuscator.git*",".{0,1000}\/Invoke\-ArgFuscator\.git.{0,1000}","offensive_tool_keyword","Invoke-ArgFuscator","generate obfuscated command-lines for common system-native executables","T1027 - T1059 - T1202","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/wietze/Invoke-ArgFuscator","1","1","N/A","N/A","10","2","161","28","2025-04-14T21:24:29Z","2022-11-20T17:59:23Z","8140" +"*/Invoke-ArgFuscator/releases/*",".{0,1000}\/Invoke\-ArgFuscator\/releases\/.{0,1000}","offensive_tool_keyword","Invoke-ArgFuscator","generate obfuscated command-lines for common system-native executables","T1027 - T1059 - T1202","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/wietze/Invoke-ArgFuscator","1","1","N/A","N/A","10","2","161","28","2025-04-14T21:24:29Z","2022-11-20T17:59:23Z","8141" +"*/Invoke-ArgFuscator/tarball/*",".{0,1000}\/Invoke\-ArgFuscator\/tarball\/.{0,1000}","offensive_tool_keyword","Invoke-ArgFuscator","generate obfuscated command-lines for common system-native executables","T1027 - T1059 - T1202","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/wietze/Invoke-ArgFuscator","1","1","N/A","N/A","10","2","161","28","2025-04-14T21:24:29Z","2022-11-20T17:59:23Z","8142" +"*/Invoke-ArgFuscator/zipball/*",".{0,1000}\/Invoke\-ArgFuscator\/zipball\/.{0,1000}","offensive_tool_keyword","Invoke-ArgFuscator","generate obfuscated command-lines for common system-native executables","T1027 - T1059 - T1202","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/wietze/Invoke-ArgFuscator","1","1","N/A","N/A","10","2","161","28","2025-04-14T21:24:29Z","2022-11-20T17:59:23Z","8143" +"*/Invoke-Bof/*",".{0,1000}\/Invoke\-Bof\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Load any Beacon Object File using Powershell!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/airbus-cert/Invoke-Bof","1","1","N/A","N/A","10","10","250","35","2021-12-09T15:10:41Z","2021-12-09T15:09:22Z","8144" +"*/Invoke-CleverSpray.git*",".{0,1000}\/Invoke\-CleverSpray\.git.{0,1000}","offensive_tool_keyword","Invoke-CleverSpray","Password Spraying Script detecting current and previous passwords of Active Directory User","T1110.003 - T1110.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/wavestone-cdt/Invoke-CleverSpray","1","1","N/A","N/A","10","1","65","11","2021-09-09T07:35:32Z","2018-11-29T10:05:25Z","8145" +"*/Invoke-DCOM.ps1*",".{0,1000}\/Invoke\-DCOM\.ps1.{0,1000}","offensive_tool_keyword","BloodHound","Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors","1","1","N/A","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","8146" +"*/Invoke-DCOM.ps1*",".{0,1000}\/Invoke\-DCOM\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","8147" +"*/Invoke-DCOMPowerPointPivot.ps1*",".{0,1000}\/Invoke\-DCOMPowerPointPivot\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","8148" +"*/Invoke-EternalBlue.ps1*",".{0,1000}\/Invoke\-EternalBlue\.ps1.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8149" +"*/Invoke-ExcelMacroPivot.ps1*",".{0,1000}\/Invoke\-ExcelMacroPivot\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","8150" +"*/Invoke-HostEnum.ps1*",".{0,1000}\/Invoke\-HostEnum\.ps1.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script function and alias to perform some rudimentary Windows host enumeration with Beacon built-in commands","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/red-team-scripts","1","1","N/A","N/A","10","10","1122","195","2024-11-19T19:39:01Z","2017-05-01T13:53:05Z","8151" +"*/Invoke-InternalMonologue.ps1*",".{0,1000}\/Invoke\-InternalMonologue\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","8152" +"*/Invoke-MDExclusionParser.ps1*",".{0,1000}\/Invoke\-MDExclusionParser\.ps1.{0,1000}","offensive_tool_keyword","MDExclusionParser","PowerShell script to quickly scan Event Log ID 5007 and 1121 for published Windows Defender Exclusions and Attack Surface Reduction (ASR) rule configuration.","T1562.001","TA0005 - TA0007","N/A","N/A","Defense Evasion","https://github.com/ViziosDe/MDExclusionParser","1","1","N/A","N/A","5","1","6","1","2024-06-12T14:17:08Z","2024-06-12T11:56:07Z","8154" +"*/Invoke-Mimikatz.ps1*",".{0,1000}\/Invoke\-Mimikatz\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","8155" +"*/Invoke-MS16032.ps1*",".{0,1000}\/Invoke\-MS16032\.ps1.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8156" +"*/Invoke-MS16135.ps1*",".{0,1000}\/Invoke\-MS16135\.ps1.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8157" +"*/Invoke-Obfuscation.git*",".{0,1000}\/Invoke\-Obfuscation\.git.{0,1000}","offensive_tool_keyword","Invoke-Obfuscation","Invoke-Obfuscation is a PowerShell v2.0+ compatible PowerShell command and script obfuscator.","T1027 - T1059.001 - T1564.003","TA0005 - TA0002","N/A","Oilrig - Dispossessor","Defense Evasion","https://github.com/danielbohannon/Invoke-Obfuscation","1","1","N/A","N/A","10","10","3935","782","2023-08-10T23:49:06Z","2016-09-25T03:38:02Z","8158" +"*/Invoke-PowerThIEf.ps1*",".{0,1000}\/Invoke\-PowerThIEf\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","8159" +"*/Invoke-RDPThief.git*",".{0,1000}\/Invoke\-RDPThief\.git.{0,1000}","offensive_tool_keyword","Invoke-RDPThief","perform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentials","T1055 - T1056 - T1071 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/The-Viper-One/Invoke-RDPThief","1","1","N/A","N/A","10","1","62","8","2025-01-21T20:12:33Z","2024-10-01T20:12:00Z","8160" +"*/Invoke-RunAs.ps1*",".{0,1000}\/Invoke\-RunAs\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1084","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","8161" +"*/Invoke-RunAsSystem.git*",".{0,1000}\/Invoke\-RunAsSystem\.git.{0,1000}","offensive_tool_keyword","Invoke-RunAsSystem","A simple script to elevate current session to SYSTEM (needs to be run as Administrator)","T1548.002 - T1059.001","TA0004 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/Leo4j/Invoke-RunAsSystem","1","1","N/A","N/A","8","1","14","1","2024-11-11T17:18:20Z","2023-08-24T15:12:40Z","8162" +"*/Invoke-RunAsWithCert.git*",".{0,1000}\/Invoke\-RunAsWithCert\.git.{0,1000}","offensive_tool_keyword","Invoke-RunAsWithCert","A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine","T1550.003 - T1078 - T1027","TA0006 - TA0005","N/A","N/A","Lateral Movement","https://github.com/synacktiv/Invoke-RunAsWithCert","1","1","N/A","N/A","8","2","150","14","2024-05-13T08:26:56Z","2024-05-03T12:44:21Z","8163" +"*/Invoke-SessionHunter.git*",".{0,1000}\/Invoke\-SessionHunter\.git.{0,1000}","offensive_tool_keyword","Invoke-SessionHunter","Retrieve and display information about active user sessions on remote computers. No admin privileges required","T1033 - T1078 - T1110","TA0007","N/A","N/A","Discovery","https://github.com/Leo4j/Invoke-SessionHunter","1","1","N/A","N/A","7","2","183","20","2024-08-12T13:15:10Z","2023-08-13T13:22:05Z","8164" +"*/Invoke-SMBRemoting.git*",".{0,1000}\/Invoke\-SMBRemoting\.git.{0,1000}","offensive_tool_keyword","Invoke-SMBRemoting","Interactive Shell and Command Execution over Named-Pipes (SMB)","T1059 - T1021.002 - T1572","TA0002 - TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/Leo4j/Invoke-SMBRemoting","1","1","N/A","N/A","9","2","163","25","2024-12-05T16:30:18Z","2023-09-06T16:00:47Z","8165" +"*/Invoke-SocksProxy.git*",".{0,1000}\/Invoke\-SocksProxy\.git.{0,1000}","offensive_tool_keyword","Invoke-SocksProxy","also known as PortStarter is a socks proxy and reverse socks server using powershell","T1090 - T1059.001 - T1102.003","TA0011 - TA0010 - TA0005 - TA0003","PortStarter","Vice Society - Conti","C2","https://github.com/p3nt4/Invoke-SocksProxy","1","1","N/A","N/A","10","10","788","169","2021-03-21T21:00:40Z","2017-11-09T06:20:40Z","8166" +"*/Invoke-SocksProxy/*",".{0,1000}\/Invoke\-SocksProxy\/.{0,1000}","offensive_tool_keyword","Invoke-SocksProxy","also known as PortStarter is a socks proxy and reverse socks server using powershell","T1090 - T1059.001 - T1102.003","TA0011 - TA0010 - TA0005 - TA0003","PortStarter","Vice Society - Conti","C2","https://github.com/p3nt4/Invoke-SocksProxy","1","1","N/A","N/A","10","10","788","169","2021-03-21T21:00:40Z","2017-11-09T06:20:40Z","8167" +"*/Invoke-Stealth.git*",".{0,1000}\/Invoke\-Stealth\.git.{0,1000}","offensive_tool_keyword","Invoke-Stealth","Simple & Powerful PowerShell Script Obfuscator","T1027.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/JoelGMSec/Invoke-Stealth","1","1","N/A","N/A","9","6","559","81","2023-04-21T12:49:37Z","2021-04-13T10:22:05Z","8168" +"*/invoke-stealth.php*",".{0,1000}\/invoke\-stealth\.php.{0,1000}","offensive_tool_keyword","Invoke-Stealth","Simple & Powerful PowerShell Script Obfuscator","T1027.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/JoelGMSec/Invoke-Stealth","1","1","N/A","N/A","9","6","559","81","2023-04-21T12:49:37Z","2021-04-13T10:22:05Z","8169" +"*/Invoke-Stealth.ps1*",".{0,1000}\/Invoke\-Stealth\.ps1.{0,1000}","offensive_tool_keyword","Invoke-Stealth","Simple & Powerful PowerShell Script Obfuscator","T1027.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/JoelGMSec/Invoke-Stealth","1","1","N/A","N/A","9","6","559","81","2023-04-21T12:49:37Z","2021-04-13T10:22:05Z","8170" +"*/Invoke-WMILM.ps1*",".{0,1000}\/Invoke\-WMILM\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","8171" +"*/iodine-*-windows.zip*",".{0,1000}\/iodine\-.{0,1000}\-windows\.zip.{0,1000}","offensive_tool_keyword","iodine","iodine. iodined - tunnel IPv4 over DNS","T1573.001 - T1573.002 - T1573.003 - T1573.004","TA0011 - TA0010 - TA0002 - TA0005","N/A","EMBER BEAR","C2","https://github.com/yarrick/iodine","1","1","N/A","N/A","10","10","6413","524","2025-04-08T17:44:12Z","2012-02-04T19:51:39Z","8173" +"*/iodine.exe*",".{0,1000}\/iodine\.exe.{0,1000}","offensive_tool_keyword","iodine","iodine. iodined - tunnel IPv4 over DNS","T1573.001 - T1573.002 - T1573.003 - T1573.004","TA0011 - TA0010 - TA0002 - TA0005","N/A","EMBER BEAR","C2","https://github.com/yarrick/iodine","1","1","N/A","N/A","10","10","6413","524","2025-04-08T17:44:12Z","2012-02-04T19:51:39Z","8174" +"*/iodine.git*",".{0,1000}\/iodine\.git.{0,1000}","offensive_tool_keyword","iodine","iodine. iodined - tunnel IPv4 over DNS","T1573.001 - T1573.002 - T1573.003 - T1573.004","TA0011 - TA0010 - TA0002 - TA0005","N/A","EMBER BEAR","C2","https://github.com/yarrick/iodine","1","1","N/A","N/A","10","10","6413","524","2025-04-08T17:44:12Z","2012-02-04T19:51:39Z","8175" +"*/iodine-master/*",".{0,1000}\/iodine\-master\/.{0,1000}","offensive_tool_keyword","iodine","iodine. iodined - tunnel IPv4 over DNS","T1573.001 - T1573.002 - T1573.003 - T1573.004","TA0011 - TA0010 - TA0002 - TA0005","N/A","EMBER BEAR","C2","https://github.com/yarrick/iodine","1","1","N/A","N/A","10","10","6413","524","2025-04-08T17:44:12Z","2012-02-04T19:51:39Z","8176" +"*/io-tl/Mara*",".{0,1000}\/io\-tl\/Mara.{0,1000}","offensive_tool_keyword","Mara","Mara is a userland pty/tty sniffer","T1055 - T1106 - T1059","TA0002 - TA0005 - TA0003","N/A","N/A","Sniffing & Spoofing","https://github.com/io-tl/Mara/","1","1","N/A","N/A","9","1","53","6","2023-12-22T16:52:47Z","2022-08-02T13:02:41Z","8178" +"*/ip_spoof.rb*",".{0,1000}\/ip_spoof\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8180" +"*/IPayloadService.*",".{0,1000}\/IPayloadService\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","8181" +"*/ip-forwarding.nse*",".{0,1000}\/ip\-forwarding\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8182" +"*/IPfuscation.exe*",".{0,1000}\/IPfuscation\.exe.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","8184" +"*/ip-geolocation-geoplugin.nse*",".{0,1000}\/ip\-geolocation\-geoplugin\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8185" +"*/ip-geolocation-ipinfodb.nse*",".{0,1000}\/ip\-geolocation\-ipinfodb\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8186" +"*/ip-geolocation-map-bing.nse*",".{0,1000}\/ip\-geolocation\-map\-bing\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8187" +"*/ip-geolocation-map-google.nse*",".{0,1000}\/ip\-geolocation\-map\-google\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8188" +"*/ip-geolocation-map-kml.nse*",".{0,1000}\/ip\-geolocation\-map\-kml\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8189" +"*/ip-geolocation-maxmind.nse*",".{0,1000}\/ip\-geolocation\-maxmind\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8190" +"*/ip-https-discover.nse*",".{0,1000}\/ip\-https\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8191" +"*/ipidseq.nse*",".{0,1000}\/ipidseq\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8192" +"*/ipmi_passwords.txt*",".{0,1000}\/ipmi_passwords\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8193" +"*/ipmi-brute.nse*",".{0,1000}\/ipmi\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8194" +"*/ipmi-cipher-zero.nse*",".{0,1000}\/ipmi\-cipher\-zero\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8195" +"*/ipmi-version.nse*",".{0,1000}\/ipmi\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8196" +"*/IPPrintC2.git*",".{0,1000}\/IPPrintC2\.git.{0,1000}","offensive_tool_keyword","IPPrintC2","PoC for using MS Windows printers for persistence / command and control via Internet Printing","T1090 - T1133 - T1547.012 - T1572","TA0011 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/Diverto/IPPrintC2","1","1","N/A","lolc2","10","10","146","20","2024-05-03T11:13:38Z","2024-05-03T09:13:10Z","8197" +"*/IPPrintC2.ps1*",".{0,1000}\/IPPrintC2\.ps1.{0,1000}","offensive_tool_keyword","IPPrintC2","PoC for using MS Windows printers for persistence / command and control via Internet Printing","T1090 - T1133 - T1547.012 - T1572","TA0011 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/Diverto/IPPrintC2","1","1","N/A","lolc2","10","10","146","20","2024-05-03T11:13:38Z","2024-05-03T09:13:10Z","8198" +"*/ipv6-multicast-mld-list.nse*",".{0,1000}\/ipv6\-multicast\-mld\-list\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8204" +"*/ipv6-node-info.nse*",".{0,1000}\/ipv6\-node\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8205" +"*/ipv6-ra-flood.nse*",".{0,1000}\/ipv6\-ra\-flood\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8206" +"*/irc-botnet-channels.nse*",".{0,1000}\/irc\-botnet\-channels\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8207" +"*/irc-brute.nse*",".{0,1000}\/irc\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8208" +"*/irc-info.nse*",".{0,1000}\/irc\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8209" +"*/irc-sasl-brute.nse*",".{0,1000}\/irc\-sasl\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8210" +"*/irc-unrealircd-backdoor.nse*",".{0,1000}\/irc\-unrealircd\-backdoor\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8211" +"*/irs.exe*",".{0,1000}\/irs\.exe.{0,1000}","offensive_tool_keyword","impersonate-rs","Reimplementation of Defte Impersonate in plain Rust allow you to impersonate any user on the target computer as long as you have administrator privileges (No NT SYSTEM needed) and is usable with and without GUI","T1134 - T1003 - T1008 - T1071","TA0004 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/zblurx/impersonate-rs","1","1","N/A","N/A","N/A","1","95","12","2023-06-15T15:33:49Z","2023-01-30T17:11:14Z","8212" +"*/iscsi-brute.nse*",".{0,1000}\/iscsi\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8213" +"*/iscsi-info.nse*",".{0,1000}\/iscsi\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8214" +"*/isns-info.nse*",".{0,1000}\/isns\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8215" +"*/itsdangerous.zip*",".{0,1000}\/itsdangerous\.zip.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","8216" +"*/itsecteam_shell.php*",".{0,1000}\/itsecteam_shell\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","8217" +"*/ItWasAllADream.git*",".{0,1000}\/ItWasAllADream\.git.{0,1000}","offensive_tool_keyword","ItWasAllADream","A PrintNightmare (CVE-2021-34527) Python Scanner. Scan entire subnets for hosts vulnerable to the PrintNightmare RCE","T1046 - T1210.002 - T1047","TA0007 - TA0002","N/A","N/A","Discovery","https://github.com/byt3bl33d3r/ItWasAllADream","1","1","N/A","N/A","7","8","796","123","2024-05-19T16:25:52Z","2021-07-05T20:13:49Z","8218" +"*/Ivy/Cryptor*",".{0,1000}\/Ivy\/Cryptor.{0,1000}","offensive_tool_keyword","ivy","Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory","T1059 - T1204 - T1547","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/optiv/Ivy","1","1","N/A","N/A","10","8","744","129","2023-08-18T17:30:14Z","2021-11-18T18:29:20Z","8219" +"*/Ivy/Loader/*",".{0,1000}\/Ivy\/Loader\/.{0,1000}","offensive_tool_keyword","ivy","Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory","T1059 - T1204 - T1547","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/optiv/Ivy","1","1","N/A","N/A","10","8","744","129","2023-08-18T17:30:14Z","2021-11-18T18:29:20Z","8220" +"*/jackdaw.exe",".{0,1000}\/jackdaw\.exe","offensive_tool_keyword","jackdaw","Jackdaw is here to collect all information in your domain. store it in a SQL database and show you nice graphs on how your domain objects interact with each-other an how a potential attacker may exploit these interactions. It also comes with a handy feature to help you in a password-cracking project by storing/looking up/reporting hashes/passowrds/users.","T1087 - T1482 - T1201 - T1213 - T1003","TA0007 - TA0008 - TA0009 - TA0006","N/A","N/A","Reconnaissance","https://github.com/skelsec/jackdaw","1","1","N/A","N/A","N/A","6","576","89","2025-03-15T13:37:50Z","2019-03-27T18:36:41Z","8221" +"*/jackdaw.git*",".{0,1000}\/jackdaw\.git.{0,1000}","offensive_tool_keyword","jackdaw","Jackdaw is here to collect all information in your domain. store it in a SQL database and show you nice graphs on how your domain objects interact with each-other an how a potential attacker may exploit these interactions. It also comes with a handy feature to help you in a password-cracking project by storing/looking up/reporting hashes/passowrds/users.","T1087 - T1482 - T1201 - T1213 - T1003","TA0007 - TA0008 - TA0009 - TA0006","N/A","N/A","Reconnaissance","https://github.com/skelsec/jackdaw","1","1","N/A","N/A","N/A","6","576","89","2025-03-15T13:37:50Z","2019-03-27T18:36:41Z","8222" +"*/jackdaw.zip",".{0,1000}\/jackdaw\.zip","offensive_tool_keyword","jackdaw","Jackdaw is here to collect all information in your domain. store it in a SQL database and show you nice graphs on how your domain objects interact with each-other an how a potential attacker may exploit these interactions. It also comes with a handy feature to help you in a password-cracking project by storing/looking up/reporting hashes/passowrds/users.","T1087 - T1482 - T1201 - T1213 - T1003","TA0007 - TA0008 - TA0009 - TA0006","N/A","N/A","Reconnaissance","https://github.com/skelsec/jackdaw","1","1","N/A","N/A","N/A","6","576","89","2025-03-15T13:37:50Z","2019-03-27T18:36:41Z","8223" +"*/jaff.profile*",".{0,1000}\/jaff\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","8225" +"*/jasmin-ransomware.git*",".{0,1000}\/jasmin\-ransomware\.git.{0,1000}","offensive_tool_keyword","Jasmin-Ransomware","Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks","T1486","TA0040 - TA0002 - TA0010","N/A","N/A","Ransomware","https://github.com/codesiddhant/Jasmin-Ransomware","1","1","N/A","N/A","10","3","252","80","2021-03-01T14:51:06Z","2021-02-27T07:09:08Z","8227" +"*/jasperloader.profile*",".{0,1000}\/jasperloader\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","8228" +"*/java/jndi/RMIRefServer.java*",".{0,1000}\/java\/jndi\/RMIRefServer\.java.{0,1000}","offensive_tool_keyword","POC","JNDI-Injection-Exploit is a tool for generating workable JNDI links and provide background services by starting RMI server. LDAP server and HTTP server. Using this tool allows you get JNDI links. you can insert these links into your POC to test vulnerability.","T1190 - T1133 - T1595 - T1132 - T1046 - T1041","TA0009 - TA0003 - TA0002 - TA0007 - TA0008 - TA0001","N/A","N/A","Exploitation tool","https://github.com/welk1n/JNDI-Injection-Exploit","1","1","N/A","N/A","N/A","10","2682","733","2023-03-22T21:23:32Z","2019-10-10T01:53:49Z","8229" +"*/jdwp-exec.nse*",".{0,1000}\/jdwp\-exec\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8230" +"*/jdwp-info.nse*",".{0,1000}\/jdwp\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8231" +"*/jdwp-inject.nse*",".{0,1000}\/jdwp\-inject\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8232" +"*/jdwp-version.nse*",".{0,1000}\/jdwp\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8233" +"*/jecretz.git*",".{0,1000}\/jecretz\.git.{0,1000}","offensive_tool_keyword","jecretz","Jira Secret Hunter - Helps you find credentials and sensitive contents in Jira tickets","T1552 - T1114 - T1119 - T1070","TA0006 - TA0009 - TA0005","N/A","Scattered Spider*","Discovery","https://github.com/sahadnk72/jecretz","1","1","N/A","N/A","7","1","43","9","2022-12-08T10:00:11Z","2020-05-25T14:40:28Z","8234" +"*/jecretz.py*",".{0,1000}\/jecretz\.py.{0,1000}","offensive_tool_keyword","jecretz","Jira Secret Hunter - Helps you find credentials and sensitive contents in Jira tickets","T1552 - T1114 - T1119 - T1070","TA0006 - TA0009 - TA0005","N/A","Scattered Spider*","Discovery","https://github.com/sahadnk72/jecretz","1","1","N/A","N/A","7","1","43","9","2022-12-08T10:00:11Z","2020-05-25T14:40:28Z","8235" +"*/Jeringa.exe*",".{0,1000}\/Jeringa\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","8236" +"*/Jira-Lens.git*",".{0,1000}\/Jira\-Lens\.git.{0,1000}","offensive_tool_keyword","Jira-Lens","Fast and customizable vulnerability scanner For JIRA written in Python","T1083 - T1065 - T1204 - T1087 - T1203","TA0007 - TA0005 - TA0001","N/A","N/A","Reconnaissance","https://github.com/MayankPandey01/Jira-Lens","1","1","N/A","N/A","N/A","4","318","52","2024-12-31T20:06:51Z","2021-11-14T18:37:47Z","8238" +"*/Jira-Lens/*",".{0,1000}\/Jira\-Lens\/.{0,1000}","offensive_tool_keyword","RedTeam_toolkit","Fast and customizable vulnerability scanner For JIRA written in Python","T1083 - T1065 - T1204 - T1087 - T1203","TA0007 - TA0005 - TA0001","N/A","N/A","Reconnaissance","https://github.com/MayankPandey01/Jira-Lens","1","1","N/A","N/A","N/A","4","318","52","2024-12-31T20:06:51Z","2021-11-14T18:37:47Z","8239" +"*/JoelGMSec/PyShell*",".{0,1000}\/JoelGMSec\/PyShell.{0,1000}","offensive_tool_keyword","pyshell","PyShell is Multiplatform Python WebShell. This tool helps you to obtain a shell-like interface on a web server to be remotely accessed. Unlike other webshells the main goal of the tool is to use as little code as possible on the server side regardless of the language used or the operating system of the server.","T1059.001 - T1059.002 - T1059.005 - T1059.007","TA0002 - TA0003 - TA0009","N/A","N/A","Exploitation tool","https://github.com/JoelGMSec/PyShell","1","1","N/A","N/A","N/A","4","309","60","2024-09-27T11:11:56Z","2021-10-19T07:49:17Z","8240" +"*/john.git*",".{0,1000}\/john\.git.{0,1000}","offensive_tool_keyword","ldapdomaindump","Active Directory information dumper via LDAP","T1087 - T1005 - T1016","TA0007","N/A","EMBER BEAR","Discovery","https://github.com/dirkjanm/ldapdomaindump","1","1","N/A","N/A","10","10","1242","201","2025-04-06T13:31:57Z","2016-05-24T18:46:56Z","8242" +"*/john/run/*.pl*",".{0,1000}\/john\/run\/.{0,1000}\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","8243" +"*/john/run/*.py*",".{0,1000}\/john\/run\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","8244" +"*/john_the_ripper_cracker.py*",".{0,1000}\/john_the_ripper_cracker\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","8245" +"*/JohnTheRipper*",".{0,1000}\/JohnTheRipper.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","8246" +"*/Jomungand.git*",".{0,1000}\/Jomungand\.git.{0,1000}","offensive_tool_keyword","Jomungand","Shellcode Loader with memory evasion","T1055.012 - T1027.002 - T1564.006","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/RtlDallas/Jomungand","1","1","N/A","N/A","10","","N/A","","","","8247" +"*/Jordan RAT.exe*",".{0,1000}\/Jordan\sRAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","8248" +"*/Jormungand.sln*",".{0,1000}\/Jormungand\.sln.{0,1000}","offensive_tool_keyword","Jomungand","Shellcode Loader with memory evasion","T1055.012 - T1027.002 - T1564.006","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/RtlDallas/Jomungand","1","1","N/A","N/A","10","","N/A","","","","8249" +"*/Jormungandr.git*",".{0,1000}\/Jormungandr\.git.{0,1000}","offensive_tool_keyword","Jormungandr","Jormungandr is a kernel implementation of a COFF loader allowing kernel developers to load and execute their COFFs in the kernel","T1215 - T1059.003 - T1547.006","TA0004 - TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Idov31/Jormungandr","1","1","N/A","N/A","N/A","3","228","27","2023-09-26T18:06:53Z","2023-06-25T06:24:16Z","8250" +"*/jRAT v0.8d.exe*",".{0,1000}\/jRAT\sv0\.8d\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","8260" +"*/js_inject.txt*",".{0,1000}\/js_inject\.txt.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","8261" +"*/JuicyPotato.exe*",".{0,1000}\/JuicyPotato\.exe.{0,1000}","offensive_tool_keyword","JuicyPotato","Windows Local Privilege Escalation from Service Account to System","T1055.012 - T1068 - T1548.002 - T1505.003","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/uknowsec/JuicyPotato","1","1","N/A","N/A","10","2","190","46","2021-07-01T05:28:41Z","2021-06-10T12:06:13Z","8263" +"*/JuicyPotato.git*",".{0,1000}\/JuicyPotato\.git.{0,1000}","offensive_tool_keyword","JuicyPotato","Windows Local Privilege Escalation from Service Account to System","T1055.012 - T1068 - T1548.002 - T1505.003","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/uknowsec/JuicyPotato","1","1","N/A","N/A","10","2","190","46","2021-07-01T05:28:41Z","2021-06-10T12:06:13Z","8264" +"*/JuicyPotato.x64.dll*",".{0,1000}\/JuicyPotato\.x64\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8265" +"*/JuicyPotato.x86.dll*",".{0,1000}\/JuicyPotato\.x86\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8266" +"*/JuicyPotato_x32.exe*",".{0,1000}\/JuicyPotato_x32\.exe.{0,1000}","offensive_tool_keyword","JuicyPotato","Windows Local Privilege Escalation from Service Account to System","T1055.012 - T1068 - T1548.002 - T1505.003","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/uknowsec/JuicyPotato","1","1","N/A","N/A","10","2","190","46","2021-07-01T05:28:41Z","2021-06-10T12:06:13Z","8267" +"*/JuicyPotato_x64.exe*",".{0,1000}\/JuicyPotato_x64\.exe.{0,1000}","offensive_tool_keyword","JuicyPotato","Windows Local Privilege Escalation from Service Account to System","T1055.012 - T1068 - T1548.002 - T1505.003","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/uknowsec/JuicyPotato","1","1","N/A","N/A","10","2","190","46","2021-07-01T05:28:41Z","2021-06-10T12:06:13Z","8268" +"*/JuicyPotatoNG.git*",".{0,1000}\/JuicyPotatoNG\.git.{0,1000}","offensive_tool_keyword","JuicyPotatoNG","Another Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","FoxKitten - APT33 - Volatile Cedar - Sandworm","Privilege Escalation","https://github.com/antonioCoco/JuicyPotatoNG","1","1","N/A","N/A","10","9","844","101","2022-11-12T01:48:39Z","2022-09-21T17:08:35Z","8269" +"*/JuicyPotato-webshell/*",".{0,1000}\/JuicyPotato\-webshell\/.{0,1000}","offensive_tool_keyword","JuicyPotato","Windows Local Privilege Escalation from Service Account to System","T1055.012 - T1068 - T1548.002 - T1505.003","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/uknowsec/JuicyPotato","1","1","N/A","N/A","10","2","190","46","2021-07-01T05:28:41Z","2021-06-10T12:06:13Z","8270" +"*/Jump-exec/Psexec*",".{0,1000}\/Jump\-exec\/Psexec.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","8271" +"*/JumpSession.cna*",".{0,1000}\/JumpSession\.cna.{0,1000}","offensive_tool_keyword","JumpSession_BOF","Beacon Object File allowing creation of Beacons in different sessions","T1055 - T1055.012 - T1548.002","TA0002 - TA0003 - TA0004","N/A","N/A","Persistence","https://github.com/Octoberfest7/JumpSession_BOF","1","1","N/A","N/A","9","1","80","13","2022-05-23T22:23:33Z","2022-05-21T17:38:18Z","8272" +"*/JumpSession_BOF.git*",".{0,1000}\/JumpSession_BOF\.git.{0,1000}","offensive_tool_keyword","JumpSession_BOF","Beacon Object File allowing creation of Beacons in different sessions","T1055 - T1055.012 - T1548.002","TA0002 - TA0003 - TA0004","N/A","N/A","Persistence","https://github.com/Octoberfest7/JumpSession_BOF","1","1","N/A","N/A","9","1","80","13","2022-05-23T22:23:33Z","2022-05-21T17:38:18Z","8273" +"*/K8_CS_*_*.rar*",".{0,1000}\/K8_CS_.{0,1000}_.{0,1000}\.rar.{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike4.4 one-click deployment script Randomly generate passwords. keys. port numbers. certificates. etc.. to solve the problem that cs4.x cannot run on Linux and report errors Gray often ginkgo design","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/AlphabugX/csOnvps","1","1","N/A","N/A","10","10","286","63","2022-03-19T00:10:03Z","2021-12-02T02:10:42Z","8276" +"*/k8gege/*",".{0,1000}\/k8gege\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","8277" +"*/k8gege/scrun/*",".{0,1000}\/k8gege\/scrun\/.{0,1000}","offensive_tool_keyword","cobaltstrike","BypassAV ShellCode Loader (Cobaltstrike/Metasploit)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/scrun","1","1","N/A","N/A","10","10","179","76","2019-07-27T07:10:08Z","2019-07-21T15:34:41Z","8278" +"*/k8gege520*",".{0,1000}\/k8gege520.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","8279" +"*/ka0tic.pl*",".{0,1000}\/ka0tic\.pl.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","8280" +"*/ka7ana/CVE*.ps1*",".{0,1000}\/ka7ana\/CVE.{0,1000}\.ps1.{0,1000}","offensive_tool_keyword","poc","Simple PoC in PowerShell for CVE-2023-23397","T1068 - T1557.001 - T1187 - T1212 -T1003.001 - T1550","TA0003 - TA0002 - TA0004","N/A","APT28 - STRONTIUM - Sednit - Sofacy - Fancy Bear","Exploitation tool","https://github.com/ka7ana/CVE-2023-23397","1","1","N/A","N/A","N/A","1","40","12","2023-03-16T19:29:49Z","2023-03-16T19:10:37Z","8281" +"*/KAdot Universal Shell v0.1.6.php*",".{0,1000}\/KAdot\sUniversal\sShell\sv0\.1\.6\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","8282" +"*/kali/pool/main/*",".{0,1000}\/kali\/pool\/main\/.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","8283" +"*/kalilinux/packages/winexe*",".{0,1000}\/kalilinux\/packages\/winexe.{0,1000}","offensive_tool_keyword","winexe","Winexe remotely executes commands on Windows systems from GNU/Linux","T1059.004 - T1021.005 - T1078.003","TA0002 - TA0008 - TA0011","N/A","APT28","Lateral Movement","https://www.kali.org/tools/winexe/","1","1","#linux #windows","N/A","8","8","N/A","N/A","N/A","N/A","8284" +"*/kali-linux-2023*",".{0,1000}\/kali\-linux\-2023.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","8285" +"*/kali-tools-*",".{0,1000}\/kali\-tools\-.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","8286" +"*/karmaSMB.exe*",".{0,1000}\/karmaSMB\.exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","8287" +"*/karmaSMB.py*",".{0,1000}\/karmaSMB\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","8288" +"*/katoolin3*",".{0,1000}\/katoolin3.{0,1000}","offensive_tool_keyword","katoolin3","Katoolin3 brings all programs available in Kali Linux to Debian and Ubuntu.","T1203 - T1090 - T1020","TA0006 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/s-h-3-l-l/katoolin3","1","1","#linux","N/A","N/A","4","370","120","2020-08-05T17:21:00Z","2019-09-05T13:14:46Z","8289" +"*/KaynLdr.git*",".{0,1000}\/KaynLdr\.git.{0,1000}","offensive_tool_keyword","KaynLdr","KaynLdr is a Reflective Loader written in C/ASM","T1055 - T1027 - T1055.012","TA0002 - TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/KaynLdr","1","1","N/A","N/A","9","6","532","108","2023-12-03T18:26:04Z","2021-12-26T14:32:11Z","8290" +"*/KaynStrike.cna*",".{0,1000}\/KaynStrike\.cna.{0,1000}","offensive_tool_keyword","KaynStrike","A User Defined Reflective Loader for Cobalt Strike Beacon that spoofs the thread start address and frees itself after entry point was executed.","T1055 - T1036 - T1070 - T1055.012 - T1055.001","TA0002 - TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/KaynStrike","1","1","N/A","N/A","9","5","422","66","2023-12-03T18:05:11Z","2022-05-30T04:22:59Z","8291" +"*/KaynStrike.git*",".{0,1000}\/KaynStrike\.git.{0,1000}","offensive_tool_keyword","KaynStrike","A User Defined Reflective Loader for Cobalt Strike Beacon that spoofs the thread start address and frees itself after entry point was executed.","T1055 - T1036 - T1070 - T1055.012 - T1055.001","TA0002 - TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/KaynStrike","1","1","N/A","N/A","9","5","422","66","2023-12-03T18:05:11Z","2022-05-30T04:22:59Z","8292" +"*/kdstab.*",".{0,1000}\/kdstab\..{0,1000}","offensive_tool_keyword","cobaltstrike","BOF combination of KillDefender and Backstab","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Octoberfest7/KDStab","1","1","N/A","N/A","10","10","167","37","2023-03-23T02:22:50Z","2022-03-10T06:09:52Z","8294" +"*/KDStab.*",".{0,1000}\/KDStab\..{0,1000}","offensive_tool_keyword","cobaltstrike","BOF combination of KillDefender and Backstab","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Octoberfest7/KDStab","1","1","N/A","N/A","10","10","167","37","2023-03-23T02:22:50Z","2022-03-10T06:09:52Z","8295" +"*/KDStab/*",".{0,1000}\/KDStab\/.{0,1000}","offensive_tool_keyword","cobaltstrike","BOF combination of KillDefender and Backstab","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Octoberfest7/KDStab","1","1","N/A","N/A","10","10","167","37","2023-03-23T02:22:50Z","2022-03-10T06:09:52Z","8296" +"*/KeeFarce.exe*",".{0,1000}\/KeeFarce\.exe.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","1","N/A","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","8297" +"*/KeeFarce.git*",".{0,1000}\/KeeFarce\.git.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","1","N/A","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","8298" +"*/KeeFarceDLL.dll*",".{0,1000}\/KeeFarceDLL\.dll.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","1","N/A","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","8299" +"*/keepass_discover.py*",".{0,1000}\/keepass_discover\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","8300" +"*/keepass_discover_*.txt*",".{0,1000}\/keepass_discover_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","8301" +"*/keepass_trigger.py*",".{0,1000}\/keepass_trigger\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","8302" +"*/KeePwn.git*",".{0,1000}\/KeePwn\.git.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","8304" +"*/KeePwn.py*",".{0,1000}\/KeePwn\.py.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","8305" +"*/KeePwn/keepwn/*",".{0,1000}\/KeePwn\/keepwn\/.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","8307" +"*/KeePwn/tarball/*",".{0,1000}\/KeePwn\/tarball\/.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","8308" +"*/KeePwn/zipball/*",".{0,1000}\/KeePwn\/zipball\/.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","8309" +"*/KeeTheft.exe*",".{0,1000}\/KeeTheft\.exe.{0,1000}","offensive_tool_keyword","KeeTheft","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","KeeTheft","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","8311" +"*/KeeTheft.exe*",".{0,1000}\/KeeTheft\.exe.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","8312" +"*/KeeTheft.exe*",".{0,1000}\/KeeTheft\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","KeeTheft","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","8313" +"*/KeeThief.git*",".{0,1000}\/KeeThief\.git.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","8314" +"*/KeeThief.git*",".{0,1000}\/KeeThief\.git.{0,1000}","offensive_tool_keyword","KeeThiefSyscalls","Patch GhostPack/KeeThief for it to use DInvoke and syscalls","T1003.001 - T1558.002","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/Metro-Holografix/KeeThiefSyscalls","1","1","N/A","private github repo","10","","N/A","","","","8315" +"*/KeeThief.ps1*",".{0,1000}\/KeeThief\.ps1.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","8316" +"*/kekeo.exe*",".{0,1000}\/kekeo\.exe.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","8317" +"*/kematian.exe*",".{0,1000}\/kematian\.exe.{0,1000}","offensive_tool_keyword","Kematian Stealer","Fake WinRar site distributes malware (+stealer +miner +hvnc +ransomware) from GitHub","T1195 - T1566 - T1569 - T1106 - T1486 - T1113","TA0001 - TA0002 - TA0005 - TA0006 - TA0007 - TA0009 - TA0010 - TA0011 - TA0040 - TA0043","N/A","N/A","Malware","https://github.com/Pirate-Devs/Kematian","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","8318" +"*/kerberoast.*",".{0,1000}\/kerberoast\..{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","8319" +"*/kerberoast.c*",".{0,1000}\/kerberoast\.c.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","8320" +"*/kerberoast.c*",".{0,1000}\/kerberoast\.c.{0,1000}","offensive_tool_keyword","nanorobeus","COFF file (BOF) for managing Kerberos tickets.","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","C2","https://github.com/wavvs/nanorobeus","1","1","N/A","N/A","10","10","294","31","2023-07-02T12:56:27Z","2022-07-04T00:33:30Z","8321" +"*/kerberoast.h*",".{0,1000}\/kerberoast\.h.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","8322" +"*/kerberoast.py*",".{0,1000}\/kerberoast\.py.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","8323" +"*/kerberoast/*.*",".{0,1000}\/kerberoast\/.{0,1000}\..{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","8324" +"*/kerberoast_hashes_*.txt*",".{0,1000}\/kerberoast_hashes_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","8325" +"*/KerberOPSEC.git*",".{0,1000}\/KerberOPSEC\.git.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","1","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","8327" +"*/kerberos.py*",".{0,1000}\/kerberos\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","8328" +"*/kerberos-ldap-password-hunter*",".{0,1000}\/kerberos\-ldap\-password\-hunter.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/oldboy21/LDAP-Password-Hunter","1","1","N/A","N/A","10","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","8329" +"*/kerberosticket.py*",".{0,1000}\/kerberosticket\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","8330" +"*/Kerbeus-BOF.git*",".{0,1000}\/Kerbeus\-BOF\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","BOF for Kerberos abuse (an implementation of some important features of the Rubeus)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RalfHacker/Kerbeus-BOF","1","1","N/A","N/A","10","10","458","51","2025-03-29T18:15:17Z","2023-11-20T10:01:36Z","8331" +"*/kerbrute.git*",".{0,1000}\/kerbrute\.git.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","8333" +"*/kerbrute.go*",".{0,1000}\/kerbrute\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","8334" +"*/kerbrute.py*",".{0,1000}\/kerbrute\.py.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","8335" +"*/kerbrute/*",".{0,1000}\/kerbrute\/.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","8336" +"*/KernelMii.c*",".{0,1000}\/KernelMii\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tijme/kernel-mii","1","1","N/A","N/A","10","10","81","24","2023-05-07T18:38:29Z","2022-06-25T11:13:45Z","8337" +"*/KExecDD.git*",".{0,1000}\/KExecDD\.git.{0,1000}","offensive_tool_keyword","KExecDD","Admin to Kernel code execution using the KSecDD driver","T1068 - T1055.011","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/floesen/KExecDD","1","1","N/A","N/A","8","3","244","41","2024-04-19T09:58:14Z","2024-04-19T08:54:49Z","8338" +"*/KeyCredentialLink.git*",".{0,1000}\/KeyCredentialLink\.git.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","1","N/A","N/A","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","8339" +"*/KeyCredentialLink.ps1*",".{0,1000}\/KeyCredentialLink\.ps1.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","1","N/A","N/A","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","8340" +"*/keylistattack.py*",".{0,1000}\/keylistattack\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","8342" +"*/keylog.exe*",".{0,1000}\/keylog\.exe.{0,1000}","offensive_tool_keyword","Powershell-Scripts-for-Hackers-and-Pentesters","","T1059.001 - T1119 - T1027 - T1016 - T1056.001","TA0002 - TA0009 - TA0005 - TA0007 - TA0010","N/A","N/A","Collection","https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters","1","1","N/A","N/A","10","5","415","49","2025-02-23T09:05:44Z","2023-02-27T14:27:32Z","8343" +"*/keylog.php*",".{0,1000}\/keylog\.php.{0,1000}","offensive_tool_keyword","BlackShades","remote access trojan (RAT) used by attackers to gain unauthorized control over a victim's computer","T1012 - T1059.001 - T1071.001 - T1105 - T1113 - T1125","TA0003 - TA0005 - TA0008 - TA0010 - TA0011","N/A","N/A","Malware","https://github.com/yuankong666/Ultimate-RAT-Collection/tree/main/BlackShades","1","1","N/A","N/A","10","10","2468","431","2025-04-15T16:14:10Z","2023-09-12T00:41:11Z","8344" +"*/KeyLogger.ahk*",".{0,1000}\/KeyLogger\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","8345" +"*/keylogger.cpp*",".{0,1000}\/keylogger\.cpp.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/trustedsec/SliverKeylogger","1","1","N/A","N/A","10","10","159","44","2023-09-22T19:39:04Z","2022-06-17T19:32:53Z","8346" +"*/KeyLogger.cs*",".{0,1000}\/KeyLogger\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","8347" +"*/Keylogger.dll*",".{0,1000}\/Keylogger\.dll.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","8348" +"*/keylogger.exe*",".{0,1000}\/keylogger\.exe.{0,1000}","offensive_tool_keyword","keylogger","Keyboard recording","T1056.001","TA0006 - TA0009","N/A","N/A","Collection","https://github.com/uknowsec/keylogger","1","1","N/A","N/A","9","2","140","35","2021-05-19T08:33:58Z","2020-11-10T07:15:50Z","8349" +"*/keylogger.exe*",".{0,1000}\/keylogger\.exe.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/trustedsec/SliverKeylogger","1","1","N/A","N/A","10","10","159","44","2023-09-22T19:39:04Z","2022-06-17T19:32:53Z","8350" +"*/keylogger.git*",".{0,1000}\/keylogger\.git.{0,1000}","offensive_tool_keyword","keylogger","Keyboard recording","T1056.001","TA0006 - TA0009","N/A","N/A","Collection","https://github.com/uknowsec/keylogger","1","1","N/A","N/A","9","2","140","35","2021-05-19T08:33:58Z","2020-11-10T07:15:50Z","8351" +"*/keylogger/*.*",".{0,1000}\/keylogger\/.{0,1000}\..{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","8352" +"*/keyscan.go*",".{0,1000}\/keyscan\.go.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","8353" +"*/keywa7/releases/download/*",".{0,1000}\/keywa7\/releases\/download\/.{0,1000}","offensive_tool_keyword","keywa7","The tool that bypasses the firewall's Application Based Rules and lets you connect to anywhere","T1090.001 - T1071.004 - T1071.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/keywa7/keywa7","1","1","N/A","N/A","6","1","61","9","2024-08-19T08:09:33Z","2024-08-05T15:27:26Z","8354" +"*/Kill_protector.py*",".{0,1000}\/Kill_protector\.py.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","8357" +"*/KillAV.exe*",".{0,1000}\/KillAV\.exe.{0,1000}","offensive_tool_keyword","Burntcigar KillAV","Scans for process names linked to known antivirus or EDR products - then adds their process IDs to a stack for later termination - often used by attackers","T1089 - T1489 - T1562","TA0005","KillAV","Cuba","Malware","https://www.virustotal.com/gui/file/aeb044d310801d546d10b247164c78afde638a90b6ef2f04e1f40170e54dec03?nocache=1","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","8359" +"*/killav.py*",".{0,1000}killav\.py.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","8360" +"*/killav.rb*",".{0,1000}\/killav\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8361" +"*/Killchain.ps1*",".{0,1000}\/Killchain\.ps1.{0,1000}","offensive_tool_keyword","Graphpython","Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit","T1078.004 - T1114.002","TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010","N/A","N/A","Discovery","https://github.com/mlcsec/Graphpython","1","1","N/A","N/A","7","2","145","13","2024-12-07T21:54:00Z","2024-07-10T00:04:48Z","8362" +"*/KillDefenderBOF*",".{0,1000}\/KillDefenderBOF.{0,1000}","offensive_tool_keyword","KillDefenderBOF","KillDefenderBOF is a Beacon Object File PoC implementation of pwn1sher/KillDefender - kill defender","T1055.002 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/Cerbersec/KillDefenderBOF","1","1","N/A","N/A","10","3","224","30","2022-04-12T17:45:50Z","2022-02-06T21:59:03Z","8363" +"*/killer.exe*",".{0,1000}\/killer\.exe.{0,1000}","offensive_tool_keyword","killer","evade AVs and EDRs or security tools","T1564 - T1027 - T1070","TA0005","N/A","N/A","Defense Evasion","https://github.com/0xHossam/Killer","1","1","N/A","N/A","10","9","804","128","2024-07-02T10:24:43Z","2023-04-08T16:29:52Z","8364" +"*/Killer.git*",".{0,1000}\/Killer\.git.{0,1000}","offensive_tool_keyword","killer","evade AVs and EDRs or security tools","T1564 - T1027 - T1070","TA0005","N/A","N/A","Defense Evasion","https://github.com/0xHossam/Killer","1","1","N/A","N/A","10","9","804","128","2024-07-02T10:24:43Z","2023-04-08T16:29:52Z","8365" +"*/KillEvenlogService.ps1*",".{0,1000}\/KillEvenlogService\.ps1.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8366" +"*/KillEvenlogService.ps1*",".{0,1000}\/KillEvenlogService\.ps1.{0,1000}","offensive_tool_keyword","EventLogMaster","Cobalt Strike Plugin - RDP Log Forensics & Clearing","T1070.001 - T1070.003 - T1070.004 - T1563.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/QAX-A-Team/EventLogMaster","1","1","N/A","N/A","6","4","361","73","2019-12-23T10:31:35Z","2019-12-17T05:07:09Z","8367" +"*/kimi.py*",".{0,1000}\/kimi\.py.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","8369" +"*/kintercept.py*",".{0,1000}\/kintercept\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","8370" +"*/Kirby.ps1*",".{0,1000}\/Kirby\.ps1.{0,1000}","offensive_tool_keyword","PSMapExec","A PowerShell tool heavily inspired by the popular tool CrackMapExec. Far too often I find myself on engagements without access to Linux in order to make use of CrackMapExec.","T1059.001 - T1021.006 - T1110.001 - T1021.001 - T1021.004 - T1021.005 - T1021.003 - T1621","TA0002 - TA0011 - TA0005 - TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/The-Viper-One/PsMapExec","1","1","N/A","N/A","10","10","954","108","2025-03-11T14:38:50Z","2023-06-20T16:57:27Z","8371" +"*/kismetwireless/*",".{0,1000}\/kismetwireless\/.{0,1000}","offensive_tool_keyword","kismet","Kismet is a wireless network and device detector. sniffer. wardriving tool. and WIDS (wireless intrusion detection) framework.","T1016 - T1040 - T1052 - T1065 - T1096 - T1102 - T1113 - T1114 - T1123 - T1127 - T1136 - T1143 - T1190 - T1200 - T1201 - T1219 - T1222 - T1496 - T1497 - T1557 - T1560 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0007 - TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/kismetwireless/kismet","1","1","N/A","N/A","N/A","10","1711","316","2025-04-16T21:06:48Z","2016-09-20T13:26:00Z","8373" +"*/kitrap0d.*",".{0,1000}\/kitrap0d\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8374" +"*/kittens/haloKitten*",".{0,1000}\/kittens\/haloKitten.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","8375" +"*/kittens/recycleKitten*",".{0,1000}\/kittens\/recycleKitten.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","8376" +"*/KittyStager/*",".{0,1000}\/KittyStager\/.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","8377" +"*/kiwi.rb*",".{0,1000}\/kiwi\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8378" +"*/kiwi_passwords.yar*",".{0,1000}\/kiwi_passwords\.yar.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8379" +"*/klezVirus/CandyPotato*",".{0,1000}\/klezVirus\/CandyPotato.{0,1000}","offensive_tool_keyword","CandyPotato","CandyPotato - Pure C++ weaponized fully automated implementation of RottenPotatoNG. This tool has been made on top of the original JuicyPotato with the main focus on improving and adding some functionalities which was lacking","T1547.004","TA0002","N/A","Volatile Cedar","Exploitation tool","https://github.com/klezVirus/CandyPotato","1","1","N/A","N/A","N/A","4","306","67","2021-09-16T17:08:52Z","2020-08-21T17:14:30Z","8380" +"*/klg.ps1*",".{0,1000}\/klg\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","8381" +"*/knowsmore.git*",".{0,1000}\/knowsmore\.git.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","1","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","8384" +"*/knowsmore.py*",".{0,1000}\/knowsmore\.py.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","1","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","8385" +"*/knqyf263/CVE-2022-0847*",".{0,1000}\/knqyf263\/CVE\-2022\-0847.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/knqyf263/CVE-2022-0847","1","1","N/A","N/A","N/A","1","47","9","2022-03-08T13:54:08Z","2022-03-08T13:48:55Z","8386" +"*/knx-gateway-discover.nse*",".{0,1000}\/knx\-gateway\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8387" +"*/knx-gateway-info.nse*",".{0,1000}\/knx\-gateway\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8388" +"*/koadic.git*",".{0,1000}\/koadic\.git.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","8390" +"*/Koppeling.git*",".{0,1000}\/Koppeling\.git.{0,1000}","offensive_tool_keyword","Koppeling","Adaptive DLL hijacking / dynamic export forwarding","T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/monoxgas/Koppeling","1","1","N/A","N/A","8","8","748","128","2020-07-06T14:47:57Z","2020-02-18T21:08:16Z","8391" +"*/kost/revsocks/releases*",".{0,1000}\/kost\/revsocks\/releases.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","N/A","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","8392" +"*/KrakenMask.git*",".{0,1000}\/KrakenMask\.git.{0,1000}","offensive_tool_keyword","KrakenMask","A sleep obfuscation tool is used to encrypt the content of the .text section with RC4 (using SystemFunction032). To achieve this encryption a ROP chain is employed with QueueUserAPC and NtContinue.","T1027 - T1027.002 - T1055 - T1055.011 - T1059 - T1059.003","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/RtlDallas/KrakenMask","1","1","N/A","N/A","9","3","N/A","N/A","N/A","N/A","8393" +"*/krb5/*.py",".{0,1000}\/krb5\/.{0,1000}\.py","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","8394" +"*/krb5-enum-users.nse*",".{0,1000}\/krb5\-enum\-users\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8395" +"*/krbjack.git*",".{0,1000}\/krbjack\.git.{0,1000}","offensive_tool_keyword","krbjack","A Kerberos AP-REQ hijacking tool with DNS unsecure updates abuse.","T1558.002 - T1552.004 - T1048.005","TA0006 - TA0007 ","N/A","N/A","Sniffing & Spoofing","https://github.com/almandin/krbjack","1","1","N/A","N/A","10","2","113","21","2025-01-22T18:12:00Z","2023-04-16T10:44:55Z","8396" +"*/KrbRelay*",".{0,1000}\/KrbRelay.{0,1000}","offensive_tool_keyword","KrbRelay","Relaying 3-headed dogs. More details at https://googleprojectzero.blogspot.com/2021/10/windows-exploitation-tricks-relaying.html and https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html","T1212 - T1558 - T1550","TA0001 - TA0004 -TA0006","N/A","Dispossessor","Exploitation tool","https://github.com/cube0x0/KrbRelay","1","1","N/A","N/A","N/A","10","907","125","2022-05-29T09:45:03Z","2022-02-14T08:21:57Z","8397" +"*/KrbRelay.exe*",".{0,1000}\/KrbRelay\.exe.{0,1000}","offensive_tool_keyword","KrbRelay","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","KrbRelay","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","8398" +"*/KrbRelay.exe*",".{0,1000}\/KrbRelay\.exe.{0,1000}","offensive_tool_keyword","KrbRelay-SMBServer","acts as an SMB server (instead of DCOM) to relay Kerberos AP-REQ to CIFS or HTTP","T1557 - T1021 - T1205 - T1071","TA0006 - TA0008 - TA0010","N/A","Black Basta","Lateral Movement","https://github.com/decoder-it/KrbRelay-SMBServer","1","1","N/A","N/A","9","3","215","26","2024-10-08T14:55:59Z","2024-10-05T12:28:55Z","8399" +"*/KrbRelay.exe*",".{0,1000}\/KrbRelay\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","8400" +"*/KrbRelay.exe*",".{0,1000}\/KrbRelay\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","KrbRelay","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","8401" +"*/KrbRelay.exe*",".{0,1000}\/KrbRelay\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","8402" +"*/KrbRelay-SMBServer.git*",".{0,1000}\/KrbRelay\-SMBServer\.git.{0,1000}","offensive_tool_keyword","KrbRelay-SMBServer","acts as an SMB server (instead of DCOM) to relay Kerberos AP-REQ to CIFS or HTTP","T1557 - T1021 - T1205 - T1071","TA0006 - TA0008 - TA0010","N/A","Black Basta","Lateral Movement","https://github.com/decoder-it/KrbRelay-SMBServer","1","1","N/A","N/A","9","3","215","26","2024-10-08T14:55:59Z","2024-10-05T12:28:55Z","8403" +"*/KrbRelay-SMBServer/releases/*",".{0,1000}\/KrbRelay\-SMBServer\/releases\/.{0,1000}","offensive_tool_keyword","KrbRelay-SMBServer","acts as an SMB server (instead of DCOM) to relay Kerberos AP-REQ to CIFS or HTTP","T1557 - T1021 - T1205 - T1071","TA0006 - TA0008 - TA0010","N/A","Black Basta","Lateral Movement","https://github.com/decoder-it/KrbRelay-SMBServer","1","1","N/A","N/A","9","3","215","26","2024-10-08T14:55:59Z","2024-10-05T12:28:55Z","8404" +"*/KrbRelayUp.exe*",".{0,1000}\/KrbRelayUp\.exe.{0,1000}","offensive_tool_keyword","KrbRelayUp","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","Dispossessor - Back Basta","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","KrbRelayUp","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","8405" +"*/KrbRelayUp.exe*",".{0,1000}\/KrbRelayUp\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","8406" +"*/KrbRelayUp.exe*",".{0,1000}\/KrbRelayUp\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","KrbRelayUp","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","8407" +"*/KrbRelayUp.exe*",".{0,1000}\/KrbRelayUp\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","8408" +"*/KrbRelayUp.git*",".{0,1000}\/KrbRelayUp\.git.{0,1000}","offensive_tool_keyword","KrbRelayUp","a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).","T1558 - T1210","TA0004 - TA0003","N/A","Dispossessor - Back Basta","Privilege Escalation","https://github.com/Dec0ne/KrbRelayUp","1","1","N/A","N/A","10","10","1580","209","2022-08-06T12:23:58Z","2022-04-24T21:33:00Z","8409" +"*/krbrelayx*",".{0,1000}\/krbrelayx.{0,1000}","offensive_tool_keyword","krbrelayx","Kerberos unconstrained delegation abuse toolkit","T1558.003 - T1098","TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/dirkjanm/krbrelayx","1","1","N/A","N/A","N/A","10","1281","181","2025-01-27T09:22:54Z","2019-01-08T18:42:07Z","8410" +"*/KRBUACBypass*",".{0,1000}\/KRBUACBypass.{0,1000}","offensive_tool_keyword","KRBUACBypass","UAC Bypass By Abusing Kerberos Tickets","T1548.002 - T1558 - T1558.003","TA0004 - TA0006","N/A","N/A","Defense Evasion","https://github.com/wh0amitz/KRBUACBypass","1","1","N/A","N/A","8","5","496","62","2023-08-10T02:51:59Z","2023-07-27T12:08:12Z","8411" +"*/KRBUACBypass.git*",".{0,1000}\/KRBUACBypass\.git.{0,1000}","offensive_tool_keyword","KRBUACBypass","UAC Bypass By Abusing Kerberos Tickets","T1548.002 - T1558 - T1558.003","TA0004 - TA0006","N/A","N/A","Defense Evasion","https://github.com/wh0amitz/KRBUACBypass","1","1","N/A","N/A","8","5","496","62","2023-08-10T02:51:59Z","2023-07-27T12:08:12Z","8412" +"*/kronos.profile*",".{0,1000}\/kronos\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","8413" +"*/Krueger.exe*",".{0,1000}\/Krueger\.exe.{0,1000}","offensive_tool_keyword","Krueger","remotely killing EDR with WDAC","T1562.001 - T1562.004 - T1218.011 - T1548.002 - T1027","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/logangoins/Krueger","1","1","N/A","N/A","9","4","353","42","2025-01-06T06:57:14Z","2024-11-15T20:11:01Z","8414" +"*/Krueger.git*",".{0,1000}\/Krueger\.git.{0,1000}","offensive_tool_keyword","Krueger","remotely killing EDR with WDAC","T1562.001 - T1562.004 - T1218.011 - T1548.002 - T1027","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/logangoins/Krueger","1","1","N/A","N/A","9","4","353","42","2025-01-06T06:57:14Z","2024-11-15T20:11:01Z","8415" +"*/kubesploit.git*",".{0,1000}\/kubesploit\.git.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","8416" +"*/Kubestroyer.git*",".{0,1000}\/Kubestroyer\.git.{0,1000}","offensive_tool_keyword","Kubestroyer","Kubestroyer aims to exploit Kubernetes clusters misconfigurations and be the swiss army knife of your Kubernetes pentests","T1588.002 - T1596 - T1552.004","TA0005 - TA0007","N/A","N/A","Exploitation tool","https://github.com/Rolix44/Kubestroyer","1","1","N/A","N/A","10","4","359","22","2024-07-26T06:33:00Z","2022-09-15T13:31:21Z","8417" +"*/L0ading-x/cve-2022-23131*",".{0,1000}\/L0ading\-x\/cve\-2022\-23131.{0,1000}","offensive_tool_keyword","POC","POC exploitaiton of zabbix saml bypass exp vulnerability cve-2022-23131 (Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML)","T1548 - T1190","TA0001 - TA0002","N/A","N/A","Exploitation tool","https://github.com/L0ading-x/cve-2022-23131","1","1","N/A","N/A","N/A","1","29","12","2022-02-22T01:45:34Z","2022-02-22T01:39:52Z","8418" +"*/laconicwolf/burp-extensions*",".{0,1000}\/laconicwolf\/burp\-extensions.{0,1000}","offensive_tool_keyword","burpsuite","A collection of scripts to extend Burp Suite","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Discovery","https://github.com/laconicwolf/burp-extensions","1","1","N/A","network exploitation tool","N/A","2","142","31","2019-04-08T00:49:45Z","2018-03-23T16:05:01Z","8420" +"*/Ladon.exe*",".{0,1000}\/Ladon\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8421" +"*/Ladon.go*",".{0,1000}\/Ladon\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","8422" +"*/Ladon.ps1*",".{0,1000}\/Ladon\.ps1.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","8423" +"*/Ladon.py*",".{0,1000}\/Ladon\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","8424" +"*/Ladon/Ladon.*",".{0,1000}\/Ladon\/Ladon\..{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","8425" +"*/Ladon/obj/x86*",".{0,1000}\/Ladon\/obj\/x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","8426" +"*/Ladon1.exe*",".{0,1000}\/Ladon1\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8427" +"*/LadonGo/*",".{0,1000}\/LadonGo\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","8428" +"*/lambda__backdoor_new_roles*",".{0,1000}\/lambda__backdoor_new_roles.{0,1000}","offensive_tool_keyword","pacu","The AWS exploitation framework designed for testing the security of Amazon Web Services environments.","T1136.003 - T1190 - T1078.004","TA0006 - TA0001","N/A","Scattered Spider*","Framework","https://github.com/RhinoSecurityLabs/pacu","1","1","N/A","N/A","9","10","4651","731","2025-03-20T21:08:57Z","2018-06-13T21:58:59Z","8429" +"*/lambda__backdoor_new_sec_groups*",".{0,1000}\/lambda__backdoor_new_sec_groups.{0,1000}","offensive_tool_keyword","pacu","The AWS exploitation framework designed for testing the security of Amazon Web Services environments.","T1136.003 - T1190 - T1078.004","TA0006 - TA0001","N/A","Scattered Spider*","Framework","https://github.com/RhinoSecurityLabs/pacu","1","1","N/A","N/A","9","10","4651","731","2025-03-20T21:08:57Z","2018-06-13T21:58:59Z","8430" +"*/lambda__backdoor_new_users*",".{0,1000}\/lambda__backdoor_new_users.{0,1000}","offensive_tool_keyword","pacu","The AWS exploitation framework designed for testing the security of Amazon Web Services environments.","T1136.003 - T1190 - T1078.004","TA0006 - TA0001","N/A","Scattered Spider*","Framework","https://github.com/RhinoSecurityLabs/pacu","1","1","N/A","N/A","9","10","4651","731","2025-03-20T21:08:57Z","2018-06-13T21:58:59Z","8431" +"*/lambdaenum.py*",".{0,1000}\/lambdaenum\.py.{0,1000}","offensive_tool_keyword","quiet-riot","Unauthenticated enumeration of AWS - Azure and GCP Principals","T1087 - T1083 - T1210","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/righteousgambit/quiet-riot","1","1","N/A","N/A","6","3","224","30","2024-11-13T19:41:26Z","2021-10-28T15:12:27Z","8432" +"*/LambdaLooter.py*",".{0,1000}\/LambdaLooter\.py.{0,1000}","offensive_tool_keyword","AWS-Loot","Searches an AWS environment looking for secrets. by enumerating environment variables and source code. This tool allows quick enumeration over large sets of AWS instances and services.","T1552","TA0002","N/A","N/A","Exploitation tool","https://github.com/sebastian-mora/AWS-Loot","1","1","N/A","N/A","N/A","1","70","25","2020-02-02T00:51:56Z","2020-02-02T00:25:46Z","8433" +"*/lanattacks/*",".{0,1000}\/lanattacks\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8434" +"*/laps_dump_*.txt*",".{0,1000}\/laps_dump_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","8440" +"*/LAPSDumper.git*",".{0,1000}\/LAPSDumper\.git.{0,1000}","offensive_tool_keyword","LAPSDumper","Dumping LAPS from Python","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/n00py/LAPSDumper","1","1","N/A","N/A","10","3","267","35","2022-12-07T18:35:28Z","2020-12-19T05:15:10Z","8441" +"*/LAPSToolkit.git*",".{0,1000}\/LAPSToolkit\.git.{0,1000}","offensive_tool_keyword","LAPSToolkit","Functions written in PowerShell that leverage PowerView to audit and attack Active Directory environments that have deployed Microsofts Local Administrator Password Solution (LAPS). It includes finding groups specifically delegated by sysadmins. finding users with All Extended Rights that can view passwords. and viewing all computers with LAPS enabled","T1087.001 - T1069 - T1069.003 - T1069.007 - T1069.002 - T1069.001","TA0007 - TA0008 - TA0009","N/A","Scattered Spider*","Discovery","https://github.com/leoloobeek/LAPSToolkit","1","1","N/A","N/A","10","9","859","119","2018-01-31T14:45:35Z","2016-04-27T00:06:20Z","8442" +"*/LAPSToolkit.ps1*",".{0,1000}\/LAPSToolkit\.ps1.{0,1000}","offensive_tool_keyword","LAPSToolkit","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","LAPSToolkit","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","8443" +"*/LAPSToolkit.ps1*",".{0,1000}\/LAPSToolkit\.ps1.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","LAPSToolkit","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","8444" +"*/LastenLoader.exe*",".{0,1000}\/LastenLoader\.exe.{0,1000}","offensive_tool_keyword","Lastenzug","Socka4a proxy based on websockets","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","Dispossessor","C2","https://github.com/codewhitesec/Lastenzug","1","1","N/A","N/A","10","10","218","33","2022-10-18T08:55:46Z","2022-07-21T12:57:52Z","8445" +"*/Lastenzug.git*",".{0,1000}\/Lastenzug\.git.{0,1000}","offensive_tool_keyword","Lastenzug","Socka4a proxy based on websockets","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","Dispossessor","C2","https://github.com/codewhitesec/Lastenzug","1","1","N/A","N/A","10","10","218","33","2022-10-18T08:55:46Z","2022-07-21T12:57:52Z","8446" +"*/lastpass.py*",".{0,1000}\/lastpass\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","8447" +"*/Lateral movement.cna*",".{0,1000}\/Lateral\smovement\.cna.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8448" +"*/Lateral/SMB.cs*",".{0,1000}\/Lateral\/SMB\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","8449" +"*/lateral_movement/*.ps1",".{0,1000}\/lateral_movement\/.{0,1000}\.ps1","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1092","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","8451" +"*/latest/download/linpeas.sh*",".{0,1000}\/latest\/download\/linpeas\.sh.{0,1000}","offensive_tool_keyword","hackshell","Make BASH stealthy and hacker friendly with lots of bash functions","T1070.003 - T1059.004 - T1564.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/hackerschoice/hackshell","1","1","N/A","N/A","9","3","251","28","2025-04-21T11:23:41Z","2024-07-16T15:56:11Z","8452" +"*/LatLoader.git*",".{0,1000}\/LatLoader\.git.{0,1000}","offensive_tool_keyword","LatLoader","PoC module to demonstrate automated lateral movement with the Havoc C2 framework","T1570 - T1071 - T1021 - T1563 - T1105","TA0008 - TA0011 - TA0002 - TA0010","N/A","N/A","Lateral Movement","https://github.com/icyguider/LatLoader","1","1","N/A","N/A","9","4","301","35","2023-12-09T00:28:32Z","2023-10-06T15:03:17Z","8454" +"*/LatLoader.py*",".{0,1000}\/LatLoader\.py.{0,1000}","offensive_tool_keyword","LatLoader","PoC module to demonstrate automated lateral movement with the Havoc C2 framework","T1570 - T1071 - T1021 - T1563 - T1105","TA0008 - TA0011 - TA0002 - TA0010","N/A","N/A","Lateral Movement","https://github.com/icyguider/LatLoader","1","1","N/A","N/A","9","4","301","35","2023-12-09T00:28:32Z","2023-10-06T15:03:17Z","8455" +"*/lazagne.exe*",".{0,1000}\/lazagne\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8456" +"*/lazagne.exe*",".{0,1000}\/lazagne\.exe.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","8457" +"*/LaZagne.git*",".{0,1000}\/LaZagne\.git.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","8458" +"*/laZagne.py*",".{0,1000}\/laZagne\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","8459" +"*/LaZagne.py*",".{0,1000}\/LaZagne\.py.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","8460" +"*/lazagne.zip*",".{0,1000}\/lazagne\.zip.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","8461" +"*/LaZagne/Windows/*",".{0,1000}\/LaZagne\/Windows\/.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","8462" +"*/ldap_injection.txt*",".{0,1000}\/ldap_injection\.txt.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","8465" +"*/ldap_search_bof.py*",".{0,1000}\/ldap_search_bof\.py.{0,1000}","offensive_tool_keyword","bofhound","Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel","T1046 - T1087 - T1003","TA0007 - TA0009 - TA0001","N/A","N/A","Discovery","https://github.com/fortalice/bofhound","1","1","N/A","N/A","5","4","328","56","2024-02-23T15:36:24Z","2022-05-10T17:41:53Z","8466" +"*/ldap-brute.nse*",".{0,1000}\/ldap\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8467" +"*/ldap-checker.py*",".{0,1000}\/ldap\-checker\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","8468" +"*/ldapnomnom.git*",".{0,1000}\/ldapnomnom\.git.{0,1000}","offensive_tool_keyword","ldapnomnom","Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)","T1110.003 - T1205","TA0007","N/A","N/A","Discovery","https://github.com/lkarlslund/ldapnomnom","1","1","N/A","N/A","6","10","1030","80","2024-11-09T10:15:13Z","2022-09-18T10:35:09Z","8469" +"*/ldapnomnom/releases/download/*",".{0,1000}\/ldapnomnom\/releases\/download\/.{0,1000}","offensive_tool_keyword","ldapnomnom","Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)","T1110.003 - T1205","TA0007","N/A","N/A","Discovery","https://github.com/lkarlslund/ldapnomnom","1","1","N/A","N/A","6","10","1030","80","2024-11-09T10:15:13Z","2022-09-18T10:35:09Z","8470" +"*/ldapnomnom@latest*",".{0,1000}\/ldapnomnom\@latest.{0,1000}","offensive_tool_keyword","ldapnomnom","Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)","T1110.003 - T1205","TA0007","N/A","N/A","Discovery","https://github.com/lkarlslund/ldapnomnom","1","1","N/A","N/A","6","10","1030","80","2024-11-09T10:15:13Z","2022-09-18T10:35:09Z","8471" +"*/ldap-novell-getpass.nse*",".{0,1000}\/ldap\-novell\-getpass\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8472" +"*/LDAP-Password-Hunter.git*",".{0,1000}\/LDAP\-Password\-Hunter\.git.{0,1000}","offensive_tool_keyword","LDAP-Password-Hunter","Password Hunter in Active Directory","T1087.002","TA0001 - TA0007","N/A","N/A","Discovery","https://github.com/oldboy21/LDAP-Password-Hunter","1","1","N/A","N/A","7","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","8473" +"*/LDAPPER.git*",".{0,1000}\/LDAPPER\.git.{0,1000}","offensive_tool_keyword","LDAPPER","LDAP Querying without the Suck","T1087 - T1069 - T1018","TA0007","N/A","N/A","Discovery","https://github.com/shellster/LDAPPER","1","1","N/A","N/A","7","1","99","11","2024-11-09T03:53:26Z","2020-06-17T16:53:35Z","8474" +"*/ldapper.py*",".{0,1000}\/ldapper\.py.{0,1000}","offensive_tool_keyword","LDAPPER","LDAP Querying without the Suck","T1087 - T1069 - T1018","TA0007","N/A","N/A","Discovery","https://github.com/shellster/LDAPPER","1","1","N/A","N/A","7","1","99","11","2024-11-09T03:53:26Z","2020-06-17T16:53:35Z","8475" +"*/LdapRelayScan.git*",".{0,1000}\/LdapRelayScan\.git.{0,1000}","offensive_tool_keyword","LdapRelayScan","Check for LDAP protections regarding the relay of NTLM authentication","T1557","TA0001 - TA0006","N/A","N/A","Reconnaissance","https://github.com/zyn3rgy/LdapRelayScan","1","1","N/A","N/A","8","5","492","70","2024-11-19T21:11:53Z","2022-01-16T06:50:44Z","8478" +"*/ldap-rootdse.nse*",".{0,1000}\/ldap\-rootdse\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8479" +"*/ldap-search.nse*",".{0,1000}\/ldap\-search\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8480" +"*/ldapsearch-ad.git*",".{0,1000}\/ldapsearch\-ad\.git.{0,1000}","offensive_tool_keyword","ldapsearch-ad","Python3 script to quickly get various information from a domain controller through his LDAP service.","T1018 - T1087 - T1069","TA0007 - TA0002 - TA0008","N/A","N/A","Reconnaissance","https://github.com/yaap7/ldapsearch-ad","1","1","#linux #windows","N/A","5","3","215","36","2024-12-10T17:00:02Z","2019-12-08T00:25:57Z","8481" +"*/ldapsearch-ad.py*",".{0,1000}\/ldapsearch\-ad\.py.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","8482" +"*/LDAPWordlistHarvester.git*",".{0,1000}\/LDAPWordlistHarvester\.git.{0,1000}","offensive_tool_keyword","LDAPWordlistHarvester","A tool to generate a wordlist from the information present in LDAP in order to crack passwords of domain accounts.","T1210.001 - T1087.003 - T1110","TA0001 - TA0006 - TA0007","N/A","Black Basta","Credential Access","https://github.com/p0dalirius/LDAPWordlistHarvester","1","1","N/A","N/A","5","4","N/A","N/A","N/A","N/A","8483" +"*/ldeep/*",".{0,1000}\/ldeep\/.{0,1000}","offensive_tool_keyword","ldeep","In-depth ldap enumeration utility","T1087.002 - T1018 - T1482 - T1083","TA0007 - TA0008 - TA0009","N/A","N/A","Reconnaissance","https://github.com/franc-pentest/ldeep","1","1","N/A","N/A","5","5","465","54","2025-03-02T18:43:27Z","2018-10-22T18:21:44Z","8484" +"*/ldeepDump*",".{0,1000}\/ldeepDump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","8485" +"*/LdrLockLiberator.git*",".{0,1000}\/LdrLockLiberator\.git.{0,1000}","offensive_tool_keyword","LdrLockLiberator","LdrLockLiberator is a collection of techniques for escaping or otherwise forgoing Loader Lock while executing your code from DllMain or anywhere else the lock may be present.","T1574.002 - T1055","TA0005","N/A","N/A","Defense Evasion","https://github.com/ElliotKillick/LdrLockLiberator","1","1","N/A","N/A","9","4","375","65","2024-10-29T23:05:45Z","2023-10-31T10:11:16Z","8486" +"*/legba.git*",".{0,1000}\/legba\.git.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","1","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","8487" +"*/letmein.ps1*",".{0,1000}\/letmein\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","8489" +"*/LetMeOutSharp/*",".{0,1000}\/LetMeOutSharp\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Project to enumerate proxy configurations and generate shellcode from CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EncodeGroup/AggressiveProxy","1","1","N/A","N/A","10","10","141","25","2020-11-04T16:08:11Z","2020-11-04T12:53:00Z","8490" +"*/LetMeowIn.git*",".{0,1000}\/LetMeowIn\.git.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","1","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","8491" +"*/lexmark-config.nse*",".{0,1000}\/lexmark\-config\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8494" +"*/lfs_injection.exe*",".{0,1000}\/lfs_injection\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","8495" +"*/lib/GHunt/*",".{0,1000}\/lib\/GHunt\/.{0,1000}","offensive_tool_keyword","SocialPwned","SocialPwned is an OSINT tool that allows to get the emails. from a target. published in social networks like Instagram. Linkedin and Twitter to find the possible credential leaks in PwnDB or Dehashed and obtain Google account information via GHunt.","T1596","TA0002","N/A","N/A","Reconnaissance","https://github.com/MrTuxx/SocialPwned","1","1","N/A","N/A","N/A","10","1139","106","2025-01-28T19:07:29Z","2020-04-07T22:25:38Z","8497" +"*/lib/ipLookupHelper.py*",".{0,1000}\/lib\/ipLookupHelper\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","8499" +"*/lib/msf/*",".{0,1000}\/lib\/msf\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8500" +"*/libgobuster*",".{0,1000}\/libgobuster.{0,1000}","offensive_tool_keyword","gobuster","Directory/File DNS and VHost busting tool written in Go","T1046 - T1590.002 - T1590.005","TA0007 - TA0043 - TA0006","N/A","Volatile Cedar","Reconnaissance","https://github.com/OJ/gobuster","1","1","#linux","network exploitation tool","N/A","10","11434","1338","2025-04-17T06:41:43Z","2014-11-14T13:18:35Z","8503" +"*/liboffsetfinder64*",".{0,1000}\/liboffsetfinder64.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8504" +"*/libprocesshider.git*",".{0,1000}\/libprocesshider\.git.{0,1000}","offensive_tool_keyword","libprocesshider","Hide a process under Linux using the ld preloader","T1055 - T1564 - T1620","TA0005 ","N/A","Sandworm","Defense Evasion","https://github.com/gianlucaborello/libprocesshider","1","1","#linux","N/A","9","10","1061","320","2019-08-02T14:28:28Z","2014-08-16T01:09:30Z","8505" +"*/LibSnaffle*",".{0,1000}\/LibSnaffle.{0,1000}","offensive_tool_keyword","Group3r","Find vulnerabilities in AD Group Policy","T1484.002 - T1069.002 - T1087.002","TA0007 - TA0040","N/A","KNOTWEED","Discovery","https://github.com/Group3r/Group3r","1","1","N/A","AD Enumeration","7","8","781","68","2025-04-08T05:03:34Z","2021-07-05T05:05:42Z","8509" +"*/LightsOut.git*",".{0,1000}\/LightsOut\.git.{0,1000}","offensive_tool_keyword","LightsOut","Generate an obfuscated DLL that will disable AMSI & ETW","T1027.003 - T1059.001 - T1082","TA0005 - TA0002 - TA0004","N/A","N/A","Exploitation tool","https://github.com/icyguider/LightsOut","1","1","N/A","N/A","10","4","321","44","2024-07-15T21:29:16Z","2023-06-01T14:57:44Z","8510" +"*/ligolo.git*",".{0,1000}\/ligolo\.git.{0,1000}","offensive_tool_keyword","ligolo","ligolo is a simple and lightweight tool for establishing SOCKS5 or TCP tunnels from a reverse connection in complete safety (TLS certificate with elliptical curve)","T1071 - T1021 - T1573","TA0011 - TA0002","N/A","AvosLocker - LockBit","C2","https://github.com/sysdream/ligolo","1","1","N/A","N/A","10","10","1764","224","2023-01-06T19:49:22Z","2020-05-22T07:58:13Z","8511" +"*/ligolo_agent.exe*",".{0,1000}\/ligolo_agent\.exe.{0,1000}","offensive_tool_keyword","ligolo","ligolo is a simple and lightweight tool for establishing SOCKS5 or TCP tunnels from a reverse connection in complete safety (TLS certificate with elliptical curve)","T1071 - T1021 - T1573","TA0011 - TA0002","N/A","AvosLocker - LockBit","C2","https://github.com/sysdream/ligolo","1","1","N/A","N/A","10","10","1764","224","2023-01-06T19:49:22Z","2020-05-22T07:58:13Z","8513" +"*/ligolo-ng*",".{0,1000}\/ligolo\-ng.{0,1000}","offensive_tool_keyword","ligolo","ligolo is a simple and lightweight tool for establishing SOCKS5 or TCP tunnels from a reverse connection in complete safety (TLS certificate with elliptical curve)","T1071 - T1021 - T1573","TA0011 - TA0002","N/A","AvosLocker - LockBit","C2","https://github.com/sysdream/ligolo","1","1","N/A","N/A","10","10","1764","224","2023-01-06T19:49:22Z","2020-05-22T07:58:13Z","8514" +"*/ligolo-ng.git*",".{0,1000}\/ligolo\-ng\.git.{0,1000}","offensive_tool_keyword","ligolo-ng","An advanced tunneling tool that uses TUN interfaces","T1572 - T1090","TA0011","N/A","Dispossessor - AvosLocker - LockBit","C2","https://github.com/nicocha30/ligolo-ng","1","1","N/A","N/A","10","10","3380","338","2025-04-17T07:48:36Z","2021-07-28T12:55:36Z","8515" +"*/ligolo-ng/releases*",".{0,1000}\/ligolo\-ng\/releases.{0,1000}","offensive_tool_keyword","ligolo-ng","An advanced tunneling tool that uses TUN interfaces","T1572 - T1090","TA0011","N/A","Dispossessor - AvosLocker - LockBit","C2","https://github.com/nicocha30/ligolo-ng","1","1","N/A","N/A","10","10","3380","338","2025-04-17T07:48:36Z","2021-07-28T12:55:36Z","8516" +"*/Lime-Crypter.git*",".{0,1000}\/Lime\-Crypter\.git.{0,1000}","offensive_tool_keyword","Lime-Crypter","An obfuscation tool for .Net + Native files","T1027 - T1045","TA0005 ","N/A","N/A","Defense Evasion","https://github.com/NYAN-x-CAT/Lime-Crypter","1","1","N/A","N/A","9","6","515","199","2024-04-22T21:31:18Z","2018-07-14T13:44:58Z","8519" +"*/Lime-RAT-*.zip*",".{0,1000}\/Lime\-RAT\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","Lime-RAT","remote administration tool for Windows (RAT)","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","APT-C-36 - Operation Comando","Malware","https://github.com/NYAN-x-CAT/Lime-RAT","1","1","N/A","N/A","10","10","1086","413","2019-06-24T17:05:48Z","2018-02-07T15:35:56Z","8520" +"*/LimeRAT.exe*",".{0,1000}\/LimeRAT\.exe.{0,1000}","offensive_tool_keyword","Lime-RAT","remote administration tool for Windows (RAT)","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","APT-C-36 - Operation Comando","Malware","https://github.com/NYAN-x-CAT/Lime-RAT","1","1","N/A","N/A","10","10","1086","413","2019-06-24T17:05:48Z","2018-02-07T15:35:56Z","8521" +"*/Lime-RAT.git*",".{0,1000}\/Lime\-RAT\.git.{0,1000}","offensive_tool_keyword","Lime-RAT","remote administration tool for Windows (RAT)","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","APT-C-36 - Operation Comando","Malware","https://github.com/NYAN-x-CAT/Lime-RAT","1","1","N/A","N/A","10","10","1086","413","2019-06-24T17:05:48Z","2018-02-07T15:35:56Z","8522" +"*/LimeRAT.v*.zip*",".{0,1000}\/LimeRAT\.v.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","Lime-RAT","remote administration tool for Windows (RAT)","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","APT-C-36 - Operation Comando","Malware","https://github.com/NYAN-x-CAT/Lime-RAT","1","1","N/A","N/A","10","10","1086","413","2019-06-24T17:05:48Z","2018-02-07T15:35:56Z","8523" +"*/Lime-RAT/releases/download/*",".{0,1000}\/Lime\-RAT\/releases\/download\/.{0,1000}","offensive_tool_keyword","Lime-RAT","remote administration tool for Windows (RAT)","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","APT-C-36 - Operation Comando","Malware","https://github.com/NYAN-x-CAT/Lime-RAT","1","1","N/A","N/A","10","10","1086","413","2019-06-24T17:05:48Z","2018-02-07T15:35:56Z","8524" +"*/LimeRAT-MUSIC.MP3*",".{0,1000}\/LimeRAT\-MUSIC\.MP3.{0,1000}","offensive_tool_keyword","Lime-RAT","remote administration tool for Windows (RAT)","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","APT-C-36 - Operation Comando","Malware","https://github.com/NYAN-x-CAT/Lime-RAT","1","1","N/A","N/A","10","10","1086","413","2019-06-24T17:05:48Z","2018-02-07T15:35:56Z","8525" +"*/LinEnum.git*",".{0,1000}\/LinEnum\.git.{0,1000}","offensive_tool_keyword","LinEnum","Scripted Local Linux Enumeration & Privilege Escalation Checks","T1046 - T1087.001 - T1057 - T1082 - T1016 - T1135 - T1049 - T1059.004 - T1007 - T1069.001 - T1083 - T1018","TA0007 - TA0009 - TA0002 - TA0003 - TA0001","N/A","N/A","Privilege Escalation","https://github.com/rebootuser/LinEnum","1","1","#linux","N/A","10","10","7309","2011","2023-09-06T18:02:29Z","2013-08-20T06:26:58Z","8526" +"*/LinEnum/*",".{0,1000}\/LinEnum\/.{0,1000}","offensive_tool_keyword","LinEnum","Scripted Local Linux Enumeration & Privilege Escalation Checks","T1046 - T1087.001 - T1057 - T1082 - T1016 - T1135 - T1049 - T1059.004 - T1007 - T1069.001 - T1083 - T1018","TA0007 - TA0009 - TA0002 - TA0003 - TA0001","N/A","N/A","Privilege Escalation","https://github.com/rebootuser/LinEnum","1","1","#linux","N/A","10","10","7309","2011","2023-09-06T18:02:29Z","2013-08-20T06:26:58Z","8527" +"*/linikatz.git*",".{0,1000}\/linikatz\.git.{0,1000}","offensive_tool_keyword","linikatz","linikatz is a tool to attack AD on UNIX","T1003.002 - T1558.003 - T1078 - T1550.001","TA0006 - TA0001 - TA0004 - TA0003","N/A","N/A","Exploitation tool","https://github.com/CiscoCXSecurity/linikatz","1","1","#linux","N/A","10","6","552","79","2023-10-19T17:01:47Z","2018-11-15T22:19:47Z","8528" +"*/LinikatzV2/*",".{0,1000}\/LinikatzV2\/.{0,1000}","offensive_tool_keyword","LinikatzV2","linikatz is a tool to attack AD on UNIX","T1003.002 - T1558.003 - T1078 - T1550.001","TA0006 - TA0001 - TA0004 - TA0003","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/LinikatzV2","1","1","#linux","N/A","10","2","146","15","2023-10-19T12:26:58Z","2023-10-19T11:07:53Z","8529" +"*/linpeas.sh*",".{0,1000}\/linpeas\.sh.{0,1000}","offensive_tool_keyword","D3m0n1z3dShell","Demonized Shell is an Advanced Tool for persistence in linux","T1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037","TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Persistence","https://github.com/MatheuZSecurity/D3m0n1z3dShell","1","1","#linux","N/A","10","4","373","54","2025-01-05T13:56:51Z","2023-05-30T02:30:47Z","8530" +"*/linpeas.sh*",".{0,1000}\/linpeas\.sh.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","8532" +"*/linpeas.sh*",".{0,1000}\/linpeas\.sh.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","8533" +"*/linpeas.txt*",".{0,1000}\/linpeas\.txt.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","8534" +"*/linux_stealth.py*",".{0,1000}\/linux_stealth\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","#linux","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","8541" +"*/linux-exploit-suggester.sh*",".{0,1000}\/linux\-exploit\-suggester\.sh.{0,1000}","offensive_tool_keyword","CDK","CDK is an open-sourced container penetration toolkit","T1610 - T1611 - T1203 - T1059.004 - T1564.004","TA0001 - TA0002 - TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/cdk-team/CDK","1","1","#linux","N/A","9","10","4164","566","2025-03-08T14:00:06Z","2020-11-05T09:18:51Z","8546" +"*/linux-pam-backdoor.git*",".{0,1000}\/linux\-pam\-backdoor\.git.{0,1000}","offensive_tool_keyword","linux-pam-backdoor","Linux PAM Backdoor","T1547.001 - T1556.003","TA0003 - TA0004","N/A","N/A","Persistence","https://github.com/zephrax/linux-pam-backdoor","1","1","#linux","N/A","10","4","328","85","2023-11-13T11:29:44Z","2017-06-08T21:14:34Z","8547" +"*/linuxprivchecker.git*",".{0,1000}\/linuxprivchecker\.git.{0,1000}","offensive_tool_keyword","linuxprivchecker","search for common privilege escalation vectors such as world writable files. misconfigurations. clear-text passwords and applicable exploits","T1210.001 - T1082 - T1088 - T1547.001","TA0002 - TA0004 - TA0006 - TA0007 - TA0008","N/A","N/A","Privilege Escalation","https://github.com/sleventyeleven/linuxprivchecker/blob/master/linuxprivchecker.py","1","1","#linux","N/A","7","10","1645","524","2022-01-31T10:32:08Z","2016-04-19T13:31:46Z","8548" +"*/linux-smart-enumeration.git*",".{0,1000}\/linux\-smart\-enumeration\.git.{0,1000}","offensive_tool_keyword","linux-smart-enumeration","Linux enumeration tool for privilege escalation and discovery","T1087.004 - T1016 - T1548.001 - T1046","TA0007 - TA0004 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/diego-treitos/linux-smart-enumeration","1","1","#linux","N/A","9","10","3575","584","2023-12-25T14:46:47Z","2019-02-13T11:02:21Z","8549" +"*/linWinPwn*",".{0,1000}\/linWinPwn.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","8550" +"*/ListAllUsers.ps1*",".{0,1000}\/ListAllUsers\.ps1.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8551" +"*/ListLogged-inUsers.ps1*",".{0,1000}\/ListLogged\-inUsers\.ps1.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8552" +"*/listProxyPool?k=*",".{0,1000}\/listProxyPool\?k\=.{0,1000}","offensive_tool_keyword","SecScanC2","SecScanC2 can manage assetment to create P2P network for security scanning & C2. The tool can assist security researchers in conducting penetration testing more efficiently - preventing scanning from being blocked - protecting themselves from being traced.","T1021 - T1090","TA0011 - TA0002 - TA0040 - TA0043","N/A","N/A","C2","https://github.com/T1esh0u/SecScanC2","1","1","#P2P","N/A","10","10","N/A","N/A","N/A","N/A","8553" +"*/ListRDPConnections.exe*",".{0,1000}\/ListRDPConnections\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8554" +"*/Liz0ziM Private Safe Mode Command Execuriton Bypass Exploit.php*",".{0,1000}\/Liz0ziM\sPrivate\sSafe\sMode\sCommand\sExecuriton\sBypass\sExploit\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","8555" +"*/llmnr-resolve.nse*",".{0,1000}\/llmnr\-resolve\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8556" +"*/lltd-discovery.nse*",".{0,1000}\/lltd\-discovery\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8557" +"*/lnk2pwn.git*",".{0,1000}\/lnk2pwn\.git.{0,1000}","offensive_tool_keyword","lnk2pwn","Malicious Shortcut(.lnk) Generator","T1204 - T1059.007","TA0001 - TA0002","N/A","N/A","Phishing","https://github.com/it-gorillaz/lnk2pwn","1","1","N/A","N/A","8","2","193","34","2018-11-23T17:18:49Z","2018-11-23T00:12:48Z","8560" +"*/lnk2pwn-1.0.0.zip*",".{0,1000}\/lnk2pwn\-1\.0\.0\.zip.{0,1000}","offensive_tool_keyword","lnk2pwn","Malicious Shortcut(.lnk) Generator","T1204 - T1059.007","TA0001 - TA0002","N/A","N/A","Phishing","https://github.com/it-gorillaz/lnk2pwn","1","1","N/A","N/A","8","2","193","34","2018-11-23T17:18:49Z","2018-11-23T00:12:48Z","8561" +"*/lnkbomb.git*",".{0,1000}\/lnkbomb\.git.{0,1000}","offensive_tool_keyword","lnkbomb","Malicious shortcut generator for collecting NTLM hashes from insecure file shares.","T1023.003 - T1557.002 - T1046","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/dievus/lnkbomb","1","1","N/A","N/A","10","4","327","58","2024-10-22T17:51:10Z","2022-01-03T04:17:11Z","8562" +"*/lnkbomb.py*",".{0,1000}\/lnkbomb\.py.{0,1000}","offensive_tool_keyword","lnkbomb","Malicious shortcut generator for collecting NTLM hashes from insecure file shares.","T1023.003 - T1557.002 - T1046","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/dievus/lnkbomb","1","1","N/A","N/A","10","4","327","58","2024-10-22T17:51:10Z","2022-01-03T04:17:11Z","8563" +"*/LNKUp.git*",".{0,1000}\/LNKUp\.git.{0,1000}","offensive_tool_keyword","LNKUp","Generates malicious LNK file payloads for data exfiltration","T1023.003 - T1048 - T1041 - T1204","TA0010","N/A","N/A","Data Exfiltration","https://github.com/Plazmaz/LNKUp","1","1","N/A","N/A","10","4","384","54","2017-08-21T22:58:13Z","2017-08-09T16:18:07Z","8564" +"*/LNKUp/generate.py*",".{0,1000}\/LNKUp\/generate\.py.{0,1000}","offensive_tool_keyword","LNKUp","Generates malicious LNK file payloads for data exfiltration","T1023.003 - T1048 - T1041 - T1204","TA0010","N/A","N/A","Data Exfiltration","https://github.com/Plazmaz/LNKUp","1","1","N/A","N/A","10","4","384","54","2017-08-21T22:58:13Z","2017-08-09T16:18:07Z","8565" +"*/load_ssp.x64.exe*",".{0,1000}\/load_ssp\.x64\.exe.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","8566" +"*/load-assembly.py*",".{0,1000}\/load\-assembly\.py.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","8567" +"*/loadbalancer.py*",".{0,1000}\/loadbalancer\.py.{0,1000}","offensive_tool_keyword","quiet-riot","Unauthenticated enumeration of AWS - Azure and GCP Principals","T1087 - T1083 - T1210","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/righteousgambit/quiet-riot","1","1","N/A","N/A","6","3","224","30","2024-11-13T19:41:26Z","2021-10-28T15:12:27Z","8568" +"*/LoadDllRemote.cs*",".{0,1000}\/LoadDllRemote\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","8569" +"*/loader/bypass.c",".{0,1000}\/loader\/bypass\.c","offensive_tool_keyword","donut","Donut is a position-independent code that enables in-memory execution of VBScript. JScript. EXE. DLL files and dotNET assemblies. A module created by Donut can either be staged from a HTTP server or embedded directly in the loader itself","T1071.001 - T1059 - T1059.001 - T1059.005 - T1059.006 - T1059.007 - T1562.001 - T1070 - T1105 - T1106 - T1027 - T1027.002 - T1057 - T1055 - T1620","TA0011 - TA0002 - TA0005 - TA0008 - TA0004 - TA0007 - TA0003 - TA0006 - TA0010","N/A","Indrik Spider","Exploitation tool","https://github.com/TheWover/donut","1","1","N/A","N/A","N/A","10","3882","667","2024-10-23T12:19:13Z","2019-03-27T23:24:44Z","8570" +"*/loader/bypass.h",".{0,1000}\/loader\/bypass\.h","offensive_tool_keyword","donut","Donut is a position-independent code that enables in-memory execution of VBScript. JScript. EXE. DLL files and dotNET assemblies. A module created by Donut can either be staged from a HTTP server or embedded directly in the loader itself","T1071.001 - T1059 - T1059.001 - T1059.005 - T1059.006 - T1059.007 - T1562.001 - T1070 - T1105 - T1106 - T1027 - T1027.002 - T1057 - T1055 - T1620","TA0011 - TA0002 - TA0005 - TA0008 - TA0004 - TA0007 - TA0003 - TA0006 - TA0010","N/A","Indrik Spider","Exploitation tool","https://github.com/TheWover/donut","1","1","N/A","N/A","N/A","10","3882","667","2024-10-23T12:19:13Z","2019-03-27T23:24:44Z","8571" +"*/loader/x64/Release/loader.exe*",".{0,1000}\/loader\/x64\/Release\/loader\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","A protective and Low Level Shellcode Loader that defeats modern EDR systems.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/cribdragg3r/Alaris","1","1","N/A","N/A","10","10","903","142","2024-03-20T15:50:57Z","2020-02-22T15:42:37Z","8572" +"*/loadercrypt_*.php*",".{0,1000}\/loadercrypt_.{0,1000}\.php.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","8573" +"*/LoaderMemoryModule_x64_Release.exe*",".{0,1000}\/LoaderMemoryModule_x64_Release\.exe.{0,1000}","offensive_tool_keyword","Tsunami","another C2 framework","T1573 - T1027 - T1059 - T1071 ","TA0011 - TA0009 - TA0003 - TA0007 - TA0008","N/A","N/A","C2","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","8574" +"*/LoadLibrary_x64_Release.exe*",".{0,1000}\/LoadLibrary_x64_Release\.exe.{0,1000}","offensive_tool_keyword","Tsunami","another C2 framework","T1573 - T1027 - T1059 - T1071 ","TA0011 - TA0009 - TA0003 - TA0007 - TA0008","N/A","N/A","C2","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","8575" +"*/local_execution_linux.exe*",".{0,1000}\/local_execution_linux\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","8576" +"*/local_map.exe*",".{0,1000}\/local_map\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","8578" +"*/local_thread_hijacking.exe*",".{0,1000}\/local_thread_hijacking\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","8579" +"*/LocalAdminSharp.git*",".{0,1000}\/LocalAdminSharp\.git.{0,1000}","offensive_tool_keyword","LocalAdminSharp",".NET executable to use when dealing with privilege escalation on Windows to gain local administrator access","T1055.011 - T1068 - T1548.002 - T1548.003 - T1548.004","TA0004","N/A","N/A","Privilege Escalation","https://github.com/notdodo/LocalAdminSharp","1","1","N/A","N/A","10","2","157","17","2022-11-01T17:45:43Z","2022-01-01T10:35:09Z","8580" +"*/LocalAdminSharp.sln*",".{0,1000}\/LocalAdminSharp\.sln.{0,1000}","offensive_tool_keyword","LocalAdminSharp",".NET executable to use when dealing with privilege escalation on Windows to gain local administrator access","T1055.011 - T1068 - T1548.002 - T1548.003 - T1548.004","TA0004","N/A","N/A","Privilege Escalation","https://github.com/notdodo/LocalAdminSharp","1","1","N/A","N/A","10","2","157","17","2022-11-01T17:45:43Z","2022-01-01T10:35:09Z","8581" +"*/localbrute.ps1*",".{0,1000}\/localbrute\.ps1.{0,1000}","offensive_tool_keyword","Minimalistic-offensive","A repository of tools for pentesting of restricted and isolated environments.","T1110 - T1046 - T1021 - T1203 - T1485","TA0006 - TA0007 - TA0008","N/A","Dispossessor","Discovery","https://github.com/InfosecMatter/Minimalistic-offensive-security-tools","1","1","N/A","N/A","7","6","562","121","2021-10-26T11:04:46Z","2020-05-10T17:40:31Z","8582" +"*/localbrute-extra-mini.ps1*",".{0,1000}\/localbrute\-extra\-mini\.ps1.{0,1000}","offensive_tool_keyword","Minimalistic-offensive","A repository of tools for pentesting of restricted and isolated environments.","T1110 - T1046 - T1021 - T1203 - T1485","TA0006 - TA0007 - TA0008","N/A","Dispossessor","Credential Access","https://github.com/InfosecMatter/Minimalistic-offensive-security-tools","1","1","N/A","N/A","7","6","562","121","2021-10-26T11:04:46Z","2020-05-10T17:40:31Z","8583" +"*/local-exploits/master/CVE*",".{0,1000}\/local\-exploits\/master\/CVE.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","8584" +"*/LocalPotato.git*",".{0,1000}\/LocalPotato\.git.{0,1000}","offensive_tool_keyword","localpotato","The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.","T1550.002 - T1078.003 - T1005 - T1070.004","TA0004 - TA0006 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/decoder-it/LocalPotato","1","1","N/A","N/A","10","7","691","92","2023-11-07T01:09:08Z","2023-01-04T18:22:29Z","8585" +"*/LocalPrivEsc/*",".{0,1000}\/LocalPrivEsc\/.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","8586" +"*/localroot/2.6.x/elflbl*",".{0,1000}\/localroot\/2\.6\.x\/elflbl.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","8587" +"*/localroot/2.6.x/h00lyshit*",".{0,1000}\/localroot\/2\.6\.x\/h00lyshit.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","8588" +"*/LocalShellExtParse.git*",".{0,1000}\/LocalShellExtParse\.git.{0,1000}","offensive_tool_keyword","LocalShellExtParse","Script to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User.","T1547.009 - T1129","TA0003 - TA0007","N/A","N/A","Discovery","https://github.com/herrcore/LocalShellExtParse","1","1","N/A","N/A","9","1","20","4","2015-06-08T16:55:38Z","2015-06-05T03:23:13Z","8589" +"*/LocalShellExtParse.py*",".{0,1000}\/LocalShellExtParse\.py.{0,1000}","offensive_tool_keyword","LocalShellExtParse","Script to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User.","T1547.009 - T1129","TA0003 - TA0007","N/A","N/A","Discovery","https://github.com/herrcore/LocalShellExtParse","1","1","N/A","N/A","9","1","20","4","2015-06-08T16:55:38Z","2015-06-05T03:23:13Z","8590" +"*/localtonet.dll*",".{0,1000}\/localtonet\.dll.{0,1000}","offensive_tool_keyword","localtonet","LocaltoNet is a reverse proxy that enables you to expose your localhost services to the internet","T1090 - T1102 - T1071 - T1105","TA0010 - TA0011 - TA0009 - TA0003 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/engineseller/localtonet","1","1","N/A","N/A","10","1","6","4","2022-01-31T03:19:25Z","2022-01-31T03:17:18Z","8591" +"*/localtonet.exe*",".{0,1000}\/localtonet\.exe.{0,1000}","offensive_tool_keyword","localtonet","LocaltoNet is a reverse proxy that enables you to expose your localhost services to the internet","T1090 - T1102 - T1071 - T1105","TA0010 - TA0011 - TA0009 - TA0003 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/engineseller/localtonet","1","1","N/A","N/A","10","1","6","4","2022-01-31T03:19:25Z","2022-01-31T03:17:18Z","8592" +"*/localtonet.git*",".{0,1000}\/localtonet\.git.{0,1000}","offensive_tool_keyword","localtonet","LocaltoNet is a reverse proxy that enables you to expose your localhost services to the internet","T1090 - T1102 - T1071 - T1105","TA0010 - TA0011 - TA0009 - TA0003 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/engineseller/localtonet","1","1","N/A","N/A","10","1","6","4","2022-01-31T03:19:25Z","2022-01-31T03:17:18Z","8593" +"*/localtonet-win*",".{0,1000}\/localtonet\-win.{0,1000}","offensive_tool_keyword","localtonet","LocaltoNet is a reverse proxy that enables you to expose your localhost services to the internet","T1090 - T1102 - T1071 - T1105","TA0010 - TA0011 - TA0009 - TA0003 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/engineseller/localtonet","1","1","N/A","N/A","10","1","6","4","2022-01-31T03:19:25Z","2022-01-31T03:17:18Z","8595" +"*/LockLess.exe*",".{0,1000}\/LockLess\.exe.{0,1000}","offensive_tool_keyword","Lockless","Lockless allows for the copying of locked files.","T1074 - T1020 - T1055","TA0009 - TA0010 - TA0005","N/A","N/A","Defense Evasion","https://github.com/GhostPack/Lockless","1","1","N/A","N/A","8","3","245","57","2021-04-30T17:51:41Z","2020-03-28T20:57:25Z","8601" +"*/LockLess.exe*",".{0,1000}\/LockLess\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","8602" +"*/LockLess.exe*",".{0,1000}\/LockLess\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","8603" +"*/Lockless.git*",".{0,1000}\/Lockless\.git.{0,1000}","offensive_tool_keyword","Lockless","Lockless allows for the copying of locked files.","T1074 - T1020 - T1055","TA0009 - TA0010 - TA0005","N/A","N/A","Defense Evasion","https://github.com/GhostPack/Lockless","1","1","N/A","N/A","8","3","245","57","2021-04-30T17:51:41Z","2020-03-28T20:57:25Z","8604" +"*/Locksmith.git*",".{0,1000}\/Locksmith\.git.{0,1000}","offensive_tool_keyword","Locksmith","A tiny tool to identify and remediate common misconfigurations in Active Directory Certificate Services","T1552.006 - T1222 - T1046","TA0007 - TA0040 - TA0043","N/A","N/A","Discovery","https://github.com/TrimarcJake/Locksmith","1","1","N/A","N/A","8","10","1086","100","2025-04-21T12:43:50Z","2022-04-28T01:37:32Z","8605" +"*/log4shell.py*",".{0,1000}\/log4shell\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","8610" +"*/login/e1837f4d-1d0c-49b8-a242-8f653226c137*",".{0,1000}\/login\/e1837f4d\-1d0c\-49b8\-a242\-8f653226c137.{0,1000}","offensive_tool_keyword","evilginx2","Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication","T1557.002 - T1114 - T1539","TA0001","N/A","BlackCat - COLDRIVER","Phishing","https://github.com/kgretzky/evilginx2","1","1","N/A","N/A","10","10","12879","2234","2025-01-21T15:16:19Z","2018-07-10T09:59:52Z","8611" +"*/login-securite/DonPAPI*",".{0,1000}\/login\-securite\/DonPAPI.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","8614" +"*/logon_backdoor.git*",".{0,1000}\/logon_backdoor\.git.{0,1000}","offensive_tool_keyword","logon_backdoor","automated sticky keys backdoor","T1174 - T1078 - T1546.013","TA0003","N/A","N/A","Persistence","https://github.com/szymon1118/logon_backdoor","1","1","N/A","N/A","6","1","10","4","2016-02-12T11:42:59Z","2016-02-10T22:38:46Z","8615" +"*/logonuifox.dll*",".{0,1000}\/logonuifox\.dll.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","1","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","8616" +"*/logs/*/becon_*.log",".{0,1000}\/logs\/.{0,1000}\/becon_.{0,1000}\.log","offensive_tool_keyword","cobaltstrike","Cobaltstrike toolkit","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/1135/1135-CobaltStrike-ToolKit","1","1","#logfile #linux","N/A","10","10","150","35","2023-12-01T03:18:35Z","2019-02-22T09:36:44Z","8617" +"*/logs/beacon_log*",".{0,1000}\/logs\/beacon_log.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","8618" +"*/lolbin.exe*",".{0,1000}\/lolbin\.exe.{0,1000}","offensive_tool_keyword","LOLSpoof","An interactive shell to spoof some LOLBins command line","T1036.005","TA0005","N/A","N/A","Defense Evasion","https://github.com/itaymigdal/LOLSpoof","1","1","N/A","N/A","8","2","184","24","2024-01-27T05:43:59Z","2024-01-16T20:15:38Z","8620" +"*/lolminer.exe*",".{0,1000}\/lolminer\.exe.{0,1000}","offensive_tool_keyword","lolminer","NVIDIA+AMD GPU Miner","T1496","TA0040","N/A","N/A","Cryptomining","https://github.com/Lolliedieb/lolMiner-releases","1","1","N/A","N/A","9","10","2781","601","2025-02-01T20:03:57Z","2018-10-27T20:35:03Z","8621" +"*/lolMiner_v*_Win64.zip*",".{0,1000}\/lolMiner_v.{0,1000}_Win64\.zip.{0,1000}","offensive_tool_keyword","lolminer","NVIDIA+AMD GPU Miner","T1496","TA0040","N/A","N/A","Cryptomining","https://github.com/Lolliedieb/lolMiner-releases","1","1","N/A","N/A","9","10","2781","601","2025-02-01T20:03:57Z","2018-10-27T20:35:03Z","8622" +"*/lolMinerGUI.exe*",".{0,1000}\/lolMinerGUI\.exe.{0,1000}","offensive_tool_keyword","lolminer","NVIDIA+AMD GPU Miner","T1496","TA0040","N/A","N/A","Cryptomining","https://github.com/Lolliedieb/lolMiner-releases","1","1","N/A","N/A","9","10","2781","601","2025-02-01T20:03:57Z","2018-10-27T20:35:03Z","8623" +"*/LOLSpoof.git*",".{0,1000}\/LOLSpoof\.git.{0,1000}","offensive_tool_keyword","LOLSpoof","An interactive shell to spoof some LOLBins command line","T1036.005","TA0005","N/A","N/A","Defense Evasion","https://github.com/itaymigdal/LOLSpoof","1","1","N/A","N/A","8","2","184","24","2024-01-27T05:43:59Z","2024-01-16T20:15:38Z","8624" +"*/LOLSpoof.nim*",".{0,1000}\/LOLSpoof\.nim.{0,1000}","offensive_tool_keyword","LOLSpoof","An interactive shell to spoof some LOLBins command line","T1036.005","TA0005","N/A","N/A","Defense Evasion","https://github.com/itaymigdal/LOLSpoof","1","1","N/A","N/A","8","2","184","24","2024-01-27T05:43:59Z","2024-01-16T20:15:38Z","8625" +"*/LOLSpoof/releases/download/*",".{0,1000}\/LOLSpoof\/releases\/download\/.{0,1000}","offensive_tool_keyword","LOLSpoof","An interactive shell to spoof some LOLBins command line","T1036.005","TA0005","N/A","N/A","Defense Evasion","https://github.com/itaymigdal/LOLSpoof","1","1","N/A","N/A","8","2","184","24","2024-01-27T05:43:59Z","2024-01-16T20:15:38Z","8626" +"*/lookupsid.py*",".{0,1000}\/lookupsid\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","8627" +"*/lookupsid.py*",".{0,1000}\/lookupsid\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","8628" +"*/LooneyPwner.git*",".{0,1000}\/LooneyPwner\.git.{0,1000}","offensive_tool_keyword","POC","Exploit tool for CVE-2023-4911 targeting the 'Looney Tunables' glibc vulnerability in various Linux distributions.","T1068 - T1210 - T1555","TA0001 - TA0003 - TA0005","N/A","N/A","Exploitation tool","https://github.com/chaudharyarjun/LooneyPwner","1","1","#linux","N/A","10","1","38","12","2023-10-18T04:59:50Z","2023-10-17T07:44:16Z","8629" +"*/looneypwner.sh*",".{0,1000}\/looneypwner\.sh.{0,1000}","offensive_tool_keyword","POC","Exploit tool for CVE-2023-4911 targeting the 'Looney Tunables' glibc vulnerability in various Linux distributions.","T1068 - T1210 - T1555","TA0001 - TA0003 - TA0005","N/A","N/A","Exploitation tool","https://github.com/chaudharyarjun/LooneyPwner","1","1","#linux","N/A","10","1","38","12","2023-10-18T04:59:50Z","2023-10-17T07:44:16Z","8630" +"*/loot_default/*.exe*",".{0,1000}\/loot_default\/.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","8631" +"*/loot_default/*.ps1*",".{0,1000}\/loot_default\/.{0,1000}\.ps1.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","8632" +"*/loot_default/*.py*",".{0,1000}\/loot_default\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","8633" +"*/loot_finder*",".{0,1000}\/loot_finder.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","8634" +"*/lpBunny/bof-registry*",".{0,1000}\/lpBunny\/bof\-registry.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike beacon object file that allows you to query and make changes to the Windows Registry","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ausecwa/bof-registry","1","1","N/A","N/A","10","10","27","8","2021-02-11T04:38:28Z","2021-01-29T05:07:47Z","8635" +"*/LPE_Reflect_Elevate.x64.dll*",".{0,1000}\/LPE_Reflect_Elevate\.x64\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8636" +"*/lsa_dump_*.txt*",".{0,1000}\/lsa_dump_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","8637" +"*/lsadump.py*",".{0,1000}\/lsadump\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","8638" +"*/lsarelayx.git*",".{0,1000}\/lsarelayx\.git.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","1","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","8639" +"*/lsasecrets.py*",".{0,1000}\/lsasecrets\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","8640" +"*/lsass.DMP*",".{0,1000}\/lsass\.DMP.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","8641" +"*/lsass.rar*",".{0,1000}\/lsass\.rar.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","1","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","8642" +"*/lsass.zip*",".{0,1000}\/lsass\.zip.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","1","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","8643" +"*/lsass/beacon.h*",".{0,1000}\/lsass\/beacon\.h.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of CobaltStrike beacon object files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/pwn1sher/CS-BOFs","1","1","N/A","N/A","10","10","103","22","2022-02-14T09:47:30Z","2021-01-18T08:54:48Z","8644" +"*/Lsass_Shtinkering.cpp*",".{0,1000}\/Lsass_Shtinkering\.cpp.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","1","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","8645" +"*/Lsass_Shtinkering.exe*",".{0,1000}\/Lsass_Shtinkering\.exe.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","1","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","8646" +"*/lsass64.exe*",".{0,1000}\/lsass64\.exe.{0,1000}","offensive_tool_keyword","lslsass","dump active logon session password hashes from the lsass process (old tool for vista and older)","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","8647" +"*/LSASSProtectionBypass/CredGuard.c*",".{0,1000}\/LSASSProtectionBypass\/CredGuard\.c.{0,1000}","offensive_tool_keyword","EDRSandblast-GodFault","Integrates GodFault into EDR Sandblast achieving the same result without the use of any vulnerable drivers.","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/gabriellandau/EDRSandblast-GodFault","1","1","N/A","N/A","10","3","260","48","2023-08-28T18:14:20Z","2023-06-01T19:32:09Z","8648" +"*/LsassReflectDumping.git*",".{0,1000}\/LsassReflectDumping\.git.{0,1000}","offensive_tool_keyword","LsassReflectDumping","leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process","T1003.001 - T1555.003 - T1077","TA0006","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/LsassReflectDumping","1","1","N/A","N/A","10","2","198","27","2024-10-19T08:16:13Z","2024-10-17T14:57:30Z","8649" +"*/Lsass-Shtinkering.git*",".{0,1000}\/Lsass\-Shtinkering\.git.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","1","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","8650" +"*/LsassSilentProcessExit.git*",".{0,1000}\/LsassSilentProcessExit\.git.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","1","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","8651" +"*/Lsassx.git*",".{0,1000}\/Lsassx\.git.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","1","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","8652" +"*/Lsassx.ps1*",".{0,1000}\/Lsassx\.ps1.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","1","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","8653" +"*/Lsassx-OBF.ps1*",".{0,1000}\/Lsassx\-OBF\.ps1.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","1","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","8654" +"*/lsassy*",".{0,1000}\/lsassy.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","8655" +"*/lsassy/releases/download/*",".{0,1000}\/lsassy\/releases\/download\/.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","8656" +"*/lsassy_dump.py*",".{0,1000}\/lsassy_dump\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","8657" +"*/lucksec/CVE-2022-0847*",".{0,1000}\/lucksec\/CVE\-2022\-0847.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/lucksec/CVE-2022-0847","1","1","N/A","N/A","N/A","1","1","3","2022-03-08T01:50:39Z","2022-03-08T01:17:09Z","8661" +"*/lu-enum.nse*",".{0,1000}\/lu\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8662" +"*/luijait/arpspoofing*",".{0,1000}\/luijait\/arpspoofing.{0,1000}","offensive_tool_keyword","arpspoofing","arp spoofing scripts","T1595","TA0001","N/A","N/A","Sniffing & Spoofing","https://github.com/luijait/arpspoofing","1","1","N/A","network exploitation tool","N/A","1","21","1","2022-03-10T04:44:36Z","2021-06-29T22:57:51Z","8663" +"*/Luna-Grabber.git*",".{0,1000}\/Luna\-Grabber\.git.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","8665" +"*/Luna-Grabber/releases/download/*",".{0,1000}\/Luna\-Grabber\/releases\/download\/.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","8666" +"*/Luna-Grabber/tarball/*",".{0,1000}\/Luna\-Grabber\/tarball\/.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","8667" +"*/Luna-Grabber/zipball*",".{0,1000}\/Luna\-Grabber\/zipball.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","8668" +"*/Luna-Grabber-Injection/main*",".{0,1000}\/Luna\-Grabber\-Injection\/main.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","8669" +"*/ly4k/Pachine*",".{0,1000}\/ly4k\/Pachine.{0,1000}","offensive_tool_keyword","Pachine","Python implementation for CVE-2021-42278 (Active Directory Privilege Escalation)","T1068 - T1078 - T1059.006","TA0003 - TA0004 - TA0002","N/A","Black Basta","Privilege Escalation","https://github.com/ly4k/Pachine","1","1","N/A","N/A","8","3","275","37","2022-01-13T12:35:19Z","2021-12-13T23:15:05Z","8670" +"*/lyncsmash/*",".{0,1000}\/lyncsmash\/.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","8671" +"*/LyncSniper.ps1*",".{0,1000}\/LyncSniper\.ps1.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","1","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","8672" +"*/m365-fatigue.git*",".{0,1000}\/m365\-fatigue\.git.{0,1000}","offensive_tool_keyword","m365-fatigue","automates the authentication process for Microsoft 365 by using the device code flow and Selenium for automated login. It keeps bombing the user with MFA requests and stores the access_token once the MFA was approved.","T1110.001 - T1078.001 - T1556.004","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/0xB455/m365-fatigue","1","1","N/A","N/A","10","1","77","7","2024-04-08T14:53:44Z","2023-11-30T13:33:03Z","8674" +"*/m365-fatigue.py*",".{0,1000}\/m365\-fatigue\.py.{0,1000}","offensive_tool_keyword","m365-fatigue","automates the authentication process for Microsoft 365 by using the device code flow and Selenium for automated login. It keeps bombing the user with MFA requests and stores the access_token once the MFA was approved.","T1110.001 - T1078.001 - T1556.004","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/0xB455/m365-fatigue","1","1","N/A","N/A","10","1","77","7","2024-04-08T14:53:44Z","2023-11-30T13:33:03Z","8675" +"*/MAAD-AF.git*",".{0,1000}\/MAAD\-AF\.git.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","8677" +"*/MaccaroniC2*",".{0,1000}\/MaccaroniC2.{0,1000}","offensive_tool_keyword","MaccaroniC2","A proof-of-concept Command & Control framework that utilizes the powerful AsyncSSH Python library which provides an asynchronous client and server implementation of the SSHv2 protocol and use PyNgrok wrapper for ngrok integration.","T1090 - T1059.003","TA0011 - TA0002","N/A","N/A","C2","https://github.com/CalfCrusher/MaccaroniC2","1","1","N/A","N/A","10","10","76","16","2023-06-27T17:43:59Z","2023-05-21T13:33:48Z","8678" +"*/MaceTrap.exe*",".{0,1000}\/MaceTrap\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","8679" +"*/machine_role.py*",".{0,1000}\/machine_role\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","8680" +"*/Macker's Private PHPShell.php*",".{0,1000}\/Macker\'s\sPrivate\sPHPShell\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","8681" +"*/macro_pack.exe*",".{0,1000}\/macro_pack\.exe.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","8682" +"*/macro_pack.git*",".{0,1000}\/macro_pack\.git.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","8683" +"*/macro_pack.py",".{0,1000}\/macro_pack\.py","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","8684" +"*/macro_pack/releases/download/*",".{0,1000}\/macro_pack\/releases\/download\/.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","8685" +"*/MacroPatterns.cs*",".{0,1000}\/MacroPatterns\.cs.{0,1000}","offensive_tool_keyword","Macrome","An Excel Macro Document Reader/Writer for Red Teamers & Analysts. Blog posts describing what this tool actually does can be found https://malware.pizza/2020/05/12/evading-av-with-excel-macros-and-biff8-xls/ and https://malware.pizza/2020/06/19/further-evasion-in-the-forgotten-corners-of-ms-xls/","T1140","TA0005","N/A","N/A","Exploitation tool","https://github.com/michaelweber/Macrome","1","1","N/A","N/A","N/A","6","520","79","2022-02-01T16:26:13Z","2020-05-07T22:44:11Z","8687" +"*/Macro-Payloads.py*",".{0,1000}\/Macro\-Payloads\.py.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","8688" +"*/MacroWord_Payload/macro.txt*",".{0,1000}\/MacroWord_Payload\/macro\.txt.{0,1000}","offensive_tool_keyword","Mystikal","macOS Initial Access Payload Generator","T1059.005 - T1204.002 - T1566.001","TA0002 - TA0001","N/A","N/A","Exploitation tool","https://github.com/D00MFist/Mystikal","1","1","N/A","N/A","9","4","305","39","2024-01-10T15:48:12Z","2021-05-03T14:46:16Z","8689" +"*/magnitude.profile*",".{0,1000}\/magnitude\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","8690" +"*/mailpv.exe*",".{0,1000}\/mailpv\.exe.{0,1000}","offensive_tool_keyword","MailPassView","Mail PassView is a small password-recovery tool that reveals the passwords and other account details for multiple email clients","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - Kimsuky - Evilnum - XDSpy","Credential Access","https://www.nirsoft.net/utils/mailpv.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","8691" +"*/MailRaider.ps1*",".{0,1000}\/MailRaider\.ps1.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","8692" +"*/MailRaider.ps1*",".{0,1000}\/MailRaider\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1129","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","8693" +"*/MailSniper/*",".{0,1000}\/MailSniper\/.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","8694" +"*/main/cve-2022-0847.c*",".{0,1000}\/main\/cve\-2022\-0847\.c.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","t1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/bbaranoff/CVE-2022-0847","1","1","N/A","N/A","N/A","1","49","25","2022-03-07T15:52:23Z","2022-03-07T15:50:18Z","8695" +"*/main/exploit.js",".{0,1000}\/main\/exploit\.js","offensive_tool_keyword","POC","Adobe Acrobat Reader - CVE-2023-21608 - Remote Code Execution Exploit ","T1203 - T1218 - T1059 - T1064 - T1204","TA0001 - TA0002","N/A","N/A","Exploitation tool","https://github.com/hacksysteam/CVE-2023-21608","1","1","N/A","N/A","N/A","3","272","58","2023-12-05T12:21:02Z","2023-01-30T12:57:48Z","8696" +"*/main/exploit.pdf",".{0,1000}\/main\/exploit\.pdf","offensive_tool_keyword","POC","Adobe Acrobat Reader - CVE-2023-21608 - Remote Code Execution Exploit ","T1203 - T1218 - T1059 - T1064 - T1204","TA0001 - TA0002","N/A","N/A","Exploitation tool","https://github.com/hacksysteam/CVE-2023-21608","1","1","N/A","N/A","N/A","3","272","58","2023-12-05T12:21:02Z","2023-01-30T12:57:48Z","8697" +"*/MakeMeAdmin * x64.msi*",".{0,1000}\/MakeMeAdmin\s.{0,1000}\sx64\.msi.{0,1000}","offensive_tool_keyword","MakeMeAdmin","Enables users to elevate themselves to administrator-level rights","T1078 - T1059 - T1087","TA0004","N/A","N/A","Privilege Escalation","https://github.com/pseymour/MakeMeAdmin","1","1","N/A","N/A","9","5","430","94","2024-12-22T02:56:23Z","2018-05-29T19:42:58Z","8699" +"*/MakeMeAdmin.git*",".{0,1000}\/MakeMeAdmin\.git.{0,1000}","offensive_tool_keyword","MakeMeAdmin","Enables users to elevate themselves to administrator-level rights","T1078 - T1059 - T1087","TA0004","N/A","N/A","Privilege Escalation","https://github.com/pseymour/MakeMeAdmin","1","1","N/A","N/A","9","5","430","94","2024-12-22T02:56:23Z","2018-05-29T19:42:58Z","8700" +"*/MakeMeAdmin/tarball*",".{0,1000}\/MakeMeAdmin\/tarball.{0,1000}","offensive_tool_keyword","MakeMeAdmin","Enables users to elevate themselves to administrator-level rights","T1078 - T1059 - T1087","TA0004","N/A","N/A","Privilege Escalation","https://github.com/pseymour/MakeMeAdmin","1","1","N/A","N/A","9","5","430","94","2024-12-22T02:56:23Z","2018-05-29T19:42:58Z","8701" +"*/MakeMeAdmin/tree/v*/Installers*",".{0,1000}\/MakeMeAdmin\/tree\/v.{0,1000}\/Installers.{0,1000}","offensive_tool_keyword","MakeMeAdmin","Enables users to elevate themselves to administrator-level rights","T1078 - T1059 - T1087","TA0004","N/A","N/A","Privilege Escalation","https://github.com/pseymour/MakeMeAdmin","1","1","N/A","N/A","9","5","430","94","2024-12-22T02:56:23Z","2018-05-29T19:42:58Z","8702" +"*/MakeMeAdmin/zipball*",".{0,1000}\/MakeMeAdmin\/zipball.{0,1000}","offensive_tool_keyword","MakeMeAdmin","Enables users to elevate themselves to administrator-level rights","T1078 - T1059 - T1087","TA0004","N/A","N/A","Privilege Escalation","https://github.com/pseymour/MakeMeAdmin","1","1","N/A","N/A","9","5","430","94","2024-12-22T02:56:23Z","2018-05-29T19:42:58Z","8703" +"*/MakeMeEnterpriseAdmin.ps1*",".{0,1000}\/MakeMeEnterpriseAdmin\.ps1.{0,1000}","offensive_tool_keyword","KrbRelayUp","a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).","T1558 - T1210","TA0004 - TA0003","N/A","Dispossessor - Back Basta","Privilege Escalation","https://github.com/Dec0ne/KrbRelayUp","1","1","N/A","N/A","10","10","1580","209","2022-08-06T12:23:58Z","2022-04-24T21:33:00Z","8704" +"*/MakeMeEnterpriseAdmin.ps1*",".{0,1000}\/MakeMeEnterpriseAdmin\.ps1.{0,1000}","offensive_tool_keyword","S4UTomato","Escalate Service Account To LocalSystem via Kerberos","T1558 - T1558.002 - T1548.002 - T1078 - T1078.004","TA0006 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/wh0amitz/S4UTomato","1","1","N/A","N/A","10","4","394","76","2023-09-14T08:53:19Z","2023-07-30T11:51:57Z","8705" +"*/MakeMeEnterpriseAdmin.ps1*",".{0,1000}\/MakeMeEnterpriseAdmin\.ps1.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","8706" +"*/malDll.dll*",".{0,1000}\/malDll\.dll.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","8707" +"*/MaliciousMacroMSBuild*",".{0,1000}\/MaliciousMacroMSBuild.{0,1000}","offensive_tool_keyword","MaliciousMacroMSBuild","Generates Malicious Macro and Execute Powershell or Shellcode via MSBuild Application Whitelisting Bypass.","T1059.001 - T1059.003 - T1127 - T1027.002","TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/infosecn1nja/MaliciousMacroMSBuild","1","1","N/A","N/A","8","6","507","123","2019-08-06T08:16:05Z","2018-04-09T23:16:30Z","8708" +"*/malleable-c2*",".{0,1000}\/malleable\-c2.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/malleable-c2","1","1","N/A","N/A","10","10","1676","299","2023-12-13T17:14:22Z","2018-08-14T14:19:43Z","8709" +"*/MalSCCM.git*",".{0,1000}\/MalSCCM\.git.{0,1000}","offensive_tool_keyword","MalSCCM","This tool allows you to abuse local or remote SCCM servers to deploy malicious applications to hosts they manage","T1072 - T1059.005 - T1090","TA0008 - TA0002 - TA0011","N/A","N/A","Exploitation tool","https://github.com/nettitude/MalSCCM","1","1","N/A","N/A","10","3","246","37","2023-09-28T17:29:50Z","2022-05-04T08:27:27Z","8710" +"*/MalSCCM.sln*",".{0,1000}\/MalSCCM\.sln.{0,1000}","offensive_tool_keyword","MalSCCM","This tool allows you to abuse local or remote SCCM servers to deploy malicious applications to hosts they manage","T1072 - T1059.005 - T1090","TA0008 - TA0002 - TA0011","N/A","N/A","Exploitation tool","https://github.com/nettitude/MalSCCM","1","1","N/A","N/A","10","3","246","37","2023-09-28T17:29:50Z","2022-05-04T08:27:27Z","8711" +"*/malseclogon.*",".{0,1000}\/malseclogon\..{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","8712" +"*/MalStuff.cpp*",".{0,1000}\/MalStuff\.cpp.{0,1000}","offensive_tool_keyword","D1rkInject","Threadless injection that loads a module into the target process and stomps it and reverting back memory protections and original memory state","T1055 - T1055.012 - T1055.002 - T1574.002","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/D1rkInject","1","1","N/A","N/A","9","2","177","32","2023-08-02T02:45:46Z","2023-08-02T02:13:55Z","8713" +"*/man_in_the_browser/*.js*",".{0,1000}\/man_in_the_browser\/.{0,1000}\.js.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","8714" +"*/man_in_the_browser/*.rb*",".{0,1000}\/man_in_the_browser\/.{0,1000}\.rb.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","8715" +"*/manage/exec_cmd*",".{0,1000}\/manage\/exec_cmd.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","8716" +"*/Management/C2/*",".{0,1000}\/Management\/C2\/.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","8717" +"*/manjusaka/plugins*",".{0,1000}\/manjusaka\/plugins.{0,1000}","offensive_tool_keyword","cobaltstrike","Chinese clone of cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/YDHCUI/manjusaka","1","1","N/A","N/A","10","10","818","150","2023-05-09T03:31:53Z","2022-03-18T08:16:04Z","8718" +"*/MANSPIDER.git*",".{0,1000}\/MANSPIDER\.git.{0,1000}","offensive_tool_keyword","MANSPIDER","Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!","T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083","TA0007 - TA0009 - TA0010","N/A","N/A","Discovery","https://github.com/blacklanternsecurity/MANSPIDER","1","1","N/A","N/A","8","10","1117","138","2024-07-18T06:14:04Z","2020-03-18T13:27:20Z","8719" +"*/manspider_output*.txt",".{0,1000}\/manspider_output.{0,1000}\.txt","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","8721" +"*/manspiderDump*",".{0,1000}\/manspiderDump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","8722" +"*/Mara.git*",".{0,1000}\/Mara\.git.{0,1000}","offensive_tool_keyword","Mara","Mara is a userland pty/tty sniffer","T1055 - T1106 - T1059","TA0002 - TA0005 - TA0003","N/A","N/A","Sniffing & Spoofing","https://github.com/io-tl/Mara/","1","1","N/A","N/A","9","1","53","6","2023-12-22T16:52:47Z","2022-08-02T13:02:41Z","8723" +"*/masky.py*",".{0,1000}\/masky\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","8724" +"*/master/GPSCoordinates/*",".{0,1000}\/master\/GPSCoordinates\/.{0,1000}","offensive_tool_keyword","GPSCoordinates","Tracks the system's GPS coordinates (accurate within 1km currently) if Location Services are enabled","T1018 - T1059.001","TA0001 - TA0002","N/A","N/A","Reconnaissance","https://github.com/matterpreter/OffensiveCSharp/tree/master/GPSCoordinates","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","8725" +"*/master/JunctionFolder/*",".{0,1000}\/master\/JunctionFolder\/.{0,1000}","offensive_tool_keyword","JunctionFolder","Creates a junction folder in the Windows Accessories Start Up folder as described in the Vault 7 leaks. On start or when a user browses the directory - the referenced DLL will be executed by verclsid.exe in medium integrity.","T1547.001 - T1574.001 - T1204.002","TA0005 - TA0004","N/A","N/A","Persistence","https://github.com/matterpreter/OffensiveCSharp/tree/master/JunctionFolder","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","8726" +"*/master/PhantomService/*",".{0,1000}\/master\/PhantomService\/.{0,1000}","offensive_tool_keyword","PhantomService","Searches for and removes non-ASCII services that can't be easily removed by built-in Windows tools","T1050.005 - T1055.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/matterpreter/OffensiveCSharp/tree/master/PhantomService","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","8727" +"*/master/windows/klog_main.cpp*",".{0,1000}\/master\/windows\/klog_main\.cpp.{0,1000}","offensive_tool_keyword","Powershell-Scripts-for-Hackers-and-Pentesters","","T1059.001 - T1119 - T1027 - T1016 - T1056.001","TA0002 - TA0009 - TA0005 - TA0007 - TA0010","N/A","N/A","Collection","https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters","1","1","N/A","N/A","10","5","415","49","2025-02-23T09:05:44Z","2023-02-27T14:27:32Z","8728" +"*/maxdb-info.nse*",".{0,1000}\/maxdb\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8729" +"*/mcafee-epo-agent.nse*",".{0,1000}\/mcafee\-epo\-agent\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8730" +"*/md5cracker.rb*",".{0,1000}\/md5cracker\.rb.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","8731" +"*/MDE_Enum.git*",".{0,1000}\/MDE_Enum\.git.{0,1000}","offensive_tool_keyword","MDE_Enum","extract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rules","T1070.006","TA0005 - TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/0xsp-SRD/MDE_Enum","1","1","N/A","N/A","8","2","198","18","2024-06-10T18:40:27Z","2024-06-06T15:54:44Z","8732" +"*/MDExclusionParser.git*",".{0,1000}\/MDExclusionParser\.git.{0,1000}","offensive_tool_keyword","MDExclusionParser","PowerShell script to quickly scan Event Log ID 5007 and 1121 for published Windows Defender Exclusions and Attack Surface Reduction (ASR) rule configuration.","T1562.001","TA0005 - TA0007","N/A","N/A","Defense Evasion","https://github.com/ViziosDe/MDExclusionParser","1","1","N/A","N/A","5","1","6","1","2024-06-12T14:17:08Z","2024-06-12T11:56:07Z","8733" +"*/membase-brute.nse*",".{0,1000}\/membase\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8748" +"*/membase-http-info.nse*",".{0,1000}\/membase\-http\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8749" +"*/memcached-info.nse*",".{0,1000}\/memcached\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8750" +"*/memexec.pl*",".{0,1000}\/memexec\.pl.{0,1000}","offensive_tool_keyword","Orc","Orc is a post-exploitation framework for Linux written in Bash","T1059.004 - T1036.005 - T1070.002 - T1012 - T1082 - T1003 - T1555.003 - T1049 - T1134.001 - T1202","TA0005 - TA0003 - TA0002 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/zMarch/Orc","1","1","#linux","N/A","9","4","395","53","2019-11-12T18:21:27Z","2018-08-16T11:31:39Z","8751" +"*/memexec.py*",".{0,1000}\/memexec\.py.{0,1000}","offensive_tool_keyword","Orc","Orc is a post-exploitation framework for Linux written in Bash","T1059.004 - T1036.005 - T1070.002 - T1012 - T1082 - T1003 - T1555.003 - T1049 - T1134.001 - T1202","TA0005 - TA0003 - TA0002 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/zMarch/Orc","1","1","#linux","N/A","9","4","395","53","2019-11-12T18:21:27Z","2018-08-16T11:31:39Z","8752" +"*/memory_exec.py*",".{0,1000}\/memory_exec\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","8754" +"*/MemReader_BoF/*",".{0,1000}\/MemReader_BoF\/.{0,1000}","offensive_tool_keyword","cobaltstrike","MemReader Beacon Object File will allow you to search and extract specific strings from a target process memory and return what is found to the beacon output","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trainr3kt/MemReader_BoF","1","1","N/A","N/A","10","10","46","6","2023-12-05T23:25:22Z","2021-04-21T20:51:25Z","8757" +"*/merlin.dll*",".{0,1000}\/merlin\.dll.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","8758" +"*/merlin.dll*",".{0,1000}\/merlin\.dll.{0,1000}","offensive_tool_keyword","merlin-agent-dll","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent-dll","1","1","N/A","N/A","10","10","51","15","2025-04-17T14:01:36Z","2021-04-17T16:58:24Z","8759" +"*/merlin.git*",".{0,1000}\/merlin\.git.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","8760" +"*/merlin.html*",".{0,1000}\/merlin\.html.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","0","1","N/A","high False positives rate","1","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","8761" +"*/merlin.py*",".{0,1000}\/merlin\.py.{0,1000}","offensive_tool_keyword","mythic","Cross-platform post-exploitation HTTP Command & Control agent written in golang","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/merlin","1","1","N/A","N/A","10","10","94","16","2025-04-16T13:05:47Z","2021-01-25T12:36:46Z","8762" +"*/merlin/agent_code/*",".{0,1000}\/merlin\/agent_code\/.{0,1000}","offensive_tool_keyword","mythic","Cross-platform post-exploitation HTTP Command & Control agent written in golang","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/merlin","1","1","N/A","N/A","10","10","94","16","2025-04-16T13:05:47Z","2021-01-25T12:36:46Z","8763" +"*/merlin/data/modules/*",".{0,1000}\/merlin\/data\/modules\/.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","8764" +"*/merlinAgent-*.exe*",".{0,1000}\/merlinAgent\-.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","N/A","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","8765" +"*/merlin-agent.git*",".{0,1000}\/merlin\-agent\.git.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","N/A","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","8766" +"*/merlin-agent/tarball/v*",".{0,1000}\/merlin\-agent\/tarball\/v.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","N/A","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","8767" +"*/merlin-agent/v2/cli*",".{0,1000}\/merlin\-agent\/v2\/cli.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","N/A","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","8768" +"*/merlin-agent/v2/core*",".{0,1000}\/merlin\-agent\/v2\/core.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","N/A","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","8769" +"*/merlin-agent/zipball/v*",".{0,1000}\/merlin\-agent\/zipball\/v.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","N/A","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","8770" +"*/merlin-agent-dll.git*",".{0,1000}\/merlin\-agent\-dll\.git.{0,1000}","offensive_tool_keyword","merlin-agent-dll","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent-dll","1","1","N/A","N/A","10","10","51","15","2025-04-17T14:01:36Z","2021-04-17T16:58:24Z","8771" +"*/merlin-agent-dll/*",".{0,1000}\/merlin\-agent\-dll\/.{0,1000}","offensive_tool_keyword","merlin-agent-dll","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent-dll","1","1","N/A","N/A","10","10","51","15","2025-04-17T14:01:36Z","2021-04-17T16:58:24Z","8772" +"*/merlinAgent-Linux-x64*",".{0,1000}\/merlinAgent\-Linux\-x64.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","#linux","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","8773" +"*/met_inject.py*",".{0,1000}\/met_inject\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","8780" +"*/Metasploit*",".{0,1000}\/Metasploit.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://www.metasploit.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","8781" +"*/metasploit.go*",".{0,1000}\/metasploit\.go.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","8782" +"*/metasploit/*",".{0,1000}\/metasploit\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8783" +"*/metasploit-coop:*",".{0,1000}\/metasploit\-coop\:.{0,1000}","offensive_tool_keyword","MetasploitCoop","Post-exploitation collaboration platform based on MSF","T1105 - T1098 - T1104 - T1136","TA0010 - TA0011 - TA0008","N/A","N/A","C2","https://github.com/0x727/MetasploitCoop_0x727","1","1","N/A","N/A","10","10","217","38","2021-08-17T15:24:50Z","2021-08-17T10:37:44Z","8785" +"*/MetasploitCoop_0x727.git*",".{0,1000}\/MetasploitCoop_0x727\.git.{0,1000}","offensive_tool_keyword","MetasploitCoop","Post-exploitation collaboration platform based on MSF","T1105 - T1098 - T1104 - T1136","TA0010 - TA0011 - TA0008","N/A","N/A","C2","https://github.com/0x727/MetasploitCoop_0x727","1","1","N/A","N/A","10","10","217","38","2021-08-17T15:24:50Z","2021-08-17T10:37:44Z","8786" +"*/MetasploitCoop-Backend.git*",".{0,1000}\/MetasploitCoop\-Backend\.git.{0,1000}","offensive_tool_keyword","MetasploitCoop","Post-exploitation collaboration platform based on MSF","T1105 - T1098 - T1104 - T1136","TA0010 - TA0011 - TA0008","N/A","N/A","C2","https://github.com/0x727/MetasploitCoop-Backend","1","1","N/A","N/A","10","10","37","8","2021-08-17T10:26:17Z","2021-08-17T07:52:12Z","8787" +"*/MetasploitCoop-Frontend.git*",".{0,1000}\/MetasploitCoop\-Frontend\.git.{0,1000}","offensive_tool_keyword","MetasploitCoop","Post-exploitation collaboration platform based on MSF","T1105 - T1098 - T1104 - T1136","TA0010 - TA0011 - TA0008","N/A","N/A","C2","https://github.com/0x727/MetasploitCoop-Frontend","1","1","N/A","N/A","10","10","20","7","2024-04-03T14:49:19Z","2021-08-17T10:36:52Z","8788" +"*/metasploit-framework/*",".{0,1000}\/metasploit\-framework\/.{0,1000}","offensive_tool_keyword","MetasploitCoop","Post-exploitation collaboration platform based on MSF","T1105 - T1098 - T1104 - T1136","TA0010 - TA0011 - TA0008","N/A","N/A","C2","https://github.com/0x727/MetasploitCoop-Backend","1","1","N/A","N/A","10","10","37","8","2021-08-17T10:26:17Z","2021-08-17T07:52:12Z","8789" +"*/metasploit-framework/embedded/framework*",".{0,1000}\/metasploit\-framework\/embedded\/framework.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","8790" +"*/metasploit-info.nse*",".{0,1000}\/metasploit\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8791" +"*/metasploit-msgrpc-brute.nse*",".{0,1000}\/metasploit\-msgrpc\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8792" +"*/metasploit-omnibus*",".{0,1000}\/metasploit\-omnibus.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-omnibus","1","1","N/A","N/A","10","3","268","213","2025-04-18T13:17:56Z","2015-02-26T18:42:09Z","8793" +"*/metasploit-omnibus.git*",".{0,1000}\/metasploit\-omnibus\.git.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-omnibus","1","1","N/A","N/A","10","3","268","213","2025-04-18T13:17:56Z","2015-02-26T18:42:09Z","8794" +"*/metasploit-omnibus.git*",".{0,1000}\/metasploit\-omnibus\.git.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-omnibus","1","1","N/A","N/A","10","3","268","213","2025-04-18T13:17:56Z","2015-02-26T18:42:09Z","8795" +"*/metasploit-xmlrpc-brute.nse*",".{0,1000}\/metasploit\-xmlrpc\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8796" +"*/metatwin.git*",".{0,1000}\/metatwin\.git.{0,1000}","offensive_tool_keyword","metatwin","The project is designed as a file resource cloner. Metadata including digital signature is extracted from one file and injected into another","T1553.002 - T1114.001 - T1564.003","TA0006 - TA0010","N/A","N/A","Exploitation tool","https://github.com/threatexpress/metatwin","1","1","N/A","N/A","9","4","345","71","2024-11-19T19:45:59Z","2017-10-08T13:26:00Z","8797" +"*/meterpreter*",".{0,1000}\/meterpreter.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8798" +"*/Meterpreter.classs*",".{0,1000}\/Meterpreter\.classs.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","8799" +"*/meterpreter.php*",".{0,1000}\/meterpreter\.php.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","8800" +"*/Meterpreter.py*",".{0,1000}\/Meterpreter\.py.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta - FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","8801" +"*/meterpreter.rc*",".{0,1000}\/meterpreter\.rc.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta - FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","8802" +"*/meterpreter/reverse_tcp*",".{0,1000}\/meterpreter\/reverse_tcp.{0,1000}","offensive_tool_keyword","HRShell","HRShell is an HTTPS/HTTP reverse shell built with flask. It is an advanced C2 server with many features & capabilities.","T1021.002 - T1105 - T1059.001 - T1059.003 - T1064","TA0008 - TA0011 - TA0002","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla - Black Basta","C2","https://github.com/chrispetrou/HRShell","1","1","N/A","N/A","10","10","247","70","2021-09-09T08:26:32Z","2019-08-20T15:24:46Z","8803" +"*/MFASweep.git*",".{0,1000}\/MFASweep\.git.{0,1000}","offensive_tool_keyword","MFASweep","A tool for checking if MFA is enabled on multiple Microsoft Services","T1595 - T1595.002 - T1078.003 - T1621","TA0006 - TA0009","N/A","N/A","Exploitation tool","https://github.com/dafthack/MFASweep","1","1","N/A","N/A","9","10","1484","203","2025-03-04T20:36:41Z","2020-09-22T16:25:03Z","8804" +"*/mhydeath.git*",".{0,1000}\/mhydeath\.git.{0,1000}","offensive_tool_keyword","mhydeath","Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.","T1562.001","TA0040 - TA0005","N/A","Black Basta","Defense Evasion","https://github.com/zer0condition/mhydeath","1","1","N/A","N/A","10","4","397","71","2023-08-22T08:01:04Z","2023-08-22T07:15:36Z","8805" +"*/mhydeath.sln*",".{0,1000}\/mhydeath\.sln.{0,1000}","offensive_tool_keyword","mhydeath","Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.","T1562.001","TA0040 - TA0005","N/A","Black Basta","Defense Evasion","https://github.com/zer0condition/mhydeath","1","1","N/A","N/A","10","4","397","71","2023-08-22T08:01:04Z","2023-08-22T07:15:36Z","8806" +"*/mhydeath/main.cpp*",".{0,1000}\/mhydeath\/main\.cpp.{0,1000}","offensive_tool_keyword","mhydeath","Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.","T1562.001","TA0040 - TA0005","N/A","Black Basta","Defense Evasion","https://github.com/zer0condition/mhydeath","1","1","N/A","N/A","10","4","397","71","2023-08-22T08:01:04Z","2023-08-22T07:15:36Z","8807" +"*/michaelweber/Macrome*",".{0,1000}\/michaelweber\/Macrome.{0,1000}","offensive_tool_keyword","Macrome","An Excel Macro Document Reader/Writer for Red Teamers & Analysts. Blog posts describing what this tool actually does can be found https://malware.pizza/2020/05/12/evading-av-with-excel-macros-and-biff8-xls/ and https://malware.pizza/2020/06/19/further-evasion-in-the-forgotten-corners-of-ms-xls/","T1140","TA0005","N/A","N/A","Exploitation tool","https://github.com/michaelweber/Macrome","1","1","N/A","N/A","N/A","6","520","79","2022-02-01T16:26:13Z","2020-05-07T22:44:11Z","8808" +"*/micr0%20shell.py*",".{0,1000}\/micr0\%20shell\.py.{0,1000}","offensive_tool_keyword","micr0_shell","micr0shell is a Python script that dynamically generates Windows X64 PIC Null-Free reverse shell shellcode.","T1059.003 - T1027.001","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/senzee1984/micr0_shell","1","1","N/A","N/A","9","2","186","30","2024-07-21T08:16:57Z","2023-08-13T02:46:51Z","8809" +"*/micr0_shell.git*",".{0,1000}\/micr0_shell\.git.{0,1000}","offensive_tool_keyword","micr0_shell","micr0shell is a Python script that dynamically generates Windows X64 PIC Null-Free reverse shell shellcode.","T1059.003 - T1027.001","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/senzee1984/micr0_shell","1","1","N/A","N/A","9","2","186","30","2024-07-21T08:16:57Z","2023-08-13T02:46:51Z","8810" +"*/MicroBurst.git*",".{0,1000}\/MicroBurst\.git.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","8811" +"*/mikrotik-routeros-brute.nse*",".{0,1000}\/mikrotik\-routeros\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8814" +"*/mimi32.exe*",".{0,1000}\/mimi32\.exe.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8815" +"*/mimi64.exe*",".{0,1000}\/mimi64\.exe.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8816" +"*/mimicom.idl*",".{0,1000}\/mimicom\.idl.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8817" +"*/mimidogz.git*",".{0,1000}\/mimidogz\.git.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","1","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","8818" +"*/mimidropper.hta*",".{0,1000}\/mimidropper\.hta.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","8819" +"*/mimidrv.sys*",".{0,1000}\/mimidrv\.sys.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8820" +"*/mimidrv.zip*",".{0,1000}\/mimidrv\.zip.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8821" +"*/mimikatz.bin*",".{0,1000}\/mimikatz\.bin.{0,1000}","offensive_tool_keyword","InflativeLoading","Dynamically convert a native EXE to PIC shellcode by prepending a shellcode stub","T1027 - T1055 - T1140","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/senzee1984/InflativeLoading","1","1","N/A","N/A","10","4","309","64","2024-04-12T17:14:07Z","2024-01-05T03:59:33Z","8822" +"*/mimikatz.enc*",".{0,1000}\/mimikatz\.enc.{0,1000}","offensive_tool_keyword","mortar","red teaming evasion technique to defeat and divert detection and prevention of security products.Mortar Loader performs encryption and decryption of selected binary inside the memory streams and execute it directly with out writing any malicious indicator into the hard-drive. Mortar is able to bypass modern anti-virus products and advanced XDR solutions","T1055 - T1027 - T1036 - T1112 - T1037 - T1105 - T1059 - T1562","TA0002 - TA0003 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/0xsp-SRD/mortar","1","1","N/A","N/A","10","10","1451","235","2023-12-21T22:00:38Z","2021-11-25T16:49:47Z","8823" +"*/mimikatz.exe*",".{0,1000}\/mimikatz\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","mimikatz","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","8824" +"*/mimikatz.git*",".{0,1000}\/mimikatz\.git.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz github link","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8825" +"*/mimikatz.py*",".{0,1000}\/mimikatz\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","8826" +"*/mimikatz.py*",".{0,1000}\/mimikatz\.py.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","8827" +"*/mimikatz.sln*",".{0,1000}\/mimikatz\.sln.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8828" +"*/mimikatz/archive/master.zip*",".{0,1000}\/mimikatz\/archive\/master\.zip.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archive link","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8829" +"*/mimikatz/releases/*",".{0,1000}\/mimikatz\/releases\/.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archive link","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8830" +"*/mimikatz/zipball/*",".{0,1000}\/mimikatz\/zipball\/.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archive link","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8831" +"*/mimikatz_bypass/mimikatz.py*",".{0,1000}\/mimikatz_bypass\/mimikatz\.py.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8832" +"*/mimikatz_bypass/mimikatz2.py*",".{0,1000}\/mimikatz_bypass\/mimikatz2\.py.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8833" +"*/mimikatz_bypassAV/main.exe*",".{0,1000}\/mimikatz_bypassAV\/main\.exe.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8834" +"*/mimikatz_bypassAV/mimikatz_load.exe*",".{0,1000}\/mimikatz_bypassAV\/mimikatz_load\.exe.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8835" +"*/mimikatz_load.exe*",".{0,1000}\/mimikatz_load\.exe.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8836" +"*/mimilib.def*",".{0,1000}\/mimilib\.def.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8837" +"*/mimilib.dll*",".{0,1000}\/mimilib\.dll.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","1","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","8838" +"*/mimilove.c*",".{0,1000}\/mimilove\.c.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8839" +"*/mimilove.h*",".{0,1000}\/mimilove\.h.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8840" +"*/mimilove.rc*",".{0,1000}\/mimilove\.rc.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8841" +"*/mimipenguin.*",".{0,1000}\/mimipenguin\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8842" +"*/mimipenguin.c*",".{0,1000}\/mimipenguin\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","8843" +"*/mimipenguin.md*",".{0,1000}\/mimipenguin\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8844" +"*/mimipenguin.sh*",".{0,1000}\/mimipenguin\.sh.{0,1000}","offensive_tool_keyword","mimipy","Tool to dump passwords from various processes memory","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/n1nj4sec/mimipy","1","1","N/A","N/A","10","3","207","36","2017-04-30T00:09:15Z","2017-04-05T21:06:32Z","8845" +"*/mimipenguin/*",".{0,1000}\/mimipenguin\/.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","8846" +"*/mimipenguin/*",".{0,1000}\/mimipenguin\/.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","8847" +"*/mimipenguin/releases/download/*",".{0,1000}\/mimipenguin\/releases\/download\/.{0,1000}","offensive_tool_keyword","mimipenguin","A tool to dump the login password from the current linux user","T1003.007","TA0006 - TA0002 ","N/A","TeamTNT","Credential Access","https://github.com/huntergregal/mimipenguin","1","1","#linux","N/A","10","10","3940","644","2023-05-17T13:20:46Z","2017-03-28T21:24:28Z","8848" +"*/mimipy.git*",".{0,1000}\/mimipy\.git.{0,1000}","offensive_tool_keyword","mimipy","Tool to dump passwords from various processes memory","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/n1nj4sec/mimipy","1","1","N/A","N/A","10","3","207","36","2017-04-30T00:09:15Z","2017-04-05T21:06:32Z","8849" +"*/mimipy.py*",".{0,1000}\/mimipy\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","8850" +"*/mimishim/*",".{0,1000}\/mimishim\/.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","8851" +"*/MiniDump.git*",".{0,1000}\/MiniDump\.git.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","1","N/A","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","8852" +"*/minidump.go*",".{0,1000}\/minidump\.go.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","8853" +"*/minidump.zip*",".{0,1000}\/minidump\.zip.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","8854" +"*/MiniDump-main.zip*",".{0,1000}\/MiniDump\-main\.zip.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","1","N/A","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","8855" +"*/minidump-rs.exe*",".{0,1000}\/minidump\-rs\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","8856" +"*/minimal_elf.h*",".{0,1000}\/minimal_elf\.h.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a ELF object in memory loader/runner. The goal is to create a single elf loader that can be used to run follow on capabilities across all x86_64 and x86 nix operating systems.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/ELFLoader","1","1","N/A","N/A","10","10","268","45","2022-05-16T17:48:40Z","2022-04-26T19:18:20Z","8857" +"*/Minimalistic-offensive-security-tools.git*",".{0,1000}\/Minimalistic\-offensive\-security\-tools\.git.{0,1000}","offensive_tool_keyword","Minimalistic-offensive","A repository of tools for pentesting of restricted and isolated environments.","T1110 - T1046 - T1021 - T1203 - T1485","TA0006 - TA0007 - TA0008","N/A","Dispossessor","Discovery","https://github.com/InfosecMatter/Minimalistic-offensive-security-tools","1","1","N/A","N/A","7","6","562","121","2021-10-26T11:04:46Z","2020-05-10T17:40:31Z","8858" +"*/mirai_pass.txt*",".{0,1000}\/mirai_pass\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8859" +"*/MirrorDump.exe*",".{0,1000}\/MirrorDump\.exe.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","1","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","8860" +"*/MirrorDump.git*",".{0,1000}\/MirrorDump\.git.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","1","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","8861" +"*/Misc/donut.exe*",".{0,1000}\/Misc\/donut\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Koh is a C# and Beacon Object File (BOF) toolset that allows for the capture of user credential material via purposeful token/logon session leakage.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/GhostPack/Koh","1","1","N/A","N/A","10","10","492","66","2022-07-13T23:41:38Z","2022-07-07T17:14:09Z","8862" +"*/MiTM.java*",".{0,1000}\/MiTM\.java.{0,1000}","offensive_tool_keyword","chunk-Proxy","A backdoor installed on a web server that allows for the execution of commands and facilitates persistent access.","T1505.003 - T1059 - T1105 - T1071","TA0011 - TA0002 - TA0003","Ghost Ransomware","N/A","C2","https://github.com/BeichenDream/Chunk-Proxy","1","1","N/A","N/A","10","10","283","40","2022-05-07T04:24:50Z","2021-10-28T18:45:21Z","8863" +"*/mitmAP*",".{0,1000}\/mitmAP.{0,1000}","offensive_tool_keyword","mitmAP","A python program to create a fake AP and sniff data","T1563 - T1593 - T1594 - T1567","TA0002 - TA0007 - TA0009 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/xdavidhu/mitmAP","1","1","N/A","N/A","10","10","1668","265","2019-11-03T11:34:06Z","2016-10-22T21:49:25Z","8864" +"*/MITMRecorder.py*",".{0,1000}\/MITMRecorder\.py.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","#linux","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","8866" +"*/mkzoneslices.sh*",".{0,1000}\/mkzoneslices\.sh.{0,1000}","offensive_tool_keyword","dnskire","A tool for file infiltration over DNS","T1071.004 - T1071.001 - T1048","TA0010 - TA0005 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/0xtosh/dnskire","1","1","N/A","N/A","7","1","17","0","2023-12-07T21:42:34Z","2022-09-10T17:56:30Z","8868" +"*/mmouse-brute.nse*",".{0,1000}\/mmouse\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8869" +"*/mmouse-exec.nse*",".{0,1000}\/mmouse\-exec\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8870" +"*/mobaxterm.py*",".{0,1000}\/mobaxterm\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","8871" +"*/Mockingjay_BOF.git*",".{0,1000}\/Mockingjay_BOF\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object File (BOF) Conversion of the Mockingjay Process Injection Technique","T1055.012 - T1059.001 - T1027.002","TA0002 - TA0005","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ewby/Mockingjay_BOF","1","1","N/A","N/A","9","10","151","18","2023-11-07T19:04:03Z","2023-08-27T06:01:28Z","8873" +"*/modbus-discover.nse*",".{0,1000}\/modbus\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8874" +"*/Models/PowerShellLauncher.*",".{0,1000}\/Models\/PowerShellLauncher\..{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","8875" +"*/Models/Regsvr32Launcher.*",".{0,1000}\/Models\/Regsvr32Launcher\..{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","8876" +"*/Models/ShellCodeLauncher.*",".{0,1000}\/Models\/ShellCodeLauncher\..{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","8877" +"*/Modlishka.git*",".{0,1000}\/Modlishka\.git.{0,1000}","offensive_tool_keyword","Modlishka ","Modlishka is a powerful and flexible HTTP reverse proxy. It implements an entirely new and interesting approach of handling browser-based HTTP traffic flow. which allows to transparently proxy multi-domain destination traffic. both TLS and non-TLS. over a single domain. without a requirement of installing any additional certificate on the client.","T1090.001 - T1071.001 - T1556.001 - T1204.001 - T1568.002","TA0011 - TA0001 - TA0002 - TA0005 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/drk1wi/Modlishka","1","1","N/A","network exploitation tool","5","10","4967","897","2024-04-19T12:23:00Z","2018-12-19T15:59:54Z","8878" +"*/Modules/Exitservice/uinit.exe*",".{0,1000}\/Modules\/Exitservice\/uinit\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","8880" +"*/modules/payload/*",".{0,1000}\/modules\/payload\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8882" +"*/modules/windows/shinject/*",".{0,1000}\/modules\/windows\/shinject\/.{0,1000}","offensive_tool_keyword","shad0w","A post exploitation framework designed to operate covertly on heavily monitored environments","T1071 - T1090 - T1105 - T1571 - T1001","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/bats3c/shad0w","1","1","N/A","N/A","N/A","10","2090","332","2021-09-29T00:15:36Z","2020-04-28T16:42:07Z","8883" +"*/momyshark?key=*",".{0,1000}\/momyshark\?key\=.{0,1000}","offensive_tool_keyword","BabyShark","This is a basic C2 generic server written in Python and Flask.","T1547.001 - T1059.003 - T1132.001 - T1140 - T1083 - T1070.004 - T1105 - T1056.001 - T1057 - T1012 - T1053.005 - T1218.005 - T1082 - T1016 - T1033","TA0006 - TA0011 - TA0040","N/A","Kimsuky","C2","https://github.com/UnkL4b/BabyShark","1","1","N/A","N/A","10","10","189","30","2021-07-03T00:18:18Z","2020-06-02T12:27:20Z","8885" +"*/momyshark?key=*",".{0,1000}\/momyshark\?key\=.{0,1000}","offensive_tool_keyword","BabyShark","This is a basic C2 generic server written in Python and Flask.","T1547.001 - T1059.003 - T1132.001 - T1140 - T1083 - T1070.004 - T1105 - T1056.001 - T1057 - T1012 - T1053.005 - T1218.005 - T1082 - T1016 - T1033","TA0006 - TA0011 - TA0040","N/A","Kimsuky","C2","https://github.com/UnkL4b/BabyShark","1","1","N/A","N/A","10","10","189","30","2021-07-03T00:18:18Z","2020-06-02T12:27:20Z","8886" +"*/mongodb-brute.nse*",".{0,1000}\/mongodb\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8887" +"*/mongodb-databases.nse*",".{0,1000}\/mongodb\-databases\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8888" +"*/mongodb-info.nse*",".{0,1000}\/mongodb\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8889" +"*/monkey.py",".{0,1000}\/monkey\.py","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","8890" +"*/monkey_island.py*",".{0,1000}\/monkey_island\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","8891" +"*/MonkeyWorks.git*",".{0,1000}\/MonkeyWorks\.git.{0,1000}","offensive_tool_keyword","Tokenvator","A tool to elevate privilege with Windows Tokens","T1134 - T1078","TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/0xbadjuju/Tokenvator","1","1","N/A","N/A","N/A","10","1038","201","2023-10-06T13:17:05Z","2017-12-08T01:29:11Z","8892" +"*/moonwalk.git*",".{0,1000}\/moonwalk\.git.{0,1000}","offensive_tool_keyword","moonwalk","Cover your tracks during Linux Exploitation by leaving zero traces on system logs and filesystem timestamps.","T1070 - T1036.005 - T1070.004","TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/mufeedvh/moonwalk","1","1","#linux","N/A","10","10","1440","129","2022-10-08T05:05:36Z","2021-12-19T11:24:00Z","8893" +"*/moonwalk_darwin*",".{0,1000}\/moonwalk_darwin.{0,1000}","offensive_tool_keyword","moonwalk","Cover your tracks during Linux Exploitation by leaving zero traces on system logs and filesystem timestamps.","T1070 - T1036.005 - T1070.004","TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/mufeedvh/moonwalk","1","1","#linux","N/A","10","10","1440","129","2022-10-08T05:05:36Z","2021-12-19T11:24:00Z","8894" +"*/Moriarty.exe*",".{0,1000}\/Moriarty\.exe.{0,1000}","offensive_tool_keyword","Moriarty","Moriarty is designed to enumerate missing KBs - detect various vulnerabilities and suggest potential exploits for Privilege Escalation in Windows environments.","T1068 - T1083","TA0004 - TA0007","N/A","N/A","Discovery","https://github.com/BC-SECURITY/Moriarty","1","1","N/A","N/A","7","6","510","67","2024-08-07T15:06:31Z","2023-12-11T14:15:33Z","8895" +"*/Moriarty.exe*",".{0,1000}\/Moriarty\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","8896" +"*/Moriarty.git*",".{0,1000}\/Moriarty\.git.{0,1000}","offensive_tool_keyword","Moriarty","Moriarty is designed to enumerate missing KBs - detect various vulnerabilities and suggest potential exploits for Privilege Escalation in Windows environments.","T1068 - T1083","TA0004 - TA0007","N/A","N/A","Discovery","https://github.com/BC-SECURITY/Moriarty","1","1","N/A","N/A","7","6","510","67","2024-08-07T15:06:31Z","2023-12-11T14:15:33Z","8897" +"*/mortar.git*",".{0,1000}\/mortar\.git.{0,1000}","offensive_tool_keyword","mortar","red teaming evasion technique to defeat and divert detection and prevention of security products.Mortar Loader performs encryption and decryption of selected binary inside the memory streams and execute it directly with out writing any malicious indicator into the hard-drive. Mortar is able to bypass modern anti-virus products and advanced XDR solutions","T1055 - T1027 - T1036 - T1112 - T1037 - T1105 - T1059 - T1562","TA0002 - TA0003 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/0xsp-SRD/mortar","1","1","N/A","N/A","10","10","1451","235","2023-12-21T22:00:38Z","2021-11-25T16:49:47Z","8898" +"*/mortar/releases/download/v2/encryptor*",".{0,1000}\/mortar\/releases\/download\/v2\/encryptor.{0,1000}","offensive_tool_keyword","mortar","evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)","T1027 - T1562","TA0005","N/A","N/A","Defense Evasion","https://github.com/0xsp-SRD/mortar","1","1","N/A","N/A","8","10","1451","235","2023-12-21T22:00:38Z","2021-11-25T16:49:47Z","8899" +"*/mortar/releases/download/v2/encryptor*",".{0,1000}\/mortar\/releases\/download\/v2\/encryptor.{0,1000}","offensive_tool_keyword","mortar","red teaming evasion technique to defeat and divert detection and prevention of security products.Mortar Loader performs encryption and decryption of selected binary inside the memory streams and execute it directly with out writing any malicious indicator into the hard-drive. Mortar is able to bypass modern anti-virus products and advanced XDR solutions","T1055 - T1027 - T1036 - T1112 - T1037 - T1105 - T1059 - T1562","TA0002 - TA0003 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/0xsp-SRD/mortar","1","1","N/A","N/A","10","10","1451","235","2023-12-21T22:00:38Z","2021-11-25T16:49:47Z","8900" +"*/mortar-loader.html*",".{0,1000}\/mortar\-loader\.html.{0,1000}","offensive_tool_keyword","mortar","evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)","T1027 - T1562","TA0005","N/A","N/A","Defense Evasion","https://github.com/0xsp-SRD/mortar","1","1","N/A","N/A","8","10","1451","235","2023-12-21T22:00:38Z","2021-11-25T16:49:47Z","8901" +"*/Mouse Overheat.exe*",".{0,1000}\/Mouse\sOverheat\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","8903" +"*/mouselogger.py*",".{0,1000}\/mouselogger\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","8904" +"*/mqtt_check.py*",".{0,1000}\/mqtt_check\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","8905" +"*/mqtt-subscribe.nse*",".{0,1000}\/mqtt\-subscribe\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8906" +"*/mrd0x.html*",".{0,1000}\/mrd0x\.html.{0,1000}","offensive_tool_keyword","PWA-Phishing","Phishing with Progressive Web Apps and UI manipulation","T1071.003 - T1204.002 - T1608.003 - T1071.004","TA0006","N/A","N/A","Phishing","https://github.com/mrd0x/PWA-Phishing","1","1","N/A","N/A","10","3","288","52","2024-06-16T17:47:15Z","2024-06-09T19:47:52Z","8907" +"*/mremoteng.py*",".{0,1000}\/mremoteng\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","8908" +"*/mRemoteNG-Decrypt*",".{0,1000}\/mRemoteNG\-Decrypt.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/haseebT/mRemoteNG-Decrypt","1","1","N/A","N/A","8","2","146","42","2023-07-06T16:15:20Z","2019-05-27T05:25:57Z","8909" +"*/mremoteng-decrypt.git*",".{0,1000}\/mremoteng\-decrypt\.git.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","1","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","8910" +"*/mremoteng-decrypt/releases/download/*",".{0,1000}\/mremoteng\-decrypt\/releases\/download\/.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","1","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","8911" +"*/mremoteng-decrypt/tarball/*",".{0,1000}\/mremoteng\-decrypt\/tarball\/.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","1","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","8912" +"*/mremoteng-decrypt/zipball/*",".{0,1000}\/mremoteng\-decrypt\/zipball\/.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","1","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","8913" +"*/mrinfo.nse*",".{0,1000}\/mrinfo\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8914" +"*/Mr-Un1k0d3r/*",".{0,1000}\/Mr\-Un1k0d3r\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Fileless Lateral Movement tool that relies on ChangeServiceConfigA to run command","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/SCShell","1","1","N/A","N/A","10","10","1484","248","2023-07-10T01:31:54Z","2019-11-13T23:39:27Z","8915" +"*/Mr-xn/cve-2022-23131*",".{0,1000}\/Mr\-xn\/cve\-2022\-23131.{0,1000}","offensive_tool_keyword","POC","POC exploitaiton of zabbix saml bypass exp vulnerability cve-2022-23131 (Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML)","T1548 - T1190","TA0001 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Mr-xn/cve-2022-23131","1","1","N/A","N/A","N/A","2","151","47","2024-08-11T18:14:56Z","2022-02-18T11:51:47Z","8916" +"*/MS15-034.nse*",".{0,1000}\/MS15\-034\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://github.com/cldrn/nmap-nse-scripts/tree/master/scripts","1","1","N/A","N/A","N/A","10","968","369","2022-01-22T18:40:30Z","2011-05-31T05:41:49Z","8917" +"*/ms17-010.py*",".{0,1000}\/ms17\-010\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","8918" +"*/msf.go",".{0,1000}\/msf\.go","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","8919" +"*/msf.swf*",".{0,1000}\/msf\.swf.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8920" +"*/msfcrawler*",".{0,1000}\/msfcrawler.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8921" +"*/msfnonstaged.exe*",".{0,1000}\/msfnonstaged\.exe.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","8922" +"*/msfpc.sh*",".{0,1000}\/msfpc\.sh.{0,1000}","offensive_tool_keyword","msfpc","Msfvenom is the combination of payload generation and encoding. It replaced msfpayload and msfencode on June 8th 2015.","T1027 - T1036 - T1564 - T1071 - T1059","TA0002 - TA0003 - TA0008","N/A","N/A","Resource Development","https://github.com/g0tmi1k/msfpc","1","1","N/A","N/A","N/A","10","1261","274","2021-05-09T13:16:07Z","2015-06-22T12:58:04Z","8923" +"*/msfremove.ps1*",".{0,1000}\/msfremove\.ps1.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-omnibus","1","1","N/A","N/A","10","3","268","213","2025-04-18T13:17:56Z","2015-02-26T18:42:09Z","8924" +"*/msfstaged.exe*",".{0,1000}\/msfstaged\.exe.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","8925" +"*/msftest/*",".{0,1000}\/msftest\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8926" +"*/msfupdate.bat*",".{0,1000}\/msfupdate\.bat.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-omnibus","1","1","N/A","N/A","10","3","268","213","2025-04-18T13:17:56Z","2015-02-26T18:42:09Z","8927" +"*/msfupdate.ps1*",".{0,1000}\/msfupdate\.ps1.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-omnibus","1","1","N/A","N/A","10","3","268","213","2025-04-18T13:17:56Z","2015-02-26T18:42:09Z","8928" +"*/msfvenom.bat*",".{0,1000}\/msfvenom\.bat.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","8929" +"*/msfvenom/*",".{0,1000}\/msfvenom\/.{0,1000}","offensive_tool_keyword","msfvenom","Msfvenom is the combination of payload generation and encoding. It replaced msfpayload and msfencode on June 8th 2015.","T1059.001 - T1027 - T1210.001 - T1204.002","TA0002 - TA0003 - TA0004","N/A","APT32 - Black Basta","Resource Development","https://github.com/rapid7/metasploit-framework/wiki/How-to-use-msfvenom","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8930" +"*/msf-ws.log*",".{0,1000}\/msf\-ws\.log.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","#logfile #linux","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8931" +"*/msfws.py*",".{0,1000}\/msfws\.py.{0,1000}","offensive_tool_keyword","MetasploitCoop","Post-exploitation collaboration platform based on MSF","T1105 - T1098 - T1104 - T1136","TA0010 - TA0011 - TA0008","N/A","N/A","C2","https://github.com/0x727/MetasploitCoop-Backend","1","1","N/A","N/A","10","10","37","8","2021-08-17T10:26:17Z","2021-08-17T07:52:12Z","8932" +"*/MsgKitTestTool/*",".{0,1000}\/MsgKitTestTool\/.{0,1000}","offensive_tool_keyword","poc","Exploit for the CVE-2023-23397","T1068 - T1557.001 - T1187 - T1212 -T1003.001 - T1550","TA0003 - TA0002 - TA0004","N/A","N/A","Exploitation tool","https://github.com/sqrtZeroKnowledge/CVE-2023-23397_EXPLOIT_0DAY","1","1","N/A","N/A","N/A","2","161","41","2023-03-15T17:53:53Z","2023-03-15T17:03:38Z","8933" +"*/Mshikaki.git*",".{0,1000}\/Mshikaki\.git.{0,1000}","offensive_tool_keyword","Mshikaki","A shellcode injection tool capable of bypassing AMSI. Features the QueueUserAPC() injection technique and supports XOR encryption","T1055.012 - T1116 - T1027.002 - T1562.001","TA0005 - TA0006 - TA0040 - TA0002","N/A","N/A","Exploitation tool","https://github.com/trevorsaudi/Mshikaki","1","1","N/A","N/A","9","2","135","25","2023-11-26T18:13:40Z","2023-09-03T16:35:50Z","8934" +"*/mshta.cmd*",".{0,1000}\/mshta\.cmd.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","8935" +"*/mshtajs.cmd*",".{0,1000}\/mshtajs\.cmd.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","8936" +"*/msi_search.ps1*",".{0,1000}\/msi_search\.ps1.{0,1000}","offensive_tool_keyword","msi-search","This tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairs","T1005 ","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/mandiant/msi-search","1","1","N/A","N/A","10","3","276","31","2023-07-20T18:12:49Z","2023-06-29T18:31:56Z","8937" +"*/msi-search.git*",".{0,1000}\/msi\-search\.git.{0,1000}","offensive_tool_keyword","msi-search","This tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairs","T1005 ","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/mandiant/msi-search","1","1","N/A","N/A","10","3","276","31","2023-07-20T18:12:49Z","2023-06-29T18:31:56Z","8938" +"*/msLDAPDump*",".{0,1000}\/msLDAPDump.{0,1000}","offensive_tool_keyword","msldapdump","LDAP enumeration tool implemented in Python3","T1018 - T1210.001","TA0007 - TA0001","N/A","N/A","Reconnaissance","https://github.com/dievus/msLDAPDump","1","1","N/A","N/A","N/A","3","226","31","2024-09-23T18:11:26Z","2022-12-30T23:35:40Z","8939" +"*/msol.py*",".{0,1000}\/msol\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","8940" +"*/MSOLSpray*",".{0,1000}\/MSOLSpray.{0,1000}","offensive_tool_keyword","MSOLSpray","This module will perform password spraying against Microsoft Online accounts (Azure/O365)","T1110.003 - T1553.003 - T1621","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/MSOLSpray","1","1","N/A","network exploitation tool","10","10","964","174","2024-03-19T11:03:06Z","2020-03-16T13:38:22Z","8941" +"*/msrpc-enum.nse*",".{0,1000}\/msrpc\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8942" +"*/MSSprinkler.git*",".{0,1000}\/MSSprinkler\.git.{0,1000}","offensive_tool_keyword","MSSprinkler","password spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approach","T1110.003 - T1110.001","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/TheresAFewConors/MSSprinkler","1","1","N/A","N/A","9","1","74","7","2025-02-25T13:32:41Z","2024-09-15T09:54:53Z","8943" +"*/mssprinkler.ps1*",".{0,1000}\/mssprinkler\.ps1.{0,1000}","offensive_tool_keyword","MSSprinkler","password spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approach","T1110.003 - T1110.001","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/TheresAFewConors/MSSprinkler","1","1","N/A","N/A","9","1","74","7","2025-02-25T13:32:41Z","2024-09-15T09:54:53Z","8944" +"*/mssql_priv.py*",".{0,1000}\/mssql_priv\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","8945" +"*/ms-sql-brute.nse*",".{0,1000}\/ms\-sql\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8946" +"*/mssqlclient.py*",".{0,1000}\/mssqlclient\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","8947" +"*/ms-sql-config.nse*",".{0,1000}\/ms\-sql\-config\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8948" +"*/ms-sql-dac.nse*",".{0,1000}\/ms\-sql\-dac\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8949" +"*/ms-sql-dump-hashes.nse*",".{0,1000}\/ms\-sql\-dump\-hashes\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8950" +"*/ms-sql-empty-password.nse*",".{0,1000}\/ms\-sql\-empty\-password\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8951" +"*/mssqlexec.py*",".{0,1000}\/mssqlexec\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","8952" +"*/ms-sql-hasdbaccess.nse*",".{0,1000}\/ms\-sql\-hasdbaccess\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8953" +"*/ms-sql-info.nse*",".{0,1000}\/ms\-sql\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8954" +"*/mssqlinstance.py*",".{0,1000}\/mssqlinstance\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","8955" +"*/ms-sql-ntlm-info.nse*",".{0,1000}\/ms\-sql\-ntlm\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8956" +"*/mssqlproxy.git*",".{0,1000}\/mssqlproxy\.git.{0,1000}","offensive_tool_keyword","mssqlproxy","mssqlproxy is a toolkit aimed to perform Lateral Movement in restricted environments through a compromised Microsoft SQL Server via socket reuse","T1021.002 - T1071.001 - T1573.002","TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/blackarrowsec/mssqlproxy","1","1","N/A","N/A","10","8","741","114","2021-02-16T20:13:04Z","2020-02-12T08:44:28Z","8957" +"*/ms-sql-query.nse*",".{0,1000}\/ms\-sql\-query\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8958" +"*/ms-sql-tables.nse*",".{0,1000}\/ms\-sql\-tables\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8959" +"*/ms-sql-xp-cmdshell.nse*",".{0,1000}\/ms\-sql\-xp\-cmdshell\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8960" +"*/mstscfox.dll*",".{0,1000}\/mstscfox\.dll.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","1","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","8961" +"*/mtrace.nse*",".{0,1000}\/mtrace\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8962" +"*/mtth-bfft/adeleg/releases*",".{0,1000}\/mtth\-bfft\/adeleg\/releases.{0,1000}","offensive_tool_keyword","Adeleginator","tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory","T1087 - T1136 - T1069","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/techspence/Adeleginator","1","1","N/A","N/A","6","2","179","18","2024-09-18T20:21:42Z","2024-03-04T03:44:52Z","8963" +"*/MultiDump.exe*",".{0,1000}\/MultiDump\.exe.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","1","N/A","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","8964" +"*/MultiDump.exe*",".{0,1000}\/MultiDump\.exe.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","1","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","8965" +"*/MultiDump.git*",".{0,1000}\/MultiDump\.git.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","1","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","8966" +"*/MultiPotato.git*",".{0,1000}\/MultiPotato\.git.{0,1000}","offensive_tool_keyword","MultiPotato","get SYSTEM via SeImpersonate privileges","T1548.002 - T1134.002","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S3cur3Th1sSh1t/MultiPotato","1","1","N/A","N/A","10","6","518","92","2021-11-20T16:20:23Z","2021-11-19T15:50:55Z","8967" +"*/murmur-version.nse*",".{0,1000}\/murmur\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8969" +"*/mushishi.h*",".{0,1000}\/mushishi\.h.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","8970" +"*/MutationGate.git*",".{0,1000}\/MutationGate\.git.{0,1000}","offensive_tool_keyword","MutationGate","MutationGate is a new approach to bypass EDR's inline hooking by utilizing hardware breakpoint to redirect the syscall.","T1055.011 - T1564.008 - T1557","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/senzee1984/MutationGate","1","1","N/A","N/A","8","3","251","34","2024-04-10T03:12:58Z","2024-01-15T04:29:37Z","8971" +"*/mysql-audit.nse*",".{0,1000}\/mysql\-audit\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8972" +"*/mysql-brute.nse*",".{0,1000}\/mysql\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8973" +"*/mysql-databases.nse*",".{0,1000}\/mysql\-databases\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8974" +"*/mysql-dump-hashes.nse*",".{0,1000}\/mysql\-dump\-hashes\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8975" +"*/mysql-empty-password.nse*",".{0,1000}\/mysql\-empty\-password\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8976" +"*/mysql-enum.nse*",".{0,1000}\/mysql\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8977" +"*/mysql-info.nse*",".{0,1000}\/mysql\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8978" +"*/mysql-query.nse*",".{0,1000}\/mysql\-query\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8979" +"*/mysql-users.nse*",".{0,1000}\/mysql\-users\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8980" +"*/mysql-variables.nse*",".{0,1000}\/mysql\-variables\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8981" +"*/mysql-vuln-cve2012-2122.nse*",".{0,1000}\/mysql\-vuln\-cve2012\-2122\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","8982" +"*/Mystikal.git*",".{0,1000}\/Mystikal\.git.{0,1000}","offensive_tool_keyword","Mystikal","macOS Initial Access Payload Generator","T1059.005 - T1204.002 - T1566.001","TA0002 - TA0001","N/A","N/A","Exploitation tool","https://github.com/D00MFist/Mystikal","1","1","N/A","N/A","9","4","305","39","2024-01-10T15:48:12Z","2021-05-03T14:46:16Z","8983" +"*/mystikal.py*",".{0,1000}\/mystikal\.py.{0,1000}","offensive_tool_keyword","Mystikal","macOS Initial Access Payload Generator","T1059.005 - T1204.002 - T1566.001","TA0002 - TA0001","N/A","N/A","Exploitation tool","https://github.com/D00MFist/Mystikal","1","1","N/A","N/A","9","4","305","39","2024-01-10T15:48:12Z","2021-05-03T14:46:16Z","8984" +"*/Mythic/mythic*",".{0,1000}\/Mythic\/mythic.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","8985" +"*/Mythic_CLI*",".{0,1000}\/Mythic_CLI.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","8986" +"*/MythicAgents/*",".{0,1000}\/MythicAgents\/.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","8987" +"*/MythicAgents/*",".{0,1000}\/MythicAgents\/.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","8988" +"*/MythicC2Profiles/*",".{0,1000}\/MythicC2Profiles\/.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","8989" +"*/mythic-cli*",".{0,1000}\/mythic\-cli.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","8990" +"*/MythicConfig.cs*",".{0,1000}\/MythicConfig\.cs.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","8991" +"*/mythic-react-docker*",".{0,1000}\/mythic\-react\-docker.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","8992" +"*/n0kovo_subdomains_huge.txt*",".{0,1000}\/n0kovo_subdomains_huge\.txt.{0,1000}","offensive_tool_keyword","reconftw","reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities","T1595 - T1590 - T1592 - T1596 - T1598 - T1046 - T1599 - T1213 - T1597","TA0043 - TA0042 - TA0007 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/six2dez/reconftw","1","1","#linux","N/A","7","10","6202","982","2025-04-22T13:01:31Z","2020-12-30T23:52:52Z","8996" +"*/n1nj4sec/pupy*",".{0,1000}\/n1nj4sec\/pupy.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","8997" +"*/NachoVPN.git*",".{0,1000}\/NachoVPN\.git.{0,1000}","offensive_tool_keyword","NachoVPN","NachoVPN is a Proof of Concept that demonstrates exploitation of SSL-VPN clients using a rogue VPN serve","T1071 - T1027 - T1547 - T1204","TA0003 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/AmberWolfCyber/NachoVPN","1","1","N/A","N/A","7","3","218","28","2024-11-28T12:40:55Z","2024-10-30T15:53:56Z","8998" +"*/nachovpn:release*",".{0,1000}\/nachovpn\:release.{0,1000}","offensive_tool_keyword","NachoVPN","NachoVPN is a Proof of Concept that demonstrates exploitation of SSL-VPN clients using a rogue VPN serve","T1071 - T1027 - T1547 - T1204","TA0003 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/AmberWolfCyber/NachoVPN","1","1","N/A","N/A","7","3","218","28","2024-11-28T12:40:55Z","2024-10-30T15:53:56Z","8999" +"*/nachovpn-1.0.0-py3-none-any.whl*",".{0,1000}\/nachovpn\-1\.0\.0\-py3\-none\-any\.whl.{0,1000}","offensive_tool_keyword","NachoVPN","NachoVPN is a Proof of Concept that demonstrates exploitation of SSL-VPN clients using a rogue VPN serve","T1071 - T1027 - T1547 - T1204","TA0003 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/AmberWolfCyber/NachoVPN","1","1","N/A","N/A","7","3","218","28","2024-11-28T12:40:55Z","2024-10-30T15:53:56Z","9000" +"*/NamedPipeMaster.git*",".{0,1000}\/NamedPipeMaster\.git.{0,1000}","offensive_tool_keyword","NamedPipeMaster","a tool used to analyze monitor and interact with named pipes - allows dll injection and impersonation","T1055.001 - T1134.001 - T1010 - T1550.002","TA0007 - TA0008 - TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/zeze-zeze/NamedPipeMaster","1","1","N/A","N/A","9","2","161","15","2024-10-27T05:24:11Z","2024-08-23T02:03:44Z","9001" +"*/NamedPipeMaster/tarball/*",".{0,1000}\/NamedPipeMaster\/tarball\/.{0,1000}","offensive_tool_keyword","NamedPipeMaster","a tool used to analyze monitor and interact with named pipes - allows dll injection and impersonation","T1055.001 - T1134.001 - T1010 - T1550.002","TA0007 - TA0008 - TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/zeze-zeze/NamedPipeMaster","1","1","N/A","N/A","9","2","161","15","2024-10-27T05:24:11Z","2024-08-23T02:03:44Z","9002" +"*/NamedPipeMaster/zipball/*",".{0,1000}\/NamedPipeMaster\/zipball\/.{0,1000}","offensive_tool_keyword","NamedPipeMaster","a tool used to analyze monitor and interact with named pipes - allows dll injection and impersonation","T1055.001 - T1134.001 - T1010 - T1550.002","TA0007 - TA0008 - TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/zeze-zeze/NamedPipeMaster","1","1","N/A","N/A","9","2","161","15","2024-10-27T05:24:11Z","2024-08-23T02:03:44Z","9003" +"*/NamedPipeMasterBase/*",".{0,1000}\/NamedPipeMasterBase\/.{0,1000}","offensive_tool_keyword","NamedPipeMaster","a tool used to analyze monitor and interact with named pipes - allows dll injection and impersonation","T1055.001 - T1134.001 - T1010 - T1550.002","TA0007 - TA0008 - TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/zeze-zeze/NamedPipeMaster","1","1","N/A","N/A","9","2","161","15","2024-10-27T05:24:11Z","2024-08-23T02:03:44Z","9004" +"*/NamelessC2.git*",".{0,1000}\/NamelessC2\.git.{0,1000}","offensive_tool_keyword","NamelessC2","A C2 with all its components written in Rust","T1102 - T1573.001 - T1027 - T1219 - T1205","TA0011 - TA0003 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/trickster0/NamelessC2","1","1","N/A","N/A","10","10","266","33","2024-09-26T21:21:20Z","2024-09-26T21:06:37Z","9005" +"*/nanodump*",".{0,1000}\/nanodump.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","9008" +"*/nanodump.*",".{0,1000}\/nanodump\..{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","9009" +"*/nanodump.py*",".{0,1000}\/nanodump\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","9010" +"*/nanorobeus.git*",".{0,1000}\/nanorobeus\.git.{0,1000}","offensive_tool_keyword","nanorobeus","COFF file (BOF) for managing Kerberos tickets.","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","C2","https://github.com/wavvs/nanorobeus","1","1","N/A","N/A","10","10","294","31","2023-07-02T12:56:27Z","2022-07-04T00:33:30Z","9011" +"*/nanorubeus/*",".{0,1000}\/nanorubeus\/.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","9012" +"*/Native/SigFlip/*",".{0,1000}\/Native\/SigFlip\/.{0,1000}","offensive_tool_keyword","cobaltstrike","SigFlip is a tool for patching authenticode signed PE files (exe. dll. sys ..etc) without invalidating or breaking the existing signature.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/med0x2e/SigFlip","1","1","N/A","N/A","10","10","1139","197","2023-08-27T18:27:50Z","2021-08-08T15:59:19Z","9013" +"*/NativeBypassCredGuard.git*",".{0,1000}\/NativeBypassCredGuard\.git.{0,1000}","offensive_tool_keyword","NativeBypassCredGuard","Bypass Credential Guard by patching WDigest.dll using only NTAPI functions","T1558 - T1003.006","TA0006 - TA0005","N/A","N/A","Defense Evasion","https://github.com/ricardojoserf/NativeBypassCredGuard","1","1","N/A","N/A","7","3","236","28","2025-04-08T18:58:37Z","2024-12-01T16:58:03Z","9014" +"*/NativeDump.exe*",".{0,1000}\/NativeDump\.exe.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","1","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","9015" +"*/NativeDump.git*",".{0,1000}\/NativeDump\.git.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","1","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","9016" +"*/nat-pmp-info.nse*",".{0,1000}\/nat\-pmp\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9017" +"*/nat-pmp-mapport.nse*",".{0,1000}\/nat\-pmp\-mapport\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9018" +"*/navicatpwd.exe*",".{0,1000}\/navicatpwd\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","9020" +"*/nbd-info.nse*",".{0,1000}\/nbd\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9021" +"*/nbns-interfaces.nse*",".{0,1000}\/nbns\-interfaces\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9022" +"*/nbnsspoof.py*",".{0,1000}\/nbnsspoof\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","9023" +"*/nbstat.nse*",".{0,1000}\/nbstat\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9024" +"*/NBTNS.py*",".{0,1000}\/NBTNS\.py.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","N/A","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","9025" +"*/nc_srv.bat",".{0,1000}\/nc_srv\.bat","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","9026" +"*/nccgroup/nccfsas/*",".{0,1000}\/nccgroup\/nccfsas\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","9031" +"*/ncp-enum-users.nse*",".{0,1000}\/ncp\-enum\-users\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9032" +"*/ncp-serverinfo.nse*",".{0,1000}\/ncp\-serverinfo\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9033" +"*/ncrack.git*",".{0,1000}\/ncrack\.git.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","1","N/A","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","9035" +"*/ndmp-fs-info.nse*",".{0,1000}\/ndmp\-fs\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9036" +"*/ndmp-version.nse*",".{0,1000}\/ndmp\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9037" +"*/ndp_spoof*",".{0,1000}\/ndp_spoof.{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","9038" +"*/ndroRat Binder.exe*",".{0,1000}\/ndroRat\sBinder\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","9039" +"*/Necro-Stealer.git*",".{0,1000}\/Necro\-Stealer\.git.{0,1000}","offensive_tool_keyword","Necro-Stealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/Necro-Stealer","1","1","N/A","N/A","8","1","6","1","2022-12-06T16:06:55Z","2022-12-06T15:52:17Z","9040" +"*/Needle_Sift_BOF/*",".{0,1000}\/Needle_Sift_BOF\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Strstr with user-supplied needle and filename as a BOF.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/Needle_Sift_BOF","1","1","N/A","N/A","10","10","32","8","2021-09-27T22:57:33Z","2021-09-27T20:13:10Z","9041" +"*/Nemesis.git*",".{0,1000}\/Nemesis\.git.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","9042" +"*/nemesis_connector.py*",".{0,1000}\/nemesis_connector\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","9043" +"*/nemesis_db.py*",".{0,1000}\/nemesis_db\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","9044" +"*/nemesis_reg_collect_parser.py*",".{0,1000}\/nemesis_reg_collect_parser\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","9045" +"*/nemesis-cli.py*",".{0,1000}\/nemesis\-cli\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","9046" +"*/nessus.py*",".{0,1000}\/nessus\.py.{0,1000}","offensive_tool_keyword","crackmapexec","parser nessus.py from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9052" +"*/nessus.rb*",".{0,1000}\/nessus\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","9053" +"*/nessus-brute.nse*",".{0,1000}\/nessus\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9054" +"*/nessus-xmlrpc-brute.nse*",".{0,1000}\/nessus\-xmlrpc\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9055" +"*/net_4.0_32_RunasCs.exe*",".{0,1000}\/net_4\.0_32_RunasCs\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9056" +"*/net_4.0_32SharpDoor.exe*",".{0,1000}\/net_4\.0_32SharpDoor\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9057" +"*/net_4.0_32sharpfiles.exe*",".{0,1000}\/net_4\.0_32sharpfiles\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9058" +"*/net_4.0_64_RunasCs.exe*",".{0,1000}\/net_4\.0_64_RunasCs\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9059" +"*/net_4.0_64SharpDoor.exe*",".{0,1000}\/net_4\.0_64SharpDoor\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9060" +"*/net_4.0_64sharpfiles.exe*",".{0,1000}\/net_4\.0_64sharpfiles\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9061" +"*/net_4.0_Any_RunasCs.exe*",".{0,1000}\/net_4\.0_Any_RunasCs\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9062" +"*/net_4.0_AnySharpDoor.exe*",".{0,1000}\/net_4\.0_AnySharpDoor\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9063" +"*/net_4.0_Anysharpfiles.exe*",".{0,1000}\/net_4\.0_Anysharpfiles\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9064" +"*/net_4.5_32_RunasCs.exe*",".{0,1000}\/net_4\.5_32_RunasCs\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9065" +"*/net_4.5_32SharpDoor.exe*",".{0,1000}\/net_4\.5_32SharpDoor\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9066" +"*/net_4.5_32sharpfiles.exe*",".{0,1000}\/net_4\.5_32sharpfiles\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9067" +"*/net_4.5_64_RunasCs.exe*",".{0,1000}\/net_4\.5_64_RunasCs\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9068" +"*/net_4.5_64SharpDoor.exe*",".{0,1000}\/net_4\.5_64SharpDoor\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9069" +"*/net_4.5_64sharpfiles.exe*",".{0,1000}\/net_4\.5_64sharpfiles\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9070" +"*/net_4.5_Any_RunasCs.exe*",".{0,1000}\/net_4\.5_Any_RunasCs\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9071" +"*/net_4.5_AnySharpDoor.exe*",".{0,1000}\/net_4\.5_AnySharpDoor\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9072" +"*/net_4.5_Anysharpfiles.exe*",".{0,1000}\/net_4\.5_Anysharpfiles\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9073" +"*/net_4.7_32_RunasCs.exe*",".{0,1000}\/net_4\.7_32_RunasCs\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9074" +"*/net_4.7_64_RunasCs.exe*",".{0,1000}\/net_4\.7_64_RunasCs\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9075" +"*/net_4.7_Any_RunasCs.exe*",".{0,1000}\/net_4\.7_Any_RunasCs\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9076" +"*/net_portscan.py*",".{0,1000}\/net_portscan\.py.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","9077" +"*/net_recon/*",".{0,1000}\/net_recon\/.{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","9078" +"*/net_sniff.*",".{0,1000}\/net_sniff\..{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","9079" +"*/net_sniff_*.*",".{0,1000}\/net_sniff_.{0,1000}\..{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","9080" +"*/NETAMSI.ps1*",".{0,1000}\/NETAMSI\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","9081" +"*/netbus-auth-bypass.nse*",".{0,1000}\/netbus\-auth\-bypass\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9082" +"*/netbus-brute.nse*",".{0,1000}\/netbus\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9083" +"*/netbus-info.nse*",".{0,1000}\/netbus\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9084" +"*/netbus-version.nse*",".{0,1000}\/netbus\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9085" +"*/NetClone.exe*",".{0,1000}\/NetClone\.exe.{0,1000}","offensive_tool_keyword","Koppeling","Adaptive DLL hijacking / dynamic export forwarding","T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/monoxgas/Koppeling","1","1","N/A","N/A","8","8","748","128","2020-07-06T14:47:57Z","2020-02-18T21:08:16Z","9087" +"*/netcreds.py*",".{0,1000}\/netcreds\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","9088" +"*/netcreds.py*",".{0,1000}\/netcreds\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","9089" +"*/NetExec.git*",".{0,1000}\/NetExec\.git.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","9090" +"*/netexec.py*",".{0,1000}\/netexec\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","9091" +"*/NetExec-main*",".{0,1000}\/NetExec\-main.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","9092" +"*/Net-GPPPassword.exe*",".{0,1000}\/Net\-GPPPassword\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","9093" +"*/Net-GPPPassword.git*",".{0,1000}\/Net\-GPPPassword\.git.{0,1000}","offensive_tool_keyword","Net-GPPPassword",".NET implementation of Get-GPPPassword. Retrieves the plaintext password and other information for accounts pushed through Group Policy Preferences.","T1059.001 - T1552.007","TA0002 - TA0006","N/A","N/A","Credential Access","https://github.com/outflanknl/Net-GPPPassword","1","1","N/A","N/A","10","2","172","36","2019-12-18T10:14:32Z","2019-10-14T12:35:46Z","9094" +"*/nethunter-images/*",".{0,1000}\/nethunter\-images\/.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","9095" +"*/netkit.git*",".{0,1000}\/netkit\.git.{0,1000}","offensive_tool_keyword","netkit","Netkit is a purposefully small rootkit which can be used by clients over network to maintain a sneaky foothold into a device.","T1547 - T1021 - T1071 - T1562.001 - T1055 - T1041 - T1105","TA0003 - TA0005 - TA0002 - TA0007 - TA0009 - TA0040","N/A","N/A","Defense Evasion","https://github.com/Notselwyn/netkit","1","1","N/A","N/A","10","1","30","7","2024-03-27T19:07:03Z","2023-07-19T00:00:45Z","9096" +"*/netkit/client/shell.py*",".{0,1000}\/netkit\/client\/shell\.py.{0,1000}","offensive_tool_keyword","netkit","Netkit is a purposefully small rootkit which can be used by clients over network to maintain a sneaky foothold into a device.","T1547 - T1021 - T1071 - T1562.001 - T1055 - T1041 - T1105","TA0003 - TA0005 - TA0002 - TA0007 - TA0009 - TA0040","N/A","N/A","Defense Evasion","https://github.com/Notselwyn/netkit","1","1","N/A","N/A","10","1","30","7","2024-03-27T19:07:03Z","2023-07-19T00:00:45Z","9097" +"*/netkit/src/netkit.*",".{0,1000}\/netkit\/src\/netkit\..{0,1000}","offensive_tool_keyword","netkit","Netkit is a purposefully small rootkit which can be used by clients over network to maintain a sneaky foothold into a device.","T1547 - T1021 - T1071 - T1562.001 - T1055 - T1041 - T1105","TA0003 - TA0005 - TA0002 - TA0007 - TA0009 - TA0040","N/A","N/A","Defense Evasion","https://github.com/Notselwyn/netkit","1","1","N/A","N/A","10","1","30","7","2024-03-27T19:07:03Z","2023-07-19T00:00:45Z","9098" +"*/NetLoader.git*",".{0,1000}\/NetLoader\.git.{0,1000}","offensive_tool_keyword","NetLoader","Loads any C# binary in memory - patching AMSI + ETW","T1055.012 - T1112 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Flangvik/NetLoader","1","1","N/A","N/A","10","9","820","147","2021-10-03T16:41:03Z","2020-05-05T15:20:16Z","9099" +"*/netntlm.pl*",".{0,1000}\/netntlm\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","9100" +"*/NetNTLMtoSilverTicket*",".{0,1000}\/NetNTLMtoSilverTicket.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","1","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","9101" +"*/NetRipper.dll*",".{0,1000}\/NetRipper\.dll.{0,1000}","offensive_tool_keyword","NetRipper","NetRipper - Smart traffic sniffing for penetration testers","T1173 - T1557 - T1573.001 - T1056.001","TA0009 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/NytroRST/NetRipper","1","1","N/A","N/A","10","10","1368","318","2022-06-17T21:08:54Z","2015-07-14T20:31:04Z","9102" +"*/NetRipper.exe*",".{0,1000}\/NetRipper\.exe.{0,1000}","offensive_tool_keyword","NetRipper","NetRipper - Smart traffic sniffing for penetration testers","T1173 - T1557 - T1573.001 - T1056.001","TA0009 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/NytroRST/NetRipper","1","1","N/A","N/A","10","10","1368","318","2022-06-17T21:08:54Z","2015-07-14T20:31:04Z","9103" +"*/NetRipper.git*",".{0,1000}\/NetRipper\.git.{0,1000}","offensive_tool_keyword","NetRipper","NetRipper - Smart traffic sniffing for penetration testers","T1173 - T1557 - T1573.001 - T1056.001","TA0009 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/NytroRST/NetRipper","1","1","N/A","N/A","10","10","1368","318","2022-06-17T21:08:54Z","2015-07-14T20:31:04Z","9104" +"*/NetRipper.x64.exe*",".{0,1000}\/NetRipper\.x64\.exe.{0,1000}","offensive_tool_keyword","NetRipper","NetRipper - Smart traffic sniffing for penetration testers","T1173 - T1557 - T1573.001 - T1056.001","TA0009 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/NytroRST/NetRipper","1","1","N/A","N/A","10","10","1368","318","2022-06-17T21:08:54Z","2015-07-14T20:31:04Z","9105" +"*/NetRipper.x86.exe*",".{0,1000}\/NetRipper\.x86\.exe.{0,1000}","offensive_tool_keyword","NetRipper","NetRipper - Smart traffic sniffing for penetration testers","T1173 - T1557 - T1573.001 - T1056.001","TA0009 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/NytroRST/NetRipper","1","1","N/A","N/A","10","10","1368","318","2022-06-17T21:08:54Z","2015-07-14T20:31:04Z","9106" +"*/NetSess.exe*",".{0,1000}\/NetSess\.exe.{0,1000}","offensive_tool_keyword","NetSess","Command line tool to enumerate NetBIOS sessions on a specified local or remote machine. ","T1016 - T1046 - T1087","TA0007 - TA0043","N/A","MUSTANG PANDA","Discovery","https://www.joeware.net/freetools/tools/netsess/","1","1","N/A","N/A","7","9","N/A","N/A","N/A","N/A","9114" +"*/NetSess.zip*",".{0,1000}\/NetSess\.zip.{0,1000}","offensive_tool_keyword","NetSess","Command line tool to enumerate NetBIOS sessions on a specified local or remote machine. ","T1016 - T1046 - T1087","TA0007 - TA0043","N/A","MUSTANG PANDA","Discovery","https://www.joeware.net/freetools/tools/netsess/","1","1","N/A","N/A","7","9","N/A","N/A","N/A","N/A","9115" +"*/NetshHelperBeacon.git*",".{0,1000}\/NetshHelperBeacon\.git.{0,1000}","offensive_tool_keyword","NetshHelperBeacon","DLL to load from Windows NetShell. Will pop calc and execute shellcode.","T1055 - T1218","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/outflanknl/NetshHelperBeacon","1","1","N/A","N/A","10","2","179","36","2016-09-26T19:57:08Z","2016-09-26T12:52:02Z","9116" +"*/netsparker.rb*",".{0,1000}\/netsparker\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","9118" +"*/netstat_windows.go*",".{0,1000}\/netstat_windows\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","9119" +"*/nettitude/*",".{0,1000}\/nettitude\/.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","9120" +"*/nettitude/RunOF/*",".{0,1000}\/nettitude\/RunOF\/.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool to run object files mainly beacon object files (BOF) in .Net.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nettitude/RunOF","1","1","N/A","N/A","10","10","145","21","2023-01-06T15:30:05Z","2022-02-21T13:53:39Z","9121" +"*/NetUser.cpp*",".{0,1000}\/NetUser\.cpp.{0,1000}","offensive_tool_keyword","cobaltstrike","Use windows api to add users which can be used when net is unavailable","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/lengjibo/NetUser","1","1","N/A","N/A","10","10","420","90","2021-09-29T14:22:09Z","2020-01-09T08:33:27Z","9122" +"*/NetUser.exe*",".{0,1000}\/NetUser\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Use windows api to add users which can be used when net is unavailable","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/lengjibo/NetUser","1","1","N/A","N/A","10","10","420","90","2021-09-29T14:22:09Z","2020-01-09T08:33:27Z","9123" +"*/netuserenum/*",".{0,1000}\/netuserenum\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","9124" +"*/netview.py*",".{0,1000}\/netview\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","9125" +"*/network/bloodhound3*",".{0,1000}\/network\/bloodhound3.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","9126" +"*/Network/PortScan/*",".{0,1000}\/Network\/PortScan\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Various Cobalt Strike BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rvrsh3ll/BOF_Collection","1","1","N/A","N/A","10","10","635","57","2022-10-16T13:57:18Z","2020-07-16T18:24:55Z","9127" +"*/NetworkFileManagerPHP.php*",".{0,1000}\/NetworkFileManagerPHP\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","9128" +"*/NewPhish.ps1*",".{0,1000}\/NewPhish\.ps1.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","9129" +"*/nexpose-brute.nse*",".{0,1000}\/nexpose\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9130" +"*/nfs-ls.nse*",".{0,1000}\/nfs\-ls\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9131" +"*/nfs-showmount.nse*",".{0,1000}\/nfs\-showmount\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9132" +"*/nfs-statfs.nse*",".{0,1000}\/nfs\-statfs\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9133" +"*/nginxed-root.sh*",".{0,1000}\/nginxed\-root\.sh.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","9134" +"*/Ngrok-Disk.dll*",".{0,1000}\/Ngrok\-Disk\.dll.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","9141" +"*/Ngrok-Install.dll*",".{0,1000}\/Ngrok\-Install\.dll.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","9142" +"*/NiceRAT.git*",".{0,1000}\/NiceRAT\.git.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","1","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","9144" +"*/NiceRAT.py*",".{0,1000}\/NiceRAT\.py.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","1","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","9145" +"*/NiceRAT-1.0.0.zip*",".{0,1000}\/NiceRAT\-1\.0\.0\.zip.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","1","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","9146" +"*/nidem/kerberoast*",".{0,1000}\/nidem\/kerberoast.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","1","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","9147" +"*/Nidhogg.cpp*",".{0,1000}\/Nidhogg\.cpp.{0,1000}","offensive_tool_keyword","Nidhogg","Nidhogg is an all-in-one simple to use rootkit for red teams.","T1055 - T1055.012 - T1574 - T1574.002 - T1056 - T1056.001 - T1027 - T1027.002 - T1112 - T1050 - T1106 - T1554 - T1554.002 - T1134 - T1134.001 - T1037 - T1037.001 - T1053 - T1053.005 - T1055.011 - T1098 - T1098.003 - T1070.001 - T1070.002 - T1070.003 - T1070.004 - T1070.006 - T1070.007 - T1070.008 - T1070.009 - T1083 - T1113 - T1113.001 - T1125 - T1125.001 - T1482 - T1489 - T1490 - T1497 - T1497.001 - T1497.002 - T1497.003 - T1498 - T1498.001 - T1498.002 - T1499 - T1499.001 - T1499.002 - T1499.003 - T1499.004 - T1499.005 - T1562 - T1562.001 - T1562.003 - T1562.004 - T1562.006 - T1562.007 - T1562.008 - T1562.009 - T1562.010 - T1562.011 - T1562.012","TA0005 - TA0003 - TA0004 - TA0006 - TA0009 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/Idov31/Nidhogg","1","1","N/A","N/A","10","10","1946","284","2025-04-19T14:28:47Z","2022-05-29T14:37:50Z","9148" +"*/Nidhogg.exe*",".{0,1000}\/Nidhogg\.exe.{0,1000}","offensive_tool_keyword","Nidhogg","Nidhogg is an all-in-one simple to use rootkit for red teams.","T1055 - T1055.012 - T1574 - T1574.002 - T1056 - T1056.001 - T1027 - T1027.002 - T1112 - T1050 - T1106 - T1554 - T1554.002 - T1134 - T1134.001 - T1037 - T1037.001 - T1053 - T1053.005 - T1055.011 - T1098 - T1098.003 - T1070.001 - T1070.002 - T1070.003 - T1070.004 - T1070.006 - T1070.007 - T1070.008 - T1070.009 - T1083 - T1113 - T1113.001 - T1125 - T1125.001 - T1482 - T1489 - T1490 - T1497 - T1497.001 - T1497.002 - T1497.003 - T1498 - T1498.001 - T1498.002 - T1499 - T1499.001 - T1499.002 - T1499.003 - T1499.004 - T1499.005 - T1562 - T1562.001 - T1562.003 - T1562.004 - T1562.006 - T1562.007 - T1562.008 - T1562.009 - T1562.010 - T1562.011 - T1562.012","TA0005 - TA0003 - TA0004 - TA0006 - TA0009 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/Idov31/Nidhogg","1","1","N/A","N/A","10","10","1946","284","2025-04-19T14:28:47Z","2022-05-29T14:37:50Z","9149" +"*/Nidhogg.git*",".{0,1000}\/Nidhogg\.git.{0,1000}","offensive_tool_keyword","Nidhogg","Nidhogg is an all-in-one simple to use rootkit for red teams.","T1055 - T1055.012 - T1574 - T1574.002 - T1056 - T1056.001 - T1027 - T1027.002 - T1112 - T1050 - T1106 - T1554 - T1554.002 - T1134 - T1134.001 - T1037 - T1037.001 - T1053 - T1053.005 - T1055.011 - T1098 - T1098.003 - T1070.001 - T1070.002 - T1070.003 - T1070.004 - T1070.006 - T1070.007 - T1070.008 - T1070.009 - T1083 - T1113 - T1113.001 - T1125 - T1125.001 - T1482 - T1489 - T1490 - T1497 - T1497.001 - T1497.002 - T1497.003 - T1498 - T1498.001 - T1498.002 - T1499 - T1499.001 - T1499.002 - T1499.003 - T1499.004 - T1499.005 - T1562 - T1562.001 - T1562.003 - T1562.004 - T1562.006 - T1562.007 - T1562.008 - T1562.009 - T1562.010 - T1562.011 - T1562.012","TA0005 - TA0003 - TA0004 - TA0006 - TA0009 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/Idov31/Nidhogg","1","1","N/A","N/A","10","10","1946","284","2025-04-19T14:28:47Z","2022-05-29T14:37:50Z","9150" +"*/Nidhogg.zip*",".{0,1000}\/Nidhogg\.zip.{0,1000}","offensive_tool_keyword","Nidhogg","Nidhogg is an all-in-one simple to use rootkit for red teams.","T1055 - T1055.012 - T1574 - T1574.002 - T1056 - T1056.001 - T1027 - T1027.002 - T1112 - T1050 - T1106 - T1554 - T1554.002 - T1134 - T1134.001 - T1037 - T1037.001 - T1053 - T1053.005 - T1055.011 - T1098 - T1098.003 - T1070.001 - T1070.002 - T1070.003 - T1070.004 - T1070.006 - T1070.007 - T1070.008 - T1070.009 - T1083 - T1113 - T1113.001 - T1125 - T1125.001 - T1482 - T1489 - T1490 - T1497 - T1497.001 - T1497.002 - T1497.003 - T1498 - T1498.001 - T1498.002 - T1499 - T1499.001 - T1499.002 - T1499.003 - T1499.004 - T1499.005 - T1562 - T1562.001 - T1562.003 - T1562.004 - T1562.006 - T1562.007 - T1562.008 - T1562.009 - T1562.010 - T1562.011 - T1562.012","TA0005 - TA0003 - TA0004 - TA0006 - TA0009 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/Idov31/Nidhogg","1","1","N/A","N/A","10","10","1946","284","2025-04-19T14:28:47Z","2022-05-29T14:37:50Z","9151" +"*/NidhoggClient.exe*",".{0,1000}\/NidhoggClient\.exe.{0,1000}","offensive_tool_keyword","Nidhogg","Nidhogg is an all-in-one simple to use rootkit for red teams.","T1055 - T1055.012 - T1574 - T1574.002 - T1056 - T1056.001 - T1027 - T1027.002 - T1112 - T1050 - T1106 - T1554 - T1554.002 - T1134 - T1134.001 - T1037 - T1037.001 - T1053 - T1053.005 - T1055.011 - T1098 - T1098.003 - T1070.001 - T1070.002 - T1070.003 - T1070.004 - T1070.006 - T1070.007 - T1070.008 - T1070.009 - T1083 - T1113 - T1113.001 - T1125 - T1125.001 - T1482 - T1489 - T1490 - T1497 - T1497.001 - T1497.002 - T1497.003 - T1498 - T1498.001 - T1498.002 - T1499 - T1499.001 - T1499.002 - T1499.003 - T1499.004 - T1499.005 - T1562 - T1562.001 - T1562.003 - T1562.004 - T1562.006 - T1562.007 - T1562.008 - T1562.009 - T1562.010 - T1562.011 - T1562.012","TA0005 - TA0003 - TA0004 - TA0006 - TA0009 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/Idov31/Nidhogg","1","1","N/A","N/A","10","10","1946","284","2025-04-19T14:28:47Z","2022-05-29T14:37:50Z","9152" +"*/NidhoggClient/*",".{0,1000}\/NidhoggClient\/.{0,1000}","offensive_tool_keyword","Nidhogg","Nidhogg is an all-in-one simple to use rootkit for red teams.","T1055 - T1055.012 - T1574 - T1574.002 - T1056 - T1056.001 - T1027 - T1027.002 - T1112 - T1050 - T1106 - T1554 - T1554.002 - T1134 - T1134.001 - T1037 - T1037.001 - T1053 - T1053.005 - T1055.011 - T1098 - T1098.003 - T1070.001 - T1070.002 - T1070.003 - T1070.004 - T1070.006 - T1070.007 - T1070.008 - T1070.009 - T1083 - T1113 - T1113.001 - T1125 - T1125.001 - T1482 - T1489 - T1490 - T1497 - T1497.001 - T1497.002 - T1497.003 - T1498 - T1498.001 - T1498.002 - T1499 - T1499.001 - T1499.002 - T1499.003 - T1499.004 - T1499.005 - T1562 - T1562.001 - T1562.003 - T1562.004 - T1562.006 - T1562.007 - T1562.008 - T1562.009 - T1562.010 - T1562.011 - T1562.012","TA0005 - TA0003 - TA0004 - TA0006 - TA0009 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/Idov31/Nidhogg","1","1","N/A","N/A","10","10","1946","284","2025-04-19T14:28:47Z","2022-05-29T14:37:50Z","9153" +"*/nightCrawler.ps1*",".{0,1000}\/nightCrawler\.ps1.{0,1000}","offensive_tool_keyword","DataBouncing","Data Bouncing is a technique for transmitting data between two endpoints using DNS lookups and HTTP header manipulation","T1048 - T1041","TA0010","N/A","N/A","Data Exfiltration","https://github.com/Unit-259/DataBouncing","1","1","N/A","N/A","9","1","15","0","2025-03-12T07:34:04Z","2025-03-12T06:58:51Z","9154" +"*/Nightmangle.git*",".{0,1000}\/Nightmangle\.git.{0,1000}","offensive_tool_keyword","Nightmangle","ightmangle is post-exploitation Telegram Command and Control (C2/C&C) Agent","T1105 - T1132 - T1071.001","TA0011 - TA0009 - TA0002","N/A","N/A","C2","https://github.com/1N73LL1G3NC3x/Nightmangle","1","1","N/A","N/A","10","10","156","19","2023-09-26T19:21:31Z","2023-09-26T18:25:23Z","9155" +"*/nikto.git*",".{0,1000}\/nikto\.git.{0,1000}","offensive_tool_keyword","nikto","Nikto web server scanner","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/sullo/nikto","1","1","#linux","N/A","N/A","10","9184","1306","2025-02-22T14:30:28Z","2012-11-24T04:24:29Z","9156" +"*/nikto.pl*",".{0,1000}\/nikto\.pl.{0,1000}","offensive_tool_keyword","nikto","Nikto web scanner tool","T1210.001 - T1190 - T1046 - T1222","TA0007 - TA0002 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/sullo/nikto","1","1","#linux","N/A","N/A","10","9184","1306","2025-02-22T14:30:28Z","2012-11-24T04:24:29Z","9157" +"*/nikto.pl*",".{0,1000}\/nikto\.pl.{0,1000}","offensive_tool_keyword","nikto","Nikto web server scanner","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/sullo/nikto","1","1","#linux","N/A","N/A","10","9184","1306","2025-02-22T14:30:28Z","2012-11-24T04:24:29Z","9158" +"*/NimBlackout*",".{0,1000}\/NimBlackout.{0,1000}","offensive_tool_keyword","NimBlackout","Kill AV/EDR leveraging BYOVD attack","T1562.001 - T1055.001 - T1055.012","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/Helixo32/NimBlackout","1","1","N/A","N/A","N/A","4","352","42","2023-07-11T07:32:50Z","2023-07-06T18:40:02Z","9159" +"*/NimBlackout*",".{0,1000}\/NimBlackout.{0,1000}","offensive_tool_keyword","NimBlackout","Kill AV/EDR leveraging BYOVD attack","T1562.001 - T1055.001 - T1055.012","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/Helixo32/NimBlackout","1","1","N/A","N/A","N/A","4","352","42","2023-07-11T07:32:50Z","2023-07-06T18:40:02Z","9160" +"*/NimBlackout*",".{0,1000}\/NimBlackout.{0,1000}","offensive_tool_keyword","NimBlackout","Kill AV/EDR leveraging BYOVD attack","T1562.001 - T1055.001 - T1055.012","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/Helixo32/NimBlackout","1","1","N/A","N/A","N/A","4","352","42","2023-07-11T07:32:50Z","2023-07-06T18:40:02Z","9161" +"*/nimcrypt.nim*",".{0,1000}\/nimcrypt\.nim.{0,1000}","offensive_tool_keyword","nimcrypt","Nimcrypt is a .NET PE Crypter written in Nim based entirely on the work of @byt3bl33d3r's OffensiveNim project","T1027 - T1055 - T1099 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/icyguider/nimcrypt","1","1","N/A","N/A","N/A","1","98","7","2021-03-25T00:27:12Z","2021-03-24T17:51:52Z","9163" +"*/nimcrypt/*",".{0,1000}\/nimcrypt\/.{0,1000}","offensive_tool_keyword","nimcrypt","Nimcrypt is a .NET PE Crypter written in Nim based entirely on the work of @byt3bl33d3r's OffensiveNim project","T1027 - T1055 - T1099 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/icyguider/nimcrypt","1","1","N/A","N/A","N/A","1","98","7","2021-03-25T00:27:12Z","2021-03-24T17:51:52Z","9164" +"*/Nimcrypt2*",".{0,1000}\/Nimcrypt2.{0,1000}","offensive_tool_keyword","Nimcrypt2",".NET PE & Raw Shellcode Packer/Loader Written in Nim","T1027 - T1202 - T1059.005 - T1105 - T1045","TA0005 - TA0011 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/icyguider/Nimcrypt2","1","1","N/A","N/A","N/A","8","771","124","2023-01-20T22:07:15Z","2022-02-23T15:43:16Z","9165" +"*/NimDllSideload.git*",".{0,1000}\/NimDllSideload\.git.{0,1000}","offensive_tool_keyword","NimDllSideload","DLL sideloading/proxying","T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/byt3bl33d3r/NimDllSideload","1","1","N/A","N/A","9","2","167","17","2022-12-04T21:52:49Z","2022-12-03T03:25:57Z","9166" +"*/NimDllSideload/*",".{0,1000}\/NimDllSideload\/.{0,1000}","offensive_tool_keyword","NimDllSideload","DLL sideloading/proxying","T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/byt3bl33d3r/NimDllSideload","1","1","N/A","N/A","9","2","167","17","2022-12-04T21:52:49Z","2022-12-03T03:25:57Z","9167" +"*/NimExec.git*",".{0,1000}\/NimExec\.git.{0,1000}","offensive_tool_keyword","NimExec","Fileless Command Execution for Lateral Movement in Nim","T1021.006 - T1059.005 - T1564.001","TA0008 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/frkngksl/NimExec","1","1","N/A","N/A","N/A","4","372","38","2023-12-12T06:59:59Z","2023-04-21T19:46:53Z","9168" +"*/Nimperiments.git*",".{0,1000}\/Nimperiments\.git.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","9169" +"*/NimPlant.*",".{0,1000}\/NimPlant\..{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","9170" +"*/NimPlant/*",".{0,1000}\/NimPlant\/.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","9171" +"*/nimplants/*",".{0,1000}\/nimplants\/.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","9172" +"*/nimproxydll.git*",".{0,1000}\/nimproxydll\.git.{0,1000}","offensive_tool_keyword","nimproxydll","A Docker container for byt3bl33d3r/NimDllSideload - DLL sideloading/proxying","T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/cyllective/nimproxydll","1","1","N/A","N/A","9","1","10","0","2024-05-26T17:34:01Z","2024-03-15T15:15:45Z","9173" +"*/nimproxydll/*",".{0,1000}\/nimproxydll\/.{0,1000}","offensive_tool_keyword","nimproxydll","A Docker container for byt3bl33d3r/NimDllSideload - DLL sideloading/proxying","T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/cyllective/nimproxydll","1","1","N/A","N/A","9","1","10","0","2024-05-26T17:34:01Z","2024-03-15T15:15:45Z","9174" +"*/ninja.crt*",".{0,1000}\/ninja\.crt.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","9178" +"*/Ninja.git*",".{0,1000}\/Ninja\.git.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","9179" +"*/ninja.key*",".{0,1000}\/ninja\.key.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","9180" +"*/Ninja.py*",".{0,1000}\/Ninja\.py.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","9181" +"*/nipe.pl",".{0,1000}\/nipe\.pl","offensive_tool_keyword","nipe","An engine to make Tor Network your default gateway.","T1560 - T1573 - T1578","TA0005 - TA0007","N/A","N/A","Data Exfiltration","https://github.com/htrgouvea/nipe","1","1","N/A","N/A","N/A","10","2029","321","2025-04-03T13:57:13Z","2015-09-07T18:47:10Z","9183" +"*/nishang*",".{0,1000}\/nishang.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security. penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","9188" +"*/nishang/*",".{0,1000}\/nishang\/.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","9189" +"*/NIX REMOTE WEB-SHELL.php*",".{0,1000}\/NIX\sREMOTE\sWEB\-SHELL\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","9190" +"*/nje-node-brute.nse*",".{0,1000}\/nje\-node\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9191" +"*/nje-pass-brute.nse*",".{0,1000}\/nje\-pass\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9192" +"*/NJRAT 7.exe*",".{0,1000}\/NJRAT\s7\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1071.001 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1555.003 - T1132.001 - T1005 - T1568.001 - T1041 - T1083 - T1562.004 - T1070.004 - T1070.009 - T1105 - T1056.001 - T1112 - T1106 - T1571 - T1027.004 - T1027.013 - T1120 - T1057 - T1012 - T1021.001 - T1018 - T1091 - T1113 - T1082 - T1033 - T1125","TA0002 - TA0003 - TA0005 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Transparent Tribe - Group5 - Aquatic Panda - APT41 - LazyScripter - Gorgon Group - TA2541 - APT-C-36","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","9193" +"*/NLBrute*.rar*",".{0,1000}\/NLBrute.{0,1000}\.rar.{0,1000}","offensive_tool_keyword","NLBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/amazond/NLBrute-1.2","1","1","N/A","N/A","10","1","1","2","2023-12-21T12:25:54Z","2023-12-21T12:22:27Z","9194" +"*/NLBrute*.zip*",".{0,1000}\/NLBrute.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","NLBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/amazond/NLBrute-1.2","1","1","N/A","N/A","10","1","1","2","2023-12-21T12:25:54Z","2023-12-21T12:22:27Z","9195" +"*/NLBrute.exe*",".{0,1000}\/NLBrute\.exe.{0,1000}","offensive_tool_keyword","NLBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/amazond/NLBrute-1.2","1","1","N/A","N/A","10","1","1","2","2023-12-21T12:25:54Z","2023-12-21T12:22:27Z","9196" +"*/nmap.py*",".{0,1000}\/nmap\.py.{0,1000}","offensive_tool_keyword","crackmapexec","parser nmap.py from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9197" +"*/nmap_smb_scan_all_*.txt*",".{0,1000}\/nmap_smb_scan_all_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","9201" +"*/nmapAnswerMachine.exe*",".{0,1000}\/nmapAnswerMachine\.exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","9202" +"*/nmapAnswerMachine.py*",".{0,1000}\/nmapAnswerMachine\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","9203" +"*/nntp-ntlm-info.nse*",".{0,1000}\/nntp\-ntlm\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9213" +"*/no_defender.exe*",".{0,1000}\/no_defender\.exe.{0,1000}","offensive_tool_keyword","no_defender","disable windows defender. (through the WSC api)","T1089","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/es3n1n/no-defender","1","1","N/A","N/A","10","10","1907","13","2024-06-08T01:29:18Z","2024-05-23T05:18:38Z","9214" +"*/NoAmci.exe*",".{0,1000}\/NoAmci\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","9215" +"*/NoArgs.exe*",".{0,1000}\/NoArgs\.exe.{0,1000}","offensive_tool_keyword","NoArgs","NoArgs is a tool designed to dynamically spoof and conceal process arguments while staying undetected. It achieves this by hooking into Windows APIs to dynamically manipulate the Windows internals on the go. This allows NoArgs to alter process arguments discreetly.","T1055 - T1574 - T1112 - T1056","TA0005 - TA0040 - TA0009","N/A","N/A","Defense Evasion","https://github.com/oh-az/NoArgs","1","1","N/A","N/A","8","2","151","25","2024-05-07T20:38:34Z","2024-03-15T16:54:49Z","9216" +"*/NoArgs.git*",".{0,1000}\/NoArgs\.git.{0,1000}","offensive_tool_keyword","NoArgs","NoArgs is a tool designed to dynamically spoof and conceal process arguments while staying undetected. It achieves this by hooking into Windows APIs to dynamically manipulate the Windows internals on the go. This allows NoArgs to alter process arguments discreetly.","T1055 - T1574 - T1112 - T1056","TA0005 - TA0040 - TA0009","N/A","N/A","Defense Evasion","https://github.com/oh-az/NoArgs","1","1","N/A","N/A","8","2","151","25","2024-05-07T20:38:34Z","2024-03-15T16:54:49Z","9217" +"*/No-Consolation.git*",".{0,1000}\/No\-Consolation\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a Beacon Object File (BOF) that executes unmanaged PEs inline and retrieves their output without allocating a console (i.e spawning conhost.exe)","T1055 - T1129","TA0005 - TA0003","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Defense Evasion","https://github.com/fortra/No-Consolation","1","1","N/A","N/A","9","6","593","68","2024-10-23T16:25:21Z","2023-11-06T22:01:42Z","9218" +"*/no-defender.git*",".{0,1000}\/no\-defender\.git.{0,1000}","offensive_tool_keyword","no_defender","disable windows defender. (through the WSC api)","T1089","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/es3n1n/no-defender","1","1","N/A","N/A","10","10","1907","13","2024-06-08T01:29:18Z","2024-05-23T05:18:38Z","9219" +"*/no-defender.sln*",".{0,1000}\/no\-defender\.sln.{0,1000}","offensive_tool_keyword","no_defender","disable windows defender. (through the WSC api)","T1089","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/es3n1n/no-defender","1","1","N/A","N/A","10","10","1907","13","2024-06-08T01:29:18Z","2024-05-23T05:18:38Z","9220" +"*/no-defender.vcxproj*",".{0,1000}\/no\-defender\.vcxproj.{0,1000}","offensive_tool_keyword","no_defender","disable windows defender. (through the WSC api)","T1089","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/es3n1n/no-defender","1","1","N/A","N/A","10","10","1907","13","2024-06-08T01:29:18Z","2024-05-23T05:18:38Z","9221" +"*/no-defender-loader.exe*",".{0,1000}\/no\-defender\-loader\.exe.{0,1000}","offensive_tool_keyword","no_defender","disable windows defender. (through the WSC api)","T1089","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/es3n1n/no-defender","1","1","N/A","N/A","10","10","1907","13","2024-06-08T01:29:18Z","2024-05-23T05:18:38Z","9222" +"*/no-defender-loader/main.cpp*",".{0,1000}\/no\-defender\-loader\/main\.cpp.{0,1000}","offensive_tool_keyword","no_defender","disable windows defender. (through the WSC api)","T1089","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/es3n1n/no-defender","1","1","N/A","N/A","10","10","1907","13","2024-06-08T01:29:18Z","2024-05-23T05:18:38Z","9223" +"*/NodeRelayConsoleExe_d64.exe*",".{0,1000}\/NodeRelayConsoleExe_d64\.exe.{0,1000}","offensive_tool_keyword","C3","Framework designed for red teams to create and manage custom C2 (Command and Control) channels. Unlike traditional C2 frameworks that rely on typical communication methods like HTTP/S DNS or TCP - C3 allows for the creation of non-traditional and esoteric C2 channels using platforms like Slack Dropbox GitHub OneDrive and more.","T1071 - T1102 - T1090 - T1573 - T1048","TA0011 - TA0002 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/WithSecureLabs/C3","1","1","N/A","N/A","9","10","1602","276","2023-03-04T20:32:13Z","2019-08-30T11:21:04Z","9224" +"*/Nofault.exe*",".{0,1000}\/Nofault\.exe.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","9225" +"*/NoFilter.cpp*",".{0,1000}\/NoFilter\.cpp.{0,1000}","offensive_tool_keyword","NoFilter","Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.","T1548 - T1548.002 - T1055 - T1055.004","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/deepinstinct/NoFilter","1","1","N/A","N/A","9","3","298","48","2024-10-29T07:30:35Z","2023-07-30T09:25:38Z","9226" +"*/NoFilter.exe*",".{0,1000}\/NoFilter\.exe.{0,1000}","offensive_tool_keyword","NoFilter","Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.","T1548 - T1548.002 - T1055 - T1055.004","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/deepinstinct/NoFilter","1","1","N/A","N/A","9","3","298","48","2024-10-29T07:30:35Z","2023-07-30T09:25:38Z","9227" +"*/NoFilter.git*",".{0,1000}\/NoFilter\.git.{0,1000}","offensive_tool_keyword","NoFilter","Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.","T1548 - T1548.002 - T1055 - T1055.004","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/deepinstinct/NoFilter","1","1","N/A","N/A","9","3","298","48","2024-10-29T07:30:35Z","2023-07-30T09:25:38Z","9228" +"*/NoFilter.sln*",".{0,1000}\/NoFilter\.sln.{0,1000}","offensive_tool_keyword","NoFilter","Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.","T1548 - T1548.002 - T1055 - T1055.004","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/deepinstinct/NoFilter","1","1","N/A","N/A","9","3","298","48","2024-10-29T07:30:35Z","2023-07-30T09:25:38Z","9229" +"*/NoFilter.vcxproj*",".{0,1000}\/NoFilter\.vcxproj.{0,1000}","offensive_tool_keyword","NoFilter","Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.","T1548 - T1548.002 - T1055 - T1055.004","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/deepinstinct/NoFilter","1","1","N/A","N/A","9","3","298","48","2024-10-29T07:30:35Z","2023-07-30T09:25:38Z","9230" +"*/nopac.py*",".{0,1000}\/nopac\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","9232" +"*/No-PowerShell.cs*",".{0,1000}\/No\-PowerShell\.cs.{0,1000}","offensive_tool_keyword","No-powershell","powershell script to C# (no-powershell)","T1059.001 - T1027 - T1500","TA0002 - TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/gtworek/PSBits/blob/master/Misc/No-PowerShell.cs","1","1","N/A","N/A","8","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","9233" +"*/NoPowerShell.exe*",".{0,1000}\/NoPowerShell\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","9234" +"*/NoPowerShell.exe*",".{0,1000}\/NoPowerShell\.exe.{0,1000}","offensive_tool_keyword","NoPowerShell","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","NoPowerShell","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","9235" +"*/NoPowerShell.exe*",".{0,1000}\/NoPowerShell\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","NoPowerShell","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","9236" +"*/No-PowerShell.exe*",".{0,1000}\/No\-PowerShell\.exe.{0,1000}","offensive_tool_keyword","No-powershell","powershell script to C# (no-powershell)","T1059.001 - T1027 - T1500","TA0002 - TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/gtworek/PSBits/blob/master/Misc/No-PowerShell.cs","1","1","N/A","N/A","8","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","9237" +"*/nopowershell.git*",".{0,1000}\/nopowershell\.git.{0,1000}","offensive_tool_keyword","nopowershell","NoPowerShell is a tool implemented in C# which supports executing PowerShell-like commands while remaining invisible to any PowerShell logging mechanisms. This .NET Framework 2 compatible binary can be loaded in Cobalt Strike to execute commands in-memory. No System.Management.Automation.dll is used. only native .NET libraries. An alternative usecase for NoPowerShell is to launch it as a DLL via rundll32.exe: rundll32 NoPowerShell.dll.main.","T1059 - T1086 - T1500 - T1564 - T1127 - T1027","TA0002 - TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","9238" +"*/nopowershell/*",".{0,1000}\/nopowershell\/.{0,1000}","offensive_tool_keyword","C2 related tools","PowerShell rebuilt in C# for Red Teaming purposes","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","9239" +"*/NoPowerShell/*",".{0,1000}\/NoPowerShell\/.{0,1000}","offensive_tool_keyword","nopowershell","NoPowerShell is a tool implemented in C# which supports executing PowerShell-like commands while remaining invisible to any PowerShell logging mechanisms. This .NET Framework 2 compatible binary can be loaded in Cobalt Strike to execute commands in-memory. No System.Management.Automation.dll is used. only native .NET libraries. An alternative usecase for NoPowerShell is to launch it as a DLL via rundll32.exe: rundll32 NoPowerShell.dll.main.","T1059 - T1086 - T1500 - T1564 - T1127 - T1027","TA0002 - TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","9240" +"*/norouteconfig.sh*",".{0,1000}\/norouteconfig\.sh.{0,1000}","offensive_tool_keyword","TunnelVision","TunnelVision uses DHCP option 121 to manipulate routing tables and decloak VPN traffic","T1557 - T1498.003","TA0009 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/leviathansecurity/TunnelVision","1","1","N/A","N/A","9","2","132","17","2024-05-08T19:40:13Z","2024-03-11T22:24:56Z","9241" +"*/noseyparker.git*",".{0,1000}\/noseyparker\.git.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","1","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","9242" +"*/NotQuite0DayFriday/zip/trunk*",".{0,1000}\/NotQuite0DayFriday\/zip\/trunk.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","9243" +"*/NovaLdr.exe",".{0,1000}\/NovaLdr\.exe","offensive_tool_keyword","NovaLdr","NovaLdr is a Threadless Module Stomping written in Rust designed as a learning project while exploring the world of malware development. It uses advanced techniques like indirect syscalls and string encryption to achieve its functionalities","T1027.001 - T1055.012 - T1112 - T1574.002 - T1055 - T1056.002 - T1027.002 - T1070.004 - T1129","TA0004 - TA0005 - TA0040 - TA0011","N/A","N/A","Defense Evasion","https://github.com/BlackSnufkin/NovaLdr","1","1","N/A","N/A","10","3","242","40","2024-06-29T10:34:48Z","2023-10-19T07:54:39Z","9244" +"*/NovaLdr.git*",".{0,1000}\/NovaLdr\.git.{0,1000}","offensive_tool_keyword","NovaLdr","NovaLdr is a Threadless Module Stomping written in Rust designed as a learning project while exploring the world of malware development. It uses advanced techniques like indirect syscalls and string encryption to achieve its functionalities","T1027.001 - T1055.012 - T1112 - T1574.002 - T1055 - T1056.002 - T1027.002 - T1070.004 - T1129","TA0004 - TA0005 - TA0040 - TA0011","N/A","N/A","Defense Evasion","https://github.com/BlackSnufkin/NovaLdr","1","1","N/A","N/A","10","3","242","40","2024-06-29T10:34:48Z","2023-10-19T07:54:39Z","9245" +"*/NoveLdr.exe",".{0,1000}\/NoveLdr\.exe","offensive_tool_keyword","NovaLdr","NovaLdr is a Threadless Module Stomping written in Rust designed as a learning project while exploring the world of malware development. It uses advanced techniques like indirect syscalls and string encryption to achieve its functionalities","T1027.001 - T1055.012 - T1112 - T1574.002 - T1055 - T1056.002 - T1027.002 - T1070.004 - T1129","TA0004 - TA0005 - TA0040 - TA0011","N/A","N/A","Defense Evasion","https://github.com/BlackSnufkin/NovaLdr","1","1","N/A","N/A","10","3","242","40","2024-06-29T10:34:48Z","2023-10-19T07:54:39Z","9246" +"*/nowsecure/dirtycow*",".{0,1000}\/nowsecure\/dirtycow.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirtycow vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/nowsecure/dirtycow","1","1","N/A","N/A","N/A","1","93","25","2019-05-13T13:17:31Z","2016-10-22T14:00:37Z","9250" +"*/nping-brute.nse*",".{0,1000}\/nping\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9251" +"*/NPPSPY.dll*",".{0,1000}\/NPPSPY\.dll.{0,1000}","offensive_tool_keyword","NPPSpy","Simple code for NPLogonNotify(). The function obtains logon data including cleartext password","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/blob/master/PasswordStealing/NPPSpy","1","1","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","9252" +"*/NPPSpy.exe*",".{0,1000}\/NPPSpy\.exe.{0,1000}","offensive_tool_keyword","NPPSpy","Simple code for NPLogonNotify(). The function obtains logon data including cleartext password","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/blob/master/PasswordStealing/NPPSpy","1","1","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","9253" +"*/nps/releases/download/*",".{0,1000}\/nps\/releases\/download\/.{0,1000}","offensive_tool_keyword","nps","chinese intranet penetration proxy server","T1090 - T1071 - T1102 - T1075 - T1133","TA0002 - TA0011 - TA0010","N/A","N/A","Defense Evasion","https://github.com/yisier/nps","1","1","N/A","N/A","9","10","2674","327","2025-04-17T09:43:50Z","2022-09-14T06:24:00Z","9254" +"*/nps_payload.git*",".{0,1000}\/nps_payload\.git.{0,1000}","offensive_tool_keyword","nps_payload","This script will generate payloads for basic intrusion detection avoidance","T1027 - T1027.005 - T1055 - T1211","TA0005 - TA0004","N/A","N/A","Exploitation tool","https://github.com/trustedsec/nps_payload","1","1","N/A","N/A","9","5","442","123","2023-11-30T09:24:13Z","2017-07-23T17:01:19Z","9255" +"*/nrpe-enum.nse*",".{0,1000}\/nrpe\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9257" +"*/nsa-rules.git*",".{0,1000}\/nsa\-rules\.git.{0,1000}","offensive_tool_keyword","nsa-rules","Password cracking rules and masks for hashcat that I generated from cracked passwords.","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/NSAKEY/nsa-rules","1","1","N/A","N/A","10","6","547","125","2017-01-03T11:53:25Z","2016-02-15T20:49:32Z","9258" +"*/nsocks.dll*",".{0,1000}\/nsocks\.dll.{0,1000}","offensive_tool_keyword","nsocks",".NET HttpClient proxy handler implementation for SOCKS proxies","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","Scattered Spider* - Black Basta","C2","https://github.com/bbepis/Nsocks","1","1","N/A","N/A","8","10","3","0","2020-06-08T17:25:07Z","2020-03-28T09:00:22Z","9261" +"*/NSocks.exe*",".{0,1000}\/NSocks\.exe.{0,1000}","offensive_tool_keyword","nsocks",".NET HttpClient proxy handler implementation for SOCKS proxies","T1090.002 - T1090 - T1071.001 - T1572","TA0011 - TA0005","N/A","Scattered Spider* - Black Basta","C2","https://github.com/bbepis/NSocks","1","1","N/A","N/A","9","10","3","0","2020-06-08T17:25:07Z","2020-03-28T09:00:22Z","9262" +"*/NSocks.git*",".{0,1000}\/NSocks\.git.{0,1000}","offensive_tool_keyword","nsocks",".NET HttpClient proxy handler implementation for SOCKS proxies","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","Scattered Spider* - Black Basta","C2","https://github.com/bbepis/Nsocks","1","1","N/A","N/A","8","10","3","0","2020-06-08T17:25:07Z","2020-03-28T09:00:22Z","9263" +"*/NSudo.bat*",".{0,1000}\/NSudo\.bat.{0,1000}","offensive_tool_keyword","Defeat-Defender","script to dismantle complete windows defender protection and even bypass tamper protection - Disable Windows-Defender Permanently.","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/swagkarna/Defeat-Defender-V1.2.0","1","1","N/A","N/A","10","10","1530","316","2023-10-20T17:55:09Z","2020-12-10T07:22:06Z","9266" +"*/NSudo.exe*",".{0,1000}\/NSudo\.exe.{0,1000}","offensive_tool_keyword","Defeat-Defender","script to dismantle complete windows defender protection and even bypass tamper protection - Disable Windows-Defender Permanently.","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/swagkarna/Defeat-Defender-V1.2.0","1","1","N/A","N/A","10","10","1530","316","2023-10-20T17:55:09Z","2020-12-10T07:22:06Z","9267" +"*/NSudo.exe*",".{0,1000}\/NSudo\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","9268" +"*/ntdissector.git*",".{0,1000}\/ntdissector\.git.{0,1000}","offensive_tool_keyword","ntdissector","Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.","T1003.003","TA0006 ","N/A","N/A","Credential Access","https://github.com/synacktiv/ntdissector","1","1","N/A","N/A","9","2","139","17","2024-08-16T14:18:35Z","2023-09-05T12:13:47Z","9271" +"*/ntdll_unhooking.exe*",".{0,1000}\/ntdll_unhooking\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","9273" +"*/ntdll_unhooking.exe*",".{0,1000}\/ntdll_unhooking\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","9274" +"*/ntdlll-unhooking-collection*",".{0,1000}\/ntdlll\-unhooking\-collection.{0,1000}","offensive_tool_keyword","ntdlll-unhooking-collection","unhooking ntdll from disk - from KnownDlls - from suspended process - from remote server (fileless)","T1055 - T1055.001 - T1070 - T1070.004 - T1101 - T1574 - T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/ntdlll-unhooking-collection","1","1","N/A","N/A","9","2","188","38","2023-08-02T02:26:33Z","2023-02-07T16:54:15Z","9275" +"*/NTDLLReflection.git*",".{0,1000}\/NTDLLReflection\.git.{0,1000}","offensive_tool_keyword","NTDLLReflection","Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll and trigger exported APIs from the export table","T1055.012 - T1574.002 - T1027.001 - T1218.011","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/NTDLLReflection","1","1","N/A","N/A","9","3","293","45","2023-08-02T02:21:43Z","2023-02-03T17:12:33Z","9276" +"*/NtdllUnpatcher.git*",".{0,1000}\/NtdllUnpatcher\.git.{0,1000}","offensive_tool_keyword","NtdllUnpatcher","code for EDR bypassing","T1070.004 - T1055.001 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Signal-Labs/NtdllUnpatcher","1","1","N/A","N/A","10","2","150","33","2019-03-07T11:10:40Z","2019-03-07T10:20:19Z","9277" +"*/ntds_dump_*.txt*",".{0,1000}\/ntds_dump_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","9278" +"*/ntdsuseraccount.py*",".{0,1000}\/ntdsuseraccount\.py.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","1","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","9279" +"*/ntdsutil.py*",".{0,1000}\/ntdsutil\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","9280" +"*/ntfs-read.py*",".{0,1000}\/ntfs\-read\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","9281" +"*/NTHASH-FPC.git*",".{0,1000}\/NTHASH\-FPC\.git.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","9282" +"*/ntlm.py*",".{0,1000}\/ntlm\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","9283" +"*/ntlmdecoder.py*",".{0,1000}\/ntlmdecoder\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","9284" +"*/ntlmdecoder.py*",".{0,1000}\/ntlmdecoder\.py.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","1","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","9285" +"*/NTLMInjector.git*",".{0,1000}\/NTLMInjector\.git.{0,1000}","offensive_tool_keyword","NTLMInjector","restore the user password after a password reset (get the previous hash with DCSync)","T1555 - T1556.003 - T1078 - T1110.003 - T1201 - T1003","TA0001 - TA0003 - TA0004 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/vletoux/NTLMInjector","1","1","N/A","N/A","10","2","167","29","2017-06-08T19:01:21Z","2017-06-04T07:25:36Z","9286" +"*/NTLMParse.go*",".{0,1000}\/NTLMParse\.go.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","1","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","9287" +"*/ntlmquic*",".{0,1000}\/ntlmquic.{0,1000}","offensive_tool_keyword","ntlmquic","POC tools for exploring SMB over QUIC protocol","T1210.002 - T1210.003 - T1210.004","TA0001","N/A","N/A","Exploitation tool","https://github.com/xpn/ntlmquic","1","1","N/A","network exploitation tool","6","2","122","15","2022-04-06T11:22:11Z","2022-04-05T13:01:02Z","9288" +"*/NTLMRecon*",".{0,1000}\/NTLMRecon.{0,1000}","offensive_tool_keyword","NTMLRecon","A fast and flexible NTLM reconnaissance tool without external dependencies. Useful to find out information about NTLM endpoints when working with a large set of potential IP addresses and domains","T1595","TA0009","N/A","N/A","Discovery","https://github.com/pwnfoo/NTLMRecon","1","1","N/A","N/A","N/A","5","481","70","2024-06-24T18:11:12Z","2019-12-01T06:06:30Z","9289" +"*/NTLMRecon.git*",".{0,1000}\/NTLMRecon\.git.{0,1000}","offensive_tool_keyword","NTMLRecon","Enumerate information from NTLM authentication enabled web endpoints","T1212 - T1212.001 - T1071 - T1071.001 - T1087 - T1087.001","TA0009 - TA0007 - TA0006","N/A","N/A","Discovery","https://github.com/puzzlepeaches/NTLMRecon","1","1","N/A","N/A","8","1","35","3","2023-08-16T14:34:10Z","2023-08-09T12:10:42Z","9290" +"*/ntlmrecon/*.py*",".{0,1000}\/ntlmrecon\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","NTMLRecon","Enumerate information from NTLM authentication enabled web endpoints","T1212 - T1212.001 - T1071 - T1071.001 - T1087 - T1087.001","TA0009 - TA0007 - TA0006","N/A","N/A","Discovery","https://github.com/puzzlepeaches/NTLMRecon","1","1","N/A","N/A","8","1","35","3","2023-08-16T14:34:10Z","2023-08-09T12:10:42Z","9291" +"*/NTLMRelay2Self*",".{0,1000}\/NTLMRelay2Self.{0,1000}","offensive_tool_keyword","NTLMRelay2Self","An other No-Fix LPE - NTLMRelay2Self over HTTP (Webdav).","T1078 - T1078.004 - T1557 - T1557.001 - T1068","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/med0x2e/NTLMRelay2Self","1","1","N/A","N/A","10","5","400","42","2024-01-27T08:52:03Z","2022-04-30T10:05:02Z","9292" +"*/NtlmRelayToEWS.git*",".{0,1000}\/NtlmRelayToEWS\.git.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","1","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","9293" +"*/NtlmRelayToEWS/*",".{0,1000}\/NtlmRelayToEWS\/.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","1","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","9294" +"*/ntlmrelayx.exe*",".{0,1000}\/ntlmrelayx\.exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","9295" +"*/ntlmrelayx.exe*",".{0,1000}\/ntlmrelayx\.exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","9296" +"*/ntlmrelayx.py*",".{0,1000}\/ntlmrelayx\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","9297" +"*/ntlmrelayx.py*",".{0,1000}\/ntlmrelayx\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/LuemmelSec/ntlmrelayx.py_to_exe","1","1","N/A","N/A","10","1","86","17","2023-05-26T05:35:52Z","2023-05-15T17:58:26Z","9298" +"*/ntlmrelayx/*",".{0,1000}\/ntlmrelayx\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","9299" +"*/ntlmrelayx/*",".{0,1000}\/ntlmrelayx\/.{0,1000}","offensive_tool_keyword","PKINITtools","Tools for Kerberos PKINIT and relaying to AD CS","T1550.003 - T1557.002 - T1552.004 - T1212 - T1550","TA0009 - TA0008","N/A","N/A","Lateral Movement","https://github.com/dirkjanm/PKINITtools","1","1","N/A","N/A","N/A","8","737","82","2025-01-03T14:25:52Z","2021-07-27T19:06:09Z","9300" +"*/ntlmscan.git*",".{0,1000}\/ntlmscan\.git.{0,1000}","offensive_tool_keyword","ntlmscan","scan for NTLM directories","T1087 - T1083","TA0006","N/A","N/A","Reconnaissance","https://github.com/nyxgeek/ntlmscan","1","1","N/A","N/A","N/A","4","359","57","2024-06-27T11:10:32Z","2019-10-23T06:02:56Z","9301" +"*/ntlmscan/*",".{0,1000}\/ntlmscan\/.{0,1000}","offensive_tool_keyword","ntlmscan","scan for NTLM directories","T1087 - T1083","TA0006","N/A","N/A","Reconnaissance","https://github.com/nyxgeek/ntlmscan","1","1","N/A","N/A","N/A","4","359","57","2024-06-27T11:10:32Z","2019-10-23T06:02:56Z","9302" +"*/NTLMSleuth.git*",".{0,1000}\/NTLMSleuth\.git.{0,1000}","offensive_tool_keyword","NTLMSleuth","verify NTLM hash integrity against the robust database of ntlm.pw.","T1003 - T1555","TA0006","N/A","Black Basta","Credential Access","https://github.com/jmarr73/NTLMSleuth","1","1","N/A","N/A","8","1","8","0","2024-08-28T15:21:10Z","2023-12-12T16:41:35Z","9303" +"*/NtlmThief.git*",".{0,1000}\/NtlmThief\.git.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","1","N/A","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","9304" +"*/ntlmtransport.go*",".{0,1000}\/ntlmtransport\.go.{0,1000}","offensive_tool_keyword","ruler","A tool to abuse Exchange services","T1087 - T1110 - T1133 - T1064 - T1204","TA0007 - TA0006 - TA0003 - TA0002 - TA0005","N/A","APT33","Persistence","https://github.com/sensepost/ruler","1","1","N/A","N/A","10","10","2222","362","2024-06-10T11:03:07Z","2016-08-18T15:05:13Z","9305" +"*/ntlmutil.py*",".{0,1000}\/ntlmutil\.py.{0,1000}","offensive_tool_keyword","NTMLRecon","A fast and flexible NTLM reconnaissance tool without external dependencies. Useful to find out information about NTLM endpoints when working with a large set of potential IP addresses and domains","T1595","TA0009","N/A","N/A","Discovery","https://github.com/pwnfoo/NTLMRecon","1","1","N/A","N/A","N/A","5","481","70","2024-06-24T18:11:12Z","2019-12-01T06:06:30Z","9307" +"*/ntlmutil.py*",".{0,1000}\/ntlmutil\.py.{0,1000}","offensive_tool_keyword","NTMLRecon","Enumerate information from NTLM authentication enabled web endpoints","T1212 - T1212.001 - T1071 - T1071.001 - T1087 - T1087.001","TA0009 - TA0007 - TA0006","N/A","N/A","Discovery","https://github.com/puzzlepeaches/NTLMRecon","1","1","N/A","N/A","8","1","35","3","2023-08-16T14:34:10Z","2023-08-09T12:10:42Z","9308" +"*/ntlmv1.py*",".{0,1000}\/ntlmv1\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","9310" +"*/ntpescape.git*",".{0,1000}\/ntpescape\.git.{0,1000}","offensive_tool_keyword","ntpescape","ntpescape is a tool that can stealthily (but slowly) exfiltrate data from a computer using the Network Time Protocol (NTP).","T1048 - T1071.004","TA0010 - TA0009","N/A","Black Basta","Data Exfiltration","https://github.com/evallen/ntpescape","1","1","N/A","N/A","10","2","138","15","2023-11-14T18:54:14Z","2022-09-22T16:25:15Z","9311" +"*/ntp-info.nse*",".{0,1000}\/ntp\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9312" +"*/ntp-monlist.nse*",".{0,1000}\/ntp\-monlist\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9313" +"*/NtQuerySystemInformation.md*",".{0,1000}\/NtQuerySystemInformation\.md.{0,1000}","offensive_tool_keyword","Priv2Admin","Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS.","T1543 - T1068 - T1078","TA0003 - TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/gtworek/Priv2Admin","1","1","N/A","N/A","N/A","10","2124","286","2023-02-24T13:31:23Z","2019-08-14T11:50:17Z","9314" +"*/NtRemoteLoad.exe*",".{0,1000}\/NtRemoteLoad\.exe.{0,1000}","offensive_tool_keyword","NtRemoteLoad","Remote Shellcode Injector","T1055 - T1027 - T1218.010","TA0002 - TA0005 - TA0010","N/A","N/A","Exploitation tool","https://github.com/florylsk/NtRemoteLoad","1","1","N/A","N/A","10","3","213","37","2023-08-27T17:14:44Z","2023-08-27T16:52:31Z","9315" +"*/NtRemoteLoad.git*",".{0,1000}\/NtRemoteLoad\.git.{0,1000}","offensive_tool_keyword","NtRemoteLoad","Remote Shellcode Injector","T1055 - T1027 - T1218.010","TA0002 - TA0005 - TA0010","N/A","N/A","Exploitation tool","https://github.com/florylsk/NtRemoteLoad","1","1","N/A","N/A","10","3","213","37","2023-08-27T17:14:44Z","2023-08-27T16:52:31Z","9316" +"*/NtRights/*",".{0,1000}\/NtRights\/.{0,1000}","offensive_tool_keyword","NtRights","tool for adding privileges from the commandline","T1548.002 - T1059.003 - T1027.002","TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/gtworek/PSBits/tree/master/NtRights","1","1","N/A","N/A","7","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","9317" +"*/NtSetSystemInformation.md*",".{0,1000}\/NtSetSystemInformation\.md.{0,1000}","offensive_tool_keyword","Priv2Admin","Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS.","T1543 - T1068 - T1078","TA0003 - TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/gtworek/Priv2Admin","1","1","N/A","N/A","N/A","10","2124","286","2023-02-24T13:31:23Z","2019-08-14T11:50:17Z","9318" +"*/Nuages_Cli*",".{0,1000}\/Nuages_Cli.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","9319" +"*/nuagesAPI.js*",".{0,1000}\/nuagesAPI\.js.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","9320" +"*/nullinux.git*",".{0,1000}\/nullinux\.git.{0,1000}","offensive_tool_keyword","nullinux","Internal penetration testing tool for Linux that can be used to enumerate OS information/domain information/ shares/ directories and users through SMB.","T1087 - T1016 - T1077 - T1018","TA0007 - TA0006","N/A","N/A","Discovery","https://github.com/m8sec/nullinux","1","1","#linux","N/A","7","6","575","101","2024-06-19T14:29:09Z","2016-04-28T16:45:02Z","9321" +"*/nullinux.py*",".{0,1000}\/nullinux\.py.{0,1000}","offensive_tool_keyword","nullinux","Internal penetration testing tool for Linux that can be used to enumerate OS information/domain information/ shares/ directories and users through SMB.","T1087 - T1016 - T1077 - T1018","TA0007 - TA0006","N/A","N/A","Discovery","https://github.com/m8sec/nullinux","1","1","#linux","N/A","7","6","575","101","2024-06-19T14:29:09Z","2016-04-28T16:45:02Z","9322" +"*/nxc.exe*",".{0,1000}\/nxc\.exe.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","9325" +"*/nxc/parsers/ip.py*",".{0,1000}\/nxc\/parsers\/ip\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","9326" +"*/nxc/parsers/nmap.py*",".{0,1000}\/nxc\/parsers\/nmap\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","9327" +"*/nxc-ubuntu-latest*",".{0,1000}\/nxc\-ubuntu\-latest.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","9328" +"*/nysm.git*",".{0,1000}\/nysm\.git.{0,1000}","offensive_tool_keyword","nysm","nysm is a stealth post-exploitation container","T1610 - T1057 - T1570","TA0005 - TA0002 - TA0008","N/A","N/A","Defense Evasion","https://github.com/eeriedusk/nysm","1","1","N/A","N/A","10","3","246","39","2023-12-20T13:59:17Z","2023-09-25T10:03:52Z","9333" +"*/o365_enum_activesync.py*",".{0,1000}\/o365_enum_activesync\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9334" +"*/o365_enum_office.py*",".{0,1000}\/o365_enum_office\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9335" +"*/o365_enum_onedrive.py*",".{0,1000}\/o365_enum_onedrive\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9336" +"*/o365_spray_activesync.py*",".{0,1000}\/o365_spray_activesync\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9337" +"*/o365_spray_adfs.py*",".{0,1000}\/o365_spray_adfs\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9338" +"*/o365_spray_msol.py*",".{0,1000}\/o365_spray_msol\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9339" +"*/o365recon.git*",".{0,1000}\/o365recon\.git.{0,1000}","offensive_tool_keyword","o365recon","script to retrieve information via O365 and AzureAD with a valid cred ","T1110 - T1081 - T1081.001 - T1114 - T1087","TA0006 - TA0007","N/A","N/A","Reconnaissance","https://github.com/nyxgeek/o365recon","1","1","N/A","N/A","7","8","715","103","2022-08-14T04:18:28Z","2017-09-02T17:19:42Z","9340" +"*/o365spray.git*",".{0,1000}\/o365spray\.git.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","1","N/A","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","9341" +"*/o365spray.py*",".{0,1000}\/o365spray\.py.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","1","N/A","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","9342" +"*/oab-parse/mspack.*.dll*",".{0,1000}\/oab\-parse\/mspack\..{0,1000}\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","9343" +"*/obfs3/obfs3.py*",".{0,1000}\/obfs3\/obfs3\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","9344" +"*/obfuscate_strings.py*",".{0,1000}\/obfuscate_strings\.py.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","9345" +"*/obfuscated_scripts/*",".{0,1000}\/obfuscated_scripts\/.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9346" +"*/Obfuscated-Code.py*",".{0,1000}\/Obfuscated\-Code\.py.{0,1000}","offensive_tool_keyword","var0xshell","var0xshell - shell with xor encryption","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/yehia-mamdouh/var0xshell/tree/main","1","1","N/A","N/A","8","10","4","1","2023-01-09T06:53:42Z","2023-01-08T21:34:26Z","9347" +"*/ObfuscatedSharpCollection.git*",".{0,1000}\/ObfuscatedSharpCollection\.git.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","9348" +"*/obfuscation.exe --help*",".{0,1000}\/obfuscation\.exe\s\-\-help.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","9349" +"*/Obfuscator.py*",".{0,1000}\/Obfuscator\.py.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1027 - T1055 - T1070 - T1112 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","9350" +"*/Obfuscator.py*",".{0,1000}\/Obfuscator\.py.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","9351" +"*/obfuscator/obfuscator.*",".{0,1000}\/obfuscator\/obfuscator\..{0,1000}","offensive_tool_keyword","Alcatraz","x64 binary obfuscator","T1027 - T1140","TA0004 - TA0042","N/A","N/A","Defense Evasion","https://github.com/weak1337/Alcatraz","1","1","N/A","N/A","10","10","1808","267","2023-07-14T14:19:01Z","2022-12-21T17:27:56Z","9352" +"*/octopus.asm*",".{0,1000}\/octopus\.asm.{0,1000}","offensive_tool_keyword","octopus","Octopus is an open source. pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S.","T1059.001 - T1105 - T1071.001 - T1219 - T1573","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/mhaskar/Octopus","1","1","N/A","N/A","10","10","750","156","2021-07-06T23:52:37Z","2019-08-30T21:09:07Z","9353" +"*/Octopus.git*",".{0,1000}\/Octopus\.git.{0,1000}","offensive_tool_keyword","octopus","Octopus is an open source. pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S.","T1059.001 - T1105 - T1071.001 - T1219 - T1573","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/mhaskar/Octopus","1","1","N/A","N/A","10","10","750","156","2021-07-06T23:52:37Z","2019-08-30T21:09:07Z","9354" +"*/octopusx64.asm*",".{0,1000}\/octopusx64\.asm.{0,1000}","offensive_tool_keyword","octopus","Octopus is an open source. pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S.","T1059.001 - T1105 - T1071.001 - T1219 - T1573","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/mhaskar/Octopus","1","1","N/A","N/A","10","10","750","156","2021-07-06T23:52:37Z","2019-08-30T21:09:07Z","9355" +"*/OffensiveCpp.git*",".{0,1000}\/OffensiveCpp\.git.{0,1000}","offensive_tool_keyword","OffensiveCpp","C/C++ snippets that can be handy in specific offensive scenarios","T1055 - T1047 - T1105 - T1117 - T1129 - T1135 - T1203","TA0002 - TA0003 - TA0006 - TA0007 - TA0009","N/A","N/A","Exploitation tool","https://github.com/lsecqt/OffensiveCpp","1","1","N/A","N/A","10","8","700","83","2025-01-26T08:05:48Z","2023-04-05T09:39:33Z","9356" +"*/OffensiveCSharp.git*",".{0,1000}\/OffensiveCSharp\.git.{0,1000}","offensive_tool_keyword","OffensiveCSharp","Collection of Offensive C# Tooling","T1059.001 - T1055.001 - T1027","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/matterpreter/OffensiveCSharp/tree/master","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","9357" +"*/OffensiveCSharp/*",".{0,1000}\/OffensiveCSharp\/.{0,1000}","offensive_tool_keyword","OffensiveCSharp","Collection of Offensive C# Tooling","T1059.001 - T1055.001 - T1027","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/matterpreter/OffensiveCSharp/tree/master","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","9358" +"*/OffensiveLua.git*",".{0,1000}\/OffensiveLua\.git.{0,1000}","offensive_tool_keyword","OffensiveLua","Offensive Lua is a collection of offensive security scripts written in Lua with FFI","T1059 - T1218.011 - T1105 - T1021.002 - T1564.001 - T1112 - T1113 - T1204.002 - T1547.002","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hackerhouse-opensource/OffensiveLua","1","1","N/A","N/A","8","2","184","25","2023-11-17T00:35:10Z","2023-10-25T17:21:13Z","9359" +"*/Offensive-Netsh-Helper.git*",".{0,1000}\/Offensive\-Netsh\-Helper\.git.{0,1000}","offensive_tool_keyword","Offensive-Netsh-Helper","Maintain Windows Persistence with an evil Netshell Helper DLL","T1174 - T1055.011 - T1546.013 - T1574.002 - T1105","TA0003 ","N/A","N/A","Persistence","https://github.com/rtcrowley/Offensive-Netsh-Helper","1","1","N/A","N/A","9","1","12","5","2018-07-28T02:12:09Z","2018-07-25T22:49:20Z","9360" +"*/OffensiveNotion.git",".{0,1000}\/OffensiveNotion\.git","offensive_tool_keyword","OffensiveNotion","Notion (yes the notetaking app) as a C2.","T1090 - T1090.002 - T1071 - T1071.001","TA0011 - TA0042","N/A","N/A","C2","https://github.com/mttaggart/OffensiveNotion","1","1","N/A","N/A","10","10","1161","130","2023-05-21T13:24:01Z","2022-01-18T16:39:54Z","9361" +"*/OffensiveNotion/agent*",".{0,1000}\/OffensiveNotion\/agent.{0,1000}","offensive_tool_keyword","OffensiveNotion","Notion (yes the notetaking app) as a C2.","T1090 - T1090.002 - T1071 - T1071.001","TA0011 - TA0042","N/A","N/A","C2","https://github.com/mttaggart/OffensiveNotion","1","1","N/A","N/A","10","10","1161","130","2023-05-21T13:24:01Z","2022-01-18T16:39:54Z","9362" +"*/OffensiveNotion/osxcross/target/bin*",".{0,1000}\/OffensiveNotion\/osxcross\/target\/bin.{0,1000}","offensive_tool_keyword","OffensiveNotion","Notion (yes the notetaking app) as a C2.","T1090 - T1090.002 - T1071 - T1071.001","TA0011 - TA0042","N/A","N/A","C2","https://github.com/mttaggart/OffensiveNotion","1","1","N/A","N/A","10","10","1161","130","2023-05-21T13:24:01Z","2022-01-18T16:39:54Z","9363" +"*/office2john.py*",".{0,1000}\/office2john\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","9365" +"*/OfficeInjector.exe*",".{0,1000}\/OfficeInjector\.exe.{0,1000}","offensive_tool_keyword","ShimMe","Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.","T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070","TA0004 - TA0005 - TA0006 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/deepinstinct/ShimMe","1","1","N/A","N/A","9","2","140","20","2024-10-29T07:33:38Z","2024-08-04T10:03:28Z","9366" +"*/Office-Persistence.git*",".{0,1000}\/Office\-Persistence\.git.{0,1000}","offensive_tool_keyword","Office-Persistence","Use powershell to test Office-based persistence methods","T1059.001 - T1137 - T1116","TA0003 ","N/A","N/A","Persistence","https://github.com/3gstudent/Office-Persistence","1","1","N/A","N/A","9","1","76","24","2021-04-17T01:39:13Z","2017-07-14T10:03:35Z","9367" +"*/OfficePersistence.ps1*",".{0,1000}\/OfficePersistence\.ps1.{0,1000}","offensive_tool_keyword","Office-Persistence","Use powershell to test Office-based persistence methods","T1059.001 - T1137 - T1116","TA0003 ","N/A","N/A","Persistence","https://github.com/3gstudent/Office-Persistence","1","1","N/A","N/A","9","1","76","24","2021-04-17T01:39:13Z","2017-07-14T10:03:35Z","9368" +"*/Office-Persistence/master/calc.ppa*",".{0,1000}\/Office\-Persistence\/master\/calc\.ppa.{0,1000}","offensive_tool_keyword","Office-Persistence","Use powershell to test Office-based persistence methods","T1059.001 - T1137 - T1116","TA0003 ","N/A","N/A","Persistence","https://github.com/3gstudent/Office-Persistence","1","1","N/A","N/A","9","1","76","24","2021-04-17T01:39:13Z","2017-07-14T10:03:35Z","9369" +"*/OG-Sadpanda/*",".{0,1000}\/OG\-Sadpanda\/.{0,1000}","offensive_tool_keyword","cobaltstrike",".NET Assembly to Retrieve Outlook Calendar Details","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OG-Sadpanda/SharpCalendar","1","1","N/A","N/A","10","10","13","1","2021-10-07T19:42:20Z","2021-10-07T17:11:46Z","9371" +"*/Oh365UserFinder*",".{0,1000}\/Oh365UserFinder.{0,1000}","offensive_tool_keyword","Oh365UserFinder","Oh365UserFinder is used for identifying valid o365 accounts and domains without the risk of account lockouts. The tool parses responses to identify the IfExistsResult flag is null or not. and responds appropriately if the user is valid. The tool will attempt to identify false positives based on response. and either automatically create a waiting period to allow the throttling value to reset. or warn the user to increase timeouts between attempts.","T1595 - T1592 - T1589 - T1591 - T1598","TA0004 - TA0005 - TA0010","N/A","N/A","Reconnaissance","https://github.com/dievus/Oh365UserFinder","1","1","N/A","N/A","N/A","6","539","94","2025-01-23T19:50:46Z","2021-11-16T22:59:04Z","9372" +"*/oh365userfinder.py*",".{0,1000}\/oh365userfinder\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","9373" +"*/OJ/gobuster*",".{0,1000}\/OJ\/gobuster.{0,1000}","offensive_tool_keyword","gobuster","Directory/File DNS and VHost busting tool written in Go","T1046 - T1590.002 - T1590.005","TA0007 - TA0043 - TA0006","N/A","Volatile Cedar","Reconnaissance","https://github.com/OJ/gobuster","1","1","#linux","network exploitation tool","N/A","10","11434","1338","2025-04-17T06:41:43Z","2014-11-14T13:18:35Z","9374" +"*/omg-payloads.git*",".{0,1000}\/omg\-payloads\.git.{0,1000}","offensive_tool_keyword","omg-payloads","Official payload library for the O.MG line of products from Mischief Gadgets","T1200 - T1095 - T1059.006 - T1027","TA0010 - TA0011","N/A","N/A","Hardware","https://github.com/hak5/omg-payloads","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","9375" +"*/Omnispray.git*",".{0,1000}\/Omnispray\.git.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9376" +"*/omnispray.py*",".{0,1000}\/omnispray\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9377" +"*/omp2-brute.nse*",".{0,1000}\/omp2\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9378" +"*/omp2-enum-targets.nse*",".{0,1000}\/omp2\-enum\-targets\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9379" +"*/omron-info.nse*",".{0,1000}\/omron\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9380" +"*/On_Demand_C2/*",".{0,1000}\/On_Demand_C2\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of beacon BOF written to learn windows and cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Yaxser/CobaltStrike-BOF","1","1","N/A","N/A","10","10","347","57","2023-02-24T13:12:14Z","2020-10-08T01:12:41Z","9381" +"*/onedrive_user_enum*",".{0,1000}\/onedrive_user_enum.{0,1000}","offensive_tool_keyword","onedrive_user_enum","enumerate valid onedrive users","T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/onedrive_user_enum","1","1","N/A","network exploitation tool","N/A","7","663","83","2025-04-17T00:13:11Z","2019-03-05T08:54:38Z","9382" +"*/oneliner.tpl*",".{0,1000}\/oneliner\.tpl.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","9383" +"*/oneliner2.tpl*",".{0,1000}\/oneliner2\.tpl.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","9384" +"*/onesixtyone/dict.txt*",".{0,1000}\/onesixtyone\/dict\.txt.{0,1000}","offensive_tool_keyword","onesixtyone","Fast SNMP scanner. onesixtyone takes a different approach to SNMP scanning. It takes advantage of the fact that SNMP is a connectionless protocol and sends all SNMP requests as fast as it can. Then the scanner waits for responses to come back and logs them in a fashion similar to Nmap ping sweeps","T1046 - T1018","TA0007 - TA0005","N/A","N/A","Reconnaissance","https://github.com/trailofbits/onesixtyone","1","1","N/A","N/A","N/A","6","594","90","2023-04-11T18:21:38Z","2014-02-07T17:02:49Z","9385" +"*/onex.git*",".{0,1000}\/onex\.git.{0,1000}","offensive_tool_keyword","onex","Onex is a package manager for hacker's. Onex manage more than 400+ hacking tools that can be installed on single click","T1105 - T1078 - T1059 - T1087","TA0007 - TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/rajkumardusad/onex","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9386" +"*/onionpipe.git*",".{0,1000}\/onionpipe\.git.{0,1000}","offensive_tool_keyword","onionpipe","onionpipe forwards ports on the local host to remote Onion addresses as Tor hidden services and vice-versa.","T1090.003 - T1573.002","TA0005 - TA0011","N/A","Black Basta","Defense Evasion","https://github.com/cmars/onionpipe","1","1","N/A","N/A","10","6","553","33","2025-04-22T16:34:56Z","2022-01-23T06:52:13Z","9387" +"*/onionpipe/releases/latest*",".{0,1000}\/onionpipe\/releases\/latest.{0,1000}","offensive_tool_keyword","onionpipe","onionpipe forwards ports on the local host to remote Onion addresses as Tor hidden services and vice-versa.","T1090.003 - T1573.002","TA0005 - TA0011","N/A","Black Basta","Defense Evasion","https://github.com/cmars/onionpipe","1","1","N/A","N/A","10","6","553","33","2025-04-22T16:34:56Z","2022-01-23T06:52:13Z","9388" +"*/open_vas.rb*",".{0,1000}\/open_vas\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","9390" +"*/openbullet.git*",".{0,1000}\/openbullet\.git.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/openbullet","1","1","N/A","N/A","10","10","1569","697","2024-09-02T12:18:29Z","2019-03-26T09:06:32Z","9391" +"*/OpenBullet2.git*",".{0,1000}\/OpenBullet2\.git.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/OpenBullet2","1","1","N/A","N/A","10","10","1953","518","2025-03-16T10:50:26Z","2020-04-23T14:04:16Z","9392" +"*/openflow-info.nse*",".{0,1000}\/openflow\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9393" +"*/openlookup-info.nse*",".{0,1000}\/openlookup\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9394" +"*/openvas-otp-brute.nse*",".{0,1000}\/openvas\-otp\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9395" +"*/openwebnet-discovery.nse*",".{0,1000}\/openwebnet\-discovery\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9397" +"*/operapassview.zip",".{0,1000}\/operapassview\.zip","offensive_tool_keyword","OperaPassView","OperaPassView is a small password recovery tool that decrypts the content of the Opera Web browser password file (wand.dat) and displays the list of all Web site passwords stored in this file","T1003 - T1555 - T1145","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/opera_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","9398" +"*/opt/implant/*",".{0,1000}\/opt\/implant\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","9415" +"*/opt/lwp-scripts*",".{0,1000}\/opt\/lwp\-scripts.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","9417" +"*/opt/lwp-wordlists*",".{0,1000}\/opt\/lwp\-wordlists.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","9418" +"*/opt/merlin/*",".{0,1000}\/opt\/merlin\/.{0,1000}","offensive_tool_keyword","mythic","Cross-platform post-exploitation HTTP Command & Control agent written in golang","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/merlin","1","1","N/A","N/A","10","10","94","16","2025-04-16T13:05:47Z","2021-01-25T12:36:46Z","9419" +"*/opt/nessus/*",".{0,1000}\/opt\/nessus\/.{0,1000}","offensive_tool_keyword","nessus","Vulnerability scanner","T1046 - T1068 - T1190 - T1201 - T1222 - T1592","TA0001 - TA0002 - TA0007 - TA0011","N/A","N/A","Vulnerability Scanner","https://fr.tenable.com/products/nessus","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","9421" +"*/opt/Ninja/*",".{0,1000}\/opt\/Ninja\/.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","9422" +"*/opt/PoshC2*",".{0,1000}\/opt\/PoshC2.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","9425" +"*/opt/rai/*",".{0,1000}\/opt\/rai\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","9427" +"*/optiv/Dent/*",".{0,1000}\/optiv\/Dent\/.{0,1000}","offensive_tool_keyword","cobaltstrike","A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/optiv/Dent","1","1","N/A","N/A","10","10","296","46","2023-08-18T17:28:54Z","2021-05-03T14:00:29Z","9434" +"*/optiv/Freeze/*",".{0,1000}\/optiv\/Freeze\/.{0,1000}","offensive_tool_keyword","Freeze","Freeze is a payload toolkit for bypassing EDRs using suspended processes. direct syscalls. and alternative execution methods","T1055 - T1055.001 - T1055.003 - T1055.004 - T1055.005 - T1055.006 - T1055.007 - T1055.008 - T1055.012 - T1055.013 - T1055.014 - T1055.015 - T1055.016 - T1055.017 - T1055.018 - T1055.019 - T1055.020 - T1055.021 - T1055.022 - T1055.023 - T1055.024 - T1055.025 - T1112","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/optiv/Freeze","1","1","N/A","N/A","N/A","10","1437","187","2023-08-18T17:25:07Z","2022-09-21T14:40:59Z","9435" +"*/oracle-brute.nse*",".{0,1000}\/oracle\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9436" +"*/oracle-brute-stealth.nse*",".{0,1000}\/oracle\-brute\-stealth\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9437" +"*/oracle-enum-users.nse*",".{0,1000}\/oracle\-enum\-users\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9438" +"*/oracle-patator.py*",".{0,1000}\/oracle\-patator\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","9439" +"*/oracle-scanner.py*",".{0,1000}\/oracle\-scanner\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","9440" +"*/oracle-sid-brute.nse*",".{0,1000}\/oracle\-sid\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9441" +"*/oracle-tnscmd.py*",".{0,1000}\/oracle\-tnscmd\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","9442" +"*/oracle-tns-version.nse*",".{0,1000}\/oracle\-tns\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9443" +"*/orbitaldump.git*",".{0,1000}\/orbitaldump\.git.{0,1000}","offensive_tool_keyword","orbitaldump","A simple multi-threaded distributed SSH brute-forcing tool written in Python.","T1110","TA0006","N/A","N/A","Exploitation tool","https://github.com/k4yt3x/orbitaldump","1","1","N/A","N/A","N/A","5","460","83","2022-10-30T23:40:57Z","2021-06-06T17:48:19Z","9444" +"*/oscp.profile*",".{0,1000}\/oscp\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","9445" +"*/OSEP-Code-Snippets.git*",".{0,1000}\/OSEP\-Code\-Snippets\.git.{0,1000}","offensive_tool_keyword","OSEP-Code-Snippets","notable code snippets for Offensive Security's PEN-300 (OSEP) course","T1116 - T1204.002 - T1027.009 - T1021.005 - T1560.001 - T1100 - T1003.001 - T1564.001 - T1047 - T1210 - T1134.002 - T1055 - T1055.011 - T1055.012 - T1204","TA0005 - TA0040 - TA0008 - TA0003 - TA0006 - TA0004","N/A","N/A","Exploitation tool","https://github.com/chvancooten/OSEP-Code-Snippets","1","1","N/A","N/A","8","10","1254","444","2024-01-04T15:17:17Z","2021-03-10T21:34:41Z","9446" +"*/osmedeus*",".{0,1000}\/osmedeus.{0,1000}","offensive_tool_keyword","Osmedeus","Osmedeus - A Workflow Engine for Offensive Security","T1595","TA0043","N/A","N/A","Exploitation tool","https://github.com/j3ssie/osmedeus","1","1","N/A","N/A","N/A","10","5566","907","2025-04-22T14:57:07Z","2018-11-10T04:17:18Z","9451" +"*/OUned.git*",".{0,1000}\/OUned\.git.{0,1000}","offensive_tool_keyword","Ouned","The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning","T1484 - T1210","TA0001 - TA0004 - TA0005 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/synacktiv/Ouned","1","1","N/A","N/A","10","2","112","14","2025-03-29T14:20:38Z","2024-04-17T10:18:04Z","9453" +"*/ouned_smbserver.py*",".{0,1000}\/ouned_smbserver\.py.{0,1000}","offensive_tool_keyword","Ouned","The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning","T1484 - T1210","TA0001 - TA0004 - TA0005 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/synacktiv/Ouned","1","1","N/A","N/A","10","2","112","14","2025-03-29T14:20:38Z","2024-04-17T10:18:04Z","9454" +"*/out:spacerunner.exe*",".{0,1000}\/out\:spacerunner\.exe.{0,1000}","offensive_tool_keyword","SpaceRunner","enables the compilation of a C# program that will execute arbitrary PowerShell code without launching PowerShell processes through the use of runspace.","T1059.001 - T1027","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Mr-B0b/SpaceRunner","1","1","N/A","N/A","7","2","195","38","2020-07-26T10:39:53Z","2020-07-26T09:31:09Z","9457" +"*/outflank_bofs/*",".{0,1000}\/outflank_bofs\/.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","9459" +"*/outflanknl/*",".{0,1000}\/outflanknl\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/InlineWhispers","1","1","N/A","N/A","10","10","315","42","2021-11-09T15:39:27Z","2020-12-25T16:52:50Z","9460" +"*/Out-Minidump.ps1*",".{0,1000}\/Out\-Minidump\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","9461" +"*/output/payloads/*",".{0,1000}\/output\/payloads\/.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","9462" +"*/ovs-agent-version.nse*",".{0,1000}\/ovs\-agent\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9464" +"*/owa_enum_activesync.py*",".{0,1000}\/owa_enum_activesync\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9465" +"*/owa_spray_activesync.py*",".{0,1000}\/owa_spray_activesync\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9466" +"*/owneredit.py*",".{0,1000}\/owneredit\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","9470" +"*/p_cve-2014-9322.tar.gz*",".{0,1000}\/p_cve\-2014\-9322\.tar\.gz.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","9471" +"*/p292/Phant0m*",".{0,1000}\/p292\/Phant0m.{0,1000}","offensive_tool_keyword","cobaltstrike","Aggressor script to integrate Phant0m with Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/p292/Phant0m_cobaltstrike","1","1","N/A","N/A","10","10","27","13","2017-06-08T06:42:18Z","2017-06-08T06:39:07Z","9472" +"*/p2p-conficker.nse*",".{0,1000}\/p2p\-conficker\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9473" +"*/package/portscan/*.go",".{0,1000}\/package\/portscan\/.{0,1000}\.go","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","9474" +"*/PackMyPayload.git*",".{0,1000}\/PackMyPayload\.git.{0,1000}","offensive_tool_keyword","PackMyPayload","A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats","T1027 - T1036 - T1048 - T1070 - T1096 - T1195","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/mgeeky/PackMyPayload/","1","1","N/A","N/A","10","10","912","143","2024-06-10T09:50:43Z","2022-02-08T19:26:28Z","9475" +"*/PackMyPayload/*",".{0,1000}\/PackMyPayload\/.{0,1000}","offensive_tool_keyword","PackMyPayload","A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats","T1027 - T1036 - T1048 - T1070 - T1096 - T1195","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/mgeeky/PackMyPayload/","1","1","N/A","N/A","10","10","912","143","2024-06-10T09:50:43Z","2022-02-08T19:26:28Z","9476" +"*/pacu.git*",".{0,1000}\/pacu\.git.{0,1000}","offensive_tool_keyword","pacu","The AWS exploitation framework designed for testing the security of Amazon Web Services environments.","T1136.003 - T1190 - T1078.004","TA0006 - TA0001","N/A","Scattered Spider*","Framework","https://github.com/RhinoSecurityLabs/pacu","1","1","N/A","N/A","9","10","4651","731","2025-03-20T21:08:57Z","2018-06-13T21:58:59Z","9477" +"*/padre/pkg/exploit*",".{0,1000}\/padre\/pkg\/exploit.{0,1000}","offensive_tool_keyword","padre","padre?is an advanced exploiter for Padding Oracle attacks against CBC mode encryption","T1203 - T1059.003 - T1027.002","TA0005 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/glebarez/padre","1","1","N/A","N/A","8","3","253","24","2024-05-13T14:28:25Z","2019-12-30T13:52:03Z","9478" +"*/paensy.cpp*",".{0,1000}\/paensy\.cpp.{0,1000}","offensive_tool_keyword","Pateensy","payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy","T1056.001 - T1200 - T1036 - T1071","TA0002 - TA0005 - TA0011 - TA0006","N/A","N/A","Exploitation tool","https://github.com/screetsec/Pateensy","1","1","N/A","N/A","N/A","2","143","60","2017-01-26T12:02:56Z","2016-03-21T07:29:38Z","9479" +"*/paloalto_enum_globalprotectportal.py*",".{0,1000}\/paloalto_enum_globalprotectportal\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9493" +"*/paloalto_spray_globalprotectportal.py*",".{0,1000}\/paloalto_spray_globalprotectportal\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9494" +"*/pamspy.git*",".{0,1000}\/pamspy\.git.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","1","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","9496" +"*/PANIX.git*",".{0,1000}\/PANIX\.git.{0,1000}","offensive_tool_keyword","panix","PANIX is a highly customizable Linux persistence tool","T1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/Aegrah/PANIX","1","1","#linux","N/A","8","7","622","68","2025-03-05T10:45:04Z","2024-05-19T12:37:40Z","9497" +"*/papacat.bat",".{0,1000}\/papacat\.bat","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","9499" +"*/papacat.ps1*",".{0,1000}\/papacat\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","9500" +"*/papacat.zip*",".{0,1000}\/papacat\.zip.{0,1000}","offensive_tool_keyword","JustEvadeBro","JustEvadeBro a cheat sheet which will aid you through AMSI/AV evasion & bypasses.","T1562.001 - T1055.012 - T1218.011","TA0005 - TA0040 - TA0010","N/A","N/A","Defense Evasion","https://github.com/sinfulz/JustEvadeBro","1","1","N/A","N/A","8","4","309","25","2024-08-21T23:10:08Z","2021-05-11T06:26:10Z","9501" +"*/paranoidninja/*",".{0,1000}\/paranoidninja\/.{0,1000}","offensive_tool_keyword","prometheus","malware C2","T1071 - T1071.001 - T1105 - T1105.002 - T1106 - T1574.002","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/paranoidninja/0xdarkvortex-MalwareDevelopment","1","1","N/A","N/A","10","10","193","66","2020-07-21T06:14:44Z","2018-09-04T15:38:53Z","9502" +"*/Parasite Invoke.exe*",".{0,1000}\/Parasite\sInvoke\.exe.{0,1000}","offensive_tool_keyword","Parasite-Invoke","Hide your P/Invoke signatures through other people's signed assemblies","T1129 - T1574.002 - T1218","TA0005","N/A","N/A","Defense Evasion","https://github.com/MzHmO/Parasite-Invoke","1","1","N/A","N/A","8","3","207","32","2024-03-10T14:53:59Z","2024-03-07T20:18:42Z","9503" +"*/Parasite%20Invoke.exe",".{0,1000}\/Parasite\%20Invoke\.exe","offensive_tool_keyword","Parasite-Invoke","Hide your P/Invoke signatures through other people's signed assemblies","T1129 - T1574.002 - T1218","TA0005","N/A","N/A","Defense Evasion","https://github.com/MzHmO/Parasite-Invoke","1","1","N/A","N/A","8","3","207","32","2024-03-10T14:53:59Z","2024-03-07T20:18:42Z","9504" +"*/Parasite-Invoke.git*",".{0,1000}\/Parasite\-Invoke\.git.{0,1000}","offensive_tool_keyword","Parasite-Invoke","Hide your P/Invoke signatures through other people's signed assemblies","T1129 - T1574.002 - T1218","TA0005","N/A","N/A","Defense Evasion","https://github.com/MzHmO/Parasite-Invoke","1","1","N/A","N/A","8","3","207","32","2024-03-10T14:53:59Z","2024-03-07T20:18:42Z","9505" +"*/parrot/iso/*.iso*",".{0,1000}\/parrot\/iso\/.{0,1000}\.iso.{0,1000}","offensive_tool_keyword","parrot os","Parrot OS is a Debian-based. security-oriented Linux distribution that is designed for ethical hacking. penetration testing and digital forensics.","T1590 - T1200 - T1027 - T1578 - T1003 - T1001 - T1046 - T1570 - T1114 - T1105","TA0043 - TA0002 - TA0003 - TA0004 - TA0006 - TA0005 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation OS","https://www.parrotsec.org/download/","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9506" +"*/parrot-mirror/*",".{0,1000}\/parrot\-mirror\/.{0,1000}","offensive_tool_keyword","parrot os","Parrot OS is a Debian-based. security-oriented Linux distribution that is designed for ethical hacking. penetration testing and digital forensics.","T1590 - T1200 - T1027 - T1578 - T1003 - T1001 - T1046 - T1570 - T1114 - T1105","TA0043 - TA0002 - TA0003 - TA0004 - TA0006 - TA0005 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation OS","https://www.parrotsec.org/download/","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9507" +"*/parrot-on-docker/*",".{0,1000}\/parrot\-on\-docker\/.{0,1000}","offensive_tool_keyword","parrot os","Parrot OS is a Debian-based. security-oriented Linux distribution that is designed for ethical hacking. penetration testing and digital forensics.","T1590 - T1200 - T1027 - T1578 - T1003 - T1001 - T1046 - T1570 - T1114 - T1105","TA0043 - TA0002 - TA0003 - TA0004 - TA0006 - TA0005 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation OS","https://www.parrotsec.org/download/","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9508" +"*/parrotsec/*",".{0,1000}\/parrotsec\/.{0,1000}","offensive_tool_keyword","parrot os","Parrot OS is a Debian-based. security-oriented Linux distribution that is designed for ethical hacking. penetration testing and digital forensics.","T1590 - T1200 - T1027 - T1578 - T1003 - T1001 - T1046 - T1570 - T1114 - T1105","TA0043 - TA0002 - TA0003 - TA0004 - TA0006 - TA0005 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation OS","https://www.parrotsec.org/download/","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9509" +"*/parsers/nessus.py*",".{0,1000}\/parsers\/nessus\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","9511" +"*/pass_gen.pl*",".{0,1000}\/pass_gen\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","9512" +"*/PassDetective.git*",".{0,1000}\/PassDetective\.git.{0,1000}","offensive_tool_keyword","PassDetective","PassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords - API keys and secrets","T1059 - T1059.004 - T1552 - T1552.001","TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/aydinnyunus/PassDetective","1","1","N/A","N/A","7","2","129","8","2024-06-19T10:39:39Z","2023-07-22T12:31:57Z","9513" +"*/passhash.sl*",".{0,1000}\/passhash\.sl.{0,1000}","offensive_tool_keyword","armitage","Armitage is a graphical cyber attack management tool for Metasploit that visualizes your targets. recommends exploits and exposes the advanced capabilities of the framework ","T1210 - T1059.003 - T1547.001 - T1057 - T1046 - T1562.001 - T1071.001 - T1060 - T1573.002","TA0002 - TA0008 - TA0005 - TA0007 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/r00t0v3rr1d3/armitage","1","1","N/A","N/A","N/A","2","129","32","2022-12-06T00:17:23Z","2022-01-23T17:32:01Z","9514" +"*/passive_sqli.txt*",".{0,1000}\/passive_sqli\.txt.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","9515" +"*/PassSpray.git*",".{0,1000}\/PassSpray\.git.{0,1000}","offensive_tool_keyword","PassSpray","Domain Password Spray","T1110.003 - T1078","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/PassSpray","1","1","N/A","N/A","10","1","7","3","2025-02-20T10:07:43Z","2023-11-16T13:35:49Z","9516" +"*/PassSpray.ps1*",".{0,1000}\/PassSpray\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","9517" +"*/PassSpray.ps1*",".{0,1000}\/PassSpray\.ps1.{0,1000}","offensive_tool_keyword","PassSpray","Domain Password Spray","T1110.003 - T1078","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/PassSpray","1","1","N/A","N/A","10","1","7","3","2025-02-20T10:07:43Z","2023-11-16T13:35:49Z","9518" +"*/PassTheCert.exe*",".{0,1000}\/PassTheCert\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","9519" +"*/PassTheCert.exe*",".{0,1000}\/PassTheCert\.exe.{0,1000}","offensive_tool_keyword","PassTheCert","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","Black Basta","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","PassTheCert","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","9520" +"*/PassTheCert.exe*",".{0,1000}\/PassTheCert\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","PassTheCert","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","9521" +"*/PassTheCert.exe*",".{0,1000}\/PassTheCert\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","9522" +"*/PassTheCert.git*",".{0,1000}\/PassTheCert\.git.{0,1000}","offensive_tool_keyword","PassTheCert","tool to authenticate to an LDAP/S server with a certificate through Schannel","T1557 - T1071 - T1021 - T1213 - T1649","TA0006 - TA0008 - TA0009","N/A","Black Basta","Lateral Movement","https://github.com/AlmondOffSec/PassTheCert","1","1","N/A","N/A","10","7","618","76","2024-07-08T22:37:30Z","2022-04-29T09:08:32Z","9523" +"*/PassTheChallenge.git*",".{0,1000}\/PassTheChallenge\.git.{0,1000}","offensive_tool_keyword","PassTheChallenge","Recovering NTLM hashes from Credential Guard","T1003 - T1555.002","TA0006 - TA0005","N/A","N/A","Exploitation tool","https://github.com/ly4k/PassTheChallenge","1","1","N/A","N/A","9","4","334","21","2022-12-26T01:09:18Z","2022-12-26T00:56:40Z","9524" +"*/PassTheChallenge/releases/download/*",".{0,1000}\/PassTheChallenge\/releases\/download\/.{0,1000}","offensive_tool_keyword","PassTheChallenge","Recovering NTLM hashes from Credential Guard","T1003 - T1555.002","TA0006 - TA0005","N/A","N/A","Exploitation tool","https://github.com/ly4k/PassTheChallenge","1","1","N/A","N/A","9","4","334","21","2022-12-26T01:09:18Z","2022-12-26T00:56:40Z","9527" +"*/password.lst*",".{0,1000}\/password\.lst.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","9530" +"*/password/mimipenguin/*",".{0,1000}\/password\/mimipenguin\/.{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","9531" +"*/password_brute.txt*",".{0,1000}\/password_brute\.txt.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","9532" +"*/password_cracker.py*",".{0,1000}\/password_cracker\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","9533" +"*/password_ruled.txt*",".{0,1000}\/password_ruled\.txt.{0,1000}","offensive_tool_keyword","hashcat-rule","Rule for hashcat or john. Aiming to crack how people generate their password","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/clem9669/hashcat-rule","1","1","#linux","N/A","10","5","435","47","2024-09-02T20:14:15Z","2020-03-06T17:20:40Z","9534" +"*/password_sniffer.html*",".{0,1000}\/password_sniffer\.html.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","9535" +"*/passwordcracker.Dockerfile*",".{0,1000}\/passwordcracker\.Dockerfile.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","9536" +"*/passwordcracker/*",".{0,1000}\/passwordcracker\/.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","9537" +"*/Passwords/Common-Credentials/10k-most-common.txt*",".{0,1000}\/Passwords\/Common\-Credentials\/10k\-most\-common\.txt.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","1","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","9539" +"*/PasswordStealer.dll*",".{0,1000}\/PasswordStealer\.dll.{0,1000}","offensive_tool_keyword","Discord-RAT-2.0","Discord Remote Administration Tool fully written in c#, stub size of ~75kb with over 40 post exploitations modules","T1059.005 - T1105 - T1569.002 - T1027.001","TA0011 - TA0003 - TA0006 - TA0009 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/moom825/Discord-RAT-2.0","1","1","N/A","N/A","10","10","512","115","2023-11-03T01:15:38Z","2022-07-15T20:09:56Z","9540" +"*/pastehakk.git*",".{0,1000}\/pastehakk\.git.{0,1000}","offensive_tool_keyword","pastehakk","perform clipboard poisoning or paste jacking attack","T1115","T0001 - T0002 - T0005","N/A","N/A","Phishing","https://github.com/3xploitGuy/pastehakk","1","1","N/A","N/A","7","1","56","10","2020-06-22T01:17:53Z","2020-06-17T19:32:24Z","9541" +"*/pastehakk.sh*",".{0,1000}\/pastehakk\.sh.{0,1000}","offensive_tool_keyword","pastehakk","perform clipboard poisoning or paste jacking attack","T1115","T0001 - T0002 - T0005","N/A","N/A","Phishing","https://github.com/3xploitGuy/pastehakk","1","1","#linux","N/A","7","1","56","10","2020-06-22T01:17:53Z","2020-06-17T19:32:24Z","9542" +"*/patch_amsi.exe*",".{0,1000}\/patch_amsi\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","9543" +"*/Patch_AMSI.py*",".{0,1000}\/Patch_AMSI\.py.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","9544" +"*/Patch_AMSI.vba*",".{0,1000}\/Patch_AMSI\.vba.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","9545" +"*/patch_etw.exe*",".{0,1000}\/patch_etw\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","9546" +"*/patchfinder64.*",".{0,1000}\/patchfinder64\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","9547" +"*/PatchingAPI.cpp*",".{0,1000}\/PatchingAPI\.cpp.{0,1000}","offensive_tool_keyword","UnhookingPatch","Bypass EDR Hooks by patching NT API stub and resolving SSNs and syscall instructions at runtime","T1055 - T1055.001 - T1070 - T1070.004 - T1211","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/UnhookingPatch","1","1","N/A","N/A","9","4","304","52","2023-08-02T02:25:38Z","2023-02-08T16:21:03Z","9548" +"*/PatchingAPI.exe*",".{0,1000}\/PatchingAPI\.exe.{0,1000}","offensive_tool_keyword","UnhookingPatch","Bypass EDR Hooks by patching NT API stub and resolving SSNs and syscall instructions at runtime","T1055 - T1055.001 - T1070 - T1070.004 - T1211","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/UnhookingPatch","1","1","N/A","N/A","9","4","304","52","2023-08-02T02:25:38Z","2023-02-08T16:21:03Z","9549" +"*/path_traversal.txt*",".{0,1000}\/path_traversal\.txt.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","9550" +"*/path_traversal_dict.txt*",".{0,1000}\/path_traversal_dict\.txt.{0,1000}","offensive_tool_keyword","slip","Slip is a CLI tool to create malicious archive files containing path traversal payloads","T1560.001 - T1059","TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/0xless/slip","1","1","N/A","N/A","10","2","100","4","2025-04-11T18:36:31Z","2022-10-29T15:38:36Z","9551" +"*/path_traversal_win32.txt*",".{0,1000}\/path_traversal_win32\.txt.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","9552" +"*/path-mtu.nse*",".{0,1000}\/path\-mtu\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9553" +"*/payload.exe*",".{0,1000}\/payload\.exe.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","9554" +"*/payload.hta*",".{0,1000}\/payload\.hta.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","9555" +"*/payload_placement.exe*",".{0,1000}\/payload_placement\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","9556" +"*/payload_scripts*",".{0,1000}\/payload_scripts.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","9557" +"*/payload_scripts/artifact*",".{0,1000}\/payload_scripts\/artifact.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","9558" +"*/payload_service.sh*",".{0,1000}\/payload_service\.sh.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","9559" +"*/Payload_Type/athena*",".{0,1000}\/Payload_Type\/athena.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","9560" +"*/Payload_Types/*",".{0,1000}\/Payload_Types\/.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","9561" +"*/payload2.ps1*",".{0,1000}\/payload2\.ps1.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","9562" +"*/Payload-Download-Cradles.git*",".{0,1000}\/Payload\-Download\-Cradles\.git.{0,1000}","offensive_tool_keyword","Payload-Download-Cradles","download cradles to bypass AV/EPP/EDR in context of download cradle detections","T1105 - T1027 - T1203 - T1071","TA0005 - TA0009 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Payload-Download-Cradles","1","1","N/A","N/A","10","3","256","51","2022-07-07T07:20:36Z","2021-05-14T08:56:54Z","9563" +"*/payloads/DllLdr/*",".{0,1000}\/payloads\/DllLdr\/.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","9564" +"*/payloads/util*",".{0,1000}\/payloads\/util.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","9565" +"*/payloadtests.py*",".{0,1000}\/payloadtests\.py.{0,1000}","offensive_tool_keyword","the-backdoor-factory","Patch PE ELF Mach-O binaries with shellcode new version in development*","T1055.002 - T1055.004 - T1059.001","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/secretsquirrel/the-backdoor-factory","1","1","N/A","N/A","10","10","3369","788","2023-10-30T14:13:32Z","2013-05-30T01:04:24Z","9566" +"*/pcanywhere-brute.nse*",".{0,1000}\/pcanywhere\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9568" +"*/pcworx-info.nse*",".{0,1000}\/pcworx\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9579" +"*/PDF_Payload/script.txt*",".{0,1000}\/PDF_Payload\/script\.txt.{0,1000}","offensive_tool_keyword","Mystikal","macOS Initial Access Payload Generator","T1059.005 - T1204.002 - T1566.001","TA0002 - TA0001","N/A","N/A","Exploitation tool","https://github.com/D00MFist/Mystikal","1","1","N/A","N/A","9","4","305","39","2024-01-10T15:48:12Z","2021-05-03T14:46:16Z","9580" +"*/pdf2john.py*",".{0,1000}\/pdf2john\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","9581" +"*/pdf-exploit.git*","\/pdf\-exploit\.git","offensive_tool_keyword","POC","CVE-2024-4367 poc exploitation","T1566","TA0042","N/A","N/A","Resource Development","https://github.com/rzte/pdf-exploit","1","1","N/A","N/A","6","3","216","41","2024-07-19T03:04:41Z","2024-07-11T14:33:11Z","9582" +"*/PE/InjectPE.cs*",".{0,1000}\/PE\/InjectPE\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","9584" +"*/pe_to_shellcode*",".{0,1000}\/pe_to_shellcode.{0,1000}","offensive_tool_keyword","pe_to_shellcode","Converts PE into a shellcode","T1027 - T1059.004 - T1105 - T1036","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/hasherezade/pe_to_shellcode","1","1","N/A","N/A","N/A","10","2521","452","2023-08-15T14:42:12Z","2018-08-19T22:57:07Z","9585" +"*/pe2shc.exe*",".{0,1000}\/pe2shc\.exe.{0,1000}","offensive_tool_keyword","exe_to_dll","Converts a EXE into DLL","T1027.004 - T1059.001","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/hasherezade/exe_to_dll","1","1","N/A","N/A","5","10","1297","197","2023-07-26T11:41:27Z","2020-04-16T16:27:00Z","9586" +"*/pe2shc/*",".{0,1000}\/pe2shc\/.{0,1000}","offensive_tool_keyword","pe_to_shellcode","Converts PE into a shellcode","T1027 - T1059.004 - T1105 - T1036","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/hasherezade/pe_to_shellcode","1","1","N/A","N/A","N/A","10","2521","452","2023-08-15T14:42:12Z","2018-08-19T22:57:07Z","9587" +"*/PEASS-ng.git*",".{0,1000}\/PEASS\-ng\.git.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","9588" +"*/PEASS-ng.git*",".{0,1000}\/PEASS\-ng\.git.{0,1000}","offensive_tool_keyword","PEASS-ng","PEASS-ng - Privilege Escalation Awesome Scripts suite","T1098","TA0004 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/peass-ng/PEASS-ng","1","1","N/A","N/A","10","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","9589" +"*/PEASS-ng/*",".{0,1000}\/PEASS\-ng\/.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","9590" +"*/PEASS-ng/releases/*",".{0,1000}\/PEASS\-ng\/releases\/.{0,1000}","offensive_tool_keyword","PEASS-ng","PEASS-ng - Privilege Escalation Awesome Scripts suite","T1098","TA0004 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/peass-ng/PEASS-ng","1","1","N/A","N/A","10","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","9591" +"*/peeping-client.exe*",".{0,1000}\/peeping\-client\.exe.{0,1000}","offensive_tool_keyword","peeping-tom","Remote keylogger for Windows written in C++","T1056.001 - T1123 - T1129 - T1113","TA0006 - TA0008 - TA0009","N/A","Dispossessor","Collection","https://github.com/shehzade/peeping-tom","1","1","N/A","keylogger","10","1","3","0","2022-07-24T09:31:59Z","2022-04-15T14:16:41Z","9592" +"*/peeping-tom.app*",".{0,1000}\/peeping\-tom\.app.{0,1000}","offensive_tool_keyword","peeping-tom","Remote keylogger for Windows written in C++","T1056.001 - T1123 - T1129 - T1113","TA0006 - TA0008 - TA0009","N/A","Dispossessor","Collection","https://github.com/shehzade/peeping-tom","1","1","#macos","keylogger","10","1","3","0","2022-07-24T09:31:59Z","2022-04-15T14:16:41Z","9593" +"*/peeping-tom.exe*",".{0,1000}\/peeping\-tom\.exe.{0,1000}","offensive_tool_keyword","peeping-tom","Remote keylogger for Windows written in C++","T1056.001 - T1123 - T1129 - T1113","TA0006 - TA0008 - TA0009","N/A","Dispossessor","Collection","https://github.com/shehzade/peeping-tom","1","1","N/A","keylogger","10","1","3","0","2022-07-24T09:31:59Z","2022-04-15T14:16:41Z","9594" +"*/peeping-tom.git*",".{0,1000}\/peeping\-tom\.git.{0,1000}","offensive_tool_keyword","peeping-tom","Remote keylogger for Windows written in C++","T1056.001 - T1123 - T1129 - T1113","TA0006 - TA0008 - TA0009","N/A","Dispossessor","Collection","https://github.com/shehzade/peeping-tom","1","1","N/A","keylogger","10","1","3","0","2022-07-24T09:31:59Z","2022-04-15T14:16:41Z","9595" +"*/PeerToPeerService.*",".{0,1000}\/PeerToPeerService\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","9596" +"*/peinjector*",".{0,1000}\/peinjector.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","9597" +"*/peinjector.*",".{0,1000}\/peinjector\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","9598" +"*/pendulum.git*",".{0,1000}\/pendulum\.git.{0,1000}","offensive_tool_keyword","pendulum","Linux Sleep Obfuscation","T1027 - T1036","TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/kyleavery/pendulum","1","1","#linux","N/A","9","1","95","11","2024-01-07T20:33:01Z","2024-01-07T20:32:38Z","9599" +"*/PE-Obfuscator*",".{0,1000}\/PE\-Obfuscator.{0,1000}","offensive_tool_keyword","PE-Obfuscator","PE obfuscator with Evasion in mind","T1027 - T1055 - T1140 - T1564.003 - T1027.002","TA0006 - TA0002","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/PE-Obfuscator","1","1","N/A","N/A","N/A","3","213","40","2023-04-25T04:58:12Z","2023-04-25T04:00:15Z","9601" +"*/Perfusion.exe*",".{0,1000}\/Perfusion\.exe.{0,1000}","offensive_tool_keyword","Perfusion","Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)","T1068 - T1055 - T1548.002","TA0003 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/itm4n/Perfusion","1","1","N/A","N/A","10","5","419","75","2021-04-22T16:20:32Z","2021-02-11T18:28:22Z","9604" +"*/Perfusion.git*",".{0,1000}\/Perfusion\.git.{0,1000}","offensive_tool_keyword","Perfusion","Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)","T1068 - T1055 - T1548.002","TA0003 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/itm4n/Perfusion","1","1","N/A","N/A","10","5","419","75","2021-04-22T16:20:32Z","2021-02-11T18:28:22Z","9605" +"*/PerfusionDll.dll*",".{0,1000}\/PerfusionDll\.dll.{0,1000}","offensive_tool_keyword","Perfusion","Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)","T1068 - T1055 - T1548.002","TA0003 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/itm4n/Perfusion","1","1","N/A","N/A","10","5","419","75","2021-04-22T16:20:32Z","2021-02-11T18:28:22Z","9606" +"*/Perl Web Shell by RST-GHC.pl*",".{0,1000}\/Perl\sWeb\sShell\sby\sRST\-GHC\.pl.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","9608" +"*/perl-reverse-shell.pl*",".{0,1000}\/perl\-reverse\-shell\.pl.{0,1000}","offensive_tool_keyword","webshell","A collection of webshell","T1505.003 - T1100 - T1190 - T1505.004","TA0003 - TA0011 ","N/A","N/A","Persistence","https://github.com/Peaky-XD/webshell","1","1","N/A","N/A","10","","N/A","","","","9609" +"*/perlweb_shell.pl*",".{0,1000}\/perlweb_shell\.pl.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","9610" +"*/persist.tpl*",".{0,1000}\/persist\.tpl.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","9611" +"*/persist_bitsadmin.py*",".{0,1000}\/persist_bitsadmin\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","9612" +"*/persist_cortana.py*",".{0,1000}\/persist_cortana\.py.{0,1000}","offensive_tool_keyword","ToRat","ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication","T1219 - T1021 - T1105","TA0008 - TA0011 - TA0005","N/A","N/A","C2","https://github.com/lu4p/ToRat","1","1","N/A","N/A","10","10","995","199","2023-03-13T08:56:55Z","2019-01-19T11:44:01Z","9613" +"*/persist_cortana.py*",".{0,1000}\/persist_cortana\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","9614" +"*/persist_dll_explorer.py*",".{0,1000}\/persist_dll_explorer\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","9615" +"*/persist_hkcu_run.py*",".{0,1000}\/persist_hkcu_run\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","#registry","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","9616" +"*/persist_hklm_run.py*",".{0,1000}\/persist_hklm_run\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","#registry","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","9617" +"*/persist_ifeo.py*",".{0,1000}\/persist_ifeo\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","9618" +"*/persist_mofcomp.py*",".{0,1000}\/persist_mofcomp\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","9619" +"*/persist_people.py*",".{0,1000}\/persist_people\.py.{0,1000}","offensive_tool_keyword","ToRat","ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication","T1219 - T1021 - T1105","TA0008 - TA0011 - TA0005","N/A","N/A","C2","https://github.com/lu4p/ToRat","1","1","N/A","N/A","10","10","995","199","2023-03-13T08:56:55Z","2019-01-19T11:44:01Z","9620" +"*/persist_people.py*",".{0,1000}\/persist_people\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","9621" +"*/persist_schtask.py*",".{0,1000}\/persist_schtask\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","9622" +"*/persist_startup_files.py*",".{0,1000}\/persist_startup_files\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","9623" +"*/persist_userinit.py*",".{0,1000}\/persist_userinit\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","9624" +"*/persist_wmic.py*",".{0,1000}\/persist_wmic\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","9625" +"*/PersistBOF/*",".{0,1000}\/PersistBOF\/.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to automate common persistence tasks for red teamers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/IcebreakerSecurity/PersistBOF","1","1","N/A","N/A","10","10","274","44","2023-03-07T11:23:42Z","2022-03-29T14:50:47Z","9626" +"*/persistence/*.ps1",".{0,1000}\/persistence\/.{0,1000}\.ps1","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1133","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","9628" +"*/persistence/*.psm1",".{0,1000}\/persistence\/.{0,1000}\.psm1","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1134","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","9629" +"*/Persistence/InstallUtil.*",".{0,1000}\/Persistence\/InstallUtil\..{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","9630" +"*/persistence_demos.git*",".{0,1000}\/persistence_demos\.git.{0,1000}","offensive_tool_keyword","persistence_demos","Demos of various (also non standard) persistence methods used by malware","T1546 - T1547 - T1133 - T1053 - T1037","TA0003 ","N/A","N/A","Persistence","https://github.com/hasherezade/persistence_demos","1","1","N/A","N/A","7","3","221","47","2023-03-05T17:01:14Z","2017-05-16T09:08:47Z","9631" +"*/persistence2.rc*",".{0,1000}\/persistence2\.rc.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","9632" +"*/Persistence-Accessibility-Features.git*",".{0,1000}\/Persistence\-Accessibility\-Features\.git.{0,1000}","offensive_tool_keyword","Persistence-Accessibility-Features","automated sticky keys backdoor","T1174 - T1078 - T1546.013","TA0003","N/A","N/A","Persistence","https://github.com/Ignitetechnologies/Persistence-Accessibility-Features","1","1","N/A","N/A","9","1","34","12","2020-05-18T05:59:58Z","2020-05-18T05:59:23Z","9633" +"*/PersistViaScheduledTask.ahk*",".{0,1000}\/PersistViaScheduledTask\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","9634" +"*/persit_linux.go*",".{0,1000}\/persit_linux\.go.{0,1000}","offensive_tool_keyword","ToRat","ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication","T1219 - T1021 - T1105","TA0008 - TA0011 - TA0005","N/A","N/A","C2","https://github.com/lu4p/ToRat","1","1","#linux","N/A","10","10","995","199","2023-03-13T08:56:55Z","2019-01-19T11:44:01Z","9635" +"*/persit_windows.go*",".{0,1000}\/persit_windows\.go.{0,1000}","offensive_tool_keyword","ToRat","ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication","T1219 - T1021 - T1105","TA0008 - TA0011 - TA0005","N/A","N/A","C2","https://github.com/lu4p/ToRat","1","1","N/A","N/A","10","10","995","199","2023-03-13T08:56:55Z","2019-01-19T11:44:01Z","9636" +"*/peterspbr/dirty-pipe-otw*",".{0,1000}\/peterspbr\/dirty\-pipe\-otw.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/peterspbr/dirty-pipe-otw","1","1","N/A","N/A","N/A","1","1","0","2022-03-10T03:42:15Z","2022-03-09T17:21:17Z","9637" +"*/PetitPotam.exe*",".{0,1000}\/PetitPotam\.exe.{0,1000}","offensive_tool_keyword","petipotam","PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.","T1557.001 - T1021","TA0008","N/A","N/A","Lateral Movement","https://github.com/topotam/PetitPotam","1","1","N/A","N/A","10","10","1944","290","2024-08-15T03:52:26Z","2021-07-18T18:19:54Z","9638" +"*/PetitPotam.git*",".{0,1000}\/PetitPotam\.git.{0,1000}","offensive_tool_keyword","petipotam","PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.","T1557.001 - T1021","TA0008","N/A","N/A","Lateral Movement","https://github.com/topotam/PetitPotam","1","1","N/A","N/A","10","10","1944","290","2024-08-15T03:52:26Z","2021-07-18T18:19:54Z","9639" +"*/petitpotam.py*",".{0,1000}\/petitpotam\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","9640" +"*/PetitPotato.cpp*",".{0,1000}\/PetitPotato\.cpp.{0,1000}","offensive_tool_keyword","PetitPotato","Local privilege escalation via PetitPotam (Abusing impersonate privileges)","T1134.005 - T1548.001","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/wh0amitz/PetitPotato","1","1","N/A","N/A","10","5","430","52","2023-03-30T10:45:00Z","2022-04-19T19:59:19Z","9641" +"*/PetitPotato.git*",".{0,1000}\/PetitPotato\.git.{0,1000}","offensive_tool_keyword","PetitPotato","Local privilege escalation via PetitPotam (Abusing impersonate privileges)","T1134.005 - T1548.001","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/wh0amitz/PetitPotato","1","1","N/A","N/A","10","5","430","52","2023-03-30T10:45:00Z","2022-04-19T19:59:19Z","9642" +"*/PetitPotato-1.0.0.zip*",".{0,1000}\/PetitPotato\-1\.0\.0\.zip.{0,1000}","offensive_tool_keyword","PetitPotato","Local privilege escalation via PetitPotam (Abusing impersonate privileges)","T1134.005 - T1548.001","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/wh0amitz/PetitPotato","1","1","N/A","N/A","10","5","430","52","2023-03-30T10:45:00Z","2022-04-19T19:59:19Z","9643" +"*/PEzor.cna*",".{0,1000}\/PEzor\.cna.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","9644" +"*/PEzor.git*",".{0,1000}\/PEzor\.git.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1027 - T1045 - T1055 - T1140 - T1204 - T1218","TA0005 - TA0043","N/A","N/A","Defense Evasion","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","9645" +"*/PEzor.git*",".{0,1000}\/PEzor\.git.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","9646" +"*/PEzor/inject.cpp*",".{0,1000}\/PEzor\/inject\.cpp.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","9649" +"*/pfsense_clickjacking*",".{0,1000}\/pfsense_clickjacking.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","9650" +"*/pgsql-brute.nse*",".{0,1000}\/pgsql\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9657" +"*/Phant0m.git*",".{0,1000}\/Phant0m\.git.{0,1000}","offensive_tool_keyword","Phant0m","Windows Event Log Killer","T1070.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/hlldz/Phant0m","1","1","N/A","N/A","N/A","10","1781","301","2023-09-21T16:08:18Z","2017-05-02T17:19:30Z","9658" +"*/phant0m-exe*",".{0,1000}\/phant0m\-exe.{0,1000}","offensive_tool_keyword","Phant0m","Windows Event Log Killer","T1070.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/hlldz/Phant0m","1","1","N/A","N/A","N/A","10","1781","301","2023-09-21T16:08:18Z","2017-05-02T17:19:30Z","9659" +"*/PhishCreds.ps1*",".{0,1000}\/PhishCreds\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","9660" +"*/phishery.exe*",".{0,1000}\/phishery\.exe.{0,1000}","offensive_tool_keyword","phishery","Phishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document.","T1566.001 - T1071 - T1204.002","TA0001 ","N/A","BERSERK BEAR","Phishing","https://github.com/ryhanson/phishery","1","1","N/A","N/A","9","10","993","209","2017-09-11T15:42:10Z","2016-09-25T02:19:24Z","9661" +"*/phishery.git*",".{0,1000}\/phishery\.git.{0,1000}","offensive_tool_keyword","phishery","Phishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document.","T1566.001 - T1071 - T1204.002","TA0001 ","N/A","BERSERK BEAR","Phishing","https://github.com/ryhanson/phishery","1","1","N/A","N/A","9","10","993","209","2017-09-11T15:42:10Z","2016-09-25T02:19:24Z","9662" +"*/phishery/releases/download/*",".{0,1000}\/phishery\/releases\/download\/.{0,1000}","offensive_tool_keyword","phishery","Phishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document.","T1566.001 - T1071 - T1204.002","TA0001 ","N/A","BERSERK BEAR","Phishing","https://github.com/ryhanson/phishery","1","1","N/A","N/A","9","10","993","209","2017-09-11T15:42:10Z","2016-09-25T02:19:24Z","9663" +"*/phishing.py*",".{0,1000}\/phishing\.py.{0,1000}","offensive_tool_keyword","Vajra","Vajra is a UI based tool with multiple techniques for attacking and enumerating in target's Azure environment","T1087 - T1098 - T1583 - T1078 - T1110 - T1566 - T1537 - T1020 - T1526 - T1482","TA0003 - TA0006 - TA0007 - TA0008 - TA0009","N/A","N/A","Exploitation tool","https://github.com/TROUBLE-1/Vajra","1","1","N/A","N/A","N/A","4","391","61","2025-02-21T16:40:23Z","2022-03-01T14:31:27Z","9664" +"*/phishing/*.html*",".{0,1000}\/phishing\/.{0,1000}\.html.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","9666" +"*/phishing/password_box*",".{0,1000}\/phishing\/password_box.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","9667" +"*/PhishingServer/*",".{0,1000}\/PhishingServer\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","9669" +"*/phishlets/example.yaml*",".{0,1000}\/phishlets\/example\.yaml.{0,1000}","offensive_tool_keyword","evilginx2","Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication","T1557.002 - T1114 - T1539","TA0001","N/A","BlackCat - COLDRIVER","Phishing","https://github.com/kgretzky/evilginx2","1","1","#linux","N/A","10","10","12879","2234","2025-01-21T15:16:19Z","2018-07-10T09:59:52Z","9670" +"*/php_custom_spy_for_mysql.php*",".{0,1000}\/php_custom_spy_for_mysql\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","9671" +"*/php_reverse_shell.php*",".{0,1000}\/php_reverse_shell\.php.{0,1000}","offensive_tool_keyword","php-reverse-shell","PHP shells that work on Linux OS - macOS and Windows OS","T1505.003 - T1059.003 - T1100","TA0003 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/ivan-sincek/php-reverse-shell","1","1","N/A","N/A","10","10","482","152","2023-10-03T09:48:21Z","2020-07-14T07:22:54Z","9672" +"*/php_webshell.py*",".{0,1000}\/php_webshell\.py.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","9673" +"*/php-backdoor.php*",".{0,1000}\/php\-backdoor\.php.{0,1000}","offensive_tool_keyword","webshell","A collection of webshell","T1505.003 - T1100 - T1190 - T1505.004","TA0003 - TA0011 ","N/A","N/A","Persistence","https://github.com/Peaky-XD/webshell","1","1","N/A","N/A","10","","N/A","","","","9674" +"*/php-backdoor.php*",".{0,1000}\/php\-backdoor\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","9675" +"*/phpkit.py*",".{0,1000}\/phpkit\.py.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","9676" +"*/phpkitcli.py*",".{0,1000}\/phpkitcli\.py.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","9677" +"*/PHPRemoteView.php*",".{0,1000}\/PHPRemoteView\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","9678" +"*/php-reverse-shell.git*",".{0,1000}\/php\-reverse\-shell\.git.{0,1000}","offensive_tool_keyword","php-reverse-shell","PHP shells that work on Linux OS - macOS and Windows OS","T1505.003 - T1059.003 - T1100","TA0003 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/ivan-sincek/php-reverse-shell","1","1","N/A","N/A","10","10","482","152","2023-10-03T09:48:21Z","2020-07-14T07:22:54Z","9679" +"*/php-reverse-shell/releases/*",".{0,1000}\/php\-reverse\-shell\/releases\/.{0,1000}","offensive_tool_keyword","php-reverse-shell","PHP shells that work on Linux OS - macOS and Windows OS","T1505.003 - T1059.003 - T1100","TA0003 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/ivan-sincek/php-reverse-shell","1","1","N/A","N/A","10","10","482","152","2023-10-03T09:48:21Z","2020-07-14T07:22:54Z","9680" +"*/php-reverse-shell/zipball/*",".{0,1000}\/php\-reverse\-shell\/zipball\/.{0,1000}","offensive_tool_keyword","php-reverse-shell","PHP shells that work on Linux OS - macOS and Windows OS","T1505.003 - T1059.003 - T1100","TA0003 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/ivan-sincek/php-reverse-shell","1","1","N/A","N/A","10","10","482","152","2023-10-03T09:48:21Z","2020-07-14T07:22:54Z","9681" +"*/phpshell.php*",".{0,1000}\/phpshell\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","9682" +"*/phpsploit.git*",".{0,1000}\/phpsploit\.git.{0,1000}","offensive_tool_keyword","PhpSploit","Full-featured C2 framework which silently persists on webserver via evil PHP oneliner","T1505.003 - T1505 - T1059 - T1219 - T1547","TA0003 - TA0011 - TA0005","N/A","N/A","C2","https://github.com/nil0x42/phpsploit","1","1","N/A","N/A","10","10","2331","453","2024-05-06T13:49:14Z","2014-05-21T19:43:03Z","9683" +"*/PHPSPY.php*",".{0,1000}\/PHPSPY\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","9685" +"*/PHVNC.exe*",".{0,1000}\/PHVNC\.exe.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","9686" +"*/physmem2minidump.py*",".{0,1000}\/physmem2minidump\.py.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","1","N/A","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","9687" +"*/physmem2profit.git*",".{0,1000}\/physmem2profit\.git.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","1","N/A","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","9688" +"*/PickleC2.git*",".{0,1000}\/PickleC2\.git.{0,1000}","offensive_tool_keyword","PickleC2","PickleC2 is a post-exploitation and Lateral Movements framework","T1059.006 - T1021 - T1071 - T1550 - T1560 - T1570","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/xRET2pwn/PickleC2","1","1","N/A","N/A","10","10","91","20","2021-07-26T21:12:04Z","2021-07-13T09:16:19Z","9689" +"*/pico_plus_user.sql*",".{0,1000}\/pico_plus_user\.sql.{0,1000}","offensive_tool_keyword","pico","hacker labs - open source and managed web services leveraging SSH","T1021.005 - T1078 - T1105 - T1109 - T1197 - T1213","TA0005 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/picosh/pico","1","1","N/A","N/A","10","10","1129","36","2025-04-22T17:33:17Z","2022-08-24T03:14:52Z","9690" +"*/PILOT/ATC.py*",".{0,1000}\/PILOT\/ATC\.py.{0,1000}","offensive_tool_keyword","PILOT","Pilot is a simplified system designed for the stealthy transfer of files across networks using ICMP","T1048.001 - T1573.001 - T1020","TA0010 - TA0002 - TA0009","N/A","N/A","Data Exfiltration","https://github.com/dahvidschloss/PILOT","1","1","N/A","N/A","9","1","79","7","2024-04-16T18:24:44Z","2024-04-03T15:04:33Z","9692" +"*/PILOT/PILOT.ps1*",".{0,1000}\/PILOT\/PILOT\.ps1.{0,1000}","offensive_tool_keyword","PILOT","Pilot is a simplified system designed for the stealthy transfer of files across networks using ICMP","T1048.001 - T1573.001 - T1020","TA0010 - TA0002 - TA0009","N/A","N/A","Data Exfiltration","https://github.com/dahvidschloss/PILOT","1","1","N/A","N/A","9","1","79","7","2024-04-16T18:24:44Z","2024-04-03T15:04:33Z","9693" +"*/ping6.py*",".{0,1000}\/ping6\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","9694" +"*/PingRAT.git*",".{0,1000}\/PingRAT\.git.{0,1000}","offensive_tool_keyword","PingRAT","secretly passes Command and Control (C2) traffic through firewalls using ICMP payloads","T1071.004 - T1573.001","TA0011 - TA0042","N/A","N/A","C2","https://github.com/umutcamliyurt/PingRAT","1","1","N/A","N/A","10","10","416","55","2023-09-29T22:26:15Z","2023-09-29T22:07:46Z","9698" +"*/PipeViewer.exe*",".{0,1000}\/PipeViewer\.exe.{0,1000}","offensive_tool_keyword","PipeViewer ","A tool that shows detailed information about named pipes in Windows","T1022.002 - T1056.002","TA0005 - TA0009","N/A","N/A","discovery","https://github.com/cyberark/PipeViewer","1","1","N/A","N/A","5","7","620","55","2024-11-15T09:55:35Z","2022-12-22T12:35:34Z","9700" +"*/PipeViewer.git*",".{0,1000}\/PipeViewer\.git.{0,1000}","offensive_tool_keyword","PipeViewer ","A tool that shows detailed information about named pipes in Windows","T1022.002 - T1056.002","TA0005 - TA0009","N/A","N/A","discovery","https://github.com/cyberark/PipeViewer","1","1","N/A","N/A","5","7","620","55","2024-11-15T09:55:35Z","2022-12-22T12:35:34Z","9701" +"*/PipeViewer.sln*",".{0,1000}\/PipeViewer\.sln.{0,1000}","offensive_tool_keyword","PipeViewer ","A tool that shows detailed information about named pipes in Windows","T1022.002 - T1056.002","TA0005 - TA0009","N/A","N/A","discovery","https://github.com/cyberark/PipeViewer","1","1","N/A","N/A","5","7","620","55","2024-11-15T09:55:35Z","2022-12-22T12:35:34Z","9702" +"*/PipeViewer/Program.cs*",".{0,1000}\/PipeViewer\/Program\.cs.{0,1000}","offensive_tool_keyword","PipeViewer ","A tool that shows detailed information about named pipes in Windows","T1022.002 - T1056.002","TA0005 - TA0009","N/A","N/A","discovery","https://github.com/cyberark/PipeViewer","1","1","N/A","N/A","5","7","620","55","2024-11-15T09:55:35Z","2022-12-22T12:35:34Z","9703" +"*/pitty_tiger.profile*",".{0,1000}\/pitty_tiger\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","9704" +"*/pivotnacci.git*",".{0,1000}\/pivotnacci\.git.{0,1000}","offensive_tool_keyword","pivotnacci","A tool to make socks connections through HTTP agents","T1090 - T1090.003","TA0003 - TA0011","N/A","Sandworm","C2","https://github.com/blackarrowsec/pivotnacci","1","1","N/A","N/A","9","10","697","114","2021-03-30T14:37:25Z","2020-04-28T11:36:45Z","9705" +"*/pixiewps/archive/master.zip*",".{0,1000}\/pixiewps\/archive\/master\.zip.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","1","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","9708" +"*/pjl-info-config.nse*",".{0,1000}\/pjl\-info\-config\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://github.com/nccgroup/nmap-nse-vulnerability-scripts","1","1","N/A","N/A","N/A","7","627","59","2022-03-04T09:08:55Z","2021-05-18T15:20:30Z","9709" +"*/pjl-ready-message.nse*",".{0,1000}\/pjl\-ready\-message\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9710" +"*/pkg/merlin.go*",".{0,1000}\/pkg\/merlin\.go.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","9711" +"*/PKINITtools*",".{0,1000}\/PKINITtools.{0,1000}","offensive_tool_keyword","PKINITtools","Tools for Kerberos PKINIT and relaying to AD CS","T1550.003 - T1557.002 - T1552.004 - T1212 - T1550","TA0009 - TA0008","N/A","N/A","Lateral Movement","https://github.com/dirkjanm/PKINITtools","1","1","N/A","N/A","N/A","8","737","82","2025-01-03T14:25:52Z","2021-07-27T19:06:09Z","9712" +"*/Plasma RAT.exe*",".{0,1000}\/Plasma\sRAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","9713" +"*/Plazmaz/LNKUp*",".{0,1000}\/Plazmaz\/LNKUp.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","9714" +"*/Plugins/HRDP.dll*",".{0,1000}\/Plugins\/HRDP\.dll.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","9715" +"*/Plugins/HVNC.dll*",".{0,1000}\/Plugins\/HVNC\.dll.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","9716" +"*/Plugins/PreventSleep.dll*",".{0,1000}\/Plugins\/PreventSleep\.dll.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","9717" +"*/POC/driverdump/*",".{0,1000}\/POC\/driverdump\/.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","9719" +"*/PoC/PrivilegeEscalation*",".{0,1000}\/PoC\/PrivilegeEscalation.{0,1000}","offensive_tool_keyword","echoac-poc","poc stealing the Kernel's KPROCESS/EPROCESS block and writing it to a newly spawned shell to elevate its privileges to the highest possible - nt authority\system","T1068 - T1203 - T1059.003","TA0002 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/kite03/echoac-poc","1","1","N/A","N/A","8","2","138","25","2024-01-09T16:44:00Z","2023-06-28T00:52:22Z","9720" +"*/POC_DLL.vcxproj*",".{0,1000}\/POC_DLL\.vcxproj.{0,1000}","offensive_tool_keyword","RunAsWinTcb","RunAsWinTcb uses an userland exploit to run a DLL with a protection level of WinTcb-Light.","T1073.002 - T1055.001 - T1055.002","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/tastypepperoni/RunAsWinTcb","1","1","N/A","N/A","10","2","132","17","2022-08-02T16:35:50Z","2022-07-29T16:36:06Z","9721" +"*/PoC-CVE-2023-21554*",".{0,1000}\/PoC\-CVE\-2023\-21554.{0,1000}","offensive_tool_keyword","poc","Windows Message Queuing vulnerability exploitation with custom payloads","T1192 - T1507","TA0002","N/A","N/A","Exploitation tool","https://github.com/Hashi0x/PoC-CVE-2023-21554","1","1","N/A","network exploitation tool","N/A","","N/A","","","","9722" +"*/poisoners/*.py",".{0,1000}\/poisoners\/.{0,1000}\.py","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","N/A","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","9723" +"*/PoolParty.cpp*",".{0,1000}\/PoolParty\.cpp.{0,1000}","offensive_tool_keyword","PoolParty","A set of fully-undetectable process injection techniques abusing Windows Thread Pools","T1055","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/SafeBreach-Labs/PoolParty","1","1","N/A","N/A","9","10","1088","143","2023-12-11T10:52:05Z","2023-05-21T16:13:32Z","9726" +"*/PoolParty.exe*",".{0,1000}\/PoolParty\.exe.{0,1000}","offensive_tool_keyword","PoolParty","A set of fully-undetectable process injection techniques abusing Windows Thread Pools","T1055","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/SafeBreach-Labs/PoolParty","1","1","N/A","N/A","9","10","1088","143","2023-12-11T10:52:05Z","2023-05-21T16:13:32Z","9727" +"*/PoolParty.git*",".{0,1000}\/PoolParty\.git.{0,1000}","offensive_tool_keyword","PoolParty","A set of fully-undetectable process injection techniques abusing Windows Thread Pools","T1055","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/SafeBreach-Labs/PoolParty","1","1","N/A","N/A","9","10","1088","143","2023-12-11T10:52:05Z","2023-05-21T16:13:32Z","9728" +"*/PoolParty.hpp*",".{0,1000}\/PoolParty\.hpp.{0,1000}","offensive_tool_keyword","PoolParty","A set of fully-undetectable process injection techniques abusing Windows Thread Pools","T1055","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/SafeBreach-Labs/PoolParty","1","1","N/A","N/A","9","10","1088","143","2023-12-11T10:52:05Z","2023-05-21T16:13:32Z","9729" +"*/PoolParty.sln*",".{0,1000}\/PoolParty\.sln.{0,1000}","offensive_tool_keyword","PoolParty","A set of fully-undetectable process injection techniques abusing Windows Thread Pools","T1055","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/SafeBreach-Labs/PoolParty","1","1","N/A","N/A","9","10","1088","143","2023-12-11T10:52:05Z","2023-05-21T16:13:32Z","9730" +"*/PoolParty.vcxproj*",".{0,1000}\/PoolParty\.vcxproj.{0,1000}","offensive_tool_keyword","PoolParty","A set of fully-undetectable process injection techniques abusing Windows Thread Pools","T1055","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/SafeBreach-Labs/PoolParty","1","1","N/A","N/A","9","10","1088","143","2023-12-11T10:52:05Z","2023-05-21T16:13:32Z","9731" +"*/PoolPartyBof.git*",".{0,1000}\/PoolPartyBof\.git.{0,1000}","offensive_tool_keyword","PoolPartyBof","A beacon object file implementation of PoolParty Process Injection Technique","T1055.011 - T1055 - T1620","TA0005","N/A","Black Basta","Privilege Escalation","https://github.com/0xEr3bus/PoolPartyBof","1","1","N/A","N/A","10","4","380","44","2023-12-21T19:00:20Z","2023-12-11T19:28:20Z","9734" +"*/PoolPartyBof/releases/download/*",".{0,1000}\/PoolPartyBof\/releases\/download\/.{0,1000}","offensive_tool_keyword","PoolPartyBof","A beacon object file implementation of PoolParty Process Injection Technique","T1055.011 - T1055 - T1620","TA0005","N/A","Black Basta","Privilege Escalation","https://github.com/0xEr3bus/PoolPartyBof","1","1","N/A","N/A","10","4","380","44","2023-12-21T19:00:20Z","2023-12-11T19:28:20Z","9736" +"*/PoolPartyBof/tarball/*",".{0,1000}\/PoolPartyBof\/tarball\/.{0,1000}","offensive_tool_keyword","PoolPartyBof","A beacon object file implementation of PoolParty Process Injection Technique","T1055.011 - T1055 - T1620","TA0005","N/A","Black Basta","Privilege Escalation","https://github.com/0xEr3bus/PoolPartyBof","1","1","N/A","N/A","10","4","380","44","2023-12-21T19:00:20Z","2023-12-11T19:28:20Z","9737" +"*/PoolPartyBof/zipball/*",".{0,1000}\/PoolPartyBof\/zipball\/.{0,1000}","offensive_tool_keyword","PoolPartyBof","A beacon object file implementation of PoolParty Process Injection Technique","T1055.011 - T1055 - T1620","TA0005","N/A","Black Basta","Privilege Escalation","https://github.com/0xEr3bus/PoolPartyBof","1","1","N/A","N/A","10","4","380","44","2023-12-21T19:00:20Z","2023-12-11T19:28:20Z","9738" +"*/pop_exfil_client.py*",".{0,1000}\/pop_exfil_client\.py.{0,1000}","offensive_tool_keyword","PyExfil","A Python Package for Data Exfiltration","T1041 - T1567 - T1027","TA0011 - TA0009 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/ytisf/PyExfil","1","1","N/A","N/A","10","8","782","141","2024-05-07T07:58:02Z","2014-11-27T19:06:24Z","9739" +"*/pop_exfil_server.py*",".{0,1000}\/pop_exfil_server\.py.{0,1000}","offensive_tool_keyword","PyExfil","A Python Package for Data Exfiltration","T1041 - T1567 - T1027","TA0011 - TA0009 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/ytisf/PyExfil","1","1","N/A","N/A","10","8","782","141","2024-05-07T07:58:02Z","2014-11-27T19:06:24Z","9740" +"*/pop3-brute.nse*",".{0,1000}\/pop3\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9741" +"*/pop3-capabilities.nse*",".{0,1000}\/pop3\-capabilities\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9742" +"*/pop3-ntlm-info.nse*",".{0,1000}\/pop3\-ntlm\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9743" +"*/popCalc.bin*",".{0,1000}\/popCalc\.bin.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF that spawns a sacrificial process. injects it with shellcode. and executes payload. Built to evade EDR/UserLand hooks by spawning sacrificial process with Arbitrary Code Guard (ACG). BlockDll. and PPID spoofing.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/spawn","1","1","N/A","N/A","10","10","455","73","2023-03-08T15:53:44Z","2021-07-17T16:35:59Z","9744" +"*/port_reuse.py*",".{0,1000}\/port_reuse\.py.{0,1000}","offensive_tool_keyword","Venom","Venom - A Multi-hop Proxy for Penetration Testers","T1090","TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/Dliv3/Venom","1","1","N/A","N/A","10","10","2070","357","2022-05-11T03:13:20Z","2019-01-13T07:35:29Z","9745" +"*/port_scan.py*",".{0,1000}\/port_scan\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","9746" +"*/PortBender/*",".{0,1000}\/PortBender\/.{0,1000}","offensive_tool_keyword","cobaltstrike","PortBender is a TCP port redirection utility that allows a red team operator to redirect inbound traffic ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/praetorian-inc/PortBender","1","1","N/A","N/A","10","10","712","111","2023-01-31T09:44:16Z","2021-05-27T02:46:29Z","9747" +"*/portscan.cna*",".{0,1000}\/portscan\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Various Cobalt Strike BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rvrsh3ll/BOF_Collection","1","1","N/A","N/A","10","10","635","57","2022-10-16T13:57:18Z","2020-07-16T18:24:55Z","9760" +"*/Portscan.exe*",".{0,1000}\/Portscan\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","9761" +"*/Portscan.exe*",".{0,1000}\/Portscan\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","9762" +"*/portscan.git*",".{0,1000}\/portscan\.git.{0,1000}","offensive_tool_keyword","portscan","A simple TCP and UDP portscanner written in Go","T1595 - T1596 - T1594","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/zs5460/portscan","1","1","N/A","N/A","N/A","1","14","4","2022-11-11T09:26:47Z","2019-06-04T09:00:00Z","9763" +"*/Port-Scan.ps1*",".{0,1000}\/Port\-Scan\.ps1.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","9764" +"*/portscan.yaml*",".{0,1000}\/portscan\.yaml.{0,1000}","offensive_tool_keyword","Osmedeus","Osmedeus - A Workflow Engine for Offensive Security","T1595","TA0043","N/A","N/A","Exploitation tool","https://github.com/j3ssie/osmedeus","1","1","N/A","N/A","N/A","10","5566","907","2025-04-22T14:57:07Z","2018-11-10T04:17:18Z","9765" +"*/portscan/releases/*",".{0,1000}\/portscan\/releases\/.{0,1000}","offensive_tool_keyword","portscan","A simple TCP and UDP portscanner written in Go","T1595 - T1596 - T1594","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/zs5460/portscan","1","1","N/A","N/A","N/A","1","14","4","2022-11-11T09:26:47Z","2019-06-04T09:00:00Z","9766" +"*/PortScanner.ahk*",".{0,1000}\/PortScanner\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","9767" +"*/port-scan-tcp.ps1*",".{0,1000}\/port\-scan\-tcp\.ps1.{0,1000}","offensive_tool_keyword","Minimalistic-offensive","A repository of tools for pentesting of restricted and isolated environments.","T1110 - T1046 - T1021 - T1203 - T1485","TA0006 - TA0007 - TA0008","N/A","Dispossessor","Discovery","https://github.com/InfosecMatter/Minimalistic-offensive-security-tools","1","1","N/A","N/A","7","6","562","121","2021-10-26T11:04:46Z","2020-05-10T17:40:31Z","9768" +"*/port-scan-udp.ps1*",".{0,1000}\/port\-scan\-udp\.ps1.{0,1000}","offensive_tool_keyword","Minimalistic-offensive","A repository of tools for pentesting of restricted and isolated environments.","T1110 - T1046 - T1021 - T1203 - T1485","TA0006 - TA0007 - TA0008","N/A","Dispossessor","Discovery","https://github.com/InfosecMatter/Minimalistic-offensive-security-tools","1","1","N/A","N/A","7","6","562","121","2021-10-26T11:04:46Z","2020-05-10T17:40:31Z","9769" +"*/port-states.nse*",".{0,1000}\/port\-states\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9770" +"*/POSeidon.profile*",".{0,1000}\/POSeidon\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","9771" +"*/posh.tpl*",".{0,1000}\/posh\.tpl.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","9773" +"*/PoshADCS.git*",".{0,1000}\/PoshADCS\.git.{0,1000}","offensive_tool_keyword","PoshADCS","attack vectors against Active Directory by abusing Active Directory Certificate Services (ADCS)","T1213.003 - T1213 - T1098.003 - T1098 - T1484.001","TA0002 - TA0003 - TA0040","N/A","N/A","Persistence","https://github.com/cfalta/PoshADCS","1","1","N/A","N/A","7","2","186","17","2021-07-07T16:47:07Z","2019-10-15T15:54:03Z","9774" +"*/PoshC2*",".{0,1000}\/PoshC2.{0,1000}","offensive_tool_keyword","poshc2","PoshC2 is a proxy aware C2 framework used to aid penetration testers with red teaming. post-exploitation and Lateral Movement. PoshC2 is primarily written in Python3 and follows a modular format to enable users to add their own modules and tools. allowing an extendible and flexible C2 framework. Out-of-the-box PoshC2 comes PowerShell/C# and Python implants with payloads written in PowerShell v2 and v4. C++ and C# source code. a variety of executables. DLLs and raw shellcode in addition to a Python2 payload. These enable C2 functionality on a wide range of devices and operating systems. including Windows. *nix and OSX.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","9775" +"*/PoshC2/*",".{0,1000}\/PoshC2\/.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","9777" +"*/posh-config*",".{0,1000}\/posh\-config.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","9778" +"*/Poshito.dll*",".{0,1000}\/Poshito\.dll.{0,1000}","offensive_tool_keyword","Poshito","Poshito is a Windows C2 over Telegram","T1102 - T1071.001 - T1571 - T1027","TA0011 - TA0005","N/A","N/A","C2","https://github.com/itaymigdal/Poshito","1","1","N/A","N/A","7","10","10","1","2024-10-30T10:40:41Z","2024-09-10T20:14:17Z","9780" +"*/Poshito.exe*",".{0,1000}\/Poshito\.exe.{0,1000}","offensive_tool_keyword","Poshito","Poshito is a Windows C2 over Telegram","T1102 - T1071.001 - T1571 - T1027","TA0011 - TA0005","N/A","N/A","C2","https://github.com/itaymigdal/Poshito","1","1","N/A","N/A","7","10","10","1","2024-10-30T10:40:41Z","2024-09-10T20:14:17Z","9781" +"*/Poshito.git*",".{0,1000}\/Poshito\.git.{0,1000}","offensive_tool_keyword","Poshito","Poshito is a Windows C2 over Telegram","T1102 - T1071.001 - T1571 - T1027","TA0011 - TA0005","N/A","N/A","C2","https://github.com/itaymigdal/Poshito","1","1","N/A","N/A","7","10","10","1","2024-10-30T10:40:41Z","2024-09-10T20:14:17Z","9782" +"*/posh-log*",".{0,1000}\/posh\-log.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","9784" +"*/posh-project*",".{0,1000}\/posh\-project.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","9785" +"*/posh-server*",".{0,1000}\/posh\-server.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","9786" +"*/posh-service*",".{0,1000}\/posh\-service.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","9787" +"*/posh-stop-service*",".{0,1000}\/posh\-stop\-service.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","9788" +"*/posh-update*",".{0,1000}\/posh\-update.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","9789" +"*/post_exploitation*",".{0,1000}\/post_exploitation.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","9790" +"*/PostDump.exe*",".{0,1000}\/PostDump\.exe.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection.","T1003.001 - T1055 - T1564.001","TA0005 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","1","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","9791" +"*/POSTDump.git*",".{0,1000}\/POSTDump\.git.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection.","T1003.001 - T1055 - T1564.001","TA0005 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","1","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","9792" +"*/postLegit/grkg*",".{0,1000}\/postLegit\/grkg.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","9793" +"*/postLegit/qhwl*",".{0,1000}\/postLegit\/qhwl.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","9794" +"*/PotentiallyCrackableAccounts.ps1*",".{0,1000}\/PotentiallyCrackableAccounts\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","9795" +"*/PowerBreach.ps1*",".{0,1000}\/PowerBreach\.ps1.{0,1000}","offensive_tool_keyword","PowerBreach","PowerBreach is a backdoor toolkit that aims to provide the user a wide variety of methods to backdoor a system","T1055 - T1203 - T1105 - T1202 - T1027 - T1059 - T1070","TA0005 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","9796" +"*/PowerBruteLogon*",".{0,1000}\/PowerBruteLogon.{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","1","N/A","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","9797" +"*/powercat.git*",".{0,1000}\/powercat\.git.{0,1000}","offensive_tool_keyword","powercat","Netcat - The powershell version","T1571 - T1048.003 - T1095","TA0042 - TA0011","N/A","N/A","C2","https://github.com/besimorhino/powercat","1","1","N/A","N/A","10","10","2229","482","2024-03-05T18:05:07Z","2014-08-21T14:38:46Z","9798" +"*/powercat.ps1",".{0,1000}\/powercat\.ps1","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","9799" +"*/powercat.ps1*",".{0,1000}\/powercat\.ps1.{0,1000}","offensive_tool_keyword","powercat","Netcat - The powershell version","T1571 - T1048.003 - T1095","TA0042 - TA0011","N/A","N/A","C2","https://github.com/besimorhino/powercat","1","1","N/A","N/A","10","10","2229","482","2024-03-05T18:05:07Z","2014-08-21T14:38:46Z","9800" +"*/PowerExtract.git*",".{0,1000}\/PowerExtract\.git.{0,1000}","offensive_tool_keyword","powerextract","This tool is able to parse memory dumps of the LSASS process without any additional tools (e.g. Debuggers) or additional sideloading of mimikatz. It is a pure PowerShell implementation for parsing and extracting secrets (LSA / MSV and Kerberos) of the LSASS process","T1003 - T1055 - T1003.001 - T1055.012","TA0007 - TA0002","N/A","N/A","Credential Access","https://github.com/powerseb/PowerExtract","1","1","N/A","N/A","N/A","2","117","14","2025-03-28T10:49:43Z","2021-12-11T15:24:44Z","9801" +"*/PowerExtract.git*",".{0,1000}\/PowerExtract\.git.{0,1000}","offensive_tool_keyword","powerextract","This tool is able to parse memory dumps of the LSASS process without any additional tools (e.g. Debuggers) or additional sideloading of mimikatz. It is a pure PowerShell implementation for parsing and extracting secrets (LSA / MSV and Kerberos) of the LSASS process","T1003 - T1055 - T1003.001 - T1055.012","TA0007 - TA0002","N/A","N/A","Credential Access","https://github.com/powerseb/PowerExtract","1","1","N/A","N/A","N/A","2","117","14","2025-03-28T10:49:43Z","2021-12-11T15:24:44Z","9802" +"*/powerfun.ps1*",".{0,1000}\/powerfun\.ps1.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","9803" +"*/powerglot/*",".{0,1000}\/powerglot\/.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","9804" +"*/powerkatz.dll*",".{0,1000}\/powerkatz\.dll.{0,1000}","offensive_tool_keyword","SharpSploit","SharpSploit is a .NET post-exploitation library written in C# that aims to highlight the attack surface of .NET and make the use of offensive .NET easier for red teamers.","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/cobbr/SharpSploit","1","1","N/A","N/A","10","10","1789","312","2021-08-12T18:23:15Z","2018-09-20T14:22:37Z","9805" +"*/powerkatz_x64.dll*",".{0,1000}\/powerkatz_x64\.dll.{0,1000}","offensive_tool_keyword","SharpSploit","SharpSploit is a .NET post-exploitation library written in C# that aims to highlight the attack surface of .NET and make the use of offensive .NET easier for red teamers.","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/cobbr/SharpSploit","1","1","N/A","N/A","10","10","1789","312","2021-08-12T18:23:15Z","2018-09-20T14:22:37Z","9806" +"*/powerkatz_x86.dll*",".{0,1000}\/powerkatz_x86\.dll.{0,1000}","offensive_tool_keyword","SharpSploit","SharpSploit is a .NET post-exploitation library written in C# that aims to highlight the attack surface of .NET and make the use of offensive .NET easier for red teamers.","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/cobbr/SharpSploit","1","1","N/A","N/A","10","10","1789","312","2021-08-12T18:23:15Z","2018-09-20T14:22:37Z","9807" +"*/Powerless.dll*",".{0,1000}\/Powerless\.dll.{0,1000}","offensive_tool_keyword","PowerLess","PowerShell-based modular backdoor that has been used by Magic Hound group","T1560 - T1217 - T1059.001 - T1005 - T1074.001 - T1140 - T1573 - T1105 - T1056.001","TA0011 - TA0009 - TA0010 - TA0005 - TA0002 - TA0006","N/A","Magic Hound","Malware","https://gist.github.com/farzinenddo/bb1f1ecb56aa9326abc7b47fc99e588e","1","1","N/A","N/A","10","4","N/A","N/A","N/A","N/A","9808" +"*/powerloader.py*",".{0,1000}\/powerloader\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","9809" +"*/PowerLurk.git*",".{0,1000}\/PowerLurk\.git.{0,1000}","offensive_tool_keyword","Powerlurk","PowerLurk is a PowerShell toolset for building malicious WMI Event Subsriptions","T1084 - T1059.001 - T1546.003 - T1053.005","TA0003 - TA0005 - TA0002 - TA0006","N/A","N/A","Persistence","https://github.com/Sw4mpf0x/PowerLurk","1","1","N/A","N/A","10","4","384","72","2016-07-25T22:19:22Z","2016-07-13T20:07:25Z","9810" +"*/PowerLurk.ps1*",".{0,1000}\/PowerLurk\.ps1.{0,1000}","offensive_tool_keyword","Powerlurk","PowerLurk is a PowerShell toolset for building malicious WMI Event Subsriptions","T1084 - T1059.001 - T1546.003 - T1053.005","TA0003 - TA0005 - TA0002 - TA0006","N/A","N/A","Persistence","https://github.com/Sw4mpf0x/PowerLurk","1","1","N/A","N/A","10","4","384","72","2016-07-25T22:19:22Z","2016-07-13T20:07:25Z","9811" +"*/Powermad.git*",".{0,1000}\/Powermad\.git.{0,1000}","offensive_tool_keyword","Powermad","PowerShell MachineAccountQuota and DNS exploit tools","T1087 - T1098 - T1018 - T1046 - T1081","TA0007 - TA0006 - TA0005 - TA0001","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/Kevin-Robertson/Powermad","1","1","N/A","N/A","N/A","10","1303","181","2023-01-11T00:48:35Z","2017-09-05T18:34:03Z","9812" +"*/Powermad.ps1*",".{0,1000}\/Powermad\.ps1.{0,1000}","offensive_tool_keyword","KrbRelayUp","a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).","T1558 - T1210","TA0004 - TA0003","N/A","Dispossessor - Back Basta","Privilege Escalation","https://github.com/Dec0ne/KrbRelayUp","1","1","N/A","N/A","10","10","1580","209","2022-08-06T12:23:58Z","2022-04-24T21:33:00Z","9813" +"*/PowerPick.exe*",".{0,1000}\/PowerPick\.exe.{0,1000}","offensive_tool_keyword","Powerpick","allowing the execution of Powershell functionality without the use of Powershell.exe","T1059.001 - T1059.003 - T1086 - T1027.001","TA0005 - TA0002","N/A","Black Basta - Dispossessor","Defense Evasion","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","9814" +"*/Powerpreter.psm1*",".{0,1000}\/Powerpreter\.psm1.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","9815" +"*/PowerProxy.git*",".{0,1000}\/PowerProxy\.git.{0,1000}","offensive_tool_keyword","PowerProxy","PowerShell SOCKS proxy with reverse proxy capabilities","T1090.003 - T1059.001 - T1105","TA0011 - TA0005 - TA0008","N/A","Dispossessor","C2","https://github.com/get-get-get-get/PowerProxy","1","1","N/A","N/A","10","10","80","10","2021-04-23T16:51:28Z","2020-01-03T18:18:58Z","9816" +"*/PowerProxy.ps1*",".{0,1000}\/PowerProxy\.ps1.{0,1000}","offensive_tool_keyword","PowerProxy","PowerShell SOCKS proxy with reverse proxy capabilities","T1090.003 - T1059.001 - T1105","TA0011 - TA0005 - TA0008","N/A","Dispossessor","C2","https://github.com/get-get-get-get/PowerProxy","1","1","N/A","N/A","10","10","80","10","2021-04-23T16:51:28Z","2020-01-03T18:18:58Z","9817" +"*/power-pwn.git*",".{0,1000}\/power\-pwn\.git.{0,1000}","offensive_tool_keyword","power-pwn","An offensive and defensive security toolset for Microsoft 365 Power Platform","T1078 - T1078.004 - T1136 - T1136.001 - T1021 - T1021.003 - T1114 - T1114.002","TA0003 - TA0004 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/mbrg/power-pwn","1","1","N/A","N/A","10","10","939","100","2025-03-20T08:54:43Z","2022-06-14T11:40:21Z","9818" +"*/PowerSCCM.git*",".{0,1000}\/PowerSCCM\.git.{0,1000}","offensive_tool_keyword","PowerSCCM","PowerSCCM - PowerShell module to interact with SCCM deployments","T1059.001 - T1018 - T1072 - T1047","TA0005 - TA0003 - TA0002","N/A","N/A","Exploitation tool","https://github.com/PowerShellMafia/PowerSCCM","1","1","N/A","N/A","8","4","354","106","2022-01-22T15:30:56Z","2016-01-28T00:20:22Z","9819" +"*/PowerSharpPack.git*",".{0,1000}\/PowerSharpPack\.git.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","9820" +"*/PowerShdll.exe*",".{0,1000}\/PowerShdll\.exe.{0,1000}","offensive_tool_keyword","Poshito","Poshito is a Windows C2 over Telegram","T1102 - T1071.001 - T1571 - T1027","TA0011 - TA0005","N/A","N/A","C2","https://github.com/itaymigdal/Poshito","1","1","N/A","N/A","7","10","10","1","2024-10-30T10:40:41Z","2024-09-10T20:14:17Z","9821" +"*/powershell/process_injection/*",".{0,1000}\/powershell\/process_injection\/.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1027 - T1055 - T1070 - T1112 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","9822" +"*/powershell_executor/*.go*",".{0,1000}\/powershell_executor\/.{0,1000}\.go.{0,1000}","offensive_tool_keyword","mythic","mythic C2 agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/freyja/","1","1","N/A","N/A","10","10","54","13","2024-10-29T17:32:07Z","2022-09-28T17:20:04Z","9823" +"*/PowershellKerberos.git*",".{0,1000}\/PowershellKerberos\.git.{0,1000}","offensive_tool_keyword","PowershellKerberos","Some scripts to abuse kerberos using Powershell","T1558.003 - T1558.004 - T1059.001","TA0006 - TA0002","N/A","N/A","Exploitation tool","https://github.com/MzHmO/PowershellKerberos","1","1","N/A","N/A","9","4","328","44","2023-07-27T09:53:47Z","2023-04-22T19:16:52Z","9824" +"*/PowerShellRunner.git*",".{0,1000}\/PowerShellRunner\.git.{0,1000}","offensive_tool_keyword","PowerShellRunner","PowerShell runner for executing malicious payloads in order to bypass Windows Defender","T1059.001 - T1562.001 - T1218.005","TA0002 - TA0005","N/A","Turla","Defense Evasion","https://github.com/dievus/PowerShellRunner","1","1","N/A","N/A","9","1","70","20","2021-11-22T18:43:16Z","2021-08-03T01:29:34Z","9825" +"*/Powershell-Scripts-for-Hackers-and-Pentesters*",".{0,1000}\/Powershell\-Scripts\-for\-Hackers\-and\-Pentesters.{0,1000}","offensive_tool_keyword","Powershell-Scripts-for-Hackers-and-Pentesters","","T1059.001 - T1119 - T1027 - T1016 - T1056.001","TA0002 - TA0009 - TA0005 - TA0007 - TA0010","N/A","N/A","Collection","https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters","1","1","N/A","N/A","10","5","415","49","2025-02-23T09:05:44Z","2023-02-27T14:27:32Z","9826" +"*/PowershellTools.git*",".{0,1000}\/PowershellTools\.git.{0,1000}","offensive_tool_keyword","PowershellTools","Powershell tools used for Red Team / Pentesting","T1087.002 - T1069.001 - T1069.002 - T1598.002 - T1083 - T1558.003 - T1564.001 - T1112","TA0007 - TA0003 - TA0006 - TA0040 - TA0005 - TA0003","N/A","N/A","Exploitation tool","https://github.com/gustanini/PowershellTools","1","1","N/A","N/A","10","1","76","13","2024-01-08T10:33:20Z","2023-10-26T16:49:59Z","9827" +"*/PowerShx.git*",".{0,1000}\/PowerShx\.git.{0,1000}","offensive_tool_keyword","PowerShx","Run Powershell without software restrictions.","T1059.001 - T1055.001 - T1055.012","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/iomoath/PowerShx","1","1","N/A","N/A","7","3","286","47","2021-09-08T03:44:10Z","2021-09-06T18:32:45Z","9828" +"*/PowerTools.ps1*",".{0,1000}\/PowerTools\.ps1.{0,1000}","offensive_tool_keyword","PowershellTools","Powershell tools used for Red Team / Pentesting","T1087.002 - T1069.001 - T1069.002 - T1598.002 - T1083 - T1558.003 - T1564.001 - T1112","TA0007 - TA0003 - TA0006 - TA0040 - TA0005 - TA0003","N/A","N/A","Exploitation tool","https://github.com/gustanini/PowershellTools","1","1","N/A","N/A","10","1","76","13","2024-01-08T10:33:20Z","2023-10-26T16:49:59Z","9829" +"*/PowerUp.ps1*",".{0,1000}\/PowerUp\.ps1.{0,1000}","offensive_tool_keyword","ADAPE-Script","Active Directory Assessment and Privilege Escalation Script","T1178 - T1087 - T1482","TA0002 - TA0004 - TA0007","N/A","Black Basta","Privilege Escalation","https://github.com/cjoan75/ADAPE-Script","1","1","N/A","N/A","8","1","0","0","2020-07-11T00:53:24Z","2020-08-09T16:52:35Z","9830" +"*/PowerUp.ps1*",".{0,1000}\/PowerUp\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","9831" +"*/PowerUpSQL.ps1*",".{0,1000}\/PowerUpSQL\.ps1.{0,1000}","offensive_tool_keyword","PowerUpSQL","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","Black Basta","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","PowerUpSQL","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","9832" +"*/PowerUpSQL.ps1*",".{0,1000}\/PowerUpSQL\.ps1.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","PowerUpSQL","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","9833" +"*/PowerView.cna*",".{0,1000}\/PowerView\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","9834" +"*/PowerView.ps1*",".{0,1000}\/PowerView\.ps1.{0,1000}","offensive_tool_keyword","ADAPE-Script","Active Directory Assessment and Privilege Escalation Script","T1178 - T1087 - T1482","TA0002 - TA0004 - TA0007","N/A","Black Basta","Privilege Escalation","https://github.com/cjoan75/ADAPE-Script","1","1","N/A","N/A","8","1","0","0","2020-07-11T00:53:24Z","2020-08-09T16:52:35Z","9835" +"*/powerview.ps1*",".{0,1000}\/powerview\.ps1.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","9836" +"*/PowerView.ps1*",".{0,1000}\/PowerView\.ps1.{0,1000}","offensive_tool_keyword","SharpView","C# implementation of harmj0y's PowerView","T1018 - T1482 - T1087.002 - T1069.002","TA0007 - TA0003 - TA0001","N/A","Conti - APT29","Discovery","https://github.com/tevora-threat/SharpView/","1","1","N/A","N/A","10","10","1032","196","2024-03-22T16:34:09Z","2018-07-24T21:15:04Z","9837" +"*/powerview.py.git*",".{0,1000}\/powerview\.py\.git.{0,1000}","offensive_tool_keyword","powerview","PowerView.py is an alternative for the awesome original PowerView.ps1","T1046 - T1087.001 - T1016","TA0007 - TA0008 - TA0009","N/A","N/A","Discovery","https://github.com/aniqfakhrul/powerview.py","1","1","N/A","N/A","10","7","622","66","2025-04-22T09:01:39Z","2022-06-19T16:13:04Z","9839" +"*/PowerView3.cna*",".{0,1000}\/PowerView3\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","9840" +"*/PPEnum/*",".{0,1000}\/PPEnum\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Simple BOF to read the protection level of a process","T1012","TA0007","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Reconnaissance","https://github.com/rasta-mouse/PPEnum","1","1","N/A","N/A","N/A","2","115","9","2023-05-10T16:41:09Z","2023-05-10T16:38:36Z","9841" +"*/ppid_spoofing.exe*",".{0,1000}\/ppid_spoofing\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","9842" +"*/ppl/ppl.c*",".{0,1000}\/ppl\/ppl\.c.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","9843" +"*/ppl_dump.*",".{0,1000}\/ppl_dump\..{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","9844" +"*/PPLBlade.git*",".{0,1000}\/PPLBlade\.git.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","1","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","9845" +"*/ppldump.*",".{0,1000}\/ppldump\..{0,1000}","offensive_tool_keyword","cobaltstrike","A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/PPLDump_BOF","1","1","N/A","N/A","10","10","140","25","2021-09-24T07:10:04Z","2021-09-24T07:05:59Z","9846" +"*/PPLDump_BOF/*",".{0,1000}\/PPLDump_BOF\/.{0,1000}","offensive_tool_keyword","cobaltstrike","A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/PPLDump_BOF","1","1","N/A","N/A","10","10","140","25","2021-09-24T07:10:04Z","2021-09-24T07:05:59Z","9847" +"*/PPLFault/*",".{0,1000}\/PPLFault\/.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","9848" +"*/PPLKiller.git*",".{0,1000}\/PPLKiller\.git.{0,1000}","offensive_tool_keyword","PPLKiller","Tool to bypass LSA Protection (aka Protected Process Light)","T1547.002 - T1558.003","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/RedCursorSecurityConsulting/PPLKiller","1","1","N/A","N/A","10","10","933","139","2022-12-04T23:38:31Z","2020-07-06T10:11:49Z","9849" +"*/PPLKiller/*",".{0,1000}\/PPLKiller\/.{0,1000}","offensive_tool_keyword","PPLKiller","Tool to bypass LSA Protection (aka Protected Process Light)","T1547.002 - T1558.003","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/RedCursorSecurityConsulting/PPLKiller","1","1","N/A","N/A","10","10","933","139","2022-12-04T23:38:31Z","2020-07-06T10:11:49Z","9850" +"*/PPLmedic.exe*",".{0,1000}\/PPLmedic\.exe.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","1","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","9851" +"*/PPLmedic.git*",".{0,1000}\/PPLmedic\.git.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","1","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","9852" +"*/pplsystem.exe*",".{0,1000}\/pplsystem\.exe.{0,1000}","offensive_tool_keyword","PPLSystem","creates a livedump of the machine through NtDebugSystemControl to extract the COM secret and context, to then inject inside this process.","T1003.002","TA0006","N/A","N/A","Credential Access","https://github.com/Slowerzs/PPLSystem","1","1","N/A","N/A","10","2","190","23","2024-05-29T18:33:35Z","2024-05-22T17:48:49Z","9853" +"*/PPLSystem.git*","\/PPLSystem\.git","offensive_tool_keyword","PPLSystem","creates a livedump of the machine through NtDebugSystemControl to extract the COM secret and context, to then inject inside this process.","T1003.002","TA0006","N/A","N/A","Credential Access","https://github.com/Slowerzs/PPLSystem","1","1","N/A","N/A","10","2","190","23","2024-05-29T18:33:35Z","2024-05-22T17:48:49Z","9854" +"*/pptp-version.nse*",".{0,1000}\/pptp\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","9855" +"*/Prasadhak.ps1*",".{0,1000}\/Prasadhak\.ps1.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","9856" +"*/Pre2kSpray.ps1*",".{0,1000}\/Pre2kSpray\.ps1.{0,1000}","offensive_tool_keyword","Invoke-Pre2kSpray","Enumerate domain machine accounts and perform pre2k password spraying.","T1087.002 - T1110.003","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/eversinc33/Invoke-Pre2kSpray","1","1","N/A","N/A","8","1","69","11","2023-07-14T06:50:22Z","2023-07-05T10:07:38Z","9857" +"*/precompiled-binaries.git*",".{0,1000}\/precompiled\-binaries\.git.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","N/A","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","9858" +"*/PredatorTheStealer.git*",".{0,1000}\/PredatorTheStealer\.git.{0,1000}","offensive_tool_keyword","PredatorTheStealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/PredatorTheStealer","1","1","N/A","N/A","8","1","11","2","2022-12-06T16:46:33Z","2022-12-06T16:34:43Z","9859" +"*/prefetch-tool.git*",".{0,1000}\/prefetch\-tool\.git.{0,1000}","offensive_tool_keyword","prefetch-tool","Windows KASLR bypass using prefetch side-channel CVE-2024-21345 exploitation","T1564.007","TA0004","N/A","N/A","Privilege Escalation","https://github.com/exploits-forsale/prefetch-tool","1","1","N/A","N/A","8","1","90","10","2024-04-26T05:40:32Z","2024-04-26T05:00:27Z","9860" +"*/pretender.exe*",".{0,1000}\/pretender\.exe.{0,1000}","offensive_tool_keyword","pretender","MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS - LLMNR and NetBIOS-NS spoofing","T1557 - T1046 - T1590 - T1557.002","TA0008 - TA0011 - TA0007 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/RedTeamPentesting/pretender","1","1","N/A","N/A","7","10","1089","79","2025-02-19T08:14:57Z","2022-07-11T13:23:23Z","9862" +"*/pretender.git*",".{0,1000}\/pretender\.git.{0,1000}","offensive_tool_keyword","pretender","MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS - LLMNR and NetBIOS-NS spoofing","T1557 - T1046 - T1590 - T1557.002","TA0008 - TA0011 - TA0007 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/RedTeamPentesting/pretender","1","1","N/A","N/A","7","10","1089","79","2025-02-19T08:14:57Z","2022-07-11T13:23:23Z","9863" +"*/pretender_Linux_arm.tar.gz*",".{0,1000}\/pretender_Linux_arm\.tar\.gz.{0,1000}","offensive_tool_keyword","pretender","MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS - LLMNR and NetBIOS-NS spoofing","T1557 - T1046 - T1590 - T1557.002","TA0008 - TA0011 - TA0007 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/RedTeamPentesting/pretender","1","1","#linux","N/A","7","10","1089","79","2025-02-19T08:14:57Z","2022-07-11T13:23:23Z","9864" +"*/pretender_Windows_x86_64.zip*",".{0,1000}\/pretender_Windows_x86_64\.zip.{0,1000}","offensive_tool_keyword","pretender","MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS - LLMNR and NetBIOS-NS spoofing","T1557 - T1046 - T1590 - T1557.002","TA0008 - TA0011 - TA0007 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/RedTeamPentesting/pretender","1","1","N/A","N/A","7","10","1089","79","2025-02-19T08:14:57Z","2022-07-11T13:23:23Z","9865" +"*/PrimusC2*",".{0,1000}\/PrimusC2.{0,1000}","offensive_tool_keyword","primusC2","another C2 framework","T1090 - T1071","TA0011 - TA0002","N/A","N/A","C2","https://github.com/Primusinterp/PrimusC2","1","1","N/A","N/A","10","10","55","4","2024-11-01T00:20:02Z","2023-04-19T10:59:30Z","9866" +"*/PrimusC2.git*",".{0,1000}\/PrimusC2\.git.{0,1000}","offensive_tool_keyword","primusC2","another C2 framework","T1090 - T1071","TA0011 - TA0002","N/A","N/A","C2","https://github.com/Primusinterp/PrimusC2","1","1","N/A","N/A","10","10","55","4","2024-11-01T00:20:02Z","2023-04-19T10:59:30Z","9867" +"*/Prince-Built.exe*",".{0,1000}\/Prince\-Built\.exe.{0,1000}","offensive_tool_keyword","Prince-Ransomware","Go ransomware utilising ChaCha20 and ECIES encryption.","T1486 - T1489 - T1027","TA0040 - TA0009 ","N/A","N/A","Ransomware","https://github.com/SecDbg/Prince-Ransomware","1","1","N/A","N/A","10","","N/A","","","","9868" +"*/Prince-Ransomware.git*",".{0,1000}\/Prince\-Ransomware\.git.{0,1000}","offensive_tool_keyword","Prince-Ransomware","Go ransomware utilising ChaCha20 and ECIES encryption.","T1486 - T1489 - T1027","TA0040 - TA0009 ","N/A","N/A","Ransomware","https://github.com/SecDbg/Prince-Ransomware","1","1","N/A","N/A","10","","N/A","","","","9869" +"*/PrintCreds.py*",".{0,1000}\/PrintCreds\.py.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","1","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","9870" +"*/printerbug.py*",".{0,1000}\/printerbug\.py.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","9871" +"*/printerbug.py*",".{0,1000}\/printerbug\.py.{0,1000}","offensive_tool_keyword","krbrelayx","Kerberos unconstrained delegation abuse toolkit","T1558.003 - T1098","TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/dirkjanm/krbrelayx","1","1","N/A","N/A","N/A","10","1281","181","2025-01-27T09:22:54Z","2019-01-08T18:42:07Z","9872" +"*/printernightmare.ps1*",".{0,1000}\/printernightmare\.ps1.{0,1000}","offensive_tool_keyword","Invoke-Stealth","Simple & Powerful PowerShell Script Obfuscator","T1027.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/JoelGMSec/Invoke-Stealth","1","1","N/A","N/A","9","6","559","81","2023-04-21T12:49:37Z","2021-04-13T10:22:05Z","9873" +"*/PrintMonitorDll.*",".{0,1000}\/PrintMonitorDll\..{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to automate common persistence tasks for red teamers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/IcebreakerSecurity/PersistBOF","1","1","N/A","N/A","10","10","274","44","2023-03-07T11:23:42Z","2022-03-29T14:50:47Z","9874" +"*/PrintMonitorDll/*",".{0,1000}\/PrintMonitorDll\/.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to automate common persistence tasks for red teamers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/IcebreakerSecurity/PersistBOF","1","1","N/A","N/A","10","10","274","44","2023-03-07T11:23:42Z","2022-03-29T14:50:47Z","9875" +"*/PrintNightmare.git*",".{0,1000}\/PrintNightmare\.git.{0,1000}","offensive_tool_keyword","PrintNightmare","PrintNightmare exploitation","T1210 - T1059.001 - T1548.002","TA0001 - TA0002 - TA0004","N/A","Dispossessor","Privilege Escalation","https://github.com/outflanknl/PrintNightmare","1","1","N/A","N/A","10","4","337","67","2021-09-13T08:45:26Z","2021-09-13T08:44:02Z","9876" +"*/printnightmare.py*",".{0,1000}\/printnightmare\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","9877" +"*/PrintSpoofer.dll*",".{0,1000}\/PrintSpoofer\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","9878" +"*/PrintSpoofer.exe*",".{0,1000}\/PrintSpoofer\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","9879" +"*/PrintSpoofer.exe*",".{0,1000}\/PrintSpoofer\.exe.{0,1000}","offensive_tool_keyword","OSEP-Code-Snippets","notable code snippets for Offensive Security's PEN-300 (OSEP) course","T1116 - T1204.002 - T1027.009 - T1021.005 - T1560.001 - T1100 - T1003.001 - T1564.001 - T1047 - T1210 - T1134.002 - T1055 - T1055.011 - T1055.012 - T1204","TA0005 - TA0040 - TA0008 - TA0003 - TA0006 - TA0004","N/A","N/A","Exploitation tool","https://github.com/chvancooten/OSEP-Code-Snippets","1","1","N/A","N/A","8","10","1254","444","2024-01-04T15:17:17Z","2021-03-10T21:34:41Z","9880" +"*/PrintSpoofer.exe*",".{0,1000}\/PrintSpoofer\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","PrintSpoofer","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","9881" +"*/PrintSpoofer.exe*",".{0,1000}\/PrintSpoofer\.exe.{0,1000}","offensive_tool_keyword","PrintSpoofer","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","PrintSpoofer","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","9882" +"*/PrintSpoofer.exe*",".{0,1000}\/PrintSpoofer\.exe.{0,1000}","offensive_tool_keyword","PrivFu","ArtsOfGetSystem privesc tools","T1134 - T1134.001 - T1078 - T1059 - T1075","TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu/","1","1","N/A","ArtsOfGetSystem","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","9883" +"*/PrintSpoofer.git*",".{0,1000}\/PrintSpoofer\.git.{0,1000}","offensive_tool_keyword","PrintSpoofer","Abusing Impersonation Privileges on Windows 10 and Server 2019","T1548.002 - T1055.001 - T1055.002","TA0005 - TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrintSpoofer","1","1","N/A","N/A","10","10","1971","342","2020-09-10T17:49:41Z","2020-04-28T08:26:29Z","9884" +"*/PrintSpoofer.git*",".{0,1000}\/PrintSpoofer\.git.{0,1000}","offensive_tool_keyword","printspoofer","Abusing impersonation privileges through the Printer Bug","T1134 - T1003 - T1055","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrintSpoofer","1","1","N/A","N/A","10","10","1971","342","2020-09-10T17:49:41Z","2020-04-28T08:26:29Z","9885" +"*/PrintSpoofer/*",".{0,1000}\/PrintSpoofer\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Reflection dll implementation of PrintSpoofer used in conjunction with Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/crisprss/PrintSpoofer","1","1","N/A","N/A","10","10","88","12","2021-10-07T17:45:00Z","2021-10-07T17:28:45Z","9886" +"*/Priv_Esc.sh*",".{0,1000}\/Priv_Esc\.sh.{0,1000}","offensive_tool_keyword","AutoC2","AutoC2 is a bash script written to install all of the red team tools that you know and love","T1059.004 - T1129 - T1486","TA0005 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/assume-breach/Home-Grown-Red-Team/tree/main/AutoC2","1","1","N/A","N/A","10","8","707","112","2024-03-22T12:32:22Z","2022-03-23T15:52:41Z","9887" +"*/PrivEditor.dll*",".{0,1000}\/PrivEditor\.dll.{0,1000}","offensive_tool_keyword","PrivFu","Kernel Mode WinDbg extension for token privilege edit","T1055 - T1078 - T1134","TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","9888" +"*/Privesc.git*",".{0,1000}\/Privesc\.git.{0,1000}","offensive_tool_keyword","Privesc","Windows PowerShell script that finds misconfiguration issues which can lead to privilege escalation","T1068 - T1548 - T1082 - T1078","TA0004","N/A","N/A","Privilege Escalation","https://github.com/enjoiz/Privesc","1","1","N/A","N/A","10","6","595","97","2024-12-01T15:24:41Z","2015-11-19T13:22:01Z","9889" +"*/privesc.ps1*",".{0,1000}\/privesc\.ps1.{0,1000}","offensive_tool_keyword","Privesc","Windows PowerShell script that finds misconfiguration issues which can lead to privilege escalation","T1068 - T1548 - T1082 - T1078","TA0004","N/A","N/A","Privilege Escalation","https://github.com/enjoiz/Privesc","1","1","N/A","N/A","10","6","595","97","2024-12-01T15:24:41Z","2015-11-19T13:22:01Z","9890" +"*/PrivEsc.psm1*",".{0,1000}\/PrivEsc\.psm1.{0,1000}","offensive_tool_keyword","ADAPE-Script","Active Directory Assessment and Privilege Escalation Script","T1178 - T1087 - T1482","TA0002 - TA0004 - TA0007","N/A","Black Basta","Privilege Escalation","https://github.com/cjoan75/ADAPE-Script","1","1","N/A","N/A","8","1","0","0","2020-07-11T00:53:24Z","2020-08-09T16:52:35Z","9891" +"*/PrivescCheck*",".{0,1000}\/PrivescCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","9893" +"*/PrivescCheck.ps1*",".{0,1000}\/PrivescCheck\.ps1.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","9894" +"*/PrivExchange*",".{0,1000}\/PrivExchange.{0,1000}","offensive_tool_keyword","PrivExchange","Exchange your privileges for Domain Admin privs by abusing Exchange","T1091.001 - T1101 - T1201 - T1570","TA0006","N/A","N/A","Exploitation tool","https://github.com/dirkjanm/PrivExchange","1","1","N/A","N/A","N/A","10","1011","173","2020-01-23T19:48:51Z","2019-01-21T17:39:47Z","9895" +"*/PrivExchange.git*",".{0,1000}\/PrivExchange\.git.{0,1000}","offensive_tool_keyword","privexchange","Exchange your privileges for Domain Admin privs by abusing Exchange","T1053.005 - T1078 - T1069.002","TA0002 - TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/dirkjanm/PrivExchange","1","1","N/A","N/A","N/A","10","1011","173","2020-01-23T19:48:51Z","2019-01-21T17:39:47Z","9896" +"*/privexchange.py*",".{0,1000}\/privexchange\.py.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","9897" +"*/PrivFu.git*",".{0,1000}\/PrivFu\.git.{0,1000}","offensive_tool_keyword","PrivFu","Kernel mode WinDbg extension and PoCs for token privilege investigation.","T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001","TA0007 - TA0008 - TA0002 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","9898" +"*/privilege escalation.cna*",".{0,1000}\/privilege\sescalation\.cna.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","9899" +"*/PrivilegeEscalation/*",".{0,1000}\/PrivilegeEscalation\/.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","9900" +"*/Privileger.git*",".{0,1000}\/Privileger\.git.{0,1000}","offensive_tool_keyword","Privileger","Privileger is a tool to work with Windows Privileges","T1548.002","TA0004 ","N/A","N/A","Privilege Escalation","https://github.com/MzHmO/Privileger","1","1","N/A","N/A","8","2","136","32","2023-02-07T07:28:40Z","2023-01-31T11:24:37Z","9901" +"*/PrivKit.git*",".{0,1000}\/PrivKit\.git.{0,1000}","offensive_tool_keyword","PrivKit","PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.","T1548.002 - T1059.003 - T1027.002","TA0005","N/A","N/A","Privilege Escalation","https://github.com/mertdas/PrivKit","1","1","N/A","N/A","9","5","405","47","2024-06-15T16:54:32Z","2023-03-20T04:19:40Z","9902" +"*/PrivKit/*",".{0,1000}\/PrivKit\/.{0,1000}","offensive_tool_keyword","PrivKit","PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.","T1548.002 - T1059.003 - T1027.002","TA0005","N/A","N/A","Privilege Escalation","https://github.com/mertdas/PrivKit","1","1","N/A","N/A","9","5","405","47","2024-06-15T16:54:32Z","2023-03-20T04:19:40Z","9903" +"*/proberbyte.go*",".{0,1000}\/proberbyte\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","9905" +"*/process_herpaderping/*",".{0,1000}\/process_herpaderping\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","9908" +"*/process_killer.cpp*",".{0,1000}\/process_killer\.cpp.{0,1000}","offensive_tool_keyword","mhydeath","Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.","T1562.001","TA0040 - TA0005","N/A","Black Basta","Defense Evasion","https://github.com/zer0condition/mhydeath","1","1","N/A","N/A","10","4","397","71","2023-08-22T08:01:04Z","2023-08-22T07:15:36Z","9909" +"*/processinjection.exe*",".{0,1000}\/processinjection\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","9913" +"*/Process-Instrumentation-Syscall-Hook*",".{0,1000}\/Process\-Instrumentation\-Syscall\-Hook.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","9914" +"*/prometheus.exe",".{0,1000}\/prometheus\.exe","offensive_tool_keyword","prometheus","malware C2","T1071 - T1071.001 - T1105 - T1105.002 - T1106 - T1574.002","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/paranoidninja/0xdarkvortex-MalwareDevelopment","1","1","N/A","N/A","10","10","193","66","2020-07-21T06:14:44Z","2018-09-04T15:38:53Z","9916" +"*/ProtectMyTooling.git*",".{0,1000}\/ProtectMyTooling\.git.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","9917" +"*/ProtectMyTooling.py*",".{0,1000}\/ProtectMyTooling\.py.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","9918" +"*/ProtectMyTooling.yaml*",".{0,1000}\/ProtectMyTooling\.yaml.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","9919" +"*/ProtectMyToolingGUI.py*",".{0,1000}\/ProtectMyToolingGUI\.py.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","9920" +"*/protocols/ftp.py*",".{0,1000}\/protocols\/ftp\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9921" +"*/protocols/ldap.py*",".{0,1000}\/protocols\/ldap\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9922" +"*/protocols/mssql.py*",".{0,1000}\/protocols\/mssql\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9923" +"*/protocols/rdp.py*",".{0,1000}\/protocols\/rdp\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9924" +"*/protocols/rdp.py*",".{0,1000}\/protocols\/rdp\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted ","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9925" +"*/protocols/smb.py*",".{0,1000}\/protocols\/smb\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9926" +"*/protocols/ssh.py*",".{0,1000}\/protocols\/ssh\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9927" +"*/Proxmark3*",".{0,1000}\\Proxmark3.{0,1000}","offensive_tool_keyword","Proxmark","The proxmark3 is a powerful general purpose RFID tool. the size of a deck of cards. designed to snoop. listen and emulate everything from Low Frequency (125kHz) to High Frequency (13.56MHz) tags.","T1210 - T1561 - T1336 - T1335","TA0002 - TA0011 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/Proxmark/proxmark3","1","1","N/A","network exploitation tool","N/A","10","3288","923","2024-02-03T13:32:36Z","2014-03-16T23:36:31Z","9933" +"*/proxy/Tor.py*",".{0,1000}\/proxy\/Tor\.py.{0,1000}","offensive_tool_keyword","tor","Tor is a python based module for using tor proxy/network services on windows - osx - linux with just one click.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0005 - TA0010 - TA0011","N/A","Dispossessor - APT28 - APT29 - Leviathan","Defense Evasion","https://github.com/r0oth3x49/Tor","1","1","#linux","N/A","N/A","2","156","42","2018-04-21T10:55:00Z","2016-09-22T11:22:33Z","9934" +"*/proxy/tor_paths.py*",".{0,1000}\/proxy\/tor_paths\.py.{0,1000}","offensive_tool_keyword","tor","Tor is a python based module for using tor proxy/network services on windows - osx - linux with just one click.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0005 - TA0010 - TA0011","N/A","Dispossessor - APT28 - APT29 - Leviathan","Defense Evasion","https://github.com/r0oth3x49/Tor","1","1","#linux","N/A","N/A","2","156","42","2018-04-21T10:55:00Z","2016-09-22T11:22:33Z","9935" +"*/Proxy_Def_File_Generator.cna*",".{0,1000}\/Proxy_Def_File_Generator\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","DLL Hijack Search Order Enumeration BOF","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/DLL-Hijack-Search-Order-BOF","1","1","N/A","N/A","10","10","147","21","2021-11-03T17:39:32Z","2021-11-02T03:47:31Z","9936" +"*/proxychains-*.zip*",".{0,1000}\/proxychains\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","proxychains","proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4 SOCKS5 or HTTP(S) proxy","T1090.004 - T1090.003 - T1027 - T1573 - T1095","TA0005 - TA0011 - TA0010","N/A","Vice Society - Qilin - Black Basta - Dispossessor - EMBER BEAR","Defense Evasion","https://github.com/haad/proxychains","1","1","N/A","N/A","8","10","7142","647","2024-06-08T02:20:54Z","2011-02-25T12:27:05Z","9937" +"*/proxychains.git*",".{0,1000}\/proxychains\.git.{0,1000}","offensive_tool_keyword","proxychains","proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4 SOCKS5 or HTTP(S) proxy","T1090.004 - T1090.003 - T1027 - T1573 - T1095","TA0005 - TA0011 - TA0010","N/A","Vice Society - Qilin - Black Basta - Dispossessor - EMBER BEAR","Defense Evasion","https://github.com/haad/proxychains","1","1","N/A","N/A","8","10","7142","647","2024-06-08T02:20:54Z","2011-02-25T12:27:05Z","9939" +"*/proxychains-ng*",".{0,1000}\/proxychains\-ng.{0,1000}","offensive_tool_keyword","proxychains","proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4 SOCKS5 or HTTP(S) proxy","T1090.004 - T1090.003 - T1027 - T1573 - T1095","TA0005 - TA0011 - TA0010","N/A","Vice Society - Qilin - Black Basta - Dispossessor - EMBER BEAR","Defense Evasion","https://github.com/haad/proxychains","1","1","N/A","N/A","8","10","7142","647","2024-06-08T02:20:54Z","2011-02-25T12:27:05Z","9940" +"*/ProxyLogon.git*",".{0,1000}\/ProxyLogon\.git.{0,1000}","offensive_tool_keyword","ProxyLogon","ProxyLogon exploitation","T1190 - T1210 - T1213 - T1003 - T1059.003","TA0001 - TA0002 - TA0006 - TA0007","N/A","Dispossessor","Exploitation tool","https://github.com/hausec/ProxyLogon","1","1","N/A","N/A","10","3","293","76","2024-07-02T10:00:00Z","2021-03-15T14:37:57Z","9941" +"*/proxylogon.git*",".{0,1000}\/proxylogon\.git.{0,1000}","offensive_tool_keyword","ProxyLogon","ProxyLogon exploitation","T1190 - T1210 - T1213 - T1003 - T1059.003","TA0001 - TA0002 - TA0006 - TA0007","N/A","Dispossessor","Exploitation tool","https://github.com/hakivvi/proxylogon","1","1","N/A","N/A","10","1","20","6","2022-04-23T03:21:44Z","2021-03-14T13:04:07Z","9942" +"*/proxylogon.py*",".{0,1000}\/proxylogon\.py.{0,1000}","offensive_tool_keyword","ProxyLogon","ProxyLogon exploitation","T1190 - T1210 - T1213 - T1003 - T1059.003","TA0001 - TA0002 - TA0006 - TA0007","N/A","Dispossessor","Exploitation tool","https://github.com/hausec/ProxyLogon","1","1","N/A","N/A","10","3","293","76","2024-07-02T10:00:00Z","2021-03-15T14:37:57Z","9943" +"*/proxymaybeshell*",".{0,1000}\/proxymaybeshell.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","9944" +"*/proxyTunnel.ps1*",".{0,1000}\/proxyTunnel\.ps1.{0,1000}","offensive_tool_keyword","Invoke-SocksProxy","also known as PortStarter is a socks proxy and reverse socks server using powershell","T1090 - T1059.001 - T1102.003","TA0011 - TA0010 - TA0005 - TA0003","PortStarter","Vice Society - Conti","C2","https://github.com/p3nt4/Invoke-SocksProxy","1","1","N/A","N/A","10","10","788","169","2021-03-21T21:00:40Z","2017-11-09T06:20:40Z","9945" +"*/ps_windows.go*",".{0,1000}\/ps_windows\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","9946" +"*/ps1_oneliner.py*",".{0,1000}\/ps1_oneliner\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","9947" +"*/PS1ToBase64.ps1*",".{0,1000}\/PS1ToBase64\.ps1.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","9948" +"*/PS2EXE.git*",".{0,1000}\/PS2EXE\.git.{0,1000}","offensive_tool_keyword","PS2EXE","Module to compile powershell scripts to executables","T1027.001 - T1564.003 - T1564.005","TA0002 - TA0006","N/A","N/A","Exploitation tool","https://github.com/MScholtes/PS2EXE","1","1","N/A","N/A","N/A","10","1395","217","2025-01-05T11:26:50Z","2019-11-08T09:25:02Z","9949" +"*/ps2exe.ps1*",".{0,1000}\/ps2exe\.ps1.{0,1000}","offensive_tool_keyword","HTTP-Shell","MultiPlatform HTTP Reverse Shell","T1573.001 - T1104 - T1205 - T1110","TA0005 - TA0011","N/A","N/A","C2","https://github.com/JoelGMSec/HTTP-Shell","1","1","N/A","N/A","10","10","231","33","2024-09-27T10:23:14Z","2023-09-05T12:01:17Z","9950" +"*/PS2EXE.ps1*",".{0,1000}\/PS2EXE\.ps1.{0,1000}","offensive_tool_keyword","PS2EXE","Convert Powershell scripts to EXEs","T1059.001 - T1588","TA0042","N/A","N/A","Resource Development","https://github.com/Leo4j/PS2EXE","1","1","N/A","N/A","7","1","5","1","2024-08-31T12:34:50Z","2024-08-22T12:22:26Z","9951" +"*/ps2exe.ps1*",".{0,1000}\/ps2exe\.ps1.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","9953" +"*/PS2EXE/*",".{0,1000}\/PS2EXE\/.{0,1000}","offensive_tool_keyword","PS2EXE","Module to compile powershell scripts to executables","T1027.001 - T1564.003 - T1564.005","TA0002 - TA0006","N/A","N/A","Exploitation tool","https://github.com/MScholtes/PS2EXE","1","1","N/A","N/A","N/A","10","1395","217","2025-01-05T11:26:50Z","2019-11-08T09:25:02Z","9954" +"*/PSAmsi.git*",".{0,1000}\/PSAmsi\.git.{0,1000}","offensive_tool_keyword","PSAmsi","PSAmsi is a tool for auditing and defeating AMSI signatures.","T1059.001 - T1562.001 - T1070.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/cobbr/PSAmsi","1","1","N/A","N/A","7","4","390","74","2018-04-22T20:56:33Z","2017-09-22T11:48:47Z","9955" +"*/PSAsyncShell.git*",".{0,1000}\/PSAsyncShell\.git.{0,1000}","offensive_tool_keyword","PSAsyncShell","PowerShell Asynchronous TCP Reverse Shell","T1059.001 - T1071.001","TA0002 - TA0011","N/A","N/A","C2","https://github.com/JoelGMSec/PSAsyncShell","1","1","N/A","N/A","10","10","155","22","2023-11-08T12:30:00Z","2022-07-19T15:38:34Z","9956" +"*/PSAsyncShell.ps1*",".{0,1000}\/PSAsyncShell\.ps1.{0,1000}","offensive_tool_keyword","PSAsyncShell","PowerShell Asynchronous TCP Reverse Shell","T1059.001 - T1071.001","TA0002 - TA0011","N/A","N/A","C2","https://github.com/JoelGMSec/PSAsyncShell","1","1","N/A","N/A","10","10","155","22","2023-11-08T12:30:00Z","2022-07-19T15:38:34Z","9957" +"*/PSAsyncShell.sh*",".{0,1000}\/PSAsyncShell\.sh.{0,1000}","offensive_tool_keyword","PSAsyncShell","PowerShell Asynchronous TCP Reverse Shell","T1059.001 - T1071.001","TA0002 - TA0011","N/A","N/A","C2","https://github.com/JoelGMSec/PSAsyncShell","1","1","N/A","N/A","10","10","155","22","2023-11-08T12:30:00Z","2022-07-19T15:38:34Z","9958" +"*/PSAttack.git*",".{0,1000}\/PSAttack\.git.{0,1000}","offensive_tool_keyword","PSAttack","PSAttack contains over 100 commands for Privilege Escalation - Recon and Data Exfilitration","T1059 - T1212 - T1012 - T1087 - T1005 - T1041 - T1020","TA0002 - TA0004 - TA0005 - TA0007 - TA0010 - TA0008","N/A","N/A","Exploitation tool","https://github.com/GDSSecurity/PSAttack","1","1","N/A","N/A","10","1","45","15","2017-04-04T20:37:33Z","2016-02-22T23:45:22Z","9960" +"*/PSAttack.zip*",".{0,1000}\/PSAttack\.zip.{0,1000}","offensive_tool_keyword","PSAttack","PSAttack contains over 100 commands for Privilege Escalation - Recon and Data Exfilitration","T1059 - T1212 - T1012 - T1087 - T1005 - T1041 - T1020","TA0002 - TA0004 - TA0005 - TA0007 - TA0010 - TA0008","N/A","N/A","Exploitation tool","https://github.com/GDSSecurity/PSAttack","1","1","N/A","N/A","10","1","45","15","2017-04-04T20:37:33Z","2016-02-22T23:45:22Z","9961" +"*/PSAttack/releases/download/*",".{0,1000}\/PSAttack\/releases\/download\/.{0,1000}","offensive_tool_keyword","PSAttack","PSAttack contains over 100 commands for Privilege Escalation - Recon and Data Exfilitration","T1059 - T1212 - T1012 - T1087 - T1005 - T1041 - T1020","TA0002 - TA0004 - TA0005 - TA0007 - TA0010 - TA0008","N/A","N/A","Exploitation tool","https://github.com/GDSSecurity/PSAttack","1","1","N/A","N/A","10","1","45","15","2017-04-04T20:37:33Z","2016-02-22T23:45:22Z","9962" +"*/ps-empire*",".{0,1000}\/ps\-empire.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","9963" +"*/psexec.py*",".{0,1000}\/psexec\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","9965" +"*/psexecsvc.py*",".{0,1000}\/psexecsvc\.py.{0,1000}","offensive_tool_keyword","susinternals","python implementation of PSExec native service implementation","T1569.002 - T1021.002 - T1035","TA0002 - TA0004 - TA0008 - TA0003","N/A","N/A","Lateral Movement","https://github.com/sensepost/susinternals","1","1","N/A","N/A","7","2","194","18","2025-02-11T09:34:50Z","2025-02-10T07:40:36Z","9966" +"*/psgetsys.ps1*",".{0,1000}\/psgetsys\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","9967" +"*/psgetsys.ps1*",".{0,1000}\/psgetsys\.ps1.{0,1000}","offensive_tool_keyword","psgetsystem","getsystem via parent process using ps1 & embeded c#","T1134 - T1548","TA0004","N/A","N/A","Privilege Escalation","https://github.com/decoder-it/psgetsystem","1","1","N/A","N/A","10","5","406","88","2023-10-26T07:13:08Z","2018-02-02T11:28:22Z","9968" +"*/psgetsystem.git*",".{0,1000}\/psgetsystem\.git.{0,1000}","offensive_tool_keyword","psgetsystem","getsystem via parent process using ps1 & embeded c#","T1134 - T1548","TA0004","N/A","N/A","Privilege Escalation","https://github.com/decoder-it/psgetsystem","1","1","N/A","N/A","10","5","406","88","2023-10-26T07:13:08Z","2018-02-02T11:28:22Z","9969" +"*/PSInject.ps1*",".{0,1000}\/PSInject\.ps1.{0,1000}","offensive_tool_keyword","Powerpick","allowing the execution of Powershell functionality without the use of Powershell.exe","T1059.001 - T1059.003 - T1086 - T1027.001","TA0005 - TA0002","N/A","Black Basta - Dispossessor","Defense Evasion","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","9970" +"*/PSLessExec.exe*",".{0,1000}\/PSLessExec\.exe.{0,1000}","offensive_tool_keyword","OSEP-Code-Snippets","notable code snippets for Offensive Security's PEN-300 (OSEP) course","T1116 - T1204.002 - T1027.009 - T1021.005 - T1560.001 - T1100 - T1003.001 - T1564.001 - T1047 - T1210 - T1134.002 - T1055 - T1055.011 - T1055.012 - T1204","TA0005 - TA0040 - TA0008 - TA0003 - TA0006 - TA0004","N/A","N/A","Exploitation tool","https://github.com/chvancooten/OSEP-Code-Snippets","1","1","N/A","N/A","8","10","1254","444","2024-01-04T15:17:17Z","2021-03-10T21:34:41Z","9971" +"*/PsMapExec.git*",".{0,1000}\/PsMapExec\.git.{0,1000}","offensive_tool_keyword","PSMapExec","A PowerShell tool heavily inspired by the popular tool CrackMapExec. Far too often I find myself on engagements without access to Linux in order to make use of CrackMapExec.","T1059.001 - T1021.006 - T1110.001 - T1021.001 - T1021.004 - T1021.005 - T1021.003 - T1621","TA0002 - TA0011 - TA0005 - TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/The-Viper-One/PsMapExec","1","1","N/A","N/A","10","10","954","108","2025-03-11T14:38:50Z","2023-06-20T16:57:27Z","9974" +"*/PsMapExec/*",".{0,1000}\/PsMapExec\/.{0,1000}","offensive_tool_keyword","PSMapExec","A PowerShell tool heavily inspired by the popular tool CrackMapExec. Far too often I find myself on engagements without access to Linux in order to make use of CrackMapExec.","T1059.001 - T1021.006 - T1110.001 - T1021.001 - T1021.004 - T1021.005 - T1021.003 - T1621","TA0002 - TA0011 - TA0005 - TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/The-Viper-One/PsMapExec","1","1","N/A","N/A","10","10","954","108","2025-03-11T14:38:50Z","2023-06-20T16:57:27Z","9975" +"*/PSnmap.git*",".{0,1000}\/PSnmap\.git.{0,1000}","offensive_tool_keyword","Psnmap","Powershell scanner (nmap like)","T1086 - T1046 - T1059","TA0007","N/A","Black Basta","Discovery","https://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps1","1","1","N/A","N/A","7","2","178","64","2024-08-23T18:24:20Z","2015-01-24T10:46:41Z","9976" +"*/PSnmap.psd1*",".{0,1000}\/PSnmap\.psd1.{0,1000}","offensive_tool_keyword","Psnmap","Powershell scanner (nmap like)","T1086 - T1046 - T1059","TA0007","N/A","Black Basta","Discovery","https://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps1","1","1","N/A","N/A","7","2","178","64","2024-08-23T18:24:20Z","2015-01-24T10:46:41Z","9978" +"*/PSnmap.psm1*",".{0,1000}\/PSnmap\.psm1.{0,1000}","offensive_tool_keyword","Psnmap","Powershell scanner (nmap like)","T1086 - T1046 - T1059","TA0007","N/A","Black Basta","Discovery","https://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps1","1","1","N/A","N/A","7","2","178","64","2024-08-23T18:24:20Z","2015-01-24T10:46:41Z","9979" +"*/psnuffle*",".{0,1000}\/psnuffle.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","9980" +"*/psobf.git*",".{0,1000}\/psobf\.git.{0,1000}","offensive_tool_keyword","psobf","PowerShell Obfuscator","T1027 - T1059 - T1564","TA0005","N/A","N/A","Defense Evasion","https://github.com/TaurusOmar/psobf","1","1","N/A","N/A","6","2","171","30","2024-06-07T02:50:43Z","2024-06-07T01:45:12Z","9981" +"*/PSObfucate.py*",".{0,1000}\/PSObfucate\.py.{0,1000}","offensive_tool_keyword","FudgeC2","FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.","T1021.002 - T1105 - T1059.001 - T1059.003","TA0008 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/Ziconius/FudgeC2","1","1","N/A","N/A","10","10","253","54","2023-05-01T21:13:56Z","2018-09-09T21:05:21Z","9982" +"*/PSpersist.git*",".{0,1000}\/PSpersist\.git.{0,1000}","offensive_tool_keyword","Pspersist","Dropping a powershell script at %HOMEPATH%\Documents\windowspowershell\ that contains the implant's path and whenever powershell process is created the implant will executed too.","T1546 - T1546.013 - T1053 - T1053.005 - T1037 - T1037.001","TA0003","N/A","N/A","Persistence","https://github.com/TheD1rkMtr/Pspersist","1","1","N/A","N/A","10","1","85","24","2023-08-02T02:27:29Z","2023-02-01T17:21:38Z","9983" +"*/PSPY.dll*",".{0,1000}\/PSPY\.dll.{0,1000}","offensive_tool_keyword","NPPSpy","Simple code for NPLogonNotify(). The function obtains logon data including cleartext password","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/blob/master/PasswordStealing/NPPSpy","1","1","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","9985" +"*/pspy.git*",".{0,1000}\/pspy\.git.{0,1000}","offensive_tool_keyword","pspy","Monitor linux processes without root permissions","T1057 - T1514 - T1082","TA0007 - TA0009 - TA0003","N/A","N/A","Discovery","https://github.com/DominicBreuker/pspy","1","1","#linux","N/A","6","10","5370","538","2023-01-17T21:09:22Z","2018-02-08T21:41:37Z","9986" +"*/pspy.git*",".{0,1000}\/pspy\.git.{0,1000}","offensive_tool_keyword","pspy","Monitor linux processes without root permissions","T1057 - T1082 - T1518.001","TA0007","N/A","N/A","Discovery","https://github.com/DominicBreuker/pspy","1","1","#linux","N/A","8","10","5370","538","2023-01-17T21:09:22Z","2018-02-08T21:41:37Z","9987" +"*/pspy/pspy.go*",".{0,1000}\/pspy\/pspy\.go.{0,1000}","offensive_tool_keyword","pspy","Monitor linux processes without root permissions","T1057 - T1082 - T1518.001","TA0007","N/A","N/A","Discovery","https://github.com/DominicBreuker/pspy","1","1","#linux","N/A","8","10","5370","538","2023-01-17T21:09:22Z","2018-02-08T21:41:37Z","9991" +"*/pspy32*",".{0,1000}\/pspy32.{0,1000}","offensive_tool_keyword","pspy","Monitor linux processes without root permissions","T1057 - T1514 - T1082","TA0007 - TA0009 - TA0003","N/A","N/A","Discovery","https://github.com/DominicBreuker/pspy","1","1","#linux","N/A","6","10","5370","538","2023-01-17T21:09:22Z","2018-02-08T21:41:37Z","9992" +"*/pspy64*",".{0,1000}\/pspy64.{0,1000}","offensive_tool_keyword","pspy","Monitor linux processes without root permissions","T1057 - T1514 - T1082","TA0007 - TA0009 - TA0003","N/A","N/A","Discovery","https://github.com/DominicBreuker/pspy","1","1","#linux","N/A","6","10","5370","538","2023-01-17T21:09:22Z","2018-02-08T21:41:37Z","9993" +"*/psscanner/psscanner.go*",".{0,1000}\/psscanner\/psscanner\.go.{0,1000}","offensive_tool_keyword","pspy","Monitor linux processes without root permissions","T1057 - T1082 - T1518.001","TA0007","N/A","N/A","Discovery","https://github.com/DominicBreuker/pspy","1","1","#linux","N/A","8","10","5370","538","2023-01-17T21:09:22Z","2018-02-08T21:41:37Z","9996" +"*/PSSW100AVB*",".{0,1000}\/PSSW100AVB.{0,1000}","offensive_tool_keyword","PSSW100AVB","This is the PSSW100AVB (Powershell Scripts With 100% AV Bypass) Framework.A list of useful Powershell scripts with 100% AV bypass ratio","T1112 - T1562.001 - T1086 - T1548.002 - T1059.001","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/tihanyin/PSSW100AVB","1","1","N/A","N/A","N/A","10","1104","174","2025-01-28T10:47:44Z","2021-10-08T17:36:24Z","9997" +"*/pswRecovery4Moz.txt*",".{0,1000}\/pswRecovery4Moz\.txt.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","9998" +"*/pth-toolkit.git*",".{0,1000}\/pth\-toolkit\.git.{0,1000}","offensive_tool_keyword","pth-toolkit","A modified version of the passing-the-hash tool collection https://code.google.com/p/passing-the-hash/ designed to be portable and work straight out of the box even on the most 'bare bones' systems","T1550.002 - T1075 - T1078","TA0006 - TA0008","N/A","APT1","Lateral Movement","https://github.com/byt3bl33d3r/pth-toolkit","1","1","N/A","N/A","10","6","575","131","2015-02-06T15:10:41Z","2015-02-03T10:31:56Z","9999" +"*/ptunnel-ng*",".{0,1000}\/ptunnel\-ng.{0,1000}","offensive_tool_keyword","ptunnel-ng","Tunnel TCP connections through ICMP.","T1095.001 - T1572.001","TA0011 - TA0040 - TA0003","N/A","N/A","Data Exfiltration","https://github.com/utoni/ptunnel-ng","1","1","N/A","N/A","8","5","456","76","2024-11-27T18:34:33Z","2017-12-19T18:10:35Z","10000" +"*/puckiestyle/CVE-2022-0847*",".{0,1000}\/puckiestyle\/CVE\-2022\-0847.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/puckiestyle/CVE-2022-0847","1","1","N/A","N/A","N/A","1","2","1","2022-03-10T08:10:40Z","2022-03-08T14:46:21Z","10001" +"*/puppet-naivesigning.nse*",".{0,1000}\/puppet\-naivesigning\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10005" +"*/pupwinutils/*.py*",".{0,1000}\/pupwinutils\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10006" +"*/pupy/*.py*",".{0,1000}\/pupy\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10007" +"*/pupy/commands/*",".{0,1000}\/pupy\/commands\/.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10008" +"*/pupy/memimporter/*",".{0,1000}\/pupy\/memimporter\/.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10010" +"*/pupy/output/pupyx64*.exe*",".{0,1000}\/pupy\/output\/pupyx64.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10011" +"*/pupy/pupygen.py*",".{0,1000}\/pupy\/pupygen\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10012" +"*/pupy_load.*",".{0,1000}\/pupy_load\..{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10013" +"*/PupyCmd.py*",".{0,1000}\/PupyCmd\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10014" +"*/PupyCompile.py*",".{0,1000}\/PupyCompile\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10015" +"*/pupygen.py*",".{0,1000}\/pupygen\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10016" +"*/pupylib/payloads/*",".{0,1000}\/pupylib\/payloads\/.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10017" +"*/PupyOffload.py*",".{0,1000}\/PupyOffload\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10018" +"*/pupyps.py*",".{0,1000}\/pupyps\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10019" +"*/PupyServer.py*",".{0,1000}\/PupyServer\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10020" +"*/PupyService.py*",".{0,1000}\/PupyService\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10021" +"*/pupysh.py*",".{0,1000}\/pupysh\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10022" +"*/PupyTriggers.py*",".{0,1000}\/PupyTriggers\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10024" +"*/PupyWeb.py*",".{0,1000}\/PupyWeb\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10025" +"*/pupyx64.dll*",".{0,1000}\/pupyx64\.dll.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10026" +"*/pupyx64.exe*",".{0,1000}\/pupyx64\.exe.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10027" +"*/pupyx64d.exe*",".{0,1000}\/pupyx64d\.exe.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10028" +"*/pupyx86.exe*",".{0,1000}\/pupyx86\.exe.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10029" +"*/pupyx86d.exe*",".{0,1000}\/pupyx86d\.exe.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10030" +"*/PurpleSharp.exe*",".{0,1000}\/PurpleSharp\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10031" +"*/PurpleSharp.exe*",".{0,1000}\/PurpleSharp\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10032" +"*/putter.profile*",".{0,1000}\/putter\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","10033" +"*/PView.psm1*",".{0,1000}\/PView\.psm1.{0,1000}","offensive_tool_keyword","ADAPE-Script","Active Directory Assessment and Privilege Escalation Script","T1178 - T1087 - T1482","TA0002 - TA0004 - TA0007","N/A","Black Basta","Privilege Escalation","https://github.com/cjoan75/ADAPE-Script","1","1","N/A","N/A","8","1","0","0","2020-07-11T00:53:24Z","2020-08-09T16:52:35Z","10034" +"*/PWA-Phishing.git*",".{0,1000}\/PWA\-Phishing\.git.{0,1000}","offensive_tool_keyword","PWA-Phishing","Phishing with Progressive Web Apps and UI manipulation","T1071.003 - T1204.002 - T1608.003 - T1071.004","TA0006","N/A","N/A","Phishing","https://github.com/mrd0x/PWA-Phishing","1","1","N/A","N/A","10","3","288","52","2024-06-16T17:47:15Z","2024-06-09T19:47:52Z","10035" +"*/pwcrack.sh*",".{0,1000}\/pwcrack\.sh.{0,1000}","offensive_tool_keyword","nsa-rules","Password cracking rules and masks for hashcat that I generated from cracked passwords.","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/NSAKEY/nsa-rules","1","1","N/A","N/A","10","6","547","125","2017-01-03T11:53:25Z","2016-02-15T20:49:32Z","10037" +"*/pwcrack-framework.git*",".{0,1000}\/pwcrack\-framework\.git.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","10038" +"*/pwcrack-framework/*",".{0,1000}\/pwcrack\-framework\/.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","10039" +"*/pwdump.py*",".{0,1000}\/pwdump\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","10040" +"*/pwdump.py*",".{0,1000}\/pwdump\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10041" +"*/pwdump7.zip*",".{0,1000}\/pwdump7\.zip.{0,1000}","offensive_tool_keyword","PwDump7","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.openwall.com/passwords/windows-pwdump","1","1","N/A","N/A","10","8","N/A","N/A","N/A","N/A","10042" +"*/pwdump8.*",".{0,1000}\/pwdump8\..{0,1000}","offensive_tool_keyword","PwDump8","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://download.openwall.net/pub/projects/john/contrib/pwdump/pwdump8-8.2.zip","1","1","N/A","N/A","10","8","N/A","N/A","N/A","N/A","10043" +"*/PwnDB.py*",".{0,1000}\/PwnDB\.py.{0,1000}","offensive_tool_keyword","SocialPwned","SocialPwned is an OSINT tool that allows to get the emails. from a target. published in social networks like Instagram. Linkedin and Twitter to find the possible credential leaks in PwnDB or Dehashed and obtain Google account information via GHunt.","T1596","TA0002","N/A","N/A","Reconnaissance","https://github.com/MrTuxx/SocialPwned","1","1","N/A","N/A","N/A","10","1139","106","2025-01-28T19:07:29Z","2020-04-07T22:25:38Z","10047" +"*/pwndrop.git*",".{0,1000}\/pwndrop\.git.{0,1000}","offensive_tool_keyword","pwndrop","Self-deployable file hosting service for red teamers allowing to easily upload and share payloads over HTTP and WebDAV.","T1105 - T1071 - T1071.001 - T1090 - T1027 - T1027.005","TA0011 - TA0005 - TA0042","N/A","N/A","C2","https://github.com/kgretzky/pwndrop","1","1","N/A","N/A","10","10","2124","267","2023-02-25T05:08:15Z","2019-11-28T19:06:30Z","10048" +"*/Pwned.as*",".{0,1000}\/Pwned\.as.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10050" +"*/PwnKit-Exploit*",".{0,1000}\/PwnKit\-Exploit.{0,1000}","offensive_tool_keyword","POC","exploitation of CVE-2021-4034","T1210","N/A","N/A","N/A","Exploitation tool","https://github.com/luijait/PwnKit-Exploit","1","1","N/A","N/A","N/A","1","96","14","2022-02-07T15:42:00Z","2022-01-26T18:01:26Z","10051" +"*/pwnlook.exe*",".{0,1000}\/pwnlook\.exe.{0,1000}","offensive_tool_keyword","pwnlook","An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails configured in it","T1114 - T1071 - T1059 - T1113 - T1123","TA0002 - TA0005 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/amjcyber/pwnlook","1","1","N/A","N/A","6","2","166","18","2024-10-09T07:50:04Z","2024-09-19T10:26:16Z","10052" +"*/pwnlook.git*",".{0,1000}\/pwnlook\.git.{0,1000}","offensive_tool_keyword","pwnlook","An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails configured in it","T1114 - T1071 - T1059 - T1113 - T1123","TA0002 - TA0005 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/amjcyber/pwnlook","1","1","N/A","N/A","6","2","166","18","2024-10-09T07:50:04Z","2024-09-19T10:26:16Z","10053" +"*/pwnlook/releases/download/*",".{0,1000}\/pwnlook\/releases\/download\/.{0,1000}","offensive_tool_keyword","pwnlook","An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails configured in it","T1114 - T1071 - T1059 - T1113 - T1123","TA0002 - TA0005 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/amjcyber/pwnlook","1","1","N/A","N/A","6","2","166","18","2024-10-09T07:50:04Z","2024-09-19T10:26:16Z","10054" +"*/pwnlook35.exe*",".{0,1000}\/pwnlook35\.exe.{0,1000}","offensive_tool_keyword","pwnlook","An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails configured in it","T1114 - T1071 - T1059 - T1113 - T1123","TA0002 - TA0005 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/amjcyber/pwnlook","1","1","N/A","N/A","6","2","166","18","2024-10-09T07:50:04Z","2024-09-19T10:26:16Z","10055" +"*/pwnlook481.exe*",".{0,1000}\/pwnlook481\.exe.{0,1000}","offensive_tool_keyword","pwnlook","An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails configured in it","T1114 - T1071 - T1059 - T1113 - T1123","TA0002 - TA0005 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/amjcyber/pwnlook","1","1","N/A","N/A","6","2","166","18","2024-10-09T07:50:04Z","2024-09-19T10:26:16Z","10056" +"*/pxesploit/*",".{0,1000}\/pxesploit\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10057" +"*/PXEThief*",".{0,1000}\/PXEThief.{0,1000}","offensive_tool_keyword","pxethief","PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager","T1555.004 - T1555.002","TA0006","N/A","N/A","Credential Access","https://github.com/MWR-CyberSec/PXEThief","1","1","N/A","N/A","N/A","4","368","57","2024-05-29T15:07:15Z","2022-08-12T22:16:46Z","10058" +"*/pxexploit*",".{0,1000}\/pxexploit.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10059" +"*/py_oneliner.py*",".{0,1000}\/py_oneliner\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10060" +"*/pyasn1/*",".{0,1000}\/pyasn1\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","10062" +"*/PyClone.py*",".{0,1000}\/PyClone\.py.{0,1000}","offensive_tool_keyword","Koppeling","Adaptive DLL hijacking / dynamic export forwarding","T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/monoxgas/Koppeling","1","1","N/A","N/A","8","8","748","128","2020-07-06T14:47:57Z","2020-02-18T21:08:16Z","10063" +"*/pycobalt-*",".{0,1000}\/pycobalt\-.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","10064" +"*/pycobalt/*",".{0,1000}\/pycobalt\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","10065" +"*/PyExec.git*",".{0,1000}\/PyExec\.git.{0,1000}","offensive_tool_keyword","PyExec","This is a very simple privilege escalation technique from admin to System. This is the same technique PSExec uses.","T1134 - T1055 - T1548.002","TA0004 - TA0005 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/OlivierLaflamme/PyExec","1","1","N/A","N/A","9","1","11","7","2019-09-11T13:56:04Z","2019-09-11T13:54:15Z","10066" +"*/PyExfil.git*",".{0,1000}\/PyExfil\.git.{0,1000}","offensive_tool_keyword","PyExfil","A Python Package for Data Exfiltration","T1041 - T1567 - T1027","TA0011 - TA0009 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/ytisf/PyExfil","1","1","N/A","N/A","10","8","782","141","2024-05-07T07:58:02Z","2014-11-27T19:06:24Z","10067" +"*/PyExfil/pyexfil/*",".{0,1000}\/PyExfil\/pyexfil\/.{0,1000}","offensive_tool_keyword","PyExfil","A Python Package for Data Exfiltration","T1041 - T1567 - T1027","TA0011 - TA0009 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/ytisf/PyExfil","1","1","N/A","N/A","10","8","782","141","2024-05-07T07:58:02Z","2014-11-27T19:06:24Z","10068" +"*/pykiller/CVE-2022-23131*",".{0,1000}\/pykiller\/CVE\-2022\-23131.{0,1000}","offensive_tool_keyword","POC","POC exploitaiton of zabbix saml bypass exp vulnerability cve-2022-23131 (Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML)","T1548 - T1190","TA0006 - TA0008","N/A","N/A","Exploitation tool","https://github.com/pykiller/CVE-2022-23131","1","1","N/A","N/A","N/A","1","2","0","2022-02-24T11:59:48Z","2022-02-24T11:34:27Z","10071" +"*/pyLAPS.git*",".{0,1000}\/pyLAPS\.git.{0,1000}","offensive_tool_keyword","pyLAPS","A simple way to read and write LAPS passwords from linux.","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/p0dalirius/pyLAPS","1","1","#linux","N/A","9","2","105","16","2024-10-28T08:36:38Z","2021-10-05T18:35:21Z","10072" +"*/pyLAPS.py*",".{0,1000}\/pyLAPS\.py.{0,1000}","offensive_tool_keyword","pyLAPS","A simple way to read and write LAPS passwords from linux.","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/p0dalirius/pyLAPS","1","1","#linux","N/A","9","2","105","16","2024-10-28T08:36:38Z","2021-10-05T18:35:21Z","10073" +"*/pypi.org/project/GraphSpy*",".{0,1000}\/pypi\.org\/project\/GraphSpy.{0,1000}","offensive_tool_keyword","GraphSpy","Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI","T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656","TA0001 - TA0006 - TA0003 - TA0005 - TA0008","N/A","N/A","Collection","https://github.com/RedByte1337/GraphSpy","1","1","N/A","N/A","10","7","680","72","2025-04-15T21:07:15Z","2024-02-07T19:47:15Z","10086" +"*/pypykatz*",".{0,1000}\/pypykatz.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","10087" +"*/pypykatz.py*",".{0,1000}\/pypykatz\.py.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","10","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","10088" +"*/Pyramid.git*",".{0,1000}\/Pyramid\.git.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","10089" +"*/pyramid.py*",".{0,1000}\/pyramid\.py.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","10090" +"*/pyrdp.git*",".{0,1000}\/pyrdp\.git.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","#linux","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","10091" +"*/pyrdp.git*",".{0,1000}\/pyrdp\.git.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","#linux","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","10092" +"*/pyrdp:latest*",".{0,1000}\/pyrdp\:latest.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","#linux","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","10093" +"*/pyrdp_mitm-*",".{0,1000}\/pyrdp_mitm\-.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","#linux","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","10094" +"*/pysecdump.git*",".{0,1000}\/pysecdump\.git.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","1","N/A","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","10095" +"*/pysnaffler.git*",".{0,1000}\/pysnaffler\.git.{0,1000}","offensive_tool_keyword","pysnaffler","This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.","T1083 - T1087 - T1114 - T1518","TA0007 - TA0009 - TA0010","N/A","N/A","Collection","https://github.com/skelsec/pysnaffler","1","1","N/A","N/A","10","1","91","5","2025-03-15T13:46:34Z","2023-11-17T21:52:40Z","10097" +"*/Pysoserial.git*",".{0,1000}\/Pysoserial\.git.{0,1000}","offensive_tool_keyword","pysoserial","Python-based proof-of-concept tool for generating payloads that utilize unsafe Java object deserialization.","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","N/A","Resource Development","https://github.com/aStrowxyu/Pysoserial","1","1","N/A","N/A","9","1","9","1","2021-12-06T07:41:55Z","2021-11-16T01:55:31Z","10098" +"*/pysoxy.git*",".{0,1000}\/pysoxy\.git.{0,1000}","offensive_tool_keyword","pysoxy","A small Socks5 Proxy Server in Python","T1090","TA0011","N/A","N/A","C2","https://github.com/MisterDaneel/pysoxy","1","1","N/A","N/A","10","10","149","51","2023-10-15T06:12:45Z","2016-04-21T07:56:24Z","10099" +"*/pysoxy.py*",".{0,1000}\/pysoxy\.py.{0,1000}","offensive_tool_keyword","pysoxy","A small Socks5 Proxy Server in Python","T1090","TA0011","N/A","N/A","C2","https://github.com/MisterDaneel/pysoxy","1","1","N/A","N/A","10","10","149","51","2023-10-15T06:12:45Z","2016-04-21T07:56:24Z","10100" +"*/PySQLRecon.git*",".{0,1000}\/PySQLRecon\.git.{0,1000}","offensive_tool_keyword","PySQLRecon","Offensive MSSQL toolkit written in Python, based off SQLRecon","T1040 - T1078 - T1072 - T1223 - T1059 - T1213","TA0001 - TA0002 - TA0007 - TA0009","N/A","N/A","Exploitation tool","https://github.com/Tw1sm/PySQLRecon","1","1","N/A","N/A","10","3","201","15","2025-01-12T02:14:59Z","2023-09-03T01:14:35Z","10101" +"*/PySQLRecon/tarball*",".{0,1000}\/PySQLRecon\/tarball.{0,1000}","offensive_tool_keyword","PySQLRecon","Offensive MSSQL toolkit written in Python, based off SQLRecon","T1040 - T1078 - T1072 - T1223 - T1059 - T1213","TA0001 - TA0002 - TA0007 - TA0009","N/A","N/A","Exploitation tool","https://github.com/Tw1sm/PySQLRecon","1","1","N/A","N/A","10","3","201","15","2025-01-12T02:14:59Z","2023-09-03T01:14:35Z","10102" +"*/PySQLRecon/zipball*",".{0,1000}\/PySQLRecon\/zipball.{0,1000}","offensive_tool_keyword","PySQLRecon","Offensive MSSQL toolkit written in Python, based off SQLRecon","T1040 - T1078 - T1072 - T1223 - T1059 - T1213","TA0001 - TA0002 - TA0007 - TA0009","N/A","N/A","Exploitation tool","https://github.com/Tw1sm/PySQLRecon","1","1","N/A","N/A","10","3","201","15","2025-01-12T02:14:59Z","2023-09-03T01:14:35Z","10103" +"*/pystinger.zip*",".{0,1000}\/pystinger\.zip.{0,1000}","offensive_tool_keyword","cobaltstrike","Bypass firewall for traffic forwarding using webshell. Pystinger implements SOCK4 proxy and port mapping through webshell. It can be directly used by metasploit-framework - viper- cobalt strike for session online.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/FunnyWolf/pystinger","1","1","N/A","N/A","10","10","1397","205","2021-09-29T13:13:43Z","2019-09-29T05:23:54Z","10104" +"*/Python-dynload-os.h*",".{0,1000}\/Python\-dynload\-os\.h.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10105" +"*/Python-Rootkit.git*",".{0,1000}\/Python\-Rootkit\.git.{0,1000}","offensive_tool_keyword","Python-Rootkit","full undetectable python RAT which can bypass almost all antivirus and open a backdoor inside any windows machine which will establish a reverse https Metasploit connection to your listening machine","T1100 - T1027 - T1219 - T1560.001 - T1021.005","TA0005 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/0xIslamTaha/Python-Rootkit","1","1","N/A","N/A","10","10","606","145","2024-10-29T16:56:39Z","2016-06-09T10:49:54Z","10107" +"*/pywerview*",".{0,1000}\/pywerview.{0,1000}","offensive_tool_keyword","pywerview","A partial Python rewriting of PowerSploit PowerView","T1069.002 - T1018 - T1087.001 - T1033 - T1069.001 - T1087.002 - T1016 - T1482","TA0007 - TA0009","N/A","N/A","Reconnaissance","https://github.com/the-useless-one/pywerview","1","1","N/A","N/A","N/A","10","974","121","2025-03-17T14:04:51Z","2016-07-06T13:25:09Z","10108" +"*/pywhisker.git*",".{0,1000}\/pywhisker\.git.{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","1","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","10109" +"*/pywsus.git*",".{0,1000}\/pywsus\.git.{0,1000}","offensive_tool_keyword","pywsus","The main goal of this tool is to be a standalone implementation of a legitimate WSUS server which sends malicious responses to clients. The MITM attack itself should be done using other dedicated tools such as Bettercap.","T1505.003 - T1001.001 - T1560.001 - T1071.001","TA0003 - TA0011 - TA0002","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pywsus","1","1","N/A","network exploitation tool","N/A","4","303","44","2022-11-11T19:59:21Z","2020-08-11T21:44:35Z","10110" +"*/pywsus.py*",".{0,1000}\/pywsus\.py.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","10111" +"*/pywsus-master.zip*",".{0,1000}\/pywsus\-master\.zip.{0,1000}","offensive_tool_keyword","pywsus","The main goal of this tool is to be a standalone implementation of a legitimate WSUS server which sends malicious responses to clients. The MITM attack itself should be done using other dedicated tools such as Bettercap.","T1505.003 - T1001.001 - T1560.001 - T1071.001","TA0003 - TA0011 - TA0002","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pywsus","1","1","N/A","network exploitation tool","N/A","4","303","44","2022-11-11T19:59:21Z","2020-08-11T21:44:35Z","10112" +"*/qakbot.profile*",".{0,1000}\/qakbot\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","10113" +"*/qconn-exec.nse*",".{0,1000}\/qconn\-exec\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10114" +"*/QHpix/CVE-2021-44521*",".{0,1000}\/QHpix\/CVE\-2021\-44521.{0,1000}","offensive_tool_keyword","POC","Automated PoC exploitation of CVE-2021-44521","T1548 - T1190","TA0006 - TA0008","N/A","N/A","Exploitation tool","https://github.com/QHpix/CVE-2021-44521","1","1","N/A","N/A","N/A","1","9","2","2022-02-24T12:04:40Z","2022-02-24T11:07:34Z","10115" +"*/qscan.nse*",".{0,1000}\/qscan\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10117" +"*/quake1-info.nse*",".{0,1000}\/quake1\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10118" +"*/quake3-info.nse*",".{0,1000}\/quake3\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10119" +"*/quake3-master-getservers.nse*",".{0,1000}\/quake3\-master\-getservers\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10120" +"*/quantloader.profile*",".{0,1000}\/quantloader\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","10121" +"*/quarkspwdump.git*",".{0,1000}\/quarkspwdump\.git.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","1","N/A","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","10122" +"*/quarkspwdump.git*",".{0,1000}\/quarkspwdump\.git.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","1","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","10123" +"*/Quasar.exe*",".{0,1000}\/Quasar\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","10124" +"*/quickcrack.py*",".{0,1000}\/quickcrack\.py.{0,1000}","offensive_tool_keyword","SMBTrap","tool capturing authentication attempts and performing man-in-the-middle (MitM) attacks leveraging SMB services","T1071.001 - T1557.001 - T1040 - T1070.001 - T1205.001 - T1185","TA0006 - TA0008 - TA0011 - TA0005","N/A","ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/cylance/SMBTrap","1","1","N/A","N/A","8","1","84","38","2015-06-02T17:22:48Z","2015-04-13T07:08:01Z","10131" +"*/QuickViewAD.ps1*",".{0,1000}\/QuickViewAD\.ps1.{0,1000}","offensive_tool_keyword","PowershellTools","Powershell tools used for Red Team / Pentesting","T1087.002 - T1069.001 - T1069.002 - T1598.002 - T1083 - T1558.003 - T1564.001 - T1112","TA0007 - TA0003 - TA0006 - TA0040 - TA0005 - TA0003","N/A","N/A","Exploitation tool","https://github.com/gustanini/PowershellTools","1","1","N/A","N/A","10","1","76","13","2024-01-08T10:33:20Z","2023-10-26T16:49:59Z","10132" +"*/quicserver.exe*",".{0,1000}\/quicserver\.exe.{0,1000}","offensive_tool_keyword","ntlmquic","POC tools for exploring SMB over QUIC protocol","T1210.002 - T1210.003 - T1210.004","TA0001","N/A","N/A","Exploitation tool","https://github.com/xpn/ntlmquic","1","1","N/A","network exploitation tool","6","2","122","15","2022-04-06T11:22:11Z","2022-04-05T13:01:02Z","10133" +"*/quiet-riot.git*",".{0,1000}\/quiet\-riot\.git.{0,1000}","offensive_tool_keyword","quiet-riot","Unauthenticated enumeration of AWS - Azure and GCP Principals","T1087 - T1083 - T1210","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/righteousgambit/quiet-riot","1","1","N/A","N/A","6","3","224","30","2024-11-13T19:41:26Z","2021-10-28T15:12:27Z","10134" +"*/r00t-3xp10it*",".{0,1000}\/r00t\-3xp10it.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","10135" +"*/r57shell.php*",".{0,1000}\/r57shell\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","10136" +"*/r57shell127.php*",".{0,1000}\/r57shell127\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","10137" +"*/r77-rootkit.git*",".{0,1000}\/r77\-rootkit\.git.{0,1000}","offensive_tool_keyword","r77-rootkit","Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections","T1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/bytecode77/r77-rootkit","1","1","N/A","N/A","10","10","1884","425","2025-03-25T17:59:20Z","2017-12-17T13:04:14Z","10138" +"*/r77-x64.dll*",".{0,1000}\/r77\-x64\.dll.{0,1000}","offensive_tool_keyword","r77-rootkit","Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections","T1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/bytecode77/r77-rootkit","1","1","N/A","N/A","10","10","1884","425","2025-03-25T17:59:20Z","2017-12-17T13:04:14Z","10139" +"*/r77-x86.dll*",".{0,1000}\/r77\-x86\.dll.{0,1000}","offensive_tool_keyword","r77-rootkit","Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections","T1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/bytecode77/r77-rootkit","1","1","N/A","N/A","10","10","1884","425","2025-03-25T17:59:20Z","2017-12-17T13:04:14Z","10140" +"*/RagingRotator.git*",".{0,1000}\/RagingRotator\.git.{0,1000}","offensive_tool_keyword","RagingRotator","A tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways.","T1110 - T1027 - T1071 - T1090 - T1621","TA0006 - TA0005 - TA0001","N/A","N/A","Credential Access","https://github.com/nickzer0/RagingRotator","1","1","N/A","N/A","10","1","79","7","2024-06-06T19:31:34Z","2023-09-01T15:19:38Z","10146" +"*/RagingRotator.go*",".{0,1000}\/RagingRotator\.go.{0,1000}","offensive_tool_keyword","RagingRotator","A tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways.","T1110 - T1027 - T1071 - T1090 - T1621","TA0006 - TA0005 - TA0001","N/A","N/A","Credential Access","https://github.com/nickzer0/RagingRotator","1","1","N/A","N/A","10","1","79","7","2024-06-06T19:31:34Z","2023-09-01T15:19:38Z","10147" +"*/rahul1406/cve-2022-0847dirtypipe-exploit*",".{0,1000}\/rahul1406\/cve\-2022\-0847dirtypipe\-exploit.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/rahul1406/cve-2022-0847dirtypipe-exploit","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10148" +"*/RAI.git*",".{0,1000}\/RAI\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","10149" +"*/rakjong/mimikatz_bypassAV/*",".{0,1000}\/rakjong\/mimikatz_bypassAV\/.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","10150" +"*/ramnit.profile*",".{0,1000}\/ramnit\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","10151" +"*/random-robbie/cve-2022-23131-exp*",".{0,1000}\/random\-robbie\/cve\-2022\-23131\-exp.{0,1000}","offensive_tool_keyword","POC","POC exploitaiton of zabbix saml bypass exp vulnerability cve-2022-23131 (Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML)","T1548 - T1190","TA0003 - TA0002","N/A","N/A","Exploitation tool","https://github.com/random-robbie/cve-2022-23131-exp/blob/main/zabbix.py","1","1","N/A","N/A","N/A","1","8","7","2022-02-23T16:37:13Z","2022-02-23T16:34:03Z","10152" +"*/Ransomware.dll*",".{0,1000}\/Ransomware\.dll.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","10153" +"*/Ransomware.exe*",".{0,1000}\/Ransomware\.exe.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","10154" +"*/Ransomware.pdb*",".{0,1000}\/Ransomware\.pdb.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","10155" +"*/rarce.py*",".{0,1000}\/rarce\.py.{0,1000}","offensive_tool_keyword","RaRCE","An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831 - WinRAR RCE before versions 6.23","T1068 - T1203 - T1059.003","TA0001 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/ignis-sec/CVE-2023-38831-RaRCE","1","1","N/A","N/A","9","2","115","18","2023-08-27T22:17:56Z","2023-08-27T21:49:37Z","10156" +"*/rasman.exe*",".{0,1000}\/rasman\.exe.{0,1000}","offensive_tool_keyword","RasmanPotato","using RasMan service for privilege escalation","T1548.002 - T1055.002 - T1055.001 ","TA0004 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/crisprss/RasmanPotato","1","1","N/A","N/A","10","4","371","53","2023-02-06T10:27:41Z","2023-02-06T09:41:51Z","10157" +"*/RasmanPotato*",".{0,1000}\/RasmanPotato.{0,1000}","offensive_tool_keyword","RasmanPotato","using RasMan service for privilege escalation","T1548.002 - T1055.002 - T1055.001 ","TA0004 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/crisprss/RasmanPotato","1","1","N/A","N/A","10","4","371","53","2023-02-06T10:27:41Z","2023-02-06T09:41:51Z","10158" +"*/Rat_Generator*",".{0,1000}\/Rat_Generator.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","10159" +"*/ratankba.profile*",".{0,1000}\/ratankba\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","10160" +"*/RATC.exe*",".{0,1000}\/RATC\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","10161" +"*/ratchatpt.git*",".{0,1000}\/ratchatpt\.git.{0,1000}","offensive_tool_keyword","ratchatgpt","ratchatpt a tool using openai api as a C2","T1094 - T1071.001","TA0011 - TA0002","N/A","N/A","C2","https://github.com/spartan-conseil/ratchatpt","1","1","N/A","N/A","10","10","16","6","2023-06-09T12:39:00Z","2023-06-09T09:19:10Z","10162" +"*/ratchatpt.git*",".{0,1000}\/ratchatpt\.git.{0,1000}","offensive_tool_keyword","ratchatpt","C2 using openAI API","T1094 - T1071.001","TA0011 - TA0002","N/A","N/A","C2","https://github.com/spartan-conseil/ratchatpt","1","1","N/A","risk of False positive","10","10","16","6","2023-06-09T12:39:00Z","2023-06-09T09:19:10Z","10163" +"*/ratchatPT.go*",".{0,1000}\/ratchatPT\.go.{0,1000}","offensive_tool_keyword","ratchatgpt","ratchatpt a tool using openai api as a C2","T1094 - T1071.001","TA0011 - TA0002","N/A","N/A","C2","https://github.com/spartan-conseil/ratchatpt","1","1","N/A","N/A","10","10","16","6","2023-06-09T12:39:00Z","2023-06-09T09:19:10Z","10164" +"*/ratchatPT.go*",".{0,1000}\/ratchatPT\.go.{0,1000}","offensive_tool_keyword","ratchatpt","C2 using openAI API","T1094 - T1071.001","TA0011 - TA0002","N/A","N/A","C2","https://github.com/spartan-conseil/ratchatpt","1","1","N/A","risk of False positive","10","10","16","6","2023-06-09T12:39:00Z","2023-06-09T09:19:10Z","10165" +"*/ratchatPT.syso*",".{0,1000}\/ratchatPT\.syso.{0,1000}","offensive_tool_keyword","ratchatgpt","ratchatpt a tool using openai api as a C2","T1094 - T1071.001","TA0011 - TA0002","N/A","N/A","C2","https://github.com/spartan-conseil/ratchatpt","1","1","N/A","N/A","10","10","16","6","2023-06-09T12:39:00Z","2023-06-09T09:19:10Z","10166" +"*/ratchatPT.syso*",".{0,1000}\/ratchatPT\.syso.{0,1000}","offensive_tool_keyword","ratchatpt","C2 using openAI API","T1094 - T1071.001","TA0011 - TA0002","N/A","N/A","C2","https://github.com/spartan-conseil/ratchatpt","1","1","N/A","risk of False positive","10","10","16","6","2023-06-09T12:39:00Z","2023-06-09T09:19:10Z","10167" +"*/RationalLove.c",".{0,1000}\/RationalLove\.c","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10176" +"*/ratnow.exe*",".{0,1000}\/ratnow\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","10177" +"*/rats/badrat_cs/*",".{0,1000}\/rats\/badrat_cs\/.{0,1000}","offensive_tool_keyword","badrats","control tool (C2) using Python server - Jscript - Powershell and C# implants and communicates via HTTP(S) and SMB","T1059 - T1027 - T1573 - T1071 - T1105","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://gitlab.com/KevinJClark/badrats","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","10178" +"*/rattler.git*",".{0,1000}\/rattler\.git.{0,1000}","offensive_tool_keyword","rattler","Automated DLL Enumerator","T1174 - T1574.007","TA0005","N/A","N/A","Discovery","https://github.com/sensepost/rattler","1","1","N/A","N/A","9","6","531","135","2017-12-21T18:01:09Z","2016-11-28T12:35:44Z","10179" +"*/Rattler_32.exe*",".{0,1000}\/Rattler_32\.exe.{0,1000}","offensive_tool_keyword","rattler","Automated DLL Enumerator","T1174 - T1574.007","TA0005","N/A","N/A","Discovery","https://github.com/sensepost/rattler","1","1","N/A","N/A","9","6","531","135","2017-12-21T18:01:09Z","2016-11-28T12:35:44Z","10180" +"*/Rattler_x64.exe*",".{0,1000}\/Rattler_x64\.exe.{0,1000}","offensive_tool_keyword","rattler","Automated DLL Enumerator","T1174 - T1574.007","TA0005","N/A","N/A","Discovery","https://github.com/sensepost/rattler","1","1","N/A","N/A","9","6","531","135","2017-12-21T18:01:09Z","2016-11-28T12:35:44Z","10181" +"*/raw/kali/main/*",".{0,1000}\/raw\/kali\/main\/.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","10182" +"*/raw/kali/master/*",".{0,1000}\/raw\/kali\/master\/.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","10183" +"*/raw/main/gsocket/*",".{0,1000}\/raw\/main\/gsocket\/.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","10184" +"*/raw/master/Release/Happy.exe*",".{0,1000}\/raw\/master\/Release\/Happy\.exe.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","10186" +"*/raw/master/Release/Happy_x64.exe*",".{0,1000}\/raw\/master\/Release\/Happy_x64\.exe.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","10187" +"*/raw_shellcode_size.txt*",".{0,1000}\/raw_shellcode_size\.txt.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Shellcode Generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RCStep/CSSG","1","1","N/A","N/A","10","10","654","112","2025-01-08T23:11:49Z","2021-01-12T14:39:06Z","10189" +"*/rawrpc.py*",".{0,1000}\/rawrpc\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","10190" +"*/rawrpc_embedded.py*",".{0,1000}\/rawrpc_embedded\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","10191" +"*/RAZAR ASRAT.exe*",".{0,1000}\/RAZAR\sASRAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","10192" +"*/Razar SRAT.exe*",".{0,1000}\/Razar\sSRAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","10193" +"*/rbcd.py*",".{0,1000}\/rbcd\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","10194" +"*/RC4BinaryEncryption.cs*",".{0,1000}\/RC4BinaryEncryption\.cs.{0,1000}","offensive_tool_keyword","Macrome","An Excel Macro Document Reader/Writer for Red Teamers & Analysts. Blog posts describing what this tool actually does can be found https://malware.pizza/2020/05/12/evading-av-with-excel-macros-and-biff8-xls/ and https://malware.pizza/2020/06/19/further-evasion-in-the-forgotten-corners-of-ms-xls/","T1140","TA0005","N/A","N/A","Exploitation tool","https://github.com/michaelweber/Macrome","1","1","N/A","N/A","N/A","6","520","79","2022-02-01T16:26:13Z","2020-05-07T22:44:11Z","10195" +"*/RC4Payload32.txt*",".{0,1000}\/RC4Payload32\.txt.{0,1000}","offensive_tool_keyword","cobaltstrike","CS anti-killing including python version and C version","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Gality369/CS-Loader","1","1","N/A","N/A","10","10","829","141","2025-04-02T09:37:10Z","2020-08-17T21:33:06Z","10196" +"*/rcat-v*-win-x86_64.exe*",".{0,1000}\/rcat\-v.{0,1000}\-win\-x86_64\.exe.{0,1000}","offensive_tool_keyword","rustcat","Rustcat(rcat) - The modern Port listener and Reverse shell","T1090.001 - T1090.002 - T1046","TA0011 - TA0009 - TA0040","N/A","N/A","C2","https://github.com/robiot/rustcat","1","1","N/A","N/A","10","10","758","63","2024-07-20T14:20:34Z","2021-06-04T17:03:47Z","10197" +"*/RCStep/CSSG/*",".{0,1000}\/RCStep\/CSSG\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Shellcode Generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RCStep/CSSG","1","1","N/A","N/A","10","10","654","112","2025-01-08T23:11:49Z","2021-01-12T14:39:06Z","10204" +"*/rdcmanfox.dll*",".{0,1000}\/rdcmanfox\.dll.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","1","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","10206" +"*/RDE1.git*",".{0,1000}\/RDE1\.git.{0,1000}","offensive_tool_keyword","RDE1","RDE1 (Rusty Data Exfiltrator) is client and server tool allowing auditor to extract files from DNS and HTTPS protocols written in Rust","T1048.003 - T1567.001 - T1020","TA0011 - TA0010 - TA0040","N/A","N/A","C2","https://github.com/g0h4n/RDE1","1","1","N/A","N/A","10","10","39","6","2025-04-04T18:54:54Z","2023-09-25T20:29:08Z","10207" +"*/rdll_template*",".{0,1000}\/rdll_template.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10208" +"*/RDP Recognizer.exe*",".{0,1000}\/RDP\sRecognizer\.exe.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","10209" +"*/rdp_brute.git*",".{0,1000}\/rdp_brute\.git.{0,1000}","offensive_tool_keyword","KPortScan","port scanner used by attackers","T1046 - T1595","TA0043 - TA0001","N/A","Dispossessor","Reconnaissance","https://github.com/stardust50578/rdp_brute","1","1","N/A","N/A","8","1","2","6","2019-05-19T14:25:06Z","2019-05-19T14:29:49Z","10211" +"*/rdp_check.py*",".{0,1000}\/rdp_check\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","10212" +"*/RDPassSpray.git*",".{0,1000}\/RDPassSpray\.git.{0,1000}","offensive_tool_keyword","RDPassSpray","Python3 tool to perform password spraying using RDP","T1110.003 - T1059.006 - T1076.001","TA0001 - TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/xFreed0m/RDPassSpray","1","1","N/A","N/A","10","7","648","244","2023-08-17T15:09:50Z","2019-06-05T17:10:42Z","10213" +"*/RDPCredentialStealer.git*",".{0,1000}\/RDPCredentialStealer\.git.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","10214" +"*/RDPCredentialStealer/releases/download/*",".{0,1000}\/RDPCredentialStealer\/releases\/download\/.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","10215" +"*/RDPCredentialStealer/tarball/latest*",".{0,1000}\/RDPCredentialStealer\/tarball\/latest.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","10216" +"*/rdp-enum-encryption.nse*",".{0,1000}\/rdp\-enum\-encryption\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10217" +"*/RDPHook.dll*",".{0,1000}\/RDPHook\.dll.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","1","N/A","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","10218" +"*/RDPKeylog.exe*",".{0,1000}\/RDPKeylog\.exe.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","10219" +"*/RDPMITM.py*",".{0,1000}\/RDPMITM\.py.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","#linux","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","10220" +"*/rdp-ntlm-info.nse*",".{0,1000}\/rdp\-ntlm\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10221" +"*/rdp-sniffer.cap*",".{0,1000}\/rdp\-sniffer\.cap.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","#linux","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","10226" +"*/RdpStrike.git*",".{0,1000}\/RdpStrike\.git.{0,1000}","offensive_tool_keyword","RdpStrike","Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP","T1081 - T1055.011 - T1012 - T1113 - T1040 - T1185","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xEr3bus/RdpStrike","1","1","N/A","N/A","10","3","238","27","2024-06-11T19:40:05Z","2024-06-11T19:31:50Z","10227" +"*/RdpThief*",".{0,1000}RdpThief.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","1","N/A","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","10228" +"*/RdpThief.cna*",".{0,1000}\/RdpThief\.cna.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10229" +"*/RdpThief.dll*",".{0,1000}\/RdpThief\.dll.{0,1000}","offensive_tool_keyword","Invoke-RDPThief","perform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentials","T1055 - T1056 - T1071 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/The-Viper-One/Invoke-RDPThief","1","1","N/A","N/A","10","1","62","8","2025-01-21T20:12:33Z","2024-10-01T20:12:00Z","10230" +"*/RdpThief.git*",".{0,1000}\/RdpThief\.git.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","1","N/A","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","10231" +"*/RdpThief_x64.tmp*",".{0,1000}\/RdpThief_x64\.tmp.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10232" +"*/rdpv.exe*",".{0,1000}\/rdpv\.exe.{0,1000}","offensive_tool_keyword","rdpv","RemoteDesktopPassView is a small utility that reveals the password stored by Microsoft Remote Desktop Connection utility inside the .rdp files.","T1110 - T1560.001 - T1555.003 - T1212","TA0006 - TA0007","N/A","Phobos - GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/remote_desktop_password.html","1","1","N/A","N/A","8","10","N/A","N/A","N/A","N/A","10233" +"*/rdp-vuln-ms12-020.nse*",".{0,1000}\/rdp\-vuln\-ms12\-020\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10234" +"*/readfile_bof.*",".{0,1000}\/readfile_bof\..{0,1000}","offensive_tool_keyword","cobaltstrike","MemReader Beacon Object File will allow you to search and extract specific strings from a target process memory and return what is found to the beacon output","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trainr3kt/Readfile_BoF","1","1","N/A","N/A","10","10","21","5","2022-06-21T04:50:39Z","2021-04-01T03:47:56Z","10240" +"*/Readfile_BoF/*",".{0,1000}\/Readfile_BoF\/.{0,1000}","offensive_tool_keyword","cobaltstrike","MemReader Beacon Object File will allow you to search and extract specific strings from a target process memory and return what is found to the beacon output","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trainr3kt/Readfile_BoF","1","1","N/A","N/A","10","10","21","5","2022-06-21T04:50:39Z","2021-04-01T03:47:56Z","10241" +"*/RealBlindingEDR.git*",".{0,1000}\/RealBlindingEDR\.git.{0,1000}","offensive_tool_keyword","RealBlindingEDR","AV/EDR evasion","T1562.001 - T1548.001","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/myzxcg/RealBlindingEDR","1","1","N/A","N/A","10","10","1050","190","2024-06-21T03:16:55Z","2023-10-28T07:06:53Z","10242" +"*/RealBlindingEDR/tarball*",".{0,1000}\/RealBlindingEDR\/tarball.{0,1000}","offensive_tool_keyword","RealBlindingEDR","AV/EDR evasion","T1562.001 - T1548.001","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/myzxcg/RealBlindingEDR","1","1","N/A","N/A","10","10","1050","190","2024-06-21T03:16:55Z","2023-10-28T07:06:53Z","10243" +"*/RealBlindingEDR/zipball*",".{0,1000}\/RealBlindingEDR\/zipball.{0,1000}","offensive_tool_keyword","RealBlindingEDR","AV/EDR evasion","T1562.001 - T1548.001","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/myzxcg/RealBlindingEDR","1","1","N/A","N/A","10","10","1050","190","2024-06-21T03:16:55Z","2023-10-28T07:06:53Z","10244" +"*/Realistic Format Virus.exe*",".{0,1000}\/Realistic\sFormat\sVirus\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","10245" +"*/realvnc-auth-bypass.nse*",".{0,1000}\/realvnc\-auth\-bypass\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10247" +"*/Reaper.git*",".{0,1000}\/Reaper\.git.{0,1000}","offensive_tool_keyword","reaper","Reaper is a proof-of-concept designed to exploit BYOVD (Bring Your Own Vulnerable Driver) driver vulnerability. This malicious technique involves inserting a legitimate - vulnerable driver into a target system - which allows attackers to exploit the driver to perform malicious actions.","T1547.009 - T1215 - T1129 - T1548.002","TA0002 - TA0003 - TA0040 - TA0005","N/A","N/A","Defense Evasion","https://github.com/MrEmpy/Reaper","1","1","N/A","N/A","10","2","158","34","2024-12-07T01:52:58Z","2023-09-21T02:09:48Z","10248" +"*/ReaperX64.zip*",".{0,1000}\/ReaperX64\.zip.{0,1000}","offensive_tool_keyword","reaper","Reaper is a proof-of-concept designed to exploit BYOVD (Bring Your Own Vulnerable Driver) driver vulnerability. This malicious technique involves inserting a legitimate - vulnerable driver into a target system - which allows attackers to exploit the driver to perform malicious actions.","T1547.009 - T1215 - T1129 - T1548.002","TA0002 - TA0003 - TA0040 - TA0005","N/A","N/A","Defense Evasion","https://github.com/MrEmpy/Reaper","1","1","N/A","N/A","10","2","158","34","2024-12-07T01:52:58Z","2023-09-21T02:09:48Z","10250" +"*/REC2.git*",".{0,1000}\/REC2\.git.{0,1000}","offensive_tool_keyword","REC2 ","REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in Rust.","T1105 - T1132 - T1071.001","TA0011 - TA0009 - TA0002","N/A","N/A","C2","https://github.com/g0h4n/REC2","1","1","N/A","N/A","10","10","153","23","2024-02-22T14:02:24Z","2023-09-25T20:39:59Z","10251" +"*/recaptcha-phish.git*",".{0,1000}\/recaptcha\-phish\.git.{0,1000}","offensive_tool_keyword","recaptcha-phish","Phishing with a fake reCAPTCHA","T1566.001 - T1204.002 - T1071.003","TA0001 - TA0002","Lumma Stealer","N/A","Phishing","https://github.com/JohnHammond/recaptcha-phish","1","1","N/A","N/A","10","6","534","104","2024-09-13T11:18:29Z","2024-09-13T07:00:40Z","10252" +"*/recaptcha-phish-main*",".{0,1000}\/recaptcha\-phish\-main.{0,1000}","offensive_tool_keyword","recaptcha-phish","Phishing with a fake reCAPTCHA","T1566.001 - T1204.002 - T1071.003","TA0001 - TA0002","Lumma Stealer","N/A","Phishing","https://github.com/JohnHammond/recaptcha-phish","1","1","N/A","N/A","10","6","534","104","2024-09-13T11:18:29Z","2024-09-13T07:00:40Z","10253" +"*/Recon-AD.git*",".{0,1000}\/Recon\-AD\.git.{0,1000}","offensive_tool_keyword","Recon-AD","AD recon tool based on ADSI and reflective DLL","T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","8","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","10254" +"*/Recon-AD-AllLocalGroups.dll",".{0,1000}\/Recon\-AD\-AllLocalGroups\.dll","offensive_tool_keyword","Recon-AD","AD recon tool based on ADSI and reflective DLL","T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","8","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","10255" +"*/Recon-AD-AllLocalGroups.dll*",".{0,1000}\/Recon\-AD\-AllLocalGroups\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10256" +"*/Recon-AD-Computers.dll",".{0,1000}\/Recon\-AD\-Computers\.dll","offensive_tool_keyword","Recon-AD","AD recon tool based on ADSI and reflective DLL","T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","8","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","10257" +"*/Recon-AD-Computers.dll*",".{0,1000}\/Recon\-AD\-Computers\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10258" +"*/Recon-AD-Domain.dll",".{0,1000}\/Recon\-AD\-Domain\.dll","offensive_tool_keyword","Recon-AD","AD recon tool based on ADSI and reflective DLL","T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","8","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","10259" +"*/Recon-AD-Domain.dll*",".{0,1000}\/Recon\-AD\-Domain\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10260" +"*/Recon-AD-Groups.dll",".{0,1000}\/Recon\-AD\-Groups\.dll","offensive_tool_keyword","Recon-AD","AD recon tool based on ADSI and reflective DLL","T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","8","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","10261" +"*/Recon-AD-Groups.dll*",".{0,1000}\/Recon\-AD\-Groups\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10262" +"*/Recon-AD-LocalGroups.dll*",".{0,1000}\/Recon\-AD\-LocalGroups\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10263" +"*/Recon-AD-LocalGroups.dll*",".{0,1000}\/Recon\-AD\-LocalGroups\.dll.{0,1000}","offensive_tool_keyword","Recon-AD","AD recon tool based on ADSI and reflective DLL","T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","8","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","10264" +"*/Recon-AD-SPNs.dll*",".{0,1000}\/Recon\-AD\-SPNs\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10265" +"*/Recon-AD-Users.dll*",".{0,1000}\/Recon\-AD\-Users\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10266" +"*/Recon-AD-Users.dll*",".{0,1000}\/Recon\-AD\-Users\.dll.{0,1000}","offensive_tool_keyword","Recon-AD","AD recon tool based on ADSI and reflective DLL","T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","8","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","10267" +"*/reconftw.cfg*",".{0,1000}\/reconftw\.cfg.{0,1000}","offensive_tool_keyword","reconftw","reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities","T1595 - T1590 - T1592 - T1596 - T1598 - T1046 - T1599 - T1213 - T1597","TA0043 - TA0042 - TA0007 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/six2dez/reconftw","1","1","#linux","N/A","7","10","6202","982","2025-04-22T13:01:31Z","2020-12-30T23:52:52Z","10269" +"*/reconftw.git*",".{0,1000}\/reconftw\.git.{0,1000}","offensive_tool_keyword","reconftw","reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities","T1595 - T1590 - T1592 - T1596 - T1598 - T1046 - T1599 - T1213 - T1597","TA0043 - TA0042 - TA0007 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/six2dez/reconftw","1","1","#linux","N/A","7","10","6202","982","2025-04-22T13:01:31Z","2020-12-30T23:52:52Z","10270" +"*/reconftw.sh*",".{0,1000}\/reconftw\.sh.{0,1000}","offensive_tool_keyword","reconftw","reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities","T1595 - T1590 - T1592 - T1596 - T1598 - T1046 - T1599 - T1213 - T1597","TA0043 - TA0042 - TA0007 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/six2dez/reconftw","1","1","#linux","N/A","7","10","6202","982","2025-04-22T13:01:31Z","2020-12-30T23:52:52Z","10271" +"*/reconFTW.yml*",".{0,1000}\/reconFTW\.yml.{0,1000}","offensive_tool_keyword","reconftw","reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities","T1595 - T1590 - T1592 - T1596 - T1598 - T1046 - T1599 - T1213 - T1597","TA0043 - TA0042 - TA0007 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/six2dez/reconftw","1","1","#linux","N/A","7","10","6202","982","2025-04-22T13:01:31Z","2020-12-30T23:52:52Z","10272" +"*/RecycledInjector*",".{0,1000}\/RecycledInjector.{0,1000}","offensive_tool_keyword","RecycledInjector","Native Syscalls Shellcode Injector","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/florylsk/RecycledInjector","1","1","N/A","N/A","N/A","3","266","43","2023-07-02T11:04:28Z","2023-06-23T16:14:56Z","10276" +"*/RecycledInjector.git*",".{0,1000}\/RecycledInjector\.git.{0,1000}","offensive_tool_keyword","RecycledInjector","Native Syscalls Shellcode Injector","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/florylsk/RecycledInjector","1","1","N/A","N/A","N/A","3","266","43","2023-07-02T11:04:28Z","2023-06-23T16:14:56Z","10277" +"*/RedBackdoorer.py*",".{0,1000}\/RedBackdoorer\.py.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","10278" +"*/RedDevil v1.0.exe*",".{0,1000}\/RedDevil\sv1\.0\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","10279" +"*/RedGuard.git*",".{0,1000}\/RedGuard\.git.{0,1000}","offensive_tool_keyword","RedGuard","RedGuard is a C2 front flow control tool.Can avoid Blue Teams.AVs.EDRs check.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/wikiZ/RedGuard","1","1","N/A","N/A","10","10","1466","204","2024-08-20T17:43:35Z","2022-05-08T04:02:33Z","10280" +"*/RedGuard.go*",".{0,1000}\/RedGuard\.go.{0,1000}","offensive_tool_keyword","RedGuard","RedGuard is a C2 front flow control tool.Can avoid Blue Teams.AVs.EDRs check.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/wikiZ/RedGuard","1","1","N/A","N/A","10","10","1466","204","2024-08-20T17:43:35Z","2022-05-08T04:02:33Z","10281" +"*/RedGuard_32",".{0,1000}\/RedGuard_32","offensive_tool_keyword","RedGuard","RedGuard is a C2 front flow control tool.Can avoid Blue Teams.AVs.EDRs check.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/wikiZ/RedGuard","1","1","N/A","N/A","10","10","1466","204","2024-08-20T17:43:35Z","2022-05-08T04:02:33Z","10282" +"*/RedGuard_64",".{0,1000}\/RedGuard_64","offensive_tool_keyword","RedGuard","RedGuard is a C2 front flow control tool.Can avoid Blue Teams.AVs.EDRs check.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/wikiZ/RedGuard","1","1","N/A","N/A","10","10","1466","204","2024-08-20T17:43:35Z","2022-05-08T04:02:33Z","10283" +"*/redirect-hack.html?id=*",".{0,1000}\/redirect\-hack\.html\?id\=.{0,1000}","offensive_tool_keyword","CursedChrome","Chrome-extension implant that turns victim Chrome browsers into fully-functional HTTP proxies allowing you to browse sites as your victims","T1176 - T1219 - T1090","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/mandatoryprogrammer/CursedChrome","1","1","N/A","N/A","10","10","1533","226","2024-10-26T19:06:54Z","2020-04-26T20:55:05Z","10284" +"*/redirector/redirector.py*",".{0,1000}\/redirector\/redirector\.py.{0,1000}","offensive_tool_keyword","Striker","Striker is a simple Command and Control (C2) program.","T1071 - T1071.001 - T1071.004 - T1071.005 - T1071.006 - T1071.007 - T1071.008 - T1071.009 - T1071.010 - T1071.012 - T1071.013 - T1071.014 - T1071.015 - T1071.016 - T1071.018 - T1105 - T1105.002 - T1573 - T1573.002 - T1573.003 - T1573.004 - T1573.005","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/4g3nt47/Striker","1","1","N/A","N/A","10","10","301","42","2023-05-04T18:00:05Z","2022-09-07T10:09:41Z","10285" +"*/redirecttosmb.py*",".{0,1000}\/redirecttosmb\.py.{0,1000}","offensive_tool_keyword","SMBTrap","tool capturing authentication attempts and performing man-in-the-middle (MitM) attacks leveraging SMB services","T1071.001 - T1557.001 - T1040 - T1070.001 - T1205.001 - T1185","TA0006 - TA0008 - TA0011 - TA0005","N/A","ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/cylance/SMBTrap","1","1","N/A","N/A","8","1","84","38","2015-06-02T17:22:48Z","2015-04-13T07:08:01Z","10286" +"*/redis-brute.nse*",".{0,1000}\/redis\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10287" +"*/redis-info.nse*",".{0,1000}\/redis\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10288" +"*/redpeanut.cer*",".{0,1000}\/redpeanut\.cer.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","10289" +"*/RedPeanut.git*",".{0,1000}\/RedPeanut\.git.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","10290" +"*/RedPeanut.html*",".{0,1000}\/RedPeanut\.html.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","10291" +"*/RedPeanutAgent/*",".{0,1000}\/RedPeanutAgent\/.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","10292" +"*/RedPeanutRP/*",".{0,1000}\/RedPeanutRP\/.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","10293" +"*/RedPersist.exe*",".{0,1000}\/RedPersist\.exe.{0,1000}","offensive_tool_keyword","RedPersist","RedPersist is a Windows Persistence tool written in C#","T1053 - T1547 - T1112","TA0004 - TA0005 - TA0040","N/A","N/A","Persistence","https://github.com/mertdas/RedPersist","1","1","N/A","N/A","10","3","215","33","2024-03-10T15:40:05Z","2023-08-13T22:10:46Z","10294" +"*/RedPersist.git*",".{0,1000}\/RedPersist\.git.{0,1000}","offensive_tool_keyword","RedPersist","RedPersist is a Windows Persistence tool written in C#","T1053 - T1547 - T1112","TA0004 - TA0005 - TA0040","N/A","N/A","Persistence","https://github.com/mertdas/RedPersist","1","1","N/A","N/A","10","3","215","33","2024-03-10T15:40:05Z","2023-08-13T22:10:46Z","10295" +"*/redpill.ps1*",".{0,1000}\/redpill\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","10296" +"*/redpill/bin/*.ps1*",".{0,1000}\/redpill\/bin\/.{0,1000}\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","#linux","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","10297" +"*/RedTeam_toolkit*",".{0,1000}\/RedTeam_toolkit.{0,1000}","offensive_tool_keyword","RedTeam_toolkit","Red Team Toolkit is an Open-Source Django Offensive Web-App which is keeping the useful offensive tools used in the red-teaming together","T1083 - T1065 - T1204 - T1087 - T1203","TA0007 - TA0005 - TA0001","N/A","N/A","Reconnaissance","https://github.com/signorrayan/RedTeam_toolkit","1","1","N/A","N/A","N/A","6","561","121","2025-03-28T06:59:25Z","2021-08-18T08:58:14Z","10300" +"*/RedTeam_Tools_n_Stuff.git*",".{0,1000}\/RedTeam_Tools_n_Stuff\.git.{0,1000}","offensive_tool_keyword","RedTeam_Tools_n_Stuff","Collection of self-made Red Team tools","T1070.004 - T1222 - T1070.003 - T1003.005 - T1057","TA0005 - TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/samkenxstream/SAMkenXCCorePHdLAwiN8SoLr77","1","1","N/A","N/A","7","1","1","1","2023-10-13T06:31:42Z","2023-10-04T13:43:37Z","10301" +"*/red-team-scripts*",".{0,1000}\/red\-team\-scripts.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script function and alias to perform some rudimentary Windows host enumeration with Beacon built-in commands","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/red-team-scripts","1","1","N/A","N/A","10","10","1122","195","2024-11-19T19:39:01Z","2017-05-01T13:53:05Z","10303" +"*/RedWarden.git*",".{0,1000}\/RedWarden\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","10304" +"*/ReferenceSourceLibraries/Sharpire*",".{0,1000}\/ReferenceSourceLibraries\/Sharpire.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","10305" +"*/ReflectDump.exe*",".{0,1000}\/ReflectDump\.exe.{0,1000}","offensive_tool_keyword","LsassReflectDumping","leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process","T1003.001 - T1555.003 - T1077","TA0006","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/LsassReflectDumping","1","1","N/A","N/A","10","2","198","27","2024-10-19T08:16:13Z","2024-10-17T14:57:30Z","10306" +"*/ReflectiveDll.c*",".{0,1000}\/ReflectiveDll\.c.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","10307" +"*/ReflectiveDll.x64.dll*",".{0,1000}\/ReflectiveDll\.x64\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10308" +"*/ReflectiveDLLInjection/*",".{0,1000}\/ReflectiveDLLInjection\/.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","10309" +"*/ReflectiveLoader.c*",".{0,1000}\/ReflectiveLoader\.c.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","10310" +"*/ReflectiveNtdll.git*",".{0,1000}\/ReflectiveNtdll\.git.{0,1000}","offensive_tool_keyword","ReflectiveNtdll","A Dropper POC with a focus on aiding in EDR evasion - NTDLL Unhooking followed by loading ntdll in-memory which is present as shellcode","T1059 - T1059.003 - T1218.011 - T1027 - T1027.005 - T1070 - T1070.004","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/reveng007/ReflectiveNtdll","1","1","N/A","N/A","10","2","170","24","2023-02-10T05:30:28Z","2023-01-30T08:43:16Z","10311" +"*/ReflectivePick_x64.dll*",".{0,1000}\/ReflectivePick_x64\.dll.{0,1000}","offensive_tool_keyword","Powerpick","allowing the execution of Powershell functionality without the use of Powershell.exe","T1059.001 - T1059.003 - T1086 - T1027.001","TA0005 - TA0002","N/A","Black Basta - Dispossessor","Defense Evasion","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","10312" +"*/ReflectivePick_x86.dll*",".{0,1000}\/ReflectivePick_x86\.dll.{0,1000}","offensive_tool_keyword","Powerpick","allowing the execution of Powershell functionality without the use of Powershell.exe","T1059.001 - T1059.003 - T1086 - T1027.001","TA0005 - TA0002","N/A","Black Basta - Dispossessor","Defense Evasion","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","10313" +"*/RefleXXion.git*",".{0,1000}\/RefleXXion\.git.{0,1000}","offensive_tool_keyword","RefleXXion","RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks. it first collects the syscall numbers of the NtOpenFile. NtCreateSection. NtOpenSection and NtMapViewOfSection found in the LdrpThunkSignature array.","T1055.004 - T1562.004 - T1070.004","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/hlldz/RefleXXion","1","1","N/A","N/A","10","5","490","105","2022-01-25T17:06:21Z","2022-01-25T16:50:34Z","10314" +"*/reg_hive_sam.py*",".{0,1000}\/reg_hive_sam\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","10315" +"*/reg_hive_security.py*",".{0,1000}\/reg_hive_security\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","10316" +"*/reg_hive_system.py*",".{0,1000}\/reg_hive_system\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","10317" +"*/reg_recover-rs.exe*",".{0,1000}\/reg_recover\-rs\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","10318" +"*/reGeorg.git*",".{0,1000}\/reGeorg\.git.{0,1000}","offensive_tool_keyword","reGeorg","The successor to reDuh - pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.","T1090 - T1095 - T1572","TA0003 - TA0011","N/A","FIN13 - IRIDIUM - UNC3524 - Worok - COZY BEAR - FANCY BEAR - EMBER BEAR - Sandworm","Data Exfiltration","https://github.com/sensepost/reGeorg","1","1","N/A","N/A","N/A","10","3075","826","2025-03-06T09:56:16Z","2014-08-08T00:58:12Z","10319" +"*/RegfDenyTSConnections.ps1*",".{0,1000}\/RegfDenyTSConnections\.ps1.{0,1000}","offensive_tool_keyword","EventLogMaster","Cobalt Strike Plugin - RDP Log Forensics & Clearing","T1070.001 - T1070.003 - T1070.004 - T1563.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/QAX-A-Team/EventLogMaster","1","1","N/A","N/A","6","4","361","73","2019-12-23T10:31:35Z","2019-12-17T05:07:09Z","10320" +"*/reghivebackup.zip*",".{0,1000}\/reghivebackup\.zip.{0,1000}","offensive_tool_keyword","RegHiveBackup","backup the Registry files on your system into the specified folder","T1012 - T1596 - T1003","TA0006 - TA0009","N/A","N/A","Collection","https://www.nirsoft.net/alpha/reghivebackup.zip","1","1","#registry","N/A","10","10","N/A","N/A","N/A","N/A","10321" +"*/register dll.exe*",".{0,1000}\/register\sdll\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","10322" +"*/RegistryPersistence.c*",".{0,1000}\/RegistryPersistence\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Various Cobalt Strike BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rvrsh3ll/BOF_Collection","1","1","N/A","N/A","10","10","635","57","2022-10-16T13:57:18Z","2020-07-16T18:24:55Z","10323" +"*/registry-read.py*",".{0,1000}\/registry\-read\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","10324" +"*/Registry-Recon/*",".{0,1000}\/Registry\-Recon\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor Script that Performs System/AV/EDR Recon","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/optiv/Registry-Recon","1","1","N/A","N/A","10","10","325","36","2022-06-06T14:39:12Z","2021-07-29T18:47:23Z","10325" +"*/reg-query.py*",".{0,1000}\/reg\-query\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","10326" +"*/RegRdpPort.ps1*",".{0,1000}\/RegRdpPort\.ps1.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10327" +"*/regread.lua*",".{0,1000}\/regread\.lua.{0,1000}","offensive_tool_keyword","OffensiveLua","Offensive Lua is a collection of offensive security scripts written in Lua with FFI","T1059 - T1218.011 - T1105 - T1021.002 - T1564.001 - T1112 - T1113 - T1204.002 - T1547.002","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hackerhouse-opensource/OffensiveLua","1","1","N/A","N/A","8","2","184","25","2023-11-17T00:35:10Z","2023-10-25T17:21:13Z","10328" +"*/regreeper.jpg*",".{0,1000}\/regreeper\.jpg.{0,1000}","offensive_tool_keyword","regreeper","gain persistence and evade sysmon event code registry (creation update and deletion) REG_NOTIFY_CLASS Registry Callback of sysmon driver filter. RegSaveKeyExW() and RegRestoreKeyW() API which is not included in monitoring.","T1050.005 - T1012 - T1112 - T1553.002 - T1053.005","TA0005 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/tccontre/Reg-Restore-Persistence-Mole","1","1","N/A","N/A","10","1","51","16","2023-08-23T11:34:26Z","2023-08-03T14:47:45Z","10329" +"*/Reg-Restore-Persistence-Mole*",".{0,1000}\/Reg\-Restore\-Persistence\-Mole.{0,1000}","offensive_tool_keyword","regreeper","gain persistence and evade sysmon event code registry (creation update and deletion) REG_NOTIFY_CLASS Registry Callback of sysmon driver filter. RegSaveKeyExW() and RegRestoreKeyW() API which is not included in monitoring.","T1050.005 - T1012 - T1112 - T1553.002 - T1053.005","TA0005 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/tccontre/Reg-Restore-Persistence-Mole","1","1","N/A","N/A","10","1","51","16","2023-08-23T11:34:26Z","2023-08-03T14:47:45Z","10330" +"*/regsvcs/meterpreter*",".{0,1000}\/regsvcs\/meterpreter.{0,1000}","offensive_tool_keyword","GreatSCT","The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This tool is intended for BOTH red and blue team.","T1055 - T1112 - T1189 - T1205","TA0005 - TA0006 - TA0008","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","Defense Evasion","https://github.com/GreatSCT/GreatSCT","1","1","N/A","N/A","N/A","10","1127","202","2021-02-10T22:05:27Z","2017-05-12T03:30:41Z","10331" +"*/regsvr.cmd*",".{0,1000}\/regsvr\.cmd.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","10332" +"*/regsvr32/shellcode_inject*",".{0,1000}\/regsvr32\/shellcode_inject.{0,1000}","offensive_tool_keyword","GreatSCT","The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This tool is intended for BOTH red and blue team.","T1055 - T1112 - T1189 - T1205","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/GreatSCT/GreatSCT","1","1","N/A","N/A","N/A","10","1127","202","2021-02-10T22:05:27Z","2017-05-12T03:30:41Z","10333" +"*/regwrite.lua*",".{0,1000}\/regwrite\.lua.{0,1000}","offensive_tool_keyword","OffensiveLua","Offensive Lua is a collection of offensive security scripts written in Lua with FFI","T1059 - T1218.011 - T1105 - T1021.002 - T1564.001 - T1112 - T1113 - T1204.002 - T1547.002","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hackerhouse-opensource/OffensiveLua","1","1","N/A","N/A","8","2","184","25","2023-11-17T00:35:10Z","2023-10-25T17:21:13Z","10334" +"*/regwritedel.lua*",".{0,1000}\/regwritedel\.lua.{0,1000}","offensive_tool_keyword","OffensiveLua","Offensive Lua is a collection of offensive security scripts written in Lua with FFI","T1059 - T1218.011 - T1105 - T1021.002 - T1564.001 - T1112 - T1113 - T1204.002 - T1547.002","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hackerhouse-opensource/OffensiveLua","1","1","N/A","N/A","8","2","184","25","2023-11-17T00:35:10Z","2023-10-25T17:21:13Z","10335" +"*/releases/download/*/abc.exe*",".{0,1000}\/releases\/download\/.{0,1000}\/abc\.exe.{0,1000}","offensive_tool_keyword","TGSThief","get the TGS of a user whose logon session is just present on the computer","T1558 - T1558.003 - T1078 - T1078.005","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/MzHmO/TGSThief","1","1","N/A","N/A","9","2","181","27","2023-07-25T05:30:39Z","2023-07-23T07:47:05Z","10338" +"*/releases/download/Binaries/DeadPotato*",".{0,1000}\/releases\/download\/Binaries\/DeadPotato.{0,1000}","offensive_tool_keyword","DeadPotato","DeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privileges","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","N/A","N/A","Privilege Escalation","https://github.com/lypd0/DeadPotato","1","1","N/A","N/A","10","4","382","45","2024-08-17T06:08:29Z","2024-07-31T01:08:30Z","10340" +"*/releases/download/impacket_*",".{0,1000}\/releases\/download\/impacket_.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","10341" +"*/releases/download/panix-v*/panix.sh*",".{0,1000}\/releases\/download\/panix\-v.{0,1000}\/panix\.sh.{0,1000}","offensive_tool_keyword","panix","PANIX is a highly customizable Linux persistence tool","T1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/Aegrah/PANIX","1","1","#linux","N/A","8","7","622","68","2025-03-05T10:45:04Z","2024-05-19T12:37:40Z","10342" +"*/releases/download/v*/pretender_*",".{0,1000}\/releases\/download\/v.{0,1000}\/pretender_.{0,1000}","offensive_tool_keyword","pretender","MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS - LLMNR and NetBIOS-NS spoofing","T1557 - T1046 - T1590 - T1557.002","TA0008 - TA0011 - TA0007 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/RedTeamPentesting/pretender","1","1","N/A","N/A","7","10","1089","79","2025-02-19T08:14:57Z","2022-07-11T13:23:23Z","10343" +"*/releases/download/v0.1.0/dnspot-*",".{0,1000}\/releases\/download\/v0\.1\.0\/dnspot\-.{0,1000}","offensive_tool_keyword","dnspot","End-to-end Encrypted DNS Tunnelling and C2 framework","T1071.004 - T1090.002 - T1573.002","TA0011 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/mosajjal/dnspot","1","1","N/A","N/A","10","10","73","16","2025-02-01T08:13:29Z","2021-09-25T08:49:43Z","10344" +"*/releases/download/v0.1/pamspy*",".{0,1000}\/releases\/download\/v0\.1\/pamspy.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","1","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","10345" +"*/releases/download/v0.2/pamspy*",".{0,1000}\/releases\/download\/v0\.2\/pamspy.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","1","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","10346" +"*/releases/download/v1.0/ADFSRelay*",".{0,1000}\/releases\/download\/v1\.0\/ADFSRelay.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","1","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","10347" +"*/releases/download/v1.0/NTLMParse*",".{0,1000}\/releases\/download\/v1\.0\/NTLMParse.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","1","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","10348" +"*/releases/download/v4.0.1-godzilla/godzilla.jar*",".{0,1000}\/releases\/download\/v4\.0\.1\-godzilla\/godzilla\.jar.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","10349" +"*/releases/latest/download/cloudflared-darwin-amd64.tgz*",".{0,1000}\/releases\/latest\/download\/cloudflared\-darwin\-amd64\.tgz.{0,1000}","offensive_tool_keyword","CamHacker","Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!","T1598 - T1204 - T1566.001","TA0009 - TA0010 - TA0043","N/A","N/A","Phishing","https://github.com/KasRoudra/CamHacker","1","1","#linux","N/A","10","","N/A","","","","10350" +"*/releases/latest/download/lse.sh*",".{0,1000}\/releases\/latest\/download\/lse\.sh.{0,1000}","offensive_tool_keyword","linux-smart-enumeration","Linux enumeration tool for privilege escalation and discovery","T1087.004 - T1016 - T1548.001 - T1046","TA0007 - TA0004 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/diego-treitos/linux-smart-enumeration","1","1","#linux","N/A","9","10","3575","584","2023-12-25T14:46:47Z","2019-02-13T11:02:21Z","10351" +"*/remot shell.pl*",".{0,1000}\/remot\sshell\.pl.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","10355" +"*/Remote/adcs_request/*",".{0,1000}\/Remote\/adcs_request\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","10357" +"*/Remote/office_tokens/*",".{0,1000}\/Remote\/office_tokens\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","10358" +"*/Remote/procdump/*",".{0,1000}\/Remote\/procdump\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","10359" +"*/Remote/ProcessDestroy/*",".{0,1000}\/Remote\/ProcessDestroy\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","10360" +"*/Remote/ProcessListHandles/*",".{0,1000}\/Remote\/ProcessListHandles\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","10361" +"*/Remote/schtaskscreate/*",".{0,1000}\/Remote\/schtaskscreate\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","10362" +"*/Remote/schtasksrun/*",".{0,1000}\/Remote\/schtasksrun\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","10363" +"*/Remote/setuserpass/",".{0,1000}\/Remote\/setuserpass\/","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","10364" +"*/Remote/setuserpass/*",".{0,1000}\/Remote\/setuserpass\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","10365" +"*/Remote/unexpireuser/*",".{0,1000}\/Remote\/unexpireuser\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","10366" +"*/RemoteAccessPolicyEnumeration.ps1*",".{0,1000}\/RemoteAccessPolicyEnumeration\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","10367" +"*/Remote-administration-tools-archive.git*",".{0,1000}\/Remote\-administration\-tools\-archive\.git.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","10368" +"*/remotedesktop.exe*",".{0,1000}\/remotedesktop\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","10371" +"*/RemoteHashRetrieval.ps1*",".{0,1000}\/RemoteHashRetrieval\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","10372" +"*/RemoteKrbRelay.git*",".{0,1000}\/RemoteKrbRelay\.git.{0,1000}","offensive_tool_keyword","RemoteKrbRelay","similar to KrbRelay and KrbRelayUp but With RemoteKrbRelay this can be done remotely","T1550.004 - T1557.001 - T1021.005 - T1105","TA0008 - TA0005","N/A","N/A","Lateral Movement","https://github.com/CICADA8-Research/RemoteKrbRelay","1","1","N/A","N/A","10","6","581","90","2024-06-30T14:08:50Z","2024-06-24T17:38:46Z","10378" +"*/RemoteMaintsvc.exe*",".{0,1000}\/RemoteMaintsvc\.exe.{0,1000}","offensive_tool_keyword","impacketremoteshell","install a legit application and interface with it over smb w/o the signature of cmd.exe / powershell.exe being called or the redirection typically used by those techniques","T1077 - T1059.007 - T1569.001","TA0008 - TA0005 - TA0040","N/A","N/A","Lateral Movement","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","10379" +"*/RemoteMaintsvc.exe*",".{0,1000}\/RemoteMaintsvc\.exe.{0,1000}","offensive_tool_keyword","impacketremoteshell","install a legit application and interface with it over smb w/o the signature of cmd.exe / powershell.exe being called or the redirection typically used by those techniques","T1077 - T1059.007 - T1569.001","TA0008 - TA0005 - TA0040","N/A","N/A","Lateral Movement","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","10380" +"*/remote-method-guesser.git*",".{0,1000}\/remote\-method\-guesser\.git.{0,1000}","offensive_tool_keyword","remote-method-guesser","remote-method-guesser?(rmg) is a?Java RMI?vulnerability scanner and can be used to identify and verify common security vulnerabilities on?Java RMI?endpoints.","T1210.002 - T1046 - T1078.003","TA0001 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/qtc-de/remote-method-guesser","1","1","N/A","N/A","6","9","860","108","2024-07-03T19:40:54Z","2019-11-04T11:37:38Z","10381" +"*/RemoteOps.py*",".{0,1000}\/RemoteOps\.py.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","10383" +"*/RemotePenetration.exe*",".{0,1000}\/RemotePenetration\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","10396" +"*/RemotePotato0.git*",".{0,1000}\/RemotePotato0\.git.{0,1000}","offensive_tool_keyword","RemotePotato0","Windows Privilege Escalation from User to Domain Admin.","T1078.002 - T1078.003 - T1078.004","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RemotePotato0","1","1","N/A","N/A","10","10","1382","215","2022-12-18T01:52:53Z","2021-02-08T22:02:19Z","10397" +"*/RemotePotato0.zip*",".{0,1000}\/RemotePotato0\.zip.{0,1000}","offensive_tool_keyword","RemotePotato0","Windows Privilege Escalation from User to Domain Admin.","T1078.002 - T1078.003 - T1078.004","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RemotePotato0","1","1","N/A","N/A","10","10","1382","215","2022-12-18T01:52:53Z","2021-02-08T22:02:19Z","10398" +"*/remotereg.c*",".{0,1000}\/remotereg\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of CobaltStrike beacon object files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/pwn1sher/CS-BOFs","1","1","N/A","N/A","10","10","103","22","2022-02-14T09:47:30Z","2021-01-18T08:54:48Z","10399" +"*/remotereg.o*",".{0,1000}\/remotereg\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of CobaltStrike beacon object files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/pwn1sher/CS-BOFs","1","1","N/A","N/A","10","10","103","22","2022-02-14T09:47:30Z","2021-01-18T08:54:48Z","10400" +"*/remoteshell.py*",".{0,1000}\/remoteshell\.py.{0,1000}","offensive_tool_keyword","impacketremoteshell","install a legit application and interface with it over smb w/o the signature of cmd.exe / powershell.exe being called or the redirection typically used by those techniques","T1077 - T1059.007 - T1569.001","TA0008 - TA0005 - TA0040","N/A","N/A","Lateral Movement","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","10401" +"*/remoteshell.py*",".{0,1000}\/remoteshell\.py.{0,1000}","offensive_tool_keyword","wmiexec2","wmiexec2.0 is the same wmiexec that everyone knows and loves (debatable). This 2.0 version is obfuscated to avoid well known signatures from various AV engines.","T1021.005 - T1047 - T1059.001 - T1059.003 - T1059.005","TA0008 - TA0002 - TA0011","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/ice-wzl/wmiexec2","1","1","N/A","N/A","9","1","34","1","2024-06-12T17:56:15Z","2023-02-07T22:10:08Z","10402" +"*/Remove_defender_moduled*",".{0,1000}\/Remove_defender_moduled.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","10403" +"*/request_shellcode.exe*",".{0,1000}\/request_shellcode\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","10404" +"*/resocks.git*",".{0,1000}\/resocks\.git.{0,1000}","offensive_tool_keyword","resocks","resocks is a reverse/back-connect SOCKS5 proxy tunnel that can be used to route traffic through a system that can't be directly accessed","T1090.003 - T1090 - T1571","TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/RedTeamPentesting/resocks","1","1","N/A","N/A","8","10","437","33","2023-09-19T10:43:29Z","2023-05-02T08:42:15Z","10407" +"*/resocks/releases/latest*",".{0,1000}\/resocks\/releases\/latest.{0,1000}","offensive_tool_keyword","resocks","resocks is a reverse/back-connect SOCKS5 proxy tunnel that can be used to route traffic through a system that can't be directly accessed","T1090.003 - T1090 - T1571","TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/RedTeamPentesting/resocks","1","1","N/A","N/A","8","10","437","33","2023-09-19T10:43:29Z","2023-05-02T08:42:15Z","10408" +"*/resocks_*_Linux_x86_64.tar.gz*",".{0,1000}\/resocks_.{0,1000}_Linux_x86_64\.tar\.gz.{0,1000}","offensive_tool_keyword","resocks","resocks is a reverse/back-connect SOCKS5 proxy tunnel that can be used to route traffic through a system that can't be directly accessed","T1090.003 - T1090 - T1571","TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/RedTeamPentesting/resocks","1","1","#linux","N/A","8","10","437","33","2023-09-19T10:43:29Z","2023-05-02T08:42:15Z","10409" +"*/resocks_*_macOS_arm64.tar.gz*",".{0,1000}\/resocks_.{0,1000}_macOS_arm64\.tar\.gz.{0,1000}","offensive_tool_keyword","resocks","resocks is a reverse/back-connect SOCKS5 proxy tunnel that can be used to route traffic through a system that can't be directly accessed","T1090.003 - T1090 - T1571","TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/RedTeamPentesting/resocks","1","1","N/A","N/A","8","10","437","33","2023-09-19T10:43:29Z","2023-05-02T08:42:15Z","10410" +"*/resocks_Darwin_x86_64.tar.gz*",".{0,1000}\/resocks_Darwin_x86_64\.tar\.gz.{0,1000}","offensive_tool_keyword","resocks","resocks is a reverse/back-connect SOCKS5 proxy tunnel that can be used to route traffic through a system that can't be directly accessed","T1090.003 - T1090 - T1571","TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/RedTeamPentesting/resocks","1","1","#linux","N/A","8","10","437","33","2023-09-19T10:43:29Z","2023-05-02T08:42:15Z","10411" +"*/resocks_Linux_*.tar.gz*",".{0,1000}\/resocks_Linux_.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","resocks","resocks is a reverse/back-connect SOCKS5 proxy tunnel that can be used to route traffic through a system that can't be directly accessed","T1090.003 - T1090 - T1571","TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/RedTeamPentesting/resocks","1","1","#linux","N/A","8","10","437","33","2023-09-19T10:43:29Z","2023-05-02T08:42:15Z","10412" +"*/resolveall.nse*",".{0,1000}\/resolveall\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10413" +"*/resources/PROCEXP.sys*",".{0,1000}\/resources\/PROCEXP\.sys.{0,1000}","offensive_tool_keyword","Backstab","A tool to kill antimalware protected processes","T1562.001 - T1569 - T1059","TA0005 - TA0040 - TA0002","N/A","Black Basta - LockBit","Defense Evasion","https://github.com/Yaxser/Backstab","1","1","N/A","N/A","10","10","1435","244","2021-06-19T20:01:52Z","2021-06-15T16:02:11Z","10414" +"*/Responder.git*",".{0,1000}\/Responder\.git.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","N/A","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","10416" +"*/responder/Responder.conf *",".{0,1000}\/responder\/Responder\.conf\s.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","N/A","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","10417" +"*/Responder-master.zip*",".{0,1000}\/Responder\-master\.zip.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","N/A","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","10420" +"*/Responder-Windows.git*",".{0,1000}\/Responder\-Windows\.git.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/lgandx/Responder-Windows/","1","1","N/A","N/A","N/A","6","523","137","2024-07-30T11:10:05Z","2015-02-07T22:59:04Z","10422" +"*/restoresig.py*",".{0,1000}\/restoresig\.py.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","1","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","10429" +"*/returnvar/wce/*",".{0,1000}\/returnvar\/wce\/.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","1","N/A","N/A","8","4","N/A","N/A","N/A","N/A","10430" +"*/rev_shell.py*",".{0,1000}\/rev_shell\.py.{0,1000}","offensive_tool_keyword","C2_Server","C2 server to connect to a victim machine via reverse shell","T1090 - T1090.001 - T1071 - T1071.001","TA0011 ","N/A","N/A","C2","https://github.com/reveng007/C2_Server","1","1","N/A","N/A","10","10","54","18","2022-02-27T02:00:02Z","2021-03-05T12:35:45Z","10431" +"*/revbshell.git*",".{0,1000}\/revbshell\.git.{0,1000}","offensive_tool_keyword","revbshell","ReVBShell - Reverse VBS Shell","T1059.005 - T1573.001 - T1105","TA0011 - TA0010","N/A","N/A","C2","https://github.com/bitsadmin/revbshell","1","1","N/A","N/A","10","10","81","27","2019-10-08T12:00:05Z","2017-02-19T18:58:52Z","10432" +"*/reverse.exe*",".{0,1000}\/reverse\.exe.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","10434" +"*/reverse-index.nse*",".{0,1000}\/reverse\-index\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10435" +"*/ReverseShell.ahk*",".{0,1000}\/ReverseShell\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","10436" +"*/reverseShell-1.0.1-zip.zip*",".{0,1000}\/reverseShell\-1\.0\.1\-zip\.zip.{0,1000}","offensive_tool_keyword","WebSocketReverseShellDotNet","A .NET-based Reverse Shell, it establishes a link to the command and control for subsequent guidance.","T1071 - T1105","TA0011 - TA0002","N/A","N/A","C2","https://github.com/The-Hustler-Hattab/WebSocketReverseShellDotNet","1","1","N/A","N/A","10","10","1","0","2024-04-18T01:00:48Z","2023-12-03T03:35:24Z","10437" +"*/reverse-shellcode.cpp*",".{0,1000}\/reverse\-shellcode\.cpp.{0,1000}","offensive_tool_keyword","killer","evade AVs and EDRs or security tools","T1564 - T1027 - T1070","TA0005","N/A","N/A","Defense Evasion","https://github.com/0xHossam/Killer","1","1","N/A","N/A","10","9","804","128","2024-07-02T10:24:43Z","2023-04-08T16:29:52Z","10438" +"*/reverse-shell-generator*",".{0,1000}\/reverse\-shell\-generator.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Hosted Reverse Shell generator with a ton of functionality","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","N/A","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","10439" +"*/reverse-shell-generator.git*",".{0,1000}\/reverse\-shell\-generator\.git.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","10440" +"*/ReverseSock5Proxy.git*",".{0,1000}\/ReverseSock5Proxy\.git.{0,1000}","offensive_tool_keyword","ReverseSock5Proxy","A tiny Reverse Sock5 Proxy","T1090.002 - T1572 - T1071","TA0011 - TA0010","N/A","N/A","C2","https://github.com/Coldzer0/ReverseSock5Proxy","1","1","N/A","N/A","10","10","317","42","2022-11-28T21:18:26Z","2022-11-25T15:12:59Z","10441" +"*/ReverseSock5Proxy/tarball/*",".{0,1000}\/ReverseSock5Proxy\/tarball\/.{0,1000}","offensive_tool_keyword","ReverseSock5Proxy","A tiny Reverse Sock5 Proxy","T1090.002 - T1572 - T1071","TA0011 - TA0010","N/A","N/A","C2","https://github.com/Coldzer0/ReverseSock5Proxy","1","1","N/A","N/A","10","10","317","42","2022-11-28T21:18:26Z","2022-11-25T15:12:59Z","10442" +"*/ReverseSock5Proxy/zipball/*",".{0,1000}\/ReverseSock5Proxy\/zipball\/.{0,1000}","offensive_tool_keyword","ReverseSock5Proxy","A tiny Reverse Sock5 Proxy","T1090.002 - T1572 - T1071","TA0011 - TA0010","N/A","N/A","C2","https://github.com/Coldzer0/ReverseSock5Proxy","1","1","N/A","N/A","10","10","317","42","2022-11-28T21:18:26Z","2022-11-25T15:12:59Z","10443" +"*/reverse-ssh.git*",".{0,1000}\/reverse\-ssh\.git.{0,1000}","offensive_tool_keyword","reverse-ssh","Statically-linked ssh server with reverse shell functionality for CTFs and such","T1105 - T1572 - T1569.002 - T1090","TA0001 - TA0002 - TA0003 - TA0010 - TA0011 - TA0005 ","N/A","N/A","C2","https://github.com/Fahrj/reverse-ssh","1","1","N/A","N/A","10","10","961","141","2023-02-15T00:16:25Z","2021-07-12T18:26:29Z","10444" +"*/reverse-ssh-armv7-x86*",".{0,1000}\/reverse\-ssh\-armv7\-x86.{0,1000}","offensive_tool_keyword","reverse-ssh","Statically-linked ssh server with reverse shell functionality for CTFs and such","T1105 - T1572 - T1569.002 - T1090","TA0001 - TA0002 - TA0003 - TA0010 - TA0011 - TA0005 ","N/A","N/A","C2","https://github.com/Fahrj/reverse-ssh","1","1","N/A","N/A","10","10","961","141","2023-02-15T00:16:25Z","2021-07-12T18:26:29Z","10446" +"*/reverse-ssh-armv8-x64*",".{0,1000}\/reverse\-ssh\-armv8\-x64.{0,1000}","offensive_tool_keyword","reverse-ssh","Statically-linked ssh server with reverse shell functionality for CTFs and such","T1105 - T1572 - T1569.002 - T1090","TA0001 - TA0002 - TA0003 - TA0010 - TA0011 - TA0005 ","N/A","N/A","C2","https://github.com/Fahrj/reverse-ssh","1","1","N/A","N/A","10","10","961","141","2023-02-15T00:16:25Z","2021-07-12T18:26:29Z","10447" +"*/reverse-sshx64*",".{0,1000}\/reverse\-sshx64.{0,1000}","offensive_tool_keyword","reverse-ssh","Statically-linked ssh server with reverse shell functionality for CTFs and such","T1105 - T1572 - T1569.002 - T1090","TA0001 - TA0002 - TA0003 - TA0010 - TA0011 - TA0005 ","N/A","N/A","C2","https://github.com/Fahrj/reverse-ssh","1","1","N/A","N/A","10","10","961","141","2023-02-15T00:16:25Z","2021-07-12T18:26:29Z","10448" +"*/ReverseTCPShell*",".{0,1000}\/ReverseTCPShell.{0,1000}","offensive_tool_keyword","ReverseTCPShell","PowerShell ReverseTCP Shell - Framework","T1059.001 ","TA0011 ","N/A","N/A","C2","https://github.com/ZHacker13/ReverseTCPShell","1","1","N/A","N/A","10","10","1053","216","2022-09-18T20:59:33Z","2019-05-27T23:43:54Z","10450" +"*/reverst.git*",".{0,1000}\/reverst\.git.{0,1000}","offensive_tool_keyword","reverst","Reverse Tunnels in Go over HTTP/3 and QUIC","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","N/A","C2","https://github.com/flipt-io/reverst","1","1","N/A","N/A","10","10","953","39","2025-04-16T22:33:32Z","2024-04-03T13:32:11Z","10454" +"*/reverst.git*",".{0,1000}\/reverst\.git.{0,1000}","offensive_tool_keyword","reverst","Reverse Tunnels in Go over HTTP/3 and QUIC","T1572 - T1071.001 - T1105","TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/flipt-io/reverst","1","1","N/A","N/A","10","10","953","39","2025-04-16T22:33:32Z","2024-04-03T13:32:11Z","10455" +"*/RevlCmd.dll*",".{0,1000}\/RevlCmd\.dll.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","10456" +"*/Rev-Shell.git*",".{0,1000}\/Rev\-Shell\.git.{0,1000}","offensive_tool_keyword","Rev-Shell","Basic script to generate reverse shell payloads","T1055.011 - T1021.005 - T1560.001","TA0002 - TA0005 - TA0042 - TA0011","N/A","N/A","C2","https://github.com/washingtonP1974/Rev-Shell","1","1","N/A","N/A","3","10","29","1","2024-03-20T13:58:21Z","2024-03-20T13:37:12Z","10458" +"*/revshell.ps1*",".{0,1000}\/revshell\.ps1.{0,1000}","offensive_tool_keyword","Invoke-Stealth","Simple & Powerful PowerShell Script Obfuscator","T1027.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/JoelGMSec/Invoke-Stealth","1","1","N/A","N/A","9","6","559","81","2023-04-21T12:49:37Z","2021-04-13T10:22:05Z","10459" +"*/revshell.ps1*",".{0,1000}\/revshell\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","10460" +"*/revshell.py*",".{0,1000}\/revshell\.py.{0,1000}","offensive_tool_keyword","Rev-Shell","Basic script to generate reverse shell payloads","T1055.011 - T1021.005 - T1560.001","TA0002 - TA0005 - TA0042 - TA0011","N/A","N/A","C2","https://github.com/washingtonP1974/Rev-Shell","1","1","N/A","N/A","3","10","29","1","2024-03-20T13:58:21Z","2024-03-20T13:37:12Z","10461" +"*/revshell32.bin*",".{0,1000}\/revshell32\.bin.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","10462" +"*/revshell64.bin*",".{0,1000}\/revshell64\.bin.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","10463" +"*/revshells.com*",".{0,1000}\/revshells\.com.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","10464" +"*/revsocks.exe*",".{0,1000}\/revsocks\.exe.{0,1000}","offensive_tool_keyword","revsocks","Cross-platform SOCKS5 proxy server program/library written in C that can also reverse itself over a firewall.","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/emilarner/revsocks","1","1","N/A","https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/iran-apt-seedworm-africa-telecoms","10","10","31","4","2022-08-08T07:59:16Z","2022-03-29T22:12:18Z","10465" +"*/revsocks.exe*",".{0,1000}\/revsocks\.exe.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","N/A","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","10466" +"*/revsocks.git*",".{0,1000}\/revsocks\.git.{0,1000}","offensive_tool_keyword","revsocks","Cross-platform SOCKS5 proxy server program/library written in C that can also reverse itself over a firewall.","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/emilarner/revsocks","1","1","N/A","https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/iran-apt-seedworm-africa-telecoms","10","10","31","4","2022-08-08T07:59:16Z","2022-03-29T22:12:18Z","10467" +"*/revsocks.git*",".{0,1000}\/revsocks\.git.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","N/A","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","10468" +"*/rexec-brute.nse*",".{0,1000}\/rexec\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10469" +"*/rfc868-time.nse*",".{0,1000}\/rfc868\-time\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10470" +"*/rfs_injection.exe*",".{0,1000}\/rfs_injection\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","10471" +"*/RGPerson.py*",".{0,1000}\/RGPerson\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","10473" +"*/riak-http-info.nse*",".{0,1000}\/riak\-http\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10474" +"*/ricardojba/Invoke-noPac*",".{0,1000}\/ricardojba\/Invoke\-noPac.{0,1000}","offensive_tool_keyword","POC","POC exploitation for CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user","T1548 - T1134 - T1078 - T1078.002","TA0003 - TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/ricardojba/Invoke-noPac","1","1","N/A","N/A","N/A","1","62","12","2023-02-16T10:45:19Z","2021-12-13T19:01:18Z","10475" +"*/ricardojba/noPac*",".{0,1000}\/ricardojba\/noPac.{0,1000}","offensive_tool_keyword","POC","POC exploitation for CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user","T1548 - T1134 - T1078 - T1078.002","TA0003 - TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/ricardojba/noPac","1","1","N/A","N/A","N/A","1","36","5","2021-12-19T17:42:12Z","2021-12-13T18:51:31Z","10476" +"*/rid_hijack.*",".{0,1000}\/rid_hijack\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10477" +"*/rid_hijack.py*",".{0,1000}\/rid_hijack\.py.{0,1000}","offensive_tool_keyword","RID-Hijacking","Windows RID Hijacking persistence technique","T1174","TA0003","N/A","N/A","Persistence","https://github.com/r4wd3r/RID-Hijacking","1","1","N/A","N/A","9","2","174","43","2024-11-20T01:43:01Z","2018-07-14T18:48:51Z","10478" +"*/RID-Hijacking.git*",".{0,1000}\/RID\-Hijacking\.git.{0,1000}","offensive_tool_keyword","RID-Hijacking","Windows RID Hijacking persistence technique","T1174","TA0003","N/A","N/A","Persistence","https://github.com/r4wd3r/RID-Hijacking","1","1","N/A","N/A","9","2","174","43","2024-11-20T01:43:01Z","2018-07-14T18:48:51Z","10480" +"*/Ridter/noPac*",".{0,1000}\/Ridter\/noPac.{0,1000}","offensive_tool_keyword","noPac","POC exploitation for CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user","T1548 - T1134 - T1078 - T1078.002","TA0003 - TA0008 - TA0002","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/Ridter/noPac","1","1","N/A","N/A","10","9","862","127","2023-01-29T03:31:27Z","2021-12-13T10:28:12Z","10481" +"*/RITM.git*",".{0,1000}\/RITM\.git.{0,1000}","offensive_tool_keyword","RITM","python Man in the middle ","T1557.002 - T1040 - T1098.002 - T1557.001 - T1552.001","TA0006 - TA0007 - TA0009 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/Tw1sm/RITM","1","1","N/A","N/A","9","3","292","27","2024-11-20T14:27:24Z","2022-10-05T01:10:33Z","10482" +"*/rlogin-brute.nse*",".{0,1000}\/rlogin\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10483" +"*/rm_injection.exe*",".{0,1000}\/rm_injection\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","10484" +"*/rmi-dumpregistry.nse*",".{0,1000}\/rmi\-dumpregistry\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10485" +"*/rmi-vuln-classloader.nse*",".{0,1000}\/rmi\-vuln\-classloader\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10486" +"*/ROADToken.exe*",".{0,1000}\/ROADToken\.exe.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","1","N/A","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","10489" +"*/ROADtoken.git*",".{0,1000}\/ROADtoken\.git.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","1","N/A","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","10490" +"*/ROADtools/*",".{0,1000}\/ROADtools\/.{0,1000}","offensive_tool_keyword","ROADtools","A collection of Azure AD tools for offensive and defensive security purposes","T1136.003 - T1078.004 - T1021.006 - T1003.003","TA0002 - TA0004 - TA0005 - TA0006","N/A","APT29 - COZY BEAR - Black Basta","Exploitation tool","https://github.com/dirkjanm/ROADtools","1","1","N/A","network exploitation tool","10","10","2126","295","2025-04-17T18:55:20Z","2020-03-28T09:56:08Z","10491" +"*/rockyou.txt*",".{0,1000}\/rockyou\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","10494" +"*/rockyou.txt*",".{0,1000}\/rockyou\.txt.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10495" +"*/RoguePotato.git*",".{0,1000}\/RoguePotato\.git.{0,1000}","offensive_tool_keyword","RoguePotato","Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RoguePotato","1","1","N/A","N/A","10","10","1081","131","2021-01-09T20:43:07Z","2020-05-10T17:38:28Z","10496" +"*/RogueWinRM.git*",".{0,1000}\/RogueWinRM\.git.{0,1000}","offensive_tool_keyword","RogueWinRM","RogueWinRM is a local privilege escalation exploit that allows to escalate from a Service account (with SeImpersonatePrivilege) to Local System account if WinRM service is not running","T1548.003 - T1134.002 - T1055","TA0004","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RogueWinRM","1","1","N/A","N/A","10","8","788","107","2020-02-23T19:26:41Z","2019-12-02T22:58:03Z","10497" +"*/RogueWinRMdll*",".{0,1000}\/RogueWinRMdll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10498" +"*/RogueWinRMexe*",".{0,1000}\/RogueWinRMexe.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10499" +"*/root/viper/*",".{0,1000}\/root\/viper\/.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","10511" +"*/rootkit.dll*",".{0,1000}\/rootkit\.dll.{0,1000}","offensive_tool_keyword","Discord-RAT-2.0","Discord Remote Administration Tool fully written in c#, stub size of ~75kb with over 40 post exploitations modules","T1059.005 - T1105 - T1569.002 - T1027.001","TA0011 - TA0003 - TA0006 - TA0009 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/moom825/Discord-RAT-2.0","1","1","N/A","N/A","10","10","512","115","2023-11-03T01:15:38Z","2022-07-15T20:09:56Z","10513" +"*/rootkiter/Binary-files*",".{0,1000}\/rootkiter\/Binary\-files.{0,1000}","offensive_tool_keyword","Termite","Termite rootit abused by threat actors","T1014 - T1069 - T1055","TA0005 - TA0003 - TA0004","Operation TunnelSnake","Whitefly","Persistence","https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4","1","1","N/A","N/A","10","10","156","177","2021-01-26T23:16:49Z","2019-01-03T05:01:20Z","10514" +"*/rop_emporium*",".{0,1000}\/rop_emporium.{0,1000}","offensive_tool_keyword","Exrop","Exrop is automatic ROP chains generator tool which can build gadget chain automatically from given binary and constraints","T1554","TA0003","N/A","N/A","Exploitation tool","https://github.com/d4em0n/exrop","1","1","N/A","N/A","N/A","3","285","22","2020-02-21T08:01:06Z","2020-01-19T05:09:00Z","10515" +"*/ropbuffers.go*",".{0,1000}\/ropbuffers\.go.{0,1000}","offensive_tool_keyword","ruler","A tool to abuse Exchange services","T1087 - T1110 - T1133 - T1064 - T1204","TA0007 - TA0006 - TA0003 - TA0002 - TA0005","N/A","APT33","Persistence","https://github.com/sensepost/ruler","1","1","N/A","N/A","10","10","2222","362","2024-06-10T11:03:07Z","2016-08-18T15:05:13Z","10516" +"*/ropfuscator*",".{0,1000}\/ropfuscator.{0,1000}","offensive_tool_keyword","ropfuscator","ROPfuscator is a fine-grained code obfuscation framework for C/C++ programs using ROP (return-oriented programming).","T1090 - T1027 - T1055 - T1099 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/ropfuscator/ropfuscator","1","1","N/A","N/A","N/A","5","426","32","2024-05-08T20:06:11Z","2021-11-16T18:13:57Z","10517" +"*/rotateproxy.exe*",".{0,1000}\/rotateproxy\.exe.{0,1000}","offensive_tool_keyword","rotateproxy","A tool that uses fofa to search for socks5 open proxies and perform proxy pool rotation","T1071.001 - T1090 - T1095 - T1189","TA0011 - TA0010 - TA0005","N/A","N/A","Defense Evasion","https://github.com/akkuman/rotateproxy","1","1","N/A","N/A","10","9","800","135","2024-01-24T05:47:37Z","2021-10-18T02:10:27Z","10518" +"*/rotateproxy.git*",".{0,1000}\/rotateproxy\.git.{0,1000}","offensive_tool_keyword","rotateproxy","A tool that uses fofa to search for socks5 open proxies and perform proxy pool rotation","T1071.001 - T1090 - T1095 - T1189","TA0011 - TA0010 - TA0005","N/A","N/A","Defense Evasion","https://github.com/akkuman/rotateproxy","1","1","N/A","N/A","10","9","800","135","2024-01-24T05:47:37Z","2021-10-18T02:10:27Z","10519" +"*/rotateproxy.service*",".{0,1000}\/rotateproxy\.service.{0,1000}","offensive_tool_keyword","rotateproxy","A tool that uses fofa to search for socks5 open proxies and perform proxy pool rotation","T1071.001 - T1090 - T1095 - T1189","TA0011 - TA0010 - TA0005","N/A","N/A","Defense Evasion","https://github.com/akkuman/rotateproxy","1","1","N/A","N/A","10","9","800","135","2024-01-24T05:47:37Z","2021-10-18T02:10:27Z","10520" +"*/rotateproxy/releases/*",".{0,1000}\/rotateproxy\/releases\/.{0,1000}","offensive_tool_keyword","rotateproxy","A tool that uses fofa to search for socks5 open proxies and perform proxy pool rotation","T1071.001 - T1090 - T1095 - T1189","TA0011 - TA0010 - TA0005","N/A","N/A","Defense Evasion","https://github.com/akkuman/rotateproxy","1","1","N/A","N/A","10","9","800","135","2024-01-24T05:47:37Z","2021-10-18T02:10:27Z","10521" +"*/rotateproxy_*.zip*",".{0,1000}\/rotateproxy_.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","rotateproxy","A tool that uses fofa to search for socks5 open proxies and perform proxy pool rotation","T1071.001 - T1090 - T1095 - T1189","TA0011 - TA0010 - TA0005","N/A","N/A","Defense Evasion","https://github.com/akkuman/rotateproxy","1","1","N/A","N/A","10","9","800","135","2024-01-24T05:47:37Z","2021-10-18T02:10:27Z","10522" +"*/rotateproxy-darwin-*",".{0,1000}\/rotateproxy\-darwin\-.{0,1000}","offensive_tool_keyword","rotateproxy","A tool that uses fofa to search for socks5 open proxies and perform proxy pool rotation","T1071.001 - T1090 - T1095 - T1189","TA0011 - TA0010 - TA0005","N/A","N/A","Defense Evasion","https://github.com/akkuman/rotateproxy","1","1","#linux","N/A","10","9","800","135","2024-01-24T05:47:37Z","2021-10-18T02:10:27Z","10523" +"*/rotateproxy-linux*",".{0,1000}\/rotateproxy\-linux.{0,1000}","offensive_tool_keyword","rotateproxy","A tool that uses fofa to search for socks5 open proxies and perform proxy pool rotation","T1071.001 - T1090 - T1095 - T1189","TA0011 - TA0010 - TA0005","N/A","N/A","Defense Evasion","https://github.com/akkuman/rotateproxy","1","1","#linux","N/A","10","9","800","135","2024-01-24T05:47:37Z","2021-10-18T02:10:27Z","10524" +"*/rotateproxy-windows*",".{0,1000}\/rotateproxy\-windows.{0,1000}","offensive_tool_keyword","rotateproxy","A tool that uses fofa to search for socks5 open proxies and perform proxy pool rotation","T1071.001 - T1090 - T1095 - T1189","TA0011 - TA0010 - TA0005","N/A","N/A","Defense Evasion","https://github.com/akkuman/rotateproxy","1","1","N/A","N/A","10","9","800","135","2024-01-24T05:47:37Z","2021-10-18T02:10:27Z","10525" +"*/RottenPotatoNG.git*",".{0,1000}\/RottenPotatoNG\.git.{0,1000}","offensive_tool_keyword","RottenPotatoNG","perform the RottenPotato attack and get a handle to a privileged token","T1134.001 - T1055.012 - T1547.001","TA0004","N/A","Sandworm","Privilege Escalation","https://github.com/breenmachine/RottenPotatoNG","1","1","N/A","N/A","8","10","935","183","2017-12-29T14:38:47Z","2017-12-29T13:19:03Z","10527" +"*/Rottie3.exe*",".{0,1000}\/Rottie3\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","10528" +"*/Routerscan.7z*",".{0,1000}\/Routerscan\.7z.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","1","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","10529" +"*/RouterScan.exe*",".{0,1000}\/RouterScan\.exe.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","1","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","10530" +"*/router-scan.git*",".{0,1000}\/router\-scan\.git.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","1","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","10531" +"*/rpc/rpcproxy.dll?*",".{0,1000}\/rpc\/rpcproxy\.dll\?.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","10533" +"*/rpcap-brute.nse*",".{0,1000}\/rpcap\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10534" +"*/rpcap-info.nse*",".{0,1000}\/rpcap\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10535" +"*/RPC-Backdoor.git*",".{0,1000}\/RPC\-Backdoor\.git.{0,1000}","offensive_tool_keyword","RPC-Backdoor","A basic emulation of an ""RPC Backdoor""","T1071.004","TA0011","N/A","N/A","C2","https://github.com/eladshamir/RPC-Backdoor","1","1","N/A","N/A","10","10","240","45","2022-08-25T14:37:41Z","2022-08-16T13:12:05Z","10536" +"*/RPC-Backdoor_v1.0.7z*",".{0,1000}\/RPC\-Backdoor_v1\.0\.7z.{0,1000}","offensive_tool_keyword","RPC-Backdoor","A basic emulation of an ""RPC Backdoor""","T1071.004","TA0011","N/A","N/A","C2","https://github.com/eladshamir/RPC-Backdoor","1","1","N/A","N/A","10","10","240","45","2022-08-25T14:37:41Z","2022-08-16T13:12:05Z","10537" +"*/RPC-Backdoor_v1.0.zip*",".{0,1000}\/RPC\-Backdoor_v1\.0\.zip.{0,1000}","offensive_tool_keyword","RPC-Backdoor","A basic emulation of an ""RPC Backdoor""","T1071.004","TA0011","N/A","N/A","C2","https://github.com/eladshamir/RPC-Backdoor","1","1","N/A","N/A","10","10","240","45","2022-08-25T14:37:41Z","2022-08-16T13:12:05Z","10538" +"*/rpcbomb.rb*",".{0,1000}\/rpcbomb\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10539" +"*/rpcdump.py*",".{0,1000}\/rpcdump\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","10542" +"*/rpcdump.py*",".{0,1000}\/rpcdump\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","10543" +"*/rpcdump.py*",".{0,1000}\/rpcdump\.py.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","1","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","10544" +"*/rpc-grind.nse*",".{0,1000}\/rpc\-grind\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10546" +"*/rpcinfo.nse*",".{0,1000}\/rpcinfo\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10547" +"*/rpcmap.py*",".{0,1000}\/rpcmap\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","10548" +"*/rpivot.git*",".{0,1000}\/rpivot\.git.{0,1000}","offensive_tool_keyword","rpivot","socks4 reverse proxy for penetration testing","T1090.004 - T1572 - T1021.001","TA0011 - TA0002 - TA0040","N/A","N/A","C2","https://github.com/klsecservices/rpivot","1","1","N/A","N/A","10","10","589","128","2018-07-12T09:53:13Z","2016-09-07T17:25:57Z","10552" +"*/rsa-vuln-roca.nse*",".{0,1000}\/rsa\-vuln\-roca\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10553" +"*/rservices_from_users.txt*",".{0,1000}\/rservices_from_users\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10555" +"*/rsockstun.git*",".{0,1000}\/rsockstun\.git.{0,1000}","offensive_tool_keyword","rsockstun","reverse socks tunneler with ntlm and proxy support","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","COZY BEAR","C2","https://github.com/llkat/rsockstun","1","1","N/A","N/A","10","10","53","22","2022-08-09T09:25:50Z","2018-10-17T09:51:11Z","10563" +"*/rsocx-*-linux-x86-64.zip*",".{0,1000}\/rsocx\-.{0,1000}\-linux\-x86\-64\.zip.{0,1000}","offensive_tool_keyword","rsocx","A bind/reverse Socks5 proxy server.","T1090.001 - T1090.002 - T1071.001","TA0011 - TA0009 - TA0040","N/A","Dispossessor - Scattered Spider*","C2","https://github.com/b23r0/rsocx","1","1","#linux","N/A","10","10","381","139","2022-09-28T08:11:34Z","2015-05-13T04:02:55Z","10564" +"*/rsocx-*-windows-x86-64.zip*",".{0,1000}\/rsocx\-.{0,1000}\-windows\-x86\-64\.zip.{0,1000}","offensive_tool_keyword","rsocx","A bind/reverse Socks5 proxy server.","T1090.001 - T1090.002 - T1071.001","TA0011 - TA0009 - TA0040","N/A","Dispossessor - Scattered Spider*","C2","https://github.com/b23r0/rsocx","1","1","N/A","N/A","10","10","381","139","2022-09-28T08:11:34Z","2015-05-13T04:02:55Z","10565" +"*/rsocx.exe*",".{0,1000}\/rsocx\.exe.{0,1000}","offensive_tool_keyword","rsocx","A bind/reverse Socks5 proxy server.","T1090.001 - T1090.002 - T1071.001","TA0011 - TA0009 - TA0040","N/A","Dispossessor - Scattered Spider*","C2","https://github.com/b23r0/rsocx","1","1","N/A","N/A","10","10","381","139","2022-09-28T08:11:34Z","2015-05-13T04:02:55Z","10566" +"*/rsocx.git",".{0,1000}\/rsocx\.git","offensive_tool_keyword","rsocx","A bind/reverse Socks5 proxy server.","T1090.001 - T1090.002 - T1071.001","TA0011 - TA0009 - TA0040","N/A","Dispossessor - Scattered Spider*","C2","https://github.com/b23r0/rsocx","1","1","N/A","N/A","10","10","381","139","2022-09-28T08:11:34Z","2015-05-13T04:02:55Z","10567" +"*/rsocx/releases/download/*",".{0,1000}\/rsocx\/releases\/download\/.{0,1000}","offensive_tool_keyword","rsocx","A bind/reverse Socks5 proxy server.","T1090.001 - T1090.002 - T1071.001","TA0011 - TA0009 - TA0040","N/A","Dispossessor - Scattered Spider*","C2","https://github.com/b23r0/rsocx","1","1","N/A","N/A","10","10","381","139","2022-09-28T08:11:34Z","2015-05-13T04:02:55Z","10568" +"*/rs-shell.exe*",".{0,1000}\/rs\-shell\.exe.{0,1000}","offensive_tool_keyword","rs-shell","rust reverse shell","T1071.004 - T1071.001 - T1573.002 - T1219 - T1059.001 - T1090.003","TA0011 - TA0005 - TA0002 - TA0007","N/A","N/A","C2","https://github.com/BlWasp/rs-shell","1","1","N/A","N/A","10","10","182","20","2024-09-03T21:48:21Z","2023-06-22T14:10:21Z","10569" +"*/rs-shell.git*",".{0,1000}\/rs\-shell\.git.{0,1000}","offensive_tool_keyword","rs-shell","rust reverse shell","T1071.004 - T1071.001 - T1573.002 - T1219 - T1059.001 - T1090.003","TA0011 - TA0005 - TA0002 - TA0007","N/A","N/A","C2","https://github.com/BlWasp/rs-shell","1","1","N/A","N/A","10","10","182","20","2024-09-03T21:48:21Z","2023-06-22T14:10:21Z","10570" +"*/rs-shell/zipball/*",".{0,1000}\/rs\-shell\/zipball\/.{0,1000}","offensive_tool_keyword","rs-shell","rust reverse shell","T1071.004 - T1071.001 - T1573.002 - T1219 - T1059.001 - T1090.003","TA0011 - TA0005 - TA0002 - TA0007","N/A","N/A","C2","https://github.com/BlWasp/rs-shell","1","1","N/A","N/A","10","10","182","20","2024-09-03T21:48:21Z","2023-06-22T14:10:21Z","10571" +"*/rs-shell-windows.exe*",".{0,1000}\/rs\-shell\-windows\.exe.{0,1000}","offensive_tool_keyword","rs-shell","rust reverse shell","T1071.004 - T1071.001 - T1573.002 - T1219 - T1059.001 - T1090.003","TA0011 - TA0005 - TA0002 - TA0007","N/A","N/A","C2","https://github.com/BlWasp/rs-shell","1","1","N/A","N/A","10","10","182","20","2024-09-03T21:48:21Z","2023-06-22T14:10:21Z","10573" +"*/rsync-brute.nse*",".{0,1000}\/rsync\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10574" +"*/rsync-list-files.py*",".{0,1000}\/rsync\-list\-files\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","10575" +"*/rsync-list-modules.nse*",".{0,1000}\/rsync\-list\-modules\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10576" +"*/rt_hijacking.exe*",".{0,1000}\/rt_hijacking\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","10577" +"*/rtsp-methods.nse*",".{0,1000}\/rtsp\-methods\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10578" +"*/rtsp-url-brute.nse*",".{0,1000}\/rtsp\-url\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10579" +"*/Rubeus*",".{0,1000}\/Rubeus.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","10590" +"*/Rubeus.dll*",".{0,1000}\/Rubeus\.dll.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","1","N/A","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","10591" +"*/Rubeus.exe*",".{0,1000}\/Rubeus\.exe.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","10593" +"*/Rubeus.exe*",".{0,1000}\/Rubeus\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10594" +"*/Rubeus.exe*",".{0,1000}\/Rubeus\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","Rubeus","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","10595" +"*/Rubeus.exe*",".{0,1000}\/Rubeus\.exe.{0,1000}","offensive_tool_keyword","Rubeus","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","Rubeus","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","10596" +"*/Rubeus.exe*",".{0,1000}\/Rubeus\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10597" +"*/Rubeus.git*",".{0,1000}\/Rubeus\.git.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","10598" +"*/Rubeus.ps1*",".{0,1000}\/Rubeus\.ps1.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","1","N/A","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","10599" +"*/Rubeus/*",".{0,1000}\/Rubeus\/.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","10600" +"*/Rubeus-Rundll32.git*",".{0,1000}\/Rubeus\-Rundll32\.git.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","1","N/A","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","10601" +"*/Rubeus-Rundll32/*",".{0,1000}\/Rubeus\-Rundll32\/.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","1","N/A","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","10602" +"*/Rudrastra.git*",".{0,1000}\/Rudrastra\.git.{0,1000}","offensive_tool_keyword","Rudrastra","Make a Fake wireless access point aka Evil Twin","T1491 - T1090.004 - T1557.001","TA0040 - TA0011 - TA0002","N/A","N/A","Sniffing & Spoofing","https://github.com/SxNade/Rudrastra","1","1","N/A","N/A","8","1","67","21","2023-04-22T15:10:42Z","2020-11-05T09:38:15Z","10603" +"*/rulerforms.go*",".{0,1000}\/rulerforms\.go.{0,1000}","offensive_tool_keyword","ruler","A tool to abuse Exchange services","T1087 - T1110 - T1133 - T1064 - T1204","TA0007 - TA0006 - TA0003 - TA0002 - TA0005","N/A","APT33","Persistence","https://github.com/sensepost/ruler","1","1","N/A","N/A","10","10","2222","362","2024-06-10T11:03:07Z","2016-08-18T15:05:13Z","10608" +"*/run/leet.pl*",".{0,1000}\/run\/leet\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","10610" +"*/run_as_psh.*",".{0,1000}\/run_as_psh\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10613" +"*/RunasCs.exe*",".{0,1000}\/RunasCs\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","RunasCs","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","10615" +"*/RunasCs.exe*",".{0,1000}\/RunasCs\.exe.{0,1000}","offensive_tool_keyword","RunasCs","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","RunasCs","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","10616" +"*/RunasCs.git*",".{0,1000}\/RunasCs\.git.{0,1000}","offensive_tool_keyword","RunasCs","RunasCs - Csharp and open version of windows builtin runas.exe","T1059.003 - T1059.001 - T1035","TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/RunasCs","1","1","N/A","N/A","7","10","1159","141","2024-07-12T23:31:35Z","2019-08-08T20:18:18Z","10617" +"*/RunasCs.zip*",".{0,1000}\/RunasCs\.zip.{0,1000}","offensive_tool_keyword","RunasCs","RunasCs is an utility to run specific processes with different permissions than the user's current logon provides using explicit credential","T1055 - T1134.001","TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/RunasCs","1","1","N/A","N/A","7","10","1159","141","2024-07-12T23:31:35Z","2019-08-08T20:18:18Z","10618" +"*/RunasCs.zip*",".{0,1000}\/RunasCs\.zip.{0,1000}","offensive_tool_keyword","RunasCs","RunasCs - Csharp and open version of windows builtin runas.exe","T1059.003 - T1059.001 - T1035","TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/RunasCs","1","1","N/A","N/A","7","10","1159","141","2024-07-12T23:31:35Z","2019-08-08T20:18:18Z","10619" +"*/RunasCs/releases/download/*",".{0,1000}\/RunasCs\/releases\/download\/.{0,1000}","offensive_tool_keyword","RunasCs","RunasCs - Csharp and open version of windows builtin runas.exe","T1059.003 - T1059.001 - T1035","TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/RunasCs","1","1","N/A","N/A","7","10","1159","141","2024-07-12T23:31:35Z","2019-08-08T20:18:18Z","10620" +"*/RunasCs_binaries.zip*",".{0,1000}\/RunasCs_binaries\.zip.{0,1000}","offensive_tool_keyword","RunasCs","RunasCs - Csharp and open version of windows builtin runas.exe","T1059.003 - T1059.001 - T1035","TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/RunasCs","1","1","N/A","N/A","7","10","1159","141","2024-07-12T23:31:35Z","2019-08-08T20:18:18Z","10621" +"*/RunasCs_x86.zip*",".{0,1000}\/RunasCs_x86\.zip.{0,1000}","offensive_tool_keyword","RunasCs","RunasCs - Csharp and open version of windows builtin runas.exe","T1059.003 - T1059.001 - T1035","TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/RunasCs","1","1","N/A","N/A","7","10","1159","141","2024-07-12T23:31:35Z","2019-08-08T20:18:18Z","10622" +"*/runasppl.py*",".{0,1000}\/runasppl\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","10623" +"*/RunAsWinTcb.git*",".{0,1000}\/RunAsWinTcb\.git.{0,1000}","offensive_tool_keyword","RunAsWinTcb","RunAsWinTcb uses an userland exploit to run a DLL with a protection level of WinTcb-Light.","T1073.002 - T1055.001 - T1055.002","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/tastypepperoni/RunAsWinTcb","1","1","N/A","N/A","10","2","132","17","2022-08-02T16:35:50Z","2022-07-29T16:36:06Z","10624" +"*/RunAsWinTcb.iml*",".{0,1000}\/RunAsWinTcb\.iml.{0,1000}","offensive_tool_keyword","RunAsWinTcb","RunAsWinTcb uses an userland exploit to run a DLL with a protection level of WinTcb-Light.","T1073.002 - T1055.001 - T1055.002","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/tastypepperoni/RunAsWinTcb","1","1","N/A","N/A","10","2","132","17","2022-08-02T16:35:50Z","2022-07-29T16:36:06Z","10625" +"*/runcalc.dll*",".{0,1000}\/runcalc\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10626" +"*/runcmd.lua*",".{0,1000}\/runcmd\.lua.{0,1000}","offensive_tool_keyword","OffensiveLua","Offensive Lua is a collection of offensive security scripts written in Lua with FFI","T1059 - T1218.011 - T1105 - T1021.002 - T1564.001 - T1112 - T1113 - T1204.002 - T1547.002","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hackerhouse-opensource/OffensiveLua","1","1","N/A","N/A","8","2","184","25","2023-11-17T00:35:10Z","2023-10-25T17:21:13Z","10627" +"*/runcmd2.lua*",".{0,1000}\/runcmd2\.lua.{0,1000}","offensive_tool_keyword","OffensiveLua","Offensive Lua is a collection of offensive security scripts written in Lua with FFI","T1059 - T1218.011 - T1105 - T1021.002 - T1564.001 - T1112 - T1113 - T1204.002 - T1547.002","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hackerhouse-opensource/OffensiveLua","1","1","N/A","N/A","8","2","184","25","2023-11-17T00:35:10Z","2023-10-25T17:21:13Z","10628" +"*/rundll32.cmd*",".{0,1000}\/rundll32\.cmd.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","10629" +"*/rundll32_js*",".{0,1000}\/rundll32_js.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","10630" +"*/RunOF/RunOF/*",".{0,1000}\/RunOF\/RunOF\/.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool to run object files mainly beacon object files (BOF) in .Net.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nettitude/RunOF","1","1","N/A","N/A","10","10","145","21","2023-01-06T15:30:05Z","2022-02-21T13:53:39Z","10631" +"*/RunPEinMemory.exe*",".{0,1000}\/RunPEinMemory\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","10632" +"*/RunPEinMemory64.exe*",".{0,1000}\/RunPEinMemory64\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","10633" +"*/runshellcode.*",".{0,1000}\/runshellcode\..{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","10634" +"*/runswhide.lua*",".{0,1000}\/runswhide\.lua.{0,1000}","offensive_tool_keyword","OffensiveLua","Offensive Lua is a collection of offensive security scripts written in Lua with FFI","T1059 - T1218.011 - T1105 - T1021.002 - T1564.001 - T1112 - T1113 - T1204.002 - T1547.002","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hackerhouse-opensource/OffensiveLua","1","1","N/A","N/A","8","2","184","25","2023-11-17T00:35:10Z","2023-10-25T17:21:13Z","10635" +"*/RuralBishop.git*",".{0,1000}\/RuralBishop\.git.{0,1000}","offensive_tool_keyword","RuralBishop","creates a local RW section in UrbanBishop and then maps that section as RX into a remote process","T1055 - T1055.012 - T1055.002 - T1098 - T1027 - T1027.002 - T1070.004","TA0005 - TA0003 - TA0002","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/RuralBishop","1","1","N/A","N/A","10","2","107","26","2020-07-19T18:47:44Z","2020-07-19T18:47:38Z","10636" +"*/rusers.nse*",".{0,1000}\/rusers\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10637" +"*/rustcat/releases/latest/download/*",".{0,1000}\/rustcat\/releases\/latest\/download\/.{0,1000}","offensive_tool_keyword","rustcat","Rustcat(rcat) - The modern Port listener and Reverse shell","T1090.001 - T1090.002 - T1046","TA0011 - TA0009 - TA0040","N/A","N/A","C2","https://github.com/robiot/rustcat","1","1","N/A","N/A","10","10","758","63","2024-07-20T14:20:34Z","2021-06-04T17:03:47Z","10638" +"*/Rust-for-Malware-Development.git*",".{0,1000}\/Rust\-for\-Malware\-Development\.git.{0,1000}","offensive_tool_keyword","Rust-for-Malware-Development","malware development using Rust","T1055.001 - T1027 - T1204 - T1518 - T1056 - T1021 - T1587/001","TA0005 - TA0003 - TA0007 - TA0009 - TA0004 - TA0008 - TA0042","N/A","N/A","Exploitation tool","https://github.com/Whitecat18/Rust-for-Malware-Development","1","1","N/A","N/A","8","10","2123","53","2025-04-22T18:09:57Z","2024-02-12T16:55:06Z","10642" +"*/rusthound.exe*",".{0,1000}\/rusthound\.exe.{0,1000}","offensive_tool_keyword","RustHound","Active Directory data collector for BloodHound written in Rust","T1087.002 - T1018 - T1059.003","TA0007 - TA0001 - TA0002","N/A","N/A","Discovery","https://github.com/OPENCYBER-FR/RustHound","1","1","N/A","AD Enumeration","9","10","1013","98","2024-10-21T18:58:20Z","2022-10-12T05:54:35Z","10643" +"*/RustHound.git*",".{0,1000}\/RustHound\.git.{0,1000}","offensive_tool_keyword","RustHound","Active Directory data collector for BloodHound written in Rust","T1087.002 - T1018 - T1059.003","TA0007 - TA0001 - TA0002","N/A","N/A","Discovery","https://github.com/OPENCYBER-FR/RustHound","1","1","N/A","AD Enumeration","9","10","1013","98","2024-10-21T18:58:20Z","2022-10-12T05:54:35Z","10644" +"*/RustiveDump.exe*",".{0,1000}\/RustiveDump\.exe.{0,1000}","offensive_tool_keyword","RustiveDump","LSASS memory dumper using only NTAPIs","T1003.001 - T1055 - T1106","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/safedv/RustiveDump","1","1","N/A","N/A","10","4","332","43","2025-03-08T12:10:35Z","2024-10-06T16:01:49Z","10645" +"*/RustiveDump.git*",".{0,1000}\/RustiveDump\.git.{0,1000}","offensive_tool_keyword","RustiveDump","LSASS memory dumper using only NTAPIs","T1003.001 - T1055 - T1106","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/safedv/RustiveDump","1","1","N/A","N/A","10","4","332","43","2025-03-08T12:10:35Z","2024-10-06T16:01:49Z","10646" +"*/RustPotato.git*",".{0,1000}\/RustPotato\.git.{0,1000}","offensive_tool_keyword","RustPotato","A Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privileges","T1134.001 - T1055.011","TA0004","N/A","N/A","Privilege Escalation","https://github.com/emdnaia/RustPotato","1","1","N/A","N/A","10","1","0","0","2025-01-06T18:10:17Z","2025-01-06T19:44:57Z","10647" +"*/RustRedOps.git*",".{0,1000}\/RustRedOps\.git.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","10648" +"*/rvrsh3ll/*",".{0,1000}\/rvrsh3ll\/.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","10652" +"*/RWXfinder.git*",".{0,1000}\/RWXfinder\.git.{0,1000}","offensive_tool_keyword","rwxfinder","The program uses the Windows API functions to traverse through directories and locate DLL files with RWX section","T1059.001 - T1059.003 - T1070.004","TA0002 - TA0005 - TA0040","N/A","N/A","Discovery","https://github.com/pwnsauc3/RWXFinder","1","1","N/A","N/A","5","2","101","14","2023-07-15T15:42:55Z","2023-07-14T07:47:21Z","10653" +"*/s3aclenum.py*",".{0,1000}\/s3aclenum\.py.{0,1000}","offensive_tool_keyword","quiet-riot","Unauthenticated enumeration of AWS - Azure and GCP Principals","T1087 - T1083 - T1210","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/righteousgambit/quiet-riot","1","1","N/A","N/A","6","3","224","30","2024-11-13T19:41:26Z","2021-10-28T15:12:27Z","10654" +"*/S3cur3Th1sSh1t/*",".{0,1000}\/S3cur3Th1sSh1t\/.{0,1000}","offensive_tool_keyword","cobaltstrike","C# binary with embeded golang hack-browser-data","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/S3cur3Th1sSh1t/Sharp-HackBrowserData","1","1","N/A","N/A","10","10","96","17","2021-12-09T18:58:27Z","2020-12-06T12:28:47Z","10655" +"*/s3enum.py*",".{0,1000}\/s3enum\.py.{0,1000}","offensive_tool_keyword","quiet-riot","Unauthenticated enumeration of AWS - Azure and GCP Principals","T1087 - T1083 - T1210","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/righteousgambit/quiet-riot","1","1","N/A","N/A","6","3","224","30","2024-11-13T19:41:26Z","2021-10-28T15:12:27Z","10656" +"*/S3Scanner.git*",".{0,1000}\/S3Scanner\.git.{0,1000}","offensive_tool_keyword","S3Scanner","Scan for open S3 buckets and dump the contents","T1583 - T1583.002 - T1114 - T1114.002","TA0010","N/A","N/A","Reconnaissance","https://github.com/sa7mon/S3Scanner","1","1","N/A","N/A","8","10","2743","384","2025-04-21T14:44:23Z","2017-06-19T22:14:21Z","10657" +"*/S4UTomato.git*",".{0,1000}\/S4UTomato\.git.{0,1000}","offensive_tool_keyword","S4UTomato","Escalate Service Account To LocalSystem via Kerberos","T1558 - T1558.002 - T1548.002 - T1078 - T1078.004","TA0006 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/wh0amitz/S4UTomato","1","1","N/A","N/A","10","4","394","76","2023-09-14T08:53:19Z","2023-07-30T11:51:57Z","10659" +"*/s72 Shell v1.1 Coding.php*",".{0,1000}\/s72\sShell\sv1\.1\sCoding\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","10660" +"*/s7-info.nse*",".{0,1000}\/s7\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10661" +"*/saefko.profile*",".{0,1000}\/saefko\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","10662" +"*/Safer_PoC_CVE*",".{0,1000}\/Safer_PoC_CVE.{0,1000}","offensive_tool_keyword","POC","A Safer PoC for CVE-2022-22965 (Spring4Shell)","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/colincowie/Safer_PoC_CVE-2022-22965","1","1","N/A","N/A","N/A","1","44","7","2022-05-27T12:56:40Z","2022-03-31T16:58:56Z","10663" +"*/SafetyDump.exe*",".{0,1000}\/SafetyDump\.exe.{0,1000}","offensive_tool_keyword","SafetyDump","in memory process dumper - uses the Minidump Windows API to dump process memory before base64 encoding that dump and writing it to standard output","T1003.005 - T1059.001 - T1105 - T1071.001","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/riskydissonance/SafetyDump","1","1","N/A","N/A","10","2","162","16","2020-10-29T16:25:04Z","2019-12-10T14:45:17Z","10664" +"*/SafetyDump.git*",".{0,1000}\/SafetyDump\.git.{0,1000}","offensive_tool_keyword","SafetyDump","in memory process dumper - uses the Minidump Windows API to dump process memory before base64 encoding that dump and writing it to standard output","T1003.005 - T1059.001 - T1105 - T1071.001","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/riskydissonance/SafetyDump","1","1","N/A","N/A","10","2","162","16","2020-10-29T16:25:04Z","2019-12-10T14:45:17Z","10665" +"*/SafetyKatz.dll*",".{0,1000}\/SafetyKatz\.dll.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","10666" +"*/SafetyKatz.dll*",".{0,1000}\/SafetyKatz\.dll.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","10667" +"*/SafetyKatz.exe*",".{0,1000}\/SafetyKatz\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10668" +"*/SafetyKatz.exe*",".{0,1000}\/SafetyKatz\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10669" +"*/SafetyKatz.exe*",".{0,1000}\/SafetyKatz\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10670" +"*/SafetyKatz.git*",".{0,1000}\/SafetyKatz\.git.{0,1000}","offensive_tool_keyword","SafetyKatz","SafetyKatz is a combination of slightly modified version of @gentilkiwis Mimikatz project and @subtees .NET PE Loader. First. the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to C:\Windows\Temp\debug.bin. Then @subtees PELoader is used to load a customized version of Mimikatz that runs sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file. removing the file after execution is complete","T1003 - T1055 - T1059 - T1574","TA0002 - TA0003 - TA0008","N/A","APT39","Credential Access","https://github.com/GhostPack/SafetyKatz","1","1","N/A","N/A","10","10","1257","247","2019-10-01T16:47:21Z","2018-07-24T17:44:15Z","10671" +"*/sAINT.git*",".{0,1000}\/sAINT\.git.{0,1000}","offensive_tool_keyword","saint","(s)AINT is a Spyware Generator for Windows systems written in Java","T1056.001 - T1125 - T1123 - T1113 - T1105 - T1573.001","TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","C2","https://github.com/tiagorlampert/sAINT","1","1","N/A","N/A","10","10","712","311","2020-04-03T14:34:34Z","2017-11-18T18:43:25Z","10672" +"*/sAINT-master.zip*",".{0,1000}\/sAINT\-master\.zip.{0,1000}","offensive_tool_keyword","saint","(s)AINT is a Spyware Generator for Windows systems written in Java","T1056.001 - T1125 - T1123 - T1113 - T1105 - T1573.001","TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","C2","https://github.com/tiagorlampert/sAINT","1","1","N/A","N/A","10","10","712","311","2020-04-03T14:34:34Z","2017-11-18T18:43:25Z","10673" +"*/Sako RAT.exe*",".{0,1000}\/Sako\sRAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","10674" +"*/sam_dump_*.txt*",".{0,1000}\/sam_dump_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","10675" +"*/sambaPipe.py*",".{0,1000}\/sambaPipe\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","10676" +"*/samba-vuln-cve-2012-1182.nse*",".{0,1000}\/samba\-vuln\-cve\-2012\-1182\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10677" +"*/samdump.go*",".{0,1000}\/samdump\.go.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","10678" +"*/samrdump.exe*",".{0,1000}\/samrdump\.exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","10681" +"*/samrdump.py*",".{0,1000}\/samrdump\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","10682" +"*/samruser.py*",".{0,1000}\/samruser\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","10683" +"*/sandcat.git*",".{0,1000}\/sandcat\.git.{0,1000}","offensive_tool_keyword","sandcat","An open-source pentest oriented web browser","T1216 - T1590 - T1071","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/syhunt/sandcat","1","1","N/A","N/A","6","6","525","72","2023-12-21T18:40:27Z","2014-05-20T23:36:21Z","10685" +"*/Sandman.exe*",".{0,1000}\/Sandman\.exe.{0,1000}","offensive_tool_keyword","Sandman","Sandman is a NTP based backdoor for red team engagements in hardened networks.","T1105 - T1027 - T1071.001","TA0011 - TA0005","N/A","N/A","Persistence","https://github.com/Idov31/Sandman","1","1","N/A","N/A","10","8","785","108","2024-03-31T17:40:15Z","2022-08-21T11:04:45Z","10686" +"*/sandman_server.py*",".{0,1000}\/sandman_server\.py.{0,1000}","offensive_tool_keyword","Sandman","Sandman is a NTP based backdoor for red team engagements in hardened networks.","T1105 - T1027 - T1071.001","TA0011 - TA0005","N/A","N/A","Persistence","https://github.com/Idov31/Sandman","1","1","N/A","N/A","10","8","785","108","2024-03-31T17:40:15Z","2022-08-21T11:04:45Z","10687" +"*/SandmanBackdoorTimeProvider.dll*",".{0,1000}\/SandmanBackdoorTimeProvider\.dll.{0,1000}","offensive_tool_keyword","Sandman","Sandman is a NTP based backdoor for red team engagements in hardened networks.","T1105 - T1027 - T1071.001","TA0011 - TA0005","N/A","N/A","Persistence","https://github.com/Idov31/Sandman","1","1","N/A","N/A","10","8","785","108","2024-03-31T17:40:15Z","2022-08-21T11:04:45Z","10688" +"*/Sandman-master.zip*",".{0,1000}\/Sandman\-master\.zip.{0,1000}","offensive_tool_keyword","Sandman","Sandman is a NTP based backdoor for red team engagements in hardened networks.","T1105 - T1027 - T1071.001","TA0011 - TA0005","N/A","N/A","Persistence","https://github.com/Idov31/Sandman","1","1","N/A","N/A","10","8","785","108","2024-03-31T17:40:15Z","2022-08-21T11:04:45Z","10689" +"*/sap_default.txt*",".{0,1000}\/sap_default\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10690" +"*/SauronEye.exe*",".{0,1000}\/SauronEye\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10691" +"*/SauronEye.exe*",".{0,1000}\/SauronEye\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10692" +"*/saycheese.html*",".{0,1000}\/saycheese\.html.{0,1000}","offensive_tool_keyword","saycheese","Grab target's webcam shots by link","T1213 - T1071 - T1102 - T1123 - T1185 - T1200","TA0001 - TA0005 - TA0009 - TA0011","N/A","N/A","Phishing","https://github.com/hangetzzu/saycheese","1","1","N/A","N/A","9","10","1175","962","2024-06-18T23:39:41Z","2019-04-29T04:07:00Z","10693" +"*/saycheese.sh*",".{0,1000}\/saycheese\.sh.{0,1000}","offensive_tool_keyword","saycheese","Grab target's webcam shots by link","T1213 - T1071 - T1102 - T1123 - T1185 - T1200","TA0001 - TA0005 - TA0009 - TA0011","N/A","N/A","Phishing","https://github.com/hangetzzu/saycheese","1","1","N/A","N/A","9","10","1175","962","2024-06-18T23:39:41Z","2019-04-29T04:07:00Z","10694" +"*/sc_inject/inject/*",".{0,1000}\/sc_inject\/inject\/.{0,1000}","offensive_tool_keyword","acheron","indirect syscalls for AV/EDR evasion in Go assembly","T1055.012 - T1059.001 - T1059.003","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/f1zm0/acheron","1","1","N/A","N/A","N/A","4","326","39","2023-06-13T19:20:33Z","2023-04-07T10:40:33Z","10700" +"*/scan4all.exe*",".{0,1000}\/scan4all\.exe.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoC","T1595 - T1190 - T1068","TA0001 - TA0007 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","10701" +"*/scan4all.git*",".{0,1000}\/scan4all\.git.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoC","T1595 - T1190 - T1068","TA0001 - TA0007 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","10702" +"*/scan4all.git*",".{0,1000}\/scan4all\.git.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoCs - 23 kinds of application password crack - 7000+Web fingerprints - 146 protocols and 90000+ rules Port scanning - Fuzz - HW - awesome BugBounty","T1046 - T1210.001 - T1059 - T1082 - T1110","TA0007 - TA0001 - TA0009 - TA0002 - TA0004 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","10703" +"*/scan4all.rb*",".{0,1000}\/scan4all\.rb.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoC","T1595 - T1190 - T1068","TA0001 - TA0007 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","10704" +"*/scan4all/lib/api*",".{0,1000}\/scan4all\/lib\/api.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoCs - 23 kinds of application password crack - 7000+Web fingerprints - 146 protocols and 90000+ rules Port scanning - Fuzz - HW - awesome BugBounty","T1046 - T1210.001 - T1059 - T1082 - T1110","TA0007 - TA0001 - TA0009 - TA0002 - TA0004 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","10705" +"*/scan4all/lib/util*",".{0,1000}\/scan4all\/lib\/util.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoCs - 23 kinds of application password crack - 7000+Web fingerprints - 146 protocols and 90000+ rules Port scanning - Fuzz - HW - awesome BugBounty","T1046 - T1210.001 - T1059 - T1082 - T1110","TA0007 - TA0001 - TA0009 - TA0002 - TA0004 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","10706" +"*/ScanInterception.ps1*",".{0,1000}\/ScanInterception\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","10707" +"*/scanner/discovery*",".{0,1000}\/scanner\/discovery.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10708" +"*/scanner/kerberos*",".{0,1000}\/scanner\/kerberos.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10709" +"*/scanner/pcanywhere*",".{0,1000}\/scanner\/pcanywhere.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10710" +"*/scanner/portscan*",".{0,1000}\/scanner\/portscan.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10711" +"*/scanner/winrm*",".{0,1000}\/scanner\/winrm.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","10712" +"*/scannerPort.go*",".{0,1000}\/scannerPort\.go.{0,1000}","offensive_tool_keyword","GONET-Scanner","port scanner and arp discover in go","T1595","TA0001","N/A","N/A","Discovery","https://github.com/luijait/GONET-Scanner","1","1","N/A","network exploitation tool","N/A","1","82","21","2022-03-10T04:35:58Z","2022-02-02T19:39:09Z","10713" +"*/scan-network.py*",".{0,1000}\/scan\-network\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","10714" +"*/Scans/servers_all_smb*.txt*",".{0,1000}\/Scans\/servers_all_smb.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","10715" +"*/sccmhunter*",".{0,1000}\/sccmhunter.{0,1000}","offensive_tool_keyword","sccmhunter","SCCMHunter is a post-ex tool built to streamline identifying profiling and attacking SCCM related assets in an Active Directory domain","T1087 - T1046 - T1484","TA0003 - TA0006 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/garrettfoster13/sccmhunter","1","1","N/A","N/A","9","8","750","97","2025-04-03T15:58:02Z","2023-02-20T14:09:42Z","10717" +"*/SCCMSecrets.git*",".{0,1000}\/SCCMSecrets\.git.{0,1000}","offensive_tool_keyword","SCCMSecrets","SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting - initial access and lateral movement.","T1555 - T1078 - T1070 - T1021","TA0006 - TA0008 - TA0001","N/A","N/A","Lateral Movement","https://github.com/synacktiv/SCCMSecrets","1","1","N/A","N/A","8","3","208","22","2024-12-17T14:29:39Z","2024-08-14T09:45:44Z","10718" +"*/SCCMVNC.git*",".{0,1000}\/SCCMVNC\.git.{0,1000}","offensive_tool_keyword","SCCMVNC","A tool to modify SCCM remote control settings on the client machine - enabling remote control without permission prompts or notifications. This can be done without requiring access to SCCM server.","T1078 - T1562 - T1557","TA0005 - TA0003 - TA0008","N/A","N/A","Lateral Movement","https://github.com/netero1010/SCCMVNC","1","1","N/A","N/A","8","1","87","10","2024-10-20T14:29:43Z","2024-10-20T14:15:28Z","10719" +"*/scdc/bob.jsp?f=fuckjp.jsp*",".{0,1000}\/scdc\/bob\.jsp\?f\=fuckjp\.jsp.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","10720" +"*/ScheduleRunner.git*",".{0,1000}\/ScheduleRunner\.git.{0,1000}","offensive_tool_keyword","ScheduleRunner","A C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operation","T1210 - T1570 - T1021 - T1550","TA0008","N/A","N/A","Persistence","https://github.com/netero1010/ScheduleRunner","1","1","N/A","N/A","9","4","336","46","2025-01-22T02:06:59Z","2021-10-12T15:27:32Z","10721" +"*/SchTask.zip*",".{0,1000}\/SchTask\.zip.{0,1000}","offensive_tool_keyword","SchTask_0x727","create hidden scheduled tasks","T1053","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/0x727/SchTask_0x727","1","1","N/A","N/A","10","6","532","112","2021-09-01T01:34:51Z","2021-08-30T03:29:34Z","10722" +"*/SchTask_0x727.git*",".{0,1000}\/SchTask_0x727\.git.{0,1000}","offensive_tool_keyword","SchTask_0x727","create hidden scheduled tasks","T1053","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/0x727/SchTask_0x727","1","1","N/A","N/A","10","6","532","112","2021-09-01T01:34:51Z","2021-08-30T03:29:34Z","10723" +"*/SchTask_0x727/*",".{0,1000}\/SchTask_0x727\/.{0,1000}","offensive_tool_keyword","SchTask_0x727","create hidden scheduled tasks","T1053","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/0x727/SchTask_0x727","1","1","N/A","N/A","10","6","532","112","2021-09-01T01:34:51Z","2021-08-30T03:29:34Z","10724" +"*/schtasksenum/*.*",".{0,1000}\/schtasksenum\/.{0,1000}\..{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","10725" +"*/sc-loader.exe*",".{0,1000}\/sc\-loader\.exe.{0,1000}","offensive_tool_keyword","DKMC","Malicious payload evasion tool","T1027 - T1055.012","TA0005 - TA0040","N/A","Molerats","Defense Evasion","https://github.com/Mr-Un1k0d3r/DKMC","1","1","N/A","N/A","10","10","1392","290","2020-07-20T03:36:56Z","2016-12-05T03:44:07Z","10726" +"*/scmuacbypass.cpp*",".{0,1000}\/scmuacbypass\.cpp.{0,1000}","offensive_tool_keyword","SCMUACBypass","SCM UAC Bypass","T1548.002 - T1088","TA0004 - TA0002","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/SCMUACBypass","1","1","N/A","N/A","8","1","97","17","2023-09-05T17:24:49Z","2023-09-04T13:11:17Z","10727" +"*/SCMUACBypass.exe*",".{0,1000}\/SCMUACBypass\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SCMUACBypass","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","10728" +"*/SCMUACBypass.exe*",".{0,1000}\/SCMUACBypass\.exe.{0,1000}","offensive_tool_keyword","SCMUACBypass","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SCMUACBypass","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","10729" +"*/scmuacbypass.exe*",".{0,1000}\/scmuacbypass\.exe.{0,1000}","offensive_tool_keyword","SCMUACBypass","SCM UAC Bypass","T1548.002 - T1088","TA0004 - TA0002","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/SCMUACBypass","1","1","N/A","N/A","8","1","97","17","2023-09-05T17:24:49Z","2023-09-04T13:11:17Z","10730" +"*/SCMUACBypass.git*",".{0,1000}\/SCMUACBypass\.git.{0,1000}","offensive_tool_keyword","SCMUACBypass","SCM UAC Bypass","T1548.002 - T1088","TA0004 - TA0002","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/SCMUACBypass","1","1","N/A","N/A","8","1","97","17","2023-09-05T17:24:49Z","2023-09-04T13:11:17Z","10731" +"*/SCMUACBypass/*",".{0,1000}\/SCMUACBypass\/.{0,1000}","offensive_tool_keyword","SCMUACBypass","SCM UAC Bypass","T1548.002 - T1088","TA0004 - TA0002","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/SCMUACBypass","1","1","N/A","N/A","8","1","97","17","2023-09-05T17:24:49Z","2023-09-04T13:11:17Z","10732" +"*/SCOMDecrypt.git*",".{0,1000}\/SCOMDecrypt\.git.{0,1000}","offensive_tool_keyword","SCOMDecrypt","SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers","T1552.001 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/nccgroup/SCOMDecrypt","1","1","N/A","N/A","10","2","123","22","2023-11-10T07:04:26Z","2017-02-21T16:15:11Z","10733" +"*/ScreenshotInject*",".{0,1000}\/ScreenshotInject.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","10734" +"*/ScriptBlock-Smuggling.git*",".{0,1000}\/ScriptBlock\-Smuggling\.git.{0,1000}","offensive_tool_keyword","ScriptBlock-Smuggling","SCRIPTBLOCK SMUGGLING: SPOOFING POWERSHELL SECURITY LOGS AND BYPASSING AMSI WITHOUT REFLECTION OR PATCHING","T1059.001 - T1562.001 - T1112 - T1202 - T1070","TA0005","N/A","N/A","Defense Evasion","https://github.com/BC-SECURITY/ScriptBlock-Smuggling","1","1","N/A","https://bc-security.org/scriptblock-smuggling/","8","1","89","13","2024-06-18T08:35:50Z","2024-06-12T21:44:47Z","10736" +"*/scripts/xor.py*",".{0,1000}\/scripts\/xor\.py.{0,1000}","offensive_tool_keyword","HadesLdr","Shellcode Loader Implementing Indirect Dynamic Syscall - API Hashing - Fileless Shellcode retrieving using Winsock2","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CognisysGroup/HadesLdr","1","1","N/A","N/A","10","3","292","47","2023-07-15T21:23:49Z","2023-07-12T11:44:07Z","10737" +"*/ScriptSentry.git*",".{0,1000}\/ScriptSentry\.git.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","10738" +"*/ScriptSentry.ps1*",".{0,1000}\/ScriptSentry\.ps1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","10739" +"*/ScriptSentry.psd1*",".{0,1000}\/ScriptSentry\.psd1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","10740" +"*/ScriptSentry.psm1*",".{0,1000}\/ScriptSentry\.psm1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","10741" +"*/ScRunHex.py*",".{0,1000}\/ScRunHex\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","BypassAV ShellCode Loader (Cobaltstrike/Metasploit)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/scrun","1","1","N/A","N/A","10","10","179","76","2019-07-27T07:10:08Z","2019-07-21T15:34:41Z","10742" +"*/scshell.py*",".{0,1000}\/scshell\.py.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","10744" +"*/scuffy.py*",".{0,1000}\/scuffy\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","10745" +"*/sdb-explorer.exe*",".{0,1000}\/sdb\-explorer\.exe.{0,1000}","offensive_tool_keyword","ShimDB","Shim database persistence (Fin7 TTP)","T1546.011","TA0003","N/A","N/A","Persistence","https://github.com/jackson5sec/ShimDB","1","1","N/A","N/A","9","1","37","10","2020-02-25T09:41:53Z","2018-06-21T00:38:10Z","10746" +"*/SearchShares.ps1*",".{0,1000}\/SearchShares\.ps1.{0,1000}","offensive_tool_keyword","SearchOpenFileShares","Searches open files shares for password files or database backups - Extend as you see fit","T1083 - T1135 - T1005 - T1025","TA0007 - TA0009","N/A","Dispossessor","Discovery","https://github.com/fashionproof/SearchOpenFileShares","1","1","N/A","N/A","7","1","29","6","2019-12-13T12:37:42Z","2019-09-21T13:50:26Z","10751" +"*/searchsploit*",".{0,1000}\/searchsploit.{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","10752" +"*/Seatbelt.exe*",".{0,1000}\/Seatbelt\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10753" +"*/SeatBelt.exe*",".{0,1000}\/SeatBelt\.exe.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","10754" +"*/Seatbelt.exe*",".{0,1000}\/Seatbelt\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10755" +"*/Seatbelt.exe*",".{0,1000}\/Seatbelt\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","Seatbelt","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","10756" +"*/Seatbelt.exe*",".{0,1000}\/Seatbelt\.exe.{0,1000}","offensive_tool_keyword","seatbelt","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","Seatbelt","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","10757" +"*/Seatbelt.exe*",".{0,1000}\/Seatbelt\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10758" +"*/Seatbelt.git*",".{0,1000}\/Seatbelt\.git.{0,1000}","offensive_tool_keyword","seatbelt","Seatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many others","T1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518","TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011","N/A","Dispossessor","Persistence","https://github.com/GhostPack/Seatbelt","1","1","N/A","N/A","10","10","4047","722","2025-01-10T20:12:49Z","2018-07-24T17:38:51Z","10759" +"*/Seatbelt.txt*",".{0,1000}\/Seatbelt\.txt.{0,1000}","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","10760" +"*/Seatbelt/Commands*",".{0,1000}\/Seatbelt\/Commands.{0,1000}","offensive_tool_keyword","seatbelt","Seatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many others","T1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518","TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011","N/A","Dispossessor","Persistence","https://github.com/GhostPack/Seatbelt","1","1","N/A","N/A","10","10","4047","722","2025-01-10T20:12:49Z","2018-07-24T17:38:51Z","10761" +"*/seatbelt_json.py*",".{0,1000}\/seatbelt_json\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","10762" +"*/SeAuditPrivilegePoC.exe*",".{0,1000}\/SeAuditPrivilegePoC\.exe.{0,1000}","offensive_tool_keyword","PrivFu","PoCs for sensitive token privileges such SeDebugPrivilege","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","PrivilegedOperations","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","10763" +"*/SeBackupPrivilege.md*",".{0,1000}\/SeBackupPrivilege\.md.{0,1000}","offensive_tool_keyword","Priv2Admin","Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS.","T1543 - T1068 - T1078","TA0003 - TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/gtworek/Priv2Admin","1","1","N/A","N/A","N/A","10","2124","286","2023-02-24T13:31:23Z","2019-08-14T11:50:17Z","10764" +"*/SeBackupPrivilegePoC.exe*",".{0,1000}\/SeBackupPrivilegePoC\.exe.{0,1000}","offensive_tool_keyword","PrivFu","PoCs for sensitive token privileges such SeDebugPrivilege","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","PrivilegedOperations","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","10765" +"*/secinject.c*",".{0,1000}\/secinject\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Section Mapping Process Injection (secinject): Cobalt Strike BOF","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/apokryptein/secinject","1","1","N/A","N/A","10","10","94","23","2022-01-07T21:09:32Z","2021-09-05T01:17:47Z","10766" +"*/SecondaryLogonVariant.exe*",".{0,1000}\/SecondaryLogonVariant\.exe.{0,1000}","offensive_tool_keyword","PrivFu","get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","KernelWritePoCs","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","10767" +"*/SecretFinder.git*",".{0,1000}\/SecretFinder\.git.{0,1000}","offensive_tool_keyword","secretfinder","SecretFinder is a python script based on LinkFinder written to discover sensitive data like apikeys - accesstoken - authorizations - jwt..etc in JavaScript files","T1083 - T1081 - T1113","TA0003 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/m4ll0k/SecretFinder","1","1","N/A","N/A","N/A","10","2153","405","2024-05-26T09:36:41Z","2020-06-08T10:50:12Z","10768" +"*/secretsdump.exe*",".{0,1000}\/secretsdump\.exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","10769" +"*/secretsdump.py*",".{0,1000}\/secretsdump\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","10770" +"*/secretsdump.py*",".{0,1000}\/secretsdump\.py.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","1","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","10771" +"*/secretsdump.py*",".{0,1000}\/secretsdump\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","10772" +"*/secretsdump_*.txt*",".{0,1000}\/secretsdump_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","10773" +"*/secretsmanagerenum.py*",".{0,1000}\/secretsmanagerenum\.py.{0,1000}","offensive_tool_keyword","quiet-riot","Unauthenticated enumeration of AWS - Azure and GCP Principals","T1087 - T1083 - T1210","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/righteousgambit/quiet-riot","1","1","N/A","N/A","6","3","224","30","2024-11-13T19:41:26Z","2021-10-28T15:12:27Z","10776" +"*/SecretStealer.ps1*",".{0,1000}\/SecretStealer\.ps1.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","1","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","10777" +"*/SecScanC2.git*",".{0,1000}\/SecScanC2\.git.{0,1000}","offensive_tool_keyword","SecScanC2","SecScanC2 can manage assetment to create P2P network for security scanning & C2. The tool can assist security researchers in conducting penetration testing more efficiently - preventing scanning from being blocked - protecting themselves from being traced.","T1021 - T1090","TA0011 - TA0002 - TA0040 - TA0043","N/A","N/A","C2","https://github.com/T1esh0u/SecScanC2","1","1","#P2P","N/A","10","","N/A","","","","10778" +"*/sec-tools/litefuzz*",".{0,1000}\/sec\-tools\/litefuzz.{0,1000}","offensive_tool_keyword","litefuzz","A multi-platform fuzzer for poking at userland binaries and servers","T1587.004","TA0009","N/A","N/A","Exploitation tool","https://github.com/sec-tools/litefuzz","1","1","N/A","N/A","7","1","68","9","2024-09-15T22:43:02Z","2021-09-17T14:40:07Z","10779" +"*/SeeYouCM-Thief*",".{0,1000}\/SeeYouCM\-Thief.{0,1000}","offensive_tool_keyword","SeeYouCM-Thief","Simple tool to automatically download and parse configuration files from Cisco phone systems searching for SSH credentials","T1110.001 - T1005 - T1071.001","TA0001 - TA0011 - TA0005","N/A","N/A","Discovery","https://github.com/trustedsec/SeeYouCM-Thief","1","1","N/A","N/A","9","2","189","35","2023-05-11T01:04:36Z","2022-01-14T20:12:25Z","10780" +"*/self_delete.cna*",".{0,1000}\/self_delete\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","BOF implementation of the research by @jonasLyk and the drafted PoC from @LloydLabs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/Self_Deletion_BOF","1","1","N/A","N/A","10","10","180","22","2021-10-03T19:10:21Z","2021-10-03T19:01:14Z","10781" +"*/self_deletion.exe*",".{0,1000}\/self_deletion\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","10782" +"*/SeManageVolumeExploit.git*",".{0,1000}\/SeManageVolumeExploit\.git.{0,1000}","offensive_tool_keyword","SeManageVolumeExploit","This exploit grants full permission on C:\ drive for all users on the machine","T1046 - T1098 - T1222.002","TA0007 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/CsEnox/SeManageVolumeExploit","1","1","N/A","N/A","10","2","110","17","2023-05-29T05:41:16Z","2021-10-11T01:17:04Z","10783" +"*/SeriousSam.sln*",".{0,1000}\/SeriousSam\.sln.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/guervild/BOFs","1","1","N/A","N/A","10","10","161","27","2022-05-02T16:59:24Z","2021-03-15T23:30:22Z","10785" +"*/server/c2/*",".{0,1000}\/server\/c2\/.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","10786" +"*/server/common/stagers.py*",".{0,1000}\/server\/common\/stagers\.py.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","10787" +"*/ServerC2.cpp*",".{0,1000}\/ServerC2\.cpp.{0,1000}","offensive_tool_keyword","DocPlz","Documents Exfiltration and C2 project","T1105 - T1567 - T1071","TA0011 - TA0010 - TA0009","N/A","N/A","Data Exfiltration","https://github.com/TheD1rkMtr/DocPlz","1","1","N/A","N/A","10","2","145","30","2023-10-10T19:01:42Z","2023-10-02T20:49:22Z","10788" +"*/ServerC2.exe*",".{0,1000}\/ServerC2\.exe.{0,1000}","offensive_tool_keyword","DocPlz","Documents Exfiltration and C2 project","T1105 - T1567 - T1071","TA0011 - TA0010 - TA0009","N/A","N/A","Data Exfiltration","https://github.com/TheD1rkMtr/DocPlz","1","1","N/A","N/A","10","2","145","30","2023-10-10T19:01:42Z","2023-10-02T20:49:22Z","10789" +"*/ServerlessRedirector.git*",".{0,1000}\/ServerlessRedirector\.git.{0,1000}","offensive_tool_keyword","ServerlessRedirector","Serverless Redirector in various cloud vendor for red team","T1090.003 - T1095 - T1001.003","TA0010 - TA0011 - TA0008","N/A","N/A","Defense Evasion","https://github.com/KINGSABRI/ServerlessRedirector","1","1","N/A","N/A","10","1","72","10","2022-12-08T08:56:02Z","2022-12-08T07:52:49Z","10790" +"*/servers/dns_server.py*",".{0,1000}\/servers\/dns_server\.py.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","10791" +"*/servers/icmp_server.py*",".{0,1000}\/servers\/icmp_server\.py.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","10792" +"*/servers/smb_server.py*",".{0,1000}\/servers\/smb_server\.py.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","10793" +"*/serverscan/CobaltStrike*",".{0,1000}\/serverscan\/CobaltStrike.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","10794" +"*/serverscan_Air*",".{0,1000}\/serverscan_Air.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","10795" +"*/serverscan_pro*",".{0,1000}\/serverscan_pro.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","10796" +"*/ServerScanForLinux/*",".{0,1000}\/ServerScanForLinux\/.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","#linux","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","10797" +"*/ServerScanForWindows/*",".{0,1000}\/ServerScanForWindows\/.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","10798" +"*/ServerScanForWindows/PE*",".{0,1000}\/ServerScanForWindows\/PE.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","10799" +"*/ServiceMove-BOF/*",".{0,1000}\/ServiceMove\-BOF\/.{0,1000}","offensive_tool_keyword","cobaltstrike","New Lateral Movement technique by abusing Windows Perception Simulation Service to achieve DLL hijacking code execution.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/ServiceMove-BOF","1","1","N/A","N/A","10","10","291","48","2022-02-23T07:17:38Z","2021-08-16T07:16:31Z","10800" +"*/ServiceName:TokenDriver*",".{0,1000}\/ServiceName\:TokenDriver.{0,1000}","offensive_tool_keyword","Tokenvator","A tool to elevate privilege with Windows Tokens","T1134 - T1078","TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/0xbadjuju/Tokenvator","1","1","N/A","N/A","N/A","10","1038","201","2023-10-06T13:17:05Z","2017-12-08T01:29:11Z","10801" +"*/Services/TransitEXE.exe*",".{0,1000}\/Services\/TransitEXE\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","10802" +"*/servicetags.nse*",".{0,1000}\/servicetags\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10803" +"*/SessionExec.exe*",".{0,1000}\/SessionExec\.exe.{0,1000}","offensive_tool_keyword","SessionExec","Execute commands in other Sessions","T1053 - T1569","TA0008","N/A","N/A","Lateral Movement","https://github.com/Leo4j/SessionExec","1","1","N/A","N/A","10","1","86","14","2024-07-29T12:24:28Z","2024-07-21T15:32:07Z","10804" +"*/SessionGopher.git*",".{0,1000}\/SessionGopher\.git.{0,1000}","offensive_tool_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","1","N/A","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","10805" +"*/SessionGopher.ps1*",".{0,1000}\/SessionGopher\.ps1.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10806" +"*/SessionGopher.ps1*",".{0,1000}\/SessionGopher\.ps1.{0,1000}","offensive_tool_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","1","N/A","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","10807" +"*/SessionSearcher.exe*",".{0,1000}\/SessionSearcher\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10808" +"*/SessionSearcher.exe*",".{0,1000}\/SessionSearcher\.exe.{0,1000}","offensive_tool_keyword","SessionSearcher","Searches all connected drives for PuTTY private keys and RDP connection files and parses them for relevant details","T1552.004 - T1083 - T1114.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/matterpreter/OffensiveCSharp/tree/master/SessionSearcher","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","10809" +"*/SetNTLM.ps1*",".{0,1000}\/SetNTLM\.ps1.{0,1000}","offensive_tool_keyword","NTLMInjector","restore the user password after a password reset (get the previous hash with DCSync)","T1555 - T1556.003 - T1078 - T1110.003 - T1201 - T1003","TA0001 - TA0003 - TA0004 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/vletoux/NTLMInjector","1","1","N/A","N/A","10","2","167","29","2017-06-08T19:01:21Z","2017-06-04T07:25:36Z","10812" +"*/SetProcessInjection.git*",".{0,1000}\/SetProcessInjection\.git.{0,1000}","offensive_tool_keyword","SetProcessInjection","alternate technique allowing execution at an arbitrary memory address on a remote process that can be used to replace the standard CreateRemoteThread call.","T1055 - T1055.008 - T1055.001 - T1055.002 - T1055.012","TA0005 - TA0004 - TA0002","N/A","N/A","Defense Evasion","https://github.com/OtterHacker/SetProcessInjection","1","1","N/A","N/A","9","2","151","27","2023-10-02T09:23:42Z","2023-10-02T08:21:47Z","10813" +"*/setuserpass.x64.*",".{0,1000}\/setuserpass\.x64\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","10815" +"*/setuserpass.x86.*",".{0,1000}\/setuserpass\.x86\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","10816" +"*/sgn_linux-amd64.zip*",".{0,1000}\/sgn_linux\-amd64\.zip.{0,1000}","offensive_tool_keyword","sgn","polymorphic encoder used in to obfuscate payloads","T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/EgeBalci/sgn","1","1","#linux","N/A","8","10","1681","224","2024-02-22T17:35:59Z","2019-10-30T10:20:01Z","10822" +"*/sgn_linux-arm64.zip*",".{0,1000}\/sgn_linux\-arm64\.zip.{0,1000}","offensive_tool_keyword","sgn","polymorphic encoder used in to obfuscate payloads","T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/EgeBalci/sgn","1","1","#linux","N/A","8","10","1681","224","2024-02-22T17:35:59Z","2019-10-30T10:20:01Z","10823" +"*/sgn_windows-amd64.exe*",".{0,1000}\/sgn_windows\-amd64\.exe.{0,1000}","offensive_tool_keyword","sgn","polymorphic encoder used in to obfuscate payloads","T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/EgeBalci/sgn","1","1","N/A","N/A","8","10","1681","224","2024-02-22T17:35:59Z","2019-10-30T10:20:01Z","10824" +"*/sgn_windows-amd64.zip*",".{0,1000}\/sgn_windows\-amd64\.zip.{0,1000}","offensive_tool_keyword","sgn","polymorphic encoder used in to obfuscate payloads","T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/EgeBalci/sgn","1","1","N/A","N/A","8","10","1681","224","2024-02-22T17:35:59Z","2019-10-30T10:20:01Z","10825" +"*/sgn32.exe*",".{0,1000}\/sgn32\.exe.{0,1000}","offensive_tool_keyword","sgn","polymorphic encoder used in to obfuscate payloads","T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/EgeBalci/sgn","1","1","N/A","N/A","8","10","1681","224","2024-02-22T17:35:59Z","2019-10-30T10:20:01Z","10826" +"*/sh_executor/*.go*",".{0,1000}\/sh_executor\/.{0,1000}\.go.{0,1000}","offensive_tool_keyword","mythic","mythic C2 agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/freyja/","1","1","N/A","N/A","10","10","54","13","2024-10-29T17:32:07Z","2022-09-28T17:20:04Z","10827" +"*/s-h-3-l-l/*",".{0,1000}\/s\-h\-3\-l\-l\/.{0,1000}","offensive_tool_keyword","katoolin3","Katoolin3 brings all programs available in Kali Linux to Debian and Ubuntu.","T1203 - T1090 - T1020","TA0006 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/s-h-3-l-l/katoolin3","1","1","#linux","N/A","N/A","4","370","120","2020-08-05T17:21:00Z","2019-09-05T13:14:46Z","10828" +"*/shad0w.deb*",".{0,1000}\/shad0w\.deb.{0,1000}","offensive_tool_keyword","shad0w","A post exploitation framework designed to operate covertly on heavily monitored environments","T1071 - T1090 - T1105 - T1571 - T1001","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/bats3c/shad0w","1","1","N/A","N/A","N/A","10","2090","332","2021-09-29T00:15:36Z","2020-04-28T16:42:07Z","10829" +"*/shad0w.py*",".{0,1000}\/shad0w\.py.{0,1000}","offensive_tool_keyword","shad0w","A post exploitation framework designed to operate covertly on heavily monitored environments","T1071 - T1090 - T1105 - T1571 - T1001","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/bats3c/shad0w","1","1","N/A","N/A","N/A","10","2090","332","2021-09-29T00:15:36Z","2020-04-28T16:42:07Z","10830" +"*/shad0w.scr*",".{0,1000}\/shad0w\.scr.{0,1000}","offensive_tool_keyword","shad0w","A post exploitation framework designed to operate covertly on heavily monitored environments","T1071 - T1090 - T1105 - T1571 - T1001","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/bats3c/shad0w","1","1","N/A","N/A","N/A","10","2090","332","2021-09-29T00:15:36Z","2020-04-28T16:42:07Z","10831" +"*/shad0w/beacon/beacon.dll*",".{0,1000}\/shad0w\/beacon\/beacon\.dll.{0,1000}","offensive_tool_keyword","shad0w","A post exploitation framework designed to operate covertly on heavily monitored environments","T1071 - T1090 - T1105 - T1571 - T1001","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/bats3c/shad0w","1","1","N/A","N/A","N/A","10","2090","332","2021-09-29T00:15:36Z","2020-04-28T16:42:07Z","10832" +"*/shadowcoerce.py*",".{0,1000}\/shadowcoerce\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","10834" +"*/ShadowDumper.git*",".{0,1000}\/ShadowDumper\.git.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","1","N/A","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","10835" +"*/ShadowDumper/releases/download/*",".{0,1000}\/ShadowDumper\/releases\/download\/.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","1","N/A","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","10836" +"*/ShadowForgeC2*",".{0,1000}\/ShadowForgeC2.{0,1000}","offensive_tool_keyword","ShadowForgeC2","ShadowForge Command & Control - Harnessing the power of Zoom API - control a compromised Windows Machine from your Zoom Chats.","T1071.001 - T1569.002 - T1059.001","TA0011 - TA0002 - TA0040","N/A","N/A","C2","https://github.com/0xEr3bus/ShadowForgeC2","1","1","N/A","N/A","10","10","47","7","2023-07-15T11:45:36Z","2023-07-13T11:49:36Z","10837" +"*/ShadowHound.git*",".{0,1000}\/ShadowHound\.git.{0,1000}","offensive_tool_keyword","ShadowHound","set of PowerShell scripts for Active Directory enumeration","T1087 - T1018 - T1482 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/Friends-Security/ShadowHound","1","1","N/A","N/A","8","4","345","36","2024-12-01T08:06:02Z","2024-11-21T15:01:14Z","10838" +"*/ShadowSpray.exe*",".{0,1000}\/ShadowSpray\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10849" +"*/ShadowSpray.git*",".{0,1000}\/ShadowSpray\.git.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1110.003 - T1098 - T1059 - T1075","TA0001 - TA0008 - TA0009","N/A","Black Basta","Discovery","https://github.com/ShorSec/ShadowSpray","1","1","N/A","N/A","7","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","10850" +"*/ShadowSpray.git*",".{0,1000}\/ShadowSpray\.git.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","1","N/A","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","10851" +"*/ShadowSpray/*.cs*",".{0,1000}\/ShadowSpray\/.{0,1000}\.cs.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1110.003 - T1098 - T1059 - T1075","TA0001 - TA0008 - TA0009","N/A","Black Basta","Discovery","https://github.com/ShorSec/ShadowSpray","1","1","N/A","N/A","7","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","10852" +"*/ShadowStealer.git*",".{0,1000}\/ShadowStealer\.git.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","1","N/A","N/A","10","","N/A","","","","10853" +"*/ShadowTech Rat.exe*",".{0,1000}\/ShadowTech\sRat\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","10854" +"*/share_enum.py*",".{0,1000}\/share_enum\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","10857" +"*/shareaudit.exe*",".{0,1000}\/shareaudit\.exe.{0,1000}","offensive_tool_keyword","ShareAudit","A tool for auditing network shares in an Active Directory environment","T1135 - T1005 - T1083 - T1210","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/dionach/ShareAudit","1","1","N/A","N/A","8","1","42","15","2019-04-29T10:07:57Z","2019-02-26T16:00:15Z","10858" +"*/ShareAudit.git*",".{0,1000}\/ShareAudit\.git.{0,1000}","offensive_tool_keyword","ShareAudit","A tool for auditing network shares in an Active Directory environment","T1135 - T1005 - T1083 - T1210","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/dionach/ShareAudit","1","1","N/A","N/A","8","1","42","15","2019-04-29T10:07:57Z","2019-02-26T16:00:15Z","10859" +"*/ShareAudit/releases/download/*",".{0,1000}\/ShareAudit\/releases\/download\/.{0,1000}","offensive_tool_keyword","ShareAudit","A tool for auditing network shares in an Active Directory environment","T1135 - T1005 - T1083 - T1210","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/dionach/ShareAudit","1","1","N/A","N/A","8","1","42","15","2019-04-29T10:07:57Z","2019-02-26T16:00:15Z","10860" +"*/ShareFinder.cs*",".{0,1000}\/ShareFinder\.cs.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","10861" +"*/Sharefinder.ps1",".{0,1000}\/Sharefinder\.ps1","offensive_tool_keyword","PowerSploit","PowerSploit is a collection of Microsoft PowerShell modules that can be used to aid penetration testers during all phases of an assessment. PowerSploit is comprised of the following modules and scripts","T1134 - T1087.001 - T1123 - T1547.001 - T1547.005 - T1059.001 - T1543.003 - T1555.004 - T1005 - T1482 - T1574.001 - T1574.007 - T1574.008 - T1574.009 - T1056.001 - T1027.005 - T1027.010 - T1003.001 - T1057 - T1055.001 - T1012 - T1620 - T1053.005 - T1113 - T1558.003 - T1552.002 - T1552.006 - T1047","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","Dispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - Turla","Framework","https://github.com/PowerShellMafia/PowerSploit","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","10862" +"*/Sharp3389.exe*",".{0,1000}\/Sharp3389\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10865" +"*/SharpADWS.git*",".{0,1000}\/SharpADWS\.git.{0,1000}","offensive_tool_keyword","SharpADWS","SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)","T1087 - T1069 - T1018 - T1083 - T1595","TA0001 - TA0002 - TA0007","N/A","N/A","Discovery","https://github.com/wh0amitz/SharpADWS","1","1","N/A","N/A","7","6","538","59","2024-03-19T08:57:52Z","2024-02-13T17:28:00Z","10866" +"*/SharpAllowedToAct.exe*",".{0,1000}\/SharpAllowedToAct\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10867" +"*/SharpAllowedToAct.exe*",".{0,1000}\/SharpAllowedToAct\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10868" +"*/SharpAltSecIds.exe*",".{0,1000}\/SharpAltSecIds\.exe.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","1","N/A","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","10869" +"*/SharpAltSecIds.git*",".{0,1000}\/SharpAltSecIds\.git.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","1","N/A","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","10870" +"*/SharpApplocker.exe*",".{0,1000}\/SharpApplocker\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10871" +"*/SharpApplocker.exe*",".{0,1000}\/SharpApplocker\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10872" +"*/SharpAppLocker.git*",".{0,1000}\/SharpAppLocker\.git.{0,1000}","offensive_tool_keyword","SharpAppLocker","Useful when you already bypassed AppLocker initially and you don't want to leave PS logs","T1086 - T1569.002 - T1070.003","TA0005 - TA0006","N/A","N/A","Defense Evasion","https://github.com/Flangvik/SharpAppLocker","1","1","N/A","N/A","7","1","99","16","2022-12-08T11:06:40Z","2020-08-01T12:58:36Z","10873" +"*/SharpAVKB.exe*",".{0,1000}\/SharpAVKB\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10874" +"*/SharpAVKB.exe*",".{0,1000}\/SharpAVKB\.exe.{0,1000}","offensive_tool_keyword","SharpAVKB","Windows Antivirus Comparison and Patch Number Comparison","T1082 - T1518 - T1083","TA0007","N/A","N/A","Discovery","https://github.com/uknowsec/SharpAVKB","1","1","N/A","N/A","4","1","58","24","2019-10-28T06:50:30Z","2019-10-14T12:44:22Z","10875" +"*/SharpAVKB.git*",".{0,1000}\/SharpAVKB\.git.{0,1000}","offensive_tool_keyword","SharpAVKB","Windows Antivirus Comparison and Patch Number Comparison","T1082 - T1518 - T1083","TA0007","N/A","N/A","Discovery","https://github.com/uknowsec/SharpAVKB","1","1","N/A","N/A","4","1","58","24","2019-10-28T06:50:30Z","2019-10-14T12:44:22Z","10876" +"*/SharpAzbelt.git*",".{0,1000}\/SharpAzbelt\.git.{0,1000}","offensive_tool_keyword","SharpAzbelt","This is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resources","T1082 - T1003 - T1027 - T1110 - T1078","TA0006 - TA0007 - TA0005 - TA0004 - TA0003","N/A","N/A","Discovery","https://github.com/redskal/SharpAzbelt","1","1","N/A","N/A","8","1","26","7","2023-09-21T21:47:32Z","2023-09-21T21:44:03Z","10877" +"*/SharpBlackout.git*",".{0,1000}\/SharpBlackout\.git.{0,1000}","offensive_tool_keyword","SharpBlackout","Terminate AV/EDR leveraging BYOVD attack","T1562.001 - T1050.005","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/dmcxblue/SharpBlackout","1","1","N/A","N/A","10","1","83","20","2025-03-21T16:33:42Z","2023-08-23T14:16:40Z","10878" +"*/SharpBlock.exe*",".{0,1000}\/SharpBlock\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10879" +"*/SharpBruteForceSSH.git*","\/SharpBruteForceSSH\.git","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","1","N/A","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","10880" +"*/SharpBuster.dll*",".{0,1000}\/SharpBuster\.dll.{0,1000}","offensive_tool_keyword","SharpBuster","This is a C# implementation of a directory brute forcing tool designed to allow for in-memory execution","T1087 - T1112 - T1048.003 - T1105","TA0007 - TA0040 - TA0002","N/A","N/A","Discovery","https://github.com/passthehashbrowns/SharpBuster","1","1","N/A","N/A","7","1","62","7","2020-09-02T15:46:03Z","2020-08-31T00:33:02Z","10881" +"*/SharpBuster.exe*",".{0,1000}\/SharpBuster\.exe.{0,1000}","offensive_tool_keyword","SharpBuster","This is a C# implementation of a directory brute forcing tool designed to allow for in-memory execution","T1087 - T1112 - T1048.003 - T1105","TA0007 - TA0040 - TA0002","N/A","N/A","Discovery","https://github.com/passthehashbrowns/SharpBuster","1","1","N/A","N/A","7","1","62","7","2020-09-02T15:46:03Z","2020-08-31T00:33:02Z","10882" +"*/SharpBypassUAC.exe*",".{0,1000}\/SharpBypassUAC\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10883" +"*/SharpBypassUAC.exe*",".{0,1000}\/SharpBypassUAC\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10884" +"*/SharpBypassUAC.exe*",".{0,1000}\/SharpBypassUAC\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10885" +"*/SharpC2*",".{0,1000}\/SharpC2.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","10886" +"*/SharpCalendar/*.*",".{0,1000}\/SharpCalendar\/.{0,1000}\..{0,1000}","offensive_tool_keyword","cobaltstrike",".NET Assembly to Retrieve Outlook Calendar Details","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OG-Sadpanda/SharpCalendar","1","1","N/A","N/A","10","10","13","1","2021-10-07T19:42:20Z","2021-10-07T17:11:46Z","10887" +"*/SharpCat/*",".{0,1000}\/SharpCat\/.{0,1000}","offensive_tool_keyword","cobaltstrike","C# alternative to the linux cat command... Prints file contents to console. For use with Cobalt Strike's Execute-Assembly","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OG-Sadpanda/SharpCat","1","1","N/A","N/A","10","10","16","3","2021-07-15T15:01:02Z","2021-07-15T14:57:53Z","10888" +"*/SharpChassisType.exe*",".{0,1000}\/SharpChassisType\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10889" +"*/SharpCheckInfo.exe*",".{0,1000}\/SharpCheckInfo\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10890" +"*/SharpChisel.exe*",".{0,1000}\/SharpChisel\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10891" +"*/SharpChisel.exe*",".{0,1000}\/SharpChisel\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10892" +"*/SharpChrome.exe*",".{0,1000}\/SharpChrome\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10893" +"*/SharpChrome.exe*",".{0,1000}\/SharpChrome\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpChrome","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","10894" +"*/SharpChrome.exe*",".{0,1000}\/SharpChrome\.exe.{0,1000}","offensive_tool_keyword","SharpChrome","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpChrome","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","10895" +"*/SharpChrome.exe*",".{0,1000}\/SharpChrome\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10896" +"*/SharpChromium.exe*",".{0,1000}\/SharpChromium\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10897" +"*/SharpChromium.exe*",".{0,1000}\/SharpChromium\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10898" +"*/SharpChromium.exe*",".{0,1000}\/SharpChromium\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10899" +"*/SharpChromium.git*",".{0,1000}\/SharpChromium\.git.{0,1000}","offensive_tool_keyword","SharpChromium",".NET 4.0 CLR Project to retrieve Chromium data such as cookies - history and saved logins.","T1555.003 - T1114.001 - T1555.004","TA0006 - TA0003","N/A","COZY BEAR","Credential Access","https://github.com/djhohnstein/SharpChromium","1","1","N/A","N/A","10","8","712","100","2020-10-23T22:28:13Z","2018-08-06T21:25:21Z","10900" +"*/SharpClipboard.git*",".{0,1000}\/SharpClipboard\.git.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","1","N/A","N/A","8","1","N/A","N/A","N/A","N/A","10901" +"*/SharpClipHistory.exe*",".{0,1000}\/SharpClipHistory\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10902" +"*/SharpCloud.exe*",".{0,1000}\/SharpCloud\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10903" +"*/SharpCloud.exe*",".{0,1000}\/SharpCloud\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10904" +"*/SharpCloud.exe*",".{0,1000}\/SharpCloud\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10905" +"*/SharpCloud.git*",".{0,1000}\/SharpCloud\.git.{0,1000}","offensive_tool_keyword","SharpCloud","Simple C# for checking for the existence of credential files related to AWS - Microsoft Azure and Google Compute.","T1083 - T1059.001 - T1114.002","TA0007 - TA0002 ","N/A","N/A","Credential Access","https://github.com/chrismaddalena/SharpCloud","1","1","N/A","N/A","10","2","171","29","2018-09-18T02:24:10Z","2018-08-20T15:06:22Z","10906" +"*/SharpCollection.git*",".{0,1000}\/SharpCollection\.git.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10907" +"*/SharpCollection/*",".{0,1000}\/SharpCollection\/.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10908" +"*/SharpCOM.exe*",".{0,1000}\/SharpCOM\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10909" +"*/SharpCOM.exe*",".{0,1000}\/SharpCOM\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10910" +"*/SharpCOM.exe*",".{0,1000}\/SharpCOM\.exe.{0,1000}","offensive_tool_keyword","SharpCOM","DCOM Lateral Movement","T1175","TA0008","N/A","N/A","Lateral Movement","https://github.com/rvrsh3ll/SharpCOM","1","1","N/A","N/A","10","2","128","30","2019-09-16T22:52:53Z","2018-12-13T15:10:55Z","10911" +"*/SharpCOM.git*",".{0,1000}\/SharpCOM\.git.{0,1000}","offensive_tool_keyword","SharpCOM","DCOM Lateral Movement","T1175","TA0008","N/A","N/A","Lateral Movement","https://github.com/rvrsh3ll/SharpCOM","1","1","N/A","N/A","10","2","128","30","2019-09-16T22:52:53Z","2018-12-13T15:10:55Z","10912" +"*/SharpCompile/*",".{0,1000}\/SharpCompile\/.{0,1000}","offensive_tool_keyword","cobaltstrike","SharpCompile is an aggressor script for Cobalt Strike which allows you to compile and execute C# in realtime. This is a more slick approach than manually compiling an .NET assembly and loading it into Cobalt Strike. The project aims to make it easier to move away from adhoc PowerShell execution instead creating a temporary assembly and executing ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/SpiderLabs/SharpCompile","1","1","N/A","N/A","10","10","291","58","2020-08-07T12:49:36Z","2018-11-01T17:18:52Z","10913" +"*/sharpcompile_*.*",".{0,1000}\/sharpcompile_.{0,1000}\..{0,1000}","offensive_tool_keyword","cobaltstrike","SharpCompile is an aggressor script for Cobalt Strike which allows you to compile and execute C# in realtime. This is a more slick approach than manually compiling an .NET assembly and loading it into Cobalt Strike. The project aims to make it easier to move away from adhoc PowerShell execution instead creating a temporary assembly and executing ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/SpiderLabs/SharpCompile","1","1","N/A","N/A","10","10","291","58","2020-08-07T12:49:36Z","2018-11-01T17:18:52Z","10914" +"*/SharpCookieMonster.exe*",".{0,1000}\/SharpCookieMonster\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10915" +"*/SharpCookieMonster.exe*",".{0,1000}\/SharpCookieMonster\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10916" +"*/SharpCradle/*",".{0,1000}\/SharpCradle\/.{0,1000}","offensive_tool_keyword","cobaltstrike","SharpCradle is a tool designed to help penetration testers or red teams download and execute .NET binaries into memory.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/anthemtotheego/SharpCradle","1","1","N/A","N/A","10","10","279","57","2020-12-30T17:15:51Z","2018-10-23T06:21:53Z","10917" +"*/SharpCrashEventLog.exe*",".{0,1000}\/SharpCrashEventLog\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10918" +"*/SharpCrashEventLog.exe*",".{0,1000}\/SharpCrashEventLog\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10919" +"*/SharpCrashEventLog.exe*",".{0,1000}\/SharpCrashEventLog\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10920" +"*/SharpDecryptPwd.exe*",".{0,1000}\/SharpDecryptPwd\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10921" +"*/SharpDecryptPwd.git*",".{0,1000}\/SharpDecryptPwd\.git.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","1","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","10922" +"*/SharpDecryptPwd2.exe*",".{0,1000}\/SharpDecryptPwd2\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10923" +"*/SharpDir.exe*",".{0,1000}\/SharpDir\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10924" +"*/SharpDir.exe*",".{0,1000}\/SharpDir\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10925" +"*/SharpDir.exe*",".{0,1000}\/SharpDir\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10926" +"*/SharpDirLister.exe*",".{0,1000}\/SharpDirLister\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10927" +"*/SharpDomainSpray.exe*",".{0,1000}\/SharpDomainSpray\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10928" +"*/SharpDomainSpray.git*",".{0,1000}\/SharpDomainSpray\.git.{0,1000}","offensive_tool_keyword","SharpDomainSpray","Basic password spraying tool for internal tests and red teaming","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/HunnicCyber/SharpDomainSpray","1","1","N/A","N/A","10","1","90","18","2020-03-21T09:17:48Z","2019-06-05T10:47:05Z","10929" +"*/SharpDoor.exe*",".{0,1000}\/SharpDoor\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10931" +"*/SharpDoor.exe*",".{0,1000}\/SharpDoor\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10932" +"*/SharpDoor.exe*",".{0,1000}\/SharpDoor\.exe.{0,1000}","offensive_tool_keyword","SharpDoor","SharpDoor is alternative RDPWrap written in C# to allowed multiple RDP (Remote Desktop) sessions by patching termsrv.dll file","T1112 - T1055 - T1562.001","TA0003 - TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/infosecn1nja/SharpDoor","1","1","N/A","N/A","9","4","311","61","2019-09-30T16:11:24Z","2019-09-29T02:24:07Z","10933" +"*/SharpDoor.git*",".{0,1000}\/SharpDoor\.git.{0,1000}","offensive_tool_keyword","SharpDoor","SharpDoor is alternative RDPWrap written in C# to allowed multiple RDP (Remote Desktop) sessions by patching termsrv.dll file","T1112 - T1055 - T1562.001","TA0003 - TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/infosecn1nja/SharpDoor","1","1","N/A","N/A","9","4","311","61","2019-09-30T16:11:24Z","2019-09-29T02:24:07Z","10934" +"*/SharpDoor.git*",".{0,1000}\/SharpDoor\.git.{0,1000}","offensive_tool_keyword","SharpDoor","SharpDoor is alternative RDPWrap written in C# to allowed multiple RDP (Remote Desktop) sessions by patching termsrv.dll file.","T1059 - T1085 - T1070.004","TA0008 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/infosecn1nja/SharpDoor","1","1","N/A","N/A","7","4","311","61","2019-09-30T16:11:24Z","2019-09-29T02:24:07Z","10935" +"*/SharpDPAPI.cna*",".{0,1000}\/SharpDPAPI\.cna.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10936" +"*/SharpDPAPI.exe*",".{0,1000}\/SharpDPAPI\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10937" +"*/SharpDPAPI.exe*",".{0,1000}\/SharpDPAPI\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10938" +"*/SharpDPAPI.exe*",".{0,1000}\/SharpDPAPI\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpDPAPI","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","10939" +"*/SharpDPAPI.exe*",".{0,1000}\/SharpDPAPI\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10940" +"*/SharpDPAPI.exe*",".{0,1000}\/SharpDPAPI\.exe.{0,1000}","offensive_tool_keyword","SharpDPAPI","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpDPAPI","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","10941" +"*/SharpDPAPI.git*",".{0,1000}\/SharpDPAPI\.git.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","10942" +"*/SharpDump*",".{0,1000}\/SharpDump.{0,1000}","offensive_tool_keyword","covenant","Covenant commands - Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","10943" +"*/SharpDump.exe*",".{0,1000}\/SharpDump\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10944" +"*/SharpDump.exe*",".{0,1000}\/SharpDump\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10945" +"*/SharpDump.exe*",".{0,1000}\/SharpDump\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10946" +"*/SharpDump.exe*",".{0,1000}\/SharpDump\.exe.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","1","N/A","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","10947" +"*/SharpDump.git*",".{0,1000}\/SharpDump\.git.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","1","N/A","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","10948" +"*/SharpEdge.exe*",".{0,1000}\/SharpEdge\.exe.{0,1000}","offensive_tool_keyword","SharpEdge","C# Implementation of Get-VaultCredential - Displays Windows vault credential objects including cleartext web credentials - based on https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-VaultCredential.ps1","T1555.004 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/SharpEdge","1","1","N/A","N/A","10","1","14","7","2018-07-31T01:31:21Z","2018-07-31T09:54:11Z","10949" +"*/SharpEdge.git*",".{0,1000}\/SharpEdge\.git.{0,1000}","offensive_tool_keyword","SharpEdge","C# Implementation of Get-VaultCredential - Displays Windows vault credential objects including cleartext web credentials - based on https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-VaultCredential.ps1","T1555.004 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/SharpEdge","1","1","N/A","N/A","10","1","14","7","2018-07-31T01:31:21Z","2018-07-31T09:54:11Z","10950" +"*/SharpEDRChecker-*.zip*",".{0,1000}\/SharpEDRChecker\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","SharpEDRChecker","Checks for the presence of known defensive products such as AV/EDR and logging tools","T1083 - T1518.001 - T1063","TA0007 - TA0005","N/A","N/A","Discovery","https://github.com/PwnDexter/SharpEDRChecker","1","1","N/A","N/A","8","8","706","98","2023-10-09T11:17:49Z","2020-06-16T10:25:00Z","10951" +"*/SharpEDRChecker.exe*",".{0,1000}\/SharpEDRChecker\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10952" +"*/SharpEDRChecker.exe*",".{0,1000}\/SharpEDRChecker\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10953" +"*/SharpEDRChecker.exe*",".{0,1000}\/SharpEDRChecker\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10954" +"*/SharpEDRChecker.git*",".{0,1000}\/SharpEDRChecker\.git.{0,1000}","offensive_tool_keyword","SharpEDRChecker","Checks for the presence of known defensive products such as AV/EDR and logging tools","T1083 - T1518.001 - T1063","TA0007 - TA0005","N/A","N/A","Discovery","https://github.com/PwnDexter/SharpEDRChecker","1","1","N/A","N/A","8","8","706","98","2023-10-09T11:17:49Z","2020-06-16T10:25:00Z","10955" +"*/SharpEDRChecker/*",".{0,1000}\/SharpEDRChecker\/.{0,1000}","offensive_tool_keyword","SharpEDRChecker","Checks for the presence of known defensive products such as AV/EDR and logging tools","T1083 - T1518.001 - T1063","TA0007 - TA0005","N/A","N/A","Discovery","https://github.com/PwnDexter/SharpEDRChecker","1","1","N/A","N/A","8","8","706","98","2023-10-09T11:17:49Z","2020-06-16T10:25:00Z","10956" +"*/SharpEfsPotato*",".{0,1000}\/SharpEfsPotato.{0,1000}","offensive_tool_keyword","SharpEfsPotato","Local privilege escalation from SeImpersonatePrivilege using EfsRpc.","T1548.002 - T1134.002","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/bugch3ck/SharpEfsPotato","1","1","N/A","N/A","10","4","317","46","2022-10-17T12:35:06Z","2022-10-17T12:20:47Z","10957" +"*/SharpElevator.exe*",".{0,1000}\/SharpElevator\.exe.{0,1000}","offensive_tool_keyword","SharpElevator","SharpElevator is a C# implementation of Elevator for UAC bypass","T1548.002 - T1548","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/eladshamir/SharpElevator","1","1","N/A","N/A","10","1","51","12","2022-08-31T18:09:10Z","2022-08-29T19:52:53Z","10958" +"*/SharpElevator.git*",".{0,1000}\/SharpElevator\.git.{0,1000}","offensive_tool_keyword","SharpElevator","SharpElevator is a C# implementation of Elevator for UAC bypass","T1548.002 - T1548","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/eladshamir/SharpElevator","1","1","N/A","N/A","10","1","51","12","2022-08-31T18:09:10Z","2022-08-29T19:52:53Z","10959" +"*/SharPersist.exe*",".{0,1000}\/SharPersist\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10960" +"*/SharPersist.exe*",".{0,1000}\/SharPersist\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10961" +"*/SharPersist.exe*",".{0,1000}\/SharPersist\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10962" +"*/SharPersist.git*",".{0,1000}\/SharPersist\.git.{0,1000}","offensive_tool_keyword","SharPersist","SharPersist Windows persistence toolkit written in C#.","T1547 - T1053 - T1027 - T1028 - T1112","TA0003 - TA0008","N/A","N/A","Persistence","https://github.com/fireeye/SharPersist","1","1","N/A","N/A","10","10","1460","257","2023-08-11T00:52:09Z","2019-06-21T13:32:14Z","10963" +"*/SharpEventLog.exe*",".{0,1000}\/SharpEventLog\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10964" +"*/SharpEventLog.exe*",".{0,1000}\/SharpEventLog\.exe.{0,1000}","offensive_tool_keyword","SharpEventLog","reads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetration","T1078 - T1087.001","TA0007","N/A","N/A","Discovery","https://github.com/uknowsec/SharpEventLog","1","1","N/A","N/A","4","3","205","34","2019-10-15T06:26:52Z","2019-10-15T06:14:32Z","10965" +"*/SharpEventLog.git*",".{0,1000}\/SharpEventLog\.git.{0,1000}","offensive_tool_keyword","SharpEventLog","reads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetration","T1078 - T1087.001","TA0007","N/A","N/A","Discovery","https://github.com/uknowsec/SharpEventLog","1","1","N/A","N/A","4","3","205","34","2019-10-15T06:26:52Z","2019-10-15T06:14:32Z","10966" +"*/SharpEventPersist.git*",".{0,1000}\/SharpEventPersist\.git.{0,1000}","offensive_tool_keyword","SharpEventPersist","Persistence by writing/reading shellcode from Event Log","T1055 - T1070.001 - T1547.001","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/improsec/SharpEventPersist","1","1","N/A","N/A","10","10","371","50","2022-05-27T14:52:02Z","2022-05-20T14:52:56Z","10967" +"*/SharpExcelDCom.exe*",".{0,1000}\/SharpExcelDCom\.exe.{0,1000}","offensive_tool_keyword","SharpExShell","SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application","T1021.003 - T1218.007 - T1127.001","TA0008 - TA0009 - TA0005","N/A","N/A","Lateral Movement","https://github.com/grayhatkiller/SharpExShell","1","1","N/A","N/A","8","1","70","15","2024-05-01T23:17:25Z","2023-10-30T18:16:41Z","10968" +"*/SharpExcelibur.exe*",".{0,1000}\/SharpExcelibur\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10969" +"*/SharpExec.exe*",".{0,1000}\/SharpExec\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10970" +"*/SharpExec.exe*",".{0,1000}\/SharpExec\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10971" +"*/SharpExec.exe*",".{0,1000}\/SharpExec\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10972" +"*/SharpExfil.git*",".{0,1000}\/SharpExfil\.git.{0,1000}","offensive_tool_keyword","SharpExfil","C# executables to extract information from target environment using OneDrive API.","T1567.002 - T1020 - T1071.001","TA0005 - TA0010 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/adm1nPanda/SharpExfil","1","1","N/A","N/A","8","1","6","1","2020-07-02T14:48:55Z","2019-07-27T05:28:40Z","10973" +"*/SharpExfiltrate.git*",".{0,1000}\/SharpExfiltrate\.git.{0,1000}","offensive_tool_keyword","SharpExfiltrate","Modular C# framework to exfiltrate loot over secure and trusted channels.","T1027 - T1567 - T1561","TA0010 - TA0040 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/Flangvik/SharpExfiltrate","1","1","N/A","N/A","10","2","126","37","2021-09-12T17:08:02Z","2021-09-08T13:17:00Z","10974" +"*/SharpExfiltrate/*",".{0,1000}\/SharpExfiltrate\/.{0,1000}","offensive_tool_keyword","SharpExfiltrate","Modular C# framework to exfiltrate loot over secure and trusted channels.","T1027 - T1567 - T1561","TA0010 - TA0040 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/Flangvik/SharpExfiltrate","1","1","N/A","N/A","10","2","126","37","2021-09-12T17:08:02Z","2021-09-08T13:17:00Z","10975" +"*/SharpExShell.exe*",".{0,1000}\/SharpExShell\.exe.{0,1000}","offensive_tool_keyword","SharpExShell","SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application","T1021.003 - T1218.007 - T1127.001","TA0008 - TA0009 - TA0005","N/A","N/A","Lateral Movement","https://github.com/grayhatkiller/SharpExShell","1","1","N/A","N/A","8","1","70","15","2024-05-01T23:17:25Z","2023-10-30T18:16:41Z","10976" +"*/SharpExShell.git*",".{0,1000}\/SharpExShell\.git.{0,1000}","offensive_tool_keyword","SharpExShell","SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application","T1021.003 - T1218.007 - T1127.001","TA0008 - TA0009 - TA0005","N/A","N/A","Lateral Movement","https://github.com/grayhatkiller/SharpExShell","1","1","N/A","N/A","8","1","70","15","2024-05-01T23:17:25Z","2023-10-30T18:16:41Z","10977" +"*/SharpFinder.exe*",".{0,1000}\/SharpFinder\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10978" +"*/SharpFtpC2.git*",".{0,1000}\/SharpFtpC2\.git.{0,1000}","offensive_tool_keyword","SharpFtpC2","A Streamlined FTP-Driven Command and Control Conduit for Interconnecting Remote Systems","T1071.002 - T1105 - T1090.001","TA0011","N/A","N/A","C2","https://github.com/PhrozenIO/SharpFtpC2","1","1","N/A","N/A","10","10","88","15","2023-11-09T10:37:20Z","2023-06-09T12:41:28Z","10979" +"*/SharpFtpC2/tarball/*",".{0,1000}\/SharpFtpC2\/tarball\/.{0,1000}","offensive_tool_keyword","SharpFtpC2","A Streamlined FTP-Driven Command and Control Conduit for Interconnecting Remote Systems","T1071.002 - T1105 - T1090.001","TA0011","N/A","N/A","C2","https://github.com/PhrozenIO/SharpFtpC2","1","1","N/A","N/A","10","10","88","15","2023-11-09T10:37:20Z","2023-06-09T12:41:28Z","10980" +"*/SharpFtpC2/zipball/*",".{0,1000}\/SharpFtpC2\/zipball\/.{0,1000}","offensive_tool_keyword","SharpFtpC2","A Streamlined FTP-Driven Command and Control Conduit for Interconnecting Remote Systems","T1071.002 - T1105 - T1090.001","TA0011","N/A","N/A","C2","https://github.com/PhrozenIO/SharpFtpC2","1","1","N/A","N/A","10","10","88","15","2023-11-09T10:37:20Z","2023-06-09T12:41:28Z","10981" +"*/SharpGetTitle.exe*",".{0,1000}\/SharpGetTitle\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10982" +"*/SharpGhostTask*",".{0,1000}\/SharpGhostTask.{0,1000}","offensive_tool_keyword","SharpGhostTask","registry manipulation to create scheduled tasks without triggering the usual event logs.","T1053.005 - T1112 - T1564.001","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/dmcxblue/SharpGhostTask","1","1","N/A","N/A","10","2","114","12","2024-01-05T15:42:55Z","2024-01-04T21:42:33Z","10983" +"*/SharpGmailC2.git*",".{0,1000}\/SharpGmailC2\.git.{0,1000}","offensive_tool_keyword","SharpGmailC2","Gmail will act as Server and implant will exfiltrate data via smtp and will read commands from C2 (Gmail) via imap protocol","T1071 - T1071.004 - T1568 - T1568.002 - T1114 - T1114.001","TA0011 - TA0040 - TA0001","N/A","N/A","C2","https://github.com/reveng007/SharpGmailC2","1","1","N/A","N/A","10","10","260","47","2022-12-27T01:45:46Z","2022-11-10T06:48:15Z","10984" +"*/SharpGpo.exe*",".{0,1000}\/SharpGpo\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpGpo","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","10985" +"*/SharpGpo.exe*",".{0,1000}\/SharpGpo\.exe.{0,1000}","offensive_tool_keyword","SharpGpo","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpGpo","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","10986" +"*/SharpGPOAbuse.exe*",".{0,1000}\/SharpGPOAbuse\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10987" +"*/SharpGPOAbuse.exe*",".{0,1000}\/SharpGPOAbuse\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10988" +"*/SharpGPOAbuse.exe*",".{0,1000}\/SharpGPOAbuse\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10989" +"*/SharpGraphView.git*",".{0,1000}\/SharpGraphView\.git.{0,1000}","offensive_tool_keyword","SharpGraphView","Microsoft Graph API post-exploitation toolkit","T1078.004 - T1114.002","TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010","N/A","N/A","Discovery","https://github.com/mlcsec/SharpGraphView","1","1","N/A","N/A","6","1","94","9","2024-07-13T12:27:38Z","2024-05-04T11:23:42Z","10990" +"*/SharpHandler.exe*",".{0,1000}\/SharpHandler\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10991" +"*/SharpHandler.exe*",".{0,1000}\/SharpHandler\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10992" +"*/SharpHandler.py*",".{0,1000}\/SharpHandler\.py.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","10993" +"*/SharpHide.exe*",".{0,1000}\/SharpHide\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","10994" +"*/SharpHide.git*",".{0,1000}\/SharpHide\.git.{0,1000}","offensive_tool_keyword","SharpHide","Tool to create hidden registry keys","T1112 - T1562 - T1562.001","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/outflanknl/SharpHide","1","1","N/A","N/A","9","5","480","96","2019-10-23T10:44:22Z","2019-10-20T14:25:47Z","10995" +"*/SharpHide.git*",".{0,1000}\/SharpHide\.git.{0,1000}","offensive_tool_keyword","SharpHide","Tool to create hidden registry keys","T1112 - T1562 - T1562.001","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/outflanknl/SharpHide","1","1","N/A","N/A","9","5","480","96","2019-10-23T10:44:22Z","2019-10-20T14:25:47Z","10996" +"*/SharpHose.exe*",".{0,1000}\/SharpHose\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","10997" +"*/SharpHose.exe*",".{0,1000}\/SharpHose\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","10998" +"*/SharpHose.exe*",".{0,1000}\/SharpHose\.exe.{0,1000}","offensive_tool_keyword","SharpHose","Asynchronous Password Spraying Tool in C# for Windows Environments","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/ustayready/SharpHose","1","1","N/A","N/A","10","4","312","62","2023-12-19T21:06:47Z","2020-05-01T22:10:49Z","10999" +"*/SharpHound.exe*",".{0,1000}\/SharpHound\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11000" +"*/SharpHound.exe*",".{0,1000}\/SharpHound\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11001" +"*/SharpHound.exe*",".{0,1000}\/SharpHound\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpHound","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11002" +"*/SharpHound.exe*",".{0,1000}\/SharpHound\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11003" +"*/SharpHound.exe*",".{0,1000}\/SharpHound\.exe.{0,1000}","offensive_tool_keyword","sharphound","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpHound","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11004" +"*/SharpHound.ps1*",".{0,1000}\/SharpHound\.ps1.{0,1000}","offensive_tool_keyword","BloodHound","Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors","1","1","N/A","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","11005" +"*/SharpHound-v*.zip*",".{0,1000}\/SharpHound\-v.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","11006" +"*/SharpIncrease.exe*",".{0,1000}\/SharpIncrease\.exe.{0,1000}","offensive_tool_keyword","SharpIncrease","binary padding to add junk data and change the on-disk representation of a file","T1480 - T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/mertdas/SharpIncrease","1","1","N/A","N/A","6","2","148","30","2024-06-28T21:36:46Z","2023-03-14T23:35:32Z","11007" +"*/SharpIncrease.git*",".{0,1000}\/SharpIncrease\.git.{0,1000}","offensive_tool_keyword","SharpIncrease","binary padding to add junk data and change the on-disk representation of a file","T1480 - T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/mertdas/SharpIncrease","1","1","N/A","N/A","6","2","148","30","2024-06-28T21:36:46Z","2023-03-14T23:35:32Z","11008" +"*/Sharpire.exe*",".{0,1000}\/Sharpire\.exe.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","11009" +"*/SharpKatz.exe*",".{0,1000}\/SharpKatz\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11010" +"*/SharpKatz.exe*",".{0,1000}\/SharpKatz\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpKatz","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11011" +"*/SharpKatz.exe*",".{0,1000}\/SharpKatz\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11012" +"*/SharpKatz.exe*",".{0,1000}\/SharpKatz\.exe.{0,1000}","offensive_tool_keyword","SharpKatz","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpKatz","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11013" +"*/SharpKiller.git*",".{0,1000}\/SharpKiller\.git.{0,1000}","offensive_tool_keyword","SharpKiller","Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8","T1211 - T1202 - T1218","TA0005","N/A","N/A","Defense Evasion","https://github.com/S1lkys/SharpKiller","1","1","N/A","N/A","10","4","349","45","2024-08-29T12:23:34Z","2023-10-21T17:27:59Z","11014" +"*/Sharp-Killer.sln*",".{0,1000}\/Sharp\-Killer\.sln.{0,1000}","offensive_tool_keyword","SharpKiller","Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8","T1211 - T1202 - T1218","TA0005","N/A","N/A","Defense Evasion","https://github.com/S1lkys/SharpKiller","1","1","N/A","N/A","10","4","349","45","2024-08-29T12:23:34Z","2023-10-21T17:27:59Z","11015" +"*/SharpLAPS.exe*",".{0,1000}\/SharpLAPS\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11016" +"*/SharpLAPS.exe*",".{0,1000}\/SharpLAPS\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpLAPS","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11017" +"*/SharpLAPS.exe*",".{0,1000}\/SharpLAPS\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11018" +"*/SharpLAPS.exe*",".{0,1000}\/SharpLAPS\.exe.{0,1000}","offensive_tool_keyword","SharpLAPS","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpLAPS","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11019" +"*/SharpLDAP.git*",".{0,1000}\/SharpLDAP\.git.{0,1000}","offensive_tool_keyword","SharpLDAP","tool written in C# that aims to do enumeration via LDAP queries","T1018 - T1069.003","TA0007 - TA0011","N/A","N/A","Discovery","https://github.com/mertdas/SharpLDAP","1","1","N/A","N/A","8","1","0","1","2023-01-14T21:52:36Z","2022-11-16T00:38:43Z","11020" +"*/SharpLocker.exe*",".{0,1000}\/SharpLocker\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11021" +"*/SharpLocker.exe*",".{0,1000}\/SharpLocker\.exe.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","1","N/A","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","11022" +"*/SharpLocker.git*",".{0,1000}\/SharpLocker\.git.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","1","N/A","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","11023" +"*/SharpLocker/releases/*",".{0,1000}\/SharpLocker\/releases\/.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","1","N/A","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","11024" +"*/SharpLocker/zipball/*",".{0,1000}\/SharpLocker\/zipball\/.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","1","N/A","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","11025" +"*/SharpLogger.exe*",".{0,1000}\/SharpLogger\.exe.{0,1000}","offensive_tool_keyword","SharpLogger","Keylogger written in C#","T1056.001 - T1056.003","TA0005 - TA0006 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/djhohnstein/SharpLogger","1","1","N/A","N/A","10","2","126","41","2019-12-13T04:40:56Z","2018-12-18T01:45:17Z","11026" +"*/Sharpmad.exe*",".{0,1000}\/Sharpmad\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","Sharpmad","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11027" +"*/Sharpmad.exe*",".{0,1000}\/Sharpmad\.exe.{0,1000}","offensive_tool_keyword","Sharpmad","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","Sharpmad","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11028" +"*/SharpMapExec.exe*",".{0,1000}\/SharpMapExec\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11029" +"*/SharpMapExec.exe*",".{0,1000}\/SharpMapExec\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11030" +"*/SharpMapExec.exe*",".{0,1000}\/SharpMapExec\.exe.{0,1000}","offensive_tool_keyword","SharpMapExec","A sharpen version of CrackMapExec","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/cube0x0/SharpMapExec","1","1","N/A","N/A","10","7","664","124","2021-11-17T17:53:12Z","2020-12-01T13:03:50Z","11031" +"*/SharpMapExec.git*",".{0,1000}\/SharpMapExec\.git.{0,1000}","offensive_tool_keyword","SharpMapExec","A sharpen version of CrackMapExec","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/cube0x0/SharpMapExec","1","1","N/A","N/A","10","7","664","124","2021-11-17T17:53:12Z","2020-12-01T13:03:50Z","11032" +"*/SharpMiniDump.exe*",".{0,1000}\/SharpMiniDump\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11033" +"*/SharpMiniDump.exe*",".{0,1000}\/SharpMiniDump\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11034" +"*/SharpMiniDump.git*",".{0,1000}\/SharpMiniDump\.git.{0,1000}","offensive_tool_keyword","SharpMiniDump","Create a minidump of the LSASS process from memory","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/b4rtik/SharpMiniDump","1","1","N/A","N/A","10","3","260","49","2022-11-02T15:47:30Z","2019-09-15T13:45:42Z","11035" +"*/SharpMove.exe*",".{0,1000}\/SharpMove\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11036" +"*/SharpMove.exe*",".{0,1000}\/SharpMove\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpMove","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11037" +"*/SharpMove.exe*",".{0,1000}\/SharpMove\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11038" +"*/SharpMove.exe*",".{0,1000}\/SharpMove\.exe.{0,1000}","offensive_tool_keyword","SharpMove","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpMove","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11039" +"*/SharpMove.exe*",".{0,1000}\/SharpMove\.exe.{0,1000}","offensive_tool_keyword","SharpMove",".NET Project for performing Authenticated Remote Execution","T1021 - T1106 - T1218","TA0002 - TA0008","N/A","N/A","Lateral Movement","https://github.com/0xthirteen/SharpMove","1","1","N/A","N/A","8","4","393","66","2023-02-08T23:48:54Z","2020-01-24T22:21:04Z","11040" +"*/SharpMove.git*",".{0,1000}\/SharpMove\.git.{0,1000}","offensive_tool_keyword","SharpMove",".NET Project for performing Authenticated Remote Execution","T1021 - T1106 - T1218","TA0002 - TA0008","N/A","N/A","Lateral Movement","https://github.com/0xthirteen/SharpMove","1","1","N/A","N/A","8","4","393","66","2023-02-08T23:48:54Z","2020-01-24T22:21:04Z","11041" +"*/SharpNamedPipePTH.exe*",".{0,1000}\/SharpNamedPipePTH\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11042" +"*/SharpNamedPipePTH.exe*",".{0,1000}\/SharpNamedPipePTH\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11043" +"*/SharpNBTScan.git*",".{0,1000}\/SharpNBTScan\.git.{0,1000}","offensive_tool_keyword","SharpNBTScan","a NetBIOS scanner. Ghost actors use this tool for hostname and IP address enumeration","T1018 - T1046","TA0007","Ghost Ransomware","N/A","Discovery","https://github.com/BronzeTicket/SharpNBTScan","1","1","N/A","N/A","7","1","71","4","2021-08-06T05:36:55Z","2021-07-12T08:57:39Z","11044" +"*/SharpNetCheck.exe*",".{0,1000}\/SharpNetCheck\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11045" +"*/SharpNoPSExec*",".{0,1000}\/SharpNoPSExec.{0,1000}","offensive_tool_keyword","SharpNoPSExec","Get file less command execution for Lateral Movement.","T1021.006 - T1059.003 - T1105","TA0008 - TA0002 - TA0011","N/A","N/A","Lateral Movement","https://github.com/juliourena/SharpNoPSExec","1","1","N/A","N/A","10","7","615","90","2022-06-03T10:32:55Z","2021-04-24T22:02:38Z","11046" +"*/SharpNoPSExec.exe*",".{0,1000}\/SharpNoPSExec\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11047" +"*/SharpNoPSExec.exe*",".{0,1000}\/SharpNoPSExec\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11048" +"*/SharpOXID-Find.exe*",".{0,1000}\/SharpOXID\-Find\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11049" +"*/SharpOxidResolver.git*",".{0,1000}\/SharpOxidResolver\.git.{0,1000}","offensive_tool_keyword","SharpOxidResolver","search the current domain for computers and get bindings for all of them","T1018 - T1046 - T1016","TA0007","N/A","KNOTWEED","Discovery","https://github.com/S3cur3Th1sSh1t/SharpOxidResolver","1","1","N/A","N/A","9","1","50","9","2020-11-25T08:42:06Z","2020-11-25T08:23:23Z","11050" +"*/SharpOxidResolver/releases/download/*",".{0,1000}\/SharpOxidResolver\/releases\/download\/.{0,1000}","offensive_tool_keyword","SharpOxidResolver","search the current domain for computers and get bindings for all of them","T1018 - T1046 - T1016","TA0007","N/A","KNOTWEED","Discovery","https://github.com/S3cur3Th1sSh1t/SharpOxidResolver","1","1","N/A","N/A","9","1","50","9","2020-11-25T08:42:06Z","2020-11-25T08:23:23Z","11051" +"*/SharpPack.git*",".{0,1000}\/SharpPack\.git.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","11052" +"*/SharpPersistSD.dll*",".{0,1000}\/SharpPersistSD\.dll.{0,1000}","offensive_tool_keyword","SharpPersistSD","A Post-Compromise granular .NET library to embed persistency to persistency by abusing Security Descriptors of remote machines","T1547 - T1053 - T1027 - T1028 - T1112","TA0003 - TA0008","N/A","N/A","Persistence","https://github.com/cybersectroll/SharpPersistSD","1","1","N/A","N/A","10","1","87","12","2024-05-15T14:55:14Z","2024-05-13T15:11:12Z","11053" +"*/SharpPersistSD.git*",".{0,1000}\/SharpPersistSD\.git.{0,1000}","offensive_tool_keyword","SharpPersistSD","A Post-Compromise granular .NET library to embed persistency to persistency by abusing Security Descriptors of remote machines","T1547 - T1053 - T1027 - T1028 - T1112","TA0003 - TA0008","N/A","N/A","Persistence","https://github.com/cybersectroll/SharpPersistSD","1","1","N/A","N/A","10","1","87","12","2024-05-15T14:55:14Z","2024-05-13T15:11:12Z","11054" +"*/sharppick.exe*",".{0,1000}\/sharppick\.exe.{0,1000}","offensive_tool_keyword","Powerpick","allowing the execution of Powershell functionality without the use of Powershell.exe","T1059.001 - T1059.003 - T1086 - T1027.001","TA0005 - TA0002","N/A","Black Basta - Dispossessor","Defense Evasion","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","11055" +"*/SharpPrinter.exe*",".{0,1000}\/SharpPrinter\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11056" +"*/SharpPrinter.exe*",".{0,1000}\/SharpPrinter\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11057" +"*/SharpRDP.exe*",".{0,1000}\/SharpRDP\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11058" +"*/SharpRDP.exe*",".{0,1000}\/SharpRDP\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpRDP","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11059" +"*/SharpRDP.exe*",".{0,1000}\/SharpRDP\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11060" +"*/SharpRDP.exe*",".{0,1000}\/SharpRDP\.exe.{0,1000}","offensive_tool_keyword","SharpRDP","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpRDP","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11061" +"*/SharpRDP.git*",".{0,1000}\/SharpRDP\.git.{0,1000}","offensive_tool_keyword","SharpRDP","Remote Desktop Protocol .NET Console Application for Authenticated Command Execution","T1021.001 - T1059.001 - T1059.003","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/0xthirteen/SharpRDP","1","1","N/A","N/A","10","10","1041","554","2022-11-13T05:29:33Z","2020-01-21T08:31:50Z","11062" +"*/SharpRDPHijack*",".{0,1000}\/SharpRDPHijack.{0,1000}","offensive_tool_keyword","SharpRDPHijack","SharpRDPHijack is a proof-of-concept .NET/C# Remote Desktop Protocol (RDP) session hijack utility for disconnected sessions","T1021.001 - T1078.003 - T1059.001","TA0002 - TA0008 - TA0006","N/A","N/A","Lateral Movement","https://github.com/bohops/SharpRDPHijack","1","1","N/A","N/A","10","5","480","80","2024-11-28T06:08:58Z","2020-07-06T02:59:46Z","11063" +"*/SharpRDPThief.git*",".{0,1000}\/SharpRDPThief\.git.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","1","N/A","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","11064" +"*/SharpReg.exe*",".{0,1000}\/SharpReg\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11065" +"*/SharpReg.exe*",".{0,1000}\/SharpReg\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11066" +"*/SharpRoast.exe*",".{0,1000}\/SharpRoast\.exe.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","11067" +"*/SharpRODC.git*",".{0,1000}\/SharpRODC\.git.{0,1000}","offensive_tool_keyword","SharpRODC","audit the security of read-only domain controllers","T1012 - T1482 - T1207 - T1208 - T1209 - T1212","TA0007 - TA0008 - TA0006","N/A","N/A","Discovery","https://github.com/wh0amitz/SharpRODC","1","1","N/A","N/A","8","2","115","8","2023-11-27T12:41:52Z","2023-11-24T14:35:49Z","11068" +"*/SharpSAMDump.git*",".{0,1000}\/SharpSAMDump\.git.{0,1000}","offensive_tool_keyword","SharpSAMDump","SAM dumping via the registry in C#/.NET","T1003.002 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/jojonas/SharpSAMDump","1","1","N/A","N/A","10","1","48","8","2025-01-16T07:08:58Z","2024-05-27T10:53:27Z","11069" +"*/SharpSC.exe*",".{0,1000}\/SharpSC\.exe.{0,1000}","offensive_tool_keyword","SharpSC",".NET assembly to interact with services. (included in powershell empire)","T1543.003","TA0003","N/A","N/A","Persistence","https://github.com/djhohnstein/SharpSC","1","1","N/A","N/A","8","1","40","6","2019-09-27T23:04:24Z","2019-09-24T21:05:38Z","11070" +"*/SharpSC.git*",".{0,1000}\/SharpSC\.git.{0,1000}","offensive_tool_keyword","SharpSC",".NET assembly to interact with services. (included in powershell empire)","T1543.003","TA0003","N/A","N/A","Persistence","https://github.com/djhohnstein/SharpSC","1","1","N/A","N/A","8","1","40","6","2019-09-27T23:04:24Z","2019-09-24T21:05:38Z","11071" +"*/SharpSCCM.exe*",".{0,1000}\/SharpSCCM\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11072" +"*/SharpSCCM.exe*",".{0,1000}\/SharpSCCM\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpSCCM","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11073" +"*/SharpSCCM.exe*",".{0,1000}\/SharpSCCM\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11074" +"*/SharpSCCM.exe*",".{0,1000}\/SharpSCCM\.exe.{0,1000}","offensive_tool_keyword","SharpSCCM","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpSCCM","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11075" +"*/SharpSCCM.git*",".{0,1000}\/SharpSCCM\.git.{0,1000}","offensive_tool_keyword","SharpSCCM","SharpSCCM is a post-exploitation tool designed to leverage Microsoft Endpoint Configuration Manager (a.k.a. ConfigMgr. formerly SCCM) for Lateral Movement and credential gathering without requiring access to the SCCM administration console GUI","T1078 - T1077 - T1547.001 - T1021.001 - T1087 - T1555.003","TA0008 - TA0006 - TA0003 - TA0011","N/A","N/A","Lateral Movement","https://github.com/Mayyhem/SharpSCCM/","1","1","N/A","N/A","10","7","626","94","2024-09-16T14:57:49Z","2021-08-19T05:09:19Z","11076" +"*/SharpSCCM/releases/download/*",".{0,1000}\/SharpSCCM\/releases\/download\/.{0,1000}","offensive_tool_keyword","SharpSCCM","SharpSCCM is a post-exploitation tool designed to leverage Microsoft Endpoint Configuration Manager (a.k.a. ConfigMgr. formerly SCCM) for Lateral Movement and credential gathering without requiring access to the SCCM administration console GUI","T1078 - T1077 - T1547.001 - T1021.001 - T1087 - T1555.003","TA0008 - TA0006 - TA0003 - TA0011","N/A","N/A","Lateral Movement","https://github.com/Mayyhem/SharpSCCM/","1","1","N/A","N/A","10","7","626","94","2024-09-16T14:57:49Z","2021-08-19T05:09:19Z","11077" +"*/SharpSCshell.exe*",".{0,1000}\/SharpSCshell\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11078" +"*/SharpSearch.exe*",".{0,1000}\/SharpSearch\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11079" +"*/SharpSearch.exe*",".{0,1000}\/SharpSearch\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11080" +"*/SharpSecDump.exe*",".{0,1000}\/SharpSecDump\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11081" +"*/SharpSecDump.exe*",".{0,1000}\/SharpSecDump\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11082" +"*/SharpSecDump.git*",".{0,1000}\/SharpSecDump\.git.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","1","N/A","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","11083" +"*/SharpShares.exe*",".{0,1000}\/SharpShares\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11084" +"*/SharpShares.exe*",".{0,1000}\/SharpShares\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11085" +"*/SharpShares.exe*",".{0,1000}\/SharpShares\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11086" +"*/SharpShares.git*",".{0,1000}\/SharpShares\.git.{0,1000}","offensive_tool_keyword","SharpShares","Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain","T1046 - T1135","TA0007 - TA0001","N/A","BlackSuit - Royal - BianLian - Fog","Discovery","https://github.com/Hackcraft-Labs/SharpShares","1","1","N/A","N/A","10","1","33","7","2023-11-13T14:08:07Z","2023-10-25T10:34:18Z","11087" +"*/SharpShares/Enums*",".{0,1000}\/SharpShares\/Enums.{0,1000}","offensive_tool_keyword","SMBeagle","SMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host.","T1087.002 - T1021.002 - T1210","TA0007 - TA0008 - TA0003","N/A","N/A","Discovery","https://github.com/punk-security/SMBeagle","1","1","N/A","N/A","9","8","712","80","2025-01-21T22:34:00Z","2021-05-31T19:46:57Z","11088" +"*/SharpShares/releases/download/*",".{0,1000}\/SharpShares\/releases\/download\/.{0,1000}","offensive_tool_keyword","SharpShares","Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain","T1046 - T1135","TA0007 - TA0001","N/A","BlackSuit - Royal - BianLian - Fog","Discovery","https://github.com/mitchmoser/SharpShares","1","1","N/A","N/A","10","4","351","49","2021-09-21T08:14:27Z","2020-09-25T22:35:57Z","11089" +"*/SharpShellPipe.git*",".{0,1000}\/SharpShellPipe\.git.{0,1000}","offensive_tool_keyword","SharpShellPipe","interactive remote shell access via named pipes and the SMB protocol.","T1056.002 - T1021.002 - T1059.001","TA0005 - TA0009 - TA0002","N/A","N/A","Lateral Movement","https://github.com/DarkCoderSc/SharpShellPipe","1","1","N/A","N/A","8","2","118","14","2025-02-21T12:33:43Z","2023-08-25T15:18:30Z","11091" +"*/SharpShooter.git*",".{0,1000}\/SharpShooter\.git.{0,1000}","offensive_tool_keyword","SharpShooter","Payload Generation Framework","T1027 - T1059","TA0042","N/A","N/A","Resource Development","https://github.com/mdsecactivebreach/SharpShooter","1","1","N/A","N/A","10","10","1859","361","2024-08-21T12:09:54Z","2018-03-06T20:04:20Z","11092" +"*/Sharp-SMBExec.exe*",".{0,1000}\/Sharp\-SMBExec\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11093" +"*/Sharp-SMBExec.exe*",".{0,1000}\/Sharp\-SMBExec\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta - APT20 - PowerPool","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11094" +"*/SharpSniper.exe*",".{0,1000}\/SharpSniper\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11095" +"*/SharpSniper.exe*",".{0,1000}\/SharpSniper\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11096" +"*/SharpSocks*",".{0,1000}\/SharpSocks.{0,1000}","offensive_tool_keyword","SharpSocks","Tunnellable HTTP/HTTPS socks4a proxy written in C# and deployable via PowerShell","T1090 - T1021.001","TA0002","N/A","N/A","C2","https://github.com/nettitude/SharpSocks","1","1","N/A","N/A","10","10","482","84","2023-03-15T19:19:30Z","2017-11-10T13:29:08Z","11097" +"*/sharpsocks.log*",".{0,1000}\/sharpsocks\.log.{0,1000}","offensive_tool_keyword","shad0w","A post exploitation framework designed to operate covertly on heavily monitored environments","T1071 - T1090 - T1105 - T1571 - T1001","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/bats3c/shad0w","1","1","#logfile #linux","N/A","N/A","10","2090","332","2021-09-29T00:15:36Z","2020-04-28T16:42:07Z","11098" +"*/SharpSocksServerCore.dll*",".{0,1000}\/SharpSocksServerCore\.dll.{0,1000}","offensive_tool_keyword","shad0w","A post exploitation framework designed to operate covertly on heavily monitored environments","T1071 - T1090 - T1105 - T1571 - T1001","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/bats3c/shad0w","1","1","N/A","N/A","N/A","10","2090","332","2021-09-29T00:15:36Z","2020-04-28T16:42:07Z","11099" +"*/SharpSphere.exe*",".{0,1000}\/SharpSphere\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11100" +"*/SharpSphere.exe*",".{0,1000}\/SharpSphere\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11101" +"*/SharpSploit*",".{0,1000}\/SharpSploit.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","11102" +"*/SharpSploit.dll*",".{0,1000}\/SharpSploit\.dll.{0,1000}","offensive_tool_keyword","SharpSploitConsole","Console Application designed to interact with SharpSploit","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/anthemtotheego/SharpSploitConsole","1","1","N/A","N/A","10","2","182","36","2022-02-21T15:12:26Z","2018-10-02T18:57:46Z","11103" +"*/SharpSploit.git*",".{0,1000}\/SharpSploit\.git.{0,1000}","offensive_tool_keyword","SharpSploit","SharpSploit is a .NET post-exploitation library written in C# that aims to highlight the attack surface of .NET and make the use of offensive .NET easier for red teamers.","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/cobbr/SharpSploit","1","1","N/A","N/A","10","10","1789","312","2021-08-12T18:23:15Z","2018-09-20T14:22:37Z","11104" +"*/SharpSploit/*",".{0,1000}\/SharpSploit\/.{0,1000}","offensive_tool_keyword","SharpBlock","A method of bypassing EDR active projection DLL by preventing entry point exection","T1070.004 - T1055.001 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/CCob/SharpBlock","1","1","N/A","N/A","10","10","1140","160","2021-03-31T09:44:48Z","2020-06-14T10:32:16Z","11105" +"*/SharpSploitConsole.git*",".{0,1000}\/SharpSploitConsole\.git.{0,1000}","offensive_tool_keyword","SharpSploitConsole","Console Application designed to interact with SharpSploit","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/anthemtotheego/SharpSploitConsole","1","1","N/A","N/A","10","2","182","36","2022-02-21T15:12:26Z","2018-10-02T18:57:46Z","11106" +"*/SharpSpoolTrigger*",".{0,1000}\/SharpSpoolTrigger.{0,1000}","offensive_tool_keyword","SharpSystemTriggers","Collection of remote authentication triggers in C#","T1078 - T1059.001 - T1550","TA0008 ","N/A","N/A","Lateral Movement","https://github.com/cube0x0/SharpSystemTriggers","1","1","N/A","N/A","10","5","483","57","2024-05-15T21:24:56Z","2021-09-12T18:18:15Z","11107" +"*/SharpSpray.exe*",".{0,1000}\/SharpSpray\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11108" +"*/SharpSpray.exe*",".{0,1000}\/SharpSpray\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11109" +"*/SharpSpray.exe*",".{0,1000}\/SharpSpray\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11110" +"*/SharpSpray.exe*",".{0,1000}\/SharpSpray\.exe.{0,1000}","offensive_tool_keyword","SharpDomainSpray","Basic password spraying tool for internal tests and red teaming","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/HunnicCyber/SharpDomainSpray","1","1","N/A","N/A","10","1","90","18","2020-03-21T09:17:48Z","2019-06-05T10:47:05Z","11111" +"*/sharpspray.exe*",".{0,1000}\/sharpspray\.exe.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","1","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","11112" +"*/SharpSpray.git*",".{0,1000}\/SharpSpray\.git.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","1","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","11113" +"*/SharpSpray-1.1.zip*",".{0,1000}\/SharpSpray\-1\.1\.zip.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","1","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","11114" +"*/SharpSpray1.exe*",".{0,1000}\/SharpSpray1\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11115" +"*/SharpSQL.exe*",".{0,1000}\/SharpSQL\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpSQL","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11116" +"*/SharpSQL.exe*",".{0,1000}\/SharpSQL\.exe.{0,1000}","offensive_tool_keyword","SharpSQL","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpSQL","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11117" +"*/SharpSQLDump.exe*",".{0,1000}\/SharpSQLDump\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11118" +"*/SharpSQLPwn.exe*",".{0,1000}\/SharpSQLPwn\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11119" +"*/SharpSQLPwn.exe*",".{0,1000}\/SharpSQLPwn\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11120" +"*/SharpSQLTools.exe*",".{0,1000}\/SharpSQLTools\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11121" +"*/SharpSSDP.git*",".{0,1000}\/SharpSSDP\.git.{0,1000}","offensive_tool_keyword","SharpSSDP"," execute SharpSSDP.exe through Cobalt Strike's Beacon ""execute-assembly"" module to discover SSDP related services","T1046 - T1016","TA0007 - TA0005","N/A","N/A","Discovery","https://github.com/rvrsh3ll/SharpSSDP","1","1","N/A","N/A","7","1","17","4","2018-12-16T17:14:28Z","2018-12-16T17:14:12Z","11122" +"*/SharpSSDP/*",".{0,1000}\/SharpSSDP\/.{0,1000}","offensive_tool_keyword","SharpSSDP"," execute SharpSSDP.exe through Cobalt Strike's Beacon ""execute-assembly"" module to discover SSDP related services","T1046 - T1016","TA0007 - TA0005","N/A","N/A","Discovery","https://github.com/rvrsh3ll/SharpSSDP","1","1","N/A","N/A","7","1","17","4","2018-12-16T17:14:28Z","2018-12-16T17:14:12Z","11123" +"*/SharpStay.exe*",".{0,1000}\/SharpStay\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11124" +"*/SharpStay.exe*",".{0,1000}\/SharpStay\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11125" +"*/SharpStay.exe*",".{0,1000}\/SharpStay\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11126" +"*/SharpStay.git*",".{0,1000}\/SharpStay\.git.{0,1000}","offensive_tool_keyword","SharpStay","SharpStay - .NET Persistence","T1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123","TA0003","N/A","N/A","Persistence","https://github.com/0xthirteen/SharpStay","1","1","N/A","N/A","10","5","475","97","2024-06-26T15:54:52Z","2020-01-24T22:22:07Z","11127" +"*/SharpStay/*",".{0,1000}\/SharpStay\/.{0,1000}","offensive_tool_keyword","SharpStay","SharpStay - .NET Persistence","T1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123","TA0003","N/A","N/A","Persistence","https://github.com/0xthirteen/SharpStay","1","1","N/A","N/A","10","5","475","97","2024-06-26T15:54:52Z","2020-01-24T22:22:07Z","11128" +"*/SharpSvc.exe*",".{0,1000}\/SharpSvc\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11129" +"*/SharpSvc.exe*",".{0,1000}\/SharpSvc\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11130" +"*/SharpSword.git*",".{0,1000}\/SharpSword\.git.{0,1000}","offensive_tool_keyword","SharpSword","Read the contents of MS Word Documents using Cobalt Strike's Execute-Assembly","T1562.004 - T1059.001 - T1021.003","TA0005 - TA0002","N/A","N/A","C2","https://github.com/OG-Sadpanda/SharpSword","1","1","N/A","N/A","8","10","117","11","2024-09-30T15:21:25Z","2021-07-15T14:50:05Z","11131" +"*/SharpSword/SharpSword*",".{0,1000}\/SharpSword\/SharpSword.{0,1000}","offensive_tool_keyword","cobaltstrike","Read the contents of DOCX files using Cobalt Strike's Execute-Assembly","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OG-Sadpanda/SharpSword","1","1","N/A","N/A","10","10","117","11","2024-09-30T15:21:25Z","2021-07-15T14:50:05Z","11132" +"*/SharpSystemTriggers*",".{0,1000}\/SharpSystemTriggers.{0,1000}","offensive_tool_keyword","SharpSystemTriggers","Collection of remote authentication triggers in C#","T1078 - T1059.001 - T1550","TA0008 ","N/A","N/A","Lateral Movement","https://github.com/cube0x0/SharpSystemTriggers","1","1","N/A","N/A","10","5","483","57","2024-05-15T21:24:56Z","2021-09-12T18:18:15Z","11133" +"*/SharpTask.exe*",".{0,1000}\/SharpTask\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11134" +"*/SharpTask.exe*",".{0,1000}\/SharpTask\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11135" +"*/SharpTask.exe*",".{0,1000}\/SharpTask\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11136" +"*/SharpTerminator/*",".{0,1000}\/SharpTerminator\/.{0,1000}","offensive_tool_keyword","SharpTerminator","Terminate AV/EDR Processes using kernel driver","T1055.003 - T1547.001 - T1053.005 - T1091 - T1014 - T1053.006 - T1053.004 - T1112 - T1112.001","TA0007 - TA0008 - TA0006 - TA0002","N/A","N/A","Exploitation tool","https://github.com/mertdas/SharpTerminator","1","1","N/A","N/A","10","4","341","66","2023-06-12T00:38:54Z","2023-06-11T06:35:51Z","11137" +"*/SharpThief.git*",".{0,1000}\/SharpThief\.git.{0,1000}","offensive_tool_keyword","SharpThief","A one-click program to steal the icon, resource information, version information, modification time, and digital signature (invalid) to make the program appear legitimate","T1036 - T1070 - T1078 - T1027 - T1202","TA0005 - TA0002 - TA0001","N/A","N/A","Defense Evasion","https://github.com/INotGreen/SharpThief","1","1","N/A","N/A","8","4","372","37","2024-12-17T05:46:39Z","2024-03-05T05:34:50Z","11138" +"*/SharpThief/tarball*",".{0,1000}\/SharpThief\/tarball.{0,1000}","offensive_tool_keyword","SharpThief","A one-click program to steal the icon, resource information, version information, modification time, and digital signature (invalid) to make the program appear legitimate","T1036 - T1070 - T1078 - T1027 - T1202","TA0005 - TA0002 - TA0001","N/A","N/A","Defense Evasion","https://github.com/INotGreen/SharpThief","1","1","N/A","N/A","8","4","372","37","2024-12-17T05:46:39Z","2024-03-05T05:34:50Z","11139" +"*/SharpThief/zipball*",".{0,1000}\/SharpThief\/zipball.{0,1000}","offensive_tool_keyword","SharpThief","A one-click program to steal the icon, resource information, version information, modification time, and digital signature (invalid) to make the program appear legitimate","T1036 - T1070 - T1078 - T1027 - T1202","TA0005 - TA0002 - TA0001","N/A","N/A","Defense Evasion","https://github.com/INotGreen/SharpThief","1","1","N/A","N/A","8","4","372","37","2024-12-17T05:46:39Z","2024-03-05T05:34:50Z","11140" +"*/SharpToken/releases/download/*",".{0,1000}\/SharpToken\/releases\/download\/.{0,1000}","offensive_tool_keyword","SharpToken","SharpToken is a tool for exploiting Token leaks. It can find leaked Tokens from all processes in the system and use them","T1134 - T1101 - T1214 - T1087 - T1038","TA0004 - TA0007","N/A","N/A","Exploitation tool","https://github.com/BeichenDream/SharpToken","1","1","N/A","N/A","N/A","5","467","66","2023-11-24T19:21:57Z","2022-06-30T07:34:57Z","11141" +"*/SharpTokenFinder.exe*",".{0,1000}\/SharpTokenFinder\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11142" +"*/SharpUnhooker.git*",".{0,1000}\/SharpUnhooker\.git.{0,1000}","offensive_tool_keyword","SharpUnhooker","C# Based Universal API Unhooker","T1055.012 - T1070.004 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/GetRektBoy724/SharpUnhooker","1","1","N/A","N/A","9","5","400","80","2022-02-18T13:11:11Z","2021-05-17T01:33:38Z","11143" +"*/SharpUp.exe*",".{0,1000}\/SharpUp\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11144" +"*/SharpUp.exe*",".{0,1000}\/SharpUp\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpUp","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11145" +"*/SharpUp.exe*",".{0,1000}\/SharpUp\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11146" +"*/SharpUp.exe*",".{0,1000}\/SharpUp\.exe.{0,1000}","offensive_tool_keyword","SharpUp","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpUp","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11147" +"*/SharpUp.git*",".{0,1000}\/SharpUp\.git.{0,1000}","offensive_tool_keyword","SharpUp","SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.","T1003 - T1082 - T1057 - T1069 - T1083","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/GhostPack/SharpUp","1","1","N/A","N/A","N/A","10","1344","253","2024-02-14T16:38:26Z","2018-07-24T17:39:33Z","11148" +"*/SharpVeeamDecryptor.*",".{0,1000}\/SharpVeeamDecryptor\..{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","1","N/A","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","11149" +"*/SharpView.exe*",".{0,1000}\/SharpView\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11150" +"*/SharpView.exe*",".{0,1000}\/SharpView\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpView","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11151" +"*/SharpView.exe*",".{0,1000}\/SharpView\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta - APT29","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11152" +"*/SharpView.exe*",".{0,1000}\/SharpView\.exe.{0,1000}","offensive_tool_keyword","SharpView","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpView","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","11153" +"*/SharpView.git*",".{0,1000}\/SharpView\.git.{0,1000}","offensive_tool_keyword","SharpView","C# implementation of harmj0y's PowerView","T1018 - T1482 - T1087.002 - T1069.002","TA0007 - TA0003 - TA0001","N/A","Conti - APT29","Discovery","https://github.com/tevora-threat/SharpView/","1","1","N/A","N/A","10","10","1032","196","2024-03-22T16:34:09Z","2018-07-24T21:15:04Z","11154" +"*/SharpWeb.dll*",".{0,1000}\/SharpWeb\.dll.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","11155" +"*/SharpWeb.exe*",".{0,1000}\/SharpWeb\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11156" +"*/SharpWeb.exe*",".{0,1000}\/SharpWeb\.exe.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","1","N/A","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","11157" +"*/SharpWeb.git*",".{0,1000}\/SharpWeb\.git.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","1","N/A","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","11158" +"*/SharpWebScan.exe*",".{0,1000}\/SharpWebScan\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11159" +"*/SharpWebServer.exe*",".{0,1000}\/SharpWebServer\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11160" +"*/SharpWebServer.exe*",".{0,1000}\/SharpWebServer\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11161" +"*/SharpWifiGrabber.exe*",".{0,1000}\/SharpWifiGrabber\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11162" +"*/SharpWifiGrabber.exe*",".{0,1000}\/SharpWifiGrabber\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11163" +"*/SharpWifiGrabber.exe*",".{0,1000}\/SharpWifiGrabber\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11164" +"*/sharpwmi.exe*",".{0,1000}\/sharpwmi\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11165" +"*/SharpWMI.exe*",".{0,1000}\/SharpWMI\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11166" +"*/SharpWMI.exe*",".{0,1000}\/SharpWMI\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11167" +"*/SharpWSManWinRM.vbs*",".{0,1000}\/SharpWSManWinRM\.vbs.{0,1000}","offensive_tool_keyword","WSMan-WinRM","remote commands over WinRM using the WSMan.Automation COM object","T1021.004 - T1059.001","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/bohops/WSMan-WinRM","1","1","N/A","N/A","10","3","236","40","2020-05-12T16:49:01Z","2020-05-12T01:30:42Z","11168" +"*/SharpWSUS*",".{0,1000}\/SharpWSUS.{0,1000}","offensive_tool_keyword","SharpWSUS","SharpWSUS is a CSharp tool for Lateral Movement through WSUS","T1047 - T1021.002 - T1021.003 - T1077 - T1069 - T1057 - T1105 - T1028 - T1070.004 - T1053 - T1086 - T1106 - T1059","TA0002 - TA0003 - TA0008","N/A","Black Basta","Lateral Movement","https://github.com/nettitude/SharpWSUS","1","1","N/A","N/A","N/A","5","452","77","2022-11-20T23:41:40Z","2022-05-04T08:27:57Z","11169" +"*/SharpXDecrypt.exe*",".{0,1000}\/SharpXDecrypt\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11170" +"*/SharPyShell*",".{0,1000}\/SharPyShell.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","11171" +"*/SharpZeroLogon.exe*",".{0,1000}\/SharpZeroLogon\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11172" +"*/SharpZeroLogon.exe*",".{0,1000}\/SharpZeroLogon\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11173" +"*/SharpZeroLogon.exe*",".{0,1000}\/SharpZeroLogon\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11174" +"*/SharpZeroLogon.git*",".{0,1000}\/SharpZeroLogon\.git.{0,1000}","offensive_tool_keyword","SharpZeroLogon","exploit for CVE-2020-1472","T1210 - T1558.003 - T1078.002 - T1098 - T1003.006","TA0001 - TA0004 - TA0005 - TA0006 - TA0003","Ghost Ransomware","N/A","Exploitation tool","https://github.com/leitosama/SharpZeroLogon","1","1","N/A","N/A","10","1","27","17","2021-02-13T10:13:32Z","2021-02-13T09:44:43Z","11175" +"*/Shell/reflect.jsp?u=http://*",".{0,1000}\/Shell\/reflect\.jsp\?u\=http\:\/\/.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","11176" +"*/shell/shell_port.*",".{0,1000}\/shell\/shell_port\..{0,1000}","offensive_tool_keyword","Heroinn","A cross platform C2/post-exploitation framework implementation by Rust.","T1027 - T1033 - T1055 - T1071 - T1082 - T1105 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/b23r0/Heroinn","1","1","N/A","N/A","10","10","672","215","2022-10-08T07:27:38Z","2015-05-16T14:54:19Z","11177" +"*/shell?cmd=whoami*",".{0,1000}\/shell\?cmd\=whoami.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","11178" +"*/shell?k=*&ip=*&cmd=*",".{0,1000}\/shell\?k\=.{0,1000}\&ip\=.{0,1000}\&cmd\=.{0,1000}","offensive_tool_keyword","SecScanC2","SecScanC2 can manage assetment to create P2P network for security scanning & C2. The tool can assist security researchers in conducting penetration testing more efficiently - preventing scanning from being blocked - protecting themselves from being traced.","T1021 - T1090","TA0011 - TA0002 - TA0040 - TA0043","N/A","N/A","C2","https://github.com/T1esh0u/SecScanC2","1","1","#P2P","N/A","10","","N/A","","","","11179" +"*/shell_exec.py*",".{0,1000}\/shell_exec\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","11180" +"*/Shell3er.git*",".{0,1000}\/Shell3er\.git.{0,1000}","offensive_tool_keyword","Shell3er","PowerShell Reverse Shell","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/yehia-mamdouh/Shell3er","1","1","N/A","N/A","9","10","61","14","2023-05-07T16:02:41Z","2023-05-07T15:35:16Z","11181" +"*/Shell3er.ps1*",".{0,1000}\/Shell3er\.ps1.{0,1000}","offensive_tool_keyword","Shell3er","PowerShell Reverse Shell","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/yehia-mamdouh/Shell3er","1","1","N/A","N/A","9","10","61","14","2023-05-07T16:02:41Z","2023-05-07T15:35:16Z","11182" +"*/Shell3er/*",".{0,1000}\/Shell3er\/.{0,1000}","offensive_tool_keyword","Shell3er","PowerShell Reverse Shell","T1059.001 - T1021.004 - T1090.002","TA0002 - TA0011","N/A","N/A","C2","https://github.com/yehia-mamdouh/Shell3er/blob/main/Shell3er.ps1","1","1","N/A","N/A","N/A","10","61","14","2023-05-07T16:02:41Z","2023-05-07T15:35:16Z","11183" +"*/shellcode*loader.bin*",".{0,1000}\/shellcode.{0,1000}loader\.bin.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","11184" +"*/shellcode.bin.*",".{0,1000}\/shellcode\.bin\..{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","11186" +"*/shellcode.hpp*",".{0,1000}\/shellcode\.hpp.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","11188" +"*/shellcode_callback.exe*",".{0,1000}\/shellcode_callback\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","11190" +"*/shellcode_excel*",".{0,1000}\/shellcode_excel.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","11191" +"*/shellcode_generate.py*",".{0,1000}\/shellcode_generate\.py.{0,1000}","offensive_tool_keyword","canisrufus","A stealthy Python based Windows backdoor that uses Github as a command and control server","T1105 - T1071 - T1027","TA0003 - TA0011 - TA0005 - TA0010","N/A","Black Basta","C2","https://github.com/maldevel/canisrufus","1","1","N/A","N/A","10","10","263","78","2017-08-15T15:46:20Z","2017-08-12T06:49:40Z","11192" +"*/ShellCode_Loader*",".{0,1000}\/ShellCode_Loader.{0,1000}","offensive_tool_keyword","cobaltstrike","ShellCode_Loader - Msf&CobaltStrike Antivirus ShellCode loader. Shellcode_encryption - Antivirus Shellcode encryption generation tool. currently tested for Antivirus 360 & Huorong & Computer Manager & Windows Defender (other antivirus software not tested).","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Axx8/ShellCode_Loader","1","1","N/A","N/A","10","10","412","47","2022-09-20T07:24:25Z","2022-09-02T14:41:18Z","11193" +"*/shellcode_samples/*",".{0,1000}\/shellcode_samples\/.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","11194" +"*/shellcode_sources/*",".{0,1000}\/shellcode_sources\/.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","11195" +"*/shellcode2vba.py*",".{0,1000}\/shellcode2vba\.py.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","11196" +"*/shellcode2vbafunc.py*",".{0,1000}\/shellcode2vbafunc\.py.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","11197" +"*/ShellcodeFluctuation*",".{0,1000}\/ShellcodeFluctuation.{0,1000}","offensive_tool_keyword","C2 related tools","An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/mgeeky/ShellcodeFluctuation","1","1","N/A","N/A","10","10","1012","160","2022-06-17T18:07:33Z","2021-09-29T10:24:52Z","11198" +"*/Shellcode-Hide.git*",".{0,1000}\/Shellcode\-Hide\.git.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","11199" +"*/SHELLCODELOADER*",".{0,1000}\/SHELLCODELOADER.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","11200" +"*/Shellcode-Loader.git*",".{0,1000}\/Shellcode\-Loader\.git.{0,1000}","offensive_tool_keyword","Shellcode-Loader","dynamic shellcode loading","T1055 - T1055.012 - T1027 - T1027.005","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/ReversingID/Shellcode-Loader","1","1","N/A","N/A","10","3","244","44","2025-01-25T16:30:56Z","2021-08-08T08:53:03Z","11201" +"*/shellcodes/utils.py*",".{0,1000}\/shellcodes\/utils\.py.{0,1000}","offensive_tool_keyword","HRShell","HRShell is an HTTPS/HTTP reverse shell built with flask. It is an advanced C2 server with many features & capabilities.","T1021.002 - T1105 - T1059.001 - T1059.003 - T1064","TA0008 - TA0011 - TA0002","N/A","Black Basta","C2","https://github.com/chrispetrou/HRShell","1","1","N/A","N/A","10","10","247","70","2021-09-09T08:26:32Z","2019-08-20T15:24:46Z","11202" +"*/shellcodetester*",".{0,1000}\/shellcodetester.{0,1000}","offensive_tool_keyword","shellcodetester","This tools test generated ShellCodes","T1059.003 - T1059.005 - T1027.002","TA0002 - TA0005 - TA0040","N/A","N/A","Resource Development","https://github.com/helviojunior/shellcodetester","1","1","N/A","N/A","N/A","1","92","30","2024-11-06T00:48:22Z","2019-06-11T04:39:58Z","11203" +"*/shellcode-xor.py*",".{0,1000}\/shellcode\-xor\.py.{0,1000}","offensive_tool_keyword","killer","evade AVs and EDRs or security tools","T1564 - T1027 - T1070","TA0005","N/A","N/A","Defense Evasion","https://github.com/0xHossam/Killer","1","1","N/A","N/A","10","9","804","128","2024-07-02T10:24:43Z","2023-04-08T16:29:52Z","11204" +"*/ShellGen.git*",".{0,1000}\/ShellGen\.git.{0,1000}","offensive_tool_keyword","ShellGen","PowerShell script to generate ShellCode in various formats","T1059.001 - T1588","TA0042","N/A","N/A","Resource Development","https://github.com/Leo4j/ShellGen","1","1","N/A","N/A","7","1","41","10","2024-09-25T09:29:13Z","2024-08-22T13:32:06Z","11205" +"*/ShellGen.ps1*",".{0,1000}\/ShellGen\.ps1.{0,1000}","offensive_tool_keyword","ShellGen","PowerShell script to generate ShellCode in various formats","T1059.001 - T1588","TA0042","N/A","N/A","Resource Development","https://github.com/Leo4j/ShellGen","1","1","N/A","N/A","7","1","41","10","2024-09-25T09:29:13Z","2024-08-22T13:32:06Z","11206" +"*/ShellGhost.git*",".{0,1000}\/ShellGhost\.git.{0,1000}","offensive_tool_keyword","ShellGhost","A memory-based evasion technique which makes shellcode invisible from process start to end","T1055.012 - T1027.002 - T1055.001","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/lem0nSec/ShellGhost","1","1","N/A","N/A","N/A","10","1175","140","2023-10-16T06:40:24Z","2023-07-01T16:56:58Z","11207" +"*/shellinject*",".{0,1000}\/shellinject.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","11208" +"*/ShellPwnsh.git*",".{0,1000}\/ShellPwnsh\.git.{0,1000}","offensive_tool_keyword","ShellPwnsh","Reverse Shell in Golang and PowerShell Fud","T1059.001 - T1573.002 - T1105","TA0011 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/BlackShell256/ShellPwnsh","1","1","N/A","N/A","9","10","9","6","2022-05-01T08:42:54Z","2022-04-28T01:26:08Z","11210" +"*/Shells/shell.aspx*",".{0,1000}\/Shells\/shell\.aspx.{0,1000}","offensive_tool_keyword","pyshell","PyShell is Multiplatform Python WebShell. This tool helps you to obtain a shell-like interface on a web server to be remotely accessed. Unlike other webshells the main goal of the tool is to use as little code as possible on the server side regardless of the language used or the operating system of the server.","T1059.001 - T1059.002 - T1059.005 - T1059.007","TA0002 - TA0003 - TA0009","N/A","N/A","Exploitation tool","https://github.com/JoelGMSec/PyShell","1","1","N/A","N/A","N/A","4","309","60","2024-09-27T11:11:56Z","2021-10-19T07:49:17Z","11211" +"*/Shells/shell.jsp*",".{0,1000}\/Shells\/shell\.jsp.{0,1000}","offensive_tool_keyword","pyshell","PyShell is Multiplatform Python WebShell. This tool helps you to obtain a shell-like interface on a web server to be remotely accessed. Unlike other webshells the main goal of the tool is to use as little code as possible on the server side regardless of the language used or the operating system of the server.","T1059.001 - T1059.002 - T1059.005 - T1059.007","TA0002 - TA0003 - TA0009","N/A","N/A","Exploitation tool","https://github.com/JoelGMSec/PyShell","1","1","N/A","N/A","N/A","4","309","60","2024-09-27T11:11:56Z","2021-10-19T07:49:17Z","11212" +"*/Shells/shell.php*",".{0,1000}\/Shells\/shell\.php.{0,1000}","offensive_tool_keyword","pyshell","PyShell is Multiplatform Python WebShell. This tool helps you to obtain a shell-like interface on a web server to be remotely accessed. Unlike other webshells the main goal of the tool is to use as little code as possible on the server side regardless of the language used or the operating system of the server.","T1059.001 - T1059.002 - T1059.005 - T1059.007","TA0002 - TA0003 - TA0009","N/A","N/A","Exploitation tool","https://github.com/JoelGMSec/PyShell","1","1","N/A","N/A","N/A","4","309","60","2024-09-27T11:11:56Z","2021-10-19T07:49:17Z","11213" +"*/Shells/shell.py*",".{0,1000}\/Shells\/shell\.py.{0,1000}","offensive_tool_keyword","pyshell","PyShell is Multiplatform Python WebShell. This tool helps you to obtain a shell-like interface on a web server to be remotely accessed. Unlike other webshells the main goal of the tool is to use as little code as possible on the server side regardless of the language used or the operating system of the server.","T1059.001 - T1059.002 - T1059.005 - T1059.007","TA0002 - TA0003 - TA0009","N/A","N/A","Exploitation tool","https://github.com/JoelGMSec/PyShell","1","1","N/A","N/A","N/A","4","309","60","2024-09-27T11:11:56Z","2021-10-19T07:49:17Z","11214" +"*/Shells/shell.sh*",".{0,1000}\/Shells\/shell\.sh.{0,1000}","offensive_tool_keyword","pyshell","PyShell is Multiplatform Python WebShell. This tool helps you to obtain a shell-like interface on a web server to be remotely accessed. Unlike other webshells the main goal of the tool is to use as little code as possible on the server side regardless of the language used or the operating system of the server.","T1059.001 - T1059.002 - T1059.005 - T1059.007","TA0002 - TA0003 - TA0009","N/A","N/A","Exploitation tool","https://github.com/JoelGMSec/PyShell","1","1","N/A","N/A","N/A","4","309","60","2024-09-27T11:11:56Z","2021-10-19T07:49:17Z","11215" +"*/Shells/tomcat.war*",".{0,1000}\/Shells\/tomcat\.war.{0,1000}","offensive_tool_keyword","pyshell","PyShell is Multiplatform Python WebShell. This tool helps you to obtain a shell-like interface on a web server to be remotely accessed. Unlike other webshells the main goal of the tool is to use as little code as possible on the server side regardless of the language used or the operating system of the server.","T1059.001 - T1059.002 - T1059.005 - T1059.007","TA0002 - TA0003 - TA0009","N/A","N/A","Exploitation tool","https://github.com/JoelGMSec/PyShell","1","1","N/A","N/A","N/A","4","309","60","2024-09-27T11:11:56Z","2021-10-19T07:49:17Z","11216" +"*/Shells/wordpress.zip*",".{0,1000}\/Shells\/wordpress\.zip.{0,1000}","offensive_tool_keyword","pyshell","PyShell is Multiplatform Python WebShell. This tool helps you to obtain a shell-like interface on a web server to be remotely accessed. Unlike other webshells the main goal of the tool is to use as little code as possible on the server side regardless of the language used or the operating system of the server.","T1059.001 - T1059.002 - T1059.005 - T1059.007","TA0002 - TA0003 - TA0009","N/A","N/A","Exploitation tool","https://github.com/JoelGMSec/PyShell","1","1","N/A","N/A","N/A","4","309","60","2024-09-27T11:11:56Z","2021-10-19T07:49:17Z","11217" +"*/ShellServe.git*",".{0,1000}\/ShellServe\.git.{0,1000}","offensive_tool_keyword","ShellServe","Multi-client network fileserver with integrated shell functionality crafted in C using system calls for efficient and direct file and command processing","T1059 - T1505 - T1046 - T1569","TA0002 - TA0007 - TA0003","N/A","N/A","Data Exfiltration","https://github.com/7etsuo/ShellServe","1","1","N/A","N/A","6","1","N/A","N/A","N/A","N/A","11218" +"*/shellshock.py*",".{0,1000}\/shellshock\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","11219" +"*/shellsilo.git*",".{0,1000}\/shellsilo\.git.{0,1000}","offensive_tool_keyword","shellsilo","cutting-edge tool that translates C syntax into syscall assembly and its corresponding shellcode","T1500 - T1588.002 - T1587.001 - T1546.015","TA0005 - TA0042","N/A","N/A","Resource Development","https://github.com/nixpal/shellsilo","1","1","N/A","N/A","6","2","132","13","2024-11-08T03:16:57Z","2024-03-08T02:04:04Z","11220" +"*/shellsilo.py*",".{0,1000}\/shellsilo\.py.{0,1000}","offensive_tool_keyword","shellsilo","cutting-edge tool that translates C syntax into syscall assembly and its corresponding shellcode","T1500 - T1588.002 - T1587.001 - T1546.015","TA0005 - TA0042","N/A","N/A","Resource Development","https://github.com/nixpal/shellsilo","1","1","N/A","N/A","6","2","132","13","2024-11-08T03:16:57Z","2024-03-08T02:04:04Z","11221" +"*/ShellSync.git*",".{0,1000}\/ShellSync\.git.{0,1000}","offensive_tool_keyword","ShellSync","exposing a server with suspicious scripts and executable from I-Am-Jakoby","T1059.003 - T1100 - T1027","TA0005 - TA0009 - TA0011 ","N/A","N/A","Data Exfiltration","https://github.com/I-Am-Jakoby/ShellSync","1","1","N/A","N/A","5","1","20","7","2023-11-08T18:01:18Z","2023-11-06T06:05:11Z","11222" +"*/ShellSync-main.zip*",".{0,1000}\/ShellSync\-main\.zip.{0,1000}","offensive_tool_keyword","ShellSync","exposing a server with suspicious scripts and executable from I-Am-Jakoby","T1059.003 - T1100 - T1027","TA0005 - TA0009 - TA0011 ","N/A","N/A","Data Exfiltration","https://github.com/I-Am-Jakoby/ShellSync","1","1","N/A","N/A","5","1","20","7","2023-11-08T18:01:18Z","2023-11-06T06:05:11Z","11223" +"*/sherlocksecurity/*",".{0,1000}\/sherlocksecurity\/.{0,1000}","offensive_tool_keyword","POC","POC and exploit tools on github","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/sherlocksecurity","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11224" +"*/Shhhavoc.py*",".{0,1000}\/Shhhavoc\.py.{0,1000}","offensive_tool_keyword","Shhhloader","shellcode loader that compiles a C++ stub to bypass AV/EDR","T1027 - T1055 - T1140 - T1218","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/icyguider/Shhhloader","1","1","N/A","N/A","9","10","1186","191","2024-05-08T20:24:35Z","2021-09-28T16:52:24Z","11225" +"*/Shhhloader.git*",".{0,1000}\/Shhhloader\.git.{0,1000}","offensive_tool_keyword","Shhhloader","shellcode loader that compiles a C++ stub to bypass AV/EDR","T1027 - T1055 - T1140 - T1218","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/icyguider/Shhhloader","1","1","N/A","N/A","9","10","1186","191","2024-05-08T20:24:35Z","2021-09-28T16:52:24Z","11226" +"*/Shhmon.exe*",".{0,1000}\/Shhmon\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11227" +"*/Shhmon.exe*",".{0,1000}\/Shhmon\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11228" +"*/Shhmon.exe*",".{0,1000}\/Shhmon\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11229" +"*/Shhmon/*",".{0,1000}\/Shhmon\/.{0,1000}","offensive_tool_keyword","shhmon","Neutering Sysmon via driver unload","T1518.001 ","TA0007","N/A","N/A","Defense Evasion","https://github.com/matterpreter/Shhmon","1","1","N/A","N/A","N/A","3","228","37","2022-10-13T16:56:41Z","2019-09-12T14:13:19Z","11230" +"*/ShimDB.git*",".{0,1000}\/ShimDB\.git.{0,1000}","offensive_tool_keyword","ShimDB","Shim database persistence (Fin7 TTP)","T1546.011","TA0003","N/A","N/A","Persistence","https://github.com/jackson5sec/ShimDB","1","1","N/A","N/A","9","1","37","10","2020-02-25T09:41:53Z","2018-06-21T00:38:10Z","11231" +"*/ShimMe.git*",".{0,1000}\/ShimMe\.git.{0,1000}","offensive_tool_keyword","ShimMe","Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.","T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070","TA0004 - TA0005 - TA0006 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/deepinstinct/ShimMe","1","1","N/A","N/A","9","2","140","20","2024-10-29T07:33:38Z","2024-08-04T10:03:28Z","11233" +"*/ShimsInstaller.*",".{0,1000}\/ShimsInstaller\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","11234" +"*/ShInject.exe*",".{0,1000}\/ShInject\.exe.{0,1000}","offensive_tool_keyword","OSEP-Code-Snippets","notable code snippets for Offensive Security's PEN-300 (OSEP) course","T1116 - T1204.002 - T1027.009 - T1021.005 - T1560.001 - T1100 - T1003.001 - T1564.001 - T1047 - T1210 - T1134.002 - T1055 - T1055.011 - T1055.012 - T1204","TA0005 - TA0040 - TA0008 - TA0003 - TA0006 - TA0004","N/A","N/A","Exploitation tool","https://github.com/chvancooten/OSEP-Code-Snippets","1","1","N/A","N/A","8","10","1254","444","2024-01-04T15:17:17Z","2021-03-10T21:34:41Z","11235" +"*/shocknawe/*",".{0,1000}\/shocknawe\/.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","11236" +"*/shodan-api.nse*",".{0,1000}\/shodan\-api\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11237" +"*/Shoggoth.exe*",".{0,1000}\/Shoggoth\.exe.{0,1000}","offensive_tool_keyword","Shoggoth","Shoggoth: Asmjit Based Polymorphic Encryptor","T1027 - T1045","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/frkngksl/Shoggoth","1","1","N/A","N/A","8","8","724","92","2024-04-10T03:04:04Z","2021-12-03T11:55:22Z","11238" +"*/Shoggoth.git*",".{0,1000}\/Shoggoth\.git.{0,1000}","offensive_tool_keyword","Shoggoth","Shoggoth: Asmjit Based Polymorphic Encryptor","T1027 - T1045","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/frkngksl/Shoggoth","1","1","N/A","N/A","8","8","724","92","2024-04-10T03:04:04Z","2021-12-03T11:55:22Z","11239" +"*/shspawnas/*",".{0,1000}\/shspawnas\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","11240" +"*/Shu1337.php*",".{0,1000}\/Shu1337\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","11241" +"*/ShuckNT.git*",".{0,1000}\/ShuckNT\.git.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","11242" +"*/Shwmae.exe*",".{0,1000}\/Shwmae\.exe.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","1","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","11243" +"*/Shwmae.git*",".{0,1000}\/Shwmae\.git.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","1","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","11244" +"*/shwmae/keys*",".{0,1000}\/shwmae\/keys.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","1","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","11245" +"*/si1ent-le/CVE-2022-0847*",".{0,1000}\/si1ent\-le\/CVE\-2022\-0847.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/si1ent-le/CVE-2022-0847","1","1","N/A","N/A","N/A","1","0","2","2022-03-08T05:18:15Z","2022-03-08T04:51:02Z","11246" +"*/SigFlip.*",".{0,1000}\/SigFlip\..{0,1000}","offensive_tool_keyword","C2 related tools","SigFlip is a tool for patching authenticode signed PE files (exe. dll. sys ..etc) without invalidating or breaking the existing signature.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/med0x2e/SigFlip","1","1","N/A","N/A","10","10","1139","197","2023-08-27T18:27:50Z","2021-08-08T15:59:19Z","11247" +"*/sigflip.x64.*",".{0,1000}\/sigflip\.x64\..{0,1000}","offensive_tool_keyword","cobaltstrike","SigFlip is a tool for patching authenticode signed PE files (exe. dll. sys ..etc) without invalidating or breaking the existing signature.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/med0x2e/SigFlip","1","1","N/A","N/A","10","10","1139","197","2023-08-27T18:27:50Z","2021-08-08T15:59:19Z","11248" +"*/sigflip.x86.*",".{0,1000}\/sigflip\.x86\..{0,1000}","offensive_tool_keyword","cobaltstrike","SigFlip is a tool for patching authenticode signed PE files (exe. dll. sys ..etc) without invalidating or breaking the existing signature.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/med0x2e/SigFlip","1","1","N/A","N/A","10","10","1139","197","2023-08-27T18:27:50Z","2021-08-08T15:59:19Z","11249" +"*/SigFlip/*",".{0,1000}\/SigFlip\/.{0,1000}","offensive_tool_keyword","C2 related tools","SigFlip is a tool for patching authenticode signed PE files (exe. dll. sys ..etc) without invalidating or breaking the existing signature.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/med0x2e/SigFlip","1","1","N/A","N/A","10","10","1139","197","2023-08-27T18:27:50Z","2021-08-08T15:59:19Z","11250" +"*/SigLoader.go*",".{0,1000}\/SigLoader\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","SigFlip is a tool for patching authenticode signed PE files (exe. dll. sys ..etc) without invalidating or breaking the existing signature.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/med0x2e/SigFlip","1","1","N/A","N/A","10","10","1139","197","2023-08-27T18:27:50Z","2021-08-08T15:59:19Z","11251" +"*/SigLoader/*",".{0,1000}\/SigLoader\/.{0,1000}","offensive_tool_keyword","C2 related tools","SigFlip is a tool for patching authenticode signed PE files (exe. dll. sys ..etc) without invalidating or breaking the existing signature.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/med0x2e/SigFlip","1","1","N/A","N/A","10","10","1139","197","2023-08-27T18:27:50Z","2021-08-08T15:59:19Z","11252" +"*/SigLoader/*",".{0,1000}\/SigLoader\/.{0,1000}","offensive_tool_keyword","cobaltstrike","SigFlip is a tool for patching authenticode signed PE files (exe. dll. sys ..etc) without invalidating or breaking the existing signature.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/med0x2e/SigFlip","1","1","N/A","N/A","10","10","1139","197","2023-08-27T18:27:50Z","2021-08-08T15:59:19Z","11253" +"*/SigmaPotato.git*",".{0,1000}\/SigmaPotato\.git.{0,1000}","offensive_tool_keyword","SigmaPotato","SeImpersonate privilege escalation tool","T1134 - T1055 - T1543","TA0004 - TA0005 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/tylerdotrar/SigmaPotato","1","1","N/A","N/A","9","4","326","38","2024-05-16T23:46:04Z","2023-09-09T01:35:42Z","11254" +"*/SigmaPotato/releases/download/*",".{0,1000}\/SigmaPotato\/releases\/download\/.{0,1000}","offensive_tool_keyword","SigmaPotato","SeImpersonate privilege escalation tool","T1134 - T1055 - T1543","TA0004 - TA0005 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/tylerdotrar/SigmaPotato","1","1","N/A","N/A","9","4","326","38","2024-05-16T23:46:04Z","2023-09-09T01:35:42Z","11255" +"*/signer-exe.py*",".{0,1000}\/signer\-exe\.py.{0,1000}","offensive_tool_keyword","PayGen","FUD metasploit Persistence RAT","T1059.001 - T1209 - T1105 - T1547 - T1027","TA0003 - TA0005 - TA0002 - TA0011","N/A","N/A","Persistence","https://github.com/youhacker55/PayGen","1","1","N/A","N/A","N/A","1","4","0","2023-02-23T00:05:57Z","2021-06-16T20:20:55Z","11256" +"*/SignToolEx.cpp*",".{0,1000}\/SignToolEx\.cpp.{0,1000}","offensive_tool_keyword","SignToolEx","Patching signtool.exe to accept expired certificates for code-signing","T1553.002 - T1649","TA0005","N/A","N/A","Defense Evasion","https://github.com/hackerhouse-opensource/SignToolEx","1","1","N/A","N/A","8","3","275","47","2024-07-19T17:22:28Z","2023-12-29T14:26:45Z","11257" +"*/SignToolEx.git*",".{0,1000}\/SignToolEx\.git.{0,1000}","offensive_tool_keyword","SignToolEx","Patching signtool.exe to accept expired certificates for code-signing","T1553.002 - T1649","TA0005","N/A","N/A","Defense Evasion","https://github.com/hackerhouse-opensource/SignToolEx","1","1","N/A","N/A","8","3","275","47","2024-07-19T17:22:28Z","2023-12-29T14:26:45Z","11258" +"*/SignToolEx.sln*",".{0,1000}\/SignToolEx\.sln.{0,1000}","offensive_tool_keyword","SignToolEx","Patching signtool.exe to accept expired certificates for code-signing","T1553.002 - T1649","TA0005","N/A","N/A","Defense Evasion","https://github.com/hackerhouse-opensource/SignToolEx","1","1","N/A","N/A","8","3","275","47","2024-07-19T17:22:28Z","2023-12-29T14:26:45Z","11259" +"*/sigthief.py*",".{0,1000}\/sigthief\.py.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","11260" +"*/SilentClean/SilentClean/*.cs*",".{0,1000}\/SilentClean\/SilentClean\/.{0,1000}\.cs.{0,1000}","offensive_tool_keyword","cobaltstrike","New UAC bypass for Silent Cleanup for CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EncodeGroup/UAC-SilentClean","1","1","N/A","N/A","10","10","192","31","2021-07-14T13:51:02Z","2020-10-07T13:25:21Z","11262" +"*/SilentCryptoMiner/*",".{0,1000}\/SilentCryptoMiner\/.{0,1000}","offensive_tool_keyword","SilentCryptoMiner","A Silent (Hidden) Free Crypto Miner Builder","T1496 - T1055 - T1546 - T1082 - T1574","TA0042 - TA0005 - TA0003 - TA0009","N/A","N/A","Cryptomining","https://github.com/UnamSanctam/SilentCryptoMiner","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","11263" +"*/silentdump.c*",".{0,1000}\/silentdump\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/guervild/BOFs","1","1","N/A","N/A","10","10","161","27","2022-05-02T16:59:24Z","2021-03-15T23:30:22Z","11264" +"*/silentdump.h*",".{0,1000}\/silentdump\.h.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/guervild/BOFs","1","1","N/A","N/A","10","10","161","27","2022-05-02T16:59:24Z","2021-03-15T23:30:22Z","11265" +"*/SilentHound.git*",".{0,1000}\/SilentHound\.git.{0,1000}","offensive_tool_keyword","SilentHound","Quietly enumerate an Active Directory Domain via LDAP parsing users + admins + groups...","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/layer8secure/SilentHound","1","1","N/A","AD Enumeration","7","5","489","47","2023-01-23T20:41:55Z","2022-07-01T13:49:24Z","11266" +"*/SilentMoonwalk.git*",".{0,1000}\/SilentMoonwalk\.git.{0,1000}","offensive_tool_keyword","SilentMoonwalk","PoC Implementation of a fully dynamic call stack spoofer","T1055 - T1055.012 - T1562 - T1562.001 - T1070 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/klezVirus/SilentMoonwalk","1","1","N/A","N/A","9","8","760","100","2024-07-20T10:41:31Z","2022-12-04T13:30:33Z","11267" +"*/silentprocessexit.py*",".{0,1000}\/silentprocessexit\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","11268" +"*/silenttrinity/*.py*",".{0,1000}\/silenttrinity\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","11269" +"*/silic webshell.jsp*",".{0,1000}\/silic\swebshell\.jsp.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","11270" +"*/SimAttacker - Vrsion 1.0.0 - priv8 4 My friend.php*",".{0,1000}\/SimAttacker\s\-\sVrsion\s1\.0\.0\s\-\spriv8\s4\sMy\sfriend\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","11271" +"*/simple_hijacker/*",".{0,1000}\/simple_hijacker\/.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","11272" +"*/simple-backdoor.php*",".{0,1000}\/simple\-backdoor\.php.{0,1000}","offensive_tool_keyword","webshell","A collection of webshell","T1505.003 - T1100 - T1190 - T1505.004","TA0003 - TA0011 ","N/A","N/A","Persistence","https://github.com/Peaky-XD/webshell","1","1","N/A","N/A","10","","N/A","","","","11273" +"*/simple-backdoor.php*",".{0,1000}\/simple\-backdoor\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","11274" +"*/SimpleLoader.cpp*",".{0,1000}\/SimpleLoader\.cpp.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","11276" +"*/SimpleLoader.exe*",".{0,1000}\/SimpleLoader\.exe.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","11277" +"*/SimpleNTSyscallFuzzer.git*",".{0,1000}\/SimpleNTSyscallFuzzer\.git.{0,1000}","offensive_tool_keyword","SimpleNTSyscallFuzzer","Fuzzer for Windows kernel syscalls.","T1055.011 - T1218","TA0005 - TA0007","N/A","N/A","Discovery","https://github.com/waleedassar/SimpleNTSyscallFuzzer","1","1","N/A","N/A","7","2","145","25","2024-01-25T02:39:31Z","2022-03-12T10:16:30Z","11278" +"*/Simple-Reverse-Shell*",".{0,1000}\/Simple\-Reverse\-Shell.{0,1000}","offensive_tool_keyword","Simple-Reverse-Shell","Simple C++ reverse shell without obfuscation to avoid Win 11 defender detection (At the time of publication","T1548 - T1562 - T1027","TA0003 - TA0008","N/A","N/A","C2","https://github.com/tihanyin/Simple-Reverse-Shell/","1","1","N/A","N/A","N/A","10","119","30","2021-12-21T15:51:48Z","2021-12-19T22:16:32Z","11279" +"*/SimplyEmail.git*",".{0,1000}\/SimplyEmail\.git.{0,1000}","offensive_tool_keyword","SimplyEmail","SimplyEmail was built arround the concept that tools should do somthing. and do that somthing well. hence simply What is the simple email recon tool? This tool was based off the work of theHarvester and kind of a port of the functionality. This was just an expansion of what was used to build theHarvester and will incorporate his work but allow users to easily build Modules for the Framework. Which I felt was desperately needed after building my first module for theHarvester.","T1210.001 - T1190 - T1583.001 - T1590","TA0007 - TA0002 - ","N/A","N/A","Reconnaissance","https://github.com/SimplySecurity/SimplyEmail","1","1","N/A","N/A","5","10","953","228","2023-01-12T22:20:25Z","2015-10-30T03:12:10Z","11280" +"*/SimShell 1.0 - Simorgh Security MGZ.php*",".{0,1000}\/SimShell\s1\.0\s\-\sSimorgh\sSecurity\sMGZ\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","11281" +"*/SingleDose.git*",".{0,1000}\/SingleDose\.git.{0,1000}","offensive_tool_keyword","SingleDose","SingleDose is a framework to build shellcode load/process injection techniques","T1055 - T1185","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/Wra7h/SingleDose","1","1","N/A","N/A","10","2","155","29","2023-05-15T19:46:43Z","2021-08-28T05:04:50Z","11282" +"*/S-inject.exe*",".{0,1000}\/S\-inject\.exe.{0,1000}","offensive_tool_keyword","S-inject","Windows injection of x86/x64 DLL and Shellcode","T1055 - T1027","TA0002 - TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/Joe1sn/S-inject","1","1","N/A","N/A","10","4","313","45","2025-04-06T08:06:39Z","2024-02-05T04:39:10Z","11283" +"*/S-inject.git*",".{0,1000}\/S\-inject\.git.{0,1000}","offensive_tool_keyword","S-inject","Windows injection of x86/x64 DLL and Shellcode","T1055 - T1027","TA0002 - TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/Joe1sn/S-inject","1","1","N/A","N/A","10","4","313","45","2025-04-06T08:06:39Z","2024-02-05T04:39:10Z","11284" +"*/S-inject_x64.exe*",".{0,1000}\/S\-inject_x64\.exe.{0,1000}","offensive_tool_keyword","S-inject","Windows injection of x86/x64 DLL and Shellcode","T1055 - T1027","TA0002 - TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/Joe1sn/S-inject","1","1","N/A","N/A","10","4","313","45","2025-04-06T08:06:39Z","2024-02-05T04:39:10Z","11285" +"*/S-inject_x86.exe*",".{0,1000}\/S\-inject_x86\.exe.{0,1000}","offensive_tool_keyword","S-inject","Windows injection of x86/x64 DLL and Shellcode","T1055 - T1027","TA0002 - TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/Joe1sn/S-inject","1","1","N/A","N/A","10","4","313","45","2025-04-06T08:06:39Z","2024-02-05T04:39:10Z","11286" +"*/sip-brute.nse*",".{0,1000}\/sip\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11287" +"*/sip-call-spoof.nse*",".{0,1000}\/sip\-call\-spoof\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11288" +"*/sip-enum-users.nse*",".{0,1000}\/sip\-enum\-users\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11289" +"*/sip-methods.nse*",".{0,1000}\/sip\-methods\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11290" +"*/sipvicious.py*",".{0,1000}\/sipvicious\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","11291" +"*/SirepRAT.git*",".{0,1000}\/SirepRAT\.git.{0,1000}","offensive_tool_keyword","SirepRAT","RAT tool - Remote Command Execution as SYSTEM on Windows IoT Core","T1059 - T1219 - T1105 - T1021","TA0002 - TA0011 - TA0003","N/A","N/A","C2","https://github.com/SafeBreach-Labs/SirepRAT","1","1","N/A","N/A","7","10","380","89","2020-12-13T09:52:55Z","2019-03-02T19:51:05Z","11293" +"*/SirepRAT.py*",".{0,1000}\/SirepRAT\.py.{0,1000}","offensive_tool_keyword","SirepRAT","RAT tool - Remote Command Execution as SYSTEM on Windows IoT Core","T1059 - T1219 - T1105 - T1021","TA0002 - TA0011 - TA0003","N/A","N/A","C2","https://github.com/SafeBreach-Labs/SirepRAT","1","1","N/A","N/A","7","10","380","89","2020-12-13T09:52:55Z","2019-03-02T19:51:05Z","11294" +"*/SirepRAT/releases/*",".{0,1000}\/SirepRAT\/releases\/.{0,1000}","offensive_tool_keyword","SirepRAT","RAT tool - Remote Command Execution as SYSTEM on Windows IoT Core","T1059 - T1219 - T1105 - T1021","TA0002 - TA0011 - TA0003","N/A","N/A","C2","https://github.com/SafeBreach-Labs/SirepRAT","1","1","N/A","N/A","7","10","380","89","2020-12-13T09:52:55Z","2019-03-02T19:51:05Z","11295" +"*/sish.git*",".{0,1000}\/sish\.git.{0,1000}","offensive_tool_keyword","sish","An open source serveo/ngrok alternative. HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH","T1572 - T1090.002","TA0010 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antoniomika/sish","1","1","N/A","N/A","10","10","4203","325","2025-04-10T20:04:08Z","2019-02-15T15:36:23Z","11298" +"*/sish/releases/download/*",".{0,1000}\/sish\/releases\/download\/.{0,1000}","offensive_tool_keyword","sish","An open source serveo/ngrok alternative. HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH","T1572 - T1090.002","TA0010 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antoniomika/sish","1","1","N/A","N/A","10","10","4203","325","2025-04-10T20:04:08Z","2019-02-15T15:36:23Z","11304" +"*/sish:latest*",".{0,1000}\/sish\:latest.{0,1000}","offensive_tool_keyword","sish","An open source serveo/ngrok alternative. HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH","T1572 - T1090.002","TA0010 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antoniomika/sish","1","1","N/A","N/A","10","10","4203","325","2025-04-10T20:04:08Z","2019-02-15T15:36:23Z","11306" +"*/Sitadel.git*",".{0,1000}\/Sitadel\.git.{0,1000}","offensive_tool_keyword","Sitadel","Web Application Security Scanner","T1592.002 - T1210.001 - T1190.001 - T1046 - T1213 - T1071.001","TA0001 - TA0007 - TA0043 - TA0002 - TA0003","N/A","N/A","Reconnaissance","https://github.com/shenril/Sitadel","1","1","N/A","N/A","5","6","577","112","2023-11-29T01:33:28Z","2018-01-17T09:06:24Z","11307" +"*/sitadel.py*",".{0,1000}\/sitadel\.py.{0,1000}","offensive_tool_keyword","Sitadel","Web Application Security Scanner","T1592.002 - T1210.001 - T1190.001 - T1046 - T1213 - T1071.001","TA0001 - TA0007 - TA0043 - TA0002 - TA0003","N/A","N/A","Reconnaissance","https://github.com/shenril/Sitadel","1","1","N/A","N/A","5","6","577","112","2023-11-29T01:33:28Z","2018-01-17T09:06:24Z","11309" +"*/sites-available/striker*",".{0,1000}\/sites\-available\/striker.{0,1000}","offensive_tool_keyword","Striker","Striker is a simple Command and Control (C2) program.","T1071 - T1071.001 - T1071.004 - T1071.005 - T1071.006 - T1071.007 - T1071.008 - T1071.009 - T1071.010 - T1071.012 - T1071.013 - T1071.014 - T1071.015 - T1071.016 - T1071.018 - T1105 - T1105.002 - T1573 - T1573.002 - T1573.003 - T1573.004 - T1573.005","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/4g3nt47/Striker","1","1","N/A","N/A","10","10","301","42","2023-05-04T18:00:05Z","2022-09-07T10:09:41Z","11310" +"*/sites-enabled/striker*",".{0,1000}\/sites\-enabled\/striker.{0,1000}","offensive_tool_keyword","Striker","Striker is a simple Command and Control (C2) program.","T1071 - T1071.001 - T1071.004 - T1071.005 - T1071.006 - T1071.007 - T1071.008 - T1071.009 - T1071.010 - T1071.012 - T1071.013 - T1071.014 - T1071.015 - T1071.016 - T1071.018 - T1105 - T1105.002 - T1573 - T1573.002 - T1573.003 - T1573.004 - T1573.005","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/4g3nt47/Striker","1","1","N/A","N/A","10","10","301","42","2023-05-04T18:00:05Z","2022-09-07T10:09:41Z","11311" +"*/situational_awareness/*.exe",".{0,1000}\/situational_awareness\/.{0,1000}\.exe","offensive_tool_keyword","empire","Empire executable paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1143","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","11312" +"*/skelsec/pypykatz*",".{0,1000}\/skelsec\/pypykatz.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","10","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","11314" +"*/skypev2-version.nse*",".{0,1000}\/skypev2\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11315" +"*/sl0p.dll*",".{0,1000}\/sl0p\.dll.{0,1000}","offensive_tool_keyword","bypassUAC","UAC bypass for Windows","T1088 - T1202 - T1112 - T1059 - T1548.002","TA0005 - TA0004","N/A","Dispossessor","Defense Evasion","https://github.com/ASkyeye/win-server2022-UAC-Bypass","1","1","N/A","N/A","9","1","0","1","2024-02-04T00:10:43Z","2021-09-25T03:36:02Z","11316" +"*/Slackor.git*",".{0,1000}\/Slackor\.git.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","11317" +"*/Slackor.git*",".{0,1000}\/Slackor\.git.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","11318" +"*/Slackor/*",".{0,1000}\/Slackor\/.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","11319" +"*/sleep_python_bridge/*",".{0,1000}\/sleep_python_bridge\/.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","11320" +"*/Sleeper/Sleeper.cna*",".{0,1000}\/Sleeper\/Sleeper\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files (BOF) for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/crypt0p3g/bof-collection","1","1","N/A","N/A","10","10","175","27","2022-12-05T04:49:33Z","2021-01-20T06:07:38Z","11321" +"*/sleepmask.cna*",".{0,1000}\/sleepmask\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","11322" +"*/slinky.py*",".{0,1000}\/slinky\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","11323" +"*/SlinkyCat.git*",".{0,1000}\/SlinkyCat\.git.{0,1000}","offensive_tool_keyword","SlinkyCat","This script performs a series of AD enumeration tasks","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/LaresLLC/SlinkyCat","1","1","N/A","AD Enumeration","7","1","79","8","2023-07-12T15:29:31Z","2023-07-03T23:44:18Z","11324" +"*/slip.git",".{0,1000}\/slip\.git","offensive_tool_keyword","slip","Slip is a CLI tool to create malicious archive files containing path traversal payloads","T1560.001 - T1059","TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/0xless/slip","1","1","N/A","N/A","10","2","100","4","2025-04-11T18:36:31Z","2022-10-29T15:38:36Z","11325" +"*/slip-main.zip",".{0,1000}\/slip\-main\.zip","offensive_tool_keyword","slip","Slip is a CLI tool to create malicious archive files containing path traversal payloads","T1560.001 - T1059","TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/0xless/slip","1","1","N/A","N/A","10","2","100","4","2025-04-11T18:36:31Z","2022-10-29T15:38:36Z","11326" +"*/sliver.exe*",".{0,1000}\/sliver\.exe.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11328" +"*/sliver.git*",".{0,1000}\/sliver\.git.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11329" +"*/sliver.pb.go*",".{0,1000}\/sliver\.pb\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11330" +"*/sliver.proto*",".{0,1000}\/sliver\.proto.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11331" +"*/sliver/evasion/*",".{0,1000}\/sliver\/evasion\/.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11332" +"*/sliver_pb2.py*",".{0,1000}\/sliver_pb2\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","11333" +"*/sliver_pb2_grpc.py*",".{0,1000}\/sliver_pb2_grpc\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","11334" +"*/sliver-client_linux*",".{0,1000}\/sliver\-client_linux.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","#linux","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11337" +"*/sliver-client_linux.sig*",".{0,1000}\/sliver\-client_linux\.sig.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","#linux","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11338" +"*/sliver-client_windows.exe*",".{0,1000}\/sliver\-client_windows\.exe.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11339" +"*/sliver-client_windows-386*.exe*",".{0,1000}\/sliver\-client_windows\-386.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11340" +"*/sliver-client_windows-amd64*.exe*",".{0,1000}\/sliver\-client_windows\-amd64.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11341" +"*/sliver-client_windows-arm64*.exe*",".{0,1000}\/sliver\-client_windows\-arm64.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11342" +"*/sliverpb.Exe*",".{0,1000}\/sliverpb\.Exe.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11343" +"*/sliver-server*",".{0,1000}\/sliver\-server.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11344" +"*/sliver-server_linux*",".{0,1000}\/sliver\-server_linux.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","#linux","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11345" +"*/SlowPathMITM.py*",".{0,1000}\/SlowPathMITM\.py.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","#linux","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","11346" +"*/SmallSecretsDump.py*",".{0,1000}\/SmallSecretsDump\.py.{0,1000}","offensive_tool_keyword","Adcheck","Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle","T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009","N/A","N/A","Discovery","https://github.com/CobblePot59/Adcheck","1","1","N/A","N/A","10","4","315","35","2025-04-18T15:17:46Z","2024-05-10T13:54:45Z","11347" +"*/smartbrute.git*",".{0,1000}\/smartbrute\.git.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","1","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","11348" +"*/smb/psexec.rb*",".{0,1000}\/smb\/psexec\.rb.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-PsExec.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","11351" +"*/SMB_RPC/*.py",".{0,1000}\/SMB_RPC\/.{0,1000}\.py","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","11352" +"*/smb2-capabilities.nse*",".{0,1000}\/smb2\-capabilities\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11353" +"*/smb2-security-mode.nse*",".{0,1000}\/smb2\-security\-mode\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11354" +"*/smb2-time.nse*",".{0,1000}\/smb2\-time\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11355" +"*/smb2-vuln-uptime.nse*",".{0,1000}\/smb2\-vuln\-uptime\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11356" +"*/smb3.py*",".{0,1000}\/smb3\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/SecureAuthCorp/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","11357" +"*/smb-brute.nse*",".{0,1000}\/smb\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11358" +"*/smbclient.py*",".{0,1000}\/smbclient\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","11360" +"*/SMBCrunch.git*",".{0,1000}\/SMBCrunch\.git.{0,1000}","offensive_tool_keyword","SMBCrunch","SMBCrunch allows a red teamer to quickly identify Windows File Shares in a network - performs a recursive directory listing of the provided shares and can even grab a file from the remote share if it looks like a juicy target.","T1021.002 - T1005 - T1210","TA0001 - TA0002 - TA0003 - TA0009","N/A","N/A","Lateral Movement","https://github.com/Raikia/SMBCrunch","1","1","N/A","N/A","9","2","165","20","2018-03-07T15:50:12Z","2016-03-25T10:10:19Z","11362" +"*/smb-double-pulsar-backdoor.nse*",".{0,1000}\/smb\-double\-pulsar\-backdoor\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11363" +"*/SMBeagle*",".{0,1000}\/SMBeagle.{0,1000}","offensive_tool_keyword","SMBeagle","SMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host.","T1087.002 - T1021.002 - T1210","TA0007 - TA0008 - TA0003","N/A","N/A","Discovery","https://github.com/punk-security/SMBeagle","1","1","N/A","N/A","9","8","712","80","2025-01-21T22:34:00Z","2021-05-31T19:46:57Z","11364" +"*/smb-enum-domains.nse*",".{0,1000}\/smb\-enum\-domains\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11365" +"*/smb-enum-groups.nse*",".{0,1000}\/smb\-enum\-groups\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11366" +"*/smb-enum-processes.nse*",".{0,1000}\/smb\-enum\-processes\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11367" +"*/smb-enum-services.nse*",".{0,1000}\/smb\-enum\-services\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11368" +"*/smb-enum-sessions.nse*",".{0,1000}\/smb\-enum\-sessions\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11369" +"*/smb-enum-shares.nse*",".{0,1000}\/smb\-enum\-shares\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11370" +"*/smb-enum-users.nse*",".{0,1000}\/smb\-enum\-users\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11371" +"*/smbexec.py*",".{0,1000}\/smbexec\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","11372" +"*/smbexec.py*",".{0,1000}\/smbexec\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","11373" +"*/smbexec.py*",".{0,1000}\/smbexec\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","11374" +"*/smb-flood.nse*",".{0,1000}\/smb\-flood\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11375" +"*/SMBForwarder.txt*",".{0,1000}\/SMBForwarder\.txt.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","11376" +"*/SMBGhost/scanner.py*",".{0,1000}\/SMBGhost\/scanner\.py.{0,1000}","offensive_tool_keyword","SMBGhost","Simple scanner for CVE-2020-0796 - SMBv3 RCE.","T1210 - T1573 - T1553 - T1216 - T1027","TA0006 - TA0011 - TA0008","N/A","N/A","Discovery","https://github.com/ollypwn/SMBGhost","1","1","N/A","N/A","7","7","678","194","2020-10-01T08:36:29Z","2020-03-11T15:21:27Z","11377" +"*/SMBGhost_RCE*",".{0,1000}\/SMBGhost_RCE.{0,1000}","offensive_tool_keyword","SMBGhost_RCE_PoC","RCE PoC for CVE-2020-0796 SMBGhost","T1210 - T1059 - T1505 - T1021 - T1027","TA0001 - TA0002 - TA0003 - TA0040","N/A","N/A","Exploitation tool","https://github.com/chompie1337/SMBGhost_RCE_PoC","1","1","N/A","N/A","N/A","10","1339","349","2020-07-02T18:51:47Z","2020-06-02T00:14:47Z","11378" +"*/SMBGrab.pl*",".{0,1000}\/SMBGrab\.pl.{0,1000}","offensive_tool_keyword","SMBCrunch","SMBCrunch allows a red teamer to quickly identify Windows File Shares in a network - performs a recursive directory listing of the provided shares and can even grab a file from the remote share if it looks like a juicy target.","T1021.002 - T1005 - T1210","TA0001 - TA0002 - TA0003 - TA0009","N/A","N/A","Lateral Movement","https://github.com/Raikia/SMBCrunch","1","1","N/A","N/A","9","2","165","20","2018-03-07T15:50:12Z","2016-03-25T10:10:19Z","11379" +"*/SMBHunt.pl*",".{0,1000}\/SMBHunt\.pl.{0,1000}","offensive_tool_keyword","SMBCrunch","SMBCrunch allows a red teamer to quickly identify Windows File Shares in a network - performs a recursive directory listing of the provided shares and can even grab a file from the remote share if it looks like a juicy target.","T1021.002 - T1005 - T1210","TA0001 - TA0002 - TA0003 - TA0009","N/A","N/A","Lateral Movement","https://github.com/Raikia/SMBCrunch","1","1","N/A","N/A","9","2","165","20","2018-03-07T15:50:12Z","2016-03-25T10:10:19Z","11380" +"*/smbldap.py*",".{0,1000}\/smbldap\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","11381" +"*/SMBList.pl*",".{0,1000}\/SMBList\.pl.{0,1000}","offensive_tool_keyword","SMBCrunch","SMBCrunch allows a red teamer to quickly identify Windows File Shares in a network - performs a recursive directory listing of the provided shares and can even grab a file from the remote share if it looks like a juicy target.","T1021.002 - T1005 - T1210","TA0001 - TA0002 - TA0003 - TA0009","N/A","N/A","Lateral Movement","https://github.com/Raikia/SMBCrunch","1","1","N/A","N/A","9","2","165","20","2018-03-07T15:50:12Z","2016-03-25T10:10:19Z","11382" +"*/smblogin.ps1*",".{0,1000}\/smblogin\.ps1.{0,1000}","offensive_tool_keyword","Minimalistic-offensive","A repository of tools for pentesting of restricted and isolated environments.","T1110 - T1046 - T1021 - T1203 - T1485","TA0006 - TA0007 - TA0008","N/A","Dispossessor","Discovery","https://github.com/InfosecMatter/Minimalistic-offensive-security-tools","1","1","N/A","N/A","7","6","562","121","2021-10-26T11:04:46Z","2020-05-10T17:40:31Z","11383" +"*/smb-ls.nse*",".{0,1000}\/smb\-ls\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11384" +"*/smbmap.git*",".{0,1000}\/smbmap\.git.{0,1000}","offensive_tool_keyword","smbmap","SMBMap allows users to enumerate samba share drives across an entire domain. List share drives. drive permissions. share contents. upload/download functionality. file name auto-download pattern matching. and even execute remote commands. This tool was designed with pen testing in mind. and is intended to simplify searching for potentially sensitive data across large networks.","T1210.001 - T1083 - T1213 - T1021","TA0007 - TA0003 - TA0002 - TA0001","N/A","MuddyWater - Dispossessor","Discovery","https://github.com/ShawnDEvans/smbmap","1","1","N/A","N/A","10","10","1890","359","2025-02-28T18:09:10Z","2015-03-16T13:15:00Z","11385" +"*/smbmap.py*",".{0,1000}\/smbmap\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","11386" +"*/smbmapDump*",".{0,1000}\/smbmapDump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","11387" +"*/smb-mbenum.nse*",".{0,1000}\/smb\-mbenum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11388" +"*/smb-os-discovery.nse*",".{0,1000}\/smb\-os\-discovery\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11389" +"*/smbpasswd.py*",".{0,1000}\/smbpasswd\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","11390" +"*/smb-print-text.nse*",".{0,1000}\/smb\-print\-text\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11391" +"*/smb-protocols.nse*",".{0,1000}\/smb\-protocols\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11392" +"*/smb-psexec.nse*",".{0,1000}\/smb\-psexec\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11393" +"*/smbrelayserver.py*",".{0,1000}\/smbrelayserver\.py.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","1","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","11394" +"*/smbrelayx.exe*",".{0,1000}\/smbrelayx\.exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","11395" +"*/smbrelayx.py*",".{0,1000}\/smbrelayx\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","11396" +"*/smb-reverse-shell*",".{0,1000}\/smb\-reverse\-shell.{0,1000}","offensive_tool_keyword","smb-reverse-shell","A Reverse Shell which uses an XML file on an SMB share as a communication channel.","T1021.002 - T1027 - T1105","TA0008 - TA0010 - TA0002","N/A","N/A","C2","https://github.com/r1cksec/smb-reverse-shell","1","1","N/A","N/A","10","10","17","0","2024-02-17T12:20:01Z","2022-01-16T21:02:14Z","11397" +"*/smbscan.git*",".{0,1000}\/smbscan\.git.{0,1000}","offensive_tool_keyword","smbscan","SMBScan is a tool to enumerate file shares on an internal network.","T1135 - T1046 - T1021","TA0007 - TA0043 - TA0008","N/A","APT22","Discovery","https://github.com/jeffhacks/smbscan","1","1","N/A","N/A","8","1","44","6","2025-03-24T01:55:30Z","2021-10-26T02:28:34Z","11400" +"*/smbscan.py*",".{0,1000}\/smbscan\.py.{0,1000}","offensive_tool_keyword","smbscan","SMBScan is a tool to enumerate file shares on an internal network.","T1135 - T1046 - T1021","TA0007 - TA0043 - TA0008","N/A","APT22","Discovery","https://github.com/jeffhacks/smbscan","1","1","N/A","N/A","8","1","44","6","2025-03-24T01:55:30Z","2021-10-26T02:28:34Z","11401" +"*/smb-security-mode.nse*",".{0,1000}\/smb\-security\-mode\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11402" +"*/smbserver.py*",".{0,1000}\/smbserver\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","11403" +"*/smbserver/smb_server.py*",".{0,1000}\/smbserver\/smb_server\.py.{0,1000}","offensive_tool_keyword","spoolsploit","A collection of Windows print spooler exploits containerized with other utilities for practical exploitation.","T1204 - T1547 - T1562 - T1003 - T1018 - T1570 - T1005","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/BeetleChunks/SpoolSploit","1","1","N/A","N/A","N/A","6","555","90","2021-07-16T04:49:43Z","2021-07-07T00:32:28Z","11404" +"*/smb-server-stats.nse*",".{0,1000}\/smb\-server\-stats\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11405" +"*/smbspider.py*",".{0,1000}\/smbspider\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","11407" +"*/smbsr.db*",".{0,1000}\/smbsr\.db.{0,1000}","offensive_tool_keyword","SMBSR","Lookup for interesting stuff in SMB shares","T1110.001 - T1046 - T1021.002 - T1077.001 - T1069.002 - T1083 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Reconnaissance","https://github.com/oldboy21/SMBSR","1","1","N/A","N/A","N/A","2","149","23","2023-06-16T14:35:30Z","2021-11-10T16:55:52Z","11408" +"*/SMBSR.git*",".{0,1000}\/SMBSR\.git.{0,1000}","offensive_tool_keyword","smbsr","Lookup for interesting stuff in SMB shares","T1135","TA0001 - TA0007","N/A","N/A","Discovery","https://github.com/oldboy21/SMBSR","1","1","N/A","N/A","7","2","149","23","2023-06-16T14:35:30Z","2021-11-10T16:55:52Z","11410" +"*/SMBSR.git*",".{0,1000}\/SMBSR\.git.{0,1000}","offensive_tool_keyword","SMBSR","Lookup for interesting stuff in SMB shares","T1110.001 - T1046 - T1021.002 - T1077.001 - T1069.002 - T1083 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Reconnaissance","https://github.com/oldboy21/SMBSR","1","1","N/A","N/A","N/A","2","149","23","2023-06-16T14:35:30Z","2021-11-10T16:55:52Z","11411" +"*/smbsr.log*",".{0,1000}\/smbsr\.log.{0,1000}","offensive_tool_keyword","smbsr","Lookup for interesting stuff in SMB shares","T1135","TA0001 - TA0007","N/A","N/A","Discovery","https://github.com/oldboy21/SMBSR","1","1","#logfile #linux","N/A","7","2","149","23","2023-06-16T14:35:30Z","2021-11-10T16:55:52Z","11412" +"*/smbsr.log*",".{0,1000}\/smbsr\.log.{0,1000}","offensive_tool_keyword","SMBSR","Lookup for interesting stuff in SMB shares","T1110.001 - T1046 - T1021.002 - T1077.001 - T1069.002 - T1083 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Reconnaissance","https://github.com/oldboy21/SMBSR","1","1","#logfile #linux","N/A","N/A","2","149","23","2023-06-16T14:35:30Z","2021-11-10T16:55:52Z","11413" +"*/smbsr.py*",".{0,1000}\/smbsr\.py.{0,1000}","offensive_tool_keyword","smbsr","Lookup for interesting stuff in SMB shares","T1135","TA0001 - TA0007","N/A","N/A","Discovery","https://github.com/oldboy21/SMBSR","1","1","N/A","N/A","7","2","149","23","2023-06-16T14:35:30Z","2021-11-10T16:55:52Z","11414" +"*/smbsr_results.csv*",".{0,1000}\/smbsr_results\.csv.{0,1000}","offensive_tool_keyword","smbsr","Lookup for interesting stuff in SMB shares","T1135","TA0001 - TA0007","N/A","N/A","Discovery","https://github.com/oldboy21/SMBSR","1","1","N/A","N/A","7","2","149","23","2023-06-16T14:35:30Z","2021-11-10T16:55:52Z","11415" +"*/smb-system-info.nse*",".{0,1000}\/smb\-system\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11416" +"*/Smbtouch-Scanner.git*",".{0,1000}\/Smbtouch\-Scanner\.git.{0,1000}","offensive_tool_keyword","Smbtouch-Scanner","Smbtouch detect whether the target is vulnerable of one of these vulnerabilities: ETERNALBLUE - ETERNALCHAMPION - ETERNALROMANCE - ETERNALSYNERGY","T1210 - T1046 - T1133","TA0007 - TA0043 - TA0008","N/A","APT15 - Turla","Lateral Movement","https://github.com/3gstudent/Smbtouch-Scanner","1","1","N/A","N/A","10","2","140","66","2021-04-17T01:42:06Z","2017-04-21T01:38:55Z","11417" +"*/SMBTrap.git*",".{0,1000}\/SMBTrap\.git.{0,1000}","offensive_tool_keyword","SMBTrap","tool capturing authentication attempts and performing man-in-the-middle (MitM) attacks leveraging SMB services","T1071.001 - T1557.001 - T1040 - T1070.001 - T1205.001 - T1185","TA0006 - TA0008 - TA0011 - TA0005","N/A","ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/cylance/SMBTrap","1","1","N/A","N/A","8","1","84","38","2015-06-02T17:22:48Z","2015-04-13T07:08:01Z","11418" +"*/smbtrap2.py*",".{0,1000}\/smbtrap2\.py.{0,1000}","offensive_tool_keyword","SMBTrap","tool capturing authentication attempts and performing man-in-the-middle (MitM) attacks leveraging SMB services","T1071.001 - T1557.001 - T1040 - T1070.001 - T1205.001 - T1185","TA0006 - TA0008 - TA0011 - TA0005","N/A","ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/cylance/SMBTrap","1","1","N/A","N/A","8","1","84","38","2015-06-02T17:22:48Z","2015-04-13T07:08:01Z","11419" +"*/smbtrap-mitmproxy-inline.py*",".{0,1000}\/smbtrap\-mitmproxy\-inline\.py.{0,1000}","offensive_tool_keyword","SMBTrap","tool capturing authentication attempts and performing man-in-the-middle (MitM) attacks leveraging SMB services","T1071.001 - T1557.001 - T1040 - T1070.001 - T1205.001 - T1185","TA0006 - TA0008 - TA0011 - TA0005","N/A","ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/cylance/SMBTrap","1","1","N/A","N/A","8","1","84","38","2015-06-02T17:22:48Z","2015-04-13T07:08:01Z","11420" +"*/smb-vuln.py*",".{0,1000}\/smb\-vuln\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","11421" +"*/smb-vuln-conficker.nse*",".{0,1000}\/smb\-vuln\-conficker\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11422" +"*/smb-vuln-cve2009-3103.nse*",".{0,1000}\/smb\-vuln\-cve2009\-3103\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11423" +"*/smb-vuln-cve-2017-7494.nse*",".{0,1000}\/smb\-vuln\-cve\-2017\-7494\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11424" +"*/smb-vuln-cve-2020-0796.nse*",".{0,1000}\/smb\-vuln\-cve\-2020\-0796\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://github.com/cldrn/nmap-nse-scripts/tree/master/scripts","1","1","N/A","N/A","N/A","10","968","369","2022-01-22T18:40:30Z","2011-05-31T05:41:49Z","11425" +"*/smb-vuln-ms06-025.nse*",".{0,1000}\/smb\-vuln\-ms06\-025\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11426" +"*/smb-vuln-ms07-029.nse*",".{0,1000}\/smb\-vuln\-ms07\-029\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11427" +"*/smb-vuln-ms08-067.nse*",".{0,1000}\/smb\-vuln\-ms08\-067\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11428" +"*/smb-vuln-ms10-054.nse*",".{0,1000}\/smb\-vuln\-ms10\-054\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11429" +"*/smb-vuln-ms10-061.nse*",".{0,1000}\/smb\-vuln\-ms10\-061\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11430" +"*/smb-vuln-ms17-010.nse*",".{0,1000}\/smb\-vuln\-ms17\-010\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11431" +"*/smb-vuln-regsvc-dos.nse*",".{0,1000}\/smb\-vuln\-regsvc\-dos\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11432" +"*/smb-vuln-webexec.nse*",".{0,1000}\/smb\-vuln\-webexec\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11433" +"*/smb-webexec-exploit.nse*",".{0,1000}\/smb\-webexec\-exploit\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11434" +"*/SMShell.git*",".{0,1000}\/SMShell\.git.{0,1000}","offensive_tool_keyword","SMShell","PoC for a SMS-based shell. Send commands and receive responses over SMS from mobile broadband capable computers","T1021.001 - T1059.006 - T1071.004 - T1069.003","TA0002 - TA0011 - TA0009 - TA0040","N/A","N/A","C2","https://github.com/persistent-security/SMShell","1","1","N/A","N/A","10","10","360","35","2023-05-22T10:40:16Z","2023-05-22T08:26:44Z","11435" +"*/smtp-brute.nse*",".{0,1000}\/smtp\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11437" +"*/smtp-commands.nse*",".{0,1000}\/smtp\-commands\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11438" +"*/smtp-enum-users.nse*",".{0,1000}\/smtp\-enum\-users\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11439" +"*/smtp-ntlm-info.nse*",".{0,1000}\/smtp\-ntlm\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11440" +"*/smtp-open-relay.nse*",".{0,1000}\/smtp\-open\-relay\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11441" +"*/smtp-strangeport.nse*",".{0,1000}\/smtp\-strangeport\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11442" +"*/smtp-user-enum*",".{0,1000}\/smtp\-user\-enum.{0,1000}","offensive_tool_keyword","smtp-user-enum","Username guessing tool primarily for use against the default Solaris SMTP service. Can use either EXPN - VRFY or RCPT TO.","T1133 - T1110.001","TA0007 - TA0006","N/A","N/A","Credential Access","https://pentestmonkey.net/tools/user-enumeration/smtp-user-enum","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11443" +"*/smtp-vuln-cve2010-4344.nse*",".{0,1000}\/smtp\-vuln\-cve2010\-4344\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11444" +"*/smtp-vuln-cve2011-1720.nse*",".{0,1000}\/smtp\-vuln\-cve2011\-1720\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11445" +"*/smtp-vuln-cve2011-1764.nse*",".{0,1000}\/smtp\-vuln\-cve2011\-1764\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11446" +"*/smtp-vuln-cve2020-28017-through-28026-21nails.nse*",".{0,1000}\/smtp\-vuln\-cve2020\-28017\-through\-28026\-21nails\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://github.com/nccgroup/nmap-nse-vulnerability-scripts","1","1","N/A","N/A","N/A","7","627","59","2022-03-04T09:08:55Z","2021-05-18T15:20:30Z","11447" +"*/smuggler.py*",".{0,1000}\/smuggler\.py.{0,1000}","offensive_tool_keyword","smuggler.py","HTML Smuggling Generator","T1564.001 - T1027 - T1566","TA0005","N/A","N/A","Phishing","https://github.com/infosecn1nja/red-team-scripts/blob/main/smuggler.py","1","1","N/A","N/A","9","3","299","55","2024-08-08T06:11:06Z","2023-01-15T22:37:34Z","11448" +"*/SnaffCon.cs*",".{0,1000}\/SnaffCon\.cs.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","11449" +"*/SnaffCon/Snaffler*",".{0,1000}\/SnaffCon\/Snaffler.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","11450" +"*/SnaffCore/*",".{0,1000}\/SnaffCore\/.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","11451" +"*/Snaffler.exe*",".{0,1000}\/Snaffler\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11452" +"*/Snaffler.exe*",".{0,1000}\/Snaffler\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11453" +"*/snaffler.py*",".{0,1000}\/snaffler\.py.{0,1000}","offensive_tool_keyword","pysnaffler","This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.","T1083 - T1087 - T1114 - T1518","TA0007 - TA0009 - TA0010","N/A","N/A","Collection","https://github.com/skelsec/pysnaffler","1","1","N/A","N/A","10","1","91","5","2025-03-15T13:46:34Z","2023-11-17T21:52:40Z","11454" +"*/snafflertest/*",".{0,1000}\/snafflertest\/.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","11455" +"*/SnaffPoint.git*",".{0,1000}\/SnaffPoint\.git.{0,1000}","offensive_tool_keyword","SnaffPoint","A tool for pointesters to find candies in SharePoint","T1210.001 - T1087.002 - T1059.006","TA0007 - TA0002 - TA0006","N/A","N/A","Discovery","https://github.com/nheiniger/SnaffPoint","1","1","N/A","N/A","7","3","254","25","2022-11-04T13:26:24Z","2022-08-25T13:16:06Z","11456" +"*/Snake.nocomments.sh*",".{0,1000}\/Snake\.nocomments\.sh.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","1","N/A","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","11457" +"*/Snake.sh*",".{0,1000}\/Snake\.sh.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","1","N/A","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","11458" +"*/sniff.py*",".{0,1000}\/sniff\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","11459" +"*/sniff.py*",".{0,1000}\/sniff\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","11460" +"*/sniffer.exe*",".{0,1000}\/sniffer\.exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","11461" +"*/sniffer.git*",".{0,1000}\/sniffer\.git.{0,1000}","offensive_tool_keyword","sniffer","A modern alternative network traffic sniffer.","T1040 - T1052.001 - T1046 - T1552.002","TA0011 - TA0007 - TA0005","N/A","N/A","Sniffing & Spoofing","https://github.com/chenjiandongx/sniffer","1","1","N/A","N/A","N/A","8","769","67","2024-03-02T07:48:19Z","2021-11-08T15:36:03Z","11462" +"*/sniffer.py*",".{0,1000}\/sniffer\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","11463" +"*/sniffer.py*",".{0,1000}\/sniffer\.py.{0,1000}","offensive_tool_keyword","RITM","python Man in the middle ","T1557.002 - T1040 - T1098.002 - T1557.001 - T1552.001","TA0006 - TA0007 - TA0009 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/Tw1sm/RITM","1","1","N/A","N/A","9","3","292","27","2024-11-20T14:27:24Z","2022-10-05T01:10:33Z","11464" +"*/sniffer-detect.nse*",".{0,1000}\/sniffer\-detect\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11465" +"*/sniffpass-x64*",".{0,1000}\/sniffpass\-x64.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","11466" +"*/SnIpEr_SA Shell.php*",".{0,1000}\/SnIpEr_SA\sShell\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","11467" +"*/snmp-brute.nse*",".{0,1000}\/snmp\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11468" +"*/snmp-hh3c-logins.nse*",".{0,1000}\/snmp\-hh3c\-logins\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11469" +"*/snmp-info.nse*",".{0,1000}\/snmp\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11470" +"*/snmp-interfaces.nse*",".{0,1000}\/snmp\-interfaces\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11471" +"*/snmp-ios-config.nse*",".{0,1000}\/snmp\-ios\-config\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11472" +"*/snmp-netstat.nse*",".{0,1000}\/snmp\-netstat\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11473" +"*/snmp-processes.nse*",".{0,1000}\/snmp\-processes\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11474" +"*/snmp-sysdescr.nse*",".{0,1000}\/snmp\-sysdescr\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11475" +"*/snmp-win32-services.nse*",".{0,1000}\/snmp\-win32\-services\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11476" +"*/snmp-win32-shares.nse*",".{0,1000}\/snmp\-win32\-shares\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11477" +"*/snmp-win32-software.nse*",".{0,1000}\/snmp\-win32\-software\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11478" +"*/snmp-win32-users.nse*",".{0,1000}\/snmp\-win32\-users\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11479" +"*/snmpwn.git*",".{0,1000}\/snmpwn\.git.{0,1000}","offensive_tool_keyword","snmpwn","SNMPwn is an SNMPv3 user enumerator and attack tool. It is a legitimate security tool designed to be used by security professionals and penetration testers against hosts you have permission to test. It takes advantage of the fact that SNMPv3 systems will respond with Unknown user name when an SNMP user does not exist. allowing us to cycle through large lists of users to find the ones that do.","T1210 - T1212 - T1558","TA0001 - TA0002","N/A","N/A","Exploitation tool","https://github.com/hatlord/snmpwn","1","1","N/A","N/A","N/A","3","253","43","2020-08-23T10:41:38Z","2016-06-16T10:31:13Z","11480" +"*/snmpwn.rb*",".{0,1000}\/snmpwn\.rb.{0,1000}","offensive_tool_keyword","snmpwn","SNMPwn is an SNMPv3 user enumerator and attack tool. It is a legitimate security tool designed to be used by security professionals and penetration testers against hosts you have permission to test. It takes advantage of the fact that SNMPv3 systems will respond with Unknown user name when an SNMP user does not exist. allowing us to cycle through large lists of users to find the ones that do","T1210 - T1212 - T1558","TA0001 - TA0002","N/A","N/A","Exploitation tool","https://github.com/hatlord/snmpwn","1","1","N/A","N/A","N/A","3","253","43","2020-08-23T10:41:38Z","2016-06-16T10:31:13Z","11481" +"*/snsenum.py*",".{0,1000}\/snsenum\.py.{0,1000}","offensive_tool_keyword","quiet-riot","Unauthenticated enumeration of AWS - Azure and GCP Principals","T1087 - T1083 - T1210","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/righteousgambit/quiet-riot","1","1","N/A","N/A","6","3","224","30","2024-11-13T19:41:26Z","2021-10-28T15:12:27Z","11482" +"*/SOAPHound.exe*",".{0,1000}\/SOAPHound\.exe.{0,1000}","offensive_tool_keyword","SOAPHound","enumerate Active Directory environments via the Active Directory Web Services (ADWS)","T1018 - T1087.002 - T1649","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/FalconForceTeam/SOAPHound","1","1","N/A","N/A","8","8","736","76","2024-02-03T08:52:49Z","2024-01-25T09:11:12Z","11483" +"*/SOAPHound.git*",".{0,1000}\/SOAPHound\.git.{0,1000}","offensive_tool_keyword","SOAPHound","enumerate Active Directory environments via the Active Directory Web Services (ADWS)","T1018 - T1087.002 - T1649","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/FalconForceTeam/SOAPHound","1","1","N/A","N/A","8","8","736","76","2024-02-03T08:52:49Z","2024-01-25T09:11:12Z","11484" +"*/SOAPHound/Program.cs*",".{0,1000}\/SOAPHound\/Program\.cs.{0,1000}","offensive_tool_keyword","SOAPHound","enumerate Active Directory environments via the Active Directory Web Services (ADWS)","T1018 - T1087.002 - T1649","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/FalconForceTeam/SOAPHound","1","1","N/A","N/A","8","8","736","76","2024-02-03T08:52:49Z","2024-01-25T09:11:12Z","11485" +"*/SocialBox.sh*",".{0,1000}\/SocialBox\.sh.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/SocialBox-Termux","1","1","N/A","N/A","7","10","3581","391","2024-09-02T19:15:22Z","2019-03-28T18:07:05Z","11486" +"*/SocialBox-Termux*",".{0,1000}\/SocialBox\-Termux.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/SocialBox-Termux","1","1","N/A","N/A","10","10","3581","391","2024-09-02T19:15:22Z","2019-03-28T18:07:05Z","11487" +"*/SocialPwned*",".{0,1000}\/SocialPwned.{0,1000}","offensive_tool_keyword","SocialPwned","SocialPwned is an OSINT tool that allows to get the emails. from a target. published in social networks like Instagram. Linkedin and Twitter to find the possible credential leaks in PwnDB or Dehashed and obtain Google account information via GHunt.","T1596","TA0002","N/A","N/A","Reconnaissance","https://github.com/MrTuxx/SocialPwned","1","1","N/A","N/A","N/A","10","1139","106","2025-01-28T19:07:29Z","2020-04-07T22:25:38Z","11488" +"*/SOCK5Server.cpp*",".{0,1000}\/SOCK5Server\.cpp.{0,1000}","offensive_tool_keyword","ReverseSock5Proxy","A tiny Reverse Sock5 Proxy","T1090.002 - T1572 - T1071","TA0011 - TA0010","N/A","N/A","C2","https://github.com/Coldzer0/ReverseSock5Proxy","1","1","N/A","N/A","10","10","317","42","2022-11-28T21:18:26Z","2022-11-25T15:12:59Z","11489" +"*/socks5proxy.py*",".{0,1000}\/socks5proxy\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","11490" +"*/socks-auth-info.nse*",".{0,1000}\/socks\-auth\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11491" +"*/socks-brute.nse*",".{0,1000}\/socks\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11492" +"*/socks-open-proxy.nse*",".{0,1000}\/socks\-open\-proxy\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11493" +"*/SolarFlare.exe*",".{0,1000}\/SolarFlare\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11501" +"*/SomalifuscatorV2.git*",".{0,1000}\/SomalifuscatorV2\.git.{0,1000}","offensive_tool_keyword","SomalifuscatorV2","windows batch obfuscator","T1027 - T1497 - T1057","TA0005","N/A","N/A","Defense Evasion","https://github.com/KDot227/SomalifuscatorV2","1","1","N/A","N/A","10","4","315","42","2025-01-19T04:30:49Z","2022-09-23T00:46:51Z","11503" +"*/Sophos Removal Tool.ps1*",".{0,1000}\/Sophos\sRemoval\sTool\.ps1.{0,1000}","offensive_tool_keyword","Dispossessor","script used by Dispossessor ransomware group to remove Sophos","T1562.001 - T1112 - T1059 - T1036","TA0005 - TA0040","N/A","Dispossessor","Defense Evasion","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","11504" +"*/Sophos%20Removal%20Tool.ps1*",".{0,1000}\/Sophos\%20Removal\%20Tool\.ps1.{0,1000}","offensive_tool_keyword","Dispossessor","script used by Dispossessor ransomware group to remove Sophos","T1562.001 - T1112 - T1059 - T1036","TA0005 - TA0040","N/A","Dispossessor","Defense Evasion","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","11505" +"*/SpaceRunner.git*",".{0,1000}\/SpaceRunner\.git.{0,1000}","offensive_tool_keyword","SpaceRunner","enables the compilation of a C# program that will execute arbitrary PowerShell code without launching PowerShell processes through the use of runspace.","T1059.001 - T1027","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Mr-B0b/SpaceRunner","1","1","N/A","N/A","7","2","195","38","2020-07-26T10:39:53Z","2020-07-26T09:31:09Z","11508" +"*/SpamChannel.git*",".{0,1000}\/SpamChannel\.git.{0,1000}","offensive_tool_keyword","SpamChannel","poof emails from any of the +2 Million domains using MailChannels","T1566 - T1566.001","TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/byt3bl33d3r/SpamChannel","1","1","N/A","N/A","8","4","335","36","2023-09-21T12:25:03Z","2022-12-20T21:31:55Z","11509" +"*/spawn.git*",".{0,1000}\/spawn\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF that spawns a sacrificial process. injects it with shellcode. and executes payload. Built to evade EDR/UserLand hooks by spawning sacrificial process with Arbitrary Code Guard (ACG). BlockDll. and PPID spoofing.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/spawn","1","1","N/A","N/A","10","10","455","73","2023-03-08T15:53:44Z","2021-07-17T16:35:59Z","11510" +"*/spellbound.git*",".{0,1000}\/spellbound\.git.{0,1000}","offensive_tool_keyword","spellbound","Spellbound is a C2 (Command and Control) framework meant for creating a botnet. ","T1105 - T1132 - T1059.003 - T1094 - T1005","TA0011 - TA0009 - TA0010 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/mhuzaifi0604/spellbound","1","1","N/A","N/A","10","10","45","5","2023-09-22T10:52:53Z","2023-09-19T14:45:15Z","11518" +"*/spider.yaml*",".{0,1000}\/spider\.yaml.{0,1000}","offensive_tool_keyword","Osmedeus","Osmedeus - A Workflow Engine for Offensive Security","T1595","TA0043","N/A","N/A","Exploitation tool","https://github.com/j3ssie/osmedeus","1","1","N/A","N/A","N/A","10","5566","907","2025-04-22T14:57:07Z","2018-11-10T04:17:18Z","11521" +"*/spider_plus.py*",".{0,1000}\/spider_plus\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","11522" +"*/spiderfoot.git*",".{0,1000}\/spiderfoot\.git.{0,1000}","offensive_tool_keyword","spiderfoot","The OSINT Platform for Security Assessments","T1595 - T1595.002 - T1596 - T1591 - T1591.002","TA0043 ","N/A","N/A","Reconnaissance","https://www.spiderfoot.net/","1","1","N/A","N/A","6","10","N/A","N/A","N/A","N/A","11525" +"*/SpiderMate/Jatayu*",".{0,1000}\/SpiderMate\/Jatayu.{0,1000}","offensive_tool_keyword","Jatayu","Stealthy Stand Alone PHP Web Shell","T1071","TA0005","N/A","N/A","C2","https://github.com/SpiderMate/Jatayu","1","1","N/A","N/A","N/A","10","33","9","2019-09-12T17:03:13Z","2019-09-12T09:04:10Z","11526" +"*/spinningteacup.py*",".{0,1000}\/spinningteacup\.py.{0,1000}","offensive_tool_keyword","spinningteacup","identify different parts of a vba script and perform substitutions","T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","11527" +"*/splunk_whisperer.git*",".{0,1000}\/splunk_whisperer\.git.{0,1000}","offensive_tool_keyword","SplunkWhisperer2","Local privilege escalation or remote code execution through Splunk Universal Forwarder (UF) misconfigurations","T1068 - T1059.003 - T1071.001","TA0004 - TA0003 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/cnotin/SplunkWhisperer2","1","1","N/A","N/A","9","10","250","53","2022-09-30T16:41:17Z","2019-02-24T18:05:51Z","11529" +"*/SplunkWhisperer2.git*",".{0,1000}\/SplunkWhisperer2\.git.{0,1000}","offensive_tool_keyword","SplunkWhisperer2","Local privilege escalation or remote code execution through Splunk Universal Forwarder (UF) misconfigurations","T1068 - T1059.003 - T1071.001","TA0004 - TA0003 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/cnotin/SplunkWhisperer2","1","1","N/A","N/A","9","10","250","53","2022-09-30T16:41:17Z","2019-02-24T18:05:51Z","11530" +"*/SPNSearcher.exe*",".{0,1000}\/SPNSearcher\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11531" +"*/spoof/dns*",".{0,1000}\/spoof\/dns.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","11532" +"*/spoof/mdns*",".{0,1000}\/spoof\/mdns.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","11533" +"*/spoof/spoof_windows.*",".{0,1000}\/spoof\/spoof_windows\..{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11534" +"*/spoofer.py*",".{0,1000}\/spoofer\.py.{0,1000}","offensive_tool_keyword","RITM","python Man in the middle ","T1557.002 - T1040 - T1098.002 - T1557.001 - T1552.001","TA0006 - TA0007 - TA0009 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/Tw1sm/RITM","1","1","N/A","N/A","9","3","292","27","2024-11-20T14:27:24Z","2022-10-05T01:10:33Z","11535" +"*/spoofing-office-macro.git*",".{0,1000}\/spoofing\-office\-macro\.git.{0,1000}","offensive_tool_keyword","spoofing-office-macro","PoC of a VBA macro spawning a process with a spoofed parent and command line","T1055.011 - T1127 - T1077","TA0005 - TA0003","N/A","N/A","Sniffing & Spoofing","https://github.com/christophetd/spoofing-office-macro","1","1","N/A","N/A","9","4","381","82","2020-04-28T16:23:43Z","2019-03-11T18:23:39Z","11536" +"*/spoofIPs_client.py*",".{0,1000}\/spoofIPs_client\.py.{0,1000}","offensive_tool_keyword","PyExfil","A Python Package for Data Exfiltration","T1041 - T1567 - T1027","TA0011 - TA0009 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/ytisf/PyExfil","1","1","N/A","N/A","10","8","782","141","2024-05-07T07:58:02Z","2014-11-27T19:06:24Z","11537" +"*/SpookFlare.git*",".{0,1000}\/SpookFlare\.git.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","11538" +"*/spooler.py*",".{0,1000}\/spooler\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","11539" +"*/SpoolFool.exe*",".{0,1000}\/SpoolFool\.exe.{0,1000}","offensive_tool_keyword","SpoolFool","Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)","T1068 - T1055 - T1059.003","TA0004 - TA0005 - TA0003","","Dispossessor","Privilege Escalation","https://github.com/ly4k/SpoolFool","1","1","N/A","N/A","9","8","788","160","2022-02-09T16:54:09Z","2022-02-08T17:25:44Z","11540" +"*/SpoolFool.git*",".{0,1000}\/SpoolFool\.git.{0,1000}","offensive_tool_keyword","SpoolFool","Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)","T1068 - T1055 - T1059.003","TA0004 - TA0005 - TA0003","","Dispossessor","Privilege Escalation","https://github.com/ly4k/SpoolFool","1","1","N/A","N/A","9","8","788","160","2022-02-09T16:54:09Z","2022-02-08T17:25:44Z","11541" +"*/SpoolFool.ps1*",".{0,1000}\/SpoolFool\.ps1.{0,1000}","offensive_tool_keyword","SpoolFool","Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)","T1068 - T1055 - T1059.003","TA0004 - TA0005 - TA0003","","Dispossessor","Privilege Escalation","https://github.com/ly4k/SpoolFool","1","1","N/A","N/A","9","8","788","160","2022-02-09T16:54:09Z","2022-02-08T17:25:44Z","11542" +"*/spoolsystem/SpoolTrigger/*",".{0,1000}\/spoolsystem\/SpoolTrigger\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","11543" +"*/SpoolTrigger.x64.dll*",".{0,1000}\/SpoolTrigger\.x64\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11544" +"*/SpoolTrigger.x86.dll*",".{0,1000}\/SpoolTrigger\.x86\.dll.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11545" +"*/spray/spray.py*",".{0,1000}\/spray\/spray\.py.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","1","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","11546" +"*/Spray365*",".{0,1000}\/Spray365.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","1","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","11547" +"*/Spray-AD.*",".{0,1000}\/Spray\-AD\..{0,1000}","offensive_tool_keyword","cobaltstrike","A Cobalt Strike tool to audit Active Directory user accounts for weak - well known or easy guessable passwords.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Spray-AD","1","1","N/A","N/A","10","10","436","54","2022-04-01T07:03:39Z","2020-01-09T10:10:48Z","11548" +"*/SprayAD.exe*",".{0,1000}\/SprayAD\.exe.{0,1000}","offensive_tool_keyword","C2-Tool-Collection","A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques","T1055 - T1218 - T1059 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","C2","https://github.com/outflanknl/C2-Tool-Collection","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","11549" +"*/Spray-AD/*",".{0,1000}\/Spray\-AD\/.{0,1000}","offensive_tool_keyword","cobaltstrike","A Cobalt Strike tool to audit Active Directory user accounts for weak - well known or easy guessable passwords.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Spray-AD","1","1","N/A","N/A","10","10","436","54","2022-04-01T07:03:39Z","2020-01-09T10:10:48Z","11550" +"*/spraycharles.git*",".{0,1000}\/spraycharles\.git.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","1","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","11551" +"*/spraycharles.py*",".{0,1000}\/spraycharles\.py.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","1","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","11552" +"*/sprayers/owa.py*",".{0,1000}\/sprayers\/owa\.py.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","1","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","11554" +"*/sprayhound.git*",".{0,1000}\/sprayhound\.git.{0,1000}","offensive_tool_keyword","sprayhound","Password spraying tool and Bloodhound integration","T1110.003 - T1210.001 - T1069.002","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/Hackndo/sprayhound","1","1","N/A","N/A","N/A","3","231","19","2024-12-31T08:09:37Z","2020-02-06T17:45:37Z","11555" +"*/sprayhound/*.py*",".{0,1000}\/sprayhound\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","sprayhound","Password spraying tool and Bloodhound integration","T1110.003 - T1210.001 - T1069.002","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/Hackndo/sprayhound","1","1","N/A","N/A","N/A","3","231","19","2024-12-31T08:09:37Z","2020-02-06T17:45:37Z","11556" +"*/spraying.py*",".{0,1000}\/spraying\.py.{0,1000}","offensive_tool_keyword","Vajra","Vajra is a UI based tool with multiple techniques for attacking and enumerating in target's Azure environment","T1087 - T1098 - T1583 - T1078 - T1110 - T1566 - T1537 - T1020 - T1526 - T1482","TA0003 - TA0006 - TA0007 - TA0008 - TA0009","N/A","N/A","Exploitation tool","https://github.com/TROUBLE-1/Vajra","1","1","N/A","N/A","N/A","4","391","61","2025-02-21T16:40:23Z","2022-03-01T14:31:27Z","11557" +"*/SprayingToolkit*",".{0,1000}\/SprayingToolkit.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","1","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","11558" +"*/SprayLove.py*",".{0,1000}\/SprayLove\.py.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","1","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","11560" +"*/spray-results.txt*",".{0,1000}\/spray\-results\.txt.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","11561" +"*/Spring4Shell-POC*",".{0,1000}\/Spring4Shell\-POC.{0,1000}","offensive_tool_keyword","Spring4Shell","Dockerized Spring4Shell (CVE-2022-22965) PoC application and exploit","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/reznok/Spring4Shell-POC","1","1","N/A","N/A","N/A","4","311","236","2022-08-04T18:26:18Z","2022-03-31T00:24:28Z","11562" +"*/Spring4Shell-POC*",".{0,1000}\/Spring4Shell\-POC.{0,1000}","offensive_tool_keyword","Spring4Shell","Spring4Shell Proof Of Concept/Information CVE-2022-22965","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/BobTheShoplifter/Spring4Shell-POC","1","1","N/A","N/A","N/A","4","366","108","2022-11-09T15:46:06Z","2022-03-30T07:54:45Z","11563" +"*/SpringCore0day*",".{0,1000}\/SpringCore0day.{0,1000}","offensive_tool_keyword","SpringCore0day","SpringCore0day from share.vx-underground.org & some additional links","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/craig/SpringCore0day","1","1","N/A","N/A","N/A","4","394","194","2022-03-31T11:54:22Z","2022-03-30T15:50:28Z","11564" +"*/spring-core-rce*",".{0,1000}\/spring\-core\-rce.{0,1000}","offensive_tool_keyword","spring-core-rce","CVE-2022-22965 : about spring core rce","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/Mr-xn/spring-core-rce","1","1","N/A","N/A","N/A","1","50","18","2022-04-01T15:34:03Z","2022-03-30T14:35:00Z","11565" +"*/Spring-CVE/*",".{0,1000}\/Spring\-CVE\/.{0,1000}","offensive_tool_keyword","POC","POC exploit for CVE-2022-22963","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/kh4sh3i/Spring-CVE","1","1","N/A","N/A","N/A","1","14","7","2022-03-31T20:58:54Z","2022-03-31T20:19:51Z","11566" +"*/springshell-rce-poc*",".{0,1000}\/springshell\-rce\-poc.{0,1000}","offensive_tool_keyword","Spring4Shell","CVE-2022-22965 - CVE-2010-1622 redux","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/DDuarte/springshell-rce-poc","1","1","N/A","N/A","N/A","1","19","12","2023-04-18T14:15:42Z","2022-03-31T08:06:46Z","11568" +"*/Spyndicapped.exe*",".{0,1000}\/Spyndicapped\.exe.{0,1000}","offensive_tool_keyword","Spyndicapped","COM ViewLogger - keylogger","T1574.001 - T1574.002 - T1574.009","TA0006","N/A","N/A","Credential Access","https://github.com/CICADA8-Research/Spyndicapped","1","1","N/A","N/A","10","4","356","50","2025-01-06T07:31:29Z","2024-12-25T11:47:39Z","11569" +"*/Spyndicapped.git*",".{0,1000}\/Spyndicapped\.git.{0,1000}","offensive_tool_keyword","Spyndicapped","COM ViewLogger - keylogger","T1574.001 - T1574.002 - T1574.009","TA0006","N/A","N/A","Credential Access","https://github.com/CICADA8-Research/Spyndicapped","1","1","N/A","N/A","10","4","356","50","2025-01-06T07:31:29Z","2024-12-25T11:47:39Z","11570" +"*/sql_inj.txt*",".{0,1000}\/sql_inj\.txt.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","11571" +"*/SQLC2.ps1*",".{0,1000}\/SQLC2\.ps1.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","11572" +"*/sqli.txt*",".{0,1000}\/sqli\.txt.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","11573" +"*/sqli/mssqli*",".{0,1000}\/sqli\/mssqli.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","11574" +"*/sqli/mysqli*",".{0,1000}\/sqli\/mysqli.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","11575" +"*/sqli/postgresqli*",".{0,1000}\/sqli\/postgresqli.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","11576" +"*/sqli/sqlitei*",".{0,1000}\/sqli\/sqlitei.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","11577" +"*/sqli/utils*",".{0,1000}\/sqli\/utils.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","11578" +"*/sqli_test.rb*",".{0,1000}\/sqli_test\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","11579" +"*/Sqlmap*",".{0,1000}\/Sqlmap.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","11580" +"*/sqlmap.zip*",".{0,1000}\/sqlmap\.zip.{0,1000}","offensive_tool_keyword","sqlipy","SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.","T1190 - T1210 - T1574","TA0002 - TA0040 - TA0043","N/A","N/A","Exploitation tool","https://github.com/codewatchorg/sqlipy","1","1","N/A","network exploitation tool","N/A","3","254","92","2024-06-19T23:38:41Z","2014-09-22T03:25:42Z","11581" +"*/SQLRecon*",".{0,1000}\/SQLRecon.{0,1000}","offensive_tool_keyword","SQLRecon","A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation","T1003.003 - T1049 - T1059.005 - T1078.003","TA0005 - TA0006 - TA0002 - TA0004","N/A","Black Basta","Exploitation tool","https://github.com/skahwah/SQLRecon","1","1","N/A","N/A","9","8","719","120","2025-01-10T17:42:49Z","2021-11-19T15:58:49Z","11582" +"*/sqrtZeroKnowledge/CVE-*",".{0,1000}\/sqrtZeroKnowledge\/CVE\-.{0,1000}","offensive_tool_keyword","poc","Exploit for the CVE-2023-23398","T1068 - T1557.001 - T1187 - T1212 -T1003.001 - T1550","TA0003 - TA0002 - TA0004","N/A","N/A","Exploitation tool","https://github.com/sqrtZeroKnowledge/CVE-2023-23397_EXPLOIT_0DAY","1","1","N/A","N/A","N/A","2","161","41","2023-03-15T17:53:53Z","2023-03-15T17:03:38Z","11583" +"*/src/exploit.html.tpl*",".{0,1000}\/src\/exploit\.html\.tpl.{0,1000}","offensive_tool_keyword","POC","Just another PoC for the new MSDT-Exploit","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/komomon/CVE-2022-30190-follina-Office-MSDT-Fixed","1","1","N/A","N/A","N/A","4","396","54","2023-04-13T16:46:26Z","2022-06-02T12:33:18Z","11585" +"*/src/gTunnel/configured*",".{0,1000}\/src\/gTunnel\/configured.{0,1000}","offensive_tool_keyword","gTunnel","tunelling solution written in golang","T1573.002 - T1071 - T1090 - T1105 - T1020","TA0005 - TA0010 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hotnops/gTunnel","1","1","N/A","N/A","10","10","266","49","2023-05-17T05:24:58Z","2020-03-09T02:52:48Z","11587" +"*/src/gTunnel/gserver/*",".{0,1000}\/src\/gTunnel\/gserver\/.{0,1000}","offensive_tool_keyword","gTunnel","tunelling solution written in golang","T1573.002 - T1071 - T1090 - T1105 - T1020","TA0005 - TA0010 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hotnops/gTunnel","1","1","N/A","N/A","10","10","266","49","2023-05-17T05:24:58Z","2020-03-09T02:52:48Z","11588" +"*/src/john.com*",".{0,1000}\/src\/john\.com.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","11590" +"*/src/jumbo.c*",".{0,1000}\/src\/jumbo\.c.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","11591" +"*/src/jumbo.h*",".{0,1000}\/src\/jumbo\.h.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","11592" +"*/src/KaynStrike.c*",".{0,1000}\/src\/KaynStrike\.c.{0,1000}","offensive_tool_keyword","KaynStrike","A User Defined Reflective Loader for Cobalt Strike Beacon that spoofs the thread start address and frees itself after entry point was executed.","T1055 - T1036 - T1070 - T1055.012 - T1055.001","TA0002 - TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/KaynStrike","1","1","N/A","N/A","9","5","422","66","2023-12-03T18:05:11Z","2022-05-30T04:22:59Z","11593" +"*/src/pendulum.c*",".{0,1000}\/src\/pendulum\.c.{0,1000}","offensive_tool_keyword","pendulum","Linux Sleep Obfuscation","T1027 - T1036","TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/kyleavery/pendulum","1","1","#linux","N/A","9","1","95","11","2024-01-07T20:33:01Z","2024-01-07T20:32:38Z","11595" +"*/src/pendulum.h*",".{0,1000}\/src\/pendulum\.h.{0,1000}","offensive_tool_keyword","pendulum","Linux Sleep Obfuscation","T1027 - T1036","TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/kyleavery/pendulum","1","1","#linux","N/A","9","1","95","11","2024-01-07T20:33:01Z","2024-01-07T20:32:38Z","11596" +"*/src/RecycledGate.h*",".{0,1000}\/src\/RecycledGate\.h.{0,1000}","offensive_tool_keyword","RecycledInjector","Native Syscalls Shellcode Injector","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/florylsk/RecycledInjector","1","1","N/A","N/A","N/A","3","266","43","2023-07-02T11:04:28Z","2023-06-23T16:14:56Z","11597" +"*/src/Sleeper.cpp*",".{0,1000}\/src\/Sleeper\.cpp.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files (BOF) for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/crypt0p3g/bof-collection","1","1","N/A","N/A","10","10","175","27","2022-12-05T04:49:33Z","2021-01-20T06:07:38Z","11598" +"*/src/unixshell.rs*",".{0,1000}\/src\/unixshell\.rs.{0,1000}","offensive_tool_keyword","rustcat","Rustcat(rcat) - The modern Port listener and Reverse shell","T1090.001 - T1090.002 - T1046","TA0011 - TA0009 - TA0040","N/A","N/A","C2","https://github.com/robiot/rustcat","1","1","N/A","N/A","10","10","758","63","2024-07-20T14:20:34Z","2021-06-04T17:03:47Z","11599" +"*/src/winsos.cpp*",".{0,1000}\/src\/winsos\.cpp.{0,1000}","offensive_tool_keyword","winsos-poc","A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.","T1574.002","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/thiagopeixoto/winsos-poc","1","1","N/A","N/A","10","2","111","26","2024-03-10T22:15:50Z","2024-03-10T21:35:08Z","11600" +"*/srdi-shellcode.go*",".{0,1000}\/srdi\-shellcode\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11601" +"*/SSH R.A.T.exe*",".{0,1000}\/SSH\sR\.A\.T\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","11603" +"*/ssh2-enum-algos.nse*",".{0,1000}\/ssh2\-enum\-algos\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11604" +"*/sshamble.git*",".{0,1000}\/sshamble\.git.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","1","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","11605" +"*/ssh-auth-methods.nse*",".{0,1000}\/ssh\-auth\-methods\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11607" +"*/ssh-brute.nse*",".{0,1000}\/ssh\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11608" +"*/ssh-hostkey.nse*",".{0,1000}\/ssh\-hostkey\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11609" +"*/sshimpanzee.git*",".{0,1000}\/sshimpanzee\.git.{0,1000}","offensive_tool_keyword","sshimpanzee","SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS - ICMP - HTTP Encapsulation - HTTP/Socks Proxies - UDP","T1572 - T1095 - T1090 - T1043","TA0010 - TA0011 - TA0005","N/A","Scattered Spider*","C2","https://github.com/lexfo/sshimpanzee","1","1","N/A","N/A","10","10","263","27","2025-03-05T08:32:56Z","2023-04-03T10:11:27Z","11610" +"*/ssh-publickey-acceptance.nse*",".{0,1000}\/ssh\-publickey\-acceptance\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11612" +"*/ssh-run.nse*",".{0,1000}\/ssh\-run\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11613" +"*/SSH-Snake.git*",".{0,1000}\/SSH\-Snake\.git.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","1","N/A","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","11614" +"*/SSH-Snake/*",".{0,1000}\/SSH\-Snake\/.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","1","N/A","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","11615" +"*/sshv1.nse*",".{0,1000}\/sshv1\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11625" +"*/ssl-ccs-injection.nse*",".{0,1000}\/ssl\-ccs\-injection\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11627" +"*/ssl-cert.nse*",".{0,1000}\/ssl\-cert\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11628" +"*/ssl-cert-intaddr.nse*",".{0,1000}\/ssl\-cert\-intaddr\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11629" +"*/ssl-date.nse*",".{0,1000}\/ssl\-date\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11630" +"*/ssl-dh-params.nse*",".{0,1000}\/ssl\-dh\-params\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11631" +"*/ssl-enum-ciphers.nse*",".{0,1000}\/ssl\-enum\-ciphers\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11632" +"*/ssl-heartbleed.nse*",".{0,1000}\/ssl\-heartbleed\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11633" +"*/ssl-known-key.nse*",".{0,1000}\/ssl\-known\-key\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11634" +"*/ssl-poodle.nse*",".{0,1000}\/ssl\-poodle\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11635" +"*/sslv2.nse*",".{0,1000}\/sslv2\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11636" +"*/sslv2-drown.nse*",".{0,1000}\/sslv2\-drown\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11637" +"*/SspiUacBypass.git*",".{0,1000}\/SspiUacBypass\.git.{0,1000}","offensive_tool_keyword","SspiUacBypass","Bypassing UAC with SSPI Datagram Contexts","T1548.002","TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/SspiUacBypass","1","1","N/A","N/A","10","5","433","56","2023-09-24T17:33:25Z","2023-09-14T20:59:22Z","11639" +"*/ssploit/*",".{0,1000}\/ssploit\/.{0,1000}","offensive_tool_keyword","spoolsploit","A collection of Windows print spooler exploits containerized with other utilities for practical exploitation.","T1204 - T1547 - T1562 - T1003 - T1018 - T1570 - T1005","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/BeetleChunks/SpoolSploit","1","1","N/A","N/A","N/A","6","555","90","2021-07-16T04:49:43Z","2021-07-07T00:32:28Z","11640" +"*/SSRFmap*",".{0,1000}\/SSRFmap.{0,1000}","offensive_tool_keyword","SSRFmap","Automatic SSRF fuzzer and exploitation tool","T1210 - T1211 - T1212 - T1574","TA0002 - TA0007 - TA0008","N/A","N/A","Exploitation tool","https://github.com/swisskyrepo/SSRFmap","1","1","N/A","N/A","N/A","10","3167","538","2025-02-26T19:39:06Z","2018-10-15T19:08:26Z","11641" +"*/sstp-discover.nse*",".{0,1000}\/sstp\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11642" +"*/Sst-Sheller.php*",".{0,1000}\/Sst\-Sheller\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","11643" +"*/StackCrypt.git*",".{0,1000}\/StackCrypt\.git.{0,1000}","offensive_tool_keyword","StackCrypt","Create a new thread that will suspend every thread and encrypt its stack then going to sleep then decrypt the stacks and resume threads","T1027 - T1055.004 - T1486","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/StackCrypt","1","1","N/A","N/A","9","2","159","27","2023-08-02T02:25:12Z","2023-04-26T03:24:56Z","11644" +"*/stager.ps1*",".{0,1000}\/stager\.ps1.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","11645" +"*/stager/powershell.py*",".{0,1000}\/stager\/powershell\.py.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","11646" +"*/stager/powershell/payload.ps1*",".{0,1000}\/stager\/powershell\/payload\.ps1.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","11647" +"*/stagers/*.ps1*",".{0,1000}\/stagers\/.{0,1000}\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1066","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","11648" +"*/stagers/CSharpPS*",".{0,1000}\/stagers\/CSharpPS.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","11649" +"*/StandIn.exe*",".{0,1000}\/StandIn\.exe.{0,1000}","offensive_tool_keyword","StandIn","StandIn is a small .NET35/45 AD post-exploitation toolkit","T1087 - T1069 - T1558 - T1204 - T1136 - T1482","TA0007 - TA0003 - TA0006 - TA0004","N/A","N/A","Discovery","https://github.com/FuzzySecurity/StandIn","1","1","N/A","N/A","9","8","761","129","2023-12-02T21:20:09Z","2020-11-05T22:49:27Z","11650" +"*/StandIn.git*",".{0,1000}\/StandIn\.git.{0,1000}","offensive_tool_keyword","StandIn","StandIn is a small .NET35/45 AD post-exploitation toolkit","T1087 - T1069 - T1558 - T1204 - T1136 - T1482","TA0007 - TA0003 - TA0006 - TA0004","N/A","N/A","Discovery","https://github.com/FuzzySecurity/StandIn","1","1","N/A","N/A","9","8","761","129","2023-12-02T21:20:09Z","2020-11-05T22:49:27Z","11651" +"*/StandIn_Net35.exe*",".{0,1000}\/StandIn_Net35\.exe.{0,1000}","offensive_tool_keyword","StandIn","StandIn is a small .NET35/45 AD post-exploitation toolkit","T1087 - T1069 - T1558 - T1204 - T1136 - T1482","TA0007 - TA0003 - TA0006 - TA0004","N/A","N/A","Discovery","https://github.com/FuzzySecurity/StandIn","1","1","N/A","N/A","9","8","761","129","2023-12-02T21:20:09Z","2020-11-05T22:49:27Z","11652" +"*/StandIn_Net45.exe *",".{0,1000}\/StandIn_Net45\.exe\s.{0,1000}","offensive_tool_keyword","StandIn","StandIn is a small .NET35/45 AD post-exploitation toolkit","T1087 - T1069 - T1558 - T1204 - T1136 - T1482","TA0007 - TA0003 - TA0006 - TA0004","N/A","N/A","Discovery","https://github.com/FuzzySecurity/StandIn","1","1","N/A","N/A","9","8","761","129","2023-12-02T21:20:09Z","2020-11-05T22:49:27Z","11653" +"*/StandIn-1.3.zip*",".{0,1000}\/StandIn\-1\.3\.zip.{0,1000}","offensive_tool_keyword","StandIn","StandIn is a small .NET35/45 AD post-exploitation toolkit","T1087 - T1069 - T1558 - T1204 - T1136 - T1482","TA0007 - TA0003 - TA0006 - TA0004","N/A","N/A","Discovery","https://github.com/FuzzySecurity/StandIn","1","1","N/A","N/A","9","8","761","129","2023-12-02T21:20:09Z","2020-11-05T22:49:27Z","11654" +"*/stardust.x64.exe*",".{0,1000}\/stardust\.x64\.exe.{0,1000}","offensive_tool_keyword","Stardust","An modern 64-bit position independent implant template","T1055 - T1105 - T1055.012 - T1027 - T1218","TA0005 - TA0003 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/Stardust","1","1","N/A","N/A","10","10","1193","193","2025-03-21T11:41:09Z","2022-02-20T01:23:35Z","11655" +"*/Stardust/scripts/loader.x64.exe*",".{0,1000}\/Stardust\/scripts\/loader\.x64\.exe.{0,1000}","offensive_tool_keyword","Stardust","An modern 64-bit position independent implant template","T1055 - T1105 - T1055.012 - T1027 - T1218","TA0005 - TA0003 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/Stardust","1","1","N/A","N/A","10","10","1193","193","2025-03-21T11:41:09Z","2022-02-20T01:23:35Z","11656" +"*/start_campaign.py*",".{0,1000}\/start_campaign\.py.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","11658" +"*/startProxyPool?k=*&random=n&number=2&ip=*",".{0,1000}\/startProxyPool\?k\=.{0,1000}\&random\=n\&number\=2\&ip\=.{0,1000}","offensive_tool_keyword","SecScanC2","SecScanC2 can manage assetment to create P2P network for security scanning & C2. The tool can assist security researchers in conducting penetration testing more efficiently - preventing scanning from being blocked - protecting themselves from being traced.","T1021 - T1090","TA0011 - TA0002 - TA0040 - TA0043","N/A","N/A","C2","https://github.com/T1esh0u/SecScanC2","1","1","#P2P","N/A","10","","N/A","","","","11659" +"*/startProxyPool?k=*&random=y&number=2*",".{0,1000}\/startProxyPool\?k\=.{0,1000}\&random\=y\&number\=2.{0,1000}","offensive_tool_keyword","SecScanC2","SecScanC2 can manage assetment to create P2P network for security scanning & C2. The tool can assist security researchers in conducting penetration testing more efficiently - preventing scanning from being blocked - protecting themselves from being traced.","T1021 - T1090","TA0011 - TA0002 - TA0040 - TA0043","N/A","N/A","C2","https://github.com/T1esh0u/SecScanC2","1","1","#P2P","N/A","10","","N/A","","","","11660" +"*/StaticSyscallsAPCSpawn/*",".{0,1000}\/StaticSyscallsAPCSpawn\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","11662" +"*/StaticSyscallsInject/*",".{0,1000}\/StaticSyscallsInject\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","11663" +"*/StayKit.cna*",".{0,1000}\/StayKit\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike kit for Persistence","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/0xthirteen/StayKit","1","1","N/A","N/A","10","10","475","73","2020-01-27T14:53:31Z","2020-01-24T22:20:20Z","11664" +"*/Staykit/StayKit.*",".{0,1000}\/Staykit\/StayKit\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike kit for Persistence","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/0xthirteen/StayKit","1","1","N/A","N/A","10","10","475","73","2020-01-27T14:53:31Z","2020-01-24T22:20:20Z","11665" +"*/Stealer.exe*",".{0,1000}\/Stealer\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11667" +"*/Stealer.exe*",".{0,1000}\/Stealer\.exe.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","1","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","11668" +"*/Stealer.exe*",".{0,1000}\/Stealer\.exe.{0,1000}","offensive_tool_keyword","Rust-Malware-Samples","open source informations stealer in rust","T1003 - T1083 - T1114 - T1074","TA0006 - TA0009 - TA0005","N/A","N/A","Credential Access","https://github.com/Whitecat18/Rust-for-Malware-Development/tree/main/Malware-Samples","1","1","N/A","N/A","10","10","2123","53","2025-04-22T18:09:57Z","2024-02-12T16:55:06Z","11669" +"*/Stealer.sln*",".{0,1000}\/Stealer\.sln.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","1","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","11670" +"*/stickykey.ps1*",".{0,1000}\/stickykey\.ps1.{0,1000}","offensive_tool_keyword","Persistence-Accessibility-Features","automated sticky keys backdoor","T1174 - T1078 - T1546.013","TA0003","N/A","N/A","Persistence","https://github.com/Ignitetechnologies/Persistence-Accessibility-Features","1","1","N/A","N/A","9","1","34","12","2020-05-18T05:59:58Z","2020-05-18T05:59:23Z","11672" +"*/Stickykeys.sh*",".{0,1000}\/Stickykeys\.sh.{0,1000}","offensive_tool_keyword","WinPirate","automated sticky keys backdoor + credentials harvesting","T1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003","TA0003 - TA0005 - TA0006","N/A","N/A","Persistence","https://github.com/l3m0n/WinPirate","1","1","N/A","N/A","9","1","13","32","2016-07-17T20:02:07Z","2016-07-18T03:40:13Z","11673" +"*/StickyNotesExtract.exe*",".{0,1000}\/StickyNotesExtract\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11674" +"*/StickyNotesExtract.exe*",".{0,1000}\/StickyNotesExtract\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11675" +"*/StickyNotesExtract.exe*",".{0,1000}\/StickyNotesExtract\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11676" +"*/stinger_client.py*",".{0,1000}\/stinger_client\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","11677" +"*/Stompy.git*",".{0,1000}\/Stompy\.git.{0,1000}","offensive_tool_keyword","Stompy","Timestomp Tool to flatten MAC times with a specific timestamp","T1070.006","TA0005","N/A","N/A","Defense Evasion","https://github.com/ZephrFish/Stompy","1","1","N/A","N/A","10","1","46","6","2023-10-15T17:38:23Z","2023-10-14T23:40:32Z","11678" +"*/Stompy.ps1*",".{0,1000}\/Stompy\.ps1.{0,1000}","offensive_tool_keyword","Stompy","Timestomp Tool to flatten MAC times with a specific timestamp","T1070.006","TA0005","N/A","N/A","Defense Evasion","https://github.com/ZephrFish/Stompy","1","1","N/A","N/A","10","1","46","6","2023-10-15T17:38:23Z","2023-10-14T23:40:32Z","11679" +"*/StomPY.py*",".{0,1000}\/StomPY\.py.{0,1000}","offensive_tool_keyword","Stompy","Timestomp Tool to flatten MAC times with a specific timestamp","T1070.006","TA0005","N/A","N/A","Defense Evasion","https://github.com/ZephrFish/Stompy","1","1","N/A","N/A","10","1","46","6","2023-10-15T17:38:23Z","2023-10-14T23:40:32Z","11680" +"*/Stowaway.git*",".{0,1000}\/Stowaway\.git.{0,1000}","offensive_tool_keyword","stowaway","Stowaway -- Multi-hop Proxy Tool for pentesters","T1021 - T1090 - T1071 - T1573","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/ph4ntonn/Stowaway","1","1","N/A","N/A","10","10","2989","422","2025-04-05T14:48:38Z","2019-11-15T03:25:50Z","11681" +"*/Stracciatella/releases/latest/download/Stracciatella.exe*",".{0,1000}\/Stracciatella\/releases\/latest\/download\/Stracciatella\.exe.{0,1000}","offensive_tool_keyword","link","link is a command and control framework written in rust","T1071 - T1094 - T1132 - T1008 - T1024","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/postrequest/link","1","1","N/A","N/A","10","10","575","90","2021-08-18T11:53:55Z","2021-02-02T11:15:43Z","11684" +"*/striker.c",".{0,1000}\/striker\.c","offensive_tool_keyword","Striker","Striker is a simple Command and Control (C2) program.","T1071 - T1071.001 - T1071.004 - T1071.005 - T1071.006 - T1071.007 - T1071.008 - T1071.009 - T1071.010 - T1071.012 - T1071.013 - T1071.014 - T1071.015 - T1071.016 - T1071.018 - T1105 - T1105.002 - T1573 - T1573.002 - T1573.003 - T1573.004 - T1573.005","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/4g3nt47/Striker","1","1","N/A","N/A","10","10","301","42","2023-05-04T18:00:05Z","2022-09-07T10:09:41Z","11685" +"*/Striker.git*",".{0,1000}\/Striker\.git.{0,1000}","offensive_tool_keyword","Striker","Striker is a simple Command and Control (C2) program.","T1071 - T1071.001 - T1071.004 - T1071.005 - T1071.006 - T1071.007 - T1071.008 - T1071.009 - T1071.010 - T1071.012 - T1071.013 - T1071.014 - T1071.015 - T1071.016 - T1071.018 - T1105 - T1105.002 - T1573 - T1573.002 - T1573.003 - T1573.004 - T1573.005","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/4g3nt47/Striker","1","1","N/A","N/A","10","10","301","42","2023-05-04T18:00:05Z","2022-09-07T10:09:41Z","11686" +"*/striker.local*",".{0,1000}\/striker\.local.{0,1000}","offensive_tool_keyword","Striker","Striker is a simple Command and Control (C2) program.","T1071 - T1071.001 - T1071.004 - T1071.005 - T1071.006 - T1071.007 - T1071.008 - T1071.009 - T1071.010 - T1071.012 - T1071.013 - T1071.014 - T1071.015 - T1071.016 - T1071.018 - T1105 - T1105.002 - T1573 - T1573.002 - T1573.003 - T1573.004 - T1573.005","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/4g3nt47/Striker","1","1","N/A","N/A","10","10","301","42","2023-05-04T18:00:05Z","2022-09-07T10:09:41Z","11687" +"*/striker.py",".{0,1000}\/striker\.py","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","11688" +"*/string_of_paerls.profile*",".{0,1000}\/string_of_paerls\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","11689" +"*/stun-info.nse*",".{0,1000}\/stun\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11690" +"*/stun-version.nse*",".{0,1000}\/stun\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11695" +"*/stuxnet-detect.nse*",".{0,1000}\/stuxnet\-detect\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11696" +"*/subbrute.git*",".{0,1000}\/subbrute\.git.{0,1000}","offensive_tool_keyword","subbrute","A DNS meta-query spider that enumerates DNS records and subdomains.","T1071.001 - T1083 - T1590.001","TA0043 - TA0007?","N/A","ENERGETIC BEAR","Reconnaissance","https://github.com/TheRook/subbrute","1","1","N/A","N/A","5","10","3422","661","2022-01-13T09:25:59Z","2012-06-10T01:08:20Z","11697" +"*/subbrute.py*",".{0,1000}\/subbrute\.py.{0,1000}","offensive_tool_keyword","subbrute","A DNS meta-query spider that enumerates DNS records and subdomains.","T1071.001 - T1083 - T1590.001","TA0043 - TA0007?","N/A","ENERGETIC BEAR","Reconnaissance","https://github.com/TheRook/subbrute","1","1","N/A","N/A","5","10","3422","661","2022-01-13T09:25:59Z","2012-06-10T01:08:20Z","11698" +"*/subbrute/releases/download/*",".{0,1000}\/subbrute\/releases\/download\/.{0,1000}","offensive_tool_keyword","subbrute","A DNS meta-query spider that enumerates DNS records and subdomains.","T1071.001 - T1083 - T1590.001","TA0043 - TA0007?","N/A","ENERGETIC BEAR","Reconnaissance","https://github.com/TheRook/subbrute","1","1","N/A","N/A","5","10","3422","661","2022-01-13T09:25:59Z","2012-06-10T01:08:20Z","11699" +"*/subdomain.yaml*",".{0,1000}\/subdomain\.yaml.{0,1000}","offensive_tool_keyword","Osmedeus","Osmedeus - A Workflow Engine for Offensive Security","T1595","TA0043","N/A","N/A","Exploitation tool","https://github.com/j3ssie/osmedeus","1","1","N/A","N/A","N/A","10","5566","907","2025-04-22T14:57:07Z","2018-11-10T04:17:18Z","11700" +"*/subdomains_n0kovo_big.txt*",".{0,1000}\/subdomains_n0kovo_big\.txt.{0,1000}","offensive_tool_keyword","reconftw","reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities","T1595 - T1590 - T1592 - T1596 - T1598 - T1046 - T1599 - T1213 - T1597","TA0043 - TA0042 - TA0007 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/six2dez/reconftw","1","1","#linux","N/A","7","10","6202","982","2025-04-22T13:01:31Z","2020-12-30T23:52:52Z","11702" +"*/Sublist3r*",".{0,1000}Sublist3r.{0,1000}","offensive_tool_keyword","Sublist3r","Sublist3r is a python tool designed to enumerate subdomains of websites using OSINT. It helps penetration testers and bug hunters collect and gather subdomains for the domain they are targeting. Sublist3r enumerates subdomains using many search engines such as Google. Yahoo. Bing. Baidu and Ask. Sublist3r also enumerates subdomains using Netcraft. Virustotal. ThreatCrowd. DNSdumpster and ReverseDNS. subbrute was integrated with Sublist3r to increase the possibility of finding more subdomains using bruteforce with an improved wordlist. The credit goes to TheRook who is the author of subbrute.","T1210.001 - T1190 - T1574.001","TA0007 - TA0002 - TA0010","N/A","ENERGETIC BEAR","Reconnaissance","https://github.com/aboul3la/Sublist3r","1","1","N/A","N/A","5","10","10300","2148","2024-08-02T00:00:30Z","2015-12-15T00:55:25Z","11706" +"*/submit_to_nemesis.py*",".{0,1000}\/submit_to_nemesis\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","11707" +"*/submit_to_nemesis.sh*",".{0,1000}\/submit_to_nemesis\.sh.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","11708" +"*/submit_to_nemesis.yaml*",".{0,1000}\/submit_to_nemesis\.yaml.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","11709" +"*/Suborner.git*",".{0,1000}\/Suborner\.git.{0,1000}","offensive_tool_keyword","Suborner","The Invisible Account Forger - A simple program to create a Windows account you will only know about ","T1098 - T1175 - T1033","TA0007 - TA0008 - TA0003","N/A","N/A","Persistence","https://github.com/r4wd3r/Suborner","1","1","N/A","N/A","9","5","469","58","2024-11-20T01:34:44Z","2022-04-26T00:12:58Z","11710" +"*/sudomy.api*",".{0,1000}\/sudomy\.api.{0,1000}","offensive_tool_keyword","Sudomy","Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting","T1595 - T1046","TA0002","N/A","N/A","Reconnaissance","https://github.com/screetsec/Sudomy","1","1","#linux","N/A","N/A","10","2139","396","2024-06-27T10:07:42Z","2019-07-26T10:26:34Z","11713" +"*/sullo/nikto*",".{0,1000}\/sullo\/nikto.{0,1000}","offensive_tool_keyword","nikto","Nikto web scanner tool","T1210.001 - T1190 - T1046 - T1222","TA0007 - TA0002 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/sullo/nikto","1","1","#linux","N/A","N/A","10","9184","1306","2025-02-22T14:30:28Z","2012-11-24T04:24:29Z","11714" +"*/sunder.exe*",".{0,1000}\/sunder\.exe.{0,1000}","offensive_tool_keyword","Sunder","Windows rootkit designed to work with BYOVD exploits","T1543.003 - T1562.001 - T1547.001 - T1068 - T1548.002","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/ColeHouston/Sunder","1","1","N/A","N/A","10","2","183","20","2025-01-18T10:41:50Z","2025-01-10T03:57:05Z","11715" +"*/sunlogin_rce*",".{0,1000}\/sunlogin_rce.{0,1000}","offensive_tool_keyword","POC","SunloginClient RCE vulnerable version","T1587","TA0001 - TA0003 - TA0009","N/A","N/A","Exploitation tool","https://github.com/Mr-xn/sunlogin_rce","1","1","N/A","N/A","N/A","5","484","195","2022-02-16T16:11:42Z","2022-02-16T14:20:41Z","11716" +"*/Suntour.ps1*",".{0,1000}\/Suntour\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","11717" +"*/Sup3r-Us3r/scripts/*",".{0,1000}\/Sup3r\-Us3r\/scripts\/.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://raw.githubusercontent.com/Sup3r-Us3r/scripts/master/fb-brute.pl","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","11728" +"*/supermicro-ipmi-conf.nse*",".{0,1000}\/supermicro\-ipmi\-conf\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11729" +"*/Supernova.exe*",".{0,1000}\/Supernova\.exe.{0,1000}","offensive_tool_keyword","Supernova","securely encrypt raw shellcodes","T1027 - T1055.004 - T1140","TA0002 - TA0005 - TA0042","N/A","N/A","Exploitation tool","https://github.com/nickvourd/Supernova","1","1","N/A","N/A","10","9","829","151","2025-04-18T19:15:22Z","2023-08-08T11:30:34Z","11730" +"*/Supernova.git*",".{0,1000}\/Supernova\.git.{0,1000}","offensive_tool_keyword","Supernova","securely encrypt raw shellcodes","T1027 - T1055.004 - T1140","TA0002 - TA0005 - TA0042","N/A","N/A","Exploitation tool","https://github.com/nickvourd/Supernova","1","1","N/A","N/A","10","9","829","151","2025-04-18T19:15:22Z","2023-08-08T11:30:34Z","11731" +"*/SuperProfileDLL*",".{0,1000}\/SuperProfileDLL.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","11732" +"*/Supershell.tar.gz*",".{0,1000}\/Supershell\.tar\.gz.{0,1000}","offensive_tool_keyword","supershell","Supershell is a C2 remote control platform accessed through WEB services. By establishing a reverse SSH tunnel it obtains a fully interactive Shell and supports multi-platform architecture Payload","T1090 - T1059 - T1021","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/tdragon6/Supershell","1","1","N/A","N/A","10","10","1561","196","2023-09-26T13:53:55Z","2023-03-25T15:02:43Z","11733" +"*/supershell/login/auth*",".{0,1000}\/supershell\/login\/auth.{0,1000}","offensive_tool_keyword","supershell","Supershell is a C2 remote control platform accessed through WEB services. By establishing a reverse SSH tunnel it obtains a fully interactive Shell and supports multi-platform architecture Payload","T1090 - T1059 - T1021","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/tdragon6/Supershell","1","1","N/A","N/A","10","10","1561","196","2023-09-26T13:53:55Z","2023-03-25T15:02:43Z","11734" +"*/Supershell/releases*",".{0,1000}\/Supershell\/releases.{0,1000}","offensive_tool_keyword","supershell","Supershell is a C2 remote control platform accessed through WEB services. By establishing a reverse SSH tunnel it obtains a fully interactive Shell and supports multi-platform architecture Payload","T1090 - T1059 - T1021","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/tdragon6/Supershell","1","1","N/A","N/A","10","10","1561","196","2023-09-26T13:53:55Z","2023-03-25T15:02:43Z","11735" +"*/Suprise/Suprise.exe*",".{0,1000}\/Suprise\/Suprise\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","11737" +"*/SurveyFile_x64_Release.exe*",".{0,1000}\/SurveyFile_x64_Release\.exe.{0,1000}","offensive_tool_keyword","Tsunami","another C2 framework","T1573 - T1027 - T1059 - T1071 ","TA0011 - TA0009 - TA0003 - TA0007 - TA0008","N/A","N/A","C2","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","11738" +"*/SurveyRegistry_x64_Release.exe*",".{0,1000}\/SurveyRegistry_x64_Release\.exe.{0,1000}","offensive_tool_keyword","Tsunami","another C2 framework","T1573 - T1027 - T1059 - T1071 ","TA0011 - TA0009 - TA0003 - TA0007 - TA0008","N/A","N/A","C2","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","11739" +"*/suspect/master/suspect.sh*",".{0,1000}\/suspect\/master\/suspect\.sh.{0,1000}","offensive_tool_keyword","Orc","Orc is a post-exploitation framework for Linux written in Bash","T1059.004 - T1036.005 - T1070.002 - T1012 - T1082 - T1003 - T1555.003 - T1049 - T1134.001 - T1202","TA0005 - TA0003 - TA0002 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/zMarch/Orc","1","1","#linux","N/A","9","4","395","53","2019-11-12T18:21:27Z","2018-08-16T11:31:39Z","11740" +"*/suspendresume.x64*",".{0,1000}\/suspendresume\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","11741" +"*/suspendresume.x86*",".{0,1000}\/suspendresume\.x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","11742" +"*/svchost_console.exe*",".{0,1000}\/svchost_console\.exe.{0,1000}","offensive_tool_keyword","gh0st","Malware RAT with keylogger - dll injection - C2 - Remote control","T1204.002 - T1071.001 - T1027 - T1036.005 - T1055.001 - T1005 - T1056.001 - T1074.001 - T1105 - T1562.001 - T1543.003 - T1547.001 - T1571 - T1573.001 - T1106 - T1219","TA0002 - TA0003 - TA0004 - TA0008 - TA0009 - TA0010 - TA0011","GhostRAT","N/A","Malware","https://github.com/sin5678/gh0st","1","1","N/A","N/A","10","6","508","274","2013-05-08T21:17:26Z","2012-10-05T06:25:36Z","11743" +"*/svn-brute.nse*",".{0,1000}\/svn\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11744" +"*/SweetPotato.dll*",".{0,1000}\/SweetPotato\.dll.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","11745" +"*/SweetPotato.dll*",".{0,1000}\/SweetPotato\.dll.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","11746" +"*/SweetPotato.exe*",".{0,1000}\/SweetPotato\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11747" +"*/SweetPotato.exe*",".{0,1000}\/SweetPotato\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","11748" +"*/Sweetpotato.exe*",".{0,1000}\/Sweetpotato\.exe.{0,1000}","offensive_tool_keyword","SweetPotato","Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019","T1548 - T1055","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/CCob/SweetPotato","1","1","N/A","N/A","10","10","1697","228","2024-09-04T17:09:30Z","2020-04-12T17:40:03Z","11749" +"*/SweetPotato.git*",".{0,1000}\/SweetPotato\.git.{0,1000}","offensive_tool_keyword","SweetPotato","Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019","T1548 - T1055","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/CCob/SweetPotato","1","1","N/A","N/A","10","10","1697","228","2024-09-04T17:09:30Z","2020-04-12T17:40:03Z","11750" +"*/SweetPotato_CS*",".{0,1000}\/SweetPotato_CS.{0,1000}","offensive_tool_keyword","cobaltstrike","Modified SweetPotato to work with CobaltStrike v4.0","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tycx2ry/SweetPotato_CS","1","1","N/A","N/A","10","10","241","48","2020-04-30T14:27:20Z","2020-04-16T08:01:31Z","11751" +"*/SweetPotato-master.zip*",".{0,1000}\/SweetPotato\-master\.zip.{0,1000}","offensive_tool_keyword","SweetPotato","Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019","T1548 - T1055","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/CCob/SweetPotato","1","1","N/A","N/A","10","10","1697","228","2024-09-04T17:09:30Z","2020-04-12T17:40:03Z","11752" +"*/SwitchPriv.exe*",".{0,1000}\/SwitchPriv\.exe.{0,1000}","offensive_tool_keyword","PrivFu","enable or disable specific token privileges for a process","T1055","TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","SwitchPriv","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","11753" +"*/Synergy-httpx.git*",".{0,1000}\/Synergy\-httpx\.git.{0,1000}","offensive_tool_keyword","Synergy-httpx","A Python http(s) server designed to assist in red teaming activities such as receiving intercepted data via POST requests and serving content dynamically","T1021.002 - T1105 - T1090","TA0002 - TA0011 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/t3l3machus/Synergy-httpx","1","1","N/A","N/A","8","2","129","17","2024-07-19T06:40:59Z","2023-06-02T10:06:41Z","11757" +"*/syscalls/syscalls_windows.go*",".{0,1000}\/syscalls\/syscalls_windows\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","11758" +"*/syscalls/syswhispers/*",".{0,1000}\/syscalls\/syswhispers\/.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1027 - T1055 - T1070 - T1112 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","11759" +"*/syscalls/syswhispersv2*",".{0,1000}\/syscalls\/syswhispersv2.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1027 - T1055 - T1070 - T1112 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","11760" +"*/SyscallsInject/*",".{0,1000}\/SyscallsInject\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","11761" +"*/SysmonQuiet*",".{0,1000}\/SysmonQuiet.{0,1000}","offensive_tool_keyword","sysmonquiet","RDLL for Cobalt Strike beacon to silence Sysmon process","T1055 - T1055.012 - T1063","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/ScriptIdiot/SysmonQuiet","1","1","N/A","N/A","N/A","1","88","16","2022-09-09T12:28:15Z","2022-07-11T14:17:34Z","11764" +"*/SysWhispers2*",".{0,1000}\/SysWhispers2.{0,1000}","offensive_tool_keyword","SysWhispers3","SysWhispers on Steroids - AV/EDR evasion via direct system calls.","T1059 - T1573 - T1218 - T1216","TA0002 - TA0008 - TA0011","N/A","N/A","Defense Evasion","https://github.com/klezVirus/SysWhispers3","1","1","N/A","N/A","N/A","10","1414","180","2024-07-31T05:24:06Z","2022-03-07T18:56:21Z","11771" +"*/SysWhispers3*",".{0,1000}\/SysWhispers3.{0,1000}","offensive_tool_keyword","SysWhispers3","SysWhispers on Steroids - AV/EDR evasion via direct system calls.","T1059 - T1573 - T1218 - T1216","TA0002 - TA0008 - TA0011","N/A","N/A","Defense Evasion","https://github.com/klezVirus/SysWhispers3","1","1","N/A","N/A","N/A","10","1414","180","2024-07-31T05:24:06Z","2022-03-07T18:56:21Z","11772" +"*/SysWhispers3.git*",".{0,1000}\/SysWhispers3\.git.{0,1000}","offensive_tool_keyword","SysWhispers3","SysWhispers on Steroids - AV/EDR evasion via direct system calls.","T1059 - T1573 - T1218 - T1216","TA0002 - TA0008 - TA0011","N/A","N/A","Defense Evasion","https://github.com/klezVirus/SysWhispers3","1","1","N/A","N/A","N/A","10","1414","180","2024-07-31T05:24:06Z","2022-03-07T18:56:21Z","11773" +"*/syswhispersv2*",".{0,1000}\/syswhispersv2.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","11774" +"*/t.me/NicestRAT*",".{0,1000}\/t\.me\/NicestRAT.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","1","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","11775" +"*/t3l3machus/Villain*",".{0,1000}\/t3l3machus\/Villain.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","11777" +"*/taidoor.profile*",".{0,1000}\/taidoor\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","11787" +"*/TakeMyRDP*",".{0,1000}\/TakeMyRDP.{0,1000}","offensive_tool_keyword","TakeMyRDP","A keystroke logger targeting the Remote Desktop Protocol (RDP) related processes","T1056.001 - T1021.001 - T1057","TA0002 - TA0003 - TA0007","N/A","N/A","Exploitation tool","https://github.com/TheD1rkMtr/TakeMyRDP","1","1","N/A","N/A","N/A","4","386","63","2023-08-02T02:23:28Z","2023-07-02T17:25:33Z","11801" +"*/TakeMyRDP2.0*",".{0,1000}\/TakeMyRDP2\.0.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","11802" +"*/Talon/*Agent/Source*",".{0,1000}\/Talon\/.{0,1000}Agent\/Source.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","11804" +"*/TaoWu.cna*",".{0,1000}\/TaoWu\.cna.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","11805" +"*/targetedKerberoast*",".{0,1000}\/targetedKerberoast.{0,1000}","offensive_tool_keyword","targetedKerberoast","Kerberoast with ACL abuse capabilities","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/ShutdownRepo/targetedKerberoast","1","1","N/A","N/A","N/A","5","442","63","2024-12-16T07:32:14Z","2021-08-02T20:19:35Z","11807" +"*/targetedKerberoast.py*",".{0,1000}\/targetedKerberoast\.py.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","11808" +"*/targets-asn.nse*",".{0,1000}\/targets\-asn\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11809" +"*/targets-ipv6-map4to6.nse*",".{0,1000}\/targets\-ipv6\-map4to6\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11810" +"*/targets-ipv6-multicast-echo.nse*",".{0,1000}\/targets\-ipv6\-multicast\-echo\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11811" +"*/targets-ipv6-multicast-invalid-dst.nse*",".{0,1000}\/targets\-ipv6\-multicast\-invalid\-dst\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11812" +"*/targets-ipv6-multicast-mld.nse*",".{0,1000}\/targets\-ipv6\-multicast\-mld\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11813" +"*/targets-ipv6-multicast-slaac.nse*",".{0,1000}\/targets\-ipv6\-multicast\-slaac\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11814" +"*/targets-ipv6-wordlist.nse*",".{0,1000}\/targets\-ipv6\-wordlist\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11815" +"*/targets-sniffer.nse*",".{0,1000}\/targets\-sniffer\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11816" +"*/targets-traceroute.nse*",".{0,1000}\/targets\-traceroute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11817" +"*/targets-xml.nse*",".{0,1000}\/targets\-xml\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11818" +"*/TartarusGate.git*",".{0,1000}\/TartarusGate\.git.{0,1000}","offensive_tool_keyword","TartarusGate","TartarusGate Bypassing EDRs","T1055 - T1218.011 - T1027.009 - T1027 - T1105 - T1102.001","TA0005 - TA0001 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/trickster0/TartarusGate","1","1","N/A","N/A","10","6","579","72","2022-01-25T20:54:28Z","2021-11-27T19:46:30Z","11819" +"*/Tash.dll*",".{0,1000}\/Tash\.dll.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","11820" +"*/TashClient.*",".{0,1000}\/TashClient\..{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","11821" +"*/TashLoader.*",".{0,1000}\/TashLoader\..{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","11822" +"*/Tater.ps1*",".{0,1000}\/Tater\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","11823" +"*/tccbypass.md*",".{0,1000}\/tccbypass\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","11824" +"*/TChopper.git*",".{0,1000}\/TChopper\.git.{0,1000}","offensive_tool_keyword","Tchopper","conduct Lateral Movement attack by leveraging unfiltered services display name to smuggle binaries as chunks into the target machine","T1021 - T1564","TA0008 - TA0005","N/A","N/A","Lateral Movement","https://github.com/lawrenceamer/Tchopper","1","1","N/A","N/A","9","1","54","7","2021-06-14T08:27:31Z","2021-06-08T15:51:14Z","11825" +"*/TCPMITM.py*",".{0,1000}\/TCPMITM\.py.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","#linux","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","11826" +"*/tcpshell.py*",".{0,1000}\/tcpshell\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","11827" +"*/TeamFiltration.dll*",".{0,1000}\/TeamFiltration\.dll.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","11830" +"*/TeamFiltration.exe*",".{0,1000}\/TeamFiltration\.exe.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","11831" +"*/TeamFiltration/releases/latest*",".{0,1000}\/TeamFiltration\/releases\/latest.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","11832" +"*/Teamphisher.txt*",".{0,1000}\/Teamphisher\.txt.{0,1000}","offensive_tool_keyword","teamsphisher","Send phishing messages and attachments to Microsoft Teams users","T1566.001 - T1566.002 - T1204.001","TA0001 - TA0005","N/A","Black Basta","Phishing","https://github.com/Octoberfest7/TeamsPhisher","1","1","N/A","N/A","N/A","10","1073","138","2024-06-19T21:41:55Z","2023-07-03T02:19:47Z","11833" +"*/Teamphisher/targets.txt*",".{0,1000}\/Teamphisher\/targets\.txt.{0,1000}","offensive_tool_keyword","teamsphisher","Send phishing messages and attachments to Microsoft Teams users","T1566.001 - T1566.002 - T1204.001","TA0001 - TA0005","N/A","Black Basta","Phishing","https://github.com/Octoberfest7/TeamsPhisher","1","1","N/A","N/A","N/A","10","1073","138","2024-06-19T21:41:55Z","2023-07-03T02:19:47Z","11834" +"*/teams_dump.git*",".{0,1000}\/teams_dump\.git.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1560.001 - T1555.003 - T1113 - T1557","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","1","N/A","N/A","7","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","11836" +"*/teams_dump.git*",".{0,1000}\/teams_dump\.git.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1555 - T1003 - T1114","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","1","N/A","N/A","9","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","11837" +"*/teams_dump.py*",".{0,1000}\/teams_dump\.py.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1560.001 - T1555.003 - T1113 - T1557","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","1","N/A","N/A","7","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","11838" +"*/teams_dump.py*",".{0,1000}\/teams_dump\.py.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1555 - T1003 - T1114","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","1","N/A","N/A","9","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","11839" +"*/teams_localdb.py*",".{0,1000}\/teams_localdb\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","11840" +"*/TeamsEnum.git*",".{0,1000}\/TeamsEnum\.git.{0,1000}","offensive_tool_keyword","TeamsEnum","User Enumeration of Microsoft Teams users via API","T1589.002 - T1590","TA0007 - TA0001","N/A","Black Basta","Discovery","https://github.com/sse-secure-systems/TeamsEnum","1","1","N/A","N/A","6","2","153","21","2024-03-27T18:14:25Z","2023-04-03T18:35:15Z","11841" +"*/teamsenum.py*",".{0,1000}\/teamsenum\.py.{0,1000}","offensive_tool_keyword","TeamsEnum","User Enumeration of Microsoft Teams users via API","T1589.002 - T1590","TA0007 - TA0001","N/A","Black Basta","Discovery","https://github.com/sse-secure-systems/TeamsEnum","1","1","N/A","N/A","6","2","153","21","2024-03-27T18:14:25Z","2023-04-03T18:35:15Z","11842" +"*/TeamServer_win.exe*",".{0,1000}\/TeamServer_win\.exe.{0,1000}","offensive_tool_keyword","XiebroC2","Command and control server - multi-person collaborative penetration testing graphical framework","T1105 - T1573.001 - T1055.001 - T1071 - T1041 - T1059.001 - T1059.008 - T1102","TA0011 - TA0003 - TA0005 - TA0007 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/INotGreen/XiebroC2","1","1","N/A","N/A","10","10","1200","192","2025-02-28T09:44:43Z","2024-02-15T15:46:07Z","11845" +"*/teamserver-linux.tar.gz*",".{0,1000}\/teamserver\-linux\.tar\.gz.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","#linux","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","11846" +"*/teamserver-win.zip*",".{0,1000}\/teamserver\-win\.zip.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","11847" +"*/teamspeak2-version.nse*",".{0,1000}\/teamspeak2\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11848" +"*/teamstracker.db*",".{0,1000}\/teamstracker\.db.{0,1000}","offensive_tool_keyword","teamstracker","using graph proxy to monitor teams user presence","T1552.007 - T1052.001 - T1602","TA0003 - TA0005 - TA0007","N/A","N/A","Reconnaissance","https://github.com/nyxgeek/teamstracker","1","1","N/A","N/A","3","1","54","4","2024-06-27T11:57:35Z","2023-08-15T03:41:46Z","11849" +"*/teamstracker.git*",".{0,1000}\/teamstracker\.git.{0,1000}","offensive_tool_keyword","teamstracker","using graph proxy to monitor teams user presence","T1552.007 - T1052.001 - T1602","TA0003 - TA0005 - TA0007","N/A","N/A","Reconnaissance","https://github.com/nyxgeek/teamstracker","1","1","N/A","N/A","3","1","54","4","2024-06-27T11:57:35Z","2023-08-15T03:41:46Z","11850" +"*/teamstracker.py*",".{0,1000}\/teamstracker\.py.{0,1000}","offensive_tool_keyword","teamstracker","using graph proxy to monitor teams user presence","T1552.007 - T1052.001 - T1602","TA0003 - TA0005 - TA0007","N/A","N/A","Reconnaissance","https://github.com/nyxgeek/teamstracker","1","1","N/A","N/A","3","1","54","4","2024-06-27T11:57:35Z","2023-08-15T03:41:46Z","11851" +"*/TelegramRAT.git*",".{0,1000}\/TelegramRAT\.git.{0,1000}","offensive_tool_keyword","TelegramRAT","Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions","T1071.001 - T1105 - T1027","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/machine1337/TelegramRAT","1","1","N/A","N/A","10","10","372","62","2024-01-23T12:05:59Z","2023-06-30T10:59:55Z","11857" +"*/Telemetry.git*",".{0,1000}\/Telemetry\.git.{0,1000}","offensive_tool_keyword","Telemetry","Abusing Windows Telemetry for persistence through registry modifications and scheduled tasks to execute arbitrary commands with system-level privileges.","T1053 - T1547 - T1059","TA0003 - TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/Imanfeng/Telemetry","1","1","N/A","N/A","9","2","140","13","2020-07-02T09:41:27Z","2020-06-24T16:30:44Z","11858" +"*/telnet_cdata_ftth_backdoor_userpass.txt*",".{0,1000}\/telnet_cdata_ftth_backdoor_userpass\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","11859" +"*/telnet-brute.nse*",".{0,1000}\/telnet\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11860" +"*/telnet-encryption.nse*",".{0,1000}\/telnet\-encryption\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11861" +"*/telnet-ntlm-info.nse*",".{0,1000}\/telnet\-ntlm\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11862" +"*/terminate/Terminator.sys*",".{0,1000}\/terminate\/Terminator\.sys.{0,1000}","offensive_tool_keyword","SharpTerminator","Terminate AV/EDR Processes using kernel driver","T1055.003 - T1547.001 - T1053.005 - T1091 - T1014 - T1053.006 - T1053.004 - T1112 - T1112.001","TA0007 - TA0008 - TA0006 - TA0002","N/A","N/A","Exploitation tool","https://github.com/mertdas/SharpTerminator","1","1","N/A","N/A","10","4","341","66","2023-06-12T00:38:54Z","2023-06-11T06:35:51Z","11863" +"*/test_privesc.py*",".{0,1000}\/test_privesc\.py.{0,1000}","offensive_tool_keyword","GTFONow","Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.","T1548.003 - T1548.002 - T1548.001","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/Frissi0n/GTFONow","1","1","N/A","N/A","6","6","566","73","2024-11-10T08:38:30Z","2021-01-18T21:16:40Z","11864" +"*/test32.dll*",".{0,1000}\/test32\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Manual Map DLL injection implemented with Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tomcarver16/BOF-DLL-Inject","1","1","N/A","N/A","10","10","151","23","2020-09-03T23:24:31Z","2020-09-03T23:04:30Z","11866" +"*/test64.dll*",".{0,1000}\/test64\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Manual Map DLL injection implemented with Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tomcarver16/BOF-DLL-Inject","1","1","N/A","N/A","10","10","151","23","2020-09-03T23:24:31Z","2020-09-03T23:04:30Z","11867" +"*/tests/NIST_CAVS/*.rsp*",".{0,1000}\/tests\/NIST_CAVS\/.{0,1000}\.rsp.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","11869" +"*/tests/test-bof.ps1*",".{0,1000}\/tests\/test\-bof\.ps1.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool to run object files mainly beacon object files (BOF) in .Net.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nettitude/RunOF","1","1","N/A","N/A","10","10","145","21","2023-01-06T15:30:05Z","2022-02-21T13:53:39Z","11870" +"*/tevora-threat/PowerView*",".{0,1000}\/tevora\-threat\/PowerView.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","11871" +"*/tftp-enum.nse*",".{0,1000}\/tftp\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11873" +"*/TGSThief.git*",".{0,1000}\/TGSThief\.git.{0,1000}","offensive_tool_keyword","TGSThief","get the TGS of a user whose logon session is just present on the computer","T1558 - T1558.003 - T1078 - T1078.005","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/MzHmO/TGSThief","1","1","N/A","N/A","9","2","181","27","2023-07-25T05:30:39Z","2023-07-23T07:47:05Z","11874" +"*/TGSThief/*",".{0,1000}\/TGSThief\/.{0,1000}","offensive_tool_keyword","TGSThief","get the TGS of a user whose logon session is just present on the computer","T1558 - T1558.003 - T1078 - T1078.005","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/MzHmO/TGSThief","1","1","N/A","N/A","9","2","181","27","2023-07-25T05:30:39Z","2023-07-23T07:47:05Z","11875" +"*/TGT_Monitor.git*",".{0,1000}\/TGT_Monitor\.git.{0,1000}","offensive_tool_keyword","TGT_Monitor","This script continuously monitors cache for new TGTs and displays them on the screen (admin privs required)","T1557.001 - T1040","TA0006 - TA0008","N/A","N/A","Lateral Movement","https://github.com/Leo4j/TGT_Monitor","1","1","N/A","N/A","9","1","3","0","2023-11-08T18:48:55Z","2023-11-07T22:53:45Z","11876" +"*/TGT_Monitor.ps1*",".{0,1000}\/TGT_Monitor\.ps1.{0,1000}","offensive_tool_keyword","TGT_Monitor","This script continuously monitors cache for new TGTs and displays them on the screen (admin privs required)","T1557.001 - T1040","TA0006 - TA0008","N/A","N/A","Lateral Movement","https://github.com/Leo4j/TGT_Monitor","1","1","N/A","N/A","9","1","3","0","2023-11-08T18:48:55Z","2023-11-07T22:53:45Z","11877" +"*/tgtParse.py*",".{0,1000}\/tgtParse\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","11878" +"*/tgtParse/tgtParse.*",".{0,1000}\/tgtParse\/tgtParse\..{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","11879" +"*/thanatos.dll*",".{0,1000}\/thanatos\.dll.{0,1000}","offensive_tool_keyword","mythic","Thanatos is a Windows and Linux C2 agent written in rust.","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/thanatos","1","1","N/A","N/A","10","10","333","49","2024-12-19T19:07:03Z","2022-03-07T20:35:33Z","11880" +"*/thanatos.exe*",".{0,1000}\/thanatos\.exe.{0,1000}","offensive_tool_keyword","mythic","Thanatos is a Windows and Linux C2 agent written in rust.","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/thanatos","1","1","N/A","N/A","10","10","333","49","2024-12-19T19:07:03Z","2022-03-07T20:35:33Z","11881" +"*/thanatos.git*",".{0,1000}\/thanatos\.git.{0,1000}","offensive_tool_keyword","mythic","Thanatos is a Windows and Linux C2 agent written in rust.","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/thanatos","1","1","N/A","N/A","10","10","333","49","2024-12-19T19:07:03Z","2022-03-07T20:35:33Z","11882" +"*/thanatos/releases/*",".{0,1000}\/thanatos\/releases\/.{0,1000}","offensive_tool_keyword","mythic","Thanatos is a Windows and Linux C2 agent written in rust.","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/thanatos","1","1","N/A","N/A","10","10","333","49","2024-12-19T19:07:03Z","2022-03-07T20:35:33Z","11883" +"*/thanatos/releases/latest*",".{0,1000}\/thanatos\/releases\/latest.{0,1000}","offensive_tool_keyword","mythic","Thanatos is a Windows and Linux C2 agent written in rust.","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/thanatos","1","1","N/A","N/A","10","10","333","49","2024-12-19T19:07:03Z","2022-03-07T20:35:33Z","11884" +"*/thc-hydra/*",".{0,1000}\/thc\-hydra\/.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","11886" +"*/the-backdoor-factory.git*",".{0,1000}\/the\-backdoor\-factory\.git.{0,1000}","offensive_tool_keyword","the-backdoor-factory","Patch PE ELF Mach-O binaries with shellcode new version in development*","T1055.002 - T1055.004 - T1059.001","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/secretsquirrel/the-backdoor-factory","1","1","N/A","N/A","10","10","3369","788","2023-10-30T14:13:32Z","2013-05-30T01:04:24Z","11887" +"*/theHarvester.py*",".{0,1000}\/theHarvester\.py.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","11889" +"*/theHarvester.py*",".{0,1000}\/theHarvester\.py.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","11890" +"*/Theif.dll*",".{0,1000}\/Theif\.dll.{0,1000}","offensive_tool_keyword","Koppeling","Adaptive DLL hijacking / dynamic export forwarding","T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/monoxgas/Koppeling","1","1","N/A","N/A","8","8","748","128","2020-07-06T14:47:57Z","2020-02-18T21:08:16Z","11892" +"*/thief.py*",".{0,1000}\/thief\.py.{0,1000}","offensive_tool_keyword","SeeYouCM-Thief","Simple tool to automatically download and parse configuration files from Cisco phone systems searching for SSH credentials","T1110.001 - T1005 - T1071.001","TA0001 - TA0011 - TA0005","N/A","N/A","Discovery","https://github.com/trustedsec/SeeYouCM-Thief","1","1","N/A","N/A","9","2","189","35","2023-05-11T01:04:36Z","2022-01-14T20:12:25Z","11894" +"*/ThievingFox.git*",".{0,1000}\/ThievingFox\.git.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","1","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","11895" +"*/ThievingFox.py*",".{0,1000}\/ThievingFox\.py.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","1","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","11896" +"*/ThisIsNotRat.git*",".{0,1000}\/ThisIsNotRat\.git.{0,1000}","offensive_tool_keyword","ThisIsNotRat","control windows computeur from telegram","T1098 - T1079 - T1105 - T1047 - T1059","TA0010 - TA0009 - TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/RealBey/ThisIsNotRat","1","1","N/A","N/A","9","10","64","17","2023-09-10T07:39:38Z","2023-09-07T14:07:32Z","11898" +"*/thoth.git*",".{0,1000}\/thoth\.git.{0,1000}","offensive_tool_keyword","thoth","Automate recon for red team assessments.","T1190 - T1083 - T1018","TA0007 - TA0043 - TA0001","N/A","N/A","Reconnaissance","https://github.com/r1cksec/thoth","1","1","N/A","N/A","7","1","95","10","2025-02-03T12:05:52Z","2021-11-15T13:40:56Z","11899" +"*/ThreadlessInject.git*",".{0,1000}\/ThreadlessInject\.git.{0,1000}","offensive_tool_keyword","ThreadlessInject","Threadless Process Injection using remote function hooking.","T1055.012 - T1055.003 - T1177","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/CCob/ThreadlessInject","1","1","N/A","N/A","10","8","751","88","2024-09-04T17:11:58Z","2023-02-05T13:50:15Z","11901" +"*/Thread-Pool-Injection-PoC.git*",".{0,1000}\/Thread\-Pool\-Injection\-PoC\.git.{0,1000}","offensive_tool_keyword","Thread-Pool-Injection-PoC","Proof of concept code for thread pool based process injection in Windows.","T1055.011","TA0005","N/A","N/A","Defense Evasion","https://github.com/Uri3n/Thread-Pool-Injection-PoC","1","1","N/A","N/A","8","2","115","13","2025-03-29T23:14:47Z","2024-01-24T07:42:08Z","11902" +"*/ThreatCheck.git*",".{0,1000}\/ThreatCheck\.git.{0,1000}","offensive_tool_keyword","ThreatCheck","Identifies the bytes that Microsoft Defender / AMSI Consumer flags on","T1059.001 - T1059.005 - T1027.002 - T1070.004","TA0002 - TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/ThreatCheck","1","1","N/A","N/A","10","10","1185","143","2024-06-01T16:46:57Z","2020-10-08T11:22:26Z","11903" +"*/Throwback.git*",".{0,1000}\/Throwback\.git.{0,1000}","offensive_tool_keyword","Throwback","HTTP/S Beaconing Implant","T1071.001 - T1102 - T1095 - T1573.001 - T1041","TA0011 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/silentbreaksec/Throwback","1","1","N/A","N/A","10","10","306","83","2017-08-25T16:49:12Z","2014-08-08T17:06:24Z","11904" +"*/ThrowbackDLL/*",".{0,1000}\/ThrowbackDLL\/.{0,1000}","offensive_tool_keyword","Throwback","HTTP/S Beaconing Implant","T1071.001 - T1102 - T1095 - T1573.001 - T1041","TA0011 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/silentbreaksec/Throwback","1","1","N/A","N/A","10","10","306","83","2017-08-25T16:49:12Z","2014-08-08T17:06:24Z","11905" +"*/ThunderDNS*",".{0,1000}\/ThunderDNS.{0,1000}","offensive_tool_keyword","ThunderDNS","This tool can forward TCP traffic over DNS protocol","T1095 - T1071.004","TA0011 - TA0003","N/A","N/A","C2","https://github.com/fbkcs/ThunderDNS","1","1","N/A","N/A","10","10","410","63","2019-12-24T12:41:17Z","2018-12-04T15:18:47Z","11906" +"*/ThunderFox.exe*",".{0,1000}\/ThunderFox\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","11907" +"*/thycotic_secretserver_dump.rb*",".{0,1000}\/thycotic_secretserver_dump\.rb.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","1","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","11908" +"*/ticket_converter.py*",".{0,1000}\/ticket_converter\.py.{0,1000}","offensive_tool_keyword","ticket_converter","A little tool to convert ccache tickets into kirbi (KRB-CRED) and vice versa based on impacket.","T1558.003 - T1110.004","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/zer1t0/ticket_converter","1","1","N/A","N/A","10","2","167","31","2022-06-16T19:38:05Z","2019-05-14T04:48:19Z","11909" +"*/ticketConverter.exe*",".{0,1000}\/ticketConverter\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","11910" +"*/ticketConverter.py*",".{0,1000}\/ticketConverter\.py.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","11911" +"*/ticketConverter.py*",".{0,1000}\/ticketConverter\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","11912" +"*/ticketer.exe*",".{0,1000}\/ticketer\.exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","11913" +"*/ticketer.py*",".{0,1000}\/ticketer\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","11916" +"*/ticketer.py*",".{0,1000}\/ticketer\.py.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","11917" +"*/ticketsplease.py*",".{0,1000}\/ticketsplease\.py.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","11918" +"*/TikiLoader/*",".{0,1000}\/TikiLoader\/.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","11920" +"*/TikiSpawn.*",".{0,1000}\/TikiSpawn\..{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","11921" +"*/TikiSpawn/*",".{0,1000}\/TikiSpawn\/.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","11922" +"*/TimeException.exe*",".{0,1000}\/TimeException\.exe.{0,1000}","offensive_tool_keyword","TimeException","A tool to find folders excluded from AV real-time scanning using a time oracle","T1518.001 - T1070.004 - T1083","TA0005 - TA0007","N/A","N/A","Defense Evasion","https://github.com/bananabr/TimeException","1","1","N/A","N/A","8","3","233","16","2024-02-13T16:22:09Z","2022-07-19T02:47:52Z","11923" +"*/TimeException.git*",".{0,1000}\/TimeException\.git.{0,1000}","offensive_tool_keyword","TimeException","A tool to find folders excluded from AV real-time scanning using a time oracle","T1518.001 - T1070.004 - T1083","TA0005 - TA0007","N/A","N/A","Defense Evasion","https://github.com/bananabr/TimeException","1","1","N/A","N/A","8","3","233","16","2024-02-13T16:22:09Z","2022-07-19T02:47:52Z","11924" +"*/timeoutpwn64*",".{0,1000}\/timeoutpwn64.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","11925" +"*/timestomp.py*",".{0,1000}\/timestomp\.py.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","11926" +"*/timestomping.ps1*",".{0,1000}\/timestomping\.ps1.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","11927" +"*/timwr/CVE-2016-5195*",".{0,1000}\/timwr\/CVE\-2016\-5195.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirtycow vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/timwr/CVE-2016-5195","1","1","N/A","N/A","N/A","10","972","393","2021-02-03T16:03:40Z","2016-10-21T11:19:21Z","11928" +"*/tinymet.exe*",".{0,1000}\/tinymet\.exe.{0,1000}","offensive_tool_keyword","TinyMet","meterpreter stager","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","CL0P - FIN7 - FIN11 - Silence group - GOLD EVERGREEN","C2","https://github.com/SherifEldeeb/TinyMet","1","1","N/A","N/A","10","10","128","43","2019-08-20T04:39:22Z","2014-05-17T13:31:55Z","11930" +"*/tls-alpn.nse*",".{0,1000}\/tls\-alpn\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11932" +"*/tls-nextprotoneg.nse*",".{0,1000}\/tls\-nextprotoneg\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11933" +"*/tls-ticketbleed.nse*",".{0,1000}\/tls\-ticketbleed\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11934" +"*/tmp/metadata/na.elf*",".{0,1000}\/tmp\/metadata\/na\.elf.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","11980" +"*/tmp/p0f.log*",".{0,1000}\/tmp\/p0f\.log.{0,1000}","offensive_tool_keyword","p0f","P0f is a tool that utilizes an array of sophisticated purely passive traffic fingerprinting mechanisms to identify the players behind any incidental TCP/IP communications","T1046 - T1040","TA0007 - TA0010","N/A","N/A","Sniffing & Spoofing","https://www.kali.org/tools/p0f/","1","1","#logfile #linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11982" +"*/tn3270-screen.nse*",".{0,1000}\/tn3270\-screen\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12008" +"*/Token%20grabber.dll*",".{0,1000}\/Token\%20grabber\.dll.{0,1000}","offensive_tool_keyword","Discord-RAT-2.0","Discord Remote Administration Tool fully written in c#, stub size of ~75kb with over 40 post exploitations modules","T1059.005 - T1105 - T1569.002 - T1027.001","TA0011 - TA0003 - TA0006 - TA0009 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/moom825/Discord-RAT-2.0","1","1","N/A","N/A","10","10","512","115","2023-11-03T01:15:38Z","2022-07-15T20:09:56Z","12009" +"*/TokenAssignor.exe*",".{0,1000}\/TokenAssignor\.exe.{0,1000}","offensive_tool_keyword","PrivFu","Tool to execute token assigned process","T1055","TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","TokenAssignor","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","12010" +"*/TokenDump.exe*",".{0,1000}\/TokenDump\.exe.{0,1000}","offensive_tool_keyword","PrivFu","inspect token information","T1057","TA0007","N/A","N/A","Discovery","https://github.com/daem0nc0re/PrivFu","1","1","N/A","TokenDump","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","12011" +"*/TokenFinder.git*",".{0,1000}\/TokenFinder\.git.{0,1000}","offensive_tool_keyword","TokenFinder","Tool to extract powerful tokens from Office desktop apps memory","T1003 - T1081 - T1110","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/doredry/TokenFinder","1","1","N/A","N/A","9","1","71","10","2024-03-01T14:27:34Z","2022-09-21T14:21:07Z","12012" +"*/TokenFinder.py*",".{0,1000}\/TokenFinder\.py.{0,1000}","offensive_tool_keyword","TokenFinder","Tool to extract powerful tokens from Office desktop apps memory","T1003 - T1081 - T1110","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/doredry/TokenFinder","1","1","N/A","N/A","9","1","71","10","2024-03-01T14:27:34Z","2022-09-21T14:21:07Z","12013" +"*/Token-Impersonation.git*",".{0,1000}\/Token\-Impersonation\.git.{0,1000}","offensive_tool_keyword","Token-Impersonation","Make a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required)","T1134.001 - T1134.002","TA0004 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/Leo4j/Token-Impersonation","1","1","N/A","N/A","8","1","7","3","2024-03-20T17:07:13Z","2023-11-02T10:46:24Z","12014" +"*/Token-Impersonation.ps1*",".{0,1000}\/Token\-Impersonation\.ps1.{0,1000}","offensive_tool_keyword","Token-Impersonation","Make a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required)","T1134.001 - T1134.002","TA0004 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/Leo4j/Token-Impersonation","1","1","N/A","N/A","8","1","7","3","2024-03-20T17:07:13Z","2023-11-02T10:46:24Z","12015" +"*/TokenPlayer.git*",".{0,1000}\/TokenPlayer\.git.{0,1000}","offensive_tool_keyword","TokenPlayer","Manipulating and Abusing Windows Access Tokens","T1134 - T1484 - T1055 - T1078","TA0004 - TA0005 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S1ckB0y1337/TokenPlayer","1","1","N/A","N/A","10","3","274","45","2021-01-15T16:07:47Z","2020-08-20T23:05:49Z","12016" +"*/TokenStealer.git*",".{0,1000}\/TokenStealer\.git.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","1","N/A","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","12017" +"*/TokenStealing*",".{0,1000}\/TokenStealing.{0,1000}","offensive_tool_keyword","PrivFu","Kernel mode WinDbg extension and PoCs for token privilege investigation.","T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001","TA0007 - TA0008 - TA0002 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","12018" +"*/TokenStealing.exe*",".{0,1000}\/TokenStealing\.exe.{0,1000}","offensive_tool_keyword","PrivFu","ArtsOfGetSystem privesc tools","T1134 - T1134.001 - T1078 - T1059 - T1075","TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu/","1","1","N/A","ArtsOfGetSystem","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","12019" +"*/TokenStomp.exe*",".{0,1000}\/TokenStomp\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","12020" +"*/TokenStomp.exe*",".{0,1000}\/TokenStomp\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","12021" +"*/TokenStripBOF*",".{0,1000}\/TokenStripBOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File to delete token privileges and lower the integrity level to untrusted for a specified process","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nick-frischkorn/TokenStripBOF","1","1","N/A","N/A","10","10","44","7","2022-06-15T21:29:24Z","2022-06-15T02:13:13Z","12022" +"*/TokenTactics.git*",".{0,1000}\/TokenTactics\.git.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","12023" +"*/TokenTacticsV2.git*",".{0,1000}\/TokenTacticsV2\.git.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","1","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","12024" +"*/TokenUniverse.git*",".{0,1000}\/TokenUniverse\.git.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","1","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","12025" +"*/TokenUniverse.zip*",".{0,1000}\/TokenUniverse\.zip.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","1","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","12026" +"*/Tokenvator/*",".{0,1000}\/Tokenvator\/.{0,1000}","offensive_tool_keyword","Tokenvator","A tool to elevate privilege with Windows Tokens","T1134 - T1078","TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/0xbadjuju/Tokenvator","1","1","N/A","N/A","N/A","10","1038","201","2023-10-06T13:17:05Z","2017-12-08T01:29:11Z","12027" +"*/tomcat-RH-root.sh*",".{0,1000}\/tomcat\-RH\-root\.sh.{0,1000}","offensive_tool_keyword","CDK","CDK is an open-sourced container penetration toolkit","T1610 - T1611 - T1203 - T1059.004 - T1564.004","TA0001 - TA0002 - TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/cdk-team/CDK","1","1","#linux","N/A","9","10","4164","566","2025-03-08T14:00:06Z","2020-11-05T09:18:51Z","12028" +"*/tomcat-RH-root.sh*",".{0,1000}\/tomcat\-RH\-root\.sh.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","12029" +"*/tools/BeaconTool/*",".{0,1000}\/tools\/BeaconTool\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Practice Go programming and implement CobaltStrike's Beacon in Go","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/darkr4y/geacon","1","1","N/A","N/A","10","10","1189","206","2020-10-02T10:34:37Z","2020-02-14T14:01:29Z","12030" +"*/tools/DHCP.py*",".{0,1000}\/tools\/DHCP\.py.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","#linux","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","12031" +"*/tools/psexec.rb*",".{0,1000}\/tools\/psexec\.rb.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-PsExec.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","12034" +"*/Tools/ResHacker.exe*",".{0,1000}\/Tools\/ResHacker\.exe.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","false positive risk","6","","N/A","","","","12035" +"*/Tools/spoolsystem/*",".{0,1000}\/Tools\/spoolsystem\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Spectrum Attack Simulation beacons","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas/","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","12036" +"*/Tools/Squeak/Squeak*",".{0,1000}\/Tools\/Squeak\/Squeak.{0,1000}","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","12037" +"*/toolsdownload/iepv.zip*",".{0,1000}\/toolsdownload\/iepv\.zip.{0,1000}","offensive_tool_keyword","IEPassView","IE PassView scans all Internet Explorer passwords in your system and display them on the main window.","T1555 - T1212","TA0006","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/internet_explorer_password.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12038" +"*/toolsdownload/rdpv.zip*",".{0,1000}\/toolsdownload\/rdpv\.zip.{0,1000}","offensive_tool_keyword","rdpv","RemoteDesktopPassView is a small utility that reveals the password stored by Microsoft Remote Desktop Connection utility inside the .rdp files.","T1110 - T1560.001 - T1555.003 - T1212","TA0006 - TA0007","N/A","Phobos - GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/remote_desktop_password.html","1","1","N/A","N/A","8","10","N/A","N/A","N/A","N/A","12039" +"*/Tool-X.git*",".{0,1000}\/Tool\-X\.git.{0,1000}","offensive_tool_keyword","Tool-X","Tool-X is a Kali Linux hacking tools installer for Termux and linux system. Tool-X was developed for Termux and linux based systems. Using Tool-X you can install almost 370+ hacking tools in Termux (android) and other Linux based distributions. Now Tool-X is available for Ubuntu Debian etc.","T1212 - T1566 - T1550 - T1133","TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/rajkumardusad/Tool-X","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12040" +"*/top_mots_combo.7z*",".{0,1000}\/top_mots_combo\.7z.{0,1000}","offensive_tool_keyword","wordlists","Various wordlists FR & EN - Cracking French passwords","T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/clem9669/wordlists","1","1","N/A","N/A","N/A","3","280","45","2025-04-22T14:34:10Z","2020-10-21T14:37:53Z","12041" +"*/tor-0.*.tar.gz*",".{0,1000}\/tor\-0\..{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12045" +"*/Tor2web-*.tar.gz*",".{0,1000}\/Tor2web\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","12046" +"*/Tor2web-*.zip*",".{0,1000}\/Tor2web\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","12047" +"*/Tor2web.git*",".{0,1000}\/Tor2web\.git.{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","12049" +"*/tor2web.js*",".{0,1000}\/tor2web\.js.{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","12050" +"*/ToRat.git*",".{0,1000}\/ToRat\.git.{0,1000}","offensive_tool_keyword","ToRat","ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication","T1219 - T1021 - T1105","TA0008 - TA0011 - TA0005","N/A","N/A","C2","https://github.com/lu4p/ToRat","1","1","N/A","N/A","10","10","995","199","2023-03-13T08:56:55Z","2019-01-19T11:44:01Z","12052" +"*/tor-browser-linux*.*",".{0,1000}\/tor\-browser\-linux.{0,1000}\..{0,1000}","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","#linux","N/A","9","10","N/A","N/A","N/A","N/A","12054" +"*/tor-browser-osx64*.*",".{0,1000}\/tor\-browser\-osx64.{0,1000}\..{0,1000}","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","12055" +"*/tor-browser-win32*.*",".{0,1000}\/tor\-browser\-win32.{0,1000}\..{0,1000}","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","12056" +"*/tor-browser-win64*.*",".{0,1000}\/tor\-browser\-win64.{0,1000}\..{0,1000}","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","12057" +"*/tor-consensus-checker.nse*",".{0,1000}\/tor\-consensus\-checker\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12058" +"*/tor-gencert.exe*",".{0,1000}\/tor\-gencert\.exe.{0,1000}","offensive_tool_keyword","tor","Tor is a python based module for using tor proxy/network services on windows - osx - linux with just one click.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0005 - TA0010 - TA0011","N/A","Dispossessor - APT28 - APT29 - Leviathan","Defense Evasion","https://github.com/r0oth3x49/Tor","1","1","#linux","N/A","N/A","2","156","42","2018-04-21T10:55:00Z","2016-09-22T11:22:33Z","12059" +"*/tor-package-archive/*",".{0,1000}\/tor\-package\-archive\/.{0,1000}","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","12061" +"*/tor-static-windows-amd64.zip*",".{0,1000}\/tor\-static\-windows\-amd64\.zip.{0,1000}","offensive_tool_keyword","ToRat","ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication","T1219 - T1021 - T1105","TA0008 - TA0011 - TA0005","N/A","N/A","C2","https://github.com/lu4p/ToRat","1","1","N/A","N/A","10","10","995","199","2023-03-13T08:56:55Z","2019-01-19T11:44:01Z","12064" +"*/TotalRecall.git*",".{0,1000}\/TotalRecall\.git.{0,1000}","offensive_tool_keyword","TotalRecall","extracts and displays data from the Recall feature in Windows 11","T1005 - T1113 - T1056.001 - T1003","TA0009 - TA0010 - TA0006 - TA0007","N/A","N/A","Sniffing & Spoofing","https://github.com/xaitax/TotalRecall","1","1","N/A","N/A","10","10","2011","159","2024-06-08T09:25:08Z","2024-06-03T16:38:04Z","12065" +"*/totalrecall.py*",".{0,1000}\/totalrecall\.py.{0,1000}","offensive_tool_keyword","TotalRecall","extracts and displays data from the Recall feature in Windows 11","T1005 - T1113 - T1056.001 - T1003","TA0009 - TA0010 - TA0006 - TA0007","N/A","N/A","Sniffing & Spoofing","https://github.com/xaitax/TotalRecall","1","1","N/A","N/A","10","10","2011","159","2024-06-08T09:25:08Z","2024-06-03T16:38:04Z","12066" +"*/toteslegit.ps1*",".{0,1000}\/toteslegit\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","12068" +"*/traceroute-geolocation.nse*",".{0,1000}\/traceroute\-geolocation\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12069" +"*/Trackflaw/CVE*.py*",".{0,1000}\/Trackflaw\/CVE.{0,1000}\.py.{0,1000}","offensive_tool_keyword","poc","Simple and dirty PoC of the CVE-2023-23397 vulnerability impacting the Outlook thick client.","T1068 - T1557.001 - T1187 - T1212 -T1003.001 - T1550","TA0003 - TA0002 - TA0004","N/A","APT28 - STRONTIUM - Sednit - Sofacy - Fancy Bear","Exploitation tool","https://github.com/Trackflaw/CVE-2023-23397","1","1","N/A","N/A","N/A","2","123","26","2023-03-24T10:46:38Z","2023-03-20T16:31:54Z","12072" +"*/transports/scramblesuit/*.py*",".{0,1000}\/transports\/scramblesuit\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","12078" +"*/trap_command.py*",".{0,1000}\/trap_command\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","12079" +"*/TreeWalker.cs*",".{0,1000}\/TreeWalker\.cs.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","12080" +"*/TREVORspray.git*",".{0,1000}\/TREVORspray\.git.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","12081" +"*/trevorspray.log*",".{0,1000}\/trevorspray\.log.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","#logfile","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","12082" +"*/trganda/CVE-2022-23131*",".{0,1000}\/trganda\/CVE\-2022\-23131.{0,1000}","offensive_tool_keyword","POC","POC exploitaiton of zabbix saml bypass exp vulnerability cve-2022-23131 (Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML)","T1548 - T1190","TA0006 - TA0008","N/A","N/A","Exploitation tool","https://github.com/trganda/CVE-2022-23131","1","1","N/A","N/A","N/A","1","1","1","2022-02-24T11:50:28Z","2022-02-24T08:10:46Z","12083" +"*/trick_ryuk.profile*",".{0,1000}\/trick_ryuk\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","12084" +"*/trickbot.profile*",".{0,1000}\/trickbot\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","12085" +"*/TrickDump.git*",".{0,1000}\/TrickDump\.git.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","1","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","12086" +"*/tricky.lnk.git*",".{0,1000}\/tricky\.lnk\.git.{0,1000}","offensive_tool_keyword","tricky.lnk","VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute","T1027 - T1036 - T1218.010","TA0002 - TA0003 - TA0008","N/A","N/A","Phishing","https://github.com/xillwillx/tricky.lnk","1","1","N/A","N/A","N/A","2","114","33","2020-12-19T23:42:10Z","2016-10-26T21:25:06Z","12087" +"*/tricky.ps1*",".{0,1000}\/tricky\.ps1.{0,1000}","offensive_tool_keyword","tricky.lnk","VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute","T1027 - T1036 - T1218.010","TA0002 - TA0003 - TA0008","N/A","N/A","Phishing","https://github.com/xillwillx/tricky.lnk","1","1","N/A","N/A","N/A","2","114","33","2020-12-19T23:42:10Z","2016-10-26T21:25:06Z","12088" +"*/tricky.vbs*",".{0,1000}\/tricky\.vbs.{0,1000}","offensive_tool_keyword","tricky.lnk","VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute","T1027 - T1036 - T1218.010","TA0002 - TA0003 - TA0008","N/A","N/A","Phishing","https://github.com/xillwillx/tricky.lnk","1","1","N/A","N/A","N/A","2","114","33","2020-12-19T23:42:10Z","2016-10-26T21:25:06Z","12089" +"*/tricky2.ps1*",".{0,1000}\/tricky2\.ps1.{0,1000}","offensive_tool_keyword","tricky.lnk","VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute","T1027 - T1036 - T1218.010","TA0002 - TA0003 - TA0008","N/A","N/A","Phishing","https://github.com/xillwillx/tricky.lnk","1","1","N/A","N/A","N/A","2","114","33","2020-12-19T23:42:10Z","2016-10-26T21:25:06Z","12090" +"*/TripleCross.git*",".{0,1000}\/TripleCross\.git.{0,1000}","offensive_tool_keyword","TripleCross","A Linux eBPF rootkit with a backdoor - C2 - library injection - execution hijacking - persistence and stealth capabilities.","T1055 - T1021.005 - T1055.011 - T1055.003 - T1547 - T1574 - T1027 - T1070.004 - T1562.001","TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/h3xduck/TripleCross","1","1","#linux","N/A","10","10","1838","232","2024-04-07T02:06:19Z","2021-10-27T17:47:58Z","12093" +"*/TripleCross-0.1.0.zip*",".{0,1000}\/TripleCross\-0\.1\.0\.zip.{0,1000}","offensive_tool_keyword","TripleCross","A Linux eBPF rootkit with a backdoor - C2 - library injection - execution hijacking - persistence and stealth capabilities.","T1055 - T1021.005 - T1055.011 - T1055.003 - T1547 - T1574 - T1027 - T1070.004 - T1562.001","TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/h3xduck/TripleCross","1","1","#linux","N/A","10","10","1838","232","2024-04-07T02:06:19Z","2021-10-27T17:47:58Z","12095" +"*/trojan.exe*",".{0,1000}\/trojan\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","12097" +"*/trollsploit/*",".{0,1000}\/trollsploit\/.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1154","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","12098" +"*/TROUBLE-1/Vajra*",".{0,1000}\/TROUBLE\-1\/Vajra.{0,1000}","offensive_tool_keyword","Vajra","Vajra is a UI based tool with multiple techniques for attacking and enumerating in target's Azure environment","T1087 - T1098 - T1583 - T1078 - T1110 - T1566 - T1537 - T1020 - T1526 - T1482","TA0003 - TA0006 - TA0007 - TA0008 - TA0009","N/A","N/A","Exploitation tool","https://github.com/TROUBLE-1/Vajra","1","1","N/A","N/A","N/A","4","391","61","2025-02-21T16:40:23Z","2022-03-01T14:31:27Z","12099" +"*/truesocks_rs.git*",".{0,1000}\/truesocks_rs\.git.{0,1000}","offensive_tool_keyword","TrueSocks","Simple API for buying renting and managing proxies","T1021 - T1071 - T1090","TA0003 - TA0008 - TA0011","N/A","Scattered Spider*","Defense Evasion","https://github.com/c0dn/truesocks_rs","1","1","N/A","N/A","10","1","0","0","2023-05-09T01:00:05Z","2023-04-06T02:32:04Z","12100" +"*/trufflehog.git*",".{0,1000}\/trufflehog\.git.{0,1000}","offensive_tool_keyword","truffleHog","Searches through git repositories for secrets. digging deep into commit history and branches. This is effective at finding secrets accidentally committed.","T1552 - T1596 - T1083","TA0009 - TA0005 - TA0002","N/A","Scattered Spider*","Reconnaissance","https://github.com/dxa4481/truffleHog","1","1","#linux","N/A","6","10","18812","1839","2025-04-22T17:32:40Z","2016-12-31T05:08:12Z","12101" +"*/trufflehog/releases/download/*",".{0,1000}\/trufflehog\/releases\/download\/.{0,1000}","offensive_tool_keyword","truffleHog","Searches through git repositories for secrets. digging deep into commit history and branches. This is effective at finding secrets accidentally committed.","T1552 - T1596 - T1083","TA0009 - TA0005 - TA0002","N/A","Scattered Spider*","Reconnaissance","https://github.com/dxa4481/truffleHog","1","1","#linux","N/A","6","10","18812","1839","2025-04-22T17:32:40Z","2016-12-31T05:08:12Z","12102" +"*/TruffleSnout.exe*",".{0,1000}\/TruffleSnout\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","12104" +"*/TruffleSnout.exe*",".{0,1000}\/TruffleSnout\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","12105" +"*/trusted_sec_bofs/*",".{0,1000}\/trusted_sec_bofs\/.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","12106" +"*/trusted_sec_remote_bofs/*",".{0,1000}\/trusted_sec_remote_bofs\/.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","12107" +"*/TrustedWave_x64.exe*",".{0,1000}\/TrustedWave_x64\.exe.{0,1000}","offensive_tool_keyword","Tsunami","another C2 framework","T1573 - T1027 - T1059 - T1071 ","TA0011 - TA0009 - TA0003 - TA0007 - TA0008","N/A","N/A","C2","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","12108" +"*/tsh_linux_amd64*",".{0,1000}\/tsh_linux_amd64.{0,1000}","offensive_tool_keyword","tsh-go","Tiny SHell Go - An open-source backdoor written in Go","T1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009","TA0003 - TA0005 - TA0011 - TA0010","N/A","N/A","Persistence","https://github.com/CykuTW/tsh-go","1","1","#linux","N/A","10","2","161","16","2024-08-29T02:59:37Z","2022-06-13T16:25:30Z","12109" +"*/tsh_windows_amd64.exe*",".{0,1000}\/tsh_windows_amd64\.exe.{0,1000}","offensive_tool_keyword","tsh-go","Tiny SHell Go - An open-source backdoor written in Go","T1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009","TA0003 - TA0005 - TA0011 - TA0010","N/A","N/A","Persistence","https://github.com/CykuTW/tsh-go","1","1","N/A","N/A","10","2","161","16","2024-08-29T02:59:37Z","2022-06-13T16:25:30Z","12110" +"*/tshd_linux_amd64*",".{0,1000}\/tshd_linux_amd64.{0,1000}","offensive_tool_keyword","tsh-go","Tiny SHell Go - An open-source backdoor written in Go","T1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009","TA0003 - TA0005 - TA0011 - TA0010","N/A","N/A","Persistence","https://github.com/CykuTW/tsh-go","1","1","#linux","N/A","10","2","161","16","2024-08-29T02:59:37Z","2022-06-13T16:25:30Z","12112" +"*/tshd_windows.go*",".{0,1000}\/tshd_windows\.go.{0,1000}","offensive_tool_keyword","tsh-go","Tiny SHell Go - An open-source backdoor written in Go","T1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009","TA0003 - TA0005 - TA0011 - TA0010","N/A","N/A","Persistence","https://github.com/CykuTW/tsh-go","1","1","N/A","N/A","10","2","161","16","2024-08-29T02:59:37Z","2022-06-13T16:25:30Z","12113" +"*/tshd_windows_amd64.exe*",".{0,1000}\/tshd_windows_amd64\.exe.{0,1000}","offensive_tool_keyword","tsh-go","Tiny SHell Go - An open-source backdoor written in Go","T1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009","TA0003 - TA0005 - TA0011 - TA0010","N/A","N/A","Persistence","https://github.com/CykuTW/tsh-go","1","1","N/A","N/A","10","2","161","16","2024-08-29T02:59:37Z","2022-06-13T16:25:30Z","12114" +"*/tsh-go.git*",".{0,1000}\/tsh\-go\.git.{0,1000}","offensive_tool_keyword","tsh-go","Tiny SHell Go - An open-source backdoor written in Go","T1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009","TA0003 - TA0005 - TA0011 - TA0010","N/A","N/A","Persistence","https://github.com/CykuTW/tsh-go","1","1","N/A","N/A","10","2","161","16","2024-08-29T02:59:37Z","2022-06-13T16:25:30Z","12115" +"*/tso-brute.nse*",".{0,1000}\/tso\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12116" +"*/tso-enum.nse*",".{0,1000}\/tso\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12117" +"*/tsunami.py*",".{0,1000}\/tsunami\.py.{0,1000}","offensive_tool_keyword","Tsunami","another C2 framework","T1573 - T1027 - T1059 - T1071 ","TA0011 - TA0009 - TA0003 - TA0007 - TA0008","N/A","N/A","C2","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","12118" +"*/tsunami_warning.py*",".{0,1000}\/tsunami_warning\.py.{0,1000}","offensive_tool_keyword","Tsunami","another C2 framework","T1573 - T1027 - T1059 - T1071 ","TA0011 - TA0009 - TA0003 - TA0007 - TA0008","N/A","N/A","C2","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","12119" +"*/TsunamiServer/*",".{0,1000}\/TsunamiServer\/.{0,1000}","offensive_tool_keyword","Tsunami","another C2 framework","T1573 - T1027 - T1059 - T1071 ","TA0011 - TA0009 - TA0003 - TA0007 - TA0008","N/A","N/A","C2","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","12120" +"*/TsunamiWave_x64.exe*",".{0,1000}\/TsunamiWave_x64\.exe.{0,1000}","offensive_tool_keyword","Tsunami","another C2 framework","T1573 - T1027 - T1059 - T1071 ","TA0011 - TA0009 - TA0003 - TA0007 - TA0008","N/A","N/A","C2","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","12121" +"*/tun2socks.git*",".{0,1000}\/tun2socks\.git.{0,1000}","offensive_tool_keyword","tun2socks","socks tunneling","T1572 - T1090 - T1071 - T1573 - T1205","TA0010 - TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/xjasonlyu/tun2socks","1","1","N/A","N/A","10","10","3785","513","2025-04-15T21:19:25Z","2019-07-16T03:25:40Z","12122" +"*/tun2socks/*",".{0,1000}\/tun2socks\/.{0,1000}","offensive_tool_keyword","tun2socks","socks tunneling","T1572 - T1090 - T1071 - T1573 - T1205","TA0010 - TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/xjasonlyu/tun2socks","1","1","N/A","N/A","10","10","3785","513","2025-04-15T21:19:25Z","2019-07-16T03:25:40Z","12123" +"*/tun2socks-darwin*",".{0,1000}\/tun2socks\-darwin.{0,1000}","offensive_tool_keyword","tun2socks","socks tunneling","T1572 - T1090 - T1071 - T1573 - T1205","TA0010 - TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/xjasonlyu/tun2socks","1","1","#linux","N/A","10","10","3785","513","2025-04-15T21:19:25Z","2019-07-16T03:25:40Z","12124" +"*/tun2socks-freebsd*",".{0,1000}\/tun2socks\-freebsd.{0,1000}","offensive_tool_keyword","tun2socks","socks tunneling","T1572 - T1090 - T1071 - T1573 - T1205","TA0010 - TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/xjasonlyu/tun2socks","1","1","N/A","N/A","10","10","3785","513","2025-04-15T21:19:25Z","2019-07-16T03:25:40Z","12125" +"*/tun2socks-linux*",".{0,1000}\/tun2socks\-linux.{0,1000}","offensive_tool_keyword","tun2socks","socks tunneling","T1572 - T1090 - T1071 - T1573 - T1205","TA0010 - TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/xjasonlyu/tun2socks","1","1","#linux","N/A","10","10","3785","513","2025-04-15T21:19:25Z","2019-07-16T03:25:40Z","12126" +"*/tun2socks-openbsd*",".{0,1000}\/tun2socks\-openbsd.{0,1000}","offensive_tool_keyword","tun2socks","socks tunneling","T1572 - T1090 - T1071 - T1573 - T1205","TA0010 - TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/xjasonlyu/tun2socks","1","1","N/A","N/A","10","10","3785","513","2025-04-15T21:19:25Z","2019-07-16T03:25:40Z","12127" +"*/tun2socks-windows*",".{0,1000}\/tun2socks\-windows.{0,1000}","offensive_tool_keyword","tun2socks","socks tunneling","T1572 - T1090 - T1071 - T1573 - T1205","TA0010 - TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/xjasonlyu/tun2socks","1","1","N/A","N/A","10","10","3785","513","2025-04-15T21:19:25Z","2019-07-16T03:25:40Z","12128" +"*/tunnel.nosocket.php*",".{0,1000}\/tunnel\.nosocket\.php.{0,1000}","offensive_tool_keyword","reGeorg","The successor to reDuh - pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.","T1090 - T1095 - T1572","TA0003 - TA0011","N/A","FIN13 - IRIDIUM - UNC3524 - Worok - COZY BEAR - FANCY BEAR - EMBER BEAR - Sandworm","Data Exfiltration","https://github.com/sensepost/reGeorg","1","1","N/A","N/A","N/A","10","3075","826","2025-03-06T09:56:16Z","2014-08-08T00:58:12Z","12130" +"*/tunnel.tomcat.5.jsp*",".{0,1000}\/tunnel\.tomcat\.5\.jsp.{0,1000}","offensive_tool_keyword","reGeorg","The successor to reDuh - pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.","T1090 - T1095 - T1572","TA0003 - TA0011","N/A","FIN13 - IRIDIUM - UNC3524 - Worok - COZY BEAR - FANCY BEAR - EMBER BEAR - Sandworm","Data Exfiltration","https://github.com/sensepost/reGeorg","1","1","N/A","N/A","N/A","10","3075","826","2025-03-06T09:56:16Z","2014-08-08T00:58:12Z","12131" +"*/TunnelVision.git*",".{0,1000}\/TunnelVision\.git.{0,1000}","offensive_tool_keyword","TunnelVision","TunnelVision uses DHCP option 121 to manipulate routing tables and decloak VPN traffic","T1557 - T1498.003","TA0009 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/leviathansecurity/TunnelVision","1","1","N/A","N/A","9","2","132","17","2024-05-08T19:40:13Z","2024-03-11T22:24:56Z","12173" +"*/TunnelVisionVM.ova*",".{0,1000}\/TunnelVisionVM\.ova.{0,1000}","offensive_tool_keyword","TunnelVision","TunnelVision uses DHCP option 121 to manipulate routing tables and decloak VPN traffic","T1557 - T1498.003","TA0009 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/leviathansecurity/TunnelVision","1","1","N/A","N/A","9","2","132","17","2024-05-08T19:40:13Z","2024-03-11T22:24:56Z","12174" +"*/tweetshell.sh*",".{0,1000}\/tweetshell\.sh.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/SocialBox-Termux","1","1","N/A","N/A","7","10","3581","391","2024-09-02T19:15:22Z","2019-03-28T18:07:05Z","12180" +"*/twittor.git*",".{0,1000}\/twittor\.git.{0,1000}","offensive_tool_keyword","twittor","A fully featured backdoor that uses Twitter as a C&C server ","T1105 - T1102 - T1041","TA0003 - TA0002 - TA0007","N/A","N/A","C2","https://github.com/PaulSec/twittor","1","1","N/A","N/A","10","10","771","217","2020-09-30T13:47:31Z","2015-09-09T07:23:25Z","12181" +"*/uac.py*",".{0,1000}\/uac\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","12182" +"*/uac_bypass.py*",".{0,1000}\/uac_bypass\.py.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","12183" +"*/uac_cmstp.py*",".{0,1000}\/uac_cmstp\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12184" +"*/uac_compmgmtlauncher.py*",".{0,1000}\/uac_compmgmtlauncher\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12185" +"*/uac_computerdefaults.py*",".{0,1000}\/uac_computerdefaults\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12186" +"*/uac_dll_cliconfg.py*",".{0,1000}\/uac_dll_cliconfg\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12187" +"*/uac_dll_mcx2prov.py*",".{0,1000}\/uac_dll_mcx2prov\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12188" +"*/uac_dll_migwiz.py*",".{0,1000}\/uac_dll_migwiz\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12189" +"*/uac_dll_sysprep.py*",".{0,1000}\/uac_dll_sysprep\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12190" +"*/uac_dotnet.py*",".{0,1000}\/uac_dotnet\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12191" +"*/uac_eventviewer.py*",".{0,1000}\/uac_eventviewer\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12192" +"*/uac_fodhelper.py*",".{0,1000}\/uac_fodhelper\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12193" +"*/uac_mockdir.py*",".{0,1000}\/uac_mockdir\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12194" +"*/uac_perfmon.py*",".{0,1000}\/uac_perfmon\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12195" +"*/uac_runas.py*",".{0,1000}\/uac_runas\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12196" +"*/uac_sdclt.py*",".{0,1000}\/uac_sdclt\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12197" +"*/uac_sdcltcontrol.py*",".{0,1000}\/uac_sdcltcontrol\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12198" +"*/uac_sdcltisolatedcommand.py*",".{0,1000}\/uac_sdcltisolatedcommand\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12199" +"*/uac_silentcleanup.py*",".{0,1000}\/uac_silentcleanup\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12200" +"*/uac_slui.py*",".{0,1000}\/uac_slui\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12201" +"*/uac_token_manipulation.py*",".{0,1000}\/uac_token_manipulation\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12202" +"*/uac_wsreset.py*",".{0,1000}\/uac_wsreset\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12203" +"*/UAC-BOF-Bonanza.git*",".{0,1000}\/UAC\-BOF\-Bonanza\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of UAC Bypass Techniques Weaponized as BOFs","T1548.002 - T1203 - T1055 - T1134.002","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/icyguider/UAC-BOF-Bonanza","1","1","N/A","N/A","10","6","500","65","2024-02-21T22:07:54Z","2024-02-16T14:47:13Z","12204" +"*/UACBypass.dll*",".{0,1000}\/UACBypass\.dll.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","12205" +"*/UAC-Bypass.ps1*",".{0,1000}\/UAC\-Bypass\.ps1.{0,1000}","offensive_tool_keyword","bypassUAC","UAC bypass for x64 Windows 7 - 11","T1088 - T1202 - T1112 - T1059 - T1548.002","TA0005 - TA0004","N/A","Dispossessor","Defense Evasion","https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC","1","1","N/A","N/A","9","9","802","156","2022-07-27T15:48:45Z","2022-07-14T02:37:50Z","12206" +"*/UACBypasses/*",".{0,1000}\/UACBypasses\/.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","12207" +"*/UacInfo64.exe*",".{0,1000}\/UacInfo64\.exe.{0,1000}","offensive_tool_keyword","UACME","Defeating Windows User Account Control by abusing built-in Windows AutoElevate backdoor.","T1548 - T1547 - T1218","TA0002 - TA0005 - TA0004","N/A","Evilnum","Defense Evasion","https://github.com/hfiref0x/UACME","1","1","N/A","N/A","10","10","6711","1348","2025-03-09T03:33:26Z","2015-03-28T12:04:33Z","12208" +"*/UACME.git*",".{0,1000}\/UACME\.git.{0,1000}","offensive_tool_keyword","UACME","Defeating Windows User Account Control by abusing built-in Windows AutoElevate backdoor.","T1548 - T1547 - T1218","TA0002 - TA0005 - TA0004","N/A","Evilnum","Defense Evasion","https://github.com/hfiref0x/UACME","1","1","N/A","N/A","10","10","6711","1348","2025-03-09T03:33:26Z","2015-03-28T12:04:33Z","12209" +"*/UAC-SilentClean/*",".{0,1000}\/UAC\-SilentClean\/.{0,1000}","offensive_tool_keyword","cobaltstrike","New UAC bypass for Silent Cleanup for CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EncodeGroup/UAC-SilentClean","1","1","N/A","N/A","10","10","192","31","2021-07-14T13:51:02Z","2020-10-07T13:25:21Z","12210" +"*/UAC-TokenMagic.ps1*",".{0,1000}\/UAC\-TokenMagic\.ps1.{0,1000}","offensive_tool_keyword","TokenPlayer","Manipulating and Abusing Windows Access Tokens","T1134 - T1484 - T1055 - T1078","TA0004 - TA0005 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S1ckB0y1337/TokenPlayer","1","1","N/A","N/A","10","3","274","45","2021-01-15T16:07:47Z","2020-08-20T23:05:49Z","12211" +"*/ubiquiti-discovery.nse*",".{0,1000}\/ubiquiti\-discovery\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12213" +"*/udmp-parser.git*",".{0,1000}\/udmp\-parser\.git.{0,1000}","offensive_tool_keyword","udmp-parser","A Cross-Platform C++ parser library for Windows user minidumps.","T1005 - T1059.003 - T1027.002","TA0009 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/0vercl0k/udmp-parser","1","1","N/A","N/A","6","3","202","23","2024-11-20T15:58:21Z","2022-01-30T18:56:21Z","12214" +"*/UefiShell.iso*",".{0,1000}\/UefiShell\.iso.{0,1000}","offensive_tool_keyword","EfiGuard","EfiGuard is a portable x64 UEFI bootkit that patches the Windows boot manager - boot loader and kernel at boot time in order to disable PatchGuard and Driver Signature Enforcement (DSE).","T1542.002 - T1542.003 - T1542.004","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Mattiwatti/EfiGuard","1","1","N/A","N/A","10","10","1977","354","2025-02-24T11:57:36Z","2019-03-25T19:47:39Z","12215" +"*/umeshshinde19/instainsane*",".{0,1000}\/umeshshinde19\/instainsane.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/umeshshinde19/instainsane","1","1","N/A","N/A","7","7","655","371","2024-02-11T10:29:05Z","2018-12-02T22:48:11Z","12216" +"*/UnconstrainedDelegationCheck .ahk*",".{0,1000}\/UnconstrainedDelegationCheck\s\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","12217" +"*/unDefender.exe*",".{0,1000}\/unDefender\.exe.{0,1000}","offensive_tool_keyword","unDefender","Killing your preferred antimalware by abusing native symbolic links and NT paths.","T1562.001 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/APTortellini/unDefender","1","1","N/A","N/A","10","4","358","81","2022-01-29T12:35:31Z","2021-08-21T14:45:39Z","12218" +"*/unDefender.git*",".{0,1000}\/unDefender\.git.{0,1000}","offensive_tool_keyword","unDefender","Killing your preferred antimalware by abusing native symbolic links and NT paths.","T1562.001 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/APTortellini/unDefender","1","1","N/A","N/A","10","4","358","81","2022-01-29T12:35:31Z","2021-08-21T14:45:39Z","12219" +"*/undertheradar.git*",".{0,1000}\/undertheradar\.git.{0,1000}","offensive_tool_keyword","undertheradar","scripts that afford the pentester AV bypass techniques","T1055.005 - T1027 - T1116 - T1070.004","TA0040 - TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/g3tsyst3m/undertheradar","1","1","N/A","N/A","9","1","11","2","2023-10-08T23:31:33Z","2023-07-01T17:59:20Z","12220" +"*/unhook-bof*",".{0,1000}\/unhook\-bof.{0,1000}","offensive_tool_keyword","C2 related tools","Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners and analysts.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/mgeeky/ThreadStackSpoofer","1","1","N/A","N/A","10","10","1109","180","2022-06-17T18:06:35Z","2021-09-26T22:48:17Z","12221" +"*/unhook-bof*",".{0,1000}\/unhook\-bof.{0,1000}","offensive_tool_keyword","cobaltstrike","Remove API hooks from a Beacon process.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/unhook-bof","1","1","N/A","N/A","10","10","57","16","2022-03-13T15:57:10Z","2021-07-02T14:55:38Z","12222" +"*/unhook-bof*",".{0,1000}\/unhook\-bof.{0,1000}","offensive_tool_keyword","cobaltstrike","Remove API hooks from a Beacon process.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/unhook-bof","1","1","N/A","N/A","10","10","268","59","2021-09-18T18:12:41Z","2021-01-13T02:20:44Z","12223" +"*/UnhookingPatch.git*",".{0,1000}\/UnhookingPatch\.git.{0,1000}","offensive_tool_keyword","UnhookingPatch","Bypass EDR Hooks by patching NT API stub and resolving SSNs and syscall instructions at runtime","T1055 - T1574","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/SaadAhla/UnhookingPatch","1","1","N/A","N/A","8","4","304","52","2023-08-02T02:25:38Z","2023-02-08T16:21:03Z","12224" +"*/UnhookingPatch.git*",".{0,1000}\/UnhookingPatch\.git.{0,1000}","offensive_tool_keyword","UnhookingPatch","Bypass EDR Hooks by patching NT API stub and resolving SSNs and syscall instructions at runtime","T1055 - T1055.001 - T1070 - T1070.004 - T1211","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/UnhookingPatch","1","1","N/A","N/A","9","4","304","52","2023-08-02T02:25:38Z","2023-02-08T16:21:03Z","12225" +"*/UnhookNTDLL.ahk*",".{0,1000}\/UnhookNTDLL\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","12226" +"*/unicorn.git*",".{0,1000}\/unicorn\.git.{0,1000}","offensive_tool_keyword","unicorn","Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory","T1059.001 - T1055.012 - T1027.002 - T1547.009","TA0002 - TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/trustedsec/unicorn","1","1","N/A","N/A","N/A","10","3818","816","2024-01-24T20:02:33Z","2013-06-19T08:38:06Z","12227" +"*/unicorn.py*",".{0,1000}\/unicorn\.py.{0,1000}","offensive_tool_keyword","unicorn","Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory","T1059.001 - T1055.012 - T1027.002 - T1547.009","TA0002 - TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/trustedsec/unicorn","1","1","N/A","N/A","N/A","10","3818","816","2024-01-24T20:02:33Z","2013-06-19T08:38:06Z","12228" +"*/unittest.nse*",".{0,1000}\/unittest\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12229" +"*/UnlinkDLL.git*",".{0,1000}\/UnlinkDLL\.git.{0,1000}","offensive_tool_keyword","UnlinkDLL","DLL Unlinking from InLoadOrderModuleList - InMemoryOrderModuleList - InInitializationOrderModuleList and LdrpHashTable","T1055 - T1027 - T1070","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/frkngksl/UnlinkDLL","1","1","N/A","N/A","7","1","57","13","2023-12-15T12:04:00Z","2023-12-13T14:37:33Z","12230" +"*/UnmanagedPowerShell.git*",".{0,1000}\/UnmanagedPowerShell\.git.{0,1000}","offensive_tool_keyword","UnmanagedPowerShell","Executes PowerShell from an unmanaged process","T1059 - T1086","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/leechristensen/UnmanagedPowerShell","1","1","N/A","N/A","6","5","487","113","2016-03-17T05:20:55Z","2014-12-15T00:59:03Z","12232" +"*/unrootkit.dll*",".{0,1000}\/unrootkit\.dll.{0,1000}","offensive_tool_keyword","Discord-RAT-2.0","Discord Remote Administration Tool fully written in c#, stub size of ~75kb with over 40 post exploitations modules","T1059.005 - T1105 - T1569.002 - T1027.001","TA0011 - TA0003 - TA0006 - TA0009 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/moom825/Discord-RAT-2.0","1","1","N/A","N/A","10","10","512","115","2023-11-03T01:15:38Z","2022-07-15T20:09:56Z","12233" +"*/unshackle.git*",".{0,1000}\/unshackle\.git.{0,1000}","offensive_tool_keyword","unshackle","Unshackle is an open-source tool to bypass Windows and Linux user passwords from a bootable USB based on Linux","T1110.004 - T1059.004 - T1070.004","TA0006 - TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Fadi002/unshackle","1","1","#linux #windows","N/A","10","10","1899","125","2023-11-10T19:48:10Z","2023-07-19T22:30:28Z","12234" +"*/unstable/net/iodine*",".{0,1000}\/unstable\/net\/iodine.{0,1000}","offensive_tool_keyword","iodine","iodine. iodined - tunnel IPv4 over DNS","T1573.001 - T1573.002 - T1573.003 - T1573.004","TA0011 - TA0010 - TA0002 - TA0005","N/A","EMBER BEAR","C2","https://github.com/yarrick/iodine","1","1","N/A","N/A","10","10","6413","524","2025-04-08T17:44:12Z","2012-02-04T19:51:39Z","12237" +"*/UnstoppableService.git*",".{0,1000}\/UnstoppableService\.git.{0,1000}","offensive_tool_keyword","UnstoppableService","a Windows service in C# that is self installing as a single executable and sets proper attributes to prevent an administrator from stopping or pausing the service through the Windows Service Control Manager interface","T1543.003 - T1564.001 - T1490","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/malcomvetter/UnstoppableService","1","1","N/A","N/A","5","1","66","15","2019-01-19T22:38:18Z","2018-08-07T22:11:22Z","12238" +"*/unused/locktest.sh*",".{0,1000}\/unused\/locktest\.sh.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","12239" +"*/unused/Yosemite.patch*",".{0,1000}\/unused\/Yosemite\.patch.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","12240" +"*/unusual-port.nse*",".{0,1000}\/unusual\-port\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12241" +"*/upload_c2profiles.py*",".{0,1000}\/upload_c2profiles\.py.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","12246" +"*/Upload-OneDrive.exe*",".{0,1000}\/Upload\-OneDrive\.exe.{0,1000}","offensive_tool_keyword","SharpExfil","C# executables to extract information from target environment using OneDrive API.","T1567.002 - T1020 - T1071.001","TA0005 - TA0010 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/adm1nPanda/SharpExfil","1","1","N/A","N/A","8","1","6","1","2020-07-02T14:48:55Z","2019-07-27T05:28:40Z","12247" +"*/upnp-info.nse*",".{0,1000}\/upnp\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12248" +"*/uptime-agent-info.nse*",".{0,1000}\/uptime\-agent\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12249" +"*/url-snarf.nse*",".{0,1000}\/url\-snarf\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12250" +"*/usb140201.zip*",".{0,1000}\/usb140201\.zip.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12251" +"*/user_data/*/keylog.txt*",".{0,1000}\/user_data\/.{0,1000}\/keylog\.txt.{0,1000}","offensive_tool_keyword","cuddlephish","Weaponized Browser-in-the-Middle (BitM) for Penetration Testers","T1185 - T1185.002 - T1071 - T1071.001 - T1556 - T1556.001","TA0009 - TA0006","N/A","N/A","Sniffing & Spoofing","https://github.com/fkasler/cuddlephish","1","1","N/A","N/A","10","5","487","51","2024-11-21T17:36:55Z","2023-08-02T14:30:41Z","12252" +"*/user_persistence_run.c*",".{0,1000}\/user_persistence_run\.c.{0,1000}","offensive_tool_keyword","OffensiveCpp","C/C++ snippets that can be handy in specific offensive scenarios","T1055 - T1047 - T1105 - T1117 - T1129 - T1135 - T1203","TA0002 - TA0003 - TA0006 - TA0007 - TA0009","N/A","N/A","Exploitation tool","https://github.com/lsecqt/OffensiveCpp","1","1","N/A","N/A","10","8","700","83","2025-01-26T08:05:48Z","2023-04-05T09:39:33Z","12253" +"*/userenum.go*",".{0,1000}\/userenum\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","12254" +"*/userenum.go*",".{0,1000}\/userenum\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","12255" +"*/username-anarchy*",".{0,1000}\/username\-anarchy.{0,1000}","offensive_tool_keyword","username-anarchy","Tools for generating usernames when penetration testing. Usernames are half the password brute force problem.","T1110 - T1134 - T1078","TA0006","N/A","Black Basta","Credential Access","https://github.com/urbanadventurer/username-anarchy","1","1","N/A","N/A","N/A","10","1000","140","2024-09-20T01:57:59Z","2012-11-07T05:35:10Z","12257" +"*/UserRightsUtil.exe*",".{0,1000}\/UserRightsUtil\.exe.{0,1000}","offensive_tool_keyword","PrivFu","manage user right without secpol.msc","T1059 - T1078","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","UserRightsUtil","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","12259" +"*/Use-Waitfor.exe*",".{0,1000}\/Use\-Waitfor\.exe.{0,1000}","offensive_tool_keyword","Waitfor-Persistence","Use Waitfor.exe to maintain persistence","T1059 - T1117 - T1053.005 - T1546.013","TA0002 - TA0003","N/A","N/A","Persistence","https://github.com/3gstudent/Waitfor-Persistence","1","1","N/A","N/A","9","1","54","19","2021-04-17T01:41:42Z","2017-06-07T09:33:13Z","12260" +"*/usniper.py*",".{0,1000}\/usniper\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","12261" +"*/usr/bin/pkexec*",".{0,1000}\/usr\/bin\/pkexec.{0,1000}","offensive_tool_keyword","POC","Exploit for the pwnkit vulnerability (https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt) from the Qualys team","T1068","TA0004","N/A","N/A","Exploitation tool","https://github.com/Ayrx/CVE-2021-4034","1","1","#linux","N/A","N/A","1","93","14","2022-01-27T11:57:05Z","2022-01-26T03:33:47Z","12338" +"*/utils/external_drive_password_recovery.html*",".{0,1000}\/utils\/external_drive_password_recovery\.html.{0,1000}","offensive_tool_keyword","ExtPassword.exe","Nirsoft tool for Windows that allows you to recover passwords stored on external drive plugged to your computer","T1081 - T1003 - T1212","TA0006 - TA0009","N/A","LockBit","Credential Access","https://www.nirsoft.net/utils/external_drive_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12381" +"*/utils/mailpv.html*",".{0,1000}\/utils\/mailpv\.html.{0,1000}","offensive_tool_keyword","MailPassView","Mail PassView is a small password-recovery tool that reveals the passwords and other account details for multiple email clients","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - Kimsuky - Evilnum - XDSpy","Credential Access","https://www.nirsoft.net/utils/mailpv.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12382" +"*/utils/network_password_recovery.html*",".{0,1000}\/utils\/network_password_recovery\.html.{0,1000}","offensive_tool_keyword","netpass","When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password.","T1081 - T1003 - T1555","TA0006 - TA0009","N/A","Kimsuky - XDSpy - TRAVELING SPIDER","Credential Access","https://www.nirsoft.net/utils/network_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12383" +"*/utils/obfuscate.py*",".{0,1000}\/utils\/obfuscate\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","12385" +"*/utils/passwordfox.html*",".{0,1000}\/utils\/passwordfox\.html.{0,1000}","offensive_tool_keyword","passwordfox","recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox","T1555.003 - T1003 - T1083","TA0006 ","N/A","LockBit - GoGoogle - 8BASE - XDSpy","Credential Access","https://www.nirsoft.net/utils/passwordfox.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12386" +"*/utils/vnc_password.html*",".{0,1000}\/utils\/vnc_password\.html.{0,1000}","offensive_tool_keyword","VNCPassView","recover the passwords stored by the VNC tool","T1003 - T1555 - T1081","TA0006 - TA0007","N/A","GoGoogle - 8BASE","Credential Access","https://www.nirsoft.net/utils/vnc_password.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12387" +"*/UTWOqVQ132/*",".{0,1000}\/UTWOqVQ132\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","12388" +"*/UUID_bypass.py*",".{0,1000}\/UUID_bypass\.py.{0,1000}","offensive_tool_keyword","FourEye","AV Evasion Tool","T1059 - T1059.001 - T1059.005 - T1027 - T1027.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/lengjibo/FourEye","1","1","N/A","N/A","10","8","758","152","2021-12-08T11:55:15Z","2020-12-11T01:29:58Z","12389" +"*/v1.0.0/moonwalk_linux*",".{0,1000}\/v1\.0\.0\/moonwalk_linux.{0,1000}","offensive_tool_keyword","moonwalk","Cover your tracks during Linux Exploitation by leaving zero traces on system logs and filesystem timestamps.","T1070 - T1036.005 - T1070.004","TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/mufeedvh/moonwalk","1","1","#linux","N/A","10","10","1440","129","2022-10-08T05:05:36Z","2021-12-19T11:24:00Z","12392" +"*/vainject.c*",".{0,1000}\/vainject\.c.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12393" +"*/vajra/phishApp.py*",".{0,1000}\/vajra\/phishApp\.py.{0,1000}","offensive_tool_keyword","Vajra","Vajra is a UI based tool with multiple techniques for attacking and enumerating in target's Azure environment","T1087 - T1098 - T1583 - T1078 - T1110 - T1566 - T1537 - T1020 - T1526 - T1482","TA0003 - TA0006 - TA0007 - TA0008 - TA0009","N/A","N/A","Exploitation tool","https://github.com/TROUBLE-1/Vajra","1","1","N/A","N/A","N/A","4","391","61","2025-02-21T16:40:23Z","2022-03-01T14:31:27Z","12394" +"*/vanity.exe*",".{0,1000}\/vanity\.exe.{0,1000}","offensive_tool_keyword","Dirty-Vanity","injection technique abusing windows fork API to evade EDRs","T1055 - T1562 - T1070 - T1027","TA0005 - TA0006","N/A","N/A","Defense Evasion","https://github.com/deepinstinct/Dirty-Vanity","1","1","N/A","N/A","10","7","633","86","2022-12-23T10:54:10Z","2022-11-24T10:54:00Z","12395" +"*/Vanity_Dump.exe*",".{0,1000}\/Vanity_Dump\.exe.{0,1000}","offensive_tool_keyword","RedTeam_Tools_n_Stuff","minidumpwritedump a RtlCreateProcessReflection copy of a targeted Windows process","T1070.004 - T1222 - T1070.003 - T1003.005 - T1057","TA0005 - TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/samkenxstream/SAMkenXCCorePHdLAwiN8SoLr77","1","1","N/A","N/A","7","1","1","1","2023-10-13T06:31:42Z","2023-10-04T13:43:37Z","12396" +"*/var/lib/ptunnel*",".{0,1000}\/var\/lib\/ptunnel.{0,1000}","offensive_tool_keyword","ptunnel-ng","Tunnel TCP connections through ICMP.","T1095.001 - T1572.001","TA0011 - TA0040 - TA0003","N/A","N/A","Data Exfiltration","https://github.com/utoni/ptunnel-ng","1","1","#linux","N/A","8","5","456","76","2024-11-27T18:34:33Z","2017-12-19T18:10:35Z","12399" +"*/var/www/html/dynasty_rce*",".{0,1000}\/var\/www\/html\/dynasty_rce.{0,1000}","offensive_tool_keyword","DynastyPersist","Linux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd Service","T1055 - T1037 - T1078 - T1547 - T1546 - T1556","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/Trevohack/DynastyPersist","1","1","#linux","N/A","9","2","153","17","2024-05-16T05:19:48Z","2023-08-13T15:05:42Z","12418" +"*/var0xshell.git*",".{0,1000}\/var0xshell\.git.{0,1000}","offensive_tool_keyword","var0xshell","var0xshell - shell with xor encryption","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/yehia-mamdouh/var0xshell/tree/main","1","1","#linux","N/A","8","10","4","1","2023-01-09T06:53:42Z","2023-01-08T21:34:26Z","12419" +"*/vas/fuzzers/fuzz/*",".{0,1000}\/vas\/fuzzers\/fuzz\/.{0,1000}","offensive_tool_keyword","linikatz","linikatz is a tool to attack AD on UNIX","T1003.002 - T1558.003 - T1078 - T1550.001","TA0006 - TA0001 - TA0004 - TA0003","N/A","N/A","Exploitation tool","https://github.com/CiscoCXSecurity/linikatz","1","1","#linux","N/A","10","6","552","79","2023-10-19T17:01:47Z","2018-11-15T22:19:47Z","12420" +"*/vba_gen.py*",".{0,1000}\/vba_gen\.py.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","12421" +"*/VBad.git*",".{0,1000}\/VBad\.git.{0,1000}","offensive_tool_keyword","vbad","VBad is fully customizable VBA Obfuscation Tool combined with an MS Office document generator. It aims to help Red & Blue team for attack or defense.","T1564 - T1117 - T1204 - T1070","TA0002 - TA0008 - TA0011","N/A","N/A","Defense Evasion","https://github.com/Pepitoh/Vbad","1","1","N/A","N/A","8","6","544","127","2017-10-15T12:56:18Z","2016-03-09T12:36:04Z","12422" +"*/vbarandomizer.py*",".{0,1000}\/vbarandomizer\.py.{0,1000}","offensive_tool_keyword","spinningteacup","identify different parts of a vba script and perform substitutions","T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","12423" +"*/VDR.git*",".{0,1000}\/VDR\.git.{0,1000}","offensive_tool_keyword","VDR","Vulnerable driver research tool - result and exploit PoCs","T1547.009 - T1210 - T1068 - T1055","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/TakahiroHaruyama/VDR","1","1","N/A","N/A","10","2","192","29","2023-11-01T00:06:55Z","2023-10-23T08:34:44Z","12425" +"*/VDR-main.zip",".{0,1000}\/VDR\-main\.zip","offensive_tool_keyword","VDR","Vulnerable driver research tool - result and exploit PoCs","T1547.009 - T1210 - T1068 - T1055","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/TakahiroHaruyama/VDR","1","1","N/A","N/A","10","2","192","29","2023-11-01T00:06:55Z","2023-10-23T08:34:44Z","12426" +"*/VectorKernel.git*",".{0,1000}\/VectorKernel\.git.{0,1000}","offensive_tool_keyword","VectorKernel","PoCs for Kernelmode rootkit techniques research.","T1543 - T1055 - T1134 - T1564 - T1070 - T1057 - T1574 - T1562 - T1082 - T1518","TA0003 - TA0005 - TA0004 - TA0008 - TA0007","N/A","N/A","Exploitation tool","https://github.com/daem0nc0re/VectorKernel/","1","1","N/A","N/A","10","4","367","60","2025-01-21T08:22:42Z","2023-11-23T12:36:31Z","12427" +"*/veeam_dump.py*",".{0,1000}\/veeam_dump\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","12428" +"*/veeam-creds.git*",".{0,1000}\/veeam\-creds\.git.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","1","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","12429" +"*/VeeamHax.exe",".{0,1000}\/VeeamHax\.exe","offensive_tool_keyword","VeamHax","Exploit for CVE-2023-27532 against Veeam Backup & Replication (Plaintext credential leaking tool)","T1059 - T1203 - T1040 - T1189 - T1010","TA0001 - TA0002 - TA0009 - TA0011","More_eggs","Akira - FIN6","Exploitation tool","https://github.com/sfewer-r7/CVE-2023-27532","1","1","N/A","N/A","8","2","110","22","2023-03-23T18:03:27Z","2023-03-23T16:08:43Z","12430" +"*/Vegile.git*",".{0,1000}\/Vegile\.git.{0,1000}","offensive_tool_keyword","BruteSploit","Ghost In The Shell - This tool will setting up your backdoor/rootkits when backdoor already setup it will be hidden your spesisifc process.unlimited your session in metasploit and transparent. Even when it killed. it will re-run again. There always be a procces which while run another process.So we can assume that this procces is unstopable like a Ghost in The Shell","T1587 - T1588 - T1608","N/A","N/A","N/A","Exploitation tool","https://github.com/screetsec/Vegile","1","1","N/A","N/A","N/A","8","726","164","2022-09-01T01:54:35Z","2018-01-02T05:29:48Z","12431" +"*/Venom.git*",".{0,1000}\/Venom\.git.{0,1000}","offensive_tool_keyword","Venom","Venom - A Multi-hop Proxy for Penetration Testers","T1090","TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/Dliv3/Venom","1","1","N/A","N/A","10","10","2070","357","2022-05-11T03:13:20Z","2019-01-13T07:35:29Z","12432" +"*/venom.git*",".{0,1000}\/venom\.git.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","12433" +"*/Venom.v1.0.1.7z*",".{0,1000}\/Venom\.v1\.0\.1\.7z.{0,1000}","offensive_tool_keyword","Venom","Venom - A Multi-hop Proxy for Penetration Testers","T1090","TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/Dliv3/Venom","1","1","N/A","N/A","10","10","2070","357","2022-05-11T03:13:20Z","2019-01-13T07:35:29Z","12435" +"*/Venom.v1.0.2.7z*",".{0,1000}\/Venom\.v1\.0\.2\.7z.{0,1000}","offensive_tool_keyword","Venom","Venom - A Multi-hop Proxy for Penetration Testers","T1090","TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/Dliv3/Venom","1","1","N/A","N/A","10","10","2070","357","2022-05-11T03:13:20Z","2019-01-13T07:35:29Z","12436" +"*/Venom.v1.0.7z*",".{0,1000}\/Venom\.v1\.0\.7z.{0,1000}","offensive_tool_keyword","Venom","Venom - A Multi-hop Proxy for Penetration Testers","T1090","TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/Dliv3/Venom","1","1","N/A","N/A","10","10","2070","357","2022-05-11T03:13:20Z","2019-01-13T07:35:29Z","12437" +"*/Venom.v1.1.0.7z*",".{0,1000}\/Venom\.v1\.1\.0\.7z.{0,1000}","offensive_tool_keyword","Venom","Venom - A Multi-hop Proxy for Penetration Testers","T1090","TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/Dliv3/Venom","1","1","N/A","N/A","10","10","2070","357","2022-05-11T03:13:20Z","2019-01-13T07:35:29Z","12438" +"*/Venom/tarball/v*",".{0,1000}\/Venom\/tarball\/v.{0,1000}","offensive_tool_keyword","Venom","Venom - A Multi-hop Proxy for Penetration Testers","T1090","TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/Dliv3/Venom","1","1","N/A","N/A","10","10","2070","357","2022-05-11T03:13:20Z","2019-01-13T07:35:29Z","12439" +"*/Venom/zipball/v*",".{0,1000}\/Venom\/zipball\/v.{0,1000}","offensive_tool_keyword","Venom","Venom - A Multi-hop Proxy for Penetration Testers","T1090","TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/Dliv3/Venom","1","1","N/A","N/A","10","10","2070","357","2022-05-11T03:13:20Z","2019-01-13T07:35:29Z","12440" +"*/venomoussway.py*",".{0,1000}\/venomoussway\.py.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","12441" +"*/ventrilo-info.nse*",".{0,1000}\/ventrilo\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12442" +"*/versant-info.nse*",".{0,1000}\/versant\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12443" +"*/victim_info_key.py*",".{0,1000}\/victim_info_key\.py.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","12444" +"*/villain.py*",".{0,1000}villain\.py.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","12447" +"*/viper.py*",".{0,1000}\/viper\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","12448" +"*/viper.sln*",".{0,1000}\/viper\.sln.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","12449" +"*/viper/Docker/*",".{0,1000}\/viper\/Docker\/.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","12450" +"*/vipermsf*",".{0,1000}\/vipermsf.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","1","N/A","N/A","N/A","N/A","12452" +"*/viperpython.git*",".{0,1000}\/viperpython\.git.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","12454" +"*/Virus Rat v*.exe*",".{0,1000}\/Virus\sRat\sv.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","12456" +"*/VirusTotalC2/*",".{0,1000}\/VirusTotalC2\/.{0,1000}","offensive_tool_keyword","VirusTotalC2","Abusing VirusTotal API to host our C2 traffic. usefull for bypassing blocking firewall rules if VirusTotal is in the target white list and in case you don't have C2 infrastructure. now you have a free one","T1071.004 - T1102 - T1021.002","TA0011 - TA0008 - TA0042","N/A","N/A","C2","https://github.com/RATandC2/VirusTotalC2","1","1","N/A","N/A","10","10","27","81","2022-09-28T15:10:44Z","2022-09-28T15:12:42Z","12457" +"*/VisualBasicObfuscator*",".{0,1000}\/VisualBasicObfuscator.{0,1000}","offensive_tool_keyword","phishing-HTML-linter","Phishing and Social-Engineering related scripts","T1566.001 - T1056.001","TA0040 - TA0001","N/A","N/A","Phishing","https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing","1","1","N/A","N/A","10","10","2689","527","2023-06-27T19:16:49Z","2018-02-02T21:24:03Z","12458" +"*/vmauthd-brute.nse*",".{0,1000}\/vmauthd\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12459" +"*/vmware_enum_*.rb*",".{0,1000}\/vmware_enum_.{0,1000}\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","12460" +"*/vmware_vcenter_cve_2020_3952*",".{0,1000}\/vmware_vcenter_cve_2020_3952.{0,1000}","offensive_tool_keyword","POC","CVE-2020-3952 POC exploitation","T1190 - T1040 - T1059.001","TA0001 - TA0003 - TA0009","N/A","Dispossessor","Exploitation tool","https://github.com/guardicore/vmware_vcenter_cve_2020_3952","1","1","N/A","N/A","7","3","273","60","2020-04-16T08:38:42Z","2020-04-16T07:40:51Z","12461" +"*/VMware-CVE-2022-22954*",".{0,1000}\/VMware\-CVE\-2022\-22954.{0,1000}","offensive_tool_keyword","POC","POC for VMWARE CVE-2022-22954","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/sherlocksecurity/VMware-CVE-2022-22954","1","1","N/A","N/A","N/A","3","281","53","2022-04-13T06:15:11Z","2022-04-11T13:59:23Z","12462" +"*/vmware-version.nse*",".{0,1000}\/vmware\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12463" +"*/vnc-brute.nse*",".{0,1000}\/vnc\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12464" +"*/vncdll.*",".{0,1000}\/vncdll\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","12465" +"*/vncdll/*",".{0,1000}\/vncdll\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","12466" +"*/vncEncoder.*",".{0,1000}\/vncEncoder\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","12467" +"*/VNCHooks*",".{0,1000}\/VNCHooks.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","12468" +"*/VNCHooks.*",".{0,1000}\/VNCHooks\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","12469" +"*/vnc-info.nse*",".{0,1000}\/vnc\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12470" +"*/vnc-title.nse*",".{0,1000}\/vnc\-title\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12473" +"*/Voidgate.exe*",".{0,1000}\/Voidgate\.exe.{0,1000}","offensive_tool_keyword","Voidgate","bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes","T1027 - T1070 - T1055","TA0005","N/A","N/A","Defense Evasion","https://github.com/undergroundwires/privacy.sexy","1","1","N/A","N/A","9","10","4632","198","2025-04-21T21:36:39Z","2019-12-31T14:38:28Z","12475" +"*/Voidgate.git*",".{0,1000}\/Voidgate\.git.{0,1000}","offensive_tool_keyword","Voidgate","bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes","T1027 - T1070 - T1055","TA0005","N/A","N/A","Defense Evasion","https://github.com/undergroundwires/privacy.sexy","1","1","N/A","N/A","9","10","4632","198","2025-04-21T21:36:39Z","2019-12-31T14:38:28Z","12476" +"*/voldemort-info.nse*",".{0,1000}\/voldemort\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12477" +"*/Volumiser.exe*",".{0,1000}\/Volumiser\.exe.{0,1000}","offensive_tool_keyword","Volumiser","Volumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats.","T1560.001 - T1059 - T1114 - T1005","TA0005 - TA0009","N/A","N/A","Collection","https://github.com/CCob/Volumiser","1","1","N/A","N/A","7","4","379","42","2025-04-22T15:47:53Z","2022-11-08T21:38:56Z","12478" +"*/Volumiser.git*",".{0,1000}\/Volumiser\.git.{0,1000}","offensive_tool_keyword","Volumiser","Volumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats.","T1560.001 - T1059 - T1114 - T1005","TA0005 - TA0009","N/A","N/A","Collection","https://github.com/CCob/Volumiser","1","1","N/A","N/A","7","4","379","42","2025-04-22T15:47:53Z","2022-11-08T21:38:56Z","12479" +"*/Volumiser-maser.zip*",".{0,1000}\/Volumiser\-maser\.zip.{0,1000}","offensive_tool_keyword","Volumiser","Volumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats.","T1560.001 - T1059 - T1114 - T1005","TA0005 - TA0009","N/A","N/A","Collection","https://github.com/CCob/Volumiser","1","1","N/A","N/A","7","4","379","42","2025-04-22T15:47:53Z","2022-11-08T21:38:56Z","12480" +"*/vpc__enum_lateral_movement*",".{0,1000}\/vpc__enum_lateral_movement.{0,1000}","offensive_tool_keyword","pacu","The AWS exploitation framework designed for testing the security of Amazon Web Services environments.","T1136.003 - T1190 - T1078.004","TA0006 - TA0001","N/A","Scattered Spider*","Framework","https://github.com/RhinoSecurityLabs/pacu","1","1","N/A","N/A","9","10","4651","731","2025-03-20T21:08:57Z","2018-06-13T21:58:59Z","12481" +"*/vss-enum.py*",".{0,1000}\/vss\-enum\.py.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","12484" +"*/vssenum/*",".{0,1000}\/vssenum\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","12485" +"*/vtam-enum.nse*",".{0,1000}\/vtam\-enum\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12487" +"*/vulners.nse*",".{0,1000}\/vulners\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12488" +"*/vulnscan.yaml*",".{0,1000}\/vulnscan\.yaml.{0,1000}","offensive_tool_keyword","Osmedeus","Osmedeus - A Workflow Engine for Offensive Security","T1595","TA0043","N/A","N/A","Exploitation tool","https://github.com/j3ssie/osmedeus","1","1","N/A","N/A","N/A","10","5566","907","2025-04-22T14:57:07Z","2018-11-10T04:17:18Z","12489" +"*/vulnserver.py*",".{0,1000}\/vulnserver\.py.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","12490" +"*/vulscan.nse*",".{0,1000}\/vulscan\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://github.com/cldrn/nmap-nse-scripts/tree/master/scripts","1","1","N/A","N/A","N/A","10","968","369","2022-01-22T18:40:30Z","2011-05-31T05:41:49Z","12491" +"*/vuze-dht-info.nse*",".{0,1000}\/vuze\-dht\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12492" +"*/Wait_For_Command.ps1*",".{0,1000}\/Wait_For_Command\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","12494" +"*/Waitfor-Persistence.git*",".{0,1000}\/Waitfor\-Persistence\.git.{0,1000}","offensive_tool_keyword","Waitfor-Persistence","Use Waitfor.exe to maintain persistence","T1059 - T1117 - T1053.005 - T1546.013","TA0002 - TA0003","N/A","N/A","Persistence","https://github.com/3gstudent/Waitfor-Persistence","1","1","N/A","N/A","9","1","54","19","2021-04-17T01:41:42Z","2017-06-07T09:33:13Z","12495" +"*/Waitfor-Persistence.ps1*",".{0,1000}\/Waitfor\-Persistence\.ps1.{0,1000}","offensive_tool_keyword","Waitfor-Persistence","Use Waitfor.exe to maintain persistence","T1059 - T1117 - T1053.005 - T1546.013","TA0002 - TA0003","N/A","N/A","Persistence","https://github.com/3gstudent/Waitfor-Persistence","1","1","N/A","N/A","9","1","54","19","2021-04-17T01:41:42Z","2017-06-07T09:33:13Z","12496" +"*/wapitiCore/*",".{0,1000}\/wapitiCore\/.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","12497" +"*/wapiti-scanner/*",".{0,1000}\/wapiti\-scanner\/.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","12498" +"*/Watson.exe*",".{0,1000}\/Watson\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","12500" +"*/Watson.exe*",".{0,1000}\/Watson\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","12501" +"*/Watson.exe*",".{0,1000}\/Watson\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","12502" +"*/Watson.exe*",".{0,1000}\/Watson\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","12503" +"*/wce.exe*",".{0,1000}\/wce\.exe.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","1","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","12504" +"*/wce32.exe*",".{0,1000}\/wce32\.exe.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","1","N/A","N/A","8","4","N/A","N/A","N/A","N/A","12505" +"*/wce64.exe*",".{0,1000}\/wce64\.exe.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","1","N/A","N/A","8","4","N/A","N/A","N/A","N/A","12506" +"*/wce-beta.zip*",".{0,1000}\/wce\-beta\.zip.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","1","N/A","N/A","8","4","N/A","N/A","N/A","N/A","12507" +"*/wcreddump.git*",".{0,1000}\/wcreddump\.git.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","1","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","12508" +"*/wcreddump.py*",".{0,1000}\/wcreddump\.py.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","1","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","12509" +"*/wdb-version.nse*",".{0,1000}\/wdb\-version\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12510" +"*/WDExclusion.dll*",".{0,1000}\/WDExclusion\.dll.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","12511" +"*/wdextract.cpp*",".{0,1000}\/wdextract\.cpp.{0,1000}","offensive_tool_keyword","WDExtract","Extract Windows Defender database from vdm files and unpack it","T1059 - T1005 - T1119","TA0002 - TA0009 - TA0003","N/A","N/A","Defense Evasion","https://github.com/hfiref0x/WDExtract/","1","1","N/A","N/A","8","5","440","61","2020-02-10T06:53:43Z","2019-04-19T17:33:48Z","12512" +"*/wdextract.cpp*",".{0,1000}\/wdextract\.cpp.{0,1000}","offensive_tool_keyword","WDExtract","Extract Windows Defender database from vdm files and unpack it","T1059 - T1005 - T1119","TA0002 - TA0009 - TA0003","N/A","N/A","Defense Evasion","https://github.com/hfiref0x/WDExtract/","1","1","N/A","N/A","8","5","440","61","2020-02-10T06:53:43Z","2019-04-19T17:33:48Z","12513" +"*/WDExtract.git*",".{0,1000}\/WDExtract\.git.{0,1000}","offensive_tool_keyword","WDExtract","Extract Windows Defender database from vdm files and unpack it","T1059 - T1005 - T1119","TA0002 - TA0009 - TA0003","N/A","N/A","Defense Evasion","https://github.com/hfiref0x/WDExtract/","1","1","N/A","N/A","8","5","440","61","2020-02-10T06:53:43Z","2019-04-19T17:33:48Z","12514" +"*/wdextract32.exe*",".{0,1000}\/wdextract32\.exe.{0,1000}","offensive_tool_keyword","WDExtract","Extract Windows Defender database from vdm files and unpack it","T1059 - T1005 - T1119","TA0002 - TA0009 - TA0003","N/A","N/A","Defense Evasion","https://github.com/hfiref0x/WDExtract/","1","1","N/A","N/A","8","5","440","61","2020-02-10T06:53:43Z","2019-04-19T17:33:48Z","12515" +"*/wdextract64.exe*",".{0,1000}\/wdextract64\.exe.{0,1000}","offensive_tool_keyword","WDExtract","Extract Windows Defender database from vdm files and unpack it","T1059 - T1005 - T1119","TA0002 - TA0009 - TA0003","N/A","N/A","Defense Evasion","https://github.com/hfiref0x/WDExtract/","1","1","N/A","N/A","8","5","440","61","2020-02-10T06:53:43Z","2019-04-19T17:33:48Z","12516" +"*/wdigest.py*",".{0,1000}\/wdigest\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","12517" +"*/WdToggle.c*",".{0,1000}\/WdToggle\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/WdToggle","1","1","N/A","N/A","10","10","219","31","2023-05-03T19:51:43Z","2020-12-23T13:42:25Z","12518" +"*/WdToggle.h*",".{0,1000}\/WdToggle\.h.{0,1000}","offensive_tool_keyword","cobaltstrike","A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/WdToggle","1","1","N/A","N/A","10","10","219","31","2023-05-03T19:51:43Z","2020-12-23T13:42:25Z","12519" +"*/weakpass.git*",".{0,1000}\/weakpass\.git.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","12520" +"*/weakpass_2a.gz*",".{0,1000}\/weakpass_2a\.gz.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","12521" +"*/weakpass_3a.7z*",".{0,1000}\/weakpass_3a\.7z.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","12522" +"*/Web/decouverte.txt*",".{0,1000}\/Web\/decouverte\.txt.{0,1000}","offensive_tool_keyword","wordlists","Various wordlists FR & EN - Cracking French passwords","T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/clem9669/wordlists","1","1","N/A","N/A","N/A","3","280","45","2025-04-22T14:34:10Z","2020-10-21T14:37:53Z","12523" +"*/Web/discovery.txt*",".{0,1000}\/Web\/discovery\.txt.{0,1000}","offensive_tool_keyword","wordlists","Various wordlists FR & EN - Cracking French passwords","T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/clem9669/wordlists","1","1","N/A","N/A","N/A","3","280","45","2025-04-22T14:34:10Z","2020-10-21T14:37:53Z","12524" +"*/web/pwn.html*",".{0,1000}\/web\/pwn\.html.{0,1000}","offensive_tool_keyword","POC","Just another PoC for the new MSDT-Exploit","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/ItsNee/Follina-CVE-2022-30190-POC","1","1","N/A","N/A","N/A","1","5","0","2022-07-04T13:27:13Z","2022-06-05T13:54:04Z","12525" +"*/web_browser_password.html*",".{0,1000}\/web_browser_password\.html.{0,1000}","offensive_tool_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12526" +"*/web_delivery.py*",".{0,1000}\/web_delivery\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","12527" +"*/web_rce.py*",".{0,1000}\/web_rce\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","12528" +"*/webauthn-inject.js*",".{0,1000}\/webauthn\-inject\.js.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","1","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","12529" +"*/webdav.py*",".{0,1000}\/webdav\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","12531" +"*/web-hacking-toolkit*",".{0,1000}\/web\-hacking\-toolkit.{0,1000}","offensive_tool_keyword","web-hacking-toolkit","A web hacking toolkit Docker image with GUI applications support.","T1210 - T1059 - T1105 - T1189 - T1071","TA0001 - TA0002 - TA0011 - TA0005","N/A","N/A","Exploitation tool","https://github.com/signedsecurity/web-hacking-toolkit","1","1","N/A","N/A","N/A","","N/A","","","","12534" +"*/weblistener.py*",".{0,1000}\/weblistener\.py.{0,1000}","offensive_tool_keyword","octopus","Octopus is an open source. pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S.","T1059.001 - T1105 - T1071.001 - T1219 - T1573","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/mhaskar/Octopus","1","1","N/A","N/A","10","10","750","156","2021-07-06T23:52:37Z","2019-08-30T21:09:07Z","12536" +"*/WeblogicRCE.exe*",".{0,1000}\/WeblogicRCE\.exe.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","12537" +"*/weblogic-t3-info.nse*",".{0,1000}\/weblogic\-t3\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12538" +"*/webpassview.exe*",".{0,1000}\/webpassview\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","12539" +"*/webshell.py*",".{0,1000}\/webshell\.py.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1024 - T1071 - T1029 - T1569","TA0002 - TA0003 - TA0040","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","12540" +"*/webshell/*.aspx*",".{0,1000}\/webshell\/.{0,1000}\.aspx.{0,1000}","offensive_tool_keyword","cobaltstrike","Bypass firewall for traffic forwarding using webshell. Pystinger implements SOCK4 proxy and port mapping through webshell. It can be directly used by metasploit-framework - viper- cobalt strike for session online.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/FunnyWolf/pystinger","1","1","N/A","N/A","10","10","1397","205","2021-09-29T13:13:43Z","2019-09-29T05:23:54Z","12541" +"*/webshell/*.jsp*",".{0,1000}\/webshell\/.{0,1000}\.jsp.{0,1000}","offensive_tool_keyword","cobaltstrike","Bypass firewall for traffic forwarding using webshell. Pystinger implements SOCK4 proxy and port mapping through webshell. It can be directly used by metasploit-framework - viper- cobalt strike for session online.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/FunnyWolf/pystinger","1","1","N/A","N/A","10","10","1397","205","2021-09-29T13:13:43Z","2019-09-29T05:23:54Z","12542" +"*/webshell/*.php*",".{0,1000}\/webshell\/.{0,1000}\.php.{0,1000}","offensive_tool_keyword","cobaltstrike","Bypass firewall for traffic forwarding using webshell. Pystinger implements SOCK4 proxy and port mapping through webshell. It can be directly used by metasploit-framework - viper- cobalt strike for session online.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/FunnyWolf/pystinger","1","1","N/A","N/A","10","10","1397","205","2021-09-29T13:13:43Z","2019-09-29T05:23:54Z","12543" +"*/Webshell_Generate-1.1.jar*",".{0,1000}\/Webshell_Generate\-1\.1\.jar.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","12544" +"*/webshell-123.php*",".{0,1000}\/webshell\-123\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","12545" +"*/webshell-cnseay02-1.php*",".{0,1000}\/webshell\-cnseay02\-1\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","12546" +"*/webshell-cnseay-x.php*",".{0,1000}\/webshell\-cnseay\-x\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","12547" +"*/WebShellKillerTool.zip*",".{0,1000}\/WebShellKillerTool\.zip.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","12548" +"*/webshells/shell.aspx*",".{0,1000}\/webshells\/shell\.aspx.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","12549" +"*/webshells/shell.php*",".{0,1000}\/webshells\/shell\.php.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","12550" +"*/WebSocketC2.cs*",".{0,1000}\/WebSocketC2\.cs.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","12551" +"*/webtrufflehog.git*",".{0,1000}\/webtrufflehog\.git.{0,1000}","offensive_tool_keyword","webtrufflehog","Browser extension that leverages TruffleHog to scan web traffic in real-time for exposed secrets","T1552.001 - T1040 - T1036 - T1087","TA0006 - TA0007 - TA0009","N/A","N/A","Collection","https://github.com/c3l3si4n/webtrufflehog","1","1","N/A","N/A","7","2","102","10","2024-12-29T23:26:35Z","2024-12-28T19:53:09Z","12552" +"*/weevely.py*",".{0,1000}\/weevely\.py.{0,1000}","offensive_tool_keyword","Weevely3","Weevely is a web shell designed for post-exploitation purposes that can be extended over the network at runtime","T1059.003 - T1100 - T1071.001 - T1219 - T1078","TA0002 - TA0003 - TA0005 - TA0011 - TA0008","N/A","Sandworm","Resource Development","https://github.com/epinna/weevely3","1","1","N/A","N/A","8","10","3292","612","2024-10-18T04:32:13Z","2014-09-20T10:16:49Z","12557" +"*/well_known_sids.py*",".{0,1000}\/well_known_sids\.py.{0,1000}","offensive_tool_keyword","jackdaw","Jackdaw is here to collect all information in your domain. store it in a SQL database and show you nice graphs on how your domain objects interact with each-other an how a potential attacker may exploit these interactions. It also comes with a handy feature to help you in a password-cracking project by storing/looking up/reporting hashes/passowrds/users.","T1087 - T1482 - T1201 - T1213 - T1003","TA0007 - TA0008 - TA0009 - TA0006","N/A","N/A","Reconnaissance","https://github.com/skelsec/jackdaw","1","1","N/A","N/A","N/A","6","576","89","2025-03-15T13:37:50Z","2019-03-27T18:36:41Z","12558" +"*/WerTrigger.git*",".{0,1000}\/WerTrigger\.git.{0,1000}","offensive_tool_keyword","WerTrigger","Weaponizing for privileged file writes bugs with windows problem reporting","T1059.003 - T1055.001 - T1127.001 - T1546.008","TA0002 - TA0004 ","N/A","N/A","Privilege Escalation","https://github.com/sailay1996/WerTrigger","1","1","N/A","N/A","9","3","221","36","2022-05-10T17:36:49Z","2020-05-20T11:27:56Z","12559" +"*/WfpTokenDup.exe*",".{0,1000}\/WfpTokenDup\.exe.{0,1000}","offensive_tool_keyword","PrivFu","Kernel mode WinDbg extension and PoCs for token privilege investigation.","T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001","TA0007 - TA0008 - TA0002 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","12560" +"*/whatlicense.git*",".{0,1000}\/whatlicense\.git.{0,1000}","offensive_tool_keyword","whatlicense","WinLicense key extraction via Intel PIN","T1056 - T1056.001 - T1518 - T1518.001","TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/charlesnathansmith/whatlicense","1","1","N/A","N/A","6","2","101","25","2024-04-09T05:30:56Z","2023-07-10T11:57:44Z","12562" +"*/WheresMyImplant/*",".{0,1000}\/WheresMyImplant\/.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","12563" +"*/Whisker.exe*",".{0,1000}\/Whisker\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","12564" +"*/Whisker.exe*",".{0,1000}\/Whisker\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","Whisker","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","12565" +"*/Whisker.exe*",".{0,1000}\/Whisker\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","12566" +"*/Whisker.exe*",".{0,1000}\/Whisker\.exe.{0,1000}","offensive_tool_keyword","Whisker","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","Whisker","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","12567" +"*/whoami.py*",".{0,1000}\/whoami\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","12568" +"*/WhoAmI.task*",".{0,1000}\/WhoAmI\.task.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","12569" +"*/whois-domain.nse*",".{0,1000}\/whois\-domain\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12570" +"*/whois-ip.nse*",".{0,1000}\/whois\-ip\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12571" +"*/Widgets/LootWidget.*",".{0,1000}\/Widgets\/LootWidget\..{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","12572" +"*/wifi_hopping.*",".{0,1000}\/wifi_hopping\..{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","12573" +"*/WiFiBroot*",".{0,1000}\/WiFiBroot.{0,1000}","offensive_tool_keyword","wifibroot","A Wireless (WPA/WPA2) Pentest/Cracking tool. Captures & Crack 4-way handshake and PMKID key. Also. supports a deauthentication/jammer mode for stress testing","T1018 - T1040 - T1095 - T1113 - T1210 - T1437 - T1499 - T1557 - T1562 - T1573","TA0001 - TA0002 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://github.com/hash3liZer/WiFiBroot","1","1","N/A","network exploitation tool","N/A","10","1008","182","2021-01-15T09:07:36Z","2018-07-30T10:57:22Z","12574" +"*/wifidump.c*",".{0,1000}\/wifidump\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Various Cobalt Strike BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rvrsh3ll/BOF_Collection","1","1","N/A","N/A","10","10","635","57","2022-10-16T13:57:18Z","2020-07-16T18:24:55Z","12575" +"*/WifiKeys.dll*",".{0,1000}\/WifiKeys\.dll.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","12576" +"*/wifiPayload/client.py*",".{0,1000}\/wifiPayload\/client\.py.{0,1000}","offensive_tool_keyword","PyExfil","A Python Package for Data Exfiltration","T1041 - T1567 - T1027","TA0011 - TA0009 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/ytisf/PyExfil","1","1","N/A","N/A","10","8","782","141","2024-05-07T07:58:02Z","2014-11-27T19:06:24Z","12577" +"*/wifiPayload/server.py*",".{0,1000}\/wifiPayload\/server\.py.{0,1000}","offensive_tool_keyword","PyExfil","A Python Package for Data Exfiltration","T1041 - T1567 - T1027","TA0011 - TA0009 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/ytisf/PyExfil","1","1","N/A","N/A","10","8","782","141","2024-05-07T07:58:02Z","2014-11-27T19:06:24Z","12578" +"*/wifite2*",".{0,1000}\/wifite2.{0,1000}","offensive_tool_keyword","wifite2","This repo is a complete re-write of wifite. a Python script for auditing wireless networks.Run wifite. select your targets. and Wifite will automatically start trying to capture or crack the password.","T1590 - T1170 - T1595","TA0002 - TA0003 - TA0007","N/A","N/A","Credential Access","https://github.com/derv82/wifite2","1","1","N/A","network exploitation tool","N/A","10","6838","1403","2024-08-20T12:34:38Z","2015-05-30T06:09:52Z","12580" +"*/wikipedia_fr.7z*",".{0,1000}\/wikipedia_fr\.7z.{0,1000}","offensive_tool_keyword","wordlists","Various wordlists FR & EN - Cracking French passwords","T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/clem9669/wordlists","1","1","N/A","N/A","N/A","3","280","45","2025-04-22T14:34:10Z","2020-10-21T14:37:53Z","12581" +"*/wikiZ/RedGuard*",".{0,1000}\/wikiZ\/RedGuard.{0,1000}","offensive_tool_keyword","RedGuard","RedGuard is a C2 front flow control tool.Can avoid Blue Teams.AVs.EDRs check.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/wikiZ/RedGuard","1","1","N/A","N/A","10","10","1466","204","2024-08-20T17:43:35Z","2022-05-08T04:02:33Z","12582" +"*/win/Tor/tor.exe*",".{0,1000}\/win\/Tor\/tor\.exe.{0,1000}","offensive_tool_keyword","tor","Tor is a python based module for using tor proxy/network services on windows - osx - linux with just one click.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0005 - TA0010 - TA0011","N/A","Dispossessor - APT28 - APT29 - Leviathan","Defense Evasion","https://github.com/r0oth3x49/Tor","1","1","N/A","N/A","N/A","2","156","42","2018-04-21T10:55:00Z","2016-09-22T11:22:33Z","12583" +"*/Win7ElevateDll*",".{0,1000}\/Win7ElevateDll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","12584" +"*/WinBruteLogon*",".{0,1000}\/WinBruteLogon.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","1","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","12586" +"*/win-brute-logon*",".{0,1000}\/win\-brute\-logon.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","1","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","12587" +"*/win-brute-logon.git*",".{0,1000}\/win\-brute\-logon\.git.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","1","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","12588" +"*/WinBruteLogon.zip*",".{0,1000}\/WinBruteLogon\.zip.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","12589" +"*/windapsearch.git*",".{0,1000}\/windapsearch\.git.{0,1000}","offensive_tool_keyword","windapsearch","Python script to enumerate users - groups and computers from a Windows domain through LDAP queries","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/ropnop/windapsearch","1","1","N/A","AD Enumeration","7","9","866","154","2022-04-20T07:40:42Z","2016-08-10T21:43:30Z","12590" +"*/windapsearch.py*",".{0,1000}\/windapsearch\.py.{0,1000}","offensive_tool_keyword","smbsr","Lookup for interesting stuff in SMB shares","T1135","TA0001 - TA0007","N/A","N/A","Discovery","https://github.com/oldboy21/SMBSR","1","1","N/A","N/A","7","2","149","23","2023-06-16T14:35:30Z","2021-11-10T16:55:52Z","12591" +"*/windapsearch_*.txt*",".{0,1000}\/windapsearch_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","12592" +"*/WindDef_WebInstall.hta*",".{0,1000}\/WindDef_WebInstall\.hta.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","12593" +"*/windows/dcerpc*",".{0,1000}\/windows\/dcerpc.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","12594" +"*/windows/gather/netripper*",".{0,1000}\/windows\/gather\/netripper.{0,1000}","offensive_tool_keyword","NetRipper","NetRipper - Smart traffic sniffing for penetration testers","T1173 - T1557 - T1573.001 - T1056.001","TA0009 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/NytroRST/NetRipper","1","1","N/A","N/A","10","10","1368","318","2022-06-17T21:08:54Z","2015-07-14T20:31:04Z","12595" +"*/windows_autologin.rb*",".{0,1000}\/windows_autologin\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","12596" +"*/windows_downdate.py*",".{0,1000}\/windows_downdate\.py.{0,1000}","offensive_tool_keyword","WindowsDowndate","A tool that takes over Windows Updates to craft custom downgrades and expose past fixed vulnerabilities","T1072 - T1486 - T1505.002 - T1495 - T1499.004","TA0005 - TA0004 - TA0003 ","N/A","N/A","Defense Evasion","https://github.com/SafeBreach-Labs/WindowsDowndate","1","1","N/A","N/A","10","7","663","88","2024-10-26T10:18:49Z","2024-01-08T19:42:47Z","12597" +"*/Windows_MSKSSRV_LPE_CVE-2023-36802.git*",".{0,1000}\/Windows_MSKSSRV_LPE_CVE\-2023\-36802\.git.{0,1000}","offensive_tool_keyword","Windows_MSKSSRV_LPE_CVE-2023-36802","Complete exploit works on vulnerable Windows 11 22H2 systems CVE-2023-36802 Local Privilege Escalation POC","T1068 - T1548.001","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-36802","1","1","N/A","N/A","10","2","161","38","2023-10-10T17:44:17Z","2023-10-09T17:32:15Z","12598" +"*/windows-defender-remover.git*",".{0,1000}\/windows\-defender\-remover\.git.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","12603" +"*/windows-defender-remover/releases/download/*",".{0,1000}\/windows\-defender\-remover\/releases\/download\/.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","12604" +"*/windows-defender-remover/tarball/*",".{0,1000}\/windows\-defender\-remover\/tarball\/.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","12605" +"*/windows-defender-remover/zipball/*",".{0,1000}\/windows\-defender\-remover\/zipball\/.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","12606" +"*/WindowsDowndate.git*",".{0,1000}\/WindowsDowndate\.git.{0,1000}","offensive_tool_keyword","WindowsDowndate","A tool that takes over Windows Updates to craft custom downgrades and expose past fixed vulnerabilities","T1072 - T1486 - T1505.002 - T1495 - T1499.004","TA0005 - TA0004 - TA0003 ","N/A","N/A","Defense Evasion","https://github.com/SafeBreach-Labs/WindowsDowndate","1","1","N/A","N/A","10","7","663","88","2024-10-26T10:18:49Z","2024-01-08T19:42:47Z","12607" +"*/windows-login-phish*",".{0,1000}\/windows\-login\-phish.{0,1000}","offensive_tool_keyword","windows-login-phish","Windows Login Phishing page This is a windows maching login page designed using HTML CSS and JS. This can be used for red teaming or cybersecurity awareness related purposes","T1566","N/A","N/A","N/A","Phishing","https://github.com/CipherKill/windows-login-phish","1","1","N/A","N/A","N/A","1","17","6","2022-03-25T05:49:01Z","2022-03-13T20:02:15Z","12608" +"*/windows-lpe-template*",".{0,1000}\/windows\-lpe\-template.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","12609" +"*/Windows-Passwords.ps1*",".{0,1000}\/Windows\-Passwords\.ps1.{0,1000}","offensive_tool_keyword","WLAN-Windows-Passwords","Opens PowerShell hidden - grabs wlan passwords - saves as a cleartext in a variable and exfiltrates info via Discord Webhook.","T1056.005 - T1552.001 - T1119 - T1071.001","TA0004 - TA0006 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/WLAN-Windows-Passwords","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","12610" +"*/WindowsVault.cna*",".{0,1000}\/WindowsVault\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/guervild/BOFs","1","1","N/A","N/A","10","10","161","27","2022-05-02T16:59:24Z","2021-03-15T23:30:22Z","12612" +"*/WindowsVault.h*",".{0,1000}\/WindowsVault\.h.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/guervild/BOFs","1","1","N/A","N/A","10","10","161","27","2022-05-02T16:59:24Z","2021-03-15T23:30:22Z","12613" +"*/win-enum-resources*",".{0,1000}\/win\-enum\-resources.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","12614" +"*/winexe.git*",".{0,1000}\/winexe\.git.{0,1000}","offensive_tool_keyword","winexe","Winexe remotely executes commands on Windows systems from GNU/Linux","T1059.004 - T1021.005 - T1078.003","TA0002 - TA0008 - TA0011","N/A","APT28","Lateral Movement","https://www.kali.org/tools/winexe/","1","1","#linux #windows","N/A","8","8","N/A","N/A","N/A","N/A","12617" +"*/winexe-0.91.tar.gz*",".{0,1000}\/winexe\-0\.91\.tar\.gz.{0,1000}","offensive_tool_keyword","winexe","Winexe remotely executes commands on Windows systems from GNU/Linux","T1059.004 - T1021.005 - T1078.003","TA0002 - TA0008 - TA0011","N/A","APT28","Lateral Movement","https://www.kali.org/tools/winexe/","1","1","#linux #windows","N/A","8","8","N/A","N/A","N/A","N/A","12618" +"*/winexe-1.00.tar.gz*",".{0,1000}\/winexe\-1\.00\.tar\.gz.{0,1000}","offensive_tool_keyword","winexe","Winexe remotely executes commands on Windows systems from GNU/Linux","T1059.004 - T1021.005 - T1078.003","TA0002 - TA0008 - TA0011","N/A","APT28","Lateral Movement","https://www.kali.org/tools/winexe/","1","1","#linux #windows","N/A","8","8","N/A","N/A","N/A","N/A","12619" +"*/WINHELLO2hashcat.py*",".{0,1000}\/WINHELLO2hashcat\.py.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","1","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","12620" +"*/win-key-killer.ps1*",".{0,1000}\/win\-key\-killer\.ps1.{0,1000}","offensive_tool_keyword","Powershell-Scripts-for-Hackers-and-Pentesters","","T1059.001 - T1119 - T1027 - T1016 - T1056.001","TA0002 - TA0009 - TA0005 - TA0007 - TA0010","N/A","N/A","Collection","https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters","1","1","N/A","N/A","10","5","415","49","2025-02-23T09:05:44Z","2023-02-27T14:27:32Z","12621" +"*/winPEAS.exe*",".{0,1000}\/winPEAS\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","12622" +"*/winPEAS.exe*",".{0,1000}\/winPEAS\.exe.{0,1000}","offensive_tool_keyword","PEASS-ng","PEASS-ng - Privilege Escalation Awesome Scripts suite","T1098","TA0004 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/peass-ng/PEASS-ng","1","1","N/A","N/A","10","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","12623" +"*/winPEAS.exe*",".{0,1000}\/winPEAS\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","winPEAS","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","12624" +"*/winPEAS.exe*",".{0,1000}\/winPEAS\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","12625" +"*/winPEAS.exe*",".{0,1000}\/winPEAS\.exe.{0,1000}","offensive_tool_keyword","winPEAS","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","winPEAS","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","12626" +"*/winPEAS.ps1*",".{0,1000}\/winPEAS\.ps1.{0,1000}","offensive_tool_keyword","PEASS-ng","PEASS-ng - Privilege Escalation Awesome Scripts suite","T1098","TA0004 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/peass-ng/PEASS-ng","1","1","N/A","N/A","10","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","12627" +"*/winPEASany.exe*",".{0,1000}\/winPEASany\.exe.{0,1000}","offensive_tool_keyword","PEASS-ng","PEASS-ng - Privilege Escalation Awesome Scripts suite","T1098","TA0004 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/peass-ng/PEASS-ng","1","1","N/A","N/A","10","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","12628" +"*/winPEASany.exe*",".{0,1000}\/winPEASany\.exe.{0,1000}","offensive_tool_keyword","winPEAS","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","winPEAS","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","12629" +"*/winPEASany_ofs.exe*",".{0,1000}\/winPEASany_ofs\.exe.{0,1000}","offensive_tool_keyword","PEASS-ng","PEASS-ng - Privilege Escalation Awesome Scripts suite","T1098","TA0004 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/peass-ng/PEASS-ng","1","1","N/A","N/A","10","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","12630" +"*/winPEASany_ofs.exe*",".{0,1000}\/winPEASany_ofs\.exe.{0,1000}","offensive_tool_keyword","PEASS-ng","PEASS-ng - Privilege Escalation Awesome Scripts suite","T1098","TA0004 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/peass-ng/PEASS-ng","1","1","N/A","N/A","10","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","12631" +"*/winPEAS-Obfuscated.exe*",".{0,1000}\/winPEAS\-Obfuscated\.exe.{0,1000}","offensive_tool_keyword","PEASS-ng","PEASS-ng - Privilege Escalation Awesome Scripts suite","T1098","TA0004 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/peass-ng/PEASS-ng","1","1","N/A","N/A","10","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","12632" +"*/winPEASx64.exe*",".{0,1000}\/winPEASx64\.exe.{0,1000}","offensive_tool_keyword","PEASS-ng","PEASS-ng - Privilege Escalation Awesome Scripts suite","T1098","TA0004 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/peass-ng/PEASS-ng","1","1","N/A","N/A","10","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","12633" +"*/winPEASx86.exe*",".{0,1000}\/winPEASx86\.exe.{0,1000}","offensive_tool_keyword","PEASS-ng","PEASS-ng - Privilege Escalation Awesome Scripts suite","T1098","TA0004 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/peass-ng/PEASS-ng","1","1","N/A","N/A","10","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","12634" +"*/WinPirate.bat*",".{0,1000}\/WinPirate\.bat.{0,1000}","offensive_tool_keyword","WinPirate","automated sticky keys backdoor + credentials harvesting","T1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003","TA0003 - TA0005 - TA0006","N/A","N/A","Persistence","https://github.com/l3m0n/WinPirate","1","1","N/A","N/A","9","1","13","32","2016-07-17T20:02:07Z","2016-07-18T03:40:13Z","12635" +"*/WinPirate.git*",".{0,1000}\/WinPirate\.git.{0,1000}","offensive_tool_keyword","WinPirate","automated sticky keys backdoor + credentials harvesting","T1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003","TA0003 - TA0005 - TA0006","N/A","N/A","Persistence","https://github.com/l3m0n/WinPirate","1","1","N/A","N/A","9","1","13","32","2016-07-17T20:02:07Z","2016-07-18T03:40:13Z","12636" +"*/WinPwn*",".{0,1000}\/WinPwn.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","12637" +"*/WinPwn.git*",".{0,1000}\/WinPwn\.git.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","12638" +"*/WinPwn_Repo*",".{0,1000}\/WinPwn_Repo.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","12639" +"*/WinPwnage*",".{0,1000}\/WinPwnage.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","12640" +"*/WinPwnage.git*",".{0,1000}\/WinPwnage\.git.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12641" +"*/winpwnage.py*",".{0,1000}\/winpwnage\.py.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","12642" +"*/winregistry.py**",".{0,1000}\/winregistry\.py.{0,1000}.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","12644" +"*/winrm.cpp*",".{0,1000}\/winrm\.cpp.{0,1000}","offensive_tool_keyword","cobaltstrike","C++ WinRM API via Reflective DLL","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mez-0/winrmdll","1","1","N/A","N/A","10","10","144","28","2021-09-11T13:44:16Z","2021-09-11T13:40:22Z","12645" +"*/winrm.py*",".{0,1000}\/winrm\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","12646" +"*/winrmdll*",".{0,1000}\/winrmdll.{0,1000}","offensive_tool_keyword","cobaltstrike","C++ WinRM API via Reflective DLL","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mez-0/winrmdll","1","1","N/A","N/A","10","10","144","28","2021-09-11T13:44:16Z","2021-09-11T13:40:22Z","12647" +"*/winrm-reflective-dll/*",".{0,1000}\/winrm\-reflective\-dll\/.{0,1000}","offensive_tool_keyword","cobaltstrike","C++ WinRM API via Reflective DLL","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mez-0/winrmdll","1","1","N/A","N/A","10","10","144","28","2021-09-11T13:44:16Z","2021-09-11T13:40:22Z","12648" +"*/winscp_dump.py*",".{0,1000}\/winscp_dump\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","12649" +"*/Winsocky.git*",".{0,1000}\/Winsocky\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","Winsocket for Cobalt Strike.","T1572 - T1041 - T1105","TA0011 - TA0002 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/WKL-Sec/Winsocky","1","1","N/A","N/A","10","10","98","18","2023-07-06T11:47:18Z","2023-06-22T07:00:22Z","12650" +"*/winsos.exe*",".{0,1000}\/winsos\.exe.{0,1000}","offensive_tool_keyword","winsos-poc","A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.","T1574.002","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/thiagopeixoto/winsos-poc","1","1","N/A","N/A","10","2","111","26","2024-03-10T22:15:50Z","2024-03-10T21:35:08Z","12651" +"*/winsos-poc.git*",".{0,1000}\/winsos\-poc\.git.{0,1000}","offensive_tool_keyword","winsos-poc","A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.","T1574.002","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/thiagopeixoto/winsos-poc","1","1","N/A","N/A","10","2","111","26","2024-03-10T22:15:50Z","2024-03-10T21:35:08Z","12652" +"*/WinX Shell.php*",".{0,1000}\/WinX\sShell\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","12653" +"*/wireless.py*",".{0,1000}\/wireless\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","12658" +"*/wiresocks.git*",".{0,1000}\/wiresocks\.git.{0,1000}","offensive_tool_keyword","wiresocks","Docker-compose and Dockerfile to setup a wireguard VPN connection forcing specific TCP traffic through a socks proxy.","T1090.004 - T1572 - T1021.001","TA0011 - TA0002 - TA0040","N/A","N/A","Defense Evasion","https://github.com/sensepost/wiresocks","1","1","N/A","N/A","9","3","287","30","2024-01-19T10:58:20Z","2022-03-23T12:27:07Z","12669" +"*/WMEye.git*",".{0,1000}\/WMEye\.git.{0,1000}","offensive_tool_keyword","WMEye","WMEye is a post exploitation tool that uses WMI Event Filter and MSBuild Execution for Lateral Movement","T1047 - T1053.005 - T1124 - T1203 - T1569.002","TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/pwn1sher/WMEye","1","1","N/A","N/A","8","4","365","59","2021-12-24T05:38:50Z","2021-09-07T08:18:30Z","12690" +"*/wmeye/*",".{0,1000}\/wmeye\/.{0,1000}","offensive_tool_keyword","WMEye","WMEye is a post exploitation tool that uses WMI Event Filter and MSBuild Execution for Lateral Movement","T1047 - T1053.005 - T1124 - T1203 - T1569.002","TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/pwn1sher/WMEye","1","1","N/A","N/A","8","4","365","59","2021-12-24T05:38:50Z","2021-09-07T08:18:30Z","12691" +"*/WMI Lateral Movement/*",".{0,1000}\/WMI\sLateral\sMovement\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of beacon BOF written to learn windows and cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Yaxser/CobaltStrike-BOF","1","1","N/A","N/A","10","10","347","57","2023-02-24T13:12:14Z","2020-10-08T01:12:41Z","12692" +"*/wmi.dropper*",".{0,1000}\/wmi\.dropper.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","12693" +"*/WMI/wmi.py*",".{0,1000}\/WMI\/wmi\.py.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","12694" +"*/wmi_exec.exe*",".{0,1000}\/wmi_exec\.exe.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","12695" +"*/wmiexec.py*",".{0,1000}\/wmiexec\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","12696" +"*/wmiexec.py*",".{0,1000}\/wmiexec\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","12697" +"*/wmiexec.py*",".{0,1000}\/wmiexec\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","12698" +"*/wmiexec/*",".{0,1000}\/wmiexec\/.{0,1000}","offensive_tool_keyword","wmiexec","Set of python scripts which perform different ways of command execution via WMI protocol","T1047 - T1059 - T1070 - T1036","TA0002 - TA0008","N/A","Dispossessor - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Exploitation tool","https://github.com/WKL-Sec/wmiexec","1","1","N/A","N/A","N/A","2","159","27","2023-06-29T03:30:09Z","2023-06-21T13:15:04Z","12699" +"*/wmiexec2.git*",".{0,1000}\/wmiexec2\.git.{0,1000}","offensive_tool_keyword","wmiexec2","wmiexec2.0 is the same wmiexec that everyone knows and loves (debatable). This 2.0 version is obfuscated to avoid well known signatures from various AV engines.","T1021.005 - T1047 - T1059.001 - T1059.003 - T1059.005","TA0008 - TA0002 - TA0011","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/ice-wzl/wmiexec2","1","1","N/A","N/A","9","1","34","1","2024-06-12T17:56:15Z","2023-02-07T22:10:08Z","12700" +"*/wmiexec-Pro*",".{0,1000}\/wmiexec\-Pro.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","12701" +"*/wmiexec-Pro.git*",".{0,1000}\/wmiexec\-Pro\.git.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","12702" +"*/WMIHACKER.git*",".{0,1000}\/WMIHACKER\.git.{0,1000}","offensive_tool_keyword","WMIHACKER","Bypass anti-virus software lateral movement command execution test tool - No need 445 Port","T1047 - T1569.002 - T1218 - T1036.005","TA0008 - TA0002 - TA0005","N/A","N/A","Lateral Movement","https://github.com/rootclay/WMIHACKER","1","1","N/A","N/A","9","10","1423","236","2025-01-20T15:37:28Z","2020-07-02T06:57:25Z","12703" +"*/WMIHACKER.vbs*",".{0,1000}\/WMIHACKER\.vbs.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","12704" +"*/WMIHACKER.vbs*",".{0,1000}\/WMIHACKER\.vbs.{0,1000}","offensive_tool_keyword","WMIHACKER","Bypass anti-virus software lateral movement command execution test tool - No need 445 Port","T1047 - T1569.002 - T1218 - T1036.005","TA0008 - TA0002 - TA0005","N/A","N/A","Lateral Movement","https://github.com/rootclay/WMIHACKER","1","1","N/A","N/A","9","10","1423","236","2025-01-20T15:37:28Z","2020-07-02T06:57:25Z","12705" +"*/wmipersist.exe*",".{0,1000}\/wmipersist\.exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","12706" +"*/wmipersist.py*",".{0,1000}\/wmipersist\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","12707" +"*/WMIPersistence.git*",".{0,1000}\/WMIPersistence\.git.{0,1000}","offensive_tool_keyword","WMIPersistence","An example of how to perform WMI Event Subscription persistence using C#","T1547.008 - T1084 - T1053 - T1059.003","TA0003 - TA0004 - TA0002","N/A","N/A","Persistence","https://github.com/mdsecactivebreach/WMIPersistence","1","1","N/A","N/A","N/A","2","113","30","2019-05-29T09:48:46Z","2019-05-29T09:40:01Z","12708" +"*/wmiquery.py*",".{0,1000}\/wmiquery\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","12709" +"*/WMIReg.exe*",".{0,1000}\/WMIReg\.exe.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","12710" +"*/WMIReg.exe*",".{0,1000}\/WMIReg\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","12711" +"*/wmisploit*",".{0,1000}\/wmisploit.{0,1000}","offensive_tool_keyword","Wmisploit","WmiSploit is a small set of PowerShell scripts that leverage the WMI service for post-exploitation use.","T1087 - T1059.001 - T1047","TA0003 - TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/secabstraction/WmiSploit","1","1","N/A","N/A","N/A","2","164","34","2015-08-28T23:56:00Z","2015-03-15T03:30:02Z","12712" +"*/wordlists/owa_directories.txt*",".{0,1000}\/wordlists\/owa_directories\.txt.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","12720" +"*/wordlists/skype-directories.txt*",".{0,1000}\/wordlists\/skype\-directories\.txt.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","12721" +"*/wordlists/top_10000.txt*",".{0,1000}\/wordlists\/top_10000\.txt.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","12722" +"*/wordlists/top_100000.txt*",".{0,1000}\/wordlists\/top_100000\.txt.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","12723" +"*/workflow/test/dirbscan.yaml*",".{0,1000}\/workflow\/test\/dirbscan\.yaml.{0,1000}","offensive_tool_keyword","Osmedeus","Osmedeus - A Workflow Engine for Offensive Security","T1595","TA0043","N/A","N/A","Exploitation tool","https://github.com/j3ssie/osmedeus","1","1","N/A","N/A","N/A","10","5566","907","2025-04-22T14:57:07Z","2018-11-10T04:17:18Z","12725" +"*/Worm.dll*",".{0,1000}\/Worm\.dll.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","12726" +"*/worm/inject.ps1*",".{0,1000}\/worm\/inject\.ps1.{0,1000}","offensive_tool_keyword","Kematian Stealer","Fake WinRar site distributes malware (+stealer +miner +hvnc +ransomware) from GitHub","T1195 - T1566 - T1569 - T1106 - T1486 - T1113","TA0001 - TA0002 - TA0005 - TA0006 - TA0007 - TA0009 - TA0010 - TA0011 - TA0040 - TA0043","N/A","N/A","Malware","https://github[.]com/sap3r-encrypthub/encrypthub","1","1","N/A","N/A","10","7","N/A","N/A","N/A","N/A","12727" +"*/Worse Linux Shell.php*",".{0,1000}\/Worse\sLinux\sShell\.php.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","#linux","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","12728" +"*/wpscan.py*",".{0,1000}\/wpscan\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","12730" +"*/wraith.git*",".{0,1000}\/wraith\.git.{0,1000}","offensive_tool_keyword","wraith","A free and open-source, modular Remote Administration Tool (RAT) / Payload Dropper written in Go(lang) with a flexible command and control (C2) system.","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/wraith-labs/wraith","1","1","N/A","N/A","10","10","223","49","2023-12-03T22:16:27Z","2020-01-23T17:09:23Z","12731" +"*/wraith.py*",".{0,1000}\/wraith\.py.{0,1000}","offensive_tool_keyword","wraith","A free and open-source, modular Remote Administration Tool (RAT) / Payload Dropper written in Go(lang) with a flexible command and control (C2) system.","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/wraith-labs/wraith","1","1","N/A","N/A","10","10","223","49","2023-12-03T22:16:27Z","2020-01-23T17:09:23Z","12732" +"*/wraith-master.zip*",".{0,1000}\/wraith\-master\.zip.{0,1000}","offensive_tool_keyword","wraith","A free and open-source, modular Remote Administration Tool (RAT) / Payload Dropper written in Go(lang) with a flexible command and control (C2) system.","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/wraith-labs/wraith","1","1","N/A","N/A","10","10","223","49","2023-12-03T22:16:27Z","2020-01-23T17:09:23Z","12733" +"*/wraith-RAT-payloads*",".{0,1000}\/wraith\-RAT\-payloads.{0,1000}","offensive_tool_keyword","wraith","A free and open-source, modular Remote Administration Tool (RAT) / Payload Dropper written in Go(lang) with a flexible command and control (C2) system.","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/wraith-labs/wraith","1","1","N/A","N/A","10","10","223","49","2023-12-03T22:16:27Z","2020-01-23T17:09:23Z","12734" +"*/wraith-RAT-payloads.git*",".{0,1000}\/wraith\-RAT\-payloads\.git.{0,1000}","offensive_tool_keyword","wraith","A free and open-source, modular Remote Administration Tool (RAT) / Payload Dropper written in Go(lang) with a flexible command and control (C2) system.","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/wraith-labs/wraith","1","1","N/A","N/A","10","10","223","49","2023-12-03T22:16:27Z","2020-01-23T17:09:23Z","12735" +"*/wraith-server.py*",".{0,1000}\/wraith\-server\.py.{0,1000}","offensive_tool_keyword","wraith","A free and open-source, modular Remote Administration Tool (RAT) / Payload Dropper written in Go(lang) with a flexible command and control (C2) system.","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/wraith-labs/wraith","1","1","N/A","N/A","10","10","223","49","2023-12-03T22:16:27Z","2020-01-23T17:09:23Z","12736" +"*/wraith-server_v*.py*",".{0,1000}\/wraith\-server_v.{0,1000}\.py.{0,1000}","offensive_tool_keyword","wraith","A free and open-source, modular Remote Administration Tool (RAT) / Payload Dropper written in Go(lang) with a flexible command and control (C2) system.","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/wraith-labs/wraith","1","1","N/A","N/A","10","10","223","49","2023-12-03T22:16:27Z","2020-01-23T17:09:23Z","12737" +"*/WSAAcceptBackdoor.git*",".{0,1000}\/WSAAcceptBackdoor\.git.{0,1000}","offensive_tool_keyword","WSAAcceptBackdoor","Winsock accept() Backdoor Implant","T1574.001 - T1059 - T1213 - T1105 - T1546","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/EgeBalci/WSAAcceptBackdoor","1","1","N/A","N/A","10","2","112","23","2021-02-13T19:18:41Z","2021-02-13T15:59:01Z","12738" +"*/wsdd-discover.nse*",".{0,1000}\/wsdd\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12739" +"*/ws-dirs.txt*",".{0,1000}\/ws\-dirs\.txt.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","12740" +"*/ws-files.txt*",".{0,1000}\/ws\-files\.txt.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","12741" +"*/WSMan-WinRM.git*",".{0,1000}\/WSMan\-WinRM\.git.{0,1000}","offensive_tool_keyword","WSMan-WinRM","remote commands over WinRM using the WSMan.Automation COM object","T1021.004 - T1059.001","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/bohops/WSMan-WinRM","1","1","N/A","N/A","10","3","236","40","2020-05-12T16:49:01Z","2020-05-12T01:30:42Z","12742" +"*/WSManWinRM.ps1*",".{0,1000}\/WSManWinRM\.ps1.{0,1000}","offensive_tool_keyword","WSMan-WinRM","remote commands over WinRM using the WSMan.Automation COM object","T1021.004 - T1059.001","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/bohops/WSMan-WinRM","1","1","N/A","N/A","10","3","236","40","2020-05-12T16:49:01Z","2020-05-12T01:30:42Z","12743" +"*/wso-webshell.git*",".{0,1000}\/wso\-webshell\.git.{0,1000}","offensive_tool_keyword","wso-webshell","wso php webshell","T1100 - T1027 - T1059","TA0003 - TA0007","N/A","EMBER BEAR - Sandworm","Persistence","https://github.com/mIcHyAmRaNe/wso-webshell","1","1","N/A","N/A","10","4","376","211","2024-07-08T04:54:36Z","2017-05-04T23:34:02Z","12744" +"*/wstunnel.exe",".{0,1000}\/wstunnel\.exe","offensive_tool_keyword","wstunnel","Tunnel all your traffic over websocket protocol - Bypass firewalls/DPI - Static binary available","T1572 - T1090 - T1071","TA0005- TA0010 - TA0011","N/A","Scattered Spider*","Data Exfiltration","https://github.com/erebe/wstunnel","1","1","N/A","N/A","10","10","4759","404","2025-04-15T11:07:11Z","2016-05-14T23:58:43Z","12747" +"*/wstunnel.git*",".{0,1000}\/wstunnel\.git.{0,1000}","offensive_tool_keyword","wstunnel","Tunnel all your traffic over websocket protocol - Bypass firewalls/DPI - Static binary available","T1572 - T1090 - T1071","TA0005- TA0010 - TA0011","N/A","Scattered Spider*","Data Exfiltration","https://github.com/erebe/wstunnel","1","1","N/A","N/A","10","10","4759","404","2025-04-15T11:07:11Z","2016-05-14T23:58:43Z","12748" +"*/wstunnel:latest*",".{0,1000}\/wstunnel\:latest.{0,1000}","offensive_tool_keyword","wstunnel","Tunnel all your traffic over websocket protocol - Bypass firewalls/DPI - Static binary available","T1572 - T1090 - T1071","TA0005- TA0010 - TA0011","N/A","Scattered Spider*","Data Exfiltration","https://github.com/erebe/wstunnel","1","1","N/A","N/A","10","10","4759","404","2025-04-15T11:07:11Z","2016-05-14T23:58:43Z","12750" +"*/wwlib/lolbins/*",".{0,1000}\/wwlib\/lolbins\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike payload generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dr0op/CrossNet-Beta","1","1","N/A","N/A","10","10","362","58","2024-06-19T07:02:22Z","2021-02-08T10:52:39Z","12751" +"*/www/exploit.html*",".{0,1000}\/www\/exploit\.html.{0,1000}","offensive_tool_keyword","POC","Just another PoC for the new MSDT-Exploit","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/komomon/CVE-2022-30190-follina-Office-MSDT-Fixed","1","1","N/A","N/A","N/A","4","396","54","2023-04-13T16:46:26Z","2022-06-02T12:33:18Z","12752" +"*/x11-access.nse*",".{0,1000}\/x11\-access\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12753" +"*/x64/meterpreter/reverse_tcp_rc4*",".{0,1000}\/x64\/meterpreter\/reverse_tcp_rc4.{0,1000}","offensive_tool_keyword","metasploit","exploit used by Dispossessor ransomware group","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Dispossessor","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","12754" +"*/x64/Stardust.asm*",".{0,1000}\/x64\/Stardust\.asm.{0,1000}","offensive_tool_keyword","Stardust","An modern 64-bit position independent implant template","T1055 - T1105 - T1055.012 - T1027 - T1218","TA0005 - TA0003 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/Stardust","1","1","N/A","N/A","10","10","1193","193","2025-03-21T11:41:09Z","2022-02-20T01:23:35Z","12755" +"*/x64_slim.dll*",".{0,1000}\/x64_slim\.dll.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1110","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","12756" +"*/xan7r/kerberoast*",".{0,1000}\/xan7r\/kerberoast.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/xan7r/kerberoast","1","1","N/A","N/A","N/A","1","73","18","2017-07-22T22:28:12Z","2016-06-08T22:58:45Z","12759" +"*/xar-1.5.2.tar.gz*",".{0,1000}\/xar\-1\.5\.2\.tar\.gz.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1111","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","12760" +"*/xdmcp-discover.nse*",".{0,1000}\/xdmcp\-discover\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12761" +"*/xen-mimi.ps1*",".{0,1000}\/xen\-mimi\.ps1.{0,1000}","offensive_tool_keyword","cobaltstrike","Erebus CobaltStrike post penetration testing plugin","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DeEpinGh0st/Erebus","1","1","N/A","N/A","10","10","1518","221","2021-10-28T06:20:51Z","2019-09-26T09:32:00Z","12762" +"*/xeno-rat.git*",".{0,1000}\/xeno\-rat\.git.{0,1000}","offensive_tool_keyword","xeno-rat","Xeno-RAT is an open-source remote access tool (RAT) developed in C# providing a comprehensive set of features for remote system management. Has features such as HVNC - live microphone - reverse proxy and much much more","T1133 - T1021.001 - T1563.002 - T1113 - T1123 - T1571 - T1090","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011","N/A","N/A","C2","https://github.com/moom825/xeno-rat","1","1","N/A","N/A","10","10","1225","323","2024-03-05T06:22:36Z","2023-10-17T06:41:56Z","12763" +"*/XHVNC.exe*",".{0,1000}\/XHVNC\.exe.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","12764" +"*/XiebroC2.git*",".{0,1000}\/XiebroC2\.git.{0,1000}","offensive_tool_keyword","XiebroC2","Command and control server - multi-person collaborative penetration testing graphical framework","T1105 - T1573.001 - T1055.001 - T1071 - T1041 - T1059.001 - T1059.008 - T1102","TA0011 - TA0003 - TA0005 - TA0007 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/INotGreen/XiebroC2","1","1","N/A","N/A","10","10","1200","192","2025-02-28T09:44:43Z","2024-02-15T15:46:07Z","12765" +"*/XiebroC2/releases/download/*",".{0,1000}\/XiebroC2\/releases\/download\/.{0,1000}","offensive_tool_keyword","XiebroC2","Command and control server - multi-person collaborative penetration testing graphical framework","T1105 - T1573.001 - T1055.001 - T1071 - T1041 - T1059.001 - T1059.008 - T1102","TA0011 - TA0003 - TA0005 - TA0007 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/INotGreen/XiebroC2","1","1","N/A","N/A","10","10","1200","192","2025-02-28T09:44:43Z","2024-02-15T15:46:07Z","12766" +"*/xml_attack.txt*",".{0,1000}\/xml_attack\.txt.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","12767" +"*/xml_attacks.txt*",".{0,1000}\/xml_attacks\.txt.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","12768" +"*/xmlrpc-methods.nse*",".{0,1000}\/xmlrpc\-methods\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12769" +"*/xmpp-brute.nse*",".{0,1000}\/xmpp\-brute\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12770" +"*/xmpp-info.nse*",".{0,1000}\/xmpp\-info\.nse.{0,1000}","offensive_tool_keyword","nmap","Nmap NSE Scripts. Nmap Network Mapper is a free and open source utility for network discovery and security auditing","T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007","TA0001 - TA0007 - TA0043","N/A","Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta","Vulnerability Scanner","https://svn.nmap.org/nmap/scripts/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12771" +"*/xndpxs/CVE-2022-0847*",".{0,1000}\/xndpxs\/CVE\-2022\-0847.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/xndpxs/CVE-2022-0847","1","1","N/A","N/A","N/A","1","9","7","2022-03-07T17:59:12Z","2022-03-07T17:51:02Z","12775" +"*/xor/stager.txt*",".{0,1000}\/xor\/stager\.txt.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Shellcode Loader by Golang","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/timwhitez/Doge-Loader","1","1","N/A","N/A","10","10","280","57","2021-04-22T08:24:59Z","2020-10-09T04:47:54Z","12776" +"*/xor/xor.go*",".{0,1000}\/xor\/xor\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Shellcode Loader by Golang","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/timwhitez/Doge-Loader","1","1","N/A","N/A","10","10","280","57","2021-04-22T08:24:59Z","2020-10-09T04:47:54Z","12777" +"*/XOR_b64_encrypted/*",".{0,1000}\/XOR_b64_encrypted\/.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","12778" +"*/XorObfuscation.cs*",".{0,1000}\/XorObfuscation\.cs.{0,1000}","offensive_tool_keyword","Macrome","An Excel Macro Document Reader/Writer for Red Teamers & Analysts. Blog posts describing what this tool actually does can be found https://malware.pizza/2020/05/12/evading-av-with-excel-macros-and-biff8-xls/ and https://malware.pizza/2020/06/19/further-evasion-in-the-forgotten-corners-of-ms-xls/","T1140","TA0005","N/A","N/A","Exploitation tool","https://github.com/michaelweber/Macrome","1","1","N/A","N/A","N/A","6","520","79","2022-02-01T16:26:13Z","2020-05-07T22:44:11Z","12779" +"*/xpath_injection.txt*",".{0,1000}\/xpath_injection\.txt.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","12780" +"*/XpertRAT.exe*",".{0,1000}\/XpertRAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","12781" +"*/xPipe/*",".{0,1000}\/xPipe\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF to list Windows Pipes & return their Owners & DACL Permissions","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/xPipe","1","1","N/A","N/A","10","10","77","23","2023-03-08T15:51:47Z","2021-12-07T22:56:30Z","12782" +"*/xRAT 2.exe*",".{0,1000}\/xRAT\s2\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","12783" +"*/xrat-master/*",".{0,1000}\/xrat\-master\/.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","12784" +"*/XRulez binaries.zip*",".{0,1000}\/XRulez\sbinaries\.zip.{0,1000}","offensive_tool_keyword","Xrulez","XRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.","T1078 - T1105 - T1059 - T1566","TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Persistence","https://github.com/FSecureLABS/Xrulez","1","1","N/A","N/A","10","2","162","45","2018-12-11T16:33:08Z","2016-08-31T10:10:10Z","12785" +"*/XRulez.exe*",".{0,1000}\/XRulez\.exe.{0,1000}","offensive_tool_keyword","Xrulez","XRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.","T1078 - T1105 - T1059 - T1566","TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Persistence","https://github.com/FSecureLABS/Xrulez","1","1","N/A","N/A","10","2","162","45","2018-12-11T16:33:08Z","2016-08-31T10:10:10Z","12786" +"*/XRulez.zip*",".{0,1000}\/XRulez\.zip.{0,1000}","offensive_tool_keyword","Xrulez","XRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.","T1078 - T1105 - T1059 - T1566","TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Persistence","https://github.com/FSecureLABS/Xrulez","1","1","N/A","N/A","10","2","162","45","2018-12-11T16:33:08Z","2016-08-31T10:10:10Z","12787" +"*/xss_robertux.txt*",".{0,1000}\/xss_robertux\.txt.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","12788" +"*/XtremeRat.exe*",".{0,1000}\/XtremeRat\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","Molerats - Packrat - TA558","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","12789" +"*/XWorm.exe*",".{0,1000}\/XWorm\.exe.{0,1000}","offensive_tool_keyword","Rhadamanthys","Fake Xworm - Rhadamanthys infostealer","T1583 - T1110 - T1082 - T1505 - T1567 - T1573","TA0006 - TA0003 - TA0004 - TA0005 - TA0009","N/A","N/A","Malware","https://github.com/koyaxZ/XWorm-v5-Remote-Access-Tool","1","1","N/A","N/A","10","","N/A","","","","12790" +"*/XWorm.exe*",".{0,1000}\/XWorm\.exe.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","12791" +"*/XWorm.zip*",".{0,1000}\/XWorm\.zip.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","12793" +"*/XWorm-RAT-V*",".{0,1000}\/XWorm\-RAT\-V.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","12794" +"*/xxe_fuzz.txt*",".{0,1000}\/xxe_fuzz\.txt.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","12795" +"*/yanghaoi/_CNA*",".{0,1000}\/yanghaoi\/_CNA.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","12799" +"*/ysoserial/*",".{0,1000}\/ysoserial\/.{0,1000}","offensive_tool_keyword","ysoserial.net","Deserialization payload generator for a variety of .NET formatters","T1059.007 - T1027.002 - T1059.001","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/pwntester/ysoserial.net","1","1","N/A","N/A","10","10","3385","493","2024-12-23T20:59:47Z","2017-09-18T17:48:08Z","12801" +"*/zejius/2HZG41Zw/6Vtmo6w4yQ5tnsBHms64.php*",".{0,1000}\/zejius\/2HZG41Zw\/6Vtmo6w4yQ5tnsBHms64\.php.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","12806" +"*/zejius/2HZG41Zw/fJsnC6G4sFg2wsyn4shb.bin*",".{0,1000}\/zejius\/2HZG41Zw\/fJsnC6G4sFg2wsyn4shb\.bin.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","12807" +"*/zejius/5GPR0iy9/6Vtmo6w4yQ5tnsBHms64.php*",".{0,1000}\/zejius\/5GPR0iy9\/6Vtmo6w4yQ5tnsBHms64\.php.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","12808" +"*/zejius/5GPR0iy9/fJsnC6G4sFg2wsyn4shb.bin*",".{0,1000}\/zejius\/5GPR0iy9\/fJsnC6G4sFg2wsyn4shb\.bin.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","12809" +"*/ZeroHVCI.exe*",".{0,1000}\/ZeroHVCI\.exe.{0,1000}","offensive_tool_keyword","ZeroHVCI","Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229","T1068 - T1564 - T1014 - T1499","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/zer0condition/ZeroHVCI","1","1","N/A","N/A","7","2","198","43","2024-10-26T17:08:38Z","2024-07-20T07:29:18Z","12810" +"*/ZeroHVCI.git*",".{0,1000}\/ZeroHVCI\.git.{0,1000}","offensive_tool_keyword","ZeroHVCI","Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229","T1068 - T1564 - T1014 - T1499","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/zer0condition/ZeroHVCI","1","1","N/A","N/A","7","2","198","43","2024-10-26T17:08:38Z","2024-07-20T07:29:18Z","12811" +"*/zerologon.cna*",".{0,1000}\/zerologon\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF zerologon exploit","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/ZeroLogon-BOF","1","1","N/A","N/A","10","10","158","37","2022-04-25T11:22:45Z","2020-09-17T02:07:13Z","12812" +"*/zerologon.py*",".{0,1000}\/zerologon\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","12813" +"*/zerologon.py*",".{0,1000}\/zerologon\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","12814" +"*/ZipExec.git*",".{0,1000}\/ZipExec\.git.{0,1000}","offensive_tool_keyword","ZipExec","A unique technique to execute binaries from a password protected zip","T1560.001 - T1204.002 - T1059.005","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Tylous/ZipExec","1","1","N/A","N/A","9","10","1026","153","2022-07-01T16:25:26Z","2021-10-19T21:03:44Z","12817" +"*/ZipExec@latest*",".{0,1000}\/ZipExec\@latest.{0,1000}","offensive_tool_keyword","ZipExec","A unique technique to execute binaries from a password protected zip","T1560.001 - T1204.002 - T1059.005","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Tylous/ZipExec","1","1","N/A","N/A","9","10","1026","153","2022-07-01T16:25:26Z","2021-10-19T21:03:44Z","12818" +"*/zsh_executor/*.go*",".{0,1000}\/zsh_executor\/.{0,1000}\.go.{0,1000}","offensive_tool_keyword","mythic","mythic C2 agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/freyja/","1","1","N/A","N/A","10","10","54","13","2024-10-29T17:32:07Z","2022-09-28T17:20:04Z","12828" +"*/zwjjustdoit/cve-2022-23131*",".{0,1000}\/zwjjustdoit\/cve\-2022\-23131.{0,1000}","offensive_tool_keyword","POC","POC exploitaiton of zabbix saml bypass exp vulnerability cve-2022-23131 (Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML)","T1548 - T1190","TA0002 - TA0006 - TA0009","N/A","N/A","Exploitation tool","https://github.com/zwjjustdoit/cve-2022-23131","1","1","N/A","N/A","N/A","1","1","4","2022-02-21T04:55:57Z","2022-02-21T02:42:23Z","12829" +"*/zzz_exploit.py*",".{0,1000}\/zzz_exploit\.py.{0,1000}","offensive_tool_keyword","AutoBlue-MS17-010","automated exploit code for MS17-010","T1210 - T1040 - T1059.001","TA0001 - TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/3ndG4me/AutoBlue-MS17-010","1","1","N/A","N/A","6","10","1240","317","2023-12-24T19:22:26Z","2017-11-25T09:03:38Z","12830" +"*:8080/yara/file*",".{0,1000}\:8080\/yara\/file.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","12864" +"*:8999/Payloads/*",".{0,1000}\:8999\/Payloads\/.{0,1000}","offensive_tool_keyword","primusC2","another C2 framework","T1090 - T1071","TA0011 - TA0002","N/A","N/A","C2","https://github.com/Primusinterp/PrimusC2","1","1","N/A","N/A","10","10","55","4","2024-11-01T00:20:02Z","2023-04-19T10:59:30Z","12865" +"*:9090*/api/v1.0/relays*",".{0,1000}\:9090.{0,1000}\/api\/v1\.0\/relays.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","12867" +"*@evilmail.to*",".{0,1000}\@evilmail\.to.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","12879" +"*@WanaDecryptor@.exe*",".{0,1000}\@WanaDecryptor\@\.exe.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","12887" +"*\elusiveMice.cna*",".{0,1000}\\elusiveMice\.cna.{0,1000}","offensive_tool_keyword","ElusiveMice","Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind","T1620 - T1055.012 - T1202","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/mgeeky/ElusiveMice","1","1","N/A","N/A","10","5","449","78","2023-07-12T17:54:07Z","2021-08-27T19:22:20Z","15262" +"*_backdoor.exe*",".{0,1000}_backdoor\.exe.{0,1000}","offensive_tool_keyword","frampton","PE Binary Shellcode Injector - Automated code cave discovery. shellcode injection - ASLR bypass - x86/x64 compatible","T1055 - T1548.002 - T1129 - T1001","TA0002 - TA0003- TA0004 -TA0011","N/A","N/A","Exploitation tool","https://github.com/ins1gn1a/Frampton","1","1","N/A","N/A","N/A","1","75","19","2019-11-24T22:34:48Z","2019-10-29T00:22:14Z","20109" +"*_backdoor.rb*",".{0,1000}_backdoor\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","20110" +"*_BloodHound.zip*",".{0,1000}_BloodHound\.zip.{0,1000}","offensive_tool_keyword","BloodHound","BloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound","1","1","N/A","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","20111" +"*_cobaltstrike*",".{0,1000}_cobaltstrike.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","20113" +"*_dcsync.txt*",".{0,1000}_dcsync\.txt.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","20114" +"*_dns_hijack/*.js*",".{0,1000}_dns_hijack\/.{0,1000}\.js.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","20117" +"*_dns_hijack/*.rb*",".{0,1000}_dns_hijack\/.{0,1000}\.rb.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","20118" +"*_dump_users.lst*",".{0,1000}_dump_users\.lst.{0,1000}","offensive_tool_keyword","ldeep","In-depth ldap enumeration utility","T1087.002 - T1018 - T1482 - T1083","TA0007 - TA0008 - TA0009","N/A","N/A","Reconnaissance","https://github.com/franc-pentest/ldeep","1","1","N/A","N/A","5","5","465","54","2025-03-02T18:43:27Z","2018-10-22T18:21:44Z","20120" +"*_execve_binsh.s*",".{0,1000}_execve_binsh\.s.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","20124" +"*_find_sharpgen_dll*",".{0,1000}_find_sharpgen_dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","20125" +"*_generate_bind_payloads_password*",".{0,1000}_generate_bind_payloads_password.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","20126" +"*_generate_scramblesuit_passwd*",".{0,1000}_generate_scramblesuit_passwd.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","20127" +"*_GetNetLoggedon.py*",".{0,1000}_GetNetLoggedon\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","20128" +"*_impacket*.tar.gz*",".{0,1000}_impacket.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","20131" +"*_lfi_rce.rb*",".{0,1000}_lfi_rce\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","20136" +"*_lsass.txt*",".{0,1000}_lsass\.txt.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","20137" +"*_lsassdecrypt.py*",".{0,1000}_lsassdecrypt\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","20138" +"*_mouse_rce.rb*",".{0,1000}_mouse_rce\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","20141" +"*_msfconsole*",".{0,1000}_msfconsole.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","20142" +"*_msfvenom*",".{0,1000}_msfvenom.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","20143" +"*_nimplant_*",".{0,1000}_nimplant_.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","20145" +"*_peloader.dll*",".{0,1000}_peloader\.dll.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","20147" +"*_posh-common*",".{0,1000}_posh\-common.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","20148" +"*_prefix_PEzor_*",".{0,1000}_prefix_PEzor_.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","20156" +"*_pycobalt_*",".{0,1000}_pycobalt_.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","20164" +"*_REFLECTIVEDLLINJECTION_REFLECTIVEDLLINJECTION_H*",".{0,1000}_REFLECTIVEDLLINJECTION_REFLECTIVEDLLINJECTION_H.{0,1000}","offensive_tool_keyword","Recon-AD","AD recon tool based on ADSI and reflective DLL","T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","8","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","20167" +"*>S4uDelegator<*",".{0,1000}\>S4uDelegator\<.{0,1000}","offensive_tool_keyword","PrivFu","perform S4U logon with SeTcbPrivilege","T1134","TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","S4uDelegator","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","20511" +"*0.0.0.0:53531*",".{0,1000}0\.0\.0\.0\:53531.{0,1000}","offensive_tool_keyword","dnscat","This tool is designed to create an encrypted command-and-control (C&C) channel over the DNS protocol","T1071.004 - T1102 - T1071.001","TA0002 - TA0003 - TA0008","N/A","EMBER BEAR","C2","https://github.com/iagox86/dnscat2","1","1","N/A","N/A","10","10","3566","618","2024-03-14T11:17:49Z","2013-01-04T23:15:55Z","20632" +"*0_evil.com_4444.exe*",".{0,1000}0_evil\.com_4444\.exe.{0,1000}","offensive_tool_keyword","TinyMet","meterpreter stager","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","CL0P - FIN7 - FIN11 - Silence group - GOLD EVERGREEN","C2","https://github.com/SherifEldeeb/TinyMet","1","1","N/A","N/A","10","10","128","43","2019-08-20T04:39:22Z","2014-05-17T13:31:55Z","20633" +"*00_create_all_modules_test*",".{0,1000}00_create_all_modules_test.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","20636" +"*01_all_exploits_have_payloads_test*",".{0,1000}01_all_exploits_have_payloads_test.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","20709" +"*0d1n*kill_listener.sh*",".{0,1000}0d1n.{0,1000}kill_listener\.sh.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","21607" +"*0dayCTF/reverse-shell-generator*",".{0,1000}0dayCTF\/reverse\-shell\-generator.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","21642" +"*0evilpwfilter*",".{0,1000}0evilpwfilter.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","21747" +"*0evilpwfilter.dll*",".{0,1000}0evilpwfilter\.dll.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","21748" +"*0evilpwfilter.dll*",".{0,1000}0evilpwfilter\.dll.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","21749" +"*0vercl0k/udmp-parser*",".{0,1000}0vercl0k\/udmp\-parser.{0,1000}","offensive_tool_keyword","udmp-parser","A Cross-Platform C++ parser library for Windows user minidumps.","T1005 - T1059.003 - T1027.002","TA0009 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/0vercl0k/udmp-parser","1","1","N/A","N/A","6","3","202","23","2024-11-20T15:58:21Z","2022-01-30T18:56:21Z","21826" +"*0x00G/NiceRAT*",".{0,1000}0x00G\/NiceRAT.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","1","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","21827" +"*0x09AL/DNS-Persist*",".{0,1000}0x09AL\/DNS\-Persist.{0,1000}","offensive_tool_keyword","DNS-Persist","DNS-Persist is a post-exploitation agent which uses DNS for command and control.","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/0x09AL/DNS-Persist","1","1","N/A","N/A","10","10","211","65","2017-11-20T08:53:25Z","2017-11-10T15:23:49Z","21828" +"*0x09AL/IIS-Raid*",".{0,1000}0x09AL\/IIS\-Raid.{0,1000}","offensive_tool_keyword","IIS-Raid","A native backdoor module for Microsoft IIS","T1505.003 - T1059.001 - T1071.001","TA0002 - TA0011","N/A","N/A","C2","https://github.com/0x09AL/IIS-Raid","1","1","N/A","N/A","10","10","541","124","2020-07-03T13:31:42Z","2020-02-17T16:28:10Z","21829" +"*0x09AL/RdpThief*",".{0,1000}0x09AL\/RdpThief.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","1","N/A","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","21830" +"*0x4xel/Bat-Potato*",".{0,1000}0x4xel\/Bat\-Potato.{0,1000}","offensive_tool_keyword","Bat-Potato","Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers","T1055.012 - T1068 - T1548.002 - T1505.003","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/0x4xel/Bat-Potato","1","1","N/A","N/A","10","1","42","11","2022-12-13T20:19:51Z","2022-12-12T20:50:22Z","21833" +"*0x727/MetasploitCoop_0x727*",".{0,1000}0x727\/MetasploitCoop_0x727.{0,1000}","offensive_tool_keyword","MetasploitCoop","Post-exploitation collaboration platform based on MSF","T1105 - T1098 - T1104 - T1136","TA0010 - TA0011 - TA0008","N/A","N/A","C2","https://github.com/0x727/MetasploitCoop_0x727","1","1","N/A","N/A","10","10","217","38","2021-08-17T15:24:50Z","2021-08-17T10:37:44Z","21834" +"*0x727/MetasploitCoop-Backend*",".{0,1000}0x727\/MetasploitCoop\-Backend.{0,1000}","offensive_tool_keyword","MetasploitCoop","Post-exploitation collaboration platform based on MSF","T1105 - T1098 - T1104 - T1136","TA0010 - TA0011 - TA0008","N/A","N/A","C2","https://github.com/0x727/MetasploitCoop-Backend","1","1","N/A","N/A","10","10","37","8","2021-08-17T10:26:17Z","2021-08-17T07:52:12Z","21835" +"*0x727/MetasploitCoop-Frontend*",".{0,1000}0x727\/MetasploitCoop\-Frontend.{0,1000}","offensive_tool_keyword","MetasploitCoop","Post-exploitation collaboration platform based on MSF","T1105 - T1098 - T1104 - T1136","TA0010 - TA0011 - TA0008","N/A","N/A","C2","https://github.com/0x727/MetasploitCoop-Frontend","1","1","N/A","N/A","10","10","20","7","2024-04-03T14:49:19Z","2021-08-17T10:36:52Z","21836" +"*0x727/SchTask_0x727*",".{0,1000}0x727\/SchTask_0x727.{0,1000}","offensive_tool_keyword","SchTask_0x727","create hidden scheduled tasks","T1053","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/0x727/SchTask_0x727","1","1","N/A","N/A","10","6","532","112","2021-09-01T01:34:51Z","2021-08-30T03:29:34Z","21837" +"*0xB455/m365-fatigue*",".{0,1000}0xB455\/m365\-fatigue.{0,1000}","offensive_tool_keyword","m365-fatigue","automates the authentication process for Microsoft 365 by using the device code flow and Selenium for automated login. It keeps bombing the user with MFA requests and stores the access_token once the MFA was approved.","T1110.001 - T1078.001 - T1556.004","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/0xB455/m365-fatigue","1","1","N/A","N/A","10","1","77","7","2024-04-08T14:53:44Z","2023-11-30T13:33:03Z","21840" +"*0xbadjuju/Tokenvator*",".{0,1000}0xbadjuju\/Tokenvator.{0,1000}","offensive_tool_keyword","Tokenvator","A tool to elevate privilege with Windows Tokens","T1134 - T1078","TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/0xbadjuju/Tokenvator","1","1","N/A","N/A","N/A","10","1038","201","2023-10-06T13:17:05Z","2017-12-08T01:29:11Z","21841" +"*0xbadjuju/WheresMyImplant*",".{0,1000}0xbadjuju\/WheresMyImplant.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","21842" +"*0xbdg/hidden-tear-remake*",".{0,1000}0xbdg\/hidden\-tear\-remake.{0,1000}","offensive_tool_keyword","hidden-tear","open source ransomware - many variant in the wild","T1486 - T1059 - T1485 - T1489 - T1070 - T1488","TA0005 - TA0009 - TA0040 - TA0042","N/A","N/A","Ransomware","https://github.com/goliate/hidden-tear","1","1","N/A","N/A","10","8","765","394","2020-07-08T22:34:01Z","2015-08-19T09:06:51Z","21843" +"*0xdarkvortex-MalwareDevelopment*",".{0,1000}0xdarkvortex\-MalwareDevelopment.{0,1000}","offensive_tool_keyword","prometheus","malware C2","T1071 - T1071.001 - T1105 - T1105.002 - T1106 - T1574.002","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/paranoidninja/0xdarkvortex-MalwareDevelopment","1","1","N/A","N/A","10","10","193","66","2020-07-21T06:14:44Z","2018-09-04T15:38:53Z","21844" +"*0xdea/blindsight*",".{0,1000}0xdea\/blindsight.{0,1000}","offensive_tool_keyword","blindsight","Red teaming tool to dump LSASS memory, bypassing basic countermeasures","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/0xdea/blindsight","1","1","N/A","N/A","10","3","225","26","2024-12-31T15:28:15Z","2024-07-18T07:35:43Z","21845" +"*0xdeadbeef*",".{0,1000}0xdeadbeef.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirtycow vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/timwr/CVE-2016-5195","1","1","N/A","N/A","N/A","10","972","393","2021-02-03T16:03:40Z","2016-10-21T11:19:21Z","21846" +"*0xEr3bus/PoolPartyBof*",".{0,1000}0xEr3bus\/PoolPartyBof.{0,1000}","offensive_tool_keyword","PoolPartyBof","A beacon object file implementation of PoolParty Process Injection Technique","T1055.011 - T1055 - T1620","TA0005","N/A","Black Basta","Privilege Escalation","https://github.com/0xEr3bus/PoolPartyBof","1","1","N/A","N/A","10","4","380","44","2023-12-21T19:00:20Z","2023-12-11T19:28:20Z","21848" +"*0xEr3bus/RdpStrike*",".{0,1000}0xEr3bus\/RdpStrike.{0,1000}","offensive_tool_keyword","RdpStrike","Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP","T1081 - T1055.011 - T1012 - T1113 - T1040 - T1185","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xEr3bus/RdpStrike","1","1","N/A","N/A","10","3","238","27","2024-06-11T19:40:05Z","2024-06-11T19:31:50Z","21849" +"*0xHossam/Killer*",".{0,1000}0xHossam\/Killer.{0,1000}","offensive_tool_keyword","killer","evade AVs and EDRs or security tools","T1564 - T1027 - T1070","TA0005","N/A","N/A","Defense Evasion","https://github.com/0xHossam/Killer","1","1","N/A","N/A","10","9","804","128","2024-07-02T10:24:43Z","2023-04-08T16:29:52Z","21850" +"*0xIslamTaha/Python-Rootkit*",".{0,1000}0xIslamTaha\/Python\-Rootkit.{0,1000}","offensive_tool_keyword","Python-Rootkit","full undetectable python RAT which can bypass almost all antivirus and open a backdoor inside any windows machine which will establish a reverse https Metasploit connection to your listening machine","T1100 - T1027 - T1219 - T1560.001 - T1021.005","TA0005 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/0xIslamTaha/Python-Rootkit","1","1","N/A","N/A","10","10","606","145","2024-10-29T16:56:39Z","2016-06-09T10:49:54Z","21851" +"*0xless/slip*",".{0,1000}0xless\/slip.{0,1000}","offensive_tool_keyword","slip","Slip is a CLI tool to create malicious archive files containing path traversal payloads","T1560.001 - T1059","TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/0xless/slip","1","1","N/A","N/A","10","2","100","4","2025-04-11T18:36:31Z","2022-10-29T15:38:36Z","21852" +"*0xsp-SRD/MDE_Enum*",".{0,1000}0xsp\-SRD\/MDE_Enum.{0,1000}","offensive_tool_keyword","MDE_Enum","extract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rules","T1070.006","TA0005 - TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/0xsp-SRD/MDE_Enum","1","1","N/A","N/A","8","2","198","18","2024-06-10T18:40:27Z","2024-06-06T15:54:44Z","21853" +"*0xsp-SRD/mortar*",".{0,1000}0xsp\-SRD\/mortar.{0,1000}","offensive_tool_keyword","mortar","evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)","T1027 - T1562","TA0005","N/A","N/A","Defense Evasion","https://github.com/0xsp-SRD/mortar","1","1","N/A","N/A","8","10","1451","235","2023-12-21T22:00:38Z","2021-11-25T16:49:47Z","21854" +"*0xsp-SRD/mortar*",".{0,1000}0xsp\-SRD\/mortar.{0,1000}","offensive_tool_keyword","mortar","red teaming evasion technique to defeat and divert detection and prevention of security products.Mortar Loader performs encryption and decryption of selected binary inside the memory streams and execute it directly with out writing any malicious indicator into the hard-drive. Mortar is able to bypass modern anti-virus products and advanced XDR solutions","T1055 - T1027 - T1036 - T1112 - T1037 - T1105 - T1059 - T1562","TA0002 - TA0003 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/0xsp-SRD/mortar","1","1","N/A","N/A","10","10","1451","235","2023-12-21T22:00:38Z","2021-11-25T16:49:47Z","21855" +"*0xthirteen/Carseat*",".{0,1000}0xthirteen\/Carseat.{0,1000}","offensive_tool_keyword","Carseat","Python implementation of GhostPack Seatbelt situational awareness tool","T1012 - T1082 - T1087 - T1124 - T1217","TA0006 - TA0007 - TA0009","N/A","N/A","Collection","https://github.com/0xthirteen/Carseat","1","1","N/A","N/A","8","3","257","21","2024-11-12T19:37:38Z","2024-11-08T02:08:53Z","21856" +"*0xthirteen/MoveKit*",".{0,1000}0xthirteen\/MoveKit.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike kit for Lateral Movement","T1021.002 - T1021.006 - T1021.004","TA0008 - TA0002","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Lateral Movement","https://github.com/0xthirteen/MoveKit","1","1","N/A","N/A","10","7","666","109","2020-02-21T20:23:45Z","2020-01-24T22:19:16Z","21857" +"*0xthirteen/PerfExec*",".{0,1000}0xthirteen\/PerfExec.{0,1000}","offensive_tool_keyword","PerfExec","PerfExec - an example performance dll that will run CMD.exe and a .NET assembly that will execute the DLL or gather performance data locally or remotely.","T1055.001 - T1059.001 - T1059.003 - T1027.002","TA0002 - TA0005 - TA0040","N/A","N/A","Lateral Movement","https://github.com/0xthirteen/PerfExec","1","1","N/A","N/A","7","1","77","12","2023-08-02T20:53:24Z","2023-07-11T16:43:47Z","21858" +"*0xthirteen/SharpMove*",".{0,1000}0xthirteen\/SharpMove.{0,1000}","offensive_tool_keyword","SharpMove",".NET Project for performing Authenticated Remote Execution","T1021 - T1106 - T1218","TA0002 - TA0008","N/A","N/A","Lateral Movement","https://github.com/0xthirteen/SharpMove","1","1","N/A","N/A","8","4","393","66","2023-02-08T23:48:54Z","2020-01-24T22:21:04Z","21859" +"*0xthirteen/SharpRDP*",".{0,1000}0xthirteen\/SharpRDP.{0,1000}","offensive_tool_keyword","SharpRDP","Remote Desktop Protocol .NET Console Application for Authenticated Command Execution","T1021.001 - T1059.001 - T1059.003","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/0xthirteen/SharpRDP","1","1","N/A","N/A","10","10","1041","554","2022-11-13T05:29:33Z","2020-01-21T08:31:50Z","21860" +"*0xthirteen/SharpStay*",".{0,1000}0xthirteen\/SharpStay.{0,1000}","offensive_tool_keyword","SharpStay","SharpStay - .NET Persistence","T1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123","TA0003","N/A","N/A","Persistence","https://github.com/0xthirteen/SharpStay","1","1","N/A","N/A","10","5","475","97","2024-06-26T15:54:52Z","2020-01-24T22:22:07Z","21861" +"*0xthirteen/StayKit*",".{0,1000}0xthirteen\/StayKit.{0,1000}","offensive_tool_keyword","cobaltstrike","StayKit is an extension for Cobalt Strike persistence by leveraging the execute_assembly function with the SharpStay .NET assembly. The aggressor script handles payload creation by reading the template files for a specific execution type.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Persistence","https://github.com/0xthirteen/StayKit","1","1","N/A","N/A","N/A","10","475","73","2020-01-27T14:53:31Z","2020-01-24T22:20:20Z","21862" +"*0xtosh/dnskire*",".{0,1000}0xtosh\/dnskire.{0,1000}","offensive_tool_keyword","dnskire","A tool for file infiltration over DNS","T1071.004 - T1071.001 - T1048","TA0010 - TA0005 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/0xtosh/dnskire","1","1","N/A","N/A","7","1","17","0","2023-12-07T21:42:34Z","2022-09-10T17:56:30Z","21863" +"*0xZDH/o365spray*",".{0,1000}0xZDH\/o365spray.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","1","N/A","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","21864" +"*0xZDH/Omnispray*",".{0,1000}0xZDH\/Omnispray.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","21865" +"*1_FindDomain.sh*",".{0,1000}1_FindDomain\.sh.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","21869" +"*104.131.124.203*",".{0,1000}104\.131\.124\.203.{0,1000}","offensive_tool_keyword","antSword","cross-platform website management toolkit - abused by attackers - supports the use of web shells","T1505.003 - T1059 - T1100 - T1027 - T1219 - T1071","TA0002 - TA0003 - TA0005 - TA0011","antSword webshell","APT41 - APT15","C2","https://github.com/AntSwordProject/antSword","1","1","#ipaddress","N/A","10","10","4010","616","2025-01-20T12:48:42Z","2016-03-11T09:28:00Z","21884" +"*10k-worst-pass.txt*",".{0,1000}10k\-worst\-pass\.txt.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Crack with TGSRepCrack","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","21934" +"*119.45.104.153:8848*",".{0,1000}119\.45\.104\.153\:8848.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","21978" +"*127.0.0.1/KingDefacer*",".{0,1000}127\.0\.0\.1\/KingDefacer.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","22040" +"*127.0.0.1/r57shell*",".{0,1000}127\.0\.0\.1\/r57shell.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","22042" +"*127.0.0.1:1337*",".{0,1000}127\.0\.0\.1\:1337.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","22045" +"*127.0.0.1:1337*",".{0,1000}127\.0\.0\.1\:1337.{0,1000}","offensive_tool_keyword","Lastenzug","Socka4a proxy based on websockets","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","Dispossessor","C2","https://github.com/codewhitesec/Lastenzug","1","1","N/A","N/A","10","10","218","33","2022-10-18T08:55:46Z","2022-07-21T12:57:52Z","22046" +"*127.0.0.1:2222*",".{0,1000}127\.0\.0\.1\:2222.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","22047" +"*127.0.0.1:31337*",".{0,1000}127\.0\.0\.1\:31337.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","22048" +"*127.0.0.1:4567*",".{0,1000}127\.0\.0\.1\:4567.{0,1000}","offensive_tool_keyword","primusC2","another C2 framework","T1090 - T1071","TA0011 - TA0002","N/A","N/A","C2","https://github.com/Primusinterp/PrimusC2","1","1","N/A","N/A","10","10","55","4","2024-11-01T00:20:02Z","2023-04-19T10:59:30Z","22049" +"*127.0.0.1:53531*",".{0,1000}127\.0\.0\.1\:53531.{0,1000}","offensive_tool_keyword","dnscat","This tool is designed to create an encrypted command-and-control (C&C) channel over the DNS protocol","T1071.004 - T1102 - T1071.001","TA0002 - TA0003 - TA0008","N/A","EMBER BEAR","C2","https://github.com/iagox86/dnscat2","1","1","N/A","N/A","10","10","3566","618","2024-03-14T11:17:49Z","2013-01-04T23:15:55Z","22050" +"*127.0.0.1:7777*",".{0,1000}127\.0\.0\.1\:7777.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","N/A","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","22052" +"*127.0.0.1:8022*",".{0,1000}127\.0\.0\.1\:8022.{0,1000}","offensive_tool_keyword","MaccaroniC2","A proof-of-concept Command & Control framework that utilizes the powerful AsyncSSH Python library which provides an asynchronous client and server implementation of the SSHv2 protocol and use PyNgrok wrapper for ngrok integration.","T1090 - T1059.003","TA0011 - TA0002","N/A","N/A","C2","https://github.com/CalfCrusher/MaccaroniC2","1","1","N/A","N/A","10","10","76","16","2023-06-27T17:43:59Z","2023-05-21T13:33:48Z","22053" +"*127.0.0.1:8118*",".{0,1000}127\.0\.0\.1\:8118\:8118.{0,1000}","offensive_tool_keyword","CursedChrome","Chrome-extension implant that turns victim Chrome browsers into fully-functional HTTP proxies allowing you to browse sites as your victims","T1176 - T1219 - T1090","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/mandatoryprogrammer/CursedChrome","1","1","N/A","privproxy port also web panel for victims","10","10","1533","226","2024-10-26T19:06:54Z","2020-04-26T20:55:05Z","22054" +"*127.0.0.1:8848*",".{0,1000}127\.0\.0\.1\:8848.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","22055" +"*127.0.0.1:9050*",".{0,1000}127\.0\.0\.1\:9050.{0,1000}","offensive_tool_keyword","MaccaroniC2","A proof-of-concept Command & Control framework that utilizes the powerful AsyncSSH Python library which provides an asynchronous client and server implementation of the SSHv2 protocol and use PyNgrok wrapper for ngrok integration.","T1090 - T1059.003","TA0011 - TA0002","N/A","N/A","C2","https://github.com/CalfCrusher/MaccaroniC2","1","1","N/A","N/A","10","10","76","16","2023-06-27T17:43:59Z","2023-05-21T13:33:48Z","22056" +"*127.0.0.1:9050*",".{0,1000}127\.0\.0\.1\:9050.{0,1000}","offensive_tool_keyword","tor","used for anonymous communication and web browsing. It is designed to protect users' privacy and freedom by preventing surveillance or traffic analysis. Abused by attacker for defense evasion, contacting C2 and data exfiltration","T1573.002 - T1090.003","TA0011 - TA0010 - TA0005","N/A","Dispossessor - APT28 - APT29 - Leviathan","C2","https://deb.torproject.org/torproject.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","22057" +"*1337*/api/agents/*/results?token=*",".{0,1000}1337.{0,1000}\/api\/agents\/.{0,1000}\/results\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","22114" +"*1337*/api/creds?token=*",".{0,1000}1337.{0,1000}\/api\/creds\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","22115" +"*1337*/api/listeners?token=*",".{0,1000}1337.{0,1000}\/api\/listeners\?token\=.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","22116" +"*1337*infernal-twin*",".{0,1000}1337.{0,1000}infernal\-twin.{0,1000}","offensive_tool_keyword","infernal-twin","This tool is created to aid the penetration testers in assessing wireless security.","T1533 - T1553 - T1560 - T1569 - T1583","TA0002 - TA0003","N/A","N/A","Exploitation tool","https://github.com/entropy1337/infernal-twin","1","1","N/A","network exploitation tool","N/A","10","1254","254","2022-10-27T11:39:14Z","2015-02-07T21:04:57Z","22117" +"*192.168.0.110:1234*",".{0,1000}192\.168\.0\.110\:1234.{0,1000}","offensive_tool_keyword","C2_Server","C2 server to connect to a victim machine via reverse shell","T1090 - T1090.001 - T1071 - T1071.001","TA0011 ","N/A","N/A","C2","https://github.com/reveng007/C2_Server","1","1","N/A","N/A","10","10","54","18","2022-02-27T02:00:02Z","2021-03-05T12:35:45Z","22507" +"*1cd05248c2diffczd.zgpnnj5ikwfugnfvmxzn3qaafstcrdwue4eevw2lzx57rx5bfkia6ryd.onion*",".{0,1000}1cd05248c2diffczd\.zgpnnj5ikwfugnfvmxzn3qaafstcrdwue4eevw2lzx57rx5bfkia6ryd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","22785" +"*1mil-AD-passwords.txt*",".{0,1000}1mil\-AD\-passwords\.txt.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","23024" +"*1N73LL1G3NC3x/Nightmangle*",".{0,1000}1N73LL1G3NC3x\/Nightmangle.{0,1000}","offensive_tool_keyword","Nightmangle","ightmangle is post-exploitation Telegram Command and Control (C2/C&C) Agent","T1105 - T1132 - T1071.001","TA0011 - TA0009 - TA0002","N/A","N/A","C2","https://github.com/1N73LL1G3NC3x/Nightmangle","1","1","N/A","N/A","10","10","156","19","2023-09-26T19:21:31Z","2023-09-26T18:25:23Z","23026" +"*1njected/CMLoot*",".{0,1000}1njected\/CMLoot.{0,1000}","offensive_tool_keyword","CMLoot","Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares","T1083 - T1039","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/1njected/CMLoot","1","1","N/A","N/A","8","2","175","22","2023-02-05T00:24:31Z","2022-06-02T10:59:21Z","23027" +"*1password2john.py*",".{0,1000}1password2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","23028" +"*1rapid7-1_amd64.deb*",".{0,1000}1rapid7\-1_amd64\.deb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-omnibus","1","1","N/A","N/A","10","3","268","213","2025-04-18T13:17:56Z","2015-02-26T18:42:09Z","23029" +"*1y0n/AV_Evasion_Tool*",".{0,1000}1y0n\/AV_Evasion_Tool.{0,1000}","offensive_tool_keyword","AV_Evasion_Tool","Undetectable Payload Generator Tool","T1027 - T1036 - T1059 - T1107","TA0005","N/A","N/A","Defense Evasion","https://github.com/1y0n/AV_Evasion_Tool","1","1","N/A","N/A","10","10","2680","406","2023-12-08T07:38:06Z","2020-04-24T01:11:09Z","23030" +"*1y0n/AVKiller*",".{0,1000}1y0n\/AVKiller.{0,1000}","offensive_tool_keyword","AVKiller","forcibly close some anti-virus processes through process injection (taking 360 Security Guard and 360 Anti-Virus as examples)","T1055.011 - T1089","TA0005 ","N/A","N/A","Defense Evasion","https://github.com/1y0n/AVKiller","1","1","N/A","N/A","10","2","127","18","2023-12-26T05:47:55Z","2023-12-19T00:55:23Z","23031" +"*2_lyncbrute.sh*",".{0,1000}2_lyncbrute\.sh.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","23032" +"*2john.c",".{0,1000}2john\.c","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","24152" +"*2john.lua*",".{0,1000}2john\.lua.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","24153" +"*2john.pl*",".{0,1000}2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","24154" +"*2john.py*",".{0,1000}2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","24155" +"*365-Stealer.py*",".{0,1000}365\-Stealer\.py.{0,1000}","offensive_tool_keyword","365-Stealer","365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack","T1111 - T1566.001 - T1078.004","TA0004 - TA0001 - TA0040","N/A","N/A","Phishing","https://github.com/AlteredSecurity/365-Stealer","1","1","N/A","N/A","10","5","488","89","2024-06-08T21:03:50Z","2020-09-20T18:22:36Z","24596" +"*365-Stealer-master*",".{0,1000}365\-Stealer\-master.{0,1000}","offensive_tool_keyword","365-Stealer","365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack","T1111 - T1566.001 - T1078.004","TA0004 - TA0001 - TA0040","N/A","N/A","Phishing","https://github.com/AlteredSecurity/365-Stealer","1","1","N/A","N/A","10","5","488","89","2024-06-08T21:03:50Z","2020-09-20T18:22:36Z","24597" +"*3gstudent.github.io/Windows-Event-Viewer-Log-*",".{0,1000}3gstudent\.github\.io\/Windows\-Event\-Viewer\-Log\-.{0,1000}","offensive_tool_keyword","Eventlogedit-evt--General","Remove individual lines from Windows Event Viewer Log (EVT) files","T1070.001 - T1564.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/3gstudent/Eventlogedit-evt--General","1","1","N/A","N/A","9","1","44","9","2021-04-17T01:36:42Z","2018-07-23T01:19:03Z","25275" +"*3gstudent/CLR-Injection*",".{0,1000}3gstudent\/CLR\-Injection.{0,1000}","offensive_tool_keyword","CLR-Injection","Use CLR to inject all the .NET apps","T1055.009","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/3gstudent/CLR-Injection","1","1","N/A","N/A","8","2","183","45","2021-04-17T01:39:32Z","2017-07-27T03:00:04Z","25276" +"*3gstudent/COM-Object-hijacking*",".{0,1000}3gstudent\/COM\-Object\-hijacking.{0,1000}","offensive_tool_keyword","COM-Object-hijacking","use COM Object hijacking to maintain persistence.(Hijack CAccPropServicesClass and MMDeviceEnumerator)","T1546.015","TA0003","N/A","N/A","Persistence","https://github.com/3gstudent/COM-Object-hijacking","1","1","N/A","N/A","8","1","58","30","2017-08-04T09:19:40Z","2017-08-04T08:15:36Z","25277" +"*3gstudent/Eventlogedit-evt--General*",".{0,1000}3gstudent\/Eventlogedit\-evt\-\-General.{0,1000}","offensive_tool_keyword","Eventlogedit-evt--General","Remove individual lines from Windows Event Viewer Log (EVT) files","T1070.001 - T1564.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/3gstudent/Eventlogedit-evt--General","1","1","N/A","N/A","9","1","44","9","2021-04-17T01:36:42Z","2018-07-23T01:19:03Z","25278" +"*3gstudent/Eventlogedit-evtx--Evolution*",".{0,1000}3gstudent\/Eventlogedit\-evtx\-\-Evolution.{0,1000}","offensive_tool_keyword","Eventlogedit-evtx--Evolution","","T1070.001 - T1564.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/3gstudent/Eventlogedit-evtx--Evolution","1","1","N/A","N/A","9","3","267","62","2021-04-17T01:28:00Z","2018-06-05T01:21:20Z","25279" +"*3gstudent/Office-Persistence*",".{0,1000}3gstudent\/Office\-Persistence.{0,1000}","offensive_tool_keyword","Office-Persistence","Use powershell to test Office-based persistence methods","T1059.001 - T1137 - T1116","TA0003 ","N/A","N/A","Persistence","https://github.com/3gstudent/Office-Persistence","1","1","N/A","N/A","9","1","76","24","2021-04-17T01:39:13Z","2017-07-14T10:03:35Z","25280" +"*3gstudent/Smbtouch-Scanner*",".{0,1000}3gstudent\/Smbtouch\-Scanner.{0,1000}","offensive_tool_keyword","Smbtouch-Scanner","Smbtouch detect whether the target is vulnerable of one of these vulnerabilities: ETERNALBLUE - ETERNALCHAMPION - ETERNALROMANCE - ETERNALSYNERGY","T1210 - T1046 - T1133","TA0007 - TA0043 - TA0008","N/A","APT15 - Turla","Lateral Movement","https://github.com/3gstudent/Smbtouch-Scanner","1","1","N/A","N/A","10","2","140","66","2021-04-17T01:42:06Z","2017-04-21T01:38:55Z","25281" +"*3gstudent/Waitfor-Persistence*",".{0,1000}3gstudent\/Waitfor\-Persistence.{0,1000}","offensive_tool_keyword","Waitfor-Persistence","Use Waitfor.exe to maintain persistence","T1059 - T1117 - T1053.005 - T1546.013","TA0002 - TA0003","N/A","N/A","Persistence","https://github.com/3gstudent/Waitfor-Persistence","1","1","N/A","N/A","9","1","54","19","2021-04-17T01:41:42Z","2017-06-07T09:33:13Z","25282" +"*3kom-superhack.txt*",".{0,1000}3kom\-superhack\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","25283" +"*3ndG4me/AutoBlue-MS17-010*",".{0,1000}3ndG4me\/AutoBlue\-MS17\-010.{0,1000}","offensive_tool_keyword","AutoBlue-MS17-010","automated exploit code for MS17-010","T1210 - T1040 - T1059.001","TA0001 - TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/3ndG4me/AutoBlue-MS17-010","1","1","N/A","N/A","6","10","1240","317","2023-12-24T19:22:26Z","2017-11-25T09:03:38Z","25284" +"*3nvzqyo6l4wkrzumzu5aod7zbosq4ipgf7ifgj3hsvbcr5vcasordvqd.onion*",".{0,1000}3nvzqyo6l4wkrzumzu5aod7zbosq4ipgf7ifgj3hsvbcr5vcasordvqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","25285" +"*3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd.onion*",".{0,1000}3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","25286" +"*3r7zqtidvujbmfhx52sb34u4vwkh66baefmqzlbqpcnwm3krzipy37yd.onion*",".{0,1000}3r7zqtidvujbmfhx52sb34u4vwkh66baefmqzlbqpcnwm3krzipy37yd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","25295" +"*3snake-master*",".{0,1000}3snake\-master.{0,1000}","offensive_tool_keyword","3snake","Tool for extracting information from newly spawned processes","T1003 - T1110 - T1552 - T1505","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/blendin/3snake","1","1","N/A","N/A","7","8","752","109","2022-02-14T17:42:10Z","2018-02-07T21:03:15Z","25296" +"*3wugtklp46ufx7dnr6j5cd6ate7wnvnivsyvwuni7hqcqt7hm5r72nid.onion*",".{0,1000}3wugtklp46ufx7dnr6j5cd6ate7wnvnivsyvwuni7hqcqt7hm5r72nid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","25297" +"*3x55o3u2b7cjs54eifja5m3ottxntlubhjzt6k6htp5nrocjmsxxh7ad.onion*",".{0,1000}3x55o3u2b7cjs54eifja5m3ottxntlubhjzt6k6htp5nrocjmsxxh7ad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","25298" +"*3xpl01tc0d3r/ProcessInjection*",".{0,1000}3xpl01tc0d3r\/ProcessInjection.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","25299" +"*3xploitGuy/pastehakk*",".{0,1000}3xploitGuy\/pastehakk.{0,1000}","offensive_tool_keyword","pastehakk","perform clipboard poisoning or paste jacking attack","T1115","T0001 - T0002 - T0005","N/A","N/A","Phishing","https://github.com/3xploitGuy/pastehakk","1","1","N/A","N/A","7","1","56","10","2020-06-22T01:17:53Z","2020-06-17T19:32:24Z","25300" +"*3ytm3d25hfzvbylkxiwyqmpvzys5of7l4pbosm7ol7czlkplgukjq6yd.onion*",".{0,1000}3ytm3d25hfzvbylkxiwyqmpvzys5of7l4pbosm7ol7czlkplgukjq6yd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","25301" +"*4.5.6.7:1337*",".{0,1000}4\.5\.6\.7\:1337.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","25302" +"*40056/service-endpoint*",".{0,1000}40056\/service\-endpoint.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","25304" +"*47h4pwve4scndaneljfnxdhzoulgsyfzbgayyonbwztfz74gsdprz5qd.onion*",".{0,1000}47h4pwve4scndaneljfnxdhzoulgsyfzbgayyonbwztfz74gsdprz5qd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","25893" +"*4g3nt47/Striker*",".{0,1000}4g3nt47\/Striker.{0,1000}","offensive_tool_keyword","Striker","Striker is a simple Command and Control (C2) program.","T1071 - T1071.001 - T1071.004 - T1071.005 - T1071.006 - T1071.007 - T1071.008 - T1071.009 - T1071.010 - T1071.012 - T1071.013 - T1071.014 - T1071.015 - T1071.016 - T1071.018 - T1105 - T1105.002 - T1573 - T1573.002 - T1573.003 - T1573.004 - T1573.005","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/4g3nt47/Striker","1","1","N/A","N/A","10","10","301","42","2023-05-04T18:00:05Z","2022-09-07T10:09:41Z","26468" +"*50050/SharpC2*",".{0,1000}50050\/SharpC2.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","26472" +"*516280565958*",".{0,1000}516280565958.{0,1000}","offensive_tool_keyword","cobaltstrike","Convert Cobalt Strike profiles to modrewrite scripts","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/cs2modrewrite","1","1","N/A","N/A","10","10","599","117","2023-01-30T17:47:51Z","2017-06-06T14:53:57Z","26574" +"*516280565959*",".{0,1000}516280565959.{0,1000}","offensive_tool_keyword","cobaltstrike","Convert Cobalt Strike profiles to modrewrite scripts","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/cs2modrewrite","1","1","N/A","N/A","10","10","599","117","2023-01-30T17:47:51Z","2017-06-06T14:53:57Z","26575" +"*5E8106A6F89B053ED91C723D5D4CAE3FFC15F1CE*",".{0,1000}5E8106A6F89B053ED91C723D5D4CAE3FFC15F1CE.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","27582" +"*5e98194a01c6b48fa582a6a9fcbb92d6*",".{0,1000}5e98194a01c6b48fa582a6a9fcbb92d6.{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike4.4 one-click deployment script Randomly generate passwords. keys. port numbers. certificates. etc.. to solve the problem that cs4.x cannot run on Linux and report errors Gray often ginkgo design","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/AlphabugX/csOnvps","1","1","N/A","N/A","10","10","286","63","2022-03-19T00:10:03Z","2021-12-02T02:10:42Z","27587" +"*5ntlvn7lmkezscee2vhatjaigkcu2rzj3bwhqaz32snmqc4jha3gcjad.onion*",".{0,1000}5ntlvn7lmkezscee2vhatjaigkcu2rzj3bwhqaz32snmqc4jha3gcjad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","27684" +"*5spider:password1234*",".{0,1000}5spider\:password1234.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","27686" +"*61106960/adPEAS*",".{0,1000}61106960\/adPEAS.{0,1000}","offensive_tool_keyword","adPEAS","adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others","T1016 - T1087.002 - T1482 - T1207 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/61106960/adPEAS","1","1","N/A","N/A","8","10","1095","132","2025-04-01T16:16:15Z","2020-12-23T08:10:19Z","27740" +"*66e0681a500c726ed52e5ea9423d2654*",".{0,1000}66e0681a500c726ed52e5ea9423d2654.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","28150" +"*67.171.34.23*",".{0,1000}67\.171\.34\.23.{0,1000}","offensive_tool_keyword","antSword","cross-platform website management toolkit - abused by attackers - supports the use of web shells","T1505.003 - T1059 - T1100 - T1027 - T1219 - T1071","TA0002 - TA0003 - TA0005 - TA0011","antSword webshell","APT41 - APT15","C2","https://github.com/AntSwordProject/antSword","1","1","#ipaddress","N/A","10","10","4010","616","2025-01-20T12:48:42Z","2016-03-11T09:28:00Z","28155" +"*6dtxgqam4crv6rr6.onion*",".{0,1000}6dtxgqam4crv6rr6\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","28586" +"*6dtxgqam4crv6rr6.onion.cab*",".{0,1000}6dtxgqam4crv6rr6\.onion\.cab.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","28587" +"*6dtxgqam4crv6rr6.onion.link*",".{0,1000}6dtxgqam4crv6rr6\.onion\.link.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","28588" +"*6dtxgqam4crv6rr6.onion.to*",".{0,1000}6dtxgqam4crv6rr6\.onion\.to.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","28589" +"*6dtxgqam4crv6rr6.tor2web.org*",".{0,1000}6dtxgqam4crv6rr6\.tor2web\.org.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","28590" +"*6v4q5w7di74grj2vtmikzgx2tnq5eagyg2cubpcnqrvvee2ijpmprzqd.onion*",".{0,1000}6v4q5w7di74grj2vtmikzgx2tnq5eagyg2cubpcnqrvvee2ijpmprzqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","28731" +"*6yofnrq7evqrtz3tzi3dkbrdovtywd35lx3iqbc5dyh367nrdh4jgfyd.onion*",".{0,1000}6yofnrq7evqrtz3tzi3dkbrdovtywd35lx3iqbc5dyh367nrdh4jgfyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","28732" +"*7443/new/payloads*",".{0,1000}7443\/new\/payloads.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","29033" +"*789CF3CBCC0DC849CC2B51703652084E2D2A4B2D02003B5C0650*",".{0,1000}789CF3CBCC0DC849CC2B51703652084E2D2A4B2D02003B5C0650.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","29329" +"*7CFC52.dll*",".{0,1000}7CFC52\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Convert Cobalt Strike profiles to modrewrite scripts","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/cs2modrewrite","1","1","N/A","N/A","10","10","599","117","2023-01-30T17:47:51Z","2017-06-06T14:53:57Z","29654" +"*7CFC52CD3F.dll*",".{0,1000}7CFC52CD3F\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Convert Cobalt Strike profiles to modrewrite scripts","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/cs2modrewrite","1","1","N/A","N/A","10","10","599","117","2023-01-30T17:47:51Z","2017-06-06T14:53:57Z","29655" +"*7etsuo/ShellServe*",".{0,1000}7etsuo\/ShellServe.{0,1000}","offensive_tool_keyword","ShellServe","Multi-client network fileserver with integrated shell functionality crafted in C using system calls for efficient and direct file and command processing","T1059 - T1505 - T1046 - T1569","TA0002 - TA0007 - TA0003","N/A","N/A","Data Exfiltration","https://github.com/7etsuo/ShellServe","1","1","N/A","N/A","6","","N/A","","","","29793" +"*7tkffbh3qiumpfjfq77plcorjmfohmbj6nwq5je6herbpya6kmgoafid.onion*",".{0,1000}7tkffbh3qiumpfjfq77plcorjmfohmbj6nwq5je6herbpya6kmgoafid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","29866" +"*7z2john.pl*",".{0,1000}7z2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","29867" +"*808Mak1r/GodzillaSource*",".{0,1000}808Mak1r\/GodzillaSource.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","29920" +"*866e5289337ab033f89bc57c5274c7ca*",".{0,1000}866e5289337ab033f89bc57c5274c7ca.{0,1000}","offensive_tool_keyword","RedGuard","RedGuard is a C2 front flow control tool.Can avoid Blue Teams.AVs.EDRs check.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/wikiZ/RedGuard","1","1","N/A","N/A","10","10","1466","204","2024-08-20T17:43:35Z","2022-05-08T04:02:33Z","30310" +"*913d774e5cf0bfad4adfa900997f7a1a*",".{0,1000}913d774e5cf0bfad4adfa900997f7a1a.{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike4.4 one-click deployment script Randomly generate passwords. keys. port numbers. certificates. etc.. to solve the problem that cs4.x cannot run on Linux and report errors Gray often ginkgo design","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/AlphabugX/csOnvps","1","1","N/A","N/A","10","10","286","63","2022-03-19T00:10:03Z","2021-12-02T02:10:42Z","31106" +"*99$1a7F1qr2HihoXfs/56u5XMdpDZ83N6hW/HI=*",".{0,1000}99\$1a7F1qr2HihoXfs\/56u5XMdpDZ83N6hW\/HI\=.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","31631" +"*9emin1/charlotte*",".{0,1000}9emin1\/charlotte.{0,1000}","offensive_tool_keyword","charlotte","c++ fully undetected shellcode launcher","T1055.012 - T1059.003 - T1027.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/9emin1/charlotte","1","1","N/A","N/A","10","10","976","211","2021-06-11T04:44:18Z","2021-05-13T07:32:03Z","32044" +"*a0rtega/metame*",".{0,1000}a0rtega\/metame.{0,1000}","offensive_tool_keyword","metame","metame is a metamorphic code engine for arbitrary executables","T1027 - T1059.003 - T1140","TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/a0rtega/metame","1","1","N/A","N/A","N/A","6","580","88","2019-10-06T18:24:14Z","2016-08-07T13:56:57Z","32214" +"*a2dbso6dijaqsmut36r6y4nps4cwivmfog5bpzf6uojovce6f3gl36id.onion*",".{0,1000}a2dbso6dijaqsmut36r6y4nps4cwivmfog5bpzf6uojovce6f3gl36id\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","32356" +"*A3h1nt/gimmeSH*",".{0,1000}A3h1nt\/gimmeSH.{0,1000}","offensive_tool_keyword","gimmeSH","gimmeSH. is a tool that generates a custom cheatsheet for Reverse Shell. File Transfer and Msfvenom within your terminal. you just need to provide the platform. your Internet protocol address and your port number.","T1059 - T1505","TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/A3h1nt/gimmeSH","1","1","N/A","N/A","N/A","2","183","28","2021-08-27T03:12:15Z","2021-08-02T07:22:15Z","32423" +"*aazsbsgya565vlu2c6bzy6yfiebkcbtvvcytvolt33s77xypi7nypxyd.onion*",".{0,1000}aazsbsgya565vlu2c6bzy6yfiebkcbtvvcytvolt33s77xypi7nypxyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","32960" +"*abpttsclient.py*",".{0,1000}abpttsclient\.py.{0,1000}","offensive_tool_keyword","ABPTTS","TCP tunneling over HTTP/HTTPS for web application servers","T1071.001 - T1573","TA0003 - TA0011","N/A","N/A","Persistence","https://github.com/nccgroup/ABPTTS","1","1","N/A","N/A","9","8","735","151","2016-08-12T19:36:24Z","2016-07-29T21:45:57Z","33044" +"*ABPTTSClient-log.txt*",".{0,1000}ABPTTSClient\-log\.txt.{0,1000}","offensive_tool_keyword","ABPTTS","TCP tunneling over HTTP/HTTPS for web application servers","T1071.001 - T1573","TA0003 - TA0011","N/A","N/A","Persistence","https://github.com/nccgroup/ABPTTS","1","1","N/A","N/A","9","8","735","151","2016-08-12T19:36:24Z","2016-07-29T21:45:57Z","33045" +"*abpttsfactory.py*",".{0,1000}abpttsfactory\.py.{0,1000}","offensive_tool_keyword","ABPTTS","TCP tunneling over HTTP/HTTPS for web application servers","T1071.001 - T1573","TA0003 - TA0011","N/A","N/A","Persistence","https://github.com/nccgroup/ABPTTS","1","1","N/A","N/A","9","8","735","151","2016-08-12T19:36:24Z","2016-07-29T21:45:57Z","33046" +"*ACBypassTest*",".{0,1000}ACBypassTest.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-FodHelperBypass.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","33102" +"*Accenture/Spartacus*",".{0,1000}Accenture\/Spartacus.{0,1000}","offensive_tool_keyword","Spartacus","Spartacus DLL/COM Hijacking Toolkit","T1574.001 - T1055.001 - T1027.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/Accenture/Spartacus","1","1","N/A","N/A","10","10","1037","141","2024-02-01T13:51:09Z","2022-10-28T09:00:35Z","33108" +"*AccessTokenImpersonationAccount*",".{0,1000}AccessTokenImpersonationAccount.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","33110" +"*ACE_Get-KerberosTicketCache.ps1*",".{0,1000}ACE_Get\-KerberosTicketCache\.ps1.{0,1000}","offensive_tool_keyword","KRBUACBypass","UAC Bypass By Abusing Kerberos Tickets","T1548.002 - T1558 - T1558.003","TA0004 - TA0006","N/A","N/A","Defense Evasion","https://github.com/wh0amitz/KRBUACBypass","1","1","N/A","N/A","8","5","496","62","2023-08-10T02:51:59Z","2023-07-27T12:08:12Z","33119" +"*ACE_Get-KerberosTicketCache.ps1*",".{0,1000}ACE_Get\-KerberosTicketCache\.ps1.{0,1000}","offensive_tool_keyword","seatbelt","Seatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many others","T1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518","TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011","N/A","Dispossessor","Persistence","https://github.com/GhostPack/Seatbelt","1","1","N/A","N/A","10","10","4047","722","2025-01-10T20:12:49Z","2018-07-24T17:38:51Z","33120" +"*ACE_Get-KerberosTicketCache.ps1*",".{0,1000}ACE_Get\-KerberosTicketCache\.ps1.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","33121" +"*AceLdr.*.bin*",".{0,1000}AceLdr\..{0,1000}\.bin.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike UDRL for memory scanner evasion.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/kyleavery/AceLdr","1","1","N/A","N/A","10","10","925","164","2024-06-04T16:45:42Z","2022-08-11T00:06:09Z","33128" +"*AceLdr.zip*",".{0,1000}AceLdr\.zip.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike UDRL for memory scanner evasion.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/kyleavery/AceLdr","1","1","N/A","N/A","10","10","925","164","2024-06-04T16:45:42Z","2022-08-11T00:06:09Z","33129" +"*acheron-master.zip*",".{0,1000}acheron\-master\.zip.{0,1000}","offensive_tool_keyword","acheron","indirect syscalls for AV/EDR evasion in Go assembly","T1055.012 - T1059.001 - T1059.003","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/f1zm0/acheron","1","1","N/A","N/A","N/A","4","326","39","2023-06-13T19:20:33Z","2023-04-07T10:40:33Z","33132" +"*ACLight.ps1*",".{0,1000}ACLight\.ps1.{0,1000}","offensive_tool_keyword","ACLight","A tool for advanced discovery of Privileged Accounts - including Shadow Admins.","T1087 - T1003 - T1208","TA0001 - TA0006 - TA0008","N/A","N/A","Discovery","https://github.com/cyberark/ACLight","1","1","N/A","AD Enumeration","7","9","801","146","2019-09-09T06:48:45Z","2017-05-17T09:29:41Z","33133" +"*ACLight.psd1*",".{0,1000}ACLight\.psd1.{0,1000}","offensive_tool_keyword","ACLight","A tool for advanced discovery of Privileged Accounts - including Shadow Admins.","T1087 - T1003 - T1208","TA0001 - TA0006 - TA0008","N/A","N/A","Discovery","https://github.com/cyberark/ACLight","1","1","N/A","AD Enumeration","7","9","801","146","2019-09-09T06:48:45Z","2017-05-17T09:29:41Z","33134" +"*ACLight.psm1*",".{0,1000}ACLight\.psm1.{0,1000}","offensive_tool_keyword","ACLight","A tool for advanced discovery of Privileged Accounts - including Shadow Admins.","T1087 - T1003 - T1208","TA0001 - TA0006 - TA0008","N/A","N/A","Discovery","https://github.com/cyberark/ACLight","1","1","N/A","AD Enumeration","7","9","801","146","2019-09-09T06:48:45Z","2017-05-17T09:29:41Z","33135" +"*ACLight2.ps1*",".{0,1000}ACLight2\.ps1.{0,1000}","offensive_tool_keyword","ACLight","A tool for advanced discovery of Privileged Accounts - including Shadow Admins.","T1087 - T1003 - T1208","TA0001 - TA0006 - TA0008","N/A","N/A","Discovery","https://github.com/cyberark/ACLight","1","1","N/A","AD Enumeration","7","9","801","146","2019-09-09T06:48:45Z","2017-05-17T09:29:41Z","33136" +"*ACLight2.psd1*",".{0,1000}ACLight2\.psd1.{0,1000}","offensive_tool_keyword","ACLight","A tool for advanced discovery of Privileged Accounts - including Shadow Admins.","T1087 - T1003 - T1208","TA0001 - TA0006 - TA0008","N/A","N/A","Discovery","https://github.com/cyberark/ACLight","1","1","N/A","AD Enumeration","7","9","801","146","2019-09-09T06:48:45Z","2017-05-17T09:29:41Z","33137" +"*ACLight2.psm1*",".{0,1000}ACLight2\.psm1.{0,1000}","offensive_tool_keyword","ACLight","A tool for advanced discovery of Privileged Accounts - including Shadow Admins.","T1087 - T1003 - T1208","TA0001 - TA0006 - TA0008","N/A","N/A","Discovery","https://github.com/cyberark/ACLight","1","1","N/A","AD Enumeration","7","9","801","146","2019-09-09T06:48:45Z","2017-05-17T09:29:41Z","33138" +"*ACLight-master*",".{0,1000}ACLight\-master.{0,1000}","offensive_tool_keyword","ACLight","A tool for advanced discovery of Privileged Accounts - including Shadow Admins.","T1087 - T1003 - T1208","TA0001 - TA0006 - TA0008","N/A","N/A","Discovery","https://github.com/cyberark/ACLight","1","1","N/A","AD Enumeration","7","9","801","146","2019-09-09T06:48:45Z","2017-05-17T09:29:41Z","33139" +"*acltoolkit.git*",".{0,1000}acltoolkit\.git.{0,1000}","offensive_tool_keyword","acltoolkit","acltoolkit is an ACL abuse swiss-army knife. It implements multiple ACL abuses","T1222.001 - T1222.002 - T1046","TA0007 - TA0040","N/A","N/A","Exploitation tool","https://github.com/zblurx/acltoolkit","1","1","N/A","N/A","N/A","2","120","12","2023-02-03T10:27:45Z","2022-01-12T22:45:49Z","33144" +"*acltoolkit-ad*",".{0,1000}acltoolkit\-ad.{0,1000}","offensive_tool_keyword","acltoolkit","acltoolkit is an ACL abuse swiss-army knife. It implements multiple ACL abuses","T1222.001 - T1222.002 - T1046","TA0007 - TA0040","N/A","N/A","Exploitation tool","https://github.com/zblurx/acltoolkit","1","1","N/A","N/A","N/A","2","120","12","2023-02-03T10:27:45Z","2022-01-12T22:45:49Z","33145" +"*acltoolkit-main*",".{0,1000}acltoolkit\-main.{0,1000}","offensive_tool_keyword","acltoolkit","acltoolkit is an ACL abuse swiss-army knife. It implements multiple ACL abuses","T1222.001 - T1222.002 - T1046","TA0007 - TA0040","N/A","N/A","Exploitation tool","https://github.com/zblurx/acltoolkit","1","1","N/A","N/A","N/A","2","120","12","2023-02-03T10:27:45Z","2022-01-12T22:45:49Z","33146" +"*acronis_trueimage_xpc_privesc*",".{0,1000}acronis_trueimage_xpc_privesc.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","33148" +"*aCSHELL/../../../../../../../*",".{0,1000}aCSHELL\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/.{0,1000}","offensive_tool_keyword","POC","CVE-2024-24919","T1005 - T1006 - T1078 - T1110 - T1135 - T1185","TA0001 - TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/LucasKatashi/CVE-2024-24919","1","1","#linux","N/A","10","1","13","5","2024-05-30T17:08:11Z","2024-05-30T16:23:18Z","33150" +"*activedirectory/pwns.go*",".{0,1000}activedirectory\/pwns\.go.{0,1000}","offensive_tool_keyword","adalanche","Active Directory ACL Visualizer and Explorer - who's really Domain Admin?","T1484 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/lkarlslund/Adalanche","1","1","N/A","AD Enumeration","10","10","1908","184","2025-03-25T13:01:45Z","2020-10-07T10:07:22Z","33172" +"*ActiveMQ-RCE.exe*",".{0,1000}ActiveMQ\-RCE\.exe.{0,1000}","offensive_tool_keyword","POC","Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)","T1190 - T1059 - T1071 - T1105 - T1041","TA0001 - TA0002 - TA0009 - TA0011 - TA0010","N/A","N/A","Exploitation tool","https://github.com/SaumyajeetDas/CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ","1","1","N/A","N/A","9","2","114","39","2024-01-20T16:59:23Z","2023-11-03T22:06:09Z","33174" +"*activeScan++.py*",".{0,1000}activeScan\+\+\.py.{0,1000}","offensive_tool_keyword","ActiveScanPlusPlus","ActiveScan++ extends Burp Suite's active and passive scanning capabilities. Designed to add minimal network overhead. it identifies application behaviour that may be of interest to advanced testers","T1583 - T1595 - T1190","TA0001 - TA0002 - TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/albinowax/ActiveScanPlusPlus","1","1","N/A","network exploitation tool","7","7","630","195","2025-04-17T10:47:54Z","2014-06-23T10:04:13Z","33179" +"*ad_dns_dump.txt*",".{0,1000}ad_dns_dump\.txt.{0,1000}","offensive_tool_keyword","adhunt","Tool for exploiting Active Directory Enviroments - enumeration","T1018 - T1087 - T1087.002 - T1069 - T1069.002","TA0007 - TA0003 - TA0001","N/A","N/A","Discovery","https://github.com/karendm/ADHunt","1","1","N/A","AD Enumeration","7","1","46","10","2023-08-10T18:55:39Z","2023-06-20T13:24:10Z","33182" +"*AD_Enumeration_Hunt.ps1*",".{0,1000}AD_Enumeration_Hunt\.ps1.{0,1000}","offensive_tool_keyword","AD_Enumeration_Hunt","This repository contains a collection of PowerShell scripts and commands that can be used for Active Directory (AD) penetration testing and security assessment","T1018 - T1003 - T1033 - T1087 - T1069 - T1046 - T1069.002 - T1047 - T1083","TA0001 - TA0007 - TA0005 - TA0002 - TA0003","N/A","N/A","Discovery","https://github.com/alperenugurlu/AD_Enumeration_Hunt","1","1","N/A","AD Enumeration","7","1","93","18","2023-08-05T06:10:26Z","2023-08-05T05:16:57Z","33183" +"*AD_Enumeration_Hunt-alperen_ugurlu_hack*",".{0,1000}AD_Enumeration_Hunt\-alperen_ugurlu_hack.{0,1000}","offensive_tool_keyword","AD_Enumeration_Hunt","This repository contains a collection of PowerShell scripts and commands that can be used for Active Directory (AD) penetration testing and security assessment","T1018 - T1003 - T1033 - T1087 - T1069 - T1046 - T1069.002 - T1047 - T1083","TA0001 - TA0007 - TA0005 - TA0002 - TA0003","N/A","N/A","Discovery","https://github.com/alperenugurlu/AD_Enumeration_Hunt","1","1","N/A","AD Enumeration","7","1","93","18","2023-08-05T06:10:26Z","2023-08-05T05:16:57Z","33184" +"*AD_Miner-main*",".{0,1000}AD_Miner\-main.{0,1000}","offensive_tool_keyword","AD_Miner","AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses","T1087.002 - T1069 - T1018 - T1595","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/Mazars-Tech/AD_Miner","1","1","N/A","AD Enumeration","7","10","1290","131","2025-03-12T10:53:09Z","2023-09-26T12:36:59Z","33186" +"*ADACLScan.ps1*",".{0,1000}ADACLScan\.ps1.{0,1000}","offensive_tool_keyword","ADACLScanner","A tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory .","T1222 - T1069 - T1018","TA0002 - TA0007 - TA0043","N/A","N/A","Discovery","https://github.com/canix1/ADACLScanner","1","1","N/A","AD Enumeration","7","10","1015","173","2025-04-11T14:35:08Z","2017-04-06T12:28:37Z","33231" +"*ADACLScanner-master*",".{0,1000}ADACLScanner\-master.{0,1000}","offensive_tool_keyword","ADACLScanner","A tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory .","T1222 - T1069 - T1018","TA0002 - TA0007 - TA0043","N/A","N/A","Discovery","https://github.com/canix1/ADACLScanner","1","1","N/A","AD Enumeration","7","10","1015","173","2025-04-11T14:35:08Z","2017-04-06T12:28:37Z","33233" +"*adalanche-*.exe*",".{0,1000}adalanche\-.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","adalanche","Active Directory ACL Visualizer and Explorer - who's really Domain Admin?","T1484 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/lkarlslund/Adalanche","1","1","N/A","AD Enumeration","10","10","1908","184","2025-03-25T13:01:45Z","2020-10-07T10:07:22Z","33236" +"*Adalanche.git*",".{0,1000}Adalanche\.git.{0,1000}","offensive_tool_keyword","adalanche","Active Directory ACL Visualizer and Explorer - who's really Domain Admin?","T1484 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/lkarlslund/Adalanche","1","1","N/A","AD Enumeration","10","10","1908","184","2025-03-25T13:01:45Z","2020-10-07T10:07:22Z","33237" +"*adalanche-collector*",".{0,1000}adalanche\-collector.{0,1000}","offensive_tool_keyword","adalanche","Active Directory ACL Visualizer and Explorer - who's really Domain Admin?","T1484 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/lkarlslund/Adalanche","1","1","N/A","AD Enumeration","10","10","1908","184","2025-03-25T13:01:45Z","2020-10-07T10:07:22Z","33238" +"*Adamantium-Thief-master*",".{0,1000}Adamantium\-Thief\-master.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","1","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","33239" +"*adaptivethreat/Empire*",".{0,1000}adaptivethreat\/Empire.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","33240" +"*Adaptix-Framework/AdaptixC2*",".{0,1000}Adaptix\-Framework\/AdaptixC2.{0,1000}","offensive_tool_keyword","AdaptixC2","C2- Adaptix is an extensible post-exploitation and adversarial emulation framework made for penetration testers","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/Adaptix-Framework/AdaptixC2","1","1","N/A","N/A","10","10","547","114","2025-04-21T06:03:46Z","2024-08-21T18:07:05Z","33242" +"*ADCollector.exe*",".{0,1000}ADCollector\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","33249" +"*adconnectdump.py*",".{0,1000}adconnectdump\.py.{0,1000}","offensive_tool_keyword","adconnectdump","Dump Azure AD Connect credentials for Azure AD and Active Directory","T1003.004 - T1059.001 - T1082","TA0006 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/fox-it/adconnectdump","1","1","N/A","N/A","10","7","668","88","2024-11-10T22:00:16Z","2019-04-09T07:41:42Z","33251" +"*adconnectdump-master*",".{0,1000}adconnectdump\-master.{0,1000}","offensive_tool_keyword","adconnectdump","Dump Azure AD Connect credentials for Azure AD and Active Directory","T1003.004 - T1059.001 - T1082","TA0006 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/fox-it/adconnectdump","1","1","N/A","N/A","10","7","668","88","2024-11-10T22:00:16Z","2019-04-09T07:41:42Z","33252" +"*adcs_enum.*",".{0,1000}adcs_enum\..{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","33254" +"*adcs_enum_com.*",".{0,1000}adcs_enum_com\..{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","33255" +"*adcs_enum_com2.*",".{0,1000}adcs_enum_com2\..{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","33256" +"*ADCS_Maybe_ESC8_HTTPS_Vulnerable.txt*",".{0,1000}ADCS_Maybe_ESC8_HTTPS_Vulnerable\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","33257" +"*adcsattack.py*",".{0,1000}adcsattack\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","33258" +"*ADCSCoercePotato.cpp*",".{0,1000}ADCSCoercePotato\.cpp.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","1","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","33259" +"*ADCSCoercePotato.exe*",".{0,1000}ADCSCoercePotato\.exe.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","1","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","33260" +"*ADCSCoercePotato.sln*",".{0,1000}ADCSCoercePotato\.sln.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","1","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","33261" +"*ADCSCoercePotato.vcxproj*",".{0,1000}ADCSCoercePotato\.vcxproj.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","1","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","33262" +"*adcshunter.py*",".{0,1000}adcshunter\.py.{0,1000}","offensive_tool_keyword","adcshunter","Uses rpcdump to locate the ADCS server and identify if ESC8 is vulnerable from unauthenticated perspective.","T1018 - T1087 - T1046 - T1201 - T1595","TA0007 - TA0043","N/A","N/A","Discovery","https://github.com/danti1988/adcshunter","1","1","N/A","N/A","7","1","80","7","2024-09-13T12:50:50Z","2023-12-14T14:31:05Z","33264" +"*adcskiller.py*",".{0,1000}adcskiller\.py.{0,1000}","offensive_tool_keyword","ADCSKiller","ADCSKiller is a Python-based tool designed to automate the process of discovering and exploiting Active Directory Certificate Services (ADCS) vulnerabilities. It leverages features of Certipy and Coercer to simplify the process of attacking ADCS infrastructure","T1552.004 - T1003.003 - T1114.002 - T1649","TA0006 - TA0003 - TA0005","N/A","N/A","Exploitation tool","https://github.com/grimlockx/ADCSKiller","1","1","N/A","N/A","N/A","8","710","70","2023-05-19T17:36:37Z","2023-05-19T06:51:41Z","33265" +"*ADCSPwn.csproj*",".{0,1000}ADCSPwn\.csproj.{0,1000}","offensive_tool_keyword","ADCSPwn","A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service","T1550.002 - T1078.003 - T1110.003 - T1649","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/bats3c/ADCSPwn","1","1","N/A","N/A","10","9","838","127","2023-03-20T20:30:40Z","2021-07-30T15:04:41Z","33266" +"*ADCSPwn.exe*",".{0,1000}ADCSPwn\.exe.{0,1000}","offensive_tool_keyword","ADCSPwn","A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service","T1550.002 - T1078.003 - T1110.003 - T1649","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/bats3c/ADCSPwn","1","1","N/A","N/A","10","9","838","127","2023-03-20T20:30:40Z","2021-07-30T15:04:41Z","33267" +"*ADCSPwn.exe*",".{0,1000}ADCSPwn\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","33269" +"*ADCSPwn.sln*",".{0,1000}ADCSPwn\.sln.{0,1000}","offensive_tool_keyword","ADCSPwn","A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service","T1550.002 - T1078.003 - T1110.003 - T1649","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/bats3c/ADCSPwn","1","1","N/A","N/A","10","9","838","127","2023-03-20T20:30:40Z","2021-07-30T15:04:41Z","33270" +"*ADCSPwn.zip*",".{0,1000}ADCSPwn\.zip.{0,1000}","offensive_tool_keyword","ADCSPwn","A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service","T1550.002 - T1078.003 - T1110.003 - T1649","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/bats3c/ADCSPwn","1","1","N/A","N/A","10","9","838","127","2023-03-20T20:30:40Z","2021-07-30T15:04:41Z","33271" +"*ADCSPwn-master*",".{0,1000}ADCSPwn\-master.{0,1000}","offensive_tool_keyword","ADCSPwn","A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service","T1550.002 - T1078.003 - T1110.003 - T1649","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/bats3c/ADCSPwn","1","1","N/A","N/A","10","9","838","127","2023-03-20T20:30:40Z","2021-07-30T15:04:41Z","33272" +"*Add-ConstrainedDelegationBackdoor*",".{0,1000}Add\-ConstrainedDelegationBackdoor.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","33324" +"*Add-Exfiltration.ps1*",".{0,1000}Add\-Exfiltration\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","33327" +"*Add-KeePassConfigTrigger*",".{0,1000}Add\-KeePassConfigTrigger.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","33331" +"*AddKeePassTrigger.ps1*",".{0,1000}AddKeePassTrigger\.ps1.{0,1000}","offensive_tool_keyword","crackmapexec","Keepass exploitations from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","33332" +"*AddKeePassTrigger.ps1*",".{0,1000}AddKeePassTrigger\.ps1.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","33333" +"*Add-Persistence.ps1*",".{0,1000}Add\-Persistence\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","33350" +"*Add-Persistence.ps1*",".{0,1000}Add\-Persistence\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","33351" +"*Add-PSFirewallRules*",".{0,1000}Add\-PSFirewallRules.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerBreach.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","33359" +"*Add-RegBackdoor.ps1*",".{0,1000}Add\-RegBackdoor\.ps1.{0,1000}","offensive_tool_keyword","chimera","Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.","T1027.002 - T1059.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/tokyoneon/Chimera/","1","1","N/A","N/A","10","10","1493","252","2021-11-09T12:39:59Z","2020-09-01T07:42:22Z","33366" +"*Add-RegBackdoor.ps1*",".{0,1000}Add\-RegBackdoor\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","33367" +"*Add-RemoteRegBackdoor*",".{0,1000}Add\-RemoteRegBackdoor.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Using DAMP toolkit We add the backdoor using the Add-RemoteRegBackdoor.ps1 cmdlet from DAMP.","T1558.001 - T1078.002 - T1550.003","TA0008 - TA0009 - TA0003","N/A","Black Basta","Persistence","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","33368" +"*Add-RemoteRegBackdoor*",".{0,1000}Add\-RemoteRegBackdoor.{0,1000}","offensive_tool_keyword","DAMP","The Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification.","T1222 - T1222.002 - T1548 - T1548.002","TA0005 ","N/A","N/A","Persistence","https://github.com/HarmJ0y/DAMP","1","1","N/A","N/A","10","4","378","79","2019-07-25T21:18:37Z","2018-04-06T22:13:58Z","33369" +"*Add-RemoteRegBackdoor.json*",".{0,1000}Add\-RemoteRegBackdoor\.json.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","33370" +"*addresshunter.h*",".{0,1000}addresshunter\.h.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","33371" +"*Add-ScrnSaveBackdoor.ps1*",".{0,1000}Add\-ScrnSaveBackdoor\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","33372" +"*Add-ServiceDacl*",".{0,1000}Add\-ServiceDacl.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","33374" +"*addspn.py*",".{0,1000}addspn\.py.{0,1000}","offensive_tool_keyword","krbrelayx","Kerberos unconstrained delegation abuse toolkit","T1558.003 - T1098","TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/dirkjanm/krbrelayx","1","1","N/A","N/A","N/A","10","1281","181","2025-01-27T09:22:54Z","2019-01-08T18:42:07Z","33376" +"*AddUser-Bof.c*",".{0,1000}AddUser\-Bof\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF that Add an admin user","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/0x3rhy/AddUser-Bof","1","1","N/A","N/A","10","10","71","14","2022-10-11T06:51:27Z","2021-08-30T10:09:20Z","33377" +"*AddUser-Bof.git*",".{0,1000}AddUser\-Bof\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF that Add an admin user","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/0x3rhy/AddUser-Bof","1","1","N/A","N/A","10","10","71","14","2022-10-11T06:51:27Z","2021-08-30T10:09:20Z","33378" +"*AddUser-Bof.o*",".{0,1000}AddUser\-Bof\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF that Add an admin user","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/0x3rhy/AddUser-Bof","1","1","N/A","N/A","10","10","71","14","2022-10-11T06:51:27Z","2021-08-30T10:09:20Z","33379" +"*AddUser-Bof.x64*",".{0,1000}AddUser\-Bof\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF that Add an admin user","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/0x3rhy/AddUser-Bof","1","1","N/A","N/A","10","10","71","14","2022-10-11T06:51:27Z","2021-08-30T10:09:20Z","33380" +"*AddUser-Bof.x86*",".{0,1000}AddUser\-Bof\.x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF that Add an admin user","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/0x3rhy/AddUser-Bof","1","1","N/A","N/A","10","10","71","14","2022-10-11T06:51:27Z","2021-08-30T10:09:20Z","33381" +"*AddUserToDomainGroup.*",".{0,1000}AddUserToDomainGroup\..{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of beacon BOF written to learn windows and cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Yaxser/CobaltStrike-BOF","1","1","N/A","N/A","10","10","347","57","2023-02-24T13:12:14Z","2020-10-08T01:12:41Z","33384" +"*AddUserToDomainGroup.cna*",".{0,1000}AddUserToDomainGroup\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of beacon BOF written to learn windows and cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Yaxser/CobaltStrike-BOF","1","1","N/A","N/A","10","10","347","57","2023-02-24T13:12:14Z","2020-10-08T01:12:41Z","33385" +"*adexplorer.go*",".{0,1000}adexplorer\.go.{0,1000}","offensive_tool_keyword","adalanche","Active Directory ACL Visualizer and Explorer - who's really Domain Admin?","T1484 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/lkarlslund/Adalanche","1","1","N/A","AD Enumeration","10","10","1908","184","2025-03-25T13:01:45Z","2020-10-07T10:07:22Z","33397" +"*ADExplorerSnapshot.py*",".{0,1000}ADExplorerSnapshot\.py.{0,1000}","offensive_tool_keyword","ADExplorerSnapshot.py","ADExplorerSnapshot.py is an AD Explorer snapshot parser. It is made as an ingestor for BloodHound and also supports full-object dumping to NDJSON.","T1087.002 - T1482 - T1083 - T1003.008","TA0007 - TA0008 - TA0009","N/A","N/A","Discovery","https://github.com/c3c/ADExplorerSnapshot.py","1","1","N/A","N/A","10","10","956","126","2025-03-14T16:13:41Z","2021-12-22T14:42:23Z","33401" +"*ADExplorerSnapshot.py.git*",".{0,1000}ADExplorerSnapshot\.py\.git.{0,1000}","offensive_tool_keyword","ADExplorerSnapshot.py","ADExplorerSnapshot.py is an AD Explorer snapshot parser. It is made as an ingestor for BloodHound and also supports full-object dumping to NDJSON.","T1087.002 - T1482 - T1083 - T1003.008","TA0007 - TA0008 - TA0009","N/A","N/A","Discovery","https://github.com/c3c/ADExplorerSnapshot.py","1","1","N/A","N/A","10","10","956","126","2025-03-14T16:13:41Z","2021-12-22T14:42:23Z","33402" +"*ADFSDump.csproj*",".{0,1000}ADFSDump\.csproj.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","1","N/A","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","33430" +"*ADFSDump.exe*",".{0,1000}ADFSDump\.exe.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","1","N/A","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","33431" +"*ADFSDump.exe*",".{0,1000}ADFSDump\.exe.{0,1000}","offensive_tool_keyword","ADFSDump","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","ADFSDump","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","33432" +"*ADFSDump.exe*",".{0,1000}ADFSDump\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","ADFSDump","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","33434" +"*ADFSDump.exe*",".{0,1000}ADFSDump\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","33435" +"*ADFSDump.sln*",".{0,1000}ADFSDump\.sln.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","1","N/A","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","33436" +"*ADFSpoof.py*",".{0,1000}ADFSpoof\.py.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","33437" +"*ADFSpoof-master*",".{0,1000}ADFSpoof\-master.{0,1000}","offensive_tool_keyword","ADFSpoof","A python tool to forge AD FS security tokens.","T1550.004 - T1071 - T1606","TA0006 - TA0011 - TA0008","N/A","N/A","Sniffing & Spoofing","https://github.com/mandiant/ADFSpoof","1","1","N/A","N/A","10","4","391","62","2024-08-12T08:13:42Z","2019-03-20T22:30:58Z","33438" +"*ADFSpray.csv*",".{0,1000}ADFSpray\.csv.{0,1000}","offensive_tool_keyword","adfspray","Python3 tool to perform password spraying against Microsoft Online service using various methods","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/xFreed0m/ADFSpray","1","1","N/A","N/A","N/A","1","87","14","2023-03-12T00:21:34Z","2020-04-23T08:56:51Z","33439" +"*adfspray.git*",".{0,1000}adfspray\.git.{0,1000}","offensive_tool_keyword","adfspray","Python3 tool to perform password spraying against Microsoft Online service using various methods","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/xFreed0m/ADFSpray","1","1","N/A","N/A","N/A","1","87","14","2023-03-12T00:21:34Z","2020-04-23T08:56:51Z","33440" +"*ADFSpray.py*",".{0,1000}ADFSpray\.py.{0,1000}","offensive_tool_keyword","adfspray","Python3 tool to perform password spraying against Microsoft Online service using various methods","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/xFreed0m/ADFSpray","1","1","N/A","N/A","N/A","1","87","14","2023-03-12T00:21:34Z","2020-04-23T08:56:51Z","33441" +"*ADHunt-main.zip*",".{0,1000}ADHunt\-main\.zip.{0,1000}","offensive_tool_keyword","adhunt","Tool for exploiting Active Directory Enviroments - enumeration","T1018 - T1087 - T1087.002 - T1069 - T1069.002","TA0007 - TA0003 - TA0001","N/A","N/A","Discovery","https://github.com/karendm/ADHunt","1","1","N/A","AD Enumeration","7","1","46","10","2023-08-10T18:55:39Z","2023-06-20T13:24:10Z","33444" +"*ad-ldap-enum.py*",".{0,1000}ad\-ldap\-enum\.py.{0,1000}","offensive_tool_keyword","ad-ldap-enum","An LDAP based Active Directory user and group enumeration tool","T1087 - T1087.001 - T1018 - T1069 - T1069.002","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/CroweCybersecurity/ad-ldap-enum","1","1","N/A","AD Enumeration","6","4","308","66","2023-02-10T19:07:34Z","2015-08-25T19:38:39Z","33449" +"*ad-ldap-enum-main*",".{0,1000}ad\-ldap\-enum\-main.{0,1000}","offensive_tool_keyword","ad-ldap-enum","An LDAP based Active Directory user and group enumeration tool","T1087 - T1087.001 - T1018 - T1069 - T1069.002","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/CroweCybersecurity/ad-ldap-enum","1","1","N/A","AD Enumeration","6","4","308","66","2023-02-10T19:07:34Z","2015-08-25T19:38:39Z","33450" +"*adm1nPanda/SharpExfil*",".{0,1000}adm1nPanda\/SharpExfil.{0,1000}","offensive_tool_keyword","SharpExfil","C# executables to extract information from target environment using OneDrive API.","T1567.002 - T1020 - T1071.001","TA0005 - TA0010 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/adm1nPanda/SharpExfil","1","1","N/A","N/A","8","1","6","1","2020-07-02T14:48:55Z","2019-07-27T05:28:40Z","33452" +"*admin.kirbi*",".{0,1000}admin\.kirbi.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","33457" +"*Admin2Sys.exe*",".{0,1000}Admin2Sys\.exe.{0,1000}","offensive_tool_keyword","Admin2Sys","Admin2Sys it's a C++ malware to escalate privileges from Administrator account to NT AUTORITY SYSTEM","T1055.002 - T1078.003 - T1068","TA0002 - TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/S12cybersecurity/Admin2Sys","1","1","N/A","N/A","10","1","54","19","2023-05-01T19:32:41Z","2023-05-01T18:50:51Z","33463" +"*Admin2Sys-main*",".{0,1000}Admin2Sys\-main.{0,1000}","offensive_tool_keyword","Admin2Sys","Admin2Sys it's a C++ malware to escalate privileges from Administrator account to NT AUTORITY SYSTEM","T1055.002 - T1078.003 - T1068","TA0002 - TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/S12cybersecurity/Admin2Sys","1","1","N/A","N/A","10","1","54","19","2023-05-01T19:32:41Z","2023-05-01T18:50:51Z","33464" +"*Adminisme/ServerScan/*",".{0,1000}Adminisme\/ServerScan\/.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","33466" +"*adnanekhan/Gato-X*",".{0,1000}adnanekhan\/Gato\-X.{0,1000}","offensive_tool_keyword","Gato-X","automate advanced enumeration and exploitation techniques against GitHub repositories and organizations","T1190 - T1083 - T1588 - T1587","TA0001 - TA0007 - TA0005","N/A","N/A","Reconnaissance","https://github.com/adnanekhan/Gato-X","1","1","N/A","N/A","7","3","270","35","2025-04-21T17:57:09Z","2024-01-27T18:55:16Z","33469" +"*adobe_top100_pass.txt*",".{0,1000}adobe_top100_pass\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","33470" +"*ADPassHunt.exe*",".{0,1000}ADPassHunt\.exe.{0,1000}","offensive_tool_keyword","ADPassHunt","credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)","T1003.003 - T1552.006","TA0006 - TA0007","N/A","N/A","Credential Access","https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","33472" +"*adsearch.exe*",".{0,1000}adsearch\.exe.{0,1000}","offensive_tool_keyword","adsearch","A tool to help query AD via the LDAP protocol","T1087 - T1069.002 - T1018","TA0003 - TA0002 - TA0007","N/A","N/A","Reconnaissance","https://github.com/tomcarver16/ADSearch","1","1","N/A","N/A","N/A","6","536","57","2024-09-25T16:13:13Z","2020-06-17T22:21:41Z","33482" +"*ADSearch.exe*",".{0,1000}ADSearch\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","33483" +"*ADSearch.sln*",".{0,1000}ADSearch\.sln.{0,1000}","offensive_tool_keyword","adsearch","A tool to help query AD via the LDAP protocol","T1087 - T1069.002 - T1018","TA0003 - TA0002 - TA0007","N/A","N/A","Reconnaissance","https://github.com/tomcarver16/ADSearch","1","1","N/A","N/A","N/A","6","536","57","2024-09-25T16:13:13Z","2020-06-17T22:21:41Z","33484" +"*adsearch-master.zip",".{0,1000}adsearch\-master\.zip","offensive_tool_keyword","adsearch","A tool to help query AD via the LDAP protocol","T1087 - T1069.002 - T1018","TA0003 - TA0002 - TA0007","N/A","N/A","Reconnaissance","https://github.com/tomcarver16/ADSearch","1","1","N/A","N/A","N/A","6","536","57","2024-09-25T16:13:13Z","2020-06-17T22:21:41Z","33486" +"*ADSyncDecrypt.exe*",".{0,1000}ADSyncDecrypt\.exe.{0,1000}","offensive_tool_keyword","adconnectdump","Dump Azure AD Connect credentials for Azure AD and Active Directory","T1003.004 - T1059.001 - T1082","TA0006 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/fox-it/adconnectdump","1","1","N/A","N/A","10","7","668","88","2024-11-10T22:00:16Z","2019-04-09T07:41:42Z","33488" +"*ADSyncDecrypt.exe*",".{0,1000}ADSyncDecrypt\.exe.{0,1000}","offensive_tool_keyword","ADSyncDecrypt","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","ADSyncDecrypt","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","33489" +"*ADSyncDecrypt.exe*",".{0,1000}ADSyncDecrypt\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","ADSyncDecrypt","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","33490" +"*ADSyncGather.exe*",".{0,1000}ADSyncGather\.exe.{0,1000}","offensive_tool_keyword","adconnectdump","Dump Azure AD Connect credentials for Azure AD and Active Directory","T1003.004 - T1059.001 - T1082","TA0006 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/fox-it/adconnectdump","1","1","N/A","N/A","10","7","668","88","2024-11-10T22:00:16Z","2019-04-09T07:41:42Z","33491" +"*Advanced.AV.Evasion.Tool.For.Red.Team.exe*",".{0,1000}Advanced\.AV\.Evasion\.Tool\.For\.Red\.Team\.exe.{0,1000}","offensive_tool_keyword","AV_Evasion_Tool","Undetectable Payload Generator Tool","T1027 - T1036 - T1059 - T1107","TA0005","N/A","N/A","Defense Evasion","https://github.com/1y0n/AV_Evasion_Tool","1","1","N/A","N/A","10","10","2680","406","2023-12-08T07:38:06Z","2020-04-24T01:11:09Z","33499" +"*Advanced-SQL-Injection-Cheatsheet*",".{0,1000}Advanced\-SQL\-Injection\-Cheatsheet.{0,1000}","offensive_tool_keyword","Advanced-SQL-Injection-Cheatsheet","A cheat sheet that contains advanced queries for SQL Injection of all types.","T1071.001 - T1190 - T1059.007 - T1040","TA0001 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/kleiton0x00/Advanced-SQL-Injection-Cheatsheet","1","1","N/A","N/A","N/A","10","3003","678","2023-05-13T17:15:20Z","2020-10-23T18:14:47Z","33505" +"*advantech_iview_networkservlet_cmd_inject.*",".{0,1000}advantech_iview_networkservlet_cmd_inject\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","33506" +"*adxcsouf2john.py*",".{0,1000}adxcsouf2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33510" +"*ADZero.py*",".{0,1000}ADZero\.py.{0,1000}","offensive_tool_keyword","POC","Zerologon CVE exploitation","T1210 - T1072","TA0001 - TA0009","N/A","N/A","Exploitation tool","https://github.com/Privia-Security/ADZero","1","1","N/A","N/A","N/A","1","22","7","2020-10-02T13:00:21Z","2020-09-29T20:43:06Z","33511" +"*Aegrah/PANIX*",".{0,1000}Aegrah\/PANIX.{0,1000}","offensive_tool_keyword","panix","PANIX is a highly customizable Linux persistence tool","T1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/Aegrah/PANIX","1","1","#linux","N/A","8","7","622","68","2025-03-05T10:45:04Z","2024-05-19T12:37:40Z","33591" +"*aem2john.py*",".{0,1000}aem2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33592" +"*AesEncryptor.py*",".{0,1000}AesEncryptor\.py.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","33606" +"*ag_load_script*",".{0,1000}ag_load_script.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","33676" +"*agent/cmd_download_files.*",".{0,1000}agent\/cmd_download_files\..{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","33683" +"*agent/cmd_exec.*",".{0,1000}agent\/cmd_exec\..{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","33684" +"*agent/cmd_kill.*",".{0,1000}agent\/cmd_kill\..{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","33685" +"*agent/cmd_proxy.*",".{0,1000}agent\/cmd_proxy\..{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","33686" +"*agent/cmd_run.c*",".{0,1000}agent\/cmd_run\.c.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","33687" +"*agent/cmd_shell.*",".{0,1000}agent\/cmd_shell\..{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","33688" +"*agent/cmd_sleep.*",".{0,1000}agent\/cmd_sleep\..{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","33689" +"*agent/cmd_sysinfo.c*",".{0,1000}agent\/cmd_sysinfo\.c.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","33690" +"*agent/cmd_upload_files.*",".{0,1000}agent\/cmd_upload_files\..{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","33691" +"*agent/dll.nim*",".{0,1000}agent\/dll\.nim.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","33692" +"*agent/elf.nim*",".{0,1000}agent\/elf\.nim.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","33693" +"*agent/exe.nim*",".{0,1000}agent\/exe\.nim.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","33694" +"*Agent/ratchatPT.go*",".{0,1000}Agent\/ratchatPT\.go.{0,1000}","offensive_tool_keyword","ratchatpt","C2 using openAI API","T1094 - T1071.001","TA0011 - TA0002","N/A","N/A","C2","https://github.com/spartan-conseil/ratchatpt","1","1","N/A","risk of False positive","10","10","16","6","2023-06-09T12:39:00Z","2023-06-09T09:19:10Z","33695" +"*agent_code/bash_executor*",".{0,1000}agent_code\/bash_executor.{0,1000}","offensive_tool_keyword","mythic","mythic C2 agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/freyja/","1","1","#linux","N/A","10","10","54","13","2024-10-29T17:32:07Z","2022-09-28T17:20:04Z","33705" +"*agent_dll.dll*",".{0,1000}agent_dll\.dll.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","33706" +"*agents/Follina-2*",".{0,1000}agents\/Follina\-2.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","33715" +"*AggressiveProxy.cna*",".{0,1000}AggressiveProxy\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Project to enumerate proxy configurations and generate shellcode from CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EncodeGroup/AggressiveProxy","1","1","N/A","N/A","10","10","141","25","2020-11-04T16:08:11Z","2020-11-04T12:53:00Z","33717" +"*aggressor.beacons*",".{0,1000}aggressor\.beacons.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","33718" +"*aggressor.bshell*",".{0,1000}aggressor\.bshell.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","33719" +"*aggressor.cna*",".{0,1000}aggressor\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of beacon BOF written to learn windows and cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Yaxser/CobaltStrike-BOF","1","1","N/A","N/A","10","10","347","57","2023-02-24T13:12:14Z","2020-10-08T01:12:41Z","33720" +"*aggressor.dialog*",".{0,1000}aggressor\.dialog.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","33721" +"*aggressor.println*",".{0,1000}aggressor\.println.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","33722" +"*aggressor.py*",".{0,1000}aggressor\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","33723" +"*Aggressor/TikiTorch*",".{0,1000}Aggressor\/TikiTorch.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","33724" +"*AggressorScripts*",".{0,1000}AggressorScripts.{0,1000}","offensive_tool_keyword","AggressorScripts-1","Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources","T1074 - T1070 - T1105 - T1558","TA0007 - TA0003 - TA0002 - TA0043","N/A","N/A","Exploitation tool","https://github.com/Cn33liz/AggressorScripts-1","1","1","N/A","N/A","N/A","1","2","1","2018-06-24T16:27:57Z","2019-10-18T12:56:35Z","33725" +"*aggressor-scripts*",".{0,1000}aggressor\-scripts.{0,1000}","offensive_tool_keyword","cobaltstrike","beacon generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/eddiezab/aggressor-scripts/tree/master","1","1","N/A","N/A","10","10","1","0","2021-01-29T21:01:58Z","2021-01-29T21:00:26Z","33726" +"*ahmedkhlief/Ninja*",".{0,1000}ahmedkhlief\/Ninja.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","33732" +"*aircrack-ng*",".{0,1000}aircrack\-ng.{0,1000}","offensive_tool_keyword","Rudrastra","Make a Fake wireless access point aka Evil Twin","T1491 - T1090.004 - T1557.001","TA0040 - TA0011 - TA0002","N/A","N/A","Sniffing & Spoofing","https://github.com/SxNade/Rudrastra","1","1","N/A","N/A","8","1","67","21","2023-04-22T15:10:42Z","2020-11-05T09:38:15Z","33747" +"*airman604/splunk_whisperer*",".{0,1000}airman604\/splunk_whisperer.{0,1000}","offensive_tool_keyword","SplunkWhisperer2","Local privilege escalation or remote code execution through Splunk Universal Forwarder (UF) misconfigurations","T1068 - T1059.003 - T1071.001","TA0004 - TA0003 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/cnotin/SplunkWhisperer2","1","1","N/A","N/A","9","10","250","53","2022-09-30T16:41:17Z","2019-02-24T18:05:51Z","33755" +"*airmon-ng*",".{0,1000}airmon\-ng.{0,1000}","offensive_tool_keyword","airmon-ng","This script can be used to enable monitor mode on wireless interfaces. It may also be used to kill network managers or go back from monitor mode to managed mode","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Sniffing & Spoofing","https://www.aircrack-ng.org/doku.php?id=airmon-ng","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","33756" +"*airpwn-ng*",".{0,1000}airpwn\-ng.{0,1000}","offensive_tool_keyword","airpwn-ng","We force the targets browser to do what we want","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/ICSec/airpwn-ng","1","1","N/A","N/A","N/A","1","36","13","2022-11-07T02:22:34Z","2021-07-20T03:43:13Z","33761" +"*aix2john.pl*",".{0,1000}aix2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33764" +"*aix2john.py*",".{0,1000}aix2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33765" +"*ajm4n/DLLHound*",".{0,1000}ajm4n\/DLLHound.{0,1000}","offensive_tool_keyword","DLLHound","Find potential DLL Sideloads on your windows computer","T1574.001 - T1574.002","TA0004 - TA0007","N/A","N/A","Discovery","https://github.com/ajm4n/DLLHound","1","1","N/A","N/A","7","3","201","22","2025-01-12T02:28:22Z","2024-12-20T02:26:16Z","33766" +"*ajpc500/BOFs*",".{0,1000}ajpc500\/BOFs.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","33767" +"*akamai/DDSpoof*",".{0,1000}akamai\/DDSpoof.{0,1000}","offensive_tool_keyword","DDSpoof","DDSpoof is a tool that enables DHCP DNS Dynamic Update attacks against Microsoft DHCP servers in AD environments.","T1557 - T1584 - T1203","TA0005 - TA0003 TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/akamai/DDSpoof","1","1","N/A","N/A","9","2","122","13","2024-04-12T22:06:02Z","2023-12-14T06:47:45Z","33769" +"*akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion*",".{0,1000}akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","33771" +"*akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion*",".{0,1000}akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","33772" +"*akkuman/rotateproxy*",".{0,1000}akkuman\/rotateproxy.{0,1000}","offensive_tool_keyword","rotateproxy","A tool that uses fofa to search for socks5 open proxies and perform proxy pool rotation","T1071.001 - T1090 - T1095 - T1189","TA0011 - TA0010 - TA0005","N/A","N/A","Defense Evasion","https://github.com/akkuman/rotateproxy","1","1","N/A","N/A","10","9","800","135","2024-01-24T05:47:37Z","2021-10-18T02:10:27Z","33774" +"*akuafif/hXOR-Packer*",".{0,1000}akuafif\/hXOR\-Packer.{0,1000}","offensive_tool_keyword","hXOR-Packer","hXOR Packer is a PE (Portable Executable) packer with Huffman Compression and Xor encryption.","T1027 - T1048.003 - T1140 - T1205.001","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/akuafif/hXOR-Packer","1","1","N/A","N/A","9","1","57","14","2021-09-11T13:00:34Z","2020-11-19T14:57:03Z","33776" +"*AlanFramework.git*",".{0,1000}AlanFramework\.git.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","33777" +"*Albertino RAT v2.2/*",".{0,1000}Albertino\sRAT\sv2\.2\/.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","33778" +"*Alcatraz.sln*",".{0,1000}Alcatraz\.sln.{0,1000}","offensive_tool_keyword","Alcatraz","x64 binary obfuscator","T1027 - T1140","TA0004 - TA0042","N/A","N/A","Defense Evasion","https://github.com/weak1337/Alcatraz","1","1","N/A","N/A","10","10","1808","267","2023-07-14T14:19:01Z","2022-12-21T17:27:56Z","33779" +"*Alcatraz.vcxproj*",".{0,1000}Alcatraz\.vcxproj.{0,1000}","offensive_tool_keyword","Alcatraz","x64 binary obfuscator","T1027 - T1140","TA0004 - TA0042","N/A","N/A","Defense Evasion","https://github.com/weak1337/Alcatraz","1","1","N/A","N/A","10","10","1808","267","2023-07-14T14:19:01Z","2022-12-21T17:27:56Z","33780" +"*Alcatraz/obfuscator*",".{0,1000}Alcatraz\/obfuscator.{0,1000}","offensive_tool_keyword","Alcatraz","x64 binary obfuscator","T1027 - T1140","TA0004 - TA0042","N/A","N/A","Defense Evasion","https://github.com/weak1337/Alcatraz","1","1","N/A","N/A","10","10","1808","267","2023-07-14T14:19:01Z","2022-12-21T17:27:56Z","33781" +"*Alcatraz-master.zip*",".{0,1000}Alcatraz\-master\.zip.{0,1000}","offensive_tool_keyword","Alcatraz","x64 binary obfuscator","T1027 - T1140","TA0004 - TA0042","N/A","N/A","Defense Evasion","https://github.com/weak1337/Alcatraz","1","1","N/A","N/A","10","10","1808","267","2023-07-14T14:19:01Z","2022-12-21T17:27:56Z","33782" +"*AlessandroZ/BeRoot*",".{0,1000}AlessandroZ\/BeRoot.{0,1000}","offensive_tool_keyword","BeRoot","BeRoot Project is a post exploitation tool to check common misconfigurations to find a way to escalate our privilege.","T1068 - T1055 - T1078 - T1548 - T1003","TA0004","N/A","N/A","Exploitation tool","https://github.com/AlessandroZ/BeRoot","1","1","N/A","N/A","10","10","2523","459","2024-10-04T11:54:01Z","2017-04-14T12:47:31Z","33783" +"*AlessandroZ/LaZagne*",".{0,1000}AlessandroZ\/LaZagne.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","33784" +"*alexa-top-20000-sites.txt*",".{0,1000}alexa\-top\-20000\-sites\.txt.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","33786" +"*AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits*",".{0,1000}AlexisAhmed\/CVE\-2022\-0847\-DirtyPipe\-Exploits.{0,1000}","offensive_tool_keyword","POC","exploit the Linux Dirty Pipe vulnerability","T1068 - T1078.003 - T1071.004 - T1072 - T1105","TA0004 - TA0006?","N/A","N/A","Privilege Escalation","https://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits","1","1","#linux","N/A","10","6","595","148","2023-05-20T05:55:45Z","2022-03-12T20:57:24Z","33787" +"*alex-sector/dns2tcp*",".{0,1000}alex\-sector\/dns2tcp.{0,1000}","offensive_tool_keyword","dns2tcp","Dns2tcp is a tool for relaying TCP connections over DNS","T1071.004 - T1048.003","TA0011 - TA0001","N/A","N/A","C2","https://github.com/alex-sector/dns2tcp","1","1","N/A","N/A","10","10","191","60","2024-06-08T09:40:52Z","2017-11-23T11:19:53Z","33788" +"*Ali-DaNGer File Registerator.exe*",".{0,1000}Ali\-DaNGer\sFile\sRegisterator\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","33790" +"*All_SubdomainTOP_Seclist.txt*",".{0,1000}All_SubdomainTOP_Seclist\.txt.{0,1000}","offensive_tool_keyword","Sudomy","Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting","T1595 - T1046","TA0002","N/A","N/A","Reconnaissance","https://github.com/screetsec/Sudomy","1","1","#linux","N/A","N/A","10","2139","396","2024-06-27T10:07:42Z","2019-07-26T10:26:34Z","33801" +"*allow_url_include%3d1+-d+auto_prepend_file%3dphp://input*",".{0,1000}allow_url_include\%3d1\+\-d\+auto_prepend_file\%3dphp\:\/\/input.{0,1000}","offensive_tool_keyword","POC","CVE-2024-4577 POC exploitation","T1190 - T1059.003","TA0001 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/watchtowrlabs/CVE-2024-4577","1","1","N/A","N/A","10","3","275","62","2024-06-22T15:13:52Z","2024-06-07T09:52:54Z","33805" +"*AllowDelegationUsers.txt*",".{0,1000}AllowDelegationUsers\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","33806" +"*AllowDelegationUsers_samaccountnames_only.txt*",".{0,1000}AllowDelegationUsers_samaccountnames_only\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","33807" +"*almandin/krbjack*",".{0,1000}almandin\/krbjack.{0,1000}","offensive_tool_keyword","krbjack","A Kerberos AP-REQ hijacking tool with DNS unsecure updates abuse.","T1558.002 - T1552.004 - T1048.005","TA0006 - TA0007 ","N/A","N/A","Sniffing & Spoofing","https://github.com/almandin/krbjack","1","1","N/A","N/A","10","2","113","21","2025-01-22T18:12:00Z","2023-04-16T10:44:55Z","33809" +"*AlmondOffSec/PassTheCert*",".{0,1000}AlmondOffSec\/PassTheCert.{0,1000}","offensive_tool_keyword","PassTheCert","tool to authenticate to an LDAP/S server with a certificate through Schannel","T1557 - T1071 - T1021 - T1213 - T1649","TA0006 - TA0008 - TA0009","N/A","Black Basta","Lateral Movement","https://github.com/AlmondOffSec/PassTheCert","1","1","N/A","N/A","10","7","618","76","2024-07-08T22:37:30Z","2022-04-29T09:08:32Z","33810" +"*ALPC-TaskSched-LPE*",".{0,1000}ALPC\-TaskSched\-LPE.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","33811" +"*ALPC-TaskSched-LPE.*",".{0,1000}ALPC\-TaskSched\-LPE\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","33812" +"*Alphabug_CS*",".{0,1000}Alphabug_CS.{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike4.4 one-click deployment script Randomly generate passwords. keys. port numbers. certificates. etc.. to solve the problem that cs4.x cannot run on Linux and report errors","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/AlphabugX/csOnvps","1","1","N/A","N/A","10","10","286","63","2022-03-19T00:10:03Z","2021-12-02T02:10:42Z","33813" +"*Alphabug_CS*",".{0,1000}Alphabug_CS.{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike4.4 one-click deployment script Randomly generate passwords. keys. port numbers. certificates. etc.. to solve the problem that cs4.x cannot run on Linux and report errors Gray often ginkgo design","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/AlphabugX/csOnvps","1","1","N/A","N/A","10","10","286","63","2022-03-19T00:10:03Z","2021-12-02T02:10:42Z","33814" +"*AlphabugX/csOnvps*",".{0,1000}AlphabugX\/csOnvps.{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike4.4 one-click deployment script Randomly generate passwords. keys. port numbers. certificates. etc.. to solve the problem that cs4.x cannot run on Linux and report errors","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/AlphabugX/csOnvps","1","1","N/A","N/A","10","10","286","63","2022-03-19T00:10:03Z","2021-12-02T02:10:42Z","33815" +"*AlphabugX/csOnvps*",".{0,1000}AlphabugX\/csOnvps.{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike4.4 one-click deployment script Randomly generate passwords. keys. port numbers. certificates. etc.. to solve the problem that cs4.x cannot run on Linux and report errors Gray often ginkgo design","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/AlphabugX/csOnvps","1","1","N/A","N/A","10","10","286","63","2022-03-19T00:10:03Z","2021-12-02T02:10:42Z","33816" +"*alphvmmm27o3abo3r2mlmjrpdmzle3rykajqc5xsj7j7ejksbpsa36ad.onion*",".{0,1000}alphvmmm27o3abo3r2mlmjrpdmzle3rykajqc5xsj7j7ejksbpsa36ad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","33818" +"*AlteredSecurity/365-Stealer*",".{0,1000}AlteredSecurity\/365\-Stealer.{0,1000}","offensive_tool_keyword","365-Stealer","365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack","T1111 - T1566.001 - T1078.004","TA0004 - TA0001 - TA0040","N/A","N/A","Phishing","https://github.com/AlteredSecurity/365-Stealer","1","1","N/A","N/A","10","5","488","89","2024-06-08T21:03:50Z","2020-09-20T18:22:36Z","33822" +"*AlteredSecurity/Disable-TamperProtection*",".{0,1000}AlteredSecurity\/Disable\-TamperProtection.{0,1000}","offensive_tool_keyword","Disable-TamperProtection","disable TamperProtection and other Defender / MDE components","T1562.001 - T1562.007","TA0005","N/A","N/A","Defense Evasion","https://github.com/AlteredSecurity/Disable-TamperProtection","1","1","N/A","N/A","10","3","208","35","2024-06-06T14:44:59Z","2024-06-05T12:48:56Z","33823" +"*alwaysinstallelevated.*",".{0,1000}alwaysinstallelevated\..{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","33824" +"*am0nsec/HellsGate*",".{0,1000}am0nsec\/HellsGate.{0,1000}","offensive_tool_keyword","HellsGate","The Hell's Gate technique is a method employed by malware to hide its malicious behavior and avoid detection. This technique involves executing system calls directly thus bypassing the Windows API (Application Programming Interface) which is typically monitored by EDRs","T1055 - T1548.002 - T1129","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/am0nsec/HellsGate","1","1","N/A","N/A","N/A","10","1028","121","2021-06-28T15:42:36Z","2020-06-02T17:10:21Z","33827" +"*amass-get-rootdomains*",".{0,1000}amass\-get\-rootdomains.{0,1000}","offensive_tool_keyword","thoth","Automate recon for red team assessments.","T1190 - T1083 - T1018","TA0007 - TA0043 - TA0001","N/A","N/A","Reconnaissance","https://github.com/r1cksec/thoth","1","1","N/A","N/A","7","1","95","10","2025-02-03T12:05:52Z","2021-11-15T13:40:56Z","33831" +"*amass-get-subdomains*",".{0,1000}amass\-get\-subdomains.{0,1000}","offensive_tool_keyword","thoth","Automate recon for red team assessments.","T1190 - T1083 - T1018","TA0007 - TA0043 - TA0001","N/A","N/A","Reconnaissance","https://github.com/r1cksec/thoth","1","1","N/A","N/A","7","1","95","10","2025-02-03T12:05:52Z","2021-11-15T13:40:56Z","33832" +"*AmberWolfCyber/NachoVPN*",".{0,1000}AmberWolfCyber\/NachoVPN.{0,1000}","offensive_tool_keyword","NachoVPN","NachoVPN is a Proof of Concept that demonstrates exploitation of SSL-VPN clients using a rogue VPN serve","T1071 - T1027 - T1547 - T1204","TA0003 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/AmberWolfCyber/NachoVPN","1","1","N/A","N/A","7","3","218","28","2024-11-28T12:40:55Z","2024-10-30T15:53:56Z","33833" +"*amibypass.exe*",".{0,1000}amibypass\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","33834" +"*amjcyber/pwnlook*",".{0,1000}amjcyber\/pwnlook.{0,1000}","offensive_tool_keyword","pwnlook","An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails configured in it","T1114 - T1071 - T1059 - T1113 - T1123","TA0002 - TA0005 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/amjcyber/pwnlook","1","1","N/A","N/A","6","2","166","18","2024-10-09T07:50:04Z","2024-09-19T10:26:16Z","33836" +"*Amnesiac.ps1*",".{0,1000}Amnesiac\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","33841" +"*Amnesiac_ShellReady.ps1*",".{0,1000}Amnesiac_ShellReady\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1059.001 - T1078 - T1086 - T1021.002 - T1046","TA0008 - TA0003 - TA0004 - TA0005 - TA0006 - TA0009 - TA0010 - TA0011","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","33842" +"*Amnesiac-main.zip*",".{0,1000}Amnesiac\-main\.zip.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","33843" +"*AMS1-Patch.exe*",".{0,1000}AMS1\-Patch\.exe.{0,1000}","offensive_tool_keyword","AMSI_patch","Patching AmsiOpenSession by forcing an error branching","T1055 - T1055.001 - T1112","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/AMSI_patch","1","1","N/A","N/A","8","2","145","29","2023-08-02T02:27:00Z","2023-02-03T18:11:37Z","33846" +"*AMSI_Bypass.ps1*",".{0,1000}AMSI_Bypass\.ps1.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1024 - T1071 - T1029 - T1569","TA0002 - TA0003 - TA0040","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","33848" +"*AMSI_bypass_20*.ps1",".{0,1000}AMSI_bypass_20.{0,1000}\.ps1","offensive_tool_keyword","PSSW100AVB","This is the PSSW100AVB (Powershell Scripts With 100% AV Bypass) Framework.A list of useful Powershell scripts with 100% AV bypass ratio","T1112 - T1562.001 - T1086 - T1548.002 - T1059.001","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/tihanyin/PSSW100AVB","1","1","N/A","N/A","N/A","10","1104","174","2025-01-28T10:47:44Z","2021-10-08T17:36:24Z","33849" +"*AMSI_patch-main*",".{0,1000}AMSI_patch\-main.{0,1000}","offensive_tool_keyword","AMSI_patch","Patching AmsiOpenSession by forcing an error branching","T1055 - T1055.001 - T1112","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/AMSI_patch","1","1","N/A","N/A","8","2","145","29","2023-08-02T02:27:00Z","2023-02-03T18:11:37Z","33850" +"*AmsiBypass.cs*",".{0,1000}AmsiBypass\.cs.{0,1000}","offensive_tool_keyword","CheeseTools","tools for Lateral Movement/Code Execution","T1021.006 - T1059.003 - T1105","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/klezVirus/CheeseTools","1","1","N/A","N/A","10","8","706","143","2021-08-17T20:22:56Z","2020-08-24T01:28:12Z","33852" +"*amsibypass.exe*",".{0,1000}amsibypass\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","33853" +"*Amsi-Killer.exe*",".{0,1000}Amsi\-Killer\.exe.{0,1000}","offensive_tool_keyword","Amsi-Killer","Lifetime AMSI bypass","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/ZeroMemoryEx/Amsi-Killer","1","1","N/A","N/A","10","7","624","90","2023-09-26T00:49:22Z","2023-02-26T19:05:14Z","33854" +"*Amsi-Killer.sln*",".{0,1000}Amsi\-Killer\.sln.{0,1000}","offensive_tool_keyword","Amsi-Killer","Lifetime AMSI bypass","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/ZeroMemoryEx/Amsi-Killer","1","1","N/A","N/A","10","7","624","90","2023-09-26T00:49:22Z","2023-02-26T19:05:14Z","33855" +"*Amsi-Killer.vcxproj*",".{0,1000}Amsi\-Killer\.vcxproj.{0,1000}","offensive_tool_keyword","Amsi-Killer","Lifetime AMSI bypass","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/ZeroMemoryEx/Amsi-Killer","1","1","N/A","N/A","10","7","624","90","2023-09-26T00:49:22Z","2023-02-26T19:05:14Z","33856" +"*Amsi-Killer-master*",".{0,1000}Amsi\-Killer\-master.{0,1000}","offensive_tool_keyword","Amsi-Killer","Lifetime AMSI bypass","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/ZeroMemoryEx/Amsi-Killer","1","1","N/A","N/A","10","7","624","90","2023-09-26T00:49:22Z","2023-02-26T19:05:14Z","33857" +"*AmsiOpenSession.cpp*",".{0,1000}AmsiOpenSession\.cpp.{0,1000}","offensive_tool_keyword","AMSI_patch","Patching AmsiOpenSession by forcing an error branching","T1055 - T1055.001 - T1112","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/AMSI_patch","1","1","N/A","N/A","8","2","145","29","2023-08-02T02:27:00Z","2023-02-03T18:11:37Z","33858" +"*AmsiOpenSession.sln*",".{0,1000}AmsiOpenSession\.sln.{0,1000}","offensive_tool_keyword","AMSI_patch","Patching AmsiOpenSession by forcing an error branching","T1055 - T1055.001 - T1112","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/AMSI_patch","1","1","N/A","N/A","8","2","145","29","2023-08-02T02:27:00Z","2023-02-03T18:11:37Z","33859" +"*AmsiOpenSession.vcxproj*",".{0,1000}AmsiOpenSession\.vcxproj.{0,1000}","offensive_tool_keyword","AMSI_patch","Patching AmsiOpenSession by forcing an error branching","T1055 - T1055.001 - T1112","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/AMSI_patch","1","1","N/A","N/A","8","2","145","29","2023-08-02T02:27:00Z","2023-02-03T18:11:37Z","33860" +"*AmsiTrigger.exe*",".{0,1000}AmsiTrigger\.exe.{0,1000}","offensive_tool_keyword","AMSITrigger","AMSITrigger will identify all of the malicious strings in a powershell file by repeatedly making calls to AMSI using AMSIScanBuffer - line by line. On receiving an AMSI_RESULT_DETECTED response code the line will then be scrutinised to identify the individual triggers","T1059.001 - T1218.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/RythmStick/AMSITrigger","1","1","N/A","https://www.rythmstick.net/posts/amsitrigger/","10","10","1195","166","2022-08-21T22:37:23Z","2020-05-27T09:17:19Z","33861" +"*AMSITrigger.exe*",".{0,1000}AMSITrigger\.exe.{0,1000}","offensive_tool_keyword","Invoke-Stealth","Simple & Powerful PowerShell Script Obfuscator","T1027.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/JoelGMSec/Invoke-Stealth","1","1","N/A","N/A","9","6","559","81","2023-04-21T12:49:37Z","2021-04-13T10:22:05Z","33862" +"*AmsiTrigger_x64.exe*",".{0,1000}AmsiTrigger_x64\.exe.{0,1000}","offensive_tool_keyword","AMSITrigger","AMSITrigger will identify all of the malicious strings in a powershell file by repeatedly making calls to AMSI using AMSIScanBuffer - line by line. On receiving an AMSI_RESULT_DETECTED response code the line will then be scrutinised to identify the individual triggers","T1059.001 - T1218.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/RythmStick/AMSITrigger","1","1","N/A","https://www.rythmstick.net/posts/amsitrigger/","10","10","1195","166","2022-08-21T22:37:23Z","2020-05-27T09:17:19Z","33863" +"*amsitrigger_x64.exe*",".{0,1000}amsitrigger_x64\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","33864" +"*AmsiTrigger_x86.exe*",".{0,1000}AmsiTrigger_x86\.exe.{0,1000}","offensive_tool_keyword","AMSITrigger","AMSITrigger will identify all of the malicious strings in a powershell file by repeatedly making calls to AMSI using AMSIScanBuffer - line by line. On receiving an AMSI_RESULT_DETECTED response code the line will then be scrutinised to identify the individual triggers","T1059.001 - T1218.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/RythmStick/AMSITrigger","1","1","N/A","https://www.rythmstick.net/posts/amsitrigger/","10","10","1195","166","2022-08-21T22:37:23Z","2020-05-27T09:17:19Z","33865" +"*andotp2john.py*",".{0,1000}andotp2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33870" +"*AndrewSpecial.cpp*",".{0,1000}AndrewSpecial\.cpp.{0,1000}","offensive_tool_keyword","AndrewSpecial","AndrewSpecial - dumping lsass memory stealthily","T1003.001 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/hoangprod/AndrewSpecial","1","1","N/A","N/A","10","4","386","98","2019-06-02T02:49:28Z","2019-01-18T19:12:09Z","33871" +"*AndrewSpecial.exe*",".{0,1000}AndrewSpecial\.exe.{0,1000}","offensive_tool_keyword","AndrewSpecial","AndrewSpecial - dumping lsass memory stealthily","T1003.001 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/hoangprod/AndrewSpecial","1","1","N/A","N/A","10","4","386","98","2019-06-02T02:49:28Z","2019-01-18T19:12:09Z","33872" +"*AndrewSpecial-master*",".{0,1000}AndrewSpecial\-master.{0,1000}","offensive_tool_keyword","AndrewSpecial","AndrewSpecial - dumping lsass memory stealthily","T1003.001 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/hoangprod/AndrewSpecial","1","1","N/A","N/A","10","4","386","98","2019-06-02T02:49:28Z","2019-01-18T19:12:09Z","33873" +"*android/meterpreter/reverse_tcp*",".{0,1000}android\/meterpreter\/reverse_tcp.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","33874" +"*androidbackup2john.py*",".{0,1000}androidbackup2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33875" +"*androidfde2john.py*",".{0,1000}androidfde2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33876" +"*AnErrupTion/LoGiC.NET*",".{0,1000}AnErrupTion\/LoGiC\.NET.{0,1000}","offensive_tool_keyword","LoGiC.NET","A more advanced free and open .NET obfuscator using dnlib","T1001","TA0011","N/A","N/A","Defense Evasion","https://github.com/AnErrupTion/LoGiC.NET","1","1","N/A","N/A","5","6","513","80","2023-08-23T09:55:54Z","2019-12-27T09:48:50Z","33877" +"*AngelSecurityTeam/BackHAck*",".{0,1000}AngelSecurityTeam\/BackHAck.{0,1000}","offensive_tool_keyword","BackHAck","Backdoor Generator with C2 server - Linux & Windows - FUD AV .py .exe","T1090 - T1095 - T1008","TA0011","N/A","N/A","C2","https://github.com/AngelSecurityTeam/BackHAck","1","1","#linux","N/A","10","10","108","34","2020-03-25T21:30:47Z","2020-03-14T19:00:36Z","33879" +"*AngelSecurityTeam/Cam-Hackers*",".{0,1000}AngelSecurityTeam\/Cam\-Hackers.{0,1000}","offensive_tool_keyword","Cam-Hackers","Hack Cameras CCTV FREE","T1125","TA0007","N/A","N/A","Discovery","https://github.com/AngelSecurityTeam/Cam-Hackers","1","1","N/A","N/A","6","10","2025","512","2024-08-06T18:49:02Z","2019-11-16T18:49:35Z","33880" +"*AngelSecurityTeam-BackdoorLinux*",".{0,1000}AngelSecurityTeam\-BackdoorLinux.{0,1000}","offensive_tool_keyword","BackHAck","Backdoor Generator with C2 server - Linux & Windows - FUD AV .py .exe","T1090 - T1095 - T1008","TA0011","N/A","N/A","C2","https://github.com/AngelSecurityTeam/BackHAck","1","1","#linux","N/A","10","10","108","34","2020-03-25T21:30:47Z","2020-03-14T19:00:36Z","33881" +"*AngelSecurityTeam-BackdoorWindows.exe*",".{0,1000}AngelSecurityTeam\-BackdoorWindows\.exe.{0,1000}","offensive_tool_keyword","BackHAck","Backdoor Generator with C2 server - Linux & Windows - FUD AV .py .exe","T1090 - T1095 - T1008","TA0011","N/A","N/A","C2","https://github.com/AngelSecurityTeam/BackHAck","1","1","#linux","N/A","10","10","108","34","2020-03-25T21:30:47Z","2020-03-14T19:00:36Z","33883" +"*ANGRYPUPPY2.cna*",".{0,1000}ANGRYPUPPY2\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Bloodhound Attack Path Automation in CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/vysecurity/ANGRYPUPPY","1","1","N/A","N/A","10","10","316","87","2020-04-26T17:35:31Z","2017-07-11T14:18:07Z","33885" +"*aniqfakhrul/powerview.py*",".{0,1000}aniqfakhrul\/powerview\.py.{0,1000}","offensive_tool_keyword","powerview","PowerView.py is an alternative for the awesome original PowerView.ps1","T1046 - T1087.001 - T1016","TA0007 - TA0008 - TA0009","N/A","N/A","Discovery","https://github.com/aniqfakhrul/powerview.py","1","1","N/A","N/A","10","7","622","66","2025-04-22T09:01:39Z","2022-06-19T16:13:04Z","33886" +"*anonsurf.py*",".{0,1000}anonsurf\.py.{0,1000}","offensive_tool_keyword","hackingtool","ALL IN ONE Hacking Tool For Hackers","T1059 - T1078 - T1105 - T1110 - T1566","TA0002 - TA0008 - TA0009 - TA0005 - TA0007","N/A","N/A","Exploitation tool","https://github.com/Z4nzu/hackingtool","1","1","N/A","N/A","N/A","10","52217","5629","2025-03-03T15:17:19Z","2020-04-11T09:21:31Z","33889" +"*ansible2john.py*",".{0,1000}ansible2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33890" +"*anthemtotheego/Detect-Hooks*",".{0,1000}anthemtotheego\/Detect\-Hooks.{0,1000}","offensive_tool_keyword","cobaltstrike","Proof of concept Beacon Object File (BOF) that attempts to detect userland hooks in place by AV/EDR","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/anthemtotheego/Detect-Hooks","1","1","N/A","N/A","10","10","158","30","2021-07-22T20:13:16Z","2021-07-22T18:58:23Z","33891" +"*anthemtotheego/SharpSploitConsole*",".{0,1000}anthemtotheego\/SharpSploitConsole.{0,1000}","offensive_tool_keyword","SharpSploitConsole","Console Application designed to interact with SharpSploit","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/anthemtotheego/SharpSploitConsole","1","1","N/A","N/A","10","2","182","36","2022-02-21T15:12:26Z","2018-10-02T18:57:46Z","33892" +"*antirez/hping*",".{0,1000}antirez\/hping.{0,1000}","offensive_tool_keyword","hping","hping3 is a network tool able to send custom TCP/IP","T1046 - T1190 - T1200","TA0001 - TA0002 - TA0007","N/A","N/A","Sniffing & Spoofing","https://github.com/antirez/hping","1","1","N/A","N/A","N/A","10","1533","341","2024-07-10T12:38:39Z","2012-06-13T17:41:54Z","33893" +"*AntivirusBypass.psm1*",".{0,1000}AntivirusBypass\.psm1.{0,1000}","offensive_tool_keyword","PowerSploit","PowerSploit is a collection of Microsoft PowerShell modules that can be used to aid penetration testers during all phases of an assessment. PowerSploit is comprised of the following modules and scripts","T1134 - T1087.001 - T1123 - T1547.001 - T1547.005 - T1059.001 - T1543.003 - T1555.004 - T1005 - T1482 - T1574.001 - T1574.007 - T1574.008 - T1574.009 - T1056.001 - T1027.005 - T1027.010 - T1003.001 - T1057 - T1055.001 - T1012 - T1620 - T1053.005 - T1113 - T1558.003 - T1552.002 - T1552.006 - T1047","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","Dispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - Turla","Framework","https://github.com/PowerShellMafia/PowerSploit","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","33894" +"*antonioCoco/ConPtyShell*",".{0,1000}antonioCoco\/ConPtyShell.{0,1000}","offensive_tool_keyword","ConPtyShell","ConPtyShell - Fully Interactive Reverse Shell for Windows","T1059.001 - T1021.004 - T1056.003","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/ConPtyShell","1","1","N/A","N/A","10","10","1102","171","2023-01-20T10:52:52Z","2019-09-13T22:11:18Z","33896" +"*antonioCoco/JuicyPotatoNG*",".{0,1000}antonioCoco\/JuicyPotatoNG.{0,1000}","offensive_tool_keyword","JuicyPotatoNG","Another Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","FoxKitten - APT33 - Volatile Cedar - Sandworm","Privilege Escalation","https://github.com/antonioCoco/JuicyPotatoNG","1","1","N/A","N/A","10","9","844","101","2022-11-12T01:48:39Z","2022-09-21T17:08:35Z","33897" +"*antonioCoco/RemotePotato0*",".{0,1000}antonioCoco\/RemotePotato0.{0,1000}","offensive_tool_keyword","RemotePotato0","Windows Privilege Escalation from User to Domain Admin.","T1078.002 - T1078.003 - T1078.004","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RemotePotato0","1","1","N/A","N/A","10","10","1382","215","2022-12-18T01:52:53Z","2021-02-08T22:02:19Z","33898" +"*antonioCoco/RoguePotato*",".{0,1000}antonioCoco\/RoguePotato.{0,1000}","offensive_tool_keyword","RoguePotato","Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RoguePotato","1","1","N/A","N/A","10","10","1081","131","2021-01-09T20:43:07Z","2020-05-10T17:38:28Z","33899" +"*antonioCoco/RogueWinRM*",".{0,1000}antonioCoco\/RogueWinRM.{0,1000}","offensive_tool_keyword","RogueWinRM","RogueWinRM is a local privilege escalation exploit that allows to escalate from a Service account (with SeImpersonatePrivilege) to Local System account if WinRM service is not running","T1548.003 - T1134.002 - T1055","TA0004","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RogueWinRM","1","1","N/A","N/A","10","8","788","107","2020-02-23T19:26:41Z","2019-12-02T22:58:03Z","33900" +"*antonioCoco/RunasCs*",".{0,1000}antonioCoco\/RunasCs.{0,1000}","offensive_tool_keyword","RunasCs","RunasCs - Csharp and open version of windows builtin runas.exe","T1059.003 - T1059.001 - T1035","TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/RunasCs","1","1","N/A","N/A","7","10","1159","141","2024-07-12T23:31:35Z","2019-08-08T20:18:18Z","33901" +"*antonioCoco/SspiUacBypass*",".{0,1000}antonioCoco\/SspiUacBypass.{0,1000}","offensive_tool_keyword","SspiUacBypass","Bypassing UAC with SSPI Datagram Contexts","T1548.002","TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/SspiUacBypass","1","1","N/A","N/A","10","5","433","56","2023-09-24T17:33:25Z","2023-09-14T20:59:22Z","33902" +"*antoniomika/sish*",".{0,1000}antoniomika\/sish.{0,1000}","offensive_tool_keyword","sish","An open source serveo/ngrok alternative. HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH","T1572 - T1090.002","TA0010 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antoniomika/sish","1","1","N/A","N/A","10","10","4203","325","2025-04-10T20:04:08Z","2019-02-15T15:36:23Z","33903" +"*AntSwordProject/antSword*",".{0,1000}AntSwordProject\/antSword.{0,1000}","offensive_tool_keyword","antSword","cross-platform website management toolkit - abused by attackers - supports the use of web shells","T1505.003 - T1059 - T1100 - T1027 - T1219 - T1071","TA0002 - TA0003 - TA0005 - TA0011","antSword webshell","APT41 - APT15","C2","https://github.com/AntSwordProject/antSword","1","1","N/A","N/A","10","10","4010","616","2025-01-20T12:48:42Z","2016-03-11T09:28:00Z","33907" +"*anypotato.exe*",".{0,1000}anypotato\.exe.{0,1000}","offensive_tool_keyword","RasmanPotato","using RasMan service for privilege escalation","T1548.002 - T1055.002 - T1055.001 ","TA0004 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/crisprss/RasmanPotato","1","1","N/A","N/A","10","4","371","53","2023-02-06T10:27:41Z","2023-02-06T09:41:51Z","33916" +"*aoacugmutagkwctu.onion*",".{0,1000}aoacugmutagkwctu\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","33923" +"*AoratosWin*.zip*",".{0,1000}AoratosWin.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","AoratosWin","AoratosWin A tool that removes traces of executed applications on Windows OS","T1070 - T1564","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/PinoyWH1Z/AoratosWin","1","1","N/A","N/A","N/A","2","120","16","2022-09-04T09:15:35Z","2022-09-04T09:04:35Z","33926" +"*AoratosWin.csproj*",".{0,1000}AoratosWin\.csproj.{0,1000}","offensive_tool_keyword","AoratosWin","AoratosWin A tool that removes traces of executed applications on Windows OS","T1070 - T1564","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/PinoyWH1Z/AoratosWin","1","1","N/A","N/A","N/A","2","120","16","2022-09-04T09:15:35Z","2022-09-04T09:04:35Z","33927" +"*AoratosWin.exe*",".{0,1000}AoratosWin\.exe.{0,1000}","offensive_tool_keyword","AoratosWin","AoratosWin A tool that removes traces of executed applications on Windows OS","T1070 - T1564","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/PinoyWH1Z/AoratosWin","1","1","N/A","N/A","N/A","2","120","16","2022-09-04T09:15:35Z","2022-09-04T09:04:35Z","33928" +"*AoratosWin.git*",".{0,1000}AoratosWin\.git.{0,1000}","offensive_tool_keyword","AoratosWin","AoratosWin A tool that removes traces of executed applications on Windows OS","T1070 - T1564","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/PinoyWH1Z/AoratosWin","1","1","N/A","N/A","N/A","2","120","16","2022-09-04T09:15:35Z","2022-09-04T09:04:35Z","33929" +"*AoratosWin.sln*",".{0,1000}AoratosWin\.sln.{0,1000}","offensive_tool_keyword","AoratosWin","AoratosWin A tool that removes traces of executed applications on Windows OS","T1070 - T1564","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/PinoyWH1Z/AoratosWin","1","1","N/A","N/A","N/A","2","120","16","2022-09-04T09:15:35Z","2022-09-04T09:04:35Z","33930" +"*AoratosWin_*.zip*",".{0,1000}AoratosWin_.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","AoratosWin","A tool that removes traces of executed applications on Windows OS.","T1070 - T1564","TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/PinoyWH1Z/AoratosWin","1","1","N/A","N/A","N/A","2","120","16","2022-09-04T09:15:35Z","2022-09-04T09:04:35Z","33931" +"*apache_felix_remote_shell*",".{0,1000}apache_felix_remote_shell.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","33932" +"*APC_Ijnect_Load.nim*",".{0,1000}APC_Ijnect_Load\.nim.{0,1000}","offensive_tool_keyword","C2 related tools","A shellcode loader written using nim","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/aeverj/NimShellCodeLoader","1","1","N/A","N/A","10","10","656","121","2025-02-18T14:31:45Z","2021-01-19T15:57:01Z","33933" +"*apex2john.py*",".{0,1000}apex2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33936" +"*apfs_encrypted_volume_passwd.md*",".{0,1000}apfs_encrypted_volume_passwd\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","33937" +"*api.truesocks.net*",".{0,1000}api\.truesocks\.net.{0,1000}","offensive_tool_keyword","TrueSocks","Simple API for buying renting and managing proxies","T1021 - T1071 - T1090","TA0003 - TA0008 - TA0011","N/A","Scattered Spider*","Defense Evasion","https://github.com/c0dn/truesocks_rs","1","1","N/A","N/A","10","1","0","0","2023-05-09T01:00:05Z","2023-04-06T02:32:04Z","33947" +"*APIHookInjectorBin.exe*",".{0,1000}APIHookInjectorBin\.exe.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","33953" +"*APIHookInjectorBin.log*",".{0,1000}APIHookInjectorBin\.log.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","#logfile","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","33954" +"*APIHookInjectorBin.pdb*",".{0,1000}APIHookInjectorBin\.pdb.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","33955" +"*APIHookInjectorBin.sln*",".{0,1000}APIHookInjectorBin\.sln.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","33956" +"*aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd.onion*",".{0,1000}aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","33959" +"*aploium/shootback*",".{0,1000}aploium\/shootback.{0,1000}","offensive_tool_keyword","shootback","a reverse TCP tunnel let you access target behind NAT or firewall","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/aploium/shootback","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","962","234","2020-09-12T07:31:56Z","2016-04-28T15:12:36Z","33960" +"*apokryptein/secinject*",".{0,1000}apokryptein\/secinject.{0,1000}","offensive_tool_keyword","cobaltstrike","Section Mapping Process Injection (secinject): Cobalt Strike BOF","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/apokryptein/secinject","1","1","N/A","N/A","10","10","94","23","2022-01-07T21:09:32Z","2021-09-05T01:17:47Z","33961" +"*apop2john.py*",".{0,1000}apop2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33962" +"*app.pentest-tools.com*",".{0,1000}app\.pentest\-tools\.com.{0,1000}","offensive_tool_keyword","pentest-tools.com","site often consulted by pentester","T1596 - T1592","TA0043","N/A","N/A","Reconnaissance","https://pentest-tools.com","1","1","N/A","N/A","8","10","N/A","N/A","N/A","N/A","33966" +"*appadmin9090@proton.me*",".{0,1000}appadmin9090\@proton\.me.{0,1000}","offensive_tool_keyword","Dispossessor","email account used by the ransomware group","T1486 - T1490 - T1059 - T1213 - T1078","TA0040 - TA0043 - TA0001 - TA0009","N/A","Dispossessor","Ransomware","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","#email","N/A","10","10","N/A","N/A","N/A","N/A","33971" +"*apple_ios/aarch64/meterpreter_reverse_tcp*",".{0,1000}apple_ios\/aarch64\/meterpreter_reverse_tcp.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","33983" +"*applenotes2john.py*",".{0,1000}applenotes2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33984" +"*Applet_ReverseTCP.jar*",".{0,1000}Applet_ReverseTCP\.jar.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","33985" +"*Application.Lazagne.H*",".{0,1000}Application\.Lazagne\.H.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","33988" +"*applocker_enum*",".{0,1000}applocker_enum.{0,1000}","offensive_tool_keyword","cobaltstrike","A Visual Studio template used to create Cobalt Strike BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/securifybv/Visual-Studio-BOF-template","1","1","N/A","N/A","10","10","304","55","2021-11-17T12:03:42Z","2021-11-13T13:44:01Z","33998" +"*applocker-enumerator*",".{0,1000}applocker\-enumerator.{0,1000}","offensive_tool_keyword","cobaltstrike","A Visual Studio template used to create Cobalt Strike BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/securifybv/Visual-Studio-BOF-template","1","1","N/A","N/A","10","10","304","55","2021-11-17T12:03:42Z","2021-11-13T13:44:01Z","33999" +"*AppProxyC2CertificateCreator.exe*",".{0,1000}AppProxyC2CertificateCreator\.exe.{0,1000}","offensive_tool_keyword","AppProxyC2","simple POC to show how to tunnel traffic through Azure Application Proxy","T1090 - T1572 - T1071","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/xpn/AppProxyC2","1","1","N/A","N/A","9","10","69","18","2021-04-21T13:02:15Z","2021-04-21T10:46:16Z","34000" +"*apt/etumbot.py*",".{0,1000}apt\/etumbot\.py.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","34021" +"*apt/putterpanda.py*",".{0,1000}apt\/putterpanda\.py.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","34022" +"*apt1_virtuallythere.profile*",".{0,1000}apt1_virtuallythere\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","34024" +"*APT64/EternalHushFramework*",".{0,1000}APT64\/EternalHushFramework.{0,1000}","offensive_tool_keyword","EternalHushFramework","EternalHush Framework is a new open source project that is an advanced C&C framework. Designed specifically for Windows operating systems","T1071.001 - T1132.001 - T1059.003 - T1547.001","TA0011 - TA0005 - TA0010 - TA0002","N/A","Equation Group","C2","https://github.com/APT64/EternalHushFramework","1","1","N/A","N/A","10","10","11","1","2023-10-28T13:08:06Z","2023-07-09T09:13:21Z","34025" +"*APTortellini/unDefender*",".{0,1000}APTortellini\/unDefender.{0,1000}","offensive_tool_keyword","unDefender","Killing your preferred antimalware by abusing native symbolic links and NT paths.","T1562.001 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/APTortellini/unDefender","1","1","N/A","N/A","10","4","358","81","2022-01-29T12:35:31Z","2021-08-21T14:45:39Z","34033" +"*APTSimulator*",".{0,1000}APTSimulator.{0,1000}","offensive_tool_keyword","APTSimulator","APT Simulator is a Windows Batch script that uses a set of tools and output files to make a system look as if it was compromised. In contrast to other adversary simulation tools. APT Simulator is deisgned to make the application as simple as possible. You don't need to run a web server. database or any agents on set of virtual machines. Just download the prepared archive. extract and run the contained Batch file as Administrator. Running APT Simulator takes less than a minute of your time.","T1036 - T1059 - T1562 - T1027 - T1003","TA0001 - TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/NextronSystems/APTSimulator","1","1","N/A","N/A","N/A","10","2570","439","2023-06-16T08:48:25Z","2018-02-03T14:19:42Z","34034" +"*apvc24autvavxuc6.onion*",".{0,1000}apvc24autvavxuc6\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","34035" +"*apvc24autvavxuc6.onion.cab*",".{0,1000}apvc24autvavxuc6\.onion\.cab.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","34036" +"*apvc24autvavxuc6.onion.city*",".{0,1000}apvc24autvavxuc6\.onion\.city.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","34037" +"*apvc24autvavxuc6.onion.to*",".{0,1000}apvc24autvavxuc6\.onion\.to.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","34038" +"*apypykatz.py*",".{0,1000}apypykatz\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","34039" +"*archive-*.kali.org/*",".{0,1000}archive\-.{0,1000}\.kali\.org\/.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","34043" +"*archive.torproject.org*",".{0,1000}archive\.torproject\.org.{0,1000}","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","34044" +"*ArchStrike*",".{0,1000}ArchStrike.{0,1000}","offensive_tool_keyword","archstrike","Arch Linux repo containing lots of exploitation tools for pentesters","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation OS","https://archstrike.org/","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","34045" +"*ares-master.zip*",".{0,1000}ares\-master\.zip.{0,1000}","offensive_tool_keyword","Ares","Python C2 botnet and backdoor ","T1105 - T1102 - T1055","TA0003 - TA0002 - TA0007","N/A","N/A","C2","https://github.com/sweetsoftware/Ares","1","1","N/A","N/A","10","10","1588","477","2023-03-02T12:43:09Z","2015-10-18T12:26:27Z","34047" +"*arget13/DDexec*",".{0,1000}arget13\/DDexec.{0,1000}","offensive_tool_keyword","Ddexec","A technique to run binaries filelessly and stealthily on Linux by ""overwriting"" the shell's process with another.","T1055.008 - T1106 - T1059.004","TA0002 - TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/arget13/DDexec","1","1","#linux","N/A","9","9","830","88","2025-03-21T17:51:04Z","2022-01-27T12:52:10Z","34048" +"*ArgFuscator.net/archive/refs/heads/*",".{0,1000}ArgFuscator\.net\/archive\/refs\/heads\/.{0,1000}","offensive_tool_keyword","Invoke-ArgFuscator","generate obfuscated command-lines for common system-native executables","T1027 - T1059 - T1202","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/wietze/Invoke-ArgFuscator","1","1","N/A","N/A","10","2","161","28","2025-04-14T21:24:29Z","2022-11-20T17:59:23Z","34049" +"*armitage.exe*",".{0,1000}armitage\.exe.{0,1000}","offensive_tool_keyword","armitage","Armitage is a graphical cyber attack management tool for Metasploit that visualizes your targets. recommends exploits and exposes the advanced capabilities of the framework ","T1210 - T1059.003 - T1547.001 - T1057 - T1046 - T1562.001 - T1071.001 - T1060 - T1573.002","TA0002 - TA0008 - TA0005 - TA0007 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/r00t0v3rr1d3/armitage","1","1","N/A","N/A","N/A","2","129","32","2022-12-06T00:17:23Z","2022-01-23T17:32:01Z","34056" +"*Arno0x/DBC2*",".{0,1000}Arno0x\/DBC2.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","34064" +"*Arno0x/DNSExfiltrator*",".{0,1000}Arno0x\/DNSExfiltrator.{0,1000}","offensive_tool_keyword","DNSExfiltrator","DNSExfiltrator allows for transfering (exfiltrate) a file over a DNS request covert channel. This is basically a data leak testing tool allowing to exfiltrate data over a covert channel.","T1041 - T1048","TA0010 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/Arno0x/DNSExfiltrator","1","1","N/A","N/A","10","9","867","188","2024-04-29T20:20:43Z","2017-12-20T13:58:09Z","34065" +"*Arno0x/EmbedInHTML*",".{0,1000}Arno0x\/EmbedInHTML.{0,1000}","offensive_tool_keyword","EmbedInHTML","What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.","T1027 - T1566.001","TA0005 - TA0002","N/A","N/A","Phishing","https://github.com/Arno0x/EmbedInHTML","1","1","N/A","N/A","N/A","5","485","119","2017-09-27T13:16:06Z","2017-09-11T07:17:20Z","34066" +"*Arno0x/NtlmRelayToEWS*",".{0,1000}Arno0x\/NtlmRelayToEWS.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","1","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","34067" +"*arp.spoof.*",".{0,1000}arp\.spoof\..{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","34070" +"*arp.spoof.targets*",".{0,1000}arp\.spoof\.targets.{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","34071" +"*arp_spoof.*",".{0,1000}arp_spoof\..{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","34073" +"*ArpSpoofer*",".{0,1000}ArpSpoofer.{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","34075" +"*arsenal_kit.cna*",".{0,1000}arsenal_kit\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","34079" +"*artifact.cna*",".{0,1000}artifact\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","34080" +"*artifact.cna*",".{0,1000}artifact\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","34081" +"*artifact.exe*",".{0,1000}artifact\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","default articfact name generated by cobaltsrike Cobalt Strike is threat emulation software. Execute targeted attacks against modern enterprises with one of the most powerful network attack kits available to penetration testers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","34082" +"*artifact.x64.exe*",".{0,1000}artifact\.x64\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","34083" +"*artifact.x86.dll*",".{0,1000}artifact\.x86\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","34084" +"*artifact.x86.exe*",".{0,1000}artifact\.x86\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","34085" +"*artifact_payload*",".{0,1000}artifact_payload.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","34086" +"*artifact_stageless*",".{0,1000}artifact_stageless.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","34087" +"*artifact_stager*",".{0,1000}artifact_stager.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","34088" +"*artifact32*.exe*",".{0,1000}artifact32.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","34089" +"*artifact32.dll*",".{0,1000}artifact32\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","34090" +"*artifact32.exe*",".{0,1000}artifact32\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","34091" +"*artifact32big.dll*",".{0,1000}artifact32big\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","34092" +"*artifact32big.exe*",".{0,1000}artifact32big\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","34093" +"*artifact32svc.exe*",".{0,1000}artifact32svc\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","34094" +"*artifact32svcbig.exe*",".{0,1000}artifact32svcbig\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","34095" +"*artifact64*.exe*",".{0,1000}artifact64.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","34096" +"*artifact64.dll*",".{0,1000}artifact64\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","34097" +"*artifact64.exe*",".{0,1000}artifact64\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","34098" +"*artifact64.x64.dll*",".{0,1000}artifact64\.x64\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","34099" +"*artifact64big.exe*",".{0,1000}artifact64big\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","34100" +"*artifact64big.x64.dll*",".{0,1000}artifact64big\.x64\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","34101" +"*artifact64svc.exe*",".{0,1000}artifact64svc\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","34102" +"*artifact64svcbig.exe*",".{0,1000}artifact64svcbig\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","34103" +"*artifactbig64.exe*",".{0,1000}artifactbig64\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","default articfact name generated by cobaltsrike Cobalt Strike is threat emulation software. Execute targeted attacks against modern enterprises with one of the most powerful network attack kits available to penetration testers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","34104" +"*artifactuac*.dll*",".{0,1000}artifactuac.{0,1000}\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","34105" +"*aruba2john.py*",".{0,1000}aruba2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","34107" +"*Arvanaghi/SessionGopher*",".{0,1000}Arvanaghi\/SessionGopher.{0,1000}","offensive_tool_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","1","N/A","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","34108" +"*ASBBypass.ps1*",".{0,1000}ASBBypass\.ps1.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1024 - T1071 - T1029 - T1569","TA0002 - TA0003 - TA0040","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","34113" +"*ASBBypass.ps1*",".{0,1000}ASBBypass\.ps1.{0,1000}","offensive_tool_keyword","octopus","Octopus is an open source. pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S.","T1059.001 - T1105 - T1071.001 - T1219 - T1573","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/mhaskar/Octopus","1","1","N/A","N/A","10","10","750","156","2021-07-06T23:52:37Z","2019-08-30T21:09:07Z","34114" +"*ASBBypass.ps1*",".{0,1000}ASBBypass\.ps1.{0,1000}","offensive_tool_keyword","unicorn","Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory","T1059.001 - T1055.012 - T1027.002 - T1547.009","TA0002 - TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/trustedsec/unicorn","1","1","N/A","N/A","N/A","10","3818","816","2024-01-24T20:02:33Z","2013-06-19T08:38:06Z","34115" +"*asp-jinja-obfuscator.py*",".{0,1000}asp\-jinja\-obfuscator\.py.{0,1000}","offensive_tool_keyword","ASPJinjaObfuscator","Heavily obfuscated ASP web shell generation tool.","T1100 - T1027","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/fin3ss3g0d/ASPJinjaObfuscator","1","1","N/A","N/A","8","2","160","21","2024-04-26T01:27:42Z","2024-04-23T01:01:53Z","34123" +"*ASR_bypass_to_dump_LSASS.cs*",".{0,1000}ASR_bypass_to_dump_LSASS\.cs.{0,1000}","offensive_tool_keyword","POSTDump","Another tool to perform minidump of LSASS process using few technics to avoid detection.","T1003 - T1055 - T1562.001 - T1218","TA0005 - TA0003 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","1","#content","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","34124" +"*ASRenum-BOF.*",".{0,1000}ASRenum\-BOF\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF that identifies Attack Surface Reduction (ASR) rules. actions. and exclusion locations","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mlcsec/ASRenum-BOF","1","1","N/A","N/A","10","10","153","17","2024-03-01T14:03:44Z","2022-12-28T14:41:02Z","34125" +"*asrep_attack*",".{0,1000}asrep_attack.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","34126" +"*asrep2kirbi*",".{0,1000}asrep2kirbi.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","34127" +"*asreprc4_attack*",".{0,1000}asreprc4_attack.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","34128" +"*Asreproast.*",".{0,1000}Asreproast\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","34131" +"*ASREPRoast.ps1*",".{0,1000}ASREPRoast\.ps1.{0,1000}","offensive_tool_keyword","ASREPRoast","Project that retrieves crackable hashes from KRB5 AS-REP responses for users without kerberoast preauthentication enabled. ","T1558.003","TA0006","N/A","N/A","Credential Access","https://github.com/HarmJ0y/ASREPRoast","1","1","N/A","N/A","N/A","3","202","58","2018-09-25T03:26:00Z","2017-01-14T21:07:57Z","34132" +"*asreproast_*.txt*",".{0,1000}asreproast_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","34133" +"*asreproast_john_results_*",".{0,1000}asreproast_john_results_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","34134" +"*asreproast_output_*.txt*",".{0,1000}asreproast_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","34135" +"*ASreproasting.txt*",".{0,1000}ASreproasting\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","34137" +"*ASRepToHashcat*",".{0,1000}ASRepToHashcat.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","34139" +"*Assemblies/SharpMove.exe*",".{0,1000}Assemblies\/SharpMove\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike kit for Lateral Movement","T1021.002 - T1021.006 - T1021.004","TA0008 - TA0002","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Lateral Movement","https://github.com/0xthirteen/MoveKit","1","1","N/A","N/A","10","7","666","109","2020-02-21T20:23:45Z","2020-01-24T22:19:16Z","34141" +"*Assets/solution/dllmain.cpp*",".{0,1000}Assets\/solution\/dllmain\.cpp.{0,1000}","offensive_tool_keyword","Spartacus","Spartacus DLL/COM Hijacking Toolkit","T1574.001 - T1055.001 - T1027.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/Accenture/Spartacus","1","1","N/A","N/A","10","10","1037","141","2024-02-01T13:51:09Z","2022-10-28T09:00:35Z","34147" +"*AsStrongAsFuck.exe*",".{0,1000}AsStrongAsFuck\.exe.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","34159" +"*AsStrongAsFuck.py*",".{0,1000}AsStrongAsFuck\.py.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","34160" +"*async_webshell-all.py*",".{0,1000}async_webshell\-all\.py.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoCs - 23 kinds of application password crack - 7000+Web fingerprints - 146 protocols and 90000+ rules Port scanning - Fuzz - HW - awesome BugBounty","T1046 - T1210.001 - T1059 - T1082 - T1110","TA0007 - TA0001 - TA0009 - TA0002 - TA0004 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","34164" +"*AsyncRAT.exe*",".{0,1000}AsyncRAT\.exe.{0,1000}","offensive_tool_keyword","AsyncRAT-C-Sharp","Open-Source Remote Administration Tool For Windows C# (RAT)","T1021.002 - T1056.001 - T1113 - T1133 - T1041 - T1555 - T1129 - T1564.001","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009","N/A","TA2541 - APT-C-36 - Earth Berberoka - Operation Comando - TA558","C2","https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp","1","1","N/A","N/A","10","10","2484","754","2023-10-16T21:41:12Z","2019-01-19T04:02:26Z","34167" +"*AsyncRAT/DCRat*",".{0,1000}AsyncRAT\/DCRat.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","34168" +"*asyncssh_commander.py *",".{0,1000}asyncssh_commander\.py\s.{0,1000}","offensive_tool_keyword","MaccaroniC2","A proof-of-concept Command & Control framework that utilizes the powerful AsyncSSH Python library which provides an asynchronous client and server implementation of the SSHv2 protocol and use PyNgrok wrapper for ngrok integration.","T1090 - T1059.003","TA0011 - TA0002","N/A","N/A","C2","https://github.com/CalfCrusher/MaccaroniC2","1","1","N/A","N/A","10","10","76","16","2023-06-27T17:43:59Z","2023-05-21T13:33:48Z","34169" +"*asyncssh_commander.py*",".{0,1000}asyncssh_commander\.py.{0,1000}","offensive_tool_keyword","MaccaroniC2","A proof-of-concept Command & Control framework that utilizes the powerful AsyncSSH Python library which provides an asynchronous client and server implementation of the SSHv2 protocol and use PyNgrok wrapper for ngrok integration.","T1090 - T1059.003","TA0011 - TA0002","N/A","N/A","C2","https://github.com/CalfCrusher/MaccaroniC2","1","1","N/A","N/A","10","10","76","16","2023-06-27T17:43:59Z","2023-05-21T13:33:48Z","34170" +"*atexec.py*",".{0,1000}atexec\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","34176" +"*Athena.Forwarders.SMB*",".{0,1000}Athena\.Forwarders\.SMB.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","34177" +"*athena/agent_code/*",".{0,1000}athena\/agent_code\/.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","34178" +"*AthenaPlugins.csproj*",".{0,1000}AthenaPlugins\.csproj.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","34179" +"*AtlasC2*APIModels*",".{0,1000}AtlasC2.{0,1000}APIModels.{0,1000}","offensive_tool_keyword","AtlasC2","C# C2 Framework centered around Stage 1 operations","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/Gr1mmie/AtlasC2","1","1","N/A","N/A","10","10","211","41","2022-04-04T16:16:15Z","2021-12-27T01:40:52Z","34193" +"*AtlasC2*Client*",".{0,1000}AtlasC2.{0,1000}Client.{0,1000}","offensive_tool_keyword","AtlasC2","C# C2 Framework centered around Stage 1 operations","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/Gr1mmie/AtlasC2","1","1","N/A","N/A","10","10","211","41","2022-04-04T16:16:15Z","2021-12-27T01:40:52Z","34194" +"*AtlasC2*implant*",".{0,1000}AtlasC2.{0,1000}implant.{0,1000}","offensive_tool_keyword","AtlasC2","C# C2 Framework centered around Stage 1 operations","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/Gr1mmie/AtlasC2","1","1","N/A","N/A","10","10","211","41","2022-04-04T16:16:15Z","2021-12-27T01:40:52Z","34195" +"*AtlasC2*TeamServer*",".{0,1000}AtlasC2.{0,1000}TeamServer.{0,1000}","offensive_tool_keyword","AtlasC2","C# C2 Framework centered around Stage 1 operations","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/Gr1mmie/AtlasC2","1","1","N/A","N/A","10","10","211","41","2022-04-04T16:16:15Z","2021-12-27T01:40:52Z","34196" +"*AtlasC2.exe*",".{0,1000}AtlasC2\.exe.{0,1000}","offensive_tool_keyword","AtlasC2","C# C2 Framework centered around Stage 1 operations","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/Gr1mmie/AtlasC2","1","1","N/A","N/A","10","10","211","41","2022-04-04T16:16:15Z","2021-12-27T01:40:52Z","34197" +"*AtlasC2b.exe*",".{0,1000}AtlasC2b\.exe.{0,1000}","offensive_tool_keyword","AtlasC2","C# C2 Framework centered around Stage 1 operations","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/Gr1mmie/AtlasC2","1","1","N/A","N/A","10","10","211","41","2022-04-04T16:16:15Z","2021-12-27T01:40:52Z","34198" +"*AtlasC2b.sln*",".{0,1000}AtlasC2b\.sln.{0,1000}","offensive_tool_keyword","AtlasC2","C# C2 Framework centered around Stage 1 operations","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/Gr1mmie/AtlasC2","1","1","N/A","N/A","10","10","211","41","2022-04-04T16:16:15Z","2021-12-27T01:40:52Z","34199" +"*AtlasImplant.yar*",".{0,1000}AtlasImplant\.yar.{0,1000}","offensive_tool_keyword","AtlasC2","C# C2 Framework centered around Stage 1 operations","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/Gr1mmie/AtlasC2","1","1","N/A","N/A","10","10","211","41","2022-04-04T16:16:15Z","2021-12-27T01:40:52Z","34200" +"*AtlasReaper.exe*",".{0,1000}AtlasReaper\.exe.{0,1000}","offensive_tool_keyword","AtlasReaper","A command-line tool for reconnaissance and targeted write operations on Confluence and Jira instances.","T1210.002 - T1078.003 - T1046 ","TA0001 - TA0007 - TA0040","N/A","N/A","Reconnaissance","https://github.com/werdhaihai/AtlasReaper","1","1","N/A","N/A","3","3","255","28","2023-09-14T23:50:33Z","2023-06-24T00:18:41Z","34201" +"*AtlasReaper-main*",".{0,1000}AtlasReaper\-main.{0,1000}","offensive_tool_keyword","AtlasReaper","A command-line tool for reconnaissance and targeted write operations on Confluence and Jira instances.","T1210.002 - T1078.003 - T1046 ","TA0001 - TA0007 - TA0040","N/A","N/A","Reconnaissance","https://github.com/werdhaihai/AtlasReaper","1","1","N/A","N/A","3","3","255","28","2023-09-14T23:50:33Z","2023-06-24T00:18:41Z","34202" +"*atmail2john.pl*",".{0,1000}atmail2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","34203" +"*AtomLdr.dll*",".{0,1000}AtomLdr\.dll.{0,1000}","offensive_tool_keyword","AtomLdr","A DLL loader with advanced evasive features","T1071.004 - T1574.001 - T1574.002 - T1071.001 - T1055.003 - T1059.003 - T1546.003 - T1574.003 - T1574.004 - T1059.001 - T1569.002","TA0011 - TA0006 - TA0002 - TA0008 - TA0007","N/A","N/A","Exploitation tool","https://github.com/NUL0x4C/AtomLdr","1","1","N/A","N/A","N/A","8","712","91","2023-02-26T19:57:09Z","2023-02-26T17:59:26Z","34211" +"*AtomLdr.sln*",".{0,1000}AtomLdr\.sln.{0,1000}","offensive_tool_keyword","AtomLdr","A DLL loader with advanced evasive features","T1071.004 - T1574.001 - T1574.002 - T1071.001 - T1055.003 - T1059.003 - T1546.003 - T1574.003 - T1574.004 - T1059.001 - T1569.002","TA0011 - TA0006 - TA0002 - TA0008 - TA0007","N/A","N/A","Exploitation tool","https://github.com/NUL0x4C/AtomLdr","1","1","N/A","N/A","N/A","8","712","91","2023-02-26T19:57:09Z","2023-02-26T17:59:26Z","34212" +"*AtomLdr.vcxproj*",".{0,1000}AtomLdr\.vcxproj.{0,1000}","offensive_tool_keyword","AtomLdr","A DLL loader with advanced evasive features","T1071.004 - T1574.001 - T1574.002 - T1071.001 - T1055.003 - T1059.003 - T1546.003 - T1574.003 - T1574.004 - T1059.001 - T1569.002","TA0011 - TA0006 - TA0002 - TA0008 - TA0007","N/A","N/A","Exploitation tool","https://github.com/NUL0x4C/AtomLdr","1","1","N/A","N/A","N/A","8","712","91","2023-02-26T19:57:09Z","2023-02-26T17:59:26Z","34213" +"*AtomLdr-main.zip*",".{0,1000}AtomLdr\-main\.zip.{0,1000}","offensive_tool_keyword","AtomLdr","A DLL loader with advanced evasive features","T1071.004 - T1574.001 - T1574.002 - T1071.001 - T1055.003 - T1059.003 - T1546.003 - T1574.003 - T1574.004 - T1059.001 - T1569.002","TA0011 - TA0006 - TA0002 - TA0008 - TA0007","N/A","N/A","Exploitation tool","https://github.com/NUL0x4C/AtomLdr","1","1","N/A","N/A","N/A","8","712","91","2023-02-26T19:57:09Z","2023-02-26T17:59:26Z","34214" +"*ATPMiniDump*",".{0,1000}ATPMiniDump.{0,1000}","offensive_tool_keyword","ATPMiniDump","Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis","T1003 - T1005 - T1055 - T1218","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/b4rtik/ATPMiniDump","1","1","N/A","N/A","N/A","3","255","46","2019-12-02T15:01:22Z","2019-11-29T19:49:54Z","34215" +"*Attack_AmsiOpenSession.ps1*",".{0,1000}Attack_AmsiOpenSession\.ps1.{0,1000}","offensive_tool_keyword","Amsi_Bypass","Amsi Bypass payload that works on Windwos 11","T1055 - T1055.012 - T1562 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/senzee1984/Amsi_Bypass_In_2023","1","1","N/A","N/A","8","4","377","67","2023-07-30T19:17:23Z","2023-07-30T16:14:19Z","34220" +"*Attack_AmsiScanBuffer.ps1*",".{0,1000}Attack_AmsiScanBuffer\.ps1.{0,1000}","offensive_tool_keyword","Amsi_Bypass","Amsi Bypass payload that works on Windwos 11","T1055 - T1055.012 - T1562 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/senzee1984/Amsi_Bypass_In_2023","1","1","N/A","N/A","8","4","377","67","2023-07-30T19:17:23Z","2023-07-30T16:14:19Z","34221" +"*AttackerSetup(windows).exe*",".{0,1000}AttackerSetup\(windows\)\.exe.{0,1000}","offensive_tool_keyword","windows-login-phish","Windows Login Phishing page This is a windows maching login page designed using HTML CSS and JS. This can be used for red teaming or cybersecurity awareness related purposes","T1566","N/A","N/A","N/A","Phishing","https://github.com/CipherKill/windows-login-phish","1","1","N/A","N/A","N/A","1","17","6","2022-03-25T05:49:01Z","2022-03-13T20:02:15Z","34224" +"*AttackerSetup.py*",".{0,1000}AttackerSetup\.py.{0,1000}","offensive_tool_keyword","windows-login-phish","Windows Login Phishing page This is a windows maching login page designed using HTML CSS and JS. This can be used for red teaming or cybersecurity awareness related purposes","T1566","N/A","N/A","N/A","Phishing","https://github.com/CipherKill/windows-login-phish","1","1","N/A","N/A","N/A","1","17","6","2022-03-25T05:49:01Z","2022-03-13T20:02:15Z","34225" +"*AttackerSetup4linux*",".{0,1000}AttackerSetup4linux.{0,1000}","offensive_tool_keyword","windows-login-phish","Windows Login Phishing page This is a windows maching login page designed using HTML CSS and JS. This can be used for red teaming or cybersecurity awareness related purposes","T1566","N/A","N/A","N/A","Phishing","https://github.com/CipherKill/windows-login-phish","1","1","#linux","N/A","N/A","1","17","6","2022-03-25T05:49:01Z","2022-03-13T20:02:15Z","34226" +"*AttackSurfaceMapper-master*",".{0,1000}AttackSurfaceMapper\-master.{0,1000}","offensive_tool_keyword","AttackSurfaceMapper","AttackSurfaceMapper (ASM) is a reconnaissance tool that uses a mixture of open source intelligence and active techniques to expand the attack surface of your target","T1595 - T1596","TA0043","N/A","N/A","Reconnaissance","https://github.com/superhedgy/AttackSurfaceMapper","1","1","N/A","N/A","6","10","1355","197","2024-04-08T16:13:24Z","2019-08-07T14:32:53Z","34228" +"*AttackTeamFamily*-bof-toolset*",".{0,1000}AttackTeamFamily.{0,1000}\-bof\-toolset.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/AttackTeamFamily/cobaltstrike-bof-toolset","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","34229" +"*au.mirrors.cicku.me/blackarch/*/os/*",".{0,1000}au\.mirrors\.cicku\.me\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","34249" +"*Augustus-main.zip*",".{0,1000}Augustus\-main\.zip.{0,1000}","offensive_tool_keyword","Augustus","Augustus is a Golang loader that execute shellcode utilizing the process hollowing technique with anti-sandbox and anti-analysis measures. The shellcode is encrypted with the Triple DES (3DES) encryption algorithm.","T1055.012 - T1027.002 - T1136.001 - T1562.001","TA0005 - TA0002 - TA0003","N/A","N/A","Exploitation tool","https://github.com/TunnelGRE/Augustus","1","1","N/A","N/A","6","2","131","26","2024-07-27T14:47:45Z","2023-08-21T15:08:40Z","34257" +"*ausecwa/bof-registry*",".{0,1000}ausecwa\/bof\-registry.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike beacon object file that allows you to query and make changes to the Windows Registry","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ausecwa/bof-registry","1","1","N/A","N/A","10","10","27","8","2021-02-11T04:38:28Z","2021-01-29T05:07:47Z","34258" +"*auth.dev.pico.sh*",".{0,1000}auth\.dev\.pico\.sh.{0,1000}","offensive_tool_keyword","pico","hacker labs - open source and managed web services leveraging SSH","T1021.005 - T1078 - T1105 - T1109 - T1197 - T1213","TA0005 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/picosh/pico","1","1","N/A","N/A","10","10","1129","36","2025-04-22T17:33:17Z","2022-08-24T03:14:52Z","34260" +"*auth/cc2_ssh.*",".{0,1000}auth\/cc2_ssh\..{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","34261" +"*auto_brute.rc*",".{0,1000}auto_brute\.rc.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","34269" +"*auto_exploit_blank_password*",".{0,1000}auto_exploit_blank_password.{0,1000}","offensive_tool_keyword","pxethief","PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager","T1555.004 - T1555.002","TA0006","N/A","N/A","Credential Access","https://github.com/MWR-CyberSec/PXEThief","1","1","N/A","N/A","N/A","4","368","57","2024-05-29T15:07:15Z","2022-08-12T22:16:46Z","34270" +"*auto_pass_the_hash.*",".{0,1000}auto_pass_the_hash\..{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","34271" +"*auto_pass_the_hash.rc*",".{0,1000}auto_pass_the_hash\.rc.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","34272" +"*auto_target_linux.rb*",".{0,1000}auto_target_linux\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","#linux","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","34273" +"*auto_target_windows.rb*",".{0,1000}auto_target_windows\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","34274" +"*autobloody.py*",".{0,1000}autobloody\.py.{0,1000}","offensive_tool_keyword","autobloody","Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound","T1078 - T1078.003 - T1021 - T1021.006 - T1076.001","TA0005 - TA0001 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/CravateRouge/autobloody","1","1","#linux","N/A","10","6","545","54","2024-11-14T13:07:54Z","2022-09-07T13:34:30Z","34276" +"*autobloody-main*",".{0,1000}autobloody\-main.{0,1000}","offensive_tool_keyword","autobloody","Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound","T1078 - T1078.003 - T1021 - T1021.006 - T1076.001","TA0005 - TA0001 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/CravateRouge/autobloody","1","1","#linux","N/A","10","6","545","54","2024-11-14T13:07:54Z","2022-09-07T13:34:30Z","34277" +"*AutoBypass.ps1*",".{0,1000}AutoBypass\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","34278" +"*AutoC2.sh*",".{0,1000}AutoC2\.sh.{0,1000}","offensive_tool_keyword","AutoC2","AutoC2 is a bash script written to install all of the red team tools that you know and love","T1059.004 - T1129 - T1486","TA0005 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/assume-breach/Home-Grown-Red-Team/tree/main/AutoC2","1","1","N/A","N/A","10","8","707","112","2024-03-22T12:32:22Z","2022-03-23T15:52:41Z","34279" +"*AutoC2/C2*",".{0,1000}AutoC2\/C2.{0,1000}","offensive_tool_keyword","AutoC2","AutoC2 is a bash script written to install all of the red team tools that you know and love","T1059.004 - T1129 - T1486","TA0005 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/assume-breach/Home-Grown-Red-Team/tree/main/AutoC2","1","1","N/A","N/A","10","8","707","112","2024-03-22T12:32:22Z","2022-03-23T15:52:41Z","34281" +"*AutoC2/Dependencies*",".{0,1000}AutoC2\/Dependencies.{0,1000}","offensive_tool_keyword","AutoC2","AutoC2 is a bash script written to install all of the red team tools that you know and love","T1059.004 - T1129 - T1486","TA0005 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/assume-breach/Home-Grown-Red-Team/tree/main/AutoC2","1","1","N/A","N/A","10","8","707","112","2024-03-22T12:32:22Z","2022-03-23T15:52:41Z","34282" +"*AutoC2/Initial_Access*",".{0,1000}AutoC2\/Initial_Access.{0,1000}","offensive_tool_keyword","AutoC2","AutoC2 is a bash script written to install all of the red team tools that you know and love","T1059.004 - T1129 - T1486","TA0005 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/assume-breach/Home-Grown-Red-Team/tree/main/AutoC2","1","1","N/A","N/A","10","8","707","112","2024-03-22T12:32:22Z","2022-03-23T15:52:41Z","34283" +"*AutoC2/Payload_Development*",".{0,1000}AutoC2\/Payload_Development.{0,1000}","offensive_tool_keyword","AutoC2","AutoC2 is a bash script written to install all of the red team tools that you know and love","T1059.004 - T1129 - T1486","TA0005 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/assume-breach/Home-Grown-Red-Team/tree/main/AutoC2","1","1","N/A","N/A","10","8","707","112","2024-03-22T12:32:22Z","2022-03-23T15:52:41Z","34285" +"*AutoC2/Recon*",".{0,1000}AutoC2\/Recon.{0,1000}","offensive_tool_keyword","AutoC2","AutoC2 is a bash script written to install all of the red team tools that you know and love","T1059.004 - T1129 - T1486","TA0005 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/assume-breach/Home-Grown-Red-Team/tree/main/AutoC2","1","1","N/A","N/A","10","8","707","112","2024-03-22T12:32:22Z","2022-03-23T15:52:41Z","34286" +"*AutoC2/Situational_Awareness*",".{0,1000}AutoC2\/Situational_Awareness.{0,1000}","offensive_tool_keyword","AutoC2","AutoC2 is a bash script written to install all of the red team tools that you know and love","T1059.004 - T1129 - T1486","TA0005 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/assume-breach/Home-Grown-Red-Team/tree/main/AutoC2","1","1","N/A","N/A","10","8","707","112","2024-03-22T12:32:22Z","2022-03-23T15:52:41Z","34287" +"*AutoC2/Staging*",".{0,1000}AutoC2\/Staging.{0,1000}","offensive_tool_keyword","AutoC2","AutoC2 is a bash script written to install all of the red team tools that you know and love","T1059.004 - T1129 - T1486","TA0005 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/assume-breach/Home-Grown-Red-Team/tree/main/AutoC2","1","1","N/A","N/A","10","8","707","112","2024-03-22T12:32:22Z","2022-03-23T15:52:41Z","34289" +"*AutoC2/Wordlists*",".{0,1000}AutoC2\/Wordlists.{0,1000}","offensive_tool_keyword","AutoC2","AutoC2 is a bash script written to install all of the red team tools that you know and love","T1059.004 - T1129 - T1486","TA0005 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/assume-breach/Home-Grown-Red-Team/tree/main/AutoC2","1","1","N/A","N/A","10","8","707","112","2024-03-22T12:32:22Z","2022-03-23T15:52:41Z","34292" +"*AutoCompletionHandlerC2ServerManager*",".{0,1000}AutoCompletionHandlerC2ServerManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","34293" +"*autodiscover/brute.go*",".{0,1000}autodiscover\/brute\.go.{0,1000}","offensive_tool_keyword","ruler","A tool to abuse Exchange services","T1087 - T1110 - T1133 - T1064 - T1204","TA0007 - TA0006 - TA0003 - TA0002 - TA0005","N/A","APT33","Persistence","https://github.com/sensepost/ruler","1","1","N/A","N/A","10","10","2222","362","2024-06-10T11:03:07Z","2016-08-18T15:05:13Z","34295" +"*autoexploit.rc*",".{0,1000}autoexploit\.rc.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","34296" +"*autokerberoast.ps1*",".{0,1000}autokerberoast\.ps1.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/xan7r/kerberoast","1","1","N/A","N/A","N/A","1","73","18","2017-07-22T22:28:12Z","2016-06-08T22:58:45Z","34302" +"*autokerberoast_noMimikatz.ps1",".{0,1000}autokerberoast_noMimikatz\.ps1","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/xan7r/kerberoast","1","1","N/A","N/A","N/A","1","73","18","2017-07-22T22:28:12Z","2016-06-08T22:58:45Z","34303" +"*autoKirbi2hashcat.py*",".{0,1000}autoKirbi2hashcat\.py.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/xan7r/kerberoast","1","1","N/A","N/A","N/A","1","73","18","2017-07-22T22:28:12Z","2016-06-08T22:58:45Z","34304" +"*autolace.twilightparadox.com*",".{0,1000}autolace\.twilightparadox\.com.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","34305" +"*automachine.servequake.com*",".{0,1000}automachine\.servequake\.com.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","34306" +"*AutoNSE*",".{0,1000}AutoNSE.{0,1000}","offensive_tool_keyword","autonse","Massive NSE (Nmap Scripting Engine) AutoSploit and AutoScanner. The Nmap Scripting Engine (NSE) is one of Nmaps most powerful and flexible features. It allows users to write (and share) simple scripts (using the Lua programming language ) to automate a wide variety of networking tasks. Those scripts are executed in parallel with the speed and efficiency you expect from Nmap. Users can rely on the growing and diverse set of scripts distributed with Nmap. or write their own to meet custom needs. For more informations https://nmap.org/book/man-nse.html","T1059.001 - T1059.003 - T1059.005 - T1059.006 - T1027 - T1064 - T1086 - T1085","TA0002 - TA0003 - TA0009","N/A","N/A","Exploitation tool","https://github.com/m4ll0k/AutoNSE","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","34307" +"*autopwn*",".{0,1000}autopwn.{0,1000}","offensive_tool_keyword","autopwn","tools for pentester. autopwn is designed to make a pentesters life easier and more consistent by allowing them to specify tools they would like to run against targets. without having to type them in a shell or write a script. This tool will probably be useful during certain exams as well..","T1583 - T1059 - T1216 - T1053 - T1027","TA0002 - TA0008 - TA0003","N/A","N/A","Exploitation tool","https://github.com/nccgroup/autopwn","1","1","N/A","N/A","N/A","4","389","89","2019-04-23T09:58:28Z","2015-02-23T08:18:01Z","34308" +"*AutoPwnKey-agent*",".{0,1000}AutoPwnKey\-agent.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","34312" +"*AutoPwnKey-server*",".{0,1000}AutoPwnKey\-server.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","34313" +"*AutoPwnKey-server/logs*",".{0,1000}AutoPwnKey\-server\/logs.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","34314" +"*AutoRDPwn*",".{0,1000}AutoRDPwn.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","34315" +"*AutoRDPwn.ps1*",".{0,1000}AutoRDPwn\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","34316" +"*AutoSmuggle.csproj*",".{0,1000}AutoSmuggle\.csproj.{0,1000}","offensive_tool_keyword","AutoSmuggle","Utility to craft HTML or SVG smuggled files for Red Team engagements","T1027.006 - T1598","TA0005 - TA0043","N/A","N/A","Defense Evasion","https://github.com/surajpkhetani/AutoSmuggle","1","1","N/A","N/A","9","3","240","26","2024-03-19T09:26:49Z","2022-03-20T19:02:06Z","34319" +"*AutoSmuggle.exe*",".{0,1000}AutoSmuggle\.exe.{0,1000}","offensive_tool_keyword","AutoSmuggle","Utility to craft HTML or SVG smuggled files for Red Team engagements","T1027.006 - T1598","TA0005 - TA0043","N/A","N/A","Defense Evasion","https://github.com/surajpkhetani/AutoSmuggle","1","1","N/A","N/A","9","3","240","26","2024-03-19T09:26:49Z","2022-03-20T19:02:06Z","34320" +"*AutoSmuggle.sln*",".{0,1000}AutoSmuggle\.sln.{0,1000}","offensive_tool_keyword","AutoSmuggle","Utility to craft HTML or SVG smuggled files for Red Team engagements","T1027.006 - T1598","TA0005 - TA0043","N/A","N/A","Defense Evasion","https://github.com/surajpkhetani/AutoSmuggle","1","1","N/A","N/A","9","3","240","26","2024-03-19T09:26:49Z","2022-03-20T19:02:06Z","34321" +"*AutoSmuggle-master*",".{0,1000}AutoSmuggle\-master.{0,1000}","offensive_tool_keyword","AutoSmuggle","Utility to craft HTML or SVG smuggled files for Red Team engagements","T1027.006 - T1598","TA0005 - TA0043","N/A","N/A","Defense Evasion","https://github.com/surajpkhetani/AutoSmuggle","1","1","N/A","N/A","9","3","240","26","2024-03-19T09:26:49Z","2022-03-20T19:02:06Z","34322" +"*AutoSUID-main.*",".{0,1000}AutoSUID\-main\..{0,1000}","offensive_tool_keyword","AutoSUID","automate harvesting the SUID executable files and to find a way for further escalating the privileges","T1548.003 - T1069.001 - T1068","TA0004 - TA0003 - TA0005","N/A","N/A","Discovery","https://github.com/IvanGlinkin/AutoSUID","1","1","N/A","N/A","7","4","375","77","2024-04-29T12:30:35Z","2021-11-28T19:44:18Z","34324" +"*autoTGS_NtlmCrack.py*",".{0,1000}autoTGS_NtlmCrack\.py.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/xan7r/kerberoast","1","1","N/A","N/A","N/A","1","73","18","2017-07-22T22:28:12Z","2016-06-08T22:58:45Z","34325" +"*aux/dump_credentials*",".{0,1000}aux\/dump_credentials.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","34328" +"*aux/enum_system.rc*",".{0,1000}aux\/enum_system\.rc.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","34329" +"*aux/msf/*",".{0,1000}aux\/msf\/.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","34330" +"*aux/persistence.rc",".{0,1000}aux\/persistence\.rc","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","34331" +"*aux/privilege_escalation.*",".{0,1000}aux\/privilege_escalation\..{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","34332" +"*aux/Start-Webserver.ps1*",".{0,1000}aux\/Start\-Webserver\.ps1.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","34333" +"*auxiliary/crawler*",".{0,1000}auxiliary\/crawler.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","34334" +"*auxiliary/sqli/*",".{0,1000}auxiliary\/sqli\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","34335" +"*av_hips_executables.txt*",".{0,1000}av_hips_executables\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","34336" +"*avaddonbotrxmuyl.onion*",".{0,1000}avaddonbotrxmuyl\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","34337" +"*avaddongun7rngel.onion*",".{0,1000}avaddongun7rngel\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","34338" +"*avast_memory_dump.md*",".{0,1000}avast_memory_dump\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","34340" +"*avet-master.zip*",".{0,1000}avet\-master\.zip.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","34342" +"*avosjon4pfh3y7ew3jdwz6ofw7lljcxlbk7hcxxmnxlh5kvf2akcqjad.onion*",".{0,1000}avosjon4pfh3y7ew3jdwz6ofw7lljcxlbk7hcxxmnxlh5kvf2akcqjad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","34344" +"*avosqxh72b5ia23dl5fgwcpndkctuzqvh2iefk5imp3pi5gfhel5klad.onion*",".{0,1000}avosqxh72b5ia23dl5fgwcpndkctuzqvh2iefk5imp3pi5gfhel5klad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","34345" +"*avred-main.zip*",".{0,1000}avred\-main\.zip.{0,1000}","offensive_tool_keyword","avred","Avred is being used to identify which parts of a file are identified by a Antivirus and tries to show as much possible information and context about each match.","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/dobin/avred","1","1","N/A","N/A","9","5","465","55","2025-02-26T08:12:03Z","2022-05-19T12:12:34Z","34347" +"*av-update-urls.txt*",".{0,1000}av\-update\-urls\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","34348" +"*awesome-cve-poc*",".{0,1000}awesome\-cve\-poc.{0,1000}","offensive_tool_keyword","POC","list of poc exploitation for nown CVE","T1210 - T1583 - T1586 - T1589 - T1596","TA0002 - TA0011 - TA0007","N/A","N/A","Exploitation tool","https://github.com/qazbnm456/awesome-cve-poc","1","1","N/A","N/A","N/A","10","3390","725","2022-01-04T19:07:43Z","2017-02-02T06:43:14Z","34372" +"*Awesome-Hacking*",".{0,1000}Awesome\-Hacking.{0,1000}","offensive_tool_keyword","Awesome-Hacking","A collection of awesome lists for hackers. pentesters & security researchers.","T1566 - T1590 - T1204 - T1210 - T1212 - T1213","TA0002 - TA0003 - TA0008 - TA0009","N/A","N/A","Exploitation tool","https://github.com/Hack-with-Github/Awesome-Hacking","1","1","N/A","N/A","N/A","10","91563","9230","2025-01-18T01:48:02Z","2016-03-30T15:47:10Z","34373" +"*Awesome-Hacking-Resources*",".{0,1000}Awesome\-Hacking\-Resources.{0,1000}","offensive_tool_keyword","Awesome-Hacking-Resources","A collection of hacking / penetration testing resources to make you better!","T1593 - T1594 - T1595 - T1567","TA0007 - TA0009 - TA0004","N/A","N/A","Exploitation tool","https://github.com/vitalysim/Awesome-Hacking-Resources","1","1","N/A","N/A","N/A","10","15815","2139","2024-03-12T00:19:30Z","2017-10-10T19:09:18Z","34374" +"*awesome-osint*",".{0,1000}awesome\-osint.{0,1000}","offensive_tool_keyword","awesome-osint","A curated list of amazingly awesome open source intelligence tools and resources. Open-source intelligence (OSINT) is intelligence collected from publicly available sources. In the intelligence community (IC). the term open refers to overt. publicly available sources (as opposed to covert or clandestine sources)","T1593 - T1594 - T1595 - T1567","TA0007 - TA0009 - TA0004","N/A","N/A","Reconnaissance","https://github.com/jivoi/awesome-osint","1","1","N/A","N/A","N/A","10","21018","3021","2025-04-20T17:31:01Z","2016-11-30T13:26:11Z","34375" +"*awesome-pentest*",".{0,1000}awesome\-pentest.{0,1000}","offensive_tool_keyword","awesome-pentest","A collection of awesome penetration testing and offensive cybersecurity resources.","T1200 - T1210 - T1213 - T1583 - T1589","TA0003 - TA0009","N/A","N/A","Exploitation tool","https://github.com/enaqx/awesome-pentest","1","1","N/A","N/A","N/A","10","22911","4542","2024-12-14T12:02:31Z","2014-08-03T23:13:53Z","34376" +"*awesome-scapy*",".{0,1000}awesome\-scapy.{0,1000}","offensive_tool_keyword","awesome-scapy","A Python tool and library for low level packet creation and manipulation","T1571 - T1596 - T1567 - T1569","TA0002 - TA0009 - TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/secdev/awesome-scapy","1","1","N/A","N/A","N/A","3","277","42","2024-08-29T09:42:39Z","2020-02-04T12:17:35Z","34378" +"*awesome-web-security*",".{0,1000}awesome\-web\-security.{0,1000}","offensive_tool_keyword","awesome-web-security","Curated list of Web Security materials and resources.Needless to say. most websites suffer from various types of bugs which may eventually lead to vulnerabilities. Why would this happen so often? There can be many factors involved including misconfiguration. shortage of engineers' security skills. etc. To combat this. here is a curated list of Web Security materials and resources for learning cutting edge penetration techniques. and I highly encourage you to read this article So you want to be a web security researcher? first","T1190 - T1191 - T1192 - T1210 - T1213","TA0002 - TA0003 - TA0007","N/A","N/A","Vulnerability Scanner","https://github.com/qazbnm456/awesome-web-security","1","1","N/A","N/A","N/A","10","11873","1696","2024-02-22T00:28:07Z","2017-01-29T16:50:21Z","34380" +"*awk_reverse_tcp.py*",".{0,1000}awk_reverse_tcp\.py.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","34383" +"*axcrypt2john.py*",".{0,1000}axcrypt2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","34389" +"*aydinnyunus/PassDetective*",".{0,1000}aydinnyunus\/PassDetective.{0,1000}","offensive_tool_keyword","PassDetective","PassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords - API keys and secrets","T1059 - T1059.004 - T1552 - T1552.001","TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/aydinnyunus/PassDetective","1","1","N/A","N/A","7","2","129","8","2024-06-19T10:39:39Z","2023-07-22T12:31:57Z","34390" +"*Azure-AccessPermissions.ps1*",".{0,1000}Azure\-AccessPermissions\.ps1.{0,1000}","offensive_tool_keyword","Azure-AccessPermissions","Easy to use PowerShell script to enumerate access permissions in an Azure Active Directory environment.","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/csandker/Azure-AccessPermissions","1","1","N/A","AD Enumeration","6","2","108","18","2023-02-21T06:46:24Z","2022-10-19T10:33:24Z","34394" +"*Azure-AccessPermissions-master*",".{0,1000}Azure\-AccessPermissions\-master.{0,1000}","offensive_tool_keyword","Azure-AccessPermissions","Easy to use PowerShell script to enumerate access permissions in an Azure Active Directory environment.","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/csandker/Azure-AccessPermissions","1","1","N/A","AD Enumeration","6","2","108","18","2023-02-21T06:46:24Z","2022-10-19T10:33:24Z","34395" +"*AzureAD_Autologon_Brute*",".{0,1000}AzureAD_Autologon_Brute.{0,1000}","offensive_tool_keyword","AzureAD_Autologon_Brute","Brute force attack tool for Azure AD Autologon","T1110 - T1078 - T1114 - T1087","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/AzureAD_Autologon_Brute","1","1","N/A","N/A","N/A","2","101","20","2024-06-27T12:23:42Z","2021-10-01T05:20:25Z","34397" +"*AzureAD_Decrypt_MSOL.ps1*",".{0,1000}AzureAD_Decrypt_MSOL\.ps1.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","N/A","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","34398" +"*azuread_decrypt_msol_*.ps1*",".{0,1000}azuread_decrypt_msol_.{0,1000}\.ps1.{0,1000}","offensive_tool_keyword","powershell","method of dumping the MSOL service account (which allows a DCSync) used by Azure AD Connect Sync","T1003.006","TA0006","N/A","N/A","Credential Access","https://gist.github.com/analyticsearch/7453d22d737e46657eb57c44d5cf4cbb","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","34399" +"*AzureADLateralMovement*",".{0,1000}AzureADLateralMovement.{0,1000}","offensive_tool_keyword","AzureADLateralMovement","AzureADLateralMovement allows to build Lateral Movement graph for Azure Active Directory entities - Users. Computers. Groups and Roles. Using the Microsoft Graph API AzureADLateralMovement extracts interesting information and builds json files containing Lateral Movement graph data compatible with Bloodhound 2.2.0","T1074 - T1075 - T1076","TA0008 - TA0009 - TA0010","N/A","N/A","Lateral Movement","https://github.com/talmaor/AzureADLateralMovement","1","1","N/A","N/A","N/A","2","122","22","2022-12-08T06:44:48Z","2019-06-22T06:13:28Z","34401" +"*AzureADRecon.ps1*",".{0,1000}AzureADRecon\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","34402" +"*AzureC2Relay.zip*",".{0,1000}AzureC2Relay\.zip.{0,1000}","offensive_tool_keyword","AzureC2Relay","AzureC2Relay is an Azure Function that validates and relays Cobalt Strike beacon traffic by verifying the incoming requests based on a Cobalt Strike Malleable C2 profile.","T1090 - T1090.003 - T1027 - T1027.005 - T1071 - T1071.001","TA0042 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/Flangvik/AzureC2Relay","1","1","N/A","N/A","10","10","220","49","2021-02-15T18:06:38Z","2021-02-14T00:03:52Z","34403" +"*AzureC2Relay-main*",".{0,1000}AzureC2Relay\-main.{0,1000}","offensive_tool_keyword","AzureC2Relay","AzureC2Relay is an Azure Function that validates and relays Cobalt Strike beacon traffic by verifying the incoming requests based on a Cobalt Strike Malleable C2 profile.","T1090 - T1090.003 - T1027 - T1027.005 - T1071 - T1071.001","TA0042 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/Flangvik/AzureC2Relay","1","1","N/A","N/A","10","10","220","49","2021-02-15T18:06:38Z","2021-02-14T00:03:52Z","34404" +"*b23r0/cliws*",".{0,1000}b23r0\/cliws.{0,1000}","offensive_tool_keyword","cliws","Cross platform interactive bind/reverse PTY shell","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","Dispossessor","C2","https://github.com/b23r0/cliws","1","1","N/A","N/A","10","10","159","29","2023-11-06T02:19:16Z","2021-10-24T04:10:07Z","34542" +"*b23r0/Heroinn*",".{0,1000}b23r0\/Heroinn.{0,1000}","offensive_tool_keyword","Heroinn","A cross platform C2/post-exploitation framework implementation by Rust.","T1059 - T1547 - T1068 - T1562 - T1110 - T1083 - T1021 - T1071","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/b23r0/Heroinn","1","1","N/A","N/A","10","10","672","215","2022-10-08T07:27:38Z","2015-05-16T14:54:19Z","34543" +"*b23r0/Heroinn*",".{0,1000}b23r0\/Heroinn.{0,1000}","offensive_tool_keyword","Heroinn","A cross platform C2/post-exploitation framework implementation by Rust.","T1027 - T1033 - T1055 - T1071 - T1082 - T1105 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/b23r0/Heroinn","1","1","N/A","N/A","10","10","672","215","2022-10-08T07:27:38Z","2015-05-16T14:54:19Z","34544" +"*b23r0/rsocx*",".{0,1000}b23r0\/rsocx.{0,1000}","offensive_tool_keyword","rsocx","A bind/reverse Socks5 proxy server.","T1090.001 - T1090.002 - T1071.001","TA0011 - TA0009 - TA0040","N/A","Dispossessor - Scattered Spider*","C2","https://github.com/b23r0/rsocx","1","1","N/A","N/A","10","10","381","139","2022-09-28T08:11:34Z","2015-05-13T04:02:55Z","34545" +"*b2xtranslator.xls.csproj*",".{0,1000}b2xtranslator\.xls\.csproj.{0,1000}","offensive_tool_keyword","Macrome","An Excel Macro Document Reader/Writer for Red Teamers & Analysts. Blog posts describing what this tool actually does can be found https://malware.pizza/2020/05/12/evading-av-with-excel-macros-and-biff8-xls/ and https://malware.pizza/2020/06/19/further-evasion-in-the-forgotten-corners-of-ms-xls/","T1140","TA0005","N/A","N/A","Exploitation tool","https://github.com/michaelweber/Macrome","1","1","N/A","N/A","N/A","6","520","79","2022-02-01T16:26:13Z","2020-05-07T22:44:11Z","34604" +"*b3rito*yodo*",".{0,1000}b3rito.{0,1000}yodo.{0,1000}","offensive_tool_keyword","yodo","This tool proves how easy it is to become root via limited sudo permissions. via dirty COW or using Pa(th)zuzu. ","T1068 - T1078 - T1529","TA0004 - TA0008","N/A","N/A","Exploitation tool","https://github.com/b3rito/yodo","1","1","N/A","N/A","N/A","3","207","22","2017-02-28T15:38:13Z","2016-11-13T21:02:03Z","34672" +"*b4rtik/ATPMiniDump*",".{0,1000}b4rtik\/ATPMiniDump.{0,1000}","offensive_tool_keyword","ATPMiniDump","Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis","T1003 - T1005 - T1055 - T1218","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/b4rtik/ATPMiniDump","1","1","N/A","N/A","N/A","3","255","46","2019-12-02T15:01:22Z","2019-11-29T19:49:54Z","34747" +"*b4rtik/RedPeanut*",".{0,1000}b4rtik\/RedPeanut.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","34748" +"*b4rtik/RedPeanut*",".{0,1000}b4rtik\/RedPeanut.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1095 - T1071.004","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","34749" +"*b4rtik/SharpMiniDump*",".{0,1000}b4rtik\/SharpMiniDump.{0,1000}","offensive_tool_keyword","SharpMiniDump","Create a minidump of the LSASS process from memory","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/b4rtik/SharpMiniDump","1","1","N/A","N/A","10","3","260","49","2022-11-02T15:47:30Z","2019-09-15T13:45:42Z","34750" +"*B64_ENCODED_PAYLOAD_UUID*",".{0,1000}B64_ENCODED_PAYLOAD_UUID.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","34839" +"*b64payloadgen.sh*",".{0,1000}b64payloadgen\.sh.{0,1000}","offensive_tool_keyword","POC","exploitation of CVE-2021-4034","T1210","N/A","N/A","N/A","Exploitation tool","https://github.com/luijait/PwnKit-Exploit","1","1","N/A","N/A","N/A","1","96","14","2022-02-07T15:42:00Z","2022-01-26T18:01:26Z","34844" +"*BabelStrike-main*",".{0,1000}BabelStrike\-main.{0,1000}","offensive_tool_keyword","BabelStrike","The purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin)","T1078 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/t3l3machus/BabelStrike","1","1","N/A","N/A","1","2","132","23","2024-07-19T07:02:42Z","2023-01-10T07:59:00Z","35147" +"*backdoor.asp*",".{0,1000}backdoor\.asp.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","35163" +"*backdoor.aspx*",".{0,1000}backdoor\.aspx.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","35169" +"*backdoor.jsp*",".{0,1000}backdoor\.jsp.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","35171" +"*backdoor.php*",".{0,1000}backdoor\.php.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","35178" +"*backdoor/traitor.go*",".{0,1000}backdoor\/traitor\.go.{0,1000}","offensive_tool_keyword","traitor","Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy","T1068 - T1548.004 - T1611 - T1203 - T1059.004","TA0004 - TA0001 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/liamg/traitor","1","1","#linux","N/A","10","10","6853","651","2024-03-12T21:01:14Z","2021-01-24T10:50:15Z","35184" +"*BackdoorableScript*",".{0,1000}BackdoorableScript.{0,1000}","offensive_tool_keyword","boko","boko.py is an application scanner for macOS that searches for and identifies potential dylib hijacking and weak dylib vulnerabilities for application executables as well as scripts an application may use that have the potential to be backdoored","T1195 - T1078 - T1079 - T1574","TA0006 - TA0008","N/A","N/A","Exploitation tool","https://github.com/bashexplode/boko","1","1","N/A","N/A","N/A","1","71","13","2021-09-28T22:36:01Z","2020-05-22T21:46:33Z","35204" +"*BackdoorLNK*",".{0,1000}BackdoorLNK.{0,1000}","offensive_tool_keyword","StayKit","StayKit - Cobalt Strike persistence kit - StayKit is an extension for Cobalt Strike persistence by leveraging the execute_assembly function with the SharpStay .NET assembly. The aggressor script handles payload creation by reading the template files for a specific execution type.","T1059 - T1053 - T1124","TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/0xthirteen/StayKit","1","1","N/A","N/A","N/A","10","475","73","2020-01-27T14:53:31Z","2020-01-24T22:20:20Z","35208" +"*backdoorlnkdialog*",".{0,1000}backdoorlnkdialog.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike kit for Persistence","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/0xthirteen/StayKit","1","1","N/A","N/A","10","10","475","73","2020-01-27T14:53:31Z","2020-01-24T22:20:20Z","35209" +"*backstab.exe*",".{0,1000}backstab\.exe.{0,1000}","offensive_tool_keyword","Backstab","A tool to kill antimalware protected processes","T1562.001 - T1569 - T1059","TA0005 - TA0040 - TA0002","N/A","Black Basta - LockBit","Defense Evasion","https://github.com/Yaxser/Backstab","1","1","N/A","N/A","10","10","1435","244","2021-06-19T20:01:52Z","2021-06-15T16:02:11Z","35210" +"*Backstab.sln*",".{0,1000}Backstab\.sln.{0,1000}","offensive_tool_keyword","Backstab","A tool to kill antimalware protected processes","T1562.001 - T1569 - T1059","TA0005 - TA0040 - TA0002","N/A","Black Basta - LockBit","Defense Evasion","https://github.com/Yaxser/Backstab","1","1","N/A","N/A","10","10","1435","244","2021-06-19T20:01:52Z","2021-06-15T16:02:11Z","35211" +"*backstab.x64.*",".{0,1000}backstab\.x64\..{0,1000}","offensive_tool_keyword","cobaltstrike","BOF combination of KillDefender and Backstab","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Octoberfest7/KDStab","1","1","N/A","N/A","10","10","167","37","2023-03-23T02:22:50Z","2022-03-10T06:09:52Z","35212" +"*backstab.x86.*",".{0,1000}backstab\.x86\..{0,1000}","offensive_tool_keyword","cobaltstrike","BOF combination of KillDefender and Backstab","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Octoberfest7/KDStab","1","1","N/A","N/A","10","10","167","37","2023-03-23T02:22:50Z","2022-03-10T06:09:52Z","35213" +"*Backstab/Driverloading*",".{0,1000}Backstab\/Driverloading.{0,1000}","offensive_tool_keyword","Backstab","A tool to kill antimalware protected processes","T1562.001 - T1569 - T1059","TA0005 - TA0040 - TA0002","N/A","Black Basta - LockBit","Defense Evasion","https://github.com/Yaxser/Backstab","1","1","N/A","N/A","10","10","1435","244","2021-06-19T20:01:52Z","2021-06-15T16:02:11Z","35214" +"*Backstab-master*",".{0,1000}Backstab\-master.{0,1000}","offensive_tool_keyword","Backstab","A tool to kill antimalware protected processes","T1562.001 - T1569 - T1059","TA0005 - TA0040 - TA0002","N/A","Black Basta - LockBit","Defense Evasion","https://github.com/Yaxser/Backstab","1","1","N/A","N/A","10","10","1435","244","2021-06-19T20:01:52Z","2021-06-15T16:02:11Z","35215" +"*BackupOperatorToDA.cpp*",".{0,1000}BackupOperatorToDA\.cpp.{0,1000}","offensive_tool_keyword","BackupOperatorToDA","From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller","T1078 - T1078.003 - T1021 - T1021.006 - T1112 - T1003.003","TA0005 - TA0001 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/mpgn/BackupOperatorToDA","1","1","N/A","N/A","10","5","421","53","2025-01-04T14:16:46Z","2022-02-15T20:51:46Z","35217" +"*BackupOperatorToDA.exe*",".{0,1000}BackupOperatorToDA\.exe.{0,1000}","offensive_tool_keyword","BackupOperatorToDA","From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller","T1078 - T1078.003 - T1021 - T1021.006 - T1112 - T1003.003","TA0005 - TA0001 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/mpgn/BackupOperatorToDA","1","1","N/A","N/A","10","5","421","53","2025-01-04T14:16:46Z","2022-02-15T20:51:46Z","35218" +"*BackupOperatorToDA.sln*",".{0,1000}BackupOperatorToDA\.sln.{0,1000}","offensive_tool_keyword","BackupOperatorToDA","From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller","T1078 - T1078.003 - T1021 - T1021.006 - T1112 - T1003.003","TA0005 - TA0001 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/mpgn/BackupOperatorToDA","1","1","N/A","N/A","10","5","421","53","2025-01-04T14:16:46Z","2022-02-15T20:51:46Z","35219" +"*BackupOperatorToDA-master*",".{0,1000}BackupOperatorToDA\-master.{0,1000}","offensive_tool_keyword","BackupOperatorToDA","From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller","T1078 - T1078.003 - T1021 - T1021.006 - T1112 - T1003.003","TA0005 - TA0001 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/mpgn/BackupOperatorToDA","1","1","N/A","N/A","10","5","421","53","2025-01-04T14:16:46Z","2022-02-15T20:51:46Z","35220" +"*backupprivsam.*",".{0,1000}backupprivsam\..{0,1000}","offensive_tool_keyword","cobaltstrike","A basic implementation of abusing the SeBackupPrivilege via Remote Registry dumping to dump the remote SAM SECURITY AND SYSTEM hives.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/m57/cobaltstrike_bofs","1","1","N/A","N/A","10","10","164","25","2022-07-23T20:37:52Z","2020-07-30T22:36:51Z","35222" +"*badger_exports.h*",".{0,1000}badger_exports\.h.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35230" +"*badger_svc.exe*",".{0,1000}badger_svc\.exe.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35232" +"*badger_template.ps1*",".{0,1000}badger_template\.ps1.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35233" +"*badger_x64.exe*",".{0,1000}badger_x64\.exe.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35234" +"*badger_x64_*.bin*",".{0,1000}badger_x64_.{0,1000}\.bin.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35235" +"*badger_x64_aws.exe*",".{0,1000}badger_x64_aws\.exe.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35236" +"*badger_x64_stealth_rtl.txt*",".{0,1000}badger_x64_stealth_rtl\.txt.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","35237" +"*Bad-Pdf*",".{0,1000}Bad\-Pdf.{0,1000}","offensive_tool_keyword","Bad-PDF","Bad-PDF create malicious PDF file to steal NTLM(NTLMv1/NTLMv2) Hashes from windows machines. it utilize vulnerability disclosed by checkpoint team to create the malicious PDF file. Bad-Pdf reads the NTLM hashes using Responder listener.","T1566.001 - T1189 - T1068 - T1207 - T1048 - T1003","TA0001 - TA0002 - TA0003 - TA0009 - TA0010 - TA0011","N/A","N/A","Credential Access","https://github.com/deepzec/Bad-Pdf","1","1","N/A","N/A","N/A","10","1105","220","2020-08-19T06:54:51Z","2018-04-29T15:21:35Z","35247" +"*BadPotato.cs*",".{0,1000}BadPotato\.cs.{0,1000}","offensive_tool_keyword","Earth Lusca Operations Tools ","Earth Lusca Operations Tools and commands","T1203 - T1218 - T1027 - T1064 - T1029 - T1210 - T1090","TA0007 - TA0008","N/A","Earth Lusca - Black Basta","Exploitation tool","https://www.trendmicro.com/content/dam/trendmicro/global/en/research/22/a/earth-lusca-employs-sophisticated-infrastructure-varied-tools-and-techniques/technical-brief-delving-deep-an-analysis-of-earth-lusca-operations.pdf https://github.com/BeichenDream/BadPotato","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","35248" +"*BadPotato.exe*",".{0,1000}BadPotato\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Erebus CobaltStrike post penetration testing plugin","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DeEpinGh0st/Erebus","1","1","N/A","N/A","10","10","1518","221","2021-10-28T06:20:51Z","2019-09-26T09:32:00Z","35249" +"*badpotato.exe*",".{0,1000}badpotato\.exe.{0,1000}","offensive_tool_keyword","Earth Lusca Operations Tools ","Earth Lusca Operations Tools and commands","T1203 - T1218 - T1027 - T1064 - T1029 - T1210 - T1090","TA0007 - TA0008","N/A","Earth Lusca - Black Basta","Exploitation tool","https://www.trendmicro.com/content/dam/trendmicro/global/en/research/22/a/earth-lusca-employs-sophisticated-infrastructure-varied-tools-and-techniques/technical-brief-delving-deep-an-analysis-of-earth-lusca-operations.pdf https://github.com/BeichenDream/BadPotato","1","1","N/A","N/A","10","","N/A","","","","35250" +"*BadPotato-master.zip*",".{0,1000}BadPotato\-master\.zip.{0,1000}","offensive_tool_keyword","BadPotato","Windows Privilege Escalation Exploit BadPotato","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","Ghost Ransomware","Earth Lusca","Privilege Escalation","https://github.com/BeichenDream/BadPotato","1","1","N/A","N/A","10","9","836","136","2020-05-10T15:42:21Z","2020-05-10T10:01:20Z","35252" +"*BadRat 1.6/server_unpacked.exe*",".{0,1000}BadRat\s1\.6\/server_unpacked\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","35253" +"*badrat.smb.hta*",".{0,1000}badrat\.smb\.hta.{0,1000}","offensive_tool_keyword","badrats","control tool (C2) using Python server - Jscript - Powershell and C# implants and communicates via HTTP(S) and SMB","T1059 - T1027 - T1573 - T1071 - T1105","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://gitlab.com/KevinJClark/badrats","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","35255" +"*badrat.smb.js*",".{0,1000}badrat\.smb\.js.{0,1000}","offensive_tool_keyword","badrats","control tool (C2) using Python server - Jscript - Powershell and C# implants and communicates via HTTP(S) and SMB","T1059 - T1027 - T1573 - T1071 - T1105","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://gitlab.com/KevinJClark/badrats","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","35256" +"*badrat_cs.csproj*",".{0,1000}badrat_cs\.csproj.{0,1000}","offensive_tool_keyword","badrats","control tool (C2) using Python server - Jscript - Powershell and C# implants and communicates via HTTP(S) and SMB","T1059 - T1027 - T1573 - T1071 - T1105","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://gitlab.com/KevinJClark/badrats","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","35257" +"*badrat_cs.exe.config*",".{0,1000}badrat_cs\.exe\.config.{0,1000}","offensive_tool_keyword","badrats","control tool (C2) using Python server - Jscript - Powershell and C# implants and communicates via HTTP(S) and SMB","T1059 - T1027 - T1573 - T1071 - T1105","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://gitlab.com/KevinJClark/badrats","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","35259" +"*badrats-c2-initial-access-payloads.html*",".{0,1000}badrats\-c2\-initial\-access\-payloads\.html.{0,1000}","offensive_tool_keyword","badrats","control tool (C2) using Python server - Jscript - Powershell and C# implants and communicates via HTTP(S) and SMB","T1059 - T1027 - T1573 - T1071 - T1105","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://gitlab.com/KevinJClark/badrats","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","35261" +"*badrats-master.zip*",".{0,1000}badrats\-master\.zip.{0,1000}","offensive_tool_keyword","badrats","control tool (C2) using Python server - Jscript - Powershell and C# implants and communicates via HTTP(S) and SMB","T1059 - T1027 - T1573 - T1071 - T1105","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://gitlab.com/KevinJClark/badrats","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","35262" +"*BadRentdrv2.exe*",".{0,1000}BadRentdrv2\.exe.{0,1000}","offensive_tool_keyword","BadRentdrv2","A vulnerable driver (BYOVD) capable of terminating several EDRs and antivirus software","T1562 - T1068 - T1210 - T1489 - T1496","TA0005 - TA0004 - TA0040","N/A","Agrius","Defense Evasion","https://github.com/keowu/BadRentdrv2","1","1","N/A","N/A","10","1","95","20","2024-12-26T13:43:18Z","2023-10-01T18:24:38Z","35263" +"*BadUSB_AddAdmin.ino*",".{0,1000}BadUSB_AddAdmin\.ino.{0,1000}","offensive_tool_keyword","Pateensy","payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy","T1056.001 - T1200 - T1036 - T1071","TA0002 - TA0005 - TA0011 - TA0006","N/A","N/A","Exploitation tool","https://github.com/screetsec/Pateensy","1","1","N/A","N/A","N/A","2","143","60","2017-01-26T12:02:56Z","2016-03-21T07:29:38Z","35264" +"*BadUSB_DownloadExecute.ino*",".{0,1000}BadUSB_DownloadExecute\.ino.{0,1000}","offensive_tool_keyword","Pateensy","payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy","T1056.001 - T1200 - T1036 - T1071","TA0002 - TA0005 - TA0011 - TA0006","N/A","N/A","Exploitation tool","https://github.com/screetsec/Pateensy","1","1","N/A","N/A","N/A","2","143","60","2017-01-26T12:02:56Z","2016-03-21T07:29:38Z","35265" +"*BadUSB_FacebookPost.ino*",".{0,1000}BadUSB_FacebookPost\.ino.{0,1000}","offensive_tool_keyword","Pateensy","payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy","T1056.001 - T1200 - T1036 - T1071","TA0002 - TA0005 - TA0011 - TA0006","N/A","N/A","Exploitation tool","https://github.com/screetsec/Pateensy","1","1","N/A","N/A","N/A","2","143","60","2017-01-26T12:02:56Z","2016-03-21T07:29:38Z","35266" +"*BadUSB_HideWindow.ino*",".{0,1000}BadUSB_HideWindow\.ino.{0,1000}","offensive_tool_keyword","Pateensy","payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy","T1056.001 - T1200 - T1036 - T1071","TA0002 - TA0005 - TA0011 - TA0006","N/A","N/A","Exploitation tool","https://github.com/screetsec/Pateensy","1","1","N/A","N/A","N/A","2","143","60","2017-01-26T12:02:56Z","2016-03-21T07:29:38Z","35267" +"*BadUSB_LockYourComputer.ino*",".{0,1000}BadUSB_LockYourComputer\.ino.{0,1000}","offensive_tool_keyword","Pateensy","payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy","T1056.001 - T1200 - T1036 - T1071","TA0002 - TA0005 - TA0011 - TA0006","N/A","N/A","Exploitation tool","https://github.com/screetsec/Pateensy","1","1","N/A","N/A","N/A","2","143","60","2017-01-26T12:02:56Z","2016-03-21T07:29:38Z","35268" +"*BadWindowsService_v1.0.7z*",".{0,1000}BadWindowsService_v1\.0\.7z.{0,1000}","offensive_tool_keyword","BadWindowsService","An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities","T1068 - T1211 - T1050","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/eladshamir/BadWindowsService","1","1","N/A","N/A","10","1","58","10","2022-08-25T14:22:25Z","2022-08-19T15:38:05Z","35269" +"*BadWindowsService_v1.0.zip*",".{0,1000}BadWindowsService_v1\.0\.zip.{0,1000}","offensive_tool_keyword","BadWindowsService","An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities","T1068 - T1211 - T1050","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/eladshamir/BadWindowsService","1","1","N/A","N/A","10","1","58","10","2022-08-25T14:22:25Z","2022-08-19T15:38:05Z","35270" +"*BadZure-main*",".{0,1000}BadZure\-main.{0,1000}","offensive_tool_keyword","badazure","BadZure orchestrates the setup of Azure Active Directory tenants populating them with diverse entities while also introducing common security misconfigurations to create vulnerable tenants with multiple attack paths","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Exploitation tool","https://github.com/mvelazc0/BadZure/","1","1","N/A","N/A","5","5","451","26","2025-04-10T03:20:03Z","2023-05-05T04:52:21Z","35271" +"*bananabr/TimeException*",".{0,1000}bananabr\/TimeException.{0,1000}","offensive_tool_keyword","TimeException","A tool to find folders excluded from AV real-time scanning using a time oracle","T1518.001 - T1070.004 - T1083","TA0005 - TA0007","N/A","N/A","Defense Evasion","https://github.com/bananabr/TimeException","1","1","N/A","N/A","8","3","233","16","2024-02-13T16:22:09Z","2022-07-19T02:47:52Z","35283" +"*bananaKitten.exe*",".{0,1000}bananaKitten\.exe.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","35284" +"*baron-samedit-heap-based-overflow-sudo.txt*",".{0,1000}baron\-samedit\-heap\-based\-overflow\-sudo\.txt.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","35286" +"*base64_conversion_commands.ps1*",".{0,1000}base64_conversion_commands\.ps1.{0,1000}","offensive_tool_keyword","RunasCs","RunasCs - Csharp and open version of windows builtin runas.exe","T1059.003 - T1059.001 - T1035","TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/RunasCs","1","1","N/A","N/A","7","10","1159","141","2024-07-12T23:31:35Z","2019-08-08T20:18:18Z","35291" +"*basemmnnqwxevlymli5bs36o5ynti55xojzvn246spahniugwkff2pad.onion*",".{0,1000}basemmnnqwxevlymli5bs36o5ynti55xojzvn246spahniugwkff2pad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","35292" +"*bash_read_line_reverse_tcp.py*",".{0,1000}bash_read_line_reverse_tcp\.py.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","35304" +"*bashfuscator.py*",".{0,1000}bashfuscator\.py.{0,1000}","offensive_tool_keyword","Bashfuscator","A fully configurable and extendable Bash obfuscation framework","T1027 - T1027.004 - T1059 - T1059.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Bashfuscator/Bashfuscator","1","1","#linux","N/A","10","10","1752","185","2023-09-05T10:40:25Z","2018-08-03T21:25:22Z","35307" +"*Bashfuscator-master*",".{0,1000}Bashfuscator\-master.{0,1000}","offensive_tool_keyword","Bashfuscator","A fully configurable and extendable Bash obfuscation framework","T1027 - T1027.004 - T1059 - T1059.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Bashfuscator/Bashfuscator","1","1","#linux","N/A","10","10","1752","185","2023-09-05T10:40:25Z","2018-08-03T21:25:22Z","35308" +"*BasicServiceExploit.class*",".{0,1000}BasicServiceExploit\.class.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","35310" +"*bastad5huzwkepdixedg2gekg7jk22ato24zyllp6lnjx7wdtyctgvyd.onion*",".{0,1000}bastad5huzwkepdixedg2gekg7jk22ato24zyllp6lnjx7wdtyctgvyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","35311" +"*BastilleResearch*",".{0,1000}BastilleResearch.{0,1000}","offensive_tool_keyword","Github Username","Open source testing tools for the SDR & security community","T1179 - T1141 - T1142 - T1143","TA0011 - ","N/A","N/A","Exploitation tool","https://github.com/BastilleResearch","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","35312" +"*Bat-Potato-main.zip*",".{0,1000}Bat\-Potato\-main\.zip.{0,1000}","offensive_tool_keyword","Bat-Potato","Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers","T1055.012 - T1068 - T1548.002 - T1505.003","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/0x4xel/Bat-Potato","1","1","N/A","N/A","10","1","42","11","2022-12-13T20:19:51Z","2022-12-12T20:50:22Z","35316" +"*bats3c/ADCSPwn*",".{0,1000}bats3c\/ADCSPwn.{0,1000}","offensive_tool_keyword","ADCSPwn","A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service","T1550.002 - T1078.003 - T1110.003 - T1649","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/bats3c/ADCSPwn","1","1","N/A","N/A","10","9","838","127","2023-03-20T20:30:40Z","2021-07-30T15:04:41Z","35317" +"*bats3c/darkarmour*",".{0,1000}bats3c\/darkarmour.{0,1000}","offensive_tool_keyword","darkarmour","Store and execute an encrypted windows binary from inside memorywithout a single bit touching disk.","T1055.012 - T1027 - T1564.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/bats3c/darkarmour","1","1","N/A","N/A","10","8","773","122","2020-04-13T10:56:23Z","2020-04-06T20:48:20Z","35318" +"*bats3c/DarkLoadLibrary*",".{0,1000}bats3c\/DarkLoadLibrary.{0,1000}","offensive_tool_keyword","DarkLoadLibrary","LoadLibrary for offensive operations","T1071.001 - T1055.002 - T1055.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bats3c/DarkLoadLibrary","1","1","N/A","N/A","10","10","1133","207","2021-10-22T07:27:58Z","2021-06-17T08:33:47Z","35319" +"*bats3c/EvtMute*",".{0,1000}bats3c\/EvtMute.{0,1000}","offensive_tool_keyword","EvtMute","This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging - mute the event log","T1562.004 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/bats3c/EvtMute","1","1","N/A","N/A","10","3","261","51","2021-04-24T19:23:39Z","2020-08-29T00:13:20Z","35320" +"*bawait_upload*",".{0,1000}bawait_upload.{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","35323" +"*bawait_upload_raw*",".{0,1000}bawait_upload_raw.{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","35324" +"*bbepis/Nsocks*",".{0,1000}bbepis\/Nsocks.{0,1000}","offensive_tool_keyword","nsocks",".NET HttpClient proxy handler implementation for SOCKS proxies","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","Scattered Spider* - Black Basta","C2","https://github.com/bbepis/Nsocks","1","1","N/A","N/A","8","10","3","0","2020-06-08T17:25:07Z","2020-03-28T09:00:22Z","35405" +"*bblockdlls*",".{0,1000}bblockdlls.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35412" +"*bbrowserpivot*",".{0,1000}bbrowserpivot.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","35413" +"*bbrowserpivot*",".{0,1000}bbrowserpivot.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35414" +"*bbtfr/evil-proxy*",".{0,1000}bbtfr\/evil\-proxy.{0,1000}","offensive_tool_keyword","evil-proxy","A ruby http/https proxy to do EVIL things","T1557 - T1110.001 - T1563.001","TA0006 - TA0001 - TA0009 - TA0040","N/A","N/A","Phishing","https://github.com/bbtfr/evil-proxy","1","1","N/A","N/A","9","2","172","96","2023-10-30T07:49:40Z","2015-07-30T01:54:40Z","35415" +"*bbypassuac*",".{0,1000}bbypassuac.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35416" +"*bcc2_setenv*",".{0,1000}bcc2_setenv.{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","35481" +"*bcc2_spawn*",".{0,1000}bcc2_spawn.{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","35482" +"*BCHASH-Rijndael-128.unverified.test-vectors.txt*",".{0,1000}BCHASH\-Rijndael\-128\.unverified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","35504" +"*BCHASH-Rijndael-256.unverified.test-vectors.txt*",".{0,1000}BCHASH\-Rijndael\-256\.unverified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","35505" +"*bcrossc2_load_dyn*",".{0,1000}bcrossc2_load_dyn.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","35506" +"*BC-SECURITY*Malleable*",".{0,1000}BC\-SECURITY.{0,1000}Malleable.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 Profiles. A collection of profiles used in different projects using Cobalt Strike & Empire.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","35508" +"*bc-security/empire*",".{0,1000}bc\-security\/empire.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","35509" +"*bcsecurity/empire:latest*",".{0,1000}bcsecurity\/empire\:latest.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","35510" +"*BC-SECURITY/Moriarty*",".{0,1000}BC\-SECURITY\/Moriarty.{0,1000}","offensive_tool_keyword","Moriarty","Moriarty is designed to enumerate missing KBs - detect various vulnerabilities and suggest potential exploits for Privilege Escalation in Windows environments.","T1068 - T1083","TA0004 - TA0007","N/A","N/A","Discovery","https://github.com/BC-SECURITY/Moriarty","1","1","N/A","N/A","7","6","510","67","2024-08-07T15:06:31Z","2023-12-11T14:15:33Z","35511" +"*BC-SECURITY/ScriptBlock-Smuggling*",".{0,1000}BC\-SECURITY\/ScriptBlock\-Smuggling.{0,1000}","offensive_tool_keyword","ScriptBlock-Smuggling","SCRIPTBLOCK SMUGGLING: SPOOFING POWERSHELL SECURITY LOGS AND BYPASSING AMSI WITHOUT REFLECTION OR PATCHING","T1059.001 - T1562.001 - T1112 - T1202 - T1070","TA0005","N/A","N/A","Defense Evasion","https://github.com/BC-SECURITY/ScriptBlock-Smuggling","1","1","N/A","N/A","8","1","89","13","2024-06-18T08:35:50Z","2024-06-12T21:44:47Z","35512" +"*BC-SECURITY/Starkiller*",".{0,1000}BC\-SECURITY\/Starkiller.{0,1000}","offensive_tool_keyword","empire","Starkiller is a Frontend for Powershell Empire. It is a web application written in VueJS","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Starkiller","1","1","N/A","N/A","10","10","1461","206","2025-03-25T03:30:16Z","2020-03-09T05:48:58Z","35513" +"*bdamele/icmpsh*",".{0,1000}bdamele\/icmpsh.{0,1000}","offensive_tool_keyword","icmpsh","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","10","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","35557" +"*bdcsync*",".{0,1000}bdcsync.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35566" +"*bdllinject*",".{0,1000}bdllinject.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","35580" +"*bdllinject*",".{0,1000}bdllinject.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35581" +"*bdllload*",".{0,1000}bdllload.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","35582" +"*bdllload*",".{0,1000}bdllload.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35583" +"*bdllspawn*",".{0,1000}bdllspawn.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","35584" +"*bdllspawn*",".{0,1000}bdllspawn.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35585" +"*bdtryujndyund6e5.azurewebsites.net*",".{0,1000}bdtryujndyund6e5\.azurewebsites\.net.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","35586" +"*beacon.*winsrv.dll*",".{0,1000}beacon\..{0,1000}winsrv\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","35632" +"*beacon.CommandBuilder*",".{0,1000}beacon\.CommandBuilder.{0,1000}","offensive_tool_keyword","cobaltstrike","Spectrum Attack Simulation beacons","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas/","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","35633" +"*beacon.dll*",".{0,1000}beacon\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35634" +"*beacon.elf*",".{0,1000}beacon\.elf.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","35635" +"*beacon.exe*",".{0,1000}beacon\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35636" +"*beacon.exe*",".{0,1000}beacon\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","default articfact name generated by cobaltsrike Cobalt Strike is threat emulation software. Execute targeted attacks against modern enterprises with one of the most powerful network attack kits available to penetration testers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35637" +"*beacon.nim*",".{0,1000}beacon\.nim.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF Files with Nim!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/byt3bl33d3r/BOF-Nim","1","1","N/A","N/A","10","10","84","13","2022-07-10T22:12:10Z","2021-01-12T18:58:23Z","35638" +"*Beacon.Object.File.zip*",".{0,1000}Beacon\.Object\.File\.zip.{0,1000}","offensive_tool_keyword","cobaltstrike","A Visual Studio template used to create Cobalt Strike BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/securifybv/Visual-Studio-BOF-template","1","1","N/A","N/A","10","10","304","55","2021-11-17T12:03:42Z","2021-11-13T13:44:01Z","35639" +"*beacon.x64*.dll*",".{0,1000}beacon\.x64.{0,1000}\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35641" +"*beacon.x64*.exe*",".{0,1000}beacon\.x64.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35642" +"*beacon.x64.dll*",".{0,1000}beacon\.x64\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","35643" +"*beacon.x86*.dll*",".{0,1000}beacon\.x86.{0,1000}\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35644" +"*beacon.x86*.exe*",".{0,1000}beacon\.x86.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35645" +"*Beacon_Com_Struct*",".{0,1000}Beacon_Com_Struct.{0,1000}","offensive_tool_keyword","cobaltstrike","SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tylous/SourcePoint","1","1","N/A","N/A","10","10","1109","156","2025-04-16T17:15:04Z","2021-08-06T20:55:26Z","35648" +"*beacon_command_describe*",".{0,1000}beacon_command_describe.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35649" +"*beacon_command_detail*",".{0,1000}beacon_command_detail.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","35651" +"*beacon_command_register*",".{0,1000}beacon_command_register.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35652" +"*beacon_commands*",".{0,1000}beacon_commands.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35653" +"*beacon_compatibility.c*",".{0,1000}beacon_compatibility\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a quick and dirty COFF loader (AKA Beacon Object Files). Currently can run un-modified BOF's so it can be used for testing without a CS agent running it","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/COFFLoader","1","1","N/A","N/A","10","10","520","78","2025-04-03T14:57:10Z","2021-02-19T19:14:43Z","35654" +"*beacon_compatibility.h*",".{0,1000}beacon_compatibility\.h.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a quick and dirty COFF loader (AKA Beacon Object Files). Currently can run un-modified BOF's so it can be used for testing without a CS agent running it","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/COFFLoader","1","1","N/A","N/A","10","10","520","78","2025-04-03T14:57:10Z","2021-02-19T19:14:43Z","35655" +"*beacon_elevator_describe*",".{0,1000}beacon_elevator_describe.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35656" +"*beacon_elevator_register*",".{0,1000}beacon_elevator_register.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35657" +"*beacon_elevators*",".{0,1000}beacon_elevators.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","35658" +"*beacon_elevators*",".{0,1000}beacon_elevators.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35659" +"*beacon_execute_job*",".{0,1000}beacon_execute_job.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","35662" +"*beacon_exploit_describe*",".{0,1000}beacon_exploit_describe.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","35663" +"*beacon_exploit_register*",".{0,1000}beacon_exploit_register.{0,1000}","offensive_tool_keyword","cobaltstrike","New UAC bypass for Silent Cleanup for CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EncodeGroup/UAC-SilentClean","1","1","N/A","N/A","10","10","192","31","2021-07-14T13:51:02Z","2020-10-07T13:25:21Z","35664" +"*beacon_funcs.c*",".{0,1000}beacon_funcs\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool to run object files mainly beacon object files (BOF) in .Net.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nettitude/RunOF","1","1","N/A","N/A","10","10","145","21","2023-01-06T15:30:05Z","2022-02-21T13:53:39Z","35665" +"*beacon_funcs.h*",".{0,1000}beacon_funcs\.h.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool to run object files mainly beacon object files (BOF) in .Net.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nettitude/RunOF","1","1","N/A","N/A","10","10","145","21","2023-01-06T15:30:05Z","2022-02-21T13:53:39Z","35666" +"*beacon_funcs.x64.*",".{0,1000}beacon_funcs\.x64\..{0,1000}","offensive_tool_keyword","cobaltstrike","A tool to run object files mainly beacon object files (BOF) in .Net.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nettitude/RunOF","1","1","N/A","N/A","10","10","145","21","2023-01-06T15:30:05Z","2022-02-21T13:53:39Z","35667" +"*beacon_funcs.x86.*",".{0,1000}beacon_funcs\.x86\..{0,1000}","offensive_tool_keyword","cobaltstrike","A tool to run object files mainly beacon object files (BOF) in .Net.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nettitude/RunOF","1","1","N/A","N/A","10","10","145","21","2023-01-06T15:30:05Z","2022-02-21T13:53:39Z","35668" +"*beacon_generate.py*",".{0,1000}beacon_generate\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a quick and dirty COFF loader (AKA Beacon Object Files). Currently can run un-modified BOF's so it can be used for testing without a CS agent running it","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/COFFLoader","1","1","N/A","N/A","10","10","520","78","2025-04-03T14:57:10Z","2021-02-19T19:14:43Z","35669" +"*beacon_generate.py*",".{0,1000}beacon_generate\.py.{0,1000}","offensive_tool_keyword","CSExec","An alternative to *exec.py from impacket with some builtin tricks","T1059.001 - T1059.005 - T1071.001","TA0002","N/A","N/A","Lateral Movement","https://github.com/Metro-Holografix/CSExec.py","1","1","N/A","private github repo","10","","N/A","","","","35670" +"*Beacon_GETPOST*",".{0,1000}Beacon_GETPOST.{0,1000}","offensive_tool_keyword","cobaltstrike","SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tylous/SourcePoint","1","1","N/A","N/A","10","10","1109","156","2025-04-16T17:15:04Z","2021-08-06T20:55:26Z","35671" +"*beacon_host_script*",".{0,1000}beacon_host_script.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","35672" +"*beacon_host_script*",".{0,1000}beacon_host_script.{0,1000}","offensive_tool_keyword","cobaltstrike","The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/ElevateKit","1","1","N/A","N/A","10","10","912","203","2020-06-22T21:12:24Z","2016-12-08T03:51:09Z","35673" +"*beacon_inline_execute*",".{0,1000}beacon_inline_execute.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35674" +"*beacon_inline_execute*",".{0,1000}beacon_inline_execute.{0,1000}","offensive_tool_keyword","RDPHijack-BOF","BOF - RDPHijack - Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.","T1021 - T1021.002 - T1032 - T1055 - T1070 - T1070.006 - T1070.007 - T1574.001","TA0002 - TA0003 - TA0004","N/A","N/A","Lateral Movement","https://github.com/netero1010/RDPHijack-BOF","1","1","N/A","N/A","N/A","3","298","46","2022-07-08T10:14:32Z","2022-07-08T10:14:07Z","35675" +"*beacon_log_clean*",".{0,1000}beacon_log_clean.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","35677" +"*beacon_output_ps.cna*",".{0,1000}beacon_output_ps\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","35678" +"*beacon_print*",".{0,1000}beacon_print.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files (BOFs) written in rust with rust core and alloc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/wumb0/rust_bof","1","1","N/A","N/A","10","10","262","27","2024-02-08T20:45:00Z","2022-02-28T23:46:00Z","35679" +"*BEACON_RDLL_*",".{0,1000}BEACON_RDLL_.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35680" +"*beacon_remote_exec_*",".{0,1000}beacon_remote_exec_.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","35681" +"*beacon_remote_exec_method_describe*",".{0,1000}beacon_remote_exec_method_describe.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35682" +"*beacon_remote_exec_method_register*",".{0,1000}beacon_remote_exec_method_register.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35683" +"*beacon_remote_exec_methods*",".{0,1000}beacon_remote_exec_methods.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35684" +"*beacon_remote_exploit*",".{0,1000}beacon_remote_exploit.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","35685" +"*beacon_remote_exploit_arch*",".{0,1000}beacon_remote_exploit_arch.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35686" +"*beacon_remote_exploit_describe*",".{0,1000}beacon_remote_exploit_describe.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35687" +"*beacon_remote_exploit_register*",".{0,1000}beacon_remote_exploit_register.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35688" +"*beacon_remote_exploits*",".{0,1000}beacon_remote_exploits.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35689" +"*beacon_smb.exe*",".{0,1000}beacon_smb\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","default articfact name generated by cobaltsrike Cobalt Strike is threat emulation software. Execute targeted attacks against modern enterprises with one of the most powerful network attack kits available to penetration testers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35690" +"*Beacon_Stage_p2_Stuct*",".{0,1000}Beacon_Stage_p2_Stuct.{0,1000}","offensive_tool_keyword","cobaltstrike","SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tylous/SourcePoint","1","1","N/A","N/A","10","10","1109","156","2025-04-16T17:15:04Z","2021-08-06T20:55:26Z","35691" +"*beacon_stage_pipe*",".{0,1000}beacon_stage_pipe.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35692" +"*Beacon_Stage_Struct_p1*",".{0,1000}Beacon_Stage_Struct_p1.{0,1000}","offensive_tool_keyword","cobaltstrike","SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tylous/SourcePoint","1","1","N/A","N/A","10","10","1109","156","2025-04-16T17:15:04Z","2021-08-06T20:55:26Z","35693" +"*Beacon_Stage_Struct_p3*",".{0,1000}Beacon_Stage_Struct_p3.{0,1000}","offensive_tool_keyword","cobaltstrike","SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tylous/SourcePoint","1","1","N/A","N/A","10","10","1109","156","2025-04-16T17:15:04Z","2021-08-06T20:55:26Z","35694" +"*beacon_stage_tcp*",".{0,1000}beacon_stage_tcp.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","35695" +"*beacon_stage_tcp*",".{0,1000}beacon_stage_tcp.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35696" +"*beacon_test.exe*",".{0,1000}beacon_test\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","default articfact name generated by cobaltsrike Cobalt Strike is threat emulation software. Execute targeted attacks against modern enterprises with one of the most powerful network attack kits available to penetration testers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35697" +"*beacon_top_callback*",".{0,1000}beacon_top_callback.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","35699" +"*BeaconApi.cs*",".{0,1000}BeaconApi\.cs.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","35700" +"*beacon-c2-go*",".{0,1000}beacon\-c2\-go.{0,1000}","offensive_tool_keyword","cobaltstrike","backdoor c2","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/wahyuhadi/beacon-c2-go","1","1","N/A","N/A","10","10","38","10","2020-01-14T11:15:42Z","2019-12-22T08:59:34Z","35701" +"*BeaconCleanupProcess*",".{0,1000}BeaconCleanupProcess.{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","35702" +"*BeaconConsoleWriter.cs*",".{0,1000}BeaconConsoleWriter\.cs.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","35703" +"*BeaconGetSpawnTo*",".{0,1000}BeaconGetSpawnTo.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","35704" +"*BeaconGetSpawnTo*",".{0,1000}BeaconGetSpawnTo.{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","35705" +"*BeaconGetSpawnTo*",".{0,1000}BeaconGetSpawnTo.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35706" +"*BeaconGetSpawnTo*",".{0,1000}BeaconGetSpawnTo.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","35707" +"*beacongrapher.py*",".{0,1000}beacongrapher\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","35708" +"*BeaconInjectProcess*",".{0,1000}BeaconInjectProcess.{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","35709" +"*BeaconInjectProcess*",".{0,1000}BeaconInjectProcess.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35710" +"*BeaconInjectProcess*",".{0,1000}BeaconInjectProcess.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","35712" +"*BeaconInjectTemporaryProcess*",".{0,1000}BeaconInjectTemporaryProcess.{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","35713" +"*BeaconInjectTemporaryProcess*",".{0,1000}BeaconInjectTemporaryProcess.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35714" +"*BeaconJob.cs*",".{0,1000}BeaconJob\.cs.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","35716" +"*BeaconJobWriter.cs*",".{0,1000}BeaconJobWriter\.cs.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","35717" +"*beaconlogs.json*",".{0,1000}beaconlogs\.json.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","35718" +"*beaconlogtracker.py*",".{0,1000}beaconlogtracker\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","35719" +"*BeaconNote.cna*",".{0,1000}BeaconNote\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike toolkit","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/1135/1135-CobaltStrike-ToolKit","1","1","N/A","N/A","10","10","150","35","2023-12-01T03:18:35Z","2019-02-22T09:36:44Z","35720" +"*BeaconNotify.cna*",".{0,1000}BeaconNotify\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike toolkit","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/1135/1135-CobaltStrike-ToolKit","1","1","N/A","N/A","10","10","150","35","2023-12-01T03:18:35Z","2019-02-22T09:36:44Z","35721" +"*BeaconObject.cs*",".{0,1000}BeaconObject\.cs.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","35722" +"*BeaconOutputStreamW*",".{0,1000}BeaconOutputStreamW.{0,1000}","offensive_tool_keyword","cobaltstrike","A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/WdToggle","1","1","N/A","N/A","10","10","219","31","2023-05-03T19:51:43Z","2020-12-23T13:42:25Z","35723" +"*BeaconOutputWriter.cs*",".{0,1000}BeaconOutputWriter\.cs.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","35724" +"*BeaconPrintf(*",".{0,1000}BeaconPrintf\(.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF for quser.exe implementation using Windows API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/Quser-BOF","1","1","N/A","N/A","10","10","85","11","2023-03-22T17:07:02Z","2021-04-01T15:19:50Z","35725" +"*BeaconPrintf*",".{0,1000}BeaconPrintf.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF to identify processes with the CLR loaded with a goal of identifying SpawnTo / injection candidates.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://gist.github.com/G0ldenGunSec/8ca0e853dd5637af2881697f8de6aecc","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35726" +"*BeaconPrintToStreamW*",".{0,1000}BeaconPrintToStreamW.{0,1000}","offensive_tool_keyword","cobaltstrike","A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/WdToggle","1","1","N/A","N/A","10","10","219","31","2023-05-03T19:51:43Z","2020-12-23T13:42:25Z","35727" +"*BeaconSpawnTemporaryProcess*",".{0,1000}BeaconSpawnTemporaryProcess.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","35728" +"*BeaconSpawnTemporaryProcess*",".{0,1000}BeaconSpawnTemporaryProcess.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35729" +"*BeaconTool/lib/sleep.jar*",".{0,1000}BeaconTool\/lib\/sleep\.jar.{0,1000}","offensive_tool_keyword","cobaltstrike","Practice Go programming and implement CobaltStrike's Beacon in Go","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/darkr4y/geacon","1","1","N/A","N/A","10","10","1189","206","2020-10-02T10:34:37Z","2020-02-14T14:01:29Z","35732" +"*BeaconUseToken*",".{0,1000}BeaconUseToken.{0,1000}","offensive_tool_keyword","cobaltstrike","Dumping SAM / SECURITY / SYSTEM registry hives with a Beacon Object File","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EncodeGroup/BOF-RegSave","1","1","N/A","N/A","10","10","198","32","2020-10-08T17:29:02Z","2020-10-07T13:46:03Z","35733" +"*beef_bind_tcp-stage.asm*",".{0,1000}beef_bind_tcp\-stage\.asm.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","35766" +"*beef_bind_tcp-stager.asm*",".{0,1000}beef_bind_tcp\-stager\.asm.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","35767" +"*beef_bind-stage*.rb*",".{0,1000}beef_bind\-stage.{0,1000}\.rb.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","35768" +"*beef_bind-stage.asm*",".{0,1000}beef_bind\-stage\.asm.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","35769" +"*beef_bind-stager.asm*",".{0,1000}beef_bind\-stager\.asm.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","35770" +"*beefproject*",".{0,1000}beefproject.{0,1000}","offensive_tool_keyword","beef","The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1210 - T1216 - T1207 - T1189 - T1190 - T1566","TA0001 - TA0002 - TA0003 - TA0006","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","35772" +"*beef-xss*",".{0,1000}beef\-xss.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","35773" +"*Beelogger*",".{0,1000}Beelogger.{0,1000}","offensive_tool_keyword","BeeLogger","Keylogger generator. fake office and acrobat file and malicious executables generator","T1056 - T1105 - T1204 - T1106","TA0003 - TA0004 - TA0007","N/A","N/A","Exploitation tool","https://github.com/4w4k3/BeeLogger","1","1","N/A","N/A","N/A","10","1054","332","2022-12-02T19:42:41Z","2017-02-17T15:34:39Z","35774" +"*BeetleChunks/SpoolSploit*",".{0,1000}BeetleChunks\/SpoolSploit.{0,1000}","offensive_tool_keyword","spoolsploit","A collection of Windows print spooler exploits containerized with other utilities for practical exploitation.","T1204 - T1547 - T1562 - T1003 - T1018 - T1570 - T1005","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/BeetleChunks/SpoolSploit","1","1","N/A","N/A","N/A","6","555","90","2021-07-16T04:49:43Z","2021-07-07T00:32:28Z","35775" +"*before-create-implant-callback*",".{0,1000}before\-create\-implant\-callback.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","35782" +"*before-create-implant-io-bin*",".{0,1000}before\-create\-implant\-io\-bin.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","35783" +"*before-find-implant-chunks*",".{0,1000}before\-find\-implant\-chunks.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","35784" +"*BeichenDream/BadPotato*",".{0,1000}BeichenDream\/BadPotato.{0,1000}","offensive_tool_keyword","BadPotato","Windows Privilege Escalation Exploit BadPotato","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","Ghost Ransomware","Earth Lusca","Privilege Escalation","https://github.com/BeichenDream/BadPotato","1","1","N/A","N/A","10","9","836","136","2020-05-10T15:42:21Z","2020-05-10T10:01:20Z","35804" +"*BeichenDream/Chunk-Proxy*",".{0,1000}BeichenDream\/Chunk\-Proxy.{0,1000}","offensive_tool_keyword","chunk-Proxy","A backdoor installed on a web server that allows for the execution of commands and facilitates persistent access.","T1505.003 - T1059 - T1105 - T1071","TA0011 - TA0002 - TA0003","Ghost Ransomware","N/A","C2","https://github.com/BeichenDream/Chunk-Proxy","1","1","N/A","N/A","10","10","283","40","2022-05-07T04:24:50Z","2021-10-28T18:45:21Z","35805" +"*BeichenDream/GodPotato*",".{0,1000}BeichenDream\/GodPotato.{0,1000}","offensive_tool_keyword","godpotato","GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","Ghost Ransomware","N/A","Privilege Escalation","https://github.com/BeichenDream/GodPotato","1","1","N/A","N/A","10","10","1938","236","2023-11-24T19:22:31Z","2022-12-23T14:37:00Z","35806" +"*BeichenDream/Godzilla*",".{0,1000}BeichenDream\/Godzilla.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","35807" +"*BeichenDream/SharpToken*",".{0,1000}BeichenDream\/SharpToken.{0,1000}","offensive_tool_keyword","SharpToken","SharpToken is a tool for exploiting Token leaks. It can find leaked Tokens from all processes in the system and use them","T1134 - T1101 - T1214 - T1087 - T1038","TA0004 - TA0007","N/A","N/A","Exploitation tool","https://github.com/BeichenDream/SharpToken","1","1","N/A","N/A","N/A","5","467","66","2023-11-24T19:21:57Z","2022-06-30T07:34:57Z","35808" +"*beichendream@gmail.com*",".{0,1000}beichendream\@gmail\.com.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/BeichenDream/Godzilla","1","1","#email","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","35809" +"*Ben0xA/DoUCMe*",".{0,1000}Ben0xA\/DoUCMe.{0,1000}","offensive_tool_keyword","doucme","leverages the NetUserAdd Win32 API to create a new computer account","T1136 - T1098 - T1078","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/Ben0xA/DoUCMe","1","1","N/A","N/A","9","1","69","18","2021-05-01T03:15:59Z","2021-04-29T15:41:28Z","35810" +"*benjamin@gentilkiwi.com*",".{0,1000}benjamin\@gentilkiwi\.com.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz default strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","#email","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","35812" +"*BernKing/ChromeStealer*",".{0,1000}BernKing\/ChromeStealer.{0,1000}","offensive_tool_keyword","ChromeStealer","extract and decrypt stored passwords from Google Chrome","T1555.003 - T1003.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/BernKing/ChromeStealer","1","1","N/A","N/A","8","2","145","18","2024-07-25T08:27:10Z","2024-07-14T13:27:30Z","35814" +"*besimorhino/powercat*",".{0,1000}besimorhino\/powercat.{0,1000}","offensive_tool_keyword","powercat","Netcat - The powershell version","T1571 - T1048.003 - T1095","TA0042 - TA0011","N/A","N/A","C2","https://github.com/besimorhino/powercat","1","1","N/A","N/A","10","10","2229","482","2024-03-05T18:05:07Z","2014-08-21T14:38:46Z","35819" +"*BesoToken-master*",".{0,1000}BesoToken\-master.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","1","N/A","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","35821" +"*bestcrypt2john.py*",".{0,1000}bestcrypt2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","35824" +"*bestcryptve2john.py*",".{0,1000}bestcryptve2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","35825" +"*BetterBackdoor*",".{0,1000}BetterBackdoor.{0,1000}","offensive_tool_keyword","BetterBackdoor","A backdoor is a tool used to gain remote access to a machine.","T1071 - T1055 - T1059 - T1053","TA0002 - TA0006 - TA0008","N/A","N/A","Persistence","https://github.com/thatcherclough/BetterBackdoor","1","1","N/A","N/A","N/A","3","280","86","2024-10-03T18:44:04Z","2019-07-29T14:45:24Z","35826" +"*bettercap.*",".{0,1000}bettercap\..{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","35829" +"*bettercap_.deb*",".{0,1000}bettercap_\.deb.{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","35830" +"*bettercap-master.zip*",".{0,1000}bettercap\-master\.zip.{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","35831" +"*betterdefaultpasslist*",".{0,1000}betterdefaultpasslist.{0,1000}","offensive_tool_keyword","betterdefaultpasslist","list includes default credentials from various manufacturers for their products like NAS. ERP. ICS etc.. that are used for standard products like mssql. vnc. oracle and so on useful for network bruteforcing","T1110 - T1111 - T1112 - T1113 - T1114 - T1115 - T1116 - T1117 - T1118 - T1119","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/govolution/betterdefaultpasslist","1","1","N/A","N/A","N/A","7","605","134","2024-10-04T18:03:58Z","2016-09-24T16:21:44Z","35832" +"*BetterSafetyKatz.*",".{0,1000}BetterSafetyKatz\..{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","35833" +"*BetterSafetyKatz.exe*",".{0,1000}BetterSafetyKatz\.exe.{0,1000}","offensive_tool_keyword","BetterSafetyKatz","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","BetterSafetyKatz","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","35834" +"*BetterSafetyKatz.exe*",".{0,1000}BetterSafetyKatz\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","BetterSafetyKatz","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","35836" +"*better-sliver-master.zip*",".{0,1000}better\-sliver\-master\.zip.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/gsmith257-cyber/better-sliver","1","1","N/A","N/A","10","10","98","10","2024-07-22T12:32:16Z","2023-12-12T02:04:36Z","35837" +"*BetterXencrypt.ps1*",".{0,1000}BetterXencrypt\.ps1.{0,1000}","offensive_tool_keyword","Invoke-Stealth","Simple & Powerful PowerShell Script Obfuscator","T1027.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/JoelGMSec/Invoke-Stealth","1","1","N/A","N/A","9","6","559","81","2023-04-21T12:49:37Z","2021-04-13T10:22:05Z","35838" +"*bgetprivs*",".{0,1000}bgetprivs.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35904" +"*bhashdump*",".{0,1000}bhashdump.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35905" +"*bhd_enum_dconly*",".{0,1000}bhd_enum_dconly.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","35906" +"*bhttp_x64.dll*",".{0,1000}bhttp_x64\.dll.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35911" +"*bianlianlbc5an4kgnay3opdemgcryg2kpfcbgczopmm3dnbz3uaunad.onion*",".{0,1000}bianlianlbc5an4kgnay3opdemgcryg2kpfcbgczopmm3dnbz3uaunad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","35913" +"*bianlivemqbawcco4cx4a672k2fip3guyxudzurfqvdszafam3ofqgqd.onion*",".{0,1000}bianlivemqbawcco4cx4a672k2fip3guyxudzurfqvdszafam3ofqgqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","35914" +"*bigb0sss/goPassGen*",".{0,1000}bigb0sss\/goPassGen.{0,1000}","offensive_tool_keyword","goPassGen","Easily-guessable Password Generator for Password Spray Attack","T1110 - T1110.003","TA0006 ","N/A","N/A","Exploitation tool","https://github.com/bigb0sss/goPassGen","1","1","N/A","N/A","8","1","21","1","2020-06-04T23:13:44Z","2020-06-04T22:33:37Z","35916" +"*bin/*/PS2EXE/*",".{0,1000}bin\/.{0,1000}\/PS2EXE\/.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","35921" +"*bin/addusertogroup.x64*",".{0,1000}bin\/addusertogroup\.x64.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","35922" +"*bin/bof_c.o*",".{0,1000}bin\/bof_c\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF Files with Nim!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/byt3bl33d3r/BOF-Nim","1","1","N/A","N/A","10","10","84","13","2022-07-10T22:12:10Z","2021-01-12T18:58:23Z","35923" +"*bin/bof_nim.o*",".{0,1000}bin\/bof_nim\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF Files with Nim!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/byt3bl33d3r/BOF-Nim","1","1","N/A","N/A","10","10","84","13","2022-07-10T22:12:10Z","2021-01-12T18:58:23Z","35924" +"*bin/dll/merlin.c*",".{0,1000}bin\/dll\/merlin\.c.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","35925" +"*bin/icmpsh/*",".{0,1000}bin\/icmpsh\/.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","35927" +"*bin/ldd2pretty*",".{0,1000}bin\/ldd2pretty.{0,1000}","offensive_tool_keyword","ldapdomaindump","Active Directory information dumper via LDAP","T1087 - T1005 - T1016","TA0007","N/A","EMBER BEAR","Discovery","https://github.com/dirkjanm/ldapdomaindump","1","1","N/A","N/A","10","10","1242","201","2025-04-06T13:31:57Z","2016-05-24T18:46:56Z","35930" +"*bin/ligolo*",".{0,1000}bin\/ligolo.{0,1000}","offensive_tool_keyword","ligolo","ligolo is a simple and lightweight tool for establishing SOCKS5 or TCP tunnels from a reverse connection in complete safety (TLS certificate with elliptical curve)","T1071 - T1021 - T1573","TA0011 - TA0002","N/A","AvosLocker - LockBit","C2","https://github.com/sysdream/ligolo","1","1","N/A","N/A","10","10","1764","224","2023-01-06T19:49:22Z","2020-05-22T07:58:13Z","35931" +"*bin/localrelay*",".{0,1000}bin\/localrelay.{0,1000}","offensive_tool_keyword","ligolo","ligolo is a simple and lightweight tool for establishing SOCKS5 or TCP tunnels from a reverse connection in complete safety (TLS certificate with elliptical curve)","T1071 - T1021 - T1573","TA0011 - TA0002","N/A","AvosLocker - LockBit","C2","https://github.com/sysdream/ligolo","1","1","N/A","N/A","10","10","1764","224","2023-01-06T19:49:22Z","2020-05-22T07:58:13Z","35932" +"*bin/PELoader.exe*",".{0,1000}bin\/PELoader\.exe.{0,1000}","offensive_tool_keyword","Shoggoth","Shoggoth: Asmjit Based Polymorphic Encryptor","T1027 - T1045","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/frkngksl/Shoggoth","1","1","N/A","N/A","8","8","724","92","2024-04-10T03:04:04Z","2021-12-03T11:55:22Z","35936" +"*bin/setoolkit*",".{0,1000}bin\/setoolkit.{0,1000}","offensive_tool_keyword","social-engineer-toolkit","The Social-Engineer Toolkit is an open-source penetration testing framework designed for social engineering. SET has a number of custom attack vectors that allow you to make a believable attack quickly. SET is a product of TrustedSec","T1566 - T1598","TA0001 - TA0002 - TA0003 - TA0009","N/A","N/A","Exploitation tool","https://github.com/trustedsec/social-engineer-toolkit","1","1","N/A","N/A","N/A","10","11798","2922","2024-10-21T15:46:18Z","2012-12-31T22:01:33Z","35937" +"*bin/setuserpass.x64*",".{0,1000}bin\/setuserpass\.x64.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","35938" +"*bin/SillyRAT/*",".{0,1000}bin\/SillyRAT\/.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","35939" +"*bin/striker*",".{0,1000}bin\/striker.{0,1000}","offensive_tool_keyword","Striker","Striker is a simple Command and Control (C2) program.","T1071 - T1071.001 - T1071.004 - T1071.005 - T1071.006 - T1071.007 - T1071.008 - T1071.009 - T1071.010 - T1071.012 - T1071.013 - T1071.014 - T1071.015 - T1071.016 - T1071.018 - T1105 - T1105.002 - T1573 - T1573.002 - T1573.003 - T1573.004 - T1573.005","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/4g3nt47/Striker","1","1","N/A","N/A","10","10","301","42","2023-05-04T18:00:05Z","2022-09-07T10:09:41Z","35941" +"*bin/void.zip*",".{0,1000}bin\/void\.zip.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","35944" +"*Binary-Offensive/ProtectMyTooling*",".{0,1000}Binary\-Offensive\/ProtectMyTooling.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","35955" +"*binderlabs/DirCreate2System*",".{0,1000}binderlabs\/DirCreate2System.{0,1000}","offensive_tool_keyword","DirCreate2System","Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting","T1068 - T1059.001 - T1070.004","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/binderlabs/DirCreate2System","1","1","N/A","N/A","8","4","357","38","2022-12-19T17:00:43Z","2022-12-15T03:49:55Z","35957" +"*binderlabs/DirCreate2System*",".{0,1000}binderlabs\/DirCreate2System.{0,1000}","offensive_tool_keyword","DirCreate2System","Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting","T1068 - T1059.001 - T1070.004","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/binderlabs/DirCreate2System","1","1","N/A","N/A","8","4","357","38","2022-12-19T17:00:43Z","2022-12-15T03:49:55Z","35958" +"*BishopFox/sliver*",".{0,1000}BishopFox\/sliver.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","35961" +"*bitb_server/phishing.ini*",".{0,1000}bitb_server\/phishing\.ini.{0,1000}","offensive_tool_keyword","bitb","Browser templates for Browser In The Browser (BITB) attack","T1056.001 - T1134 - T1090","TA0005 - TA0006 - TA0003","N/A","N/A","Sniffing & Spoofing","https://github.com/mrd0x/BITB","1","1","N/A","N/A","10","10","2823","474","2024-01-26T05:20:18Z","2022-03-15T16:51:39Z","35963" +"*bitcoin2john.py*",".{0,1000}bitcoin2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","35964" +"*Bitdefender-DisableAV-Remote.bat*",".{0,1000}Bitdefender\-DisableAV\-Remote\.bat.{0,1000}","offensive_tool_keyword","Dispossessor","tool used by Dispossessor ransomware group to remove AV","T1562.001 - T1112 - T1059 - T1036","TA0005 - TA0040","N/A","Dispossessor","Defense Evasion","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35965" +"*Bitmap-Elevate*",".{0,1000}Bitmap\-Elevate.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-MS16135.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","35988" +"*bits_ntlm_token_impersonation.*",".{0,1000}bits_ntlm_token_impersonation\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","35990" +"*bitsadmin/fakelogonscreen*",".{0,1000}bitsadmin\/fakelogonscreen.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","35993" +"*bitsadmin/nopowershell*",".{0,1000}bitsadmin\/nopowershell.{0,1000}","offensive_tool_keyword","nopowershell","NoPowerShell is a tool implemented in C# which supports executing PowerShell-like commands while remaining invisible to any PowerShell logging mechanisms. This .NET Framework 2 compatible binary can be loaded in Cobalt Strike to execute commands in-memory. No System.Management.Automation.dll is used. only native .NET libraries. An alternative usecase for NoPowerShell is to launch it as a DLL via rundll32.exe: rundll32 NoPowerShell.dll.main.","T1059 - T1086 - T1500 - T1564 - T1127 - T1027","TA0002 - TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","35994" +"*bitsadmin/revbshell*",".{0,1000}bitsadmin\/revbshell.{0,1000}","offensive_tool_keyword","revbshell","ReVBShell - Reverse VBS Shell","T1059.005 - T1573.001 - T1105","TA0011 - TA0010","N/A","N/A","C2","https://github.com/bitsadmin/revbshell","1","1","N/A","N/A","10","10","81","27","2019-10-08T12:00:05Z","2017-02-19T18:58:52Z","35995" +"*BitsadminStager*",".{0,1000}BitsadminStager.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","35996" +"*bitshares2john.py*",".{0,1000}bitshares2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","35997" +"*bitwarden2john.py*",".{0,1000}bitwarden2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","35998" +"*bkerberos_ccache_use*",".{0,1000}bkerberos_ccache_use.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36002" +"*bkerberos_ticket_purge*",".{0,1000}bkerberos_ticket_purge.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36003" +"*bkerberos_ticket_use*",".{0,1000}bkerberos_ticket_use.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36004" +"*bkeylogger*",".{0,1000}bkeylogger.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","36005" +"*bks2john.py*",".{0,1000}bks2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","36007" +"*blackarch.cs.nycu.edu.tw/*/os/*",".{0,1000}blackarch\.cs\.nycu\.edu\.tw\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","36008" +"*blackarch.leneveu.fr/*/os/*",".{0,1000}blackarch\.leneveu\.fr\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","36009" +"*blackarch.mirror.digitalpacific.com.au/*/os/*",".{0,1000}blackarch\.mirror\.digitalpacific\.com\.au\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","36010" +"*blackarch.mirror.garr.it/mirrors/blackarch/*/os/*",".{0,1000}blackarch\.mirror\.garr\.it\/mirrors\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","36011" +"*blackarch.org/blackarch/*/os/*",".{0,1000}blackarch\.org\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","36012" +"*blackarch.org/blackarch/blackarch/*/os/*",".{0,1000}blackarch\.org\/blackarch\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","36013" +"*blackarch.unixpeople.org/*/os/*",".{0,1000}blackarch\.unixpeople\.org\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","36014" +"*blackarch/tree/master/packages/rustcat*",".{0,1000}blackarch\/tree\/master\/packages\/rustcat.{0,1000}","offensive_tool_keyword","rustcat","Rustcat(rcat) - The modern Port listener and Reverse shell","T1090.001 - T1090.002 - T1046","TA0011 - TA0009 - TA0040","N/A","N/A","C2","https://github.com/robiot/rustcat","1","1","N/A","N/A","10","10","758","63","2024-07-20T14:20:34Z","2021-06-04T17:03:47Z","36015" +"*blackarrowsec/mssqlproxy*",".{0,1000}blackarrowsec\/mssqlproxy.{0,1000}","offensive_tool_keyword","mssqlproxy","mssqlproxy is a toolkit aimed to perform Lateral Movement in restricted environments through a compromised Microsoft SQL Server via socket reuse","T1021.002 - T1071.001 - T1573.002","TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/blackarrowsec/mssqlproxy","1","1","N/A","N/A","10","8","741","114","2021-02-16T20:13:04Z","2020-02-12T08:44:28Z","36016" +"*blackarrowsec/pivotnacci*",".{0,1000}blackarrowsec\/pivotnacci.{0,1000}","offensive_tool_keyword","pivotnacci","A tool to make socks connections through HTTP agents","T1090 - T1090.003","TA0003 - TA0011","N/A","Sandworm","C2","https://github.com/blackarrowsec/pivotnacci","1","1","N/A","N/A","9","10","697","114","2021-03-30T14:37:25Z","2020-04-28T11:36:45Z","36017" +"*blacklanternsecurity/MANSPIDER*",".{0,1000}blacklanternsecurity\/MANSPIDER.{0,1000}","offensive_tool_keyword","MANSPIDER","Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!","T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083","TA0007 - TA0009 - TA0010","N/A","N/A","Discovery","https://github.com/blacklanternsecurity/MANSPIDER","1","1","N/A","N/A","8","10","1117","138","2024-07-18T06:14:04Z","2020-03-18T13:27:20Z","36018" +"*blacklanternsecurity/trevorproxy*",".{0,1000}blacklanternsecurity\/trevorproxy.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","36019" +"*blacklanternsecurity/TREVORspray*",".{0,1000}blacklanternsecurity\/TREVORspray.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","36020" +"*BlackShell256/ShellPwnsh*",".{0,1000}BlackShell256\/ShellPwnsh.{0,1000}","offensive_tool_keyword","ShellPwnsh","Reverse Shell in Golang and PowerShell Fud","T1059.001 - T1573.002 - T1105","TA0011 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/BlackShell256/ShellPwnsh","1","1","N/A","N/A","9","10","9","6","2022-05-01T08:42:54Z","2022-04-28T01:26:08Z","36024" +"*BlackSnufkin/GhostDriver*",".{0,1000}BlackSnufkin\/GhostDriver.{0,1000}","offensive_tool_keyword","GhostDriver","GhostDriver is a Rust-built AV killer tool using BYOVD","T1562.001 - T1211 - T1055.001","TA0005 - TA0002","N/A","Black Basta","Defense Evasion","https://github.com/BlackSnufkin/GhostDriver","1","1","N/A","N/A","9","3","270","38","2023-12-12T13:52:32Z","2023-12-02T23:56:13Z","36030" +"*BlackSnufkin/NovaLdr*",".{0,1000}BlackSnufkin\/NovaLdr.{0,1000}","offensive_tool_keyword","NovaLdr","NovaLdr is a Threadless Module Stomping written in Rust designed as a learning project while exploring the world of malware development. It uses advanced techniques like indirect syscalls and string encryption to achieve its functionalities","T1027.001 - T1055.012 - T1112 - T1574.002 - T1055 - T1056.002 - T1027.002 - T1070.004 - T1129","TA0004 - TA0005 - TA0040 - TA0011","N/A","N/A","Defense Evasion","https://github.com/BlackSnufkin/NovaLdr","1","1","N/A","N/A","10","3","242","40","2024-06-29T10:34:48Z","2023-10-19T07:54:39Z","36031" +"*Blank-c/Blank-Grabber*",".{0,1000}Blank\-c\/Blank\-Grabber.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","1","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","36035" +"*Blank-c/BlankOBF*",".{0,1000}Blank\-c\/BlankOBF.{0,1000}","offensive_tool_keyword","BlankOBF","BlankOBF is a Python obfuscation tool designed to make Python programs harder to understand","T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/Blank-c/BlankOBF","1","1","N/A","N/A","9","2","114","22","2024-12-23T02:53:41Z","2022-01-24T13:52:00Z","36036" +"*ble_recon.go*",".{0,1000}ble_recon\.go.{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","36039" +"*blendin/3snake*",".{0,1000}blendin\/3snake.{0,1000}","offensive_tool_keyword","3snake","Tool for extracting information from newly spawned processes","T1003 - T1110 - T1552 - T1505","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/blendin/3snake","1","1","N/A","N/A","7","8","752","109","2022-02-14T17:42:10Z","2018-02-07T21:03:15Z","36040" +"*blindSQLPayloads.txt*",".{0,1000}blindSQLPayloads\.txt.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","36041" +"*blockchain2john.py*",".{0,1000}blockchain2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","36045" +"*BlockNewProcDrv_x64.sys*",".{0,1000}BlockNewProcDrv_x64\.sys.{0,1000}","offensive_tool_keyword","VectorKernel","PoCs for Kernelmode rootkit techniques research.","T1543 - T1055 - T1134 - T1564 - T1070 - T1057 - T1574 - T1562 - T1082 - T1518","TA0003 - TA0005 - TA0004 - TA0008 - TA0007","N/A","N/A","Exploitation tool","https://github.com/daem0nc0re/VectorKernel/","1","1","N/A","N/A","10","4","367","60","2025-01-21T08:22:42Z","2023-11-23T12:36:31Z","36050" +"*BlockOpenHandle.cpp*",".{0,1000}BlockOpenHandle\.cpp.{0,1000}","offensive_tool_keyword","BlockOpenHandle","Block any Process to open HANDLE to your process - only SYTEM is allowed to open handle to your process - with that you can avoid remote memory scanners","T1050.005 - T1480","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/BlockOpenHandle","1","1","N/A","N/A","9","2","167","25","2023-04-27T05:42:51Z","2023-04-27T05:40:47Z","36051" +"*BlockOpenHandle.exe*",".{0,1000}BlockOpenHandle\.exe.{0,1000}","offensive_tool_keyword","BlockOpenHandle","Block any Process to open HANDLE to your process - only SYTEM is allowed to open handle to your process - with that you can avoid remote memory scanners","T1050.005 - T1480","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/BlockOpenHandle","1","1","N/A","N/A","9","2","167","25","2023-04-27T05:42:51Z","2023-04-27T05:40:47Z","36052" +"*BlockOpenHandle.vcxproj*",".{0,1000}BlockOpenHandle\.vcxproj.{0,1000}","offensive_tool_keyword","BlockOpenHandle","Block any Process to open HANDLE to your process - only SYTEM is allowed to open handle to your process - with that you can avoid remote memory scanners","T1050.005 - T1480","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/BlockOpenHandle","1","1","N/A","N/A","9","2","167","25","2023-04-27T05:42:51Z","2023-04-27T05:40:47Z","36053" +"*BlockOpenHandle-main*",".{0,1000}BlockOpenHandle\-main.{0,1000}","offensive_tool_keyword","BlockOpenHandle","Block any Process to open HANDLE to your process - only SYTEM is allowed to open handle to your process - with that you can avoid remote memory scanners","T1050.005 - T1480","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/BlockOpenHandle","1","1","N/A","N/A","9","2","167","25","2023-04-27T05:42:51Z","2023-04-27T05:40:47Z","36054" +"*blog.lexfo.fr/sshimpanzee.html*",".{0,1000}blog\.lexfo\.fr\/sshimpanzee\.html.{0,1000}","offensive_tool_keyword","sshimpanzee","SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS - ICMP - HTTP Encapsulation - HTTP/Socks Proxies - UDP","T1572 - T1095 - T1090 - T1043","TA0010 - TA0011 - TA0005","N/A","Scattered Spider*","C2","https://github.com/lexfo/sshimpanzee","1","1","N/A","N/A","10","10","263","27","2025-03-05T08:32:56Z","2023-04-03T10:11:27Z","36056" +"*bloginuser*",".{0,1000}bloginuser.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36057" +"*blogonpasswords*",".{0,1000}blogonpasswords.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36058" +"*blogvl7tjyjvsfthobttze52w36wwiz34hrfcmorgvdzb6hikucb7aqd.onion*",".{0,1000}blogvl7tjyjvsfthobttze52w36wwiz34hrfcmorgvdzb6hikucb7aqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","36059" +"*blogxxu75w63ujqarv476otld7cyjkq4yoswzt4ijadkjwvg3vrvd5yd.onion*",".{0,1000}blogxxu75w63ujqarv476otld7cyjkq4yoswzt4ijadkjwvg3vrvd5yd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","36060" +"*BloodHound-*.zip*",".{0,1000}BloodHound\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","BloodHound","BloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound","1","1","N/A","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","36064" +"*bloodhound.ad.*",".{0,1000}bloodhound\.ad\..{0,1000}","offensive_tool_keyword","BloodHound","A Python based ingestor for BloodHound","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/fox-it/BloodHound.py","1","1","N/A","N/A","10","10","2088","343","2025-03-28T11:19:13Z","2018-02-26T14:44:20Z","36065" +"*bloodhound.bin*",".{0,1000}bloodhound\.bin.{0,1000}","offensive_tool_keyword","BloodHound","BloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound","1","1","N/A","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","36066" +"*bloodhound.enumeration*",".{0,1000}bloodhound\.enumeration.{0,1000}","offensive_tool_keyword","BloodHound","A Python based ingestor for BloodHound","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/fox-it/BloodHound.py","1","1","N/A","N/A","10","10","2088","343","2025-03-28T11:19:13Z","2018-02-26T14:44:20Z","36067" +"*BloodHound.ps1*",".{0,1000}BloodHound\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-SPN.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","36068" +"*bloodhound.py*",".{0,1000}bloodhound\.py.{0,1000}","offensive_tool_keyword","BloodHound","A Python based ingestor for BloodHound","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/fox-it/BloodHound.py","1","1","N/A","N/A","10","10","2088","343","2025-03-28T11:19:13Z","2018-02-26T14:44:20Z","36070" +"*bloodhound.rb*",".{0,1000}bloodhound\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36071" +"*bloodhound_output*/dev/null*",".{0,1000}bloodhound_output.{0,1000}\/dev\/null.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","36072" +"*bloodhound_output_*.txt*",".{0,1000}bloodhound_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","36073" +"*bloodhound_output_dconly_*",".{0,1000}bloodhound_output_dconly_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","36074" +"*BloodHound3.ps1*",".{0,1000}BloodHound3\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","36075" +"*BloodHoundAD*",".{0,1000}BloodHoundAD.{0,1000}","offensive_tool_keyword","BloodHound","BloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound","1","1","N/A","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","36076" +"*BloodHoundAD*",".{0,1000}BloodHoundAD.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","36077" +"*BloodHoundAD/BloodHound*",".{0,1000}BloodHoundAD\/BloodHound.{0,1000}","offensive_tool_keyword","BloodHound","Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors","1","1","N/A","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","36078" +"*BloodHound-darwin-x64.zip*",".{0,1000}BloodHound\-darwin\-x64\.zip.{0,1000}","offensive_tool_keyword","BloodHound","Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors","1","1","#linux","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","36079" +"*BloodHound-linux-arm64.zip*",".{0,1000}BloodHound\-linux\-arm64\.zip.{0,1000}","offensive_tool_keyword","BloodHound","Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors","1","1","#linux","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","36082" +"*BloodHoundLoopResults.zip*",".{0,1000}BloodHoundLoopResults\.zip.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","36083" +"*BloodHound-master*",".{0,1000}BloodHound\-master.{0,1000}","offensive_tool_keyword","BloodHound","A Python based ingestor for BloodHound","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/fox-it/BloodHound.py","1","1","N/A","N/A","10","10","2088","343","2025-03-28T11:19:13Z","2018-02-26T14:44:20Z","36084" +"*BloodHound-modified.ps1*",".{0,1000}BloodHound\-modified\.ps1.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Exploitation tool","https://github.com/byt3bl33d3r/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","36085" +"*bloodhound-python*",".{0,1000}bloodhound\-python.{0,1000}","offensive_tool_keyword","BloodHound","BloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/fox-it/BloodHound.py","1","1","N/A","N/A","10","10","2088","343","2025-03-28T11:19:13Z","2018-02-26T14:44:20Z","36086" +"*bloodhound-quickwin-main*",".{0,1000}bloodhound\-quickwin\-main.{0,1000}","offensive_tool_keyword","bloodhound-quickwin","Simple script to extract useful informations from the combo BloodHound + Neo4j","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/kaluche/bloodhound-quickwin","1","1","N/A","AD Enumeration","6","3","239","26","2025-04-04T05:11:46Z","2021-02-16T16:04:16Z","36088" +"*BloodHound-win32-ia32.zip*",".{0,1000}BloodHound\-win32\-ia32\.zip.{0,1000}","offensive_tool_keyword","BloodHound","Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors","1","1","N/A","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","36089" +"*BloodHound-win32-x64.zip*",".{0,1000}BloodHound\-win32\-x64\.zip.{0,1000}","offensive_tool_keyword","BloodHound","Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors","1","1","N/A","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","36090" +"*bloodyAD.py*",".{0,1000}bloodyAD\.py.{0,1000}","offensive_tool_keyword","bloodyAD","BloodyAD is an Active Directory Privilege Escalation Framework","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/CravateRouge/bloodyAD","1","1","N/A","N/A","10","10","1590","145","2025-04-10T10:47:16Z","2021-10-11T15:07:26Z","36093" +"*bloodyAD-main*",".{0,1000}bloodyAD\-main.{0,1000}","offensive_tool_keyword","bloodyAD","BloodyAD is an Active Directory Privilege Escalation Framework","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/CravateRouge/bloodyAD","1","1","N/A","N/A","10","10","1590","145","2025-04-10T10:47:16Z","2021-10-11T15:07:26Z","36094" +"*BlWasp/rs-shell*",".{0,1000}BlWasp\/rs\-shell.{0,1000}","offensive_tool_keyword","rs-shell","rust reverse shell","T1071.004 - T1071.001 - T1573.002 - T1219 - T1059.001 - T1090.003","TA0011 - TA0005 - TA0002 - TA0007","N/A","N/A","C2","https://github.com/BlWasp/rs-shell","1","1","N/A","N/A","10","10","182","20","2024-09-03T21:48:21Z","2023-06-22T14:10:21Z","36097" +"*BlWasp/syscalls-rs.git*",".{0,1000}BlWasp\/syscalls\-rs\.git.{0,1000}","offensive_tool_keyword","rs-shell","rust reverse shell","T1071.004 - T1071.001 - T1573.002 - T1219 - T1059.001 - T1090.003","TA0011 - TA0005 - TA0002 - TA0007","N/A","N/A","C2","https://github.com/BlWasp/rs-shell","1","1","N/A","N/A","10","10","182","20","2024-09-03T21:48:21Z","2023-06-22T14:10:21Z","36098" +"*bmarchev/Forensike*",".{0,1000}bmarchev\/Forensike.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","1","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","36100" +"*bmdyy/discord-c2*",".{0,1000}bmdyy\/discord\-c2.{0,1000}","offensive_tool_keyword","discord-c2","C2 communication with discord","T1102.003 - T1071.001 - T1027.010 - T1105 - T1090.002","TA0011 - TA0010","N/A","N/A","C2","https://github.com/bmdyy/discord-c2","1","1","N/A","N/A","10","10","60","6","2022-12-29T03:05:05Z","2022-12-08T19:10:23Z","36101" +"*bob@moozle.wtf*",".{0,1000}bob\@moozle\.wtf.{0,1000}","offensive_tool_keyword","FudgeC2","FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.","T1021.002 - T1105 - T1059.001 - T1059.003","TA0008 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/Ziconius/FudgeC2","1","1","#email","N/A","10","10","253","54","2023-05-01T21:13:56Z","2018-09-09T21:05:21Z","36104" +"*BobTheSmuggler.py*",".{0,1000}BobTheSmuggler\.py.{0,1000}","offensive_tool_keyword","BobTheSmuggler","HTML SMUGGLING TOOL 6 allows you to create HTML files with embedded 7z/zip archives. The tool would compress your binary (EXE/DLL) into 7z/zip file format then XOR encrypt the archive and then hides inside PNG/GIF image file format (Image Polyglots)","T1027 - T1204.002 - T1140","TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/TheCyb3rAlpha/BobTheSmuggler","1","1","N/A","N/A","10","6","534","62","2025-03-10T07:32:22Z","2024-01-10T08:04:57Z","36105" +"*bof*/CredEnum/*",".{0,1000}bof.{0,1000}\/CredEnum\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/guervild/BOFs","1","1","N/A","N/A","10","10","161","27","2022-05-02T16:59:24Z","2021-03-15T23:30:22Z","36108" +"*BOF/*procdump/*",".{0,1000}BOF\/.{0,1000}procdump\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","36111" +"*bof_allocator*",".{0,1000}bof_allocator.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36112" +"*bof_helper.py*",".{0,1000}bof_helper\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) Creation Helper","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dtmsecurity/bof_helper","1","1","N/A","N/A","10","10","228","43","2022-05-03T18:56:14Z","2020-07-01T14:50:29Z","36113" +"*bof_net_user.c*",".{0,1000}bof_net_user\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Use windows api to add users which can be used when net is unavailable","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/lengjibo/NetUser","1","1","N/A","N/A","10","10","420","90","2021-09-29T14:22:09Z","2020-01-09T08:33:27Z","36114" +"*bof_net_user.o*",".{0,1000}bof_net_user\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Use windows api to add users which can be used when net is unavailable","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/lengjibo/NetUser","1","1","N/A","N/A","10","10","420","90","2021-09-29T14:22:09Z","2020-01-09T08:33:27Z","36115" +"*bof_reuse_memory*",".{0,1000}bof_reuse_memory.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36117" +"*BOF2shellcode*",".{0,1000}BOF2shellcode.{0,1000}","offensive_tool_keyword","cobaltstrike","POC tool to convert CobaltStrike BOF files to raw shellcode","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/FalconForceTeam/BOF2shellcode","1","1","N/A","N/A","10","10","193","28","2021-11-05T18:37:53Z","2021-11-05T14:29:57Z","36118" +"*bof2shellcode.py*",".{0,1000}bof2shellcode\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","POC tool to convert CobaltStrike BOF files to raw shellcode","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/FalconForceTeam/BOF2shellcode","1","1","N/A","N/A","10","10","193","28","2021-11-05T18:37:53Z","2021-11-05T14:29:57Z","36119" +"*BOF-DLL-Inject*",".{0,1000}BOF\-DLL\-Inject.{0,1000}","offensive_tool_keyword","cobaltstrike","Manual Map DLL injection implemented with Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tomcarver16/BOF-DLL-Inject","1","1","N/A","N/A","10","10","151","23","2020-09-03T23:24:31Z","2020-09-03T23:04:30Z","36120" +"*bofentry::bof_entry*",".{0,1000}bofentry\:\:bof_entry.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files (BOFs) written in rust with rust core and alloc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/wumb0/rust_bof","1","1","N/A","N/A","10","10","262","27","2024-02-08T20:45:00Z","2022-02-28T23:46:00Z","36121" +"*BOF-ForeignLsass*",".{0,1000}BOF\-ForeignLsass.{0,1000}","offensive_tool_keyword","cobaltstrike","LSASS Dumping With Foreign Handles","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/alfarom256/BOF-ForeignLsass","1","1","N/A","N/A","10","10","100","25","2021-08-23T16:57:08Z","2021-08-21T00:19:29Z","36122" +"*bofhound-main*",".{0,1000}bofhound\-main.{0,1000}","offensive_tool_keyword","bofhound","Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel","T1046 - T1087 - T1003","TA0007 - TA0009 - TA0001","N/A","N/A","Discovery","https://github.com/fortalice/bofhound","1","1","N/A","N/A","5","4","328","56","2024-02-23T15:36:24Z","2022-05-10T17:41:53Z","36126" +"*BOF-IShellWindows-DCOM.*",".{0,1000}BOF\-IShellWindows\-DCOM\..{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of beacon BOF written to learn windows and cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Yaxser/CobaltStrike-BOF","1","1","N/A","N/A","10","10","347","57","2023-02-24T13:12:14Z","2020-10-08T01:12:41Z","36127" +"*BofLdapSignCheck*",".{0,1000}BofLdapSignCheck.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File & C# project to check LDAP signing","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/cube0x0/LdapSignCheck","1","1","N/A","N/A","10","10","189","25","2024-08-07T09:32:20Z","2022-02-24T20:25:31Z","36128" +"*bofloader.bin*",".{0,1000}bofloader\.bin.{0,1000}","offensive_tool_keyword","cobaltstrike","POC tool to convert CobaltStrike BOF files to raw shellcode","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/FalconForceTeam/BOF2shellcode","1","1","N/A","N/A","10","10","193","28","2021-11-05T18:37:53Z","2021-11-05T14:29:57Z","36129" +"*BOFMask-main*",".{0,1000}BOFMask\-main.{0,1000}","offensive_tool_keyword","BOFMask","BOFMask is a proof-of-concept for masking Cobalt Strike's Beacon payload while executing a Beacon Object File (BOF)","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/passthehashbrowns/BOFMask","1","1","N/A","N/A","10","2","120","27","2023-06-28T14:35:32Z","2023-06-27T21:19:22Z","36130" +"*bofnet*SeriousSam.*",".{0,1000}bofnet.{0,1000}SeriousSam\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/guervild/BOFs","1","1","N/A","N/A","10","10","161","27","2022-05-02T16:59:24Z","2021-03-15T23:30:22Z","36131" +"*BOFNET.Bofs*",".{0,1000}BOFNET\.Bofs.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","36132" +"*bofnet.cna*",".{0,1000}bofnet\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","36134" +"*BOFNET.csproj*",".{0,1000}BOFNET\.csproj.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","36136" +"*BOFNET.dll*",".{0,1000}BOFNET\.dll.{0,1000}","offensive_tool_keyword","C2 related tools","PowerShell rebuilt in C# for Red Teaming purposes","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","36137" +"*BOFNET.dll*",".{0,1000}BOFNET\.dll.{0,1000}","offensive_tool_keyword","nopowershell","NoPowerShell is a tool implemented in C# which supports executing PowerShell-like commands while remaining invisible to any PowerShell logging mechanisms. This .NET Framework 2 compatible binary can be loaded in Cobalt Strike to execute commands in-memory. No System.Management.Automation.dll is used. only native .NET libraries. An alternative usecase for NoPowerShell is to launch it as a DLL via rundll32.exe: rundll32 NoPowerShell.dll.main.","T1059 - T1086 - T1500 - T1564 - T1127 - T1027","TA0002 - TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","36138" +"*BOFNET.sln*",".{0,1000}BOFNET\.sln.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","36139" +"*bofnet_execute.*",".{0,1000}bofnet_execute\..{0,1000}","offensive_tool_keyword","C2 related tools","PowerShell rebuilt in C# for Red Teaming purposes","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","36143" +"*bofnet_execute.*",".{0,1000}bofnet_execute\..{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","36144" +"*bofnet_execute.cpp.x64.obj*",".{0,1000}bofnet_execute\.cpp\.x64\.obj.{0,1000}","offensive_tool_keyword","nopowershell","NoPowerShell is a tool implemented in C# which supports executing PowerShell-like commands while remaining invisible to any PowerShell logging mechanisms. This .NET Framework 2 compatible binary can be loaded in Cobalt Strike to execute commands in-memory. No System.Management.Automation.dll is used. only native .NET libraries. An alternative usecase for NoPowerShell is to launch it as a DLL via rundll32.exe: rundll32 NoPowerShell.dll.main.","T1059 - T1086 - T1500 - T1564 - T1127 - T1027","TA0002 - TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","36147" +"*bofnet_execute.cpp.x86.obj*",".{0,1000}bofnet_execute\.cpp\.x86\.obj.{0,1000}","offensive_tool_keyword","nopowershell","NoPowerShell is a tool implemented in C# which supports executing PowerShell-like commands while remaining invisible to any PowerShell logging mechanisms. This .NET Framework 2 compatible binary can be loaded in Cobalt Strike to execute commands in-memory. No System.Management.Automation.dll is used. only native .NET libraries. An alternative usecase for NoPowerShell is to launch it as a DLL via rundll32.exe: rundll32 NoPowerShell.dll.main.","T1059 - T1086 - T1500 - T1564 - T1127 - T1027","TA0002 - TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","36149" +"*bofnet_init*",".{0,1000}bofnet_init.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","36150" +"*bofnet_jobkill*",".{0,1000}bofnet_jobkill.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","36152" +"*bofnet_jobs*",".{0,1000}bofnet_jobs.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","36153" +"*bofnet_list*",".{0,1000}bofnet_list.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","36155" +"*bofnet_listassembiles*",".{0,1000}bofnet_listassembiles.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","36156" +"*bofnet_shutdown*",".{0,1000}bofnet_shutdown.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","36159" +"*BOFNET_Tests*",".{0,1000}BOFNET_Tests.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","36160" +"*bof-quser.cna*",".{0,1000}bof\-quser\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF for quser.exe implementation using Windows API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/Quser-BOF","1","1","N/A","N/A","10","10","85","11","2023-03-22T17:07:02Z","2021-04-01T15:19:50Z","36163" +"*bof-rdphijack*",".{0,1000}bof\-rdphijack.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/RDPHijack-BOF","1","1","N/A","N/A","10","3","298","46","2022-07-08T10:14:32Z","2022-07-08T10:14:07Z","36164" +"*bof-rdphijack*",".{0,1000}bof\-rdphijack.{0,1000}","offensive_tool_keyword","RDPHijack-BOF","BOF - RDPHijack - Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.","T1021 - T1021.002 - T1032 - T1055 - T1070 - T1070.006 - T1070.007 - T1574.001","TA0002 - TA0003 - TA0004","N/A","N/A","Lateral Movement","https://github.com/netero1010/RDPHijack-BOF","1","1","N/A","N/A","N/A","3","298","46","2022-07-08T10:14:32Z","2022-07-08T10:14:07Z","36165" +"*BofRunnerOutput*",".{0,1000}BofRunnerOutput.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool to run object files mainly beacon object files (BOF) in .Net.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nettitude/RunOF","1","1","N/A","N/A","10","10","145","21","2023-01-06T15:30:05Z","2022-02-21T13:53:39Z","36167" +"*BOFs*/SyscallsSpawn/*",".{0,1000}BOFs.{0,1000}\/SyscallsSpawn\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","36168" +"*Bofs/AssemblyLoader*",".{0,1000}Bofs\/AssemblyLoader.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","36169" +"*bof-trustedpath-uacbypass*",".{0,1000}bof\-trustedpath\-uacbypass.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike beacon object file implementation for trusted path UAC bypass. The target executable will be called without involving cmd.exe by using DCOM object.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/TrustedPath-UACBypass-BOF","1","1","N/A","N/A","10","10","133","40","2021-08-16T07:49:55Z","2021-08-07T03:40:33Z","36171" +"*bohops/WSMan-WinRM*",".{0,1000}bohops\/WSMan\-WinRM.{0,1000}","offensive_tool_keyword","WSMan-WinRM","remote commands over WinRM using the WSMan.Automation COM object","T1021.004 - T1059.001","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/bohops/WSMan-WinRM","1","1","N/A","N/A","10","3","236","40","2020-05-12T16:49:01Z","2020-05-12T01:30:42Z","36172" +"*bokoscanner.*",".{0,1000}bokoscanner\..{0,1000}","offensive_tool_keyword","boko","boko.py is an application scanner for macOS that searches for and identifies potential dylib hijacking and weak dylib vulnerabilities for application executables as well as scripts an application may use that have the potential to be backdoored","T1195 - T1078 - T1079 - T1574","TA0006 - TA0008","N/A","N/A","Exploitation tool","https://github.com/bashexplode/boko","1","1","N/A","N/A","N/A","1","71","13","2021-09-28T22:36:01Z","2020-05-22T21:46:33Z","36174" +"*boku_pe_customMZ*",".{0,1000}boku_pe_customMZ.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","36175" +"*boku_pe_customPE*",".{0,1000}boku_pe_customPE.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","36176" +"*boku_pe_dll*",".{0,1000}boku_pe_dll.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","36177" +"*boku_pe_mask_*",".{0,1000}boku_pe_mask_.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","36178" +"*boku_pe_MZ_from_C2Profile*",".{0,1000}boku_pe_MZ_from_C2Profile.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","36179" +"*boku_strrep*",".{0,1000}boku_strrep.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","36180" +"*boku7/BokuLoader*",".{0,1000}boku7\/BokuLoader.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","36181" +"*boku7/HOLLOW*",".{0,1000}boku7\/HOLLOW.{0,1000}","offensive_tool_keyword","cobaltstrike","EarlyBird process hollowing technique (BOF) - Spawns a process in a suspended state. inject shellcode. hijack main thread with APC and execute shellcode","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/HOLLOW","1","1","N/A","N/A","10","10","280","60","2023-03-08T15:51:19Z","2021-07-21T15:58:18Z","36182" +"*BokuLoader.cna*",".{0,1000}BokuLoader\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","36183" +"*BokuLoader.exe*",".{0,1000}BokuLoader\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","36184" +"*BokuLoader.x64*",".{0,1000}BokuLoader\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","36185" +"*Bonfee/CVE-2022-0995*",".{0,1000}Bonfee\/CVE\-2022\-0995.{0,1000}","offensive_tool_keyword","POC","CVE-2022-0995 exploit","T1550 - T1555 - T1212 - T1558","TA0005","N/A","N/A","Exploitation tool","https://github.com/Bonfee/CVE-2022-0995","1","1","N/A","N/A","N/A","5","497","67","2022-03-27T09:07:01Z","2022-03-26T21:46:09Z","36188" +"*BooExecutorImpl.cs*",".{0,1000}BooExecutorImpl\.cs.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","36189" +"*book.hacktricks.xyz/*",".{0,1000}book\.hacktricks\.xyz\/.{0,1000}","offensive_tool_keyword","hacktricks.xyz","site often consulted by pentester","T1596 - T1592","TA0043","N/A","Black Basta","Reconnaissance","https://hacktricks.xyz","1","1","N/A","N/A","8","10","N/A","N/A","N/A","N/A","36190" +"*bootkit-rs.git*",".{0,1000}bootkit\-rs\.git.{0,1000}","offensive_tool_keyword","bootkit-rs","Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus)","T1542.004 - T1067.002 - T1012 - T1053.005 - T1057","TA0002 - TA0040 - TA0003 - TA0001","N/A","N/A","Defense Evasion","https://github.com/memN0ps/bootkit-rs","1","1","N/A","N/A","N/A","6","528","67","2023-09-12T07:23:15Z","2023-04-11T03:53:15Z","36192" +"*bootkit-rs-master*",".{0,1000}bootkit\-rs\-master.{0,1000}","offensive_tool_keyword","bootkit-rs","Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus)","T1542.004 - T1067.002 - T1012 - T1053.005 - T1057","TA0002 - TA0040 - TA0003 - TA0001","N/A","N/A","Defense Evasion","https://github.com/memN0ps/bootkit-rs","1","1","N/A","N/A","N/A","6","528","67","2023-09-12T07:23:15Z","2023-04-11T03:53:15Z","36193" +"*BorjaMerino*Pazuzu*",".{0,1000}BorjaMerino.{0,1000}Pazuzu.{0,1000}","offensive_tool_keyword","Pazuzu","Pazuzu is a Python script that allows you to embed a binary within a precompiled DLL which uses reflective DLL injection. The goal is that you can run your own binary directly from memory. This can be useful in various scenarios.","T1055 - T1027 - T1071 - T1059","TA0002 - TA0005 - TA0011","N/A","N/A","Exploitation tool","https://github.com/BorjaMerino/Pazuzu","1","1","N/A","N/A","N/A","3","215","64","2020-08-04T18:49:36Z","2015-10-05T12:23:17Z","36202" +"*Bot_MSF_Exp_*.py*",".{0,1000}Bot_MSF_Exp_.{0,1000}\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","36203" +"*Bot_Python_Poc_Log4j2_VMwareHorizon.py*",".{0,1000}Bot_Python_Poc_Log4j2_VMwareHorizon\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","36204" +"*bpassthehash*",".{0,1000}bpassthehash.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","36206" +"*bpowerpick*",".{0,1000}bpowerpick.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36208" +"*bpsexec_command*",".{0,1000}bpsexec_command.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","36210" +"*bpsexec_command*",".{0,1000}bpsexec_command.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36211" +"*bpsexec_psh*",".{0,1000}bpsexec_psh.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","36212" +"*bpsinject*",".{0,1000}bpsinject.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36213" +"*bpysecdump.exe*",".{0,1000}bpysecdump\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","36214" +"*brc4_ldap_sentinel.py*",".{0,1000}brc4_ldap_sentinel\.py.{0,1000}","offensive_tool_keyword","bofhound","Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel","T1046 - T1087 - T1003","TA0007 - TA0009 - TA0001","N/A","N/A","Discovery","https://github.com/fortalice/bofhound","1","1","N/A","N/A","5","4","328","56","2024-02-23T15:36:24Z","2022-05-10T17:41:53Z","36218" +"*Brc4ConfigExtractor.exe*",".{0,1000}Brc4ConfigExtractor\.exe.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36219" +"*Brc4DecodeString*",".{0,1000}Brc4DecodeString.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36220" +"*breenmachine/RottenPotatoNG*",".{0,1000}breenmachine\/RottenPotatoNG.{0,1000}","offensive_tool_keyword","RottenPotatoNG","perform the RottenPotato attack and get a handle to a privileged token","T1134.001 - T1055.012 - T1547.001","TA0004","N/A","Sandworm","Privilege Escalation","https://github.com/breenmachine/RottenPotatoNG","1","1","N/A","N/A","8","10","935","183","2017-12-29T14:38:47Z","2017-12-29T13:19:03Z","36222" +"*breg_add_string_value*",".{0,1000}breg_add_string_value.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike beacon object file that allows you to query and make changes to the Windows Registry","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ausecwa/bof-registry","1","1","N/A","N/A","10","10","27","8","2021-02-11T04:38:28Z","2021-01-29T05:07:47Z","36226" +"*bremote_exec*",".{0,1000}bremote_exec.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","36227" +"*BronzeTicket/SharpNBTScan*",".{0,1000}BronzeTicket\/SharpNBTScan.{0,1000}","offensive_tool_keyword","SharpNBTScan","a NetBIOS scanner. Ghost actors use this tool for hostname and IP address enumeration","T1018 - T1046","TA0007","Ghost Ransomware","N/A","Discovery","https://github.com/BronzeTicket/SharpNBTScan","1","1","N/A","N/A","7","1","71","4","2021-08-06T05:36:55Z","2021-07-12T08:57:39Z","36234" +"*Bropper-main.zip*",".{0,1000}Bropper\-main\.zip.{0,1000}","offensive_tool_keyword","bropper","An automatic Blind ROP exploitation tool ","T1068 - T1059.003 - T1140","TA0002 - TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/Hakumarachi/Bropper","1","1","N/A","N/A","7","3","201","19","2023-06-09T12:40:05Z","2023-01-20T14:09:19Z","36236" +"*browser_##*",".{0,1000}browser_\#\#.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","36239" +"*browser_autopwn*",".{0,1000}browser_autopwn.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","36240" +"*browser_autopwn*",".{0,1000}browser_autopwn.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36241" +"*browser_autopwn2_spec.rb*",".{0,1000}browser_autopwn2_spec\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36242" +"*browser_exploit.rb*",".{0,1000}browser_exploit\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36243" +"*browser_exploit_server_spec.rb*",".{0,1000}browser_exploit_server_spec\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36244" +"*BrowserBookmarkDiscovery_BrowserHistory.py*",".{0,1000}BrowserBookmarkDiscovery_BrowserHistory\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","36245" +"*Browser-C2.git*",".{0,1000}Browser\-C2\.git.{0,1000}","offensive_tool_keyword","Browser-C2","Post Exploitation agent which uses a browser to do C2 operations.","T1105 - T1102","TA0003 - TA0005 - TA0008","N/A","N/A","C2","https://github.com/0x09AL/Browser-C2","1","1","N/A","N/A","10","10","102","28","2018-05-25T15:12:21Z","2018-05-22T14:33:24Z","36246" +"*Browser-C2-master.zip*",".{0,1000}Browser\-C2\-master\.zip.{0,1000}","offensive_tool_keyword","Browser-C2","Post Exploitation agent which uses a browser to do C2 operations.","T1105 - T1102","TA0003 - TA0005 - TA0008","N/A","N/A","C2","https://github.com/0x09AL/Browser-C2","1","1","N/A","N/A","10","10","102","28","2018-05-25T15:12:21Z","2018-05-22T14:33:24Z","36247" +"*BrowserDataGrabber.exe*",".{0,1000}BrowserDataGrabber\.exe.{0,1000}","offensive_tool_keyword","Browser Data Grabber","credential access tool used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://github.com/n37sn4k3/BrowserDataGrabber","1","1","N/A","N/A","10","1","7","4","2018-05-28T15:49:03Z","2018-05-04T12:33:32Z","36248" +"*BrowserDataGrabber-master.zip*",".{0,1000}BrowserDataGrabber\-master\.zip.{0,1000}","offensive_tool_keyword","Browser Data Grabber","credential access tool used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://github.com/n37sn4k3/BrowserDataGrabber","1","1","N/A","N/A","10","1","7","4","2018-05-28T15:49:03Z","2018-05-04T12:33:32Z","36249" +"*browserexploitserver.rb*",".{0,1000}browserexploitserver\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36250" +"*BrowserGhost.exe*",".{0,1000}BrowserGhost\.exe.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","1","N/A","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","36251" +"*BrowserGhost-N*.exe*",".{0,1000}BrowserGhost\-N.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","36252" +"*BrowserListener.py*",".{0,1000}BrowserListener\.py.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","N/A","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","36253" +"*Browser-password-stealer.git*",".{0,1000}Browser\-password\-stealer\.git.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","1","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","36254" +"*Browser-password-stealer-master*",".{0,1000}Browser\-password\-stealer\-master.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","1","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","36255" +"*BrowserSnatch.exe*",".{0,1000}BrowserSnatch\.exe.{0,1000}","offensive_tool_keyword","BrowserSnatch","steals important data from all chromium and gecko browsers installed in the system and gather the data in a stealer db to be exfiltrated out. A powerful Browser Stealer","T1081 - T1074 - T1114 - T1005 - T1041 - T1027","TA0006 - TA0009 - TA0010","N/A","N/A","Data Exfiltration","https://github.com/shaddy43/BrowserSnatch","1","1","N/A","N/A","10","3","246","39","2025-03-31T21:04:30Z","2024-08-26T18:38:42Z","36260" +"*BrowserSnatch64.exe*",".{0,1000}BrowserSnatch64\.exe.{0,1000}","offensive_tool_keyword","BrowserSnatch","steals important data from all chromium and gecko browsers installed in the system and gather the data in a stealer db to be exfiltrated out. A powerful Browser Stealer","T1081 - T1074 - T1114 - T1005 - T1041 - T1027","TA0006 - TA0009 - TA0010","N/A","N/A","Data Exfiltration","https://github.com/shaddy43/BrowserSnatch","1","1","N/A","N/A","10","3","246","39","2025-03-31T21:04:30Z","2024-08-26T18:38:42Z","36261" +"*BrowserSnatch-master.zip*",".{0,1000}BrowserSnatch\-master\.zip.{0,1000}","offensive_tool_keyword","BrowserSnatch","steals important data from all chromium and gecko browsers installed in the system and gather the data in a stealer db to be exfiltrated out. A powerful Browser Stealer","T1081 - T1074 - T1114 - T1005 - T1041 - T1027","TA0006 - TA0009 - TA0010","N/A","N/A","Data Exfiltration","https://github.com/shaddy43/BrowserSnatch","1","1","N/A","N/A","10","3","246","39","2025-03-31T21:04:30Z","2024-08-26T18:38:42Z","36262" +"*BrowsingHistoryView.cfg*",".{0,1000}BrowsingHistoryView\.cfg.{0,1000}","offensive_tool_keyword","BrowsingHistoryView","BrowsingHistoryView is a utility that reads the history data of different Web browsers","T1217 - T1070 - T1113","TA0009 - TA0005 - TA0007","N/A","GOBLIN PANDA","Discovery","https://www.nirsoft.net/utils/browsing_history_view.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36263" +"*BrowsingHistoryView.exe*",".{0,1000}BrowsingHistoryView\.exe.{0,1000}","offensive_tool_keyword","BrowsingHistoryView","BrowsingHistoryView is a utility that reads the history data of different Web browsers","T1217 - T1070 - T1113","TA0009 - TA0005 - TA0007","N/A","GOBLIN PANDA","Discovery","https://www.nirsoft.net/utils/browsing_history_view.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36264" +"*browsinghistoryview.zip*",".{0,1000}browsinghistoryview\.zip.{0,1000}","offensive_tool_keyword","BrowsingHistoryView","BrowsingHistoryView is a utility that reads the history data of different Web browsers","T1217 - T1070 - T1113","TA0009 - TA0005 - TA0007","N/A","GOBLIN PANDA","Discovery","https://www.nirsoft.net/utils/browsing_history_view.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36268" +"*browsinghistoryview-x64.zip*",".{0,1000}browsinghistoryview\-x64\.zip.{0,1000}","offensive_tool_keyword","BrowsingHistoryView","BrowsingHistoryView is a utility that reads the history data of different Web browsers","T1217 - T1070 - T1113","TA0009 - TA0005 - TA0007","N/A","GOBLIN PANDA","Discovery","https://www.nirsoft.net/utils/browsing_history_view.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36269" +"*brun_script_in_mem*",".{0,1000}brun_script_in_mem.{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","36271" +"*brunasadmin*",".{0,1000}brunasadmin.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36272" +"*Brute/Brute.cs*",".{0,1000}Brute\/Brute\.cs.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","36275" +"*Brute/Brute.csproj*",".{0,1000}Brute\/Brute\.csproj.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","36276" +"*Brute/Brute.sln*",".{0,1000}Brute\/Brute\.sln.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","36277" +"*brute_force_ntlm.sh*",".{0,1000}brute_force_ntlm\.sh.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","36278" +"*bruteforce.go*",".{0,1000}bruteforce\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","36281" +"*BruteForce.ps1*",".{0,1000}BruteForce\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","36282" +"*BruteforceCLSIDs.*",".{0,1000}BruteforceCLSIDs\..{0,1000}","offensive_tool_keyword","JuicyPotatoNG","Another Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","FoxKitten - APT33 - Volatile Cedar - Sandworm","Privilege Escalation","https://github.com/antonioCoco/JuicyPotatoNG","1","1","N/A","N/A","10","9","844","101","2022-11-12T01:48:39Z","2022-09-21T17:08:35Z","36290" +"*Brute-force-Instagram-*.git*",".{0,1000}Brute\-force\-Instagram\-.{0,1000}\.git.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/insta-bf","1","1","N/A","N/A","7","1","59","13","2024-04-23T02:47:28Z","2020-11-20T22:22:48Z","36292" +"*bruteForceUser*",".{0,1000}bruteForceUser.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","36296" +"*bruteloader*",".{0,1000}bruteloader.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36298" +"*brute-ratel-*",".{0,1000}brute\-ratel\-.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36300" +"*BruteRatel*.tar.gz*",".{0,1000}BruteRatel.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36301" +"*BruteRatel*.zip*",".{0,1000}BruteRatel.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36302" +"*bruteratel.com/*",".{0,1000}bruteratel\.com\/.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36303" +"*bruteratel/*",".{0,1000}bruteratel\/.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36304" +"*Brute-Ratel-C4*",".{0,1000}Brute\-Ratel\-C4.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36305" +"*Brutesploit.git*",".{0,1000}Brutesploit\.git.{0,1000}","offensive_tool_keyword","BruteSploit","BruteSploit is a collection of method for automated Generate. Bruteforce and Manipulation wordlist with interactive shell. That can be used during a penetration test to enumerate and maybe can be used in CTF for manipulation.combine.transform and permutation some words or file text","T1110","N/A","N/A","N/A","Exploitation tool","https://github.com/screetsec/BruteSploit","1","1","N/A","N/A","N/A","8","741","263","2020-04-05T00:29:26Z","2017-05-31T17:00:51Z","36306" +"*BruteSploit/wlist/*",".{0,1000}BruteSploit\/wlist\/.{0,1000}","offensive_tool_keyword","BruteSploit","BruteSploit is a collection of method for automated Generate. Bruteforce and Manipulation wordlist with interactive shell. That can be used during a penetration test to enumerate and maybe can be used in CTF for manipulation.combine.transform and permutation some words or file text","T1110","N/A","N/A","N/A","Exploitation tool","https://github.com/screetsec/BruteSploit","1","1","N/A","N/A","N/A","8","741","263","2020-04-05T00:29:26Z","2017-05-31T17:00:51Z","36307" +"*brutespray.exe*",".{0,1000}brutespray.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","1","N/A","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","36309" +"*brutespray.go*",".{0,1000}brutespray\.go.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","1","N/A","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","36310" +"*brutespray/brute*",".{0,1000}brutespray\/brute.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","1","N/A","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","36311" +"*BruteStager.csproj*",".{0,1000}BruteStager\.csproj.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","36313" +"*BruteStager.sln*",".{0,1000}BruteStager\.sln.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","36314" +"*bruteuser.go*",".{0,1000}bruteuser\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","36315" +"*bruteuserCmd*",".{0,1000}bruteuserCmd.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","36316" +"*bshinject*",".{0,1000}bshinject.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","36318" +"*bshinject*",".{0,1000}bshinject.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36319" +"*bshspawn*",".{0,1000}bshspawn.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","36320" +"*bsteal_token*",".{0,1000}bsteal_token.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","36321" +"*bsteal_token*",".{0,1000}bsteal_token.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36322" +"*bucketloot-darwin64*",".{0,1000}bucketloot\-darwin64.{0,1000}","offensive_tool_keyword","BucketLoot","BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets- flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain-text","T1562.007 - T1119 - T1530","TA0006 - TA0010","N/A","N/A","Discovery","https://github.com/redhuntlabs/BucketLoot","1","1","#linux","N/A","7","5","409","58","2025-01-22T10:48:27Z","2023-07-17T09:06:14Z","36335" +"*bucketloot-freebsd64*",".{0,1000}bucketloot\-freebsd64.{0,1000}","offensive_tool_keyword","BucketLoot","BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets- flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain-text","T1562.007 - T1119 - T1530","TA0006 - TA0010","N/A","N/A","Discovery","https://github.com/redhuntlabs/BucketLoot","1","1","N/A","N/A","7","5","409","58","2025-01-22T10:48:27Z","2023-07-17T09:06:14Z","36336" +"*BucketLoot-master*",".{0,1000}BucketLoot\-master.{0,1000}","offensive_tool_keyword","BucketLoot","BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets- flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain-text","T1562.007 - T1119 - T1530","TA0006 - TA0010","N/A","N/A","Discovery","https://github.com/redhuntlabs/BucketLoot","1","1","N/A","N/A","7","5","409","58","2025-01-22T10:48:27Z","2023-07-17T09:06:14Z","36337" +"*bucketloot-openbsd64*",".{0,1000}bucketloot\-openbsd64.{0,1000}","offensive_tool_keyword","BucketLoot","BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets- flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain-text","T1562.007 - T1119 - T1530","TA0006 - TA0010","N/A","N/A","Discovery","https://github.com/redhuntlabs/BucketLoot","1","1","N/A","N/A","7","5","409","58","2025-01-22T10:48:27Z","2023-07-17T09:06:14Z","36338" +"*bucketloot-windows32.exe*",".{0,1000}bucketloot\-windows32\.exe.{0,1000}","offensive_tool_keyword","BucketLoot","BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets- flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain-text","T1562.007 - T1119 - T1530","TA0006 - TA0010","N/A","N/A","Discovery","https://github.com/redhuntlabs/BucketLoot","1","1","N/A","N/A","7","5","409","58","2025-01-22T10:48:27Z","2023-07-17T09:06:14Z","36339" +"*bucketloot-windows64.exe*",".{0,1000}bucketloot\-windows64\.exe.{0,1000}","offensive_tool_keyword","BucketLoot","BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets- flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain-text","T1562.007 - T1119 - T1530","TA0006 - TA0010","N/A","N/A","Discovery","https://github.com/redhuntlabs/BucketLoot","1","1","N/A","N/A","7","5","409","58","2025-01-22T10:48:27Z","2023-07-17T09:06:14Z","36340" +"*buffer_overflow.py*",".{0,1000}buffer_overflow\.py.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","36341" +"*bugch3ck/SharpAltSecIds*",".{0,1000}bugch3ck\/SharpAltSecIds.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","1","N/A","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","36342" +"*build/breg.cna*",".{0,1000}build\/breg\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike beacon object file that allows you to query and make changes to the Windows Registry","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ausecwa/bof-registry","1","1","N/A","N/A","10","10","27","8","2021-02-11T04:38:28Z","2021-01-29T05:07:47Z","36354" +"*build_40xshikata_revhttpsunstaged_win32.sh*",".{0,1000}build_40xshikata_revhttpsunstaged_win32\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36356" +"*build_50xshikata_quiet_revhttps_win32.sh*",".{0,1000}build_50xshikata_quiet_revhttps_win32\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36357" +"*build_50xshikata_revhttps_win32.sh*",".{0,1000}build_50xshikata_revhttps_win32\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36358" +"*build_asciimsf_fromcmd_revhttps_win32.sh*",".{0,1000}build_asciimsf_fromcmd_revhttps_win32\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36359" +"*build_asciimsf_revhttps_win32.sh*",".{0,1000}build_asciimsf_revhttps_win32\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36360" +"*build_avetenc_dynamicfromfile_revhttps_win32.sh*",".{0,1000}build_avetenc_dynamicfromfile_revhttps_win32\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36361" +"*build_avetenc_fopen_revhttps_win32.sh*",".{0,1000}build_avetenc_fopen_revhttps_win32\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36362" +"*build_avetenc_mtrprtrxor_revhttps_win64.sh*",".{0,1000}build_avetenc_mtrprtrxor_revhttps_win64\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36363" +"*build_c_shellcode*",".{0,1000}build_c_shellcode.{0,1000}","offensive_tool_keyword","cobaltstrike","A protective and Low Level Shellcode Loader that defeats modern EDR systems.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/cribdragg3r/Alaris","1","1","N/A","N/A","10","10","903","142","2024-03-20T15:50:57Z","2020-02-22T15:42:37Z","36364" +"*build_calcfromcmd_50xshikata_revhttps_win32.sh*",".{0,1000}build_calcfromcmd_50xshikata_revhttps_win32\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36367" +"*build_calcfrompowersh_50xshikata_revhttps_win32.sh*",".{0,1000}build_calcfrompowersh_50xshikata_revhttps_win32\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36368" +"*build_checkdomain_rc4_mimikatz.sh*",".{0,1000}build_checkdomain_rc4_mimikatz\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36369" +"*build_disablewindefpsh_xorfromcmd_revhttps_win64.sh*",".{0,1000}build_disablewindefpsh_xorfromcmd_revhttps_win64\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36370" +"*build_dkmc_downloadexecshc_revhttps_win32.sh*",".{0,1000}build_dkmc_downloadexecshc_revhttps_win32\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36371" +"*build_downloadbitsadmin_mtrprtrxor_revhttps_win64.sh*",".{0,1000}build_downloadbitsadmin_mtrprtrxor_revhttps_win64\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36372" +"*build_downloadbitsadmin_revhttps_win32.sh*",".{0,1000}build_downloadbitsadmin_revhttps_win32\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36373" +"*build_downloadcertutil_revhttps_win32.sh*",".{0,1000}build_downloadcertutil_revhttps_win32\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36374" +"*build_downloadcurl_mtrprtrxor_revhttps_win64.sh*",".{0,1000}build_downloadcurl_mtrprtrxor_revhttps_win64\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36375" +"*build_onionpipe.bash*",".{0,1000}build_onionpipe\.bash.{0,1000}","offensive_tool_keyword","onionpipe","onionpipe forwards ports on the local host to remote Onion addresses as Tor hidden services and vice-versa.","T1090.003 - T1573.002","TA0005 - TA0011","N/A","Black Basta","Defense Evasion","https://github.com/cmars/onionpipe","1","1","#linux","N/A","10","6","553","33","2025-04-22T16:34:56Z","2022-01-23T06:52:13Z","36377" +"*build_sleep_rc4_mimikatz.sh*",".{0,1000}build_sleep_rc4_mimikatz\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36378" +"*build_svc_20xshikata_bindtcp_win32.sh*",".{0,1000}build_svc_20xshikata_bindtcp_win32\.sh.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","36379" +"*build_tor_darwin.bash*",".{0,1000}build_tor_darwin\.bash.{0,1000}","offensive_tool_keyword","onionpipe","onionpipe forwards ports on the local host to remote Onion addresses as Tor hidden services and vice-versa.","T1090.003 - T1573.002","TA0005 - TA0011","N/A","Black Basta","Defense Evasion","https://github.com/cmars/onionpipe","1","1","#linux","N/A","10","6","553","33","2025-04-22T16:34:56Z","2022-01-23T06:52:13Z","36380" +"*build_tor_debian.bash*",".{0,1000}build_tor_debian\.bash.{0,1000}","offensive_tool_keyword","onionpipe","onionpipe forwards ports on the local host to remote Onion addresses as Tor hidden services and vice-versa.","T1090.003 - T1573.002","TA0005 - TA0011","N/A","Black Basta","Defense Evasion","https://github.com/cmars/onionpipe","1","1","#linux","N/A","10","6","553","33","2025-04-22T16:34:56Z","2022-01-23T06:52:13Z","36381" +"*BuildBOFs.exe*",".{0,1000}BuildBOFs\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","C# .Net 5.0 project to build BOF (Beacon Object Files) in mass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ceramicskate0/BOF-Builder","1","1","N/A","N/A","10","10","28","4","2023-07-25T22:19:27Z","2021-09-07T01:28:11Z","36382" +"*BuildBOFs.sln*",".{0,1000}BuildBOFs\.sln.{0,1000}","offensive_tool_keyword","cobaltstrike","C# .Net 5.0 project to build BOF (Beacon Object Files) in mass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ceramicskate0/BOF-Builder","1","1","N/A","N/A","10","10","28","4","2023-07-25T22:19:27Z","2021-09-07T01:28:11Z","36383" +"*BulletsPassView.exe*",".{0,1000}BulletsPassView\.exe.{0,1000}","offensive_tool_keyword","bulletpassview","BulletsPassView is a password recovery tool that reveals the passwords stored behind the bullets in the standard password text-box of Windows operating system and Internet Explorer Web browser. After revealing the passwords. you can easily copy them to the clipboard or save them into text/html/csv/xml file.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/bullets_password_view.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36390" +"*BulletsPassView.zip*",".{0,1000}BulletsPassView\.zip.{0,1000}","offensive_tool_keyword","bulletpassview","BulletsPassView is a password recovery tool that reveals the passwords stored behind the bullets in the standard password text-box of Windows operating system and Internet Explorer Web browser. After revealing the passwords. you can easily copy them to the clipboard or save them into text/html/csv/xml file.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/bullets_password_view.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36391" +"*BulletsPassView_setup.exe*",".{0,1000}BulletsPassView_setup\.exe.{0,1000}","offensive_tool_keyword","bulletpassview","BulletsPassView is a password recovery tool that reveals the passwords stored behind the bullets in the standard password text-box of Windows operating system and Internet Explorer Web browser. After revealing the passwords. you can easily copy them to the clipboard or save them into text/html/csv/xml file.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/bullets_password_view.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36392" +"*BulletsPassView_x64.exe*",".{0,1000}BulletsPassView_x64\.exe.{0,1000}","offensive_tool_keyword","bulletpassview","BulletsPassView is a password recovery tool that reveals the passwords stored behind the bullets in the standard password text-box of Windows operating system and Internet Explorer Web browser. After revealing the passwords. you can easily copy them to the clipboard or save them into text/html/csv/xml file.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/bullets_password_view.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36393" +"*bunny.deb.parrot.sh/*",".{0,1000}bunny\.deb\.parrot\.sh\/.{0,1000}","offensive_tool_keyword","parrot os","Parrot OS is a Debian-based. security-oriented Linux distribution that is designed for ethical hacking. penetration testing and digital forensics.","T1590 - T1200 - T1027 - T1578 - T1003 - T1001 - T1046 - T1570 - T1114 - T1105","TA0043 - TA0002 - TA0003 - TA0004 - TA0006 - TA0005 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation OS","https://www.parrotsec.org/download/","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","36395" +"*bupload_raw*.dll*",".{0,1000}bupload_raw.{0,1000}\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","New UAC bypass for Silent Cleanup for CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EncodeGroup/UAC-SilentClean","1","1","N/A","N/A","10","10","192","31","2021-07-14T13:51:02Z","2020-10-07T13:25:21Z","36396" +"*burnett_top_1024.txt*",".{0,1000}burnett_top_1024\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36398" +"*burp*PayloadParser.py*",".{0,1000}burp.{0,1000}PayloadParser\.py.{0,1000}","offensive_tool_keyword","burpsuite","PayloadParser - Burp Suite NMap Parsing Interface in Python","T1583 - T1595 - T1190","TA0001 - TA0003 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/infodel/burp.extension-payloadparser","1","1","N/A","network exploitation tool","N/A","1","4","4","2013-03-15T20:41:45Z","2013-03-15T20:39:23Z","36400" +"*burp*SQLMapper.xml*",".{0,1000}burp.{0,1000}SQLMapper\.xml.{0,1000}","offensive_tool_keyword","burpsuite","CO2 is a project for lightweight and useful enhancements to Portswigger popular Burp Suite web penetration tool through the standard Extender API","T1583 - T1595 - T1190","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/JGillam/burp-co2","1","1","N/A","network exploitation tool","N/A","2","152","34","2024-02-21T02:23:00Z","2015-04-19T03:38:34Z","36401" +"*burp.extension-payloadparser*",".{0,1000}burp\.extension\-payloadparser.{0,1000}","offensive_tool_keyword","burpsuite","PayloadParser - Burp Suite NMap Parsing Interface in Python","T1583 - T1595 - T1190","TA0001 - TA0003 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/infodel/burp.extension-payloadparser","1","1","N/A","network exploitation tool","N/A","1","4","4","2013-03-15T20:41:45Z","2013-03-15T20:39:23Z","36402" +"*Burp_start.bat*",".{0,1000}Burp_start\.bat.{0,1000}","offensive_tool_keyword","burpsuite","Collection of burpsuite plugins","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","network exploitation tool","N/A","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","36404" +"*Burp_start_en.bat*",".{0,1000}Burp_start_en\.bat.{0,1000}","offensive_tool_keyword","burpsuite","Collection of burpsuite plugins","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","network exploitation tool","N/A","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","36405" +"*burp2malleable.*",".{0,1000}burp2malleable\..{0,1000}","offensive_tool_keyword","cobaltstrike","Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CodeXTF2/Burp2Malleable","1","1","N/A","N/A","10","10","385","34","2023-04-06T15:24:12Z","2022-08-14T18:05:39Z","36406" +"*burp-co2/out/artifacts*",".{0,1000}burp\-co2\/out\/artifacts.{0,1000}","offensive_tool_keyword","burpsuite","CO2 is a project for lightweight and useful enhancements to Portswigger popular Burp Suite web penetration tool through the standard Extender API","T1583 - T1595 - T1190","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/JGillam/burp-co2","1","1","N/A","network exploitation tool","N/A","2","152","34","2024-02-21T02:23:00Z","2015-04-19T03:38:34Z","36407" +"*BurpCO2Suite.xml*",".{0,1000}BurpCO2Suite\.xml.{0,1000}","offensive_tool_keyword","burpsuite","CO2 is a project for lightweight and useful enhancements to Portswigger popular Burp Suite web penetration tool through the standard Extender API","T1583 - T1595 - T1190","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/JGillam/burp-co2","1","1","N/A","network exploitation tool","N/A","2","152","34","2024-02-21T02:23:00Z","2015-04-19T03:38:34Z","36408" +"*burpcollaborator.net*",".{0,1000}burpcollaborator\.net.{0,1000}","offensive_tool_keyword","burpsuite","Burp Suite is a leading range of cybersecurity tools. brought to you by PortSwigger. We believe in giving our users a competitive advantage through superior research. This tool is not free and open source","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://portswigger.net/burp","1","1","N/A","network exploitation tool","N/A","N/A","N/A","N/A","N/A","N/A","36409" +"*BurpFunctions.java*",".{0,1000}BurpFunctions\.java.{0,1000}","offensive_tool_keyword","burpsuite","A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/nccgroup/BurpSuiteHTTPSmuggler","1","1","N/A","network exploitation tool","N/A","8","721","107","2019-05-04T06:15:42Z","2018-07-03T07:47:58Z","36410" +"*burpitem.py*",".{0,1000}burpitem\.py.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","36411" +"*burplog.py*",".{0,1000}burplog\.py.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","36412" +"*burp-log4shell.jar*",".{0,1000}burp\-log4shell\.jar.{0,1000}","offensive_tool_keyword","burp-log4shell","Log4Shell scanner for Burp Suite","T1190 - T1059.008 - T1071.001","TA0001 - TA0002 - TA0011","N/A","Dispossessor","Exploitation tool","https://github.com/silentsignal/burp-log4shell","1","1","N/A","N/A","8","5","484","72","2023-09-24T08:29:56Z","2021-12-12T14:52:49Z","36413" +"*BurpShiroPassiveScan.jar*",".{0,1000}BurpShiroPassiveScan\.jar.{0,1000}","offensive_tool_keyword","burpsuite","Collection of burpsuite plugins","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","network exploitation tool","N/A","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","36414" +"*burpstate.py*",".{0,1000}burpstate\.py.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","36415" +"*Burpsuite*",".{0,1000}Burpsuite.{0,1000}","offensive_tool_keyword","burpsuite","Burp Suite is a leading range of cybersecurity tools. brought to you by PortSwigger. We believe in giving our users a competitive advantage through superior research. This tool is not free and open source","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://portswigger.net/burp","1","1","N/A","network exploitation tool","N/A","N/A","N/A","N/A","N/A","N/A","36416" +"*burpsuite*.exe*",".{0,1000}burpsuite.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","burpsuite","The class-leading vulnerability scanning. penetration testing. and web app security platform","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://portswigger.net/burp","1","1","N/A","network exploitation tool","N/A","N/A","N/A","N/A","N/A","N/A","36417" +"*burpsuite*.jar*",".{0,1000}burpsuite.{0,1000}\.jar.{0,1000}","offensive_tool_keyword","burpsuite","The class-leading vulnerability scanning. penetration testing. and web app security platform","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://portswigger.net/burp","1","1","N/A","network exploitation tool","N/A","N/A","N/A","N/A","N/A","N/A","36418" +"*burpsuite*.sh*",".{0,1000}burpsuite.{0,1000}\.sh.{0,1000}","offensive_tool_keyword","burpsuite","The class-leading vulnerability scanning. penetration testing. and web app security platform","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://portswigger.net/burp","1","1","N/A","network exploitation tool","N/A","N/A","N/A","N/A","N/A","N/A","36419" +"*burpsuite*.zip*",".{0,1000}burpsuite.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","burpsuite","The class-leading vulnerability scanning. penetration testing. and web app security platform","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://portswigger.net/burp","1","1","N/A","network exploitation tool","N/A","N/A","N/A","N/A","N/A","N/A","36420" +"*BurpSuiteCn.jar*",".{0,1000}BurpSuiteCn\.jar.{0,1000}","offensive_tool_keyword","burpsuite","Collection of burpsuite plugins","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","network exploitation tool","N/A","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","36421" +"*BurpSuiteHTTPSmuggler*",".{0,1000}BurpSuiteHTTPSmuggler.{0,1000}","offensive_tool_keyword","burpsuite","A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/nccgroup/BurpSuiteHTTPSmuggler","1","1","N/A","network exploitation tool","N/A","8","721","107","2019-05-04T06:15:42Z","2018-07-03T07:47:58Z","36422" +"*BurpSuite-SecretFinder*",".{0,1000}BurpSuite\-SecretFinder.{0,1000}","offensive_tool_keyword","secretfinder","SecretFinder is a python script based on LinkFinder written to discover sensitive data like apikeys - accesstoken - authorizations - jwt..etc in JavaScript files","T1083 - T1081 - T1113","TA0003 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/m4ll0k/SecretFinder","1","1","N/A","N/A","N/A","10","2153","405","2024-05-26T09:36:41Z","2020-06-08T10:50:12Z","36423" +"*burp-vulners-scanner-*.jar*",".{0,1000}burp\-vulners\-scanner\-.{0,1000}\.jar.{0,1000}","offensive_tool_keyword","burpsuite","Collection of burpsuite plugins","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","network exploitation tool","N/A","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","36424" +"*burp-xss-sql-plugin*",".{0,1000}burp\-xss\-sql\-plugin.{0,1000}","offensive_tool_keyword","burpsuite","find several bugbounty-worthy XSSes. OpenRedirects and SQLi.","T1583 - T1595 - T1190","TA0001 - TA0002 - TA0008 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/attackercan/burp-xss-sql-plugin","1","1","N/A","network exploitation tool","N/A","1","44","12","2016-09-28T21:46:18Z","2016-08-17T14:05:24Z","36425" +"*busterPayloads.txt*",".{0,1000}busterPayloads\.txt.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","36427" +"*bwjbbpbcihglahwxxusmyy2nxqdc4oqy4rvyhayn4dxhqzji4qi7taid.onion*",".{0,1000}bwjbbpbcihglahwxxusmyy2nxqdc4oqy4rvyhayn4dxhqzji4qi7taid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","36431" +"*bWV0YXNwbG9pdA==*",".{0,1000}bWV0YXNwbG9pdA\=\=.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","36434" +"*byakugan/bin/*",".{0,1000}byakugan\/bin\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","#linux","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36440" +"*Bye_Explorer.ino*",".{0,1000}Bye_Explorer\.ino.{0,1000}","offensive_tool_keyword","Pateensy","payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy","T1056.001 - T1200 - T1036 - T1071","TA0002 - TA0005 - TA0011 - TA0006","N/A","N/A","Exploitation tool","https://github.com/screetsec/Pateensy","1","1","N/A","N/A","N/A","2","143","60","2017-01-26T12:02:56Z","2016-03-21T07:29:38Z","36441" +"*byinarie/teams_dump*",".{0,1000}byinarie\/teams_dump.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1560.001 - T1555.003 - T1113 - T1557","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","1","N/A","N/A","7","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","36442" +"*byinarie/teams_dump*",".{0,1000}byinarie\/teams_dump.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1555 - T1003 - T1114","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","1","N/A","N/A","9","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","36443" +"*BYOVD_kill_av_edr.*",".{0,1000}BYOVD_kill_av_edr\..{0,1000}","offensive_tool_keyword","BYOVD_kill_av_edr","BYOD to kill AV/EDR","T1562.001","TA0040 - TA0005","N/A","N/A","Defense Evasion","https://github.com/infosecn1nja/red-team-scripts/blob/main/BYOVD_kill_av_edr.c","1","1","N/A","N/A","10","3","299","55","2024-08-08T06:11:06Z","2023-01-15T22:37:34Z","36444" +"*bypass_cmdinject*",".{0,1000}bypass_cmdinject.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36465" +"*bypass_powershell_protections*",".{0,1000}bypass_powershell_protections.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36466" +"*BypassAV.exe*",".{0,1000}BypassAV\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike plugin for quickly generating anti-kill executable files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/hack2fun/BypassAV","1","1","N/A","N/A","10","10","908","125","2020-07-19T15:46:54Z","2020-02-17T02:33:14Z","36470" +"*bypass-classic.dll*",".{0,1000}bypass\-classic\.dll.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","36472" +"*BypassCredGuard/zipball*",".{0,1000}BypassCredGuard\/zipball.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","1","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","36473" +"*BypassCredGuard-master*",".{0,1000}BypassCredGuard\-master.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","1","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","36474" +"*BYPASS-DINVOKE*.dll*",".{0,1000}BYPASS\-DINVOKE.{0,1000}\.dll.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1027 - T1055 - T1070 - T1112 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","36475" +"*BYPASS-DINVOKE.dll*",".{0,1000}BYPASS\-DINVOKE\.dll.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","36476" +"*BYPASS-DINVOKE_MANUAL_MAPPING.dll*",".{0,1000}BYPASS\-DINVOKE_MANUAL_MAPPING\.dll.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","36477" +"*bypass-pipe.c*",".{0,1000}bypass\-pipe\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36478" +"*bypass-powershell.ps1*",".{0,1000}bypass\-powershell\.ps1.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","36479" +"*Bypass-UAC*",".{0,1000}Bypass\-UAC.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","36482" +"*bypassUAC*.boo*",".{0,1000}bypassUAC.{0,1000}\.boo.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","36483" +"*bypassUAC*.py*",".{0,1000}bypassUAC.{0,1000}\.py.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","36484" +"*bypassuac_comhijack.rb*",".{0,1000}bypassuac_comhijack\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36486" +"*bypassuac_compdefaults*",".{0,1000}bypassuac_compdefaults.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","36487" +"*bypassuac_compmgmtlauncher*",".{0,1000}bypassuac_compmgmtlauncher.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","36488" +"*bypassuac_eventvwr*",".{0,1000}bypassuac_eventvwr.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","36489" +"*bypassuac_fodhelper*",".{0,1000}bypassuac_fodhelper.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","36490" +"*bypassuac_injection*",".{0,1000}bypassuac_injection.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36491" +"*bypassuac_injection.*",".{0,1000}bypassuac_injection\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36492" +"*bypassuac_injection.rb*",".{0,1000}bypassuac_injection\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36493" +"*bypassuac_injection_winsxs.rb*",".{0,1000}bypassuac_injection_winsxs\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36494" +"*bypassuac_registry.*",".{0,1000}bypassuac_registry\..{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","36495" +"*bypassuac_sdclt*",".{0,1000}bypassuac_sdclt.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","36496" +"*bypassuac_silentcleanup.rb*",".{0,1000}bypassuac_silentcleanup\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36497" +"*bypassuac_slui*",".{0,1000}bypassuac_slui.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","36498" +"*bypassuac_sluihijack.*",".{0,1000}bypassuac_sluihijack\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36499" +"*bypassuac_systempropertiesadvanced*",".{0,1000}bypassuac_systempropertiesadvanced.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","36500" +"*bypassuac_token_imp.*",".{0,1000}bypassuac_token_imp\..{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","36501" +"*bypassuac_vbs.*",".{0,1000}bypassuac_vbs\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36502" +"*bypassuac_windows_store_reg.rb*",".{0,1000}bypassuac_windows_store_reg\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36503" +"*bypassuac_wsreset*",".{0,1000}bypassuac_wsreset.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","36504" +"*BypassUAC-ETV.exe*",".{0,1000}BypassUAC\-ETV\.exe.{0,1000}","offensive_tool_keyword","XiebroC2","Command and control server - multi-person collaborative penetration testing graphical framework","T1105 - T1573.001 - T1055.001 - T1071 - T1041 - T1059.001 - T1059.008 - T1102","TA0011 - TA0003 - TA0005 - TA0007 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/INotGreen/Xiebro-Plugins","1","1","N/A","N/A","10","10","46","8","2025-02-27T09:17:31Z","2024-02-18T02:01:06Z","36505" +"*BypassUACTokenManipulation*",".{0,1000}BypassUACTokenManipulation.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1122","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","36506" +"*bypassuac-x64.dll*",".{0,1000}bypassuac\-x64\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36507" +"*bypassuac-x64.exe*",".{0,1000}bypassuac\-x64\.exe.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36508" +"*bypassuac-x86.dll*",".{0,1000}bypassuac\-x86\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36509" +"*bypassuac-x86.exe*",".{0,1000}bypassuac\-x86\.exe.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","36510" +"*bypasswaf.jar*",".{0,1000}bypasswaf\.jar.{0,1000}","offensive_tool_keyword","burpsuite","Collection of burpsuite plugins","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","network exploitation tool","N/A","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","36511" +"*bypasswaf.jar*",".{0,1000}bypasswaf\.jar.{0,1000}","offensive_tool_keyword","bypasswaf","Add headers to all Burp requests to bypass some WAF products","T1090 - T1189 - T1001","TA0002 - TA0040","N/A","N/A","Defense Evasion","https://github.com/codewatchorg/bypasswaf","1","1","N/A","network exploitation tool","N/A","4","331","104","2018-01-28T13:13:39Z","2014-11-17T01:29:35Z","36512" +"*bypasswaf.py*",".{0,1000}bypasswaf\.py.{0,1000}","offensive_tool_keyword","bypasswaf","Add headers to all Burp requests to bypass some WAF products","T1090 - T1189 - T1001","TA0002 - TA0040","N/A","N/A","Defense Evasion","https://github.com/codewatchorg/bypasswaf","1","1","N/A","network exploitation tool","N/A","4","331","104","2018-01-28T13:13:39Z","2014-11-17T01:29:35Z","36513" +"*byt3bl33d3r/BOF-Nim*",".{0,1000}byt3bl33d3r\/BOF\-Nim.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF Files with Nim!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/byt3bl33d3r/BOF-Nim","1","1","N/A","N/A","10","10","84","13","2022-07-10T22:12:10Z","2021-01-12T18:58:23Z","36514" +"*byt3bl33d3r/dnschef-ng*",".{0,1000}byt3bl33d3r\/dnschef\-ng.{0,1000}","offensive_tool_keyword","dnschef-ng","DNSChef is a highly configurable DNS proxy for Penetration Testers and Malware Analysts. A DNS proxy (aka ""Fake DNS"") is a tool used for application network traffic analysis among other uses. For example - a DNS proxy can be used to fake requests for ""badguy.com"" to point to a local machine for termination or interception instead of a real host somewhere on the Internet.","T1568 - T1583 - T1071","TA0001 - TA0042 - TA0005","N/A","N/A","Sniffing & Spoofing","https://github.com/byt3bl33d3r/dnschef-ng","1","1","N/A","N/A","8","2","153","14","2023-11-26T06:57:04Z","2021-12-24T21:07:29Z","36516" +"*byt3bl33d3r/gcat*",".{0,1000}byt3bl33d3r\/gcat.{0,1000}","offensive_tool_keyword","gcat","A PoC backdoor that uses Gmail as a C&C server","T1071.001 - T1094 - T1102.002","TA0011 - TA0010 - TA0008","N/A","Sandworm","C2","https://github.com/byt3bl33d3r/gcat","1","1","N/A","N/A","10","10","1332","425","2018-11-16T13:43:15Z","2015-06-03T01:28:00Z","36517" +"*byt3bl33d3r/ItWasAllADream*",".{0,1000}byt3bl33d3r\/ItWasAllADream.{0,1000}","offensive_tool_keyword","ItWasAllADream","A PrintNightmare (CVE-2021-34527) Python Scanner. Scan entire subnets for hosts vulnerable to the PrintNightmare RCE","T1046 - T1210.002 - T1047","TA0007 - TA0002","N/A","N/A","Discovery","https://github.com/byt3bl33d3r/ItWasAllADream","1","1","N/A","N/A","7","8","796","123","2024-05-19T16:25:52Z","2021-07-05T20:13:49Z","36518" +"*byt3bl33d3r/NimDllSideload*",".{0,1000}byt3bl33d3r\/NimDllSideload.{0,1000}","offensive_tool_keyword","NimDllSideload","DLL sideloading/proxying","T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/byt3bl33d3r/NimDllSideload","1","1","N/A","N/A","9","2","167","17","2022-12-04T21:52:49Z","2022-12-03T03:25:57Z","36519" +"*byt3bl33d3r/pth-toolkit*",".{0,1000}byt3bl33d3r\/pth\-toolkit.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","36520" +"*byt3bl33d3r/pth-toolkit*",".{0,1000}byt3bl33d3r\/pth\-toolkit.{0,1000}","offensive_tool_keyword","pth-toolkit","A modified version of the passing-the-hash tool collection https://code.google.com/p/passing-the-hash/ designed to be portable and work straight out of the box even on the most 'bare bones' systems","T1550.002 - T1075 - T1078","TA0006 - TA0008","N/A","APT1","Lateral Movement","https://github.com/byt3bl33d3r/pth-toolkit","1","1","N/A","N/A","10","6","575","131","2015-02-06T15:10:41Z","2015-02-03T10:31:56Z","36521" +"*byt3bl33d3r/SpamChannel*",".{0,1000}byt3bl33d3r\/SpamChannel.{0,1000}","offensive_tool_keyword","SpamChannel","poof emails from any of the +2 Million domains using MailChannels","T1566 - T1566.001","TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/byt3bl33d3r/SpamChannel","1","1","N/A","N/A","8","4","335","36","2023-09-21T12:25:03Z","2022-12-20T21:31:55Z","36522" +"*byt3bl33d3r/SprayingToolkit*",".{0,1000}byt3bl33d3r\/SprayingToolkit.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","1","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","36523" +"*bytecode77/r77-rootkit*",".{0,1000}bytecode77\/r77\-rootkit.{0,1000}","offensive_tool_keyword","r77-rootkit","Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections","T1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/bytecode77/r77-rootkit","1","1","N/A","N/A","10","10","1884","425","2025-03-25T17:59:20Z","2017-12-17T13:04:14Z","36525" +"*C??/generator.cpp*",".{0,1000}C\?\?\/generator\.cpp.{0,1000}","offensive_tool_keyword","cobaltstrike","CS anti-killing including python version and C version","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Gality369/CS-Loader","1","1","N/A","N/A","10","10","829","141","2025-04-02T09:37:10Z","2020-08-17T21:33:06Z","36630" +"*c0dn/truesocks_rs*",".{0,1000}c0dn\/truesocks_rs.{0,1000}","offensive_tool_keyword","TrueSocks","Simple API for buying renting and managing proxies","T1021 - T1071 - T1090","TA0003 - TA0008 - TA0011","N/A","Scattered Spider*","Defense Evasion","https://github.com/c0dn/truesocks_rs","1","1","N/A","N/A","10","1","0","0","2023-05-09T01:00:05Z","2023-04-06T02:32:04Z","36694" +"*c2.hak5.org*",".{0,1000}c2\.hak5\.org.{0,1000}","offensive_tool_keyword","hak5 cloudc2","Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud","T1021 - T1102 - T1213","TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://shop.hak5.org/products/c2?","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","36770" +"*C2.KillDate*",".{0,1000}C2\.KillDate.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","36771" +"*c2.striker.*",".{0,1000}c2\.striker\..{0,1000}","offensive_tool_keyword","Striker","Striker is a simple Command and Control (C2) program.","T1071 - T1071.001 - T1071.004 - T1071.005 - T1071.006 - T1071.007 - T1071.008 - T1071.009 - T1071.010 - T1071.012 - T1071.013 - T1071.014 - T1071.015 - T1071.016 - T1071.018 - T1105 - T1105.002 - T1573 - T1573.002 - T1573.003 - T1573.004 - T1573.005","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/4g3nt47/Striker","1","1","N/A","N/A","10","10","301","42","2023-05-04T18:00:05Z","2022-09-07T10:09:41Z","36772" +"*C2.UserAgent*",".{0,1000}C2\.UserAgent.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","36773" +"*C2/C2Server.*",".{0,1000}C2\/C2Server\..{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","36774" +"*C2_RPC_functions.py*",".{0,1000}C2_RPC_functions\.py.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","36775" +"*c2_server*.py*",".{0,1000}c2_server.{0,1000}\.py.{0,1000}","offensive_tool_keyword","FudgeC2","FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.","T1021.002 - T1105 - T1059.001 - T1059.003","TA0008 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/Ziconius/FudgeC2","1","1","N/A","N/A","10","10","253","54","2023-05-01T21:13:56Z","2018-09-09T21:05:21Z","36776" +"*C2_Server-main*",".{0,1000}C2_Server\-main.{0,1000}","offensive_tool_keyword","C2_Server","C2 server to connect to a victim machine via reverse shell","T1090 - T1090.001 - T1071 - T1071.001","TA0011 ","N/A","N/A","C2","https://github.com/reveng007/C2_Server","1","1","N/A","N/A","10","10","54","18","2022-02-27T02:00:02Z","2021-03-05T12:35:45Z","36779" +"*c2_service.sh*",".{0,1000}c2_service\.sh.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","36780" +"*C2concealer-master*",".{0,1000}C2concealer\-master.{0,1000}","offensive_tool_keyword","C2concealer","C2concealer is a command line tool that generates randomized C2 malleable profiles for use in Cobalt Strike.","T1090 - T1090.003 - T1027 - T1027.005 - T1071 - T1071.001","TA0042 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/RedSiege/C2concealer","1","1","N/A","N/A","10","10","1053","172","2024-06-25T11:10:54Z","2020-03-23T14:13:16Z","36831" +"*'C2Default'*",".{0,1000}\'C2Default\'.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","36836" +"*c2endpoint.php*",".{0,1000}c2endpoint\.php.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","36840" +"*c2hlbGxjb2Rl*",".{0,1000}c2hlbGxjb2Rl.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","36845" +"*C2ListenerPort*",".{0,1000}C2ListenerPort.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool that can perform reverse proxy and cs online without going online","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Daybr4ak/C2ReverseProxy","1","1","N/A","N/A","10","10","486","56","2023-04-26T13:16:26Z","2020-01-16T05:43:35Z","36847" +"*c2-logs.txt*",".{0,1000}c2\-logs\.txt.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","36848" +"*c2profile.profile*",".{0,1000}c2profile\.profile.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","36852" +"*C2ProfileResponse.cs*",".{0,1000}C2ProfileResponse\.cs.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","36854" +"*-c2-randomizer.py*",".{0,1000}\-c2\-randomizer\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","36855" +"*C2ReverseClint*",".{0,1000}C2ReverseClint.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool that can perform reverse proxy and cs online without going online","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Daybr4ak/C2ReverseProxy","1","1","N/A","N/A","10","10","486","56","2023-04-26T13:16:26Z","2020-01-16T05:43:35Z","36856" +"*C2ReverseProxy*",".{0,1000}C2ReverseProxy.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool that can perform reverse proxy and cs online without going online","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Daybr4ak/C2ReverseProxy","1","1","N/A","N/A","10","10","486","56","2023-04-26T13:16:26Z","2020-01-16T05:43:35Z","36857" +"*C2ReverseServer*",".{0,1000}C2ReverseServer.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool that can perform reverse proxy and cs online without going online","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Daybr4ak/C2ReverseProxy","1","1","N/A","N/A","10","10","486","56","2023-04-26T13:16:26Z","2020-01-16T05:43:35Z","36858" +"*C2script/proxy.*",".{0,1000}C2script\/proxy\..{0,1000}","offensive_tool_keyword","cobaltstrike","A tool that can perform reverse proxy and cs online without going online","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Daybr4ak/C2ReverseProxy","1","1","N/A","N/A","10","10","486","56","2023-04-26T13:16:26Z","2020-01-16T05:43:35Z","36859" +"*c2-server.mtattab.com/reverseShellClients*",".{0,1000}c2\-server\.mtattab\.com\/reverseShellClients.{0,1000}","offensive_tool_keyword","WebSocketReverseShellDotNet","A .NET-based Reverse Shell, it establishes a link to the command and control for subsequent guidance.","T1071 - T1105","TA0011 - TA0002","N/A","N/A","C2","https://github.com/The-Hustler-Hattab/WebSocketReverseShellDotNet","1","1","N/A","N/A","10","10","1","0","2024-04-18T01:00:48Z","2023-12-03T03:35:24Z","36863" +"*C2Server.ps1*",".{0,1000}C2Server\.ps1.{0,1000}","offensive_tool_keyword","PSRansom","PSRansom is a PowerShell Ransomware Simulator with C2 Server capabilities. This tool helps you simulate encryption process of a generic ransomware in any system on any system with PowerShell installed on it. Thanks to the integrated C2 server. you can exfiltrate files and receive client information via HTTP.","T1486 - T1107 - T1566.001","TA0011 - TA0010","N/A","N/A","C2","https://github.com/JoelGMSec/PSRansom","1","1","N/A","N/A","10","5","478","116","2024-01-19T09:50:26Z","2022-02-27T11:52:03Z","36864" +"*c2server_linux*",".{0,1000}c2server_linux.{0,1000}","offensive_tool_keyword","REC2 ","REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in Rust.","T1105 - T1132 - T1071.001","TA0011 - TA0009 - TA0002","N/A","N/A","C2","https://github.com/g0h4n/REC2","1","1","#linux","N/A","10","10","153","23","2024-02-22T14:02:24Z","2023-09-25T20:39:59Z","36868" +"*c2server_macos*",".{0,1000}c2server_macos.{0,1000}","offensive_tool_keyword","REC2 ","REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in Rust.","T1105 - T1132 - T1071.001","TA0011 - TA0009 - TA0002","N/A","N/A","C2","https://github.com/g0h4n/REC2","1","1","N/A","N/A","10","10","153","23","2024-02-22T14:02:24Z","2023-09-25T20:39:59Z","36869" +"*c2server_windows*",".{0,1000}c2server_windows.{0,1000}","offensive_tool_keyword","REC2 ","REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in Rust.","T1105 - T1132 - T1071.001","TA0011 - TA0009 - TA0002","N/A","N/A","C2","https://github.com/g0h4n/REC2","1","1","N/A","N/A","10","10","153","23","2024-02-22T14:02:24Z","2023-09-25T20:39:59Z","36871" +"*C2WebSocketHandler.*",".{0,1000}C2WebSocketHandler\..{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","36877" +"*c3l3si4n/webtrufflehog*",".{0,1000}c3l3si4n\/webtrufflehog.{0,1000}","offensive_tool_keyword","webtrufflehog","Browser extension that leverages TruffleHog to scan web traffic in real-time for exposed secrets","T1552.001 - T1040 - T1036 - T1087","TA0006 - TA0007 - TA0009","N/A","N/A","Collection","https://github.com/c3l3si4n/webtrufflehog","1","1","N/A","N/A","7","2","102","10","2024-12-29T23:26:35Z","2024-12-28T19:53:09Z","36964" +"*ca.mirrors.cicku.me/blackarch/*/os/*",".{0,1000}ca\.mirrors\.cicku\.me\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","37406" +"*cache_activedirectory.py*",".{0,1000}cache_activedirectory\.py.{0,1000}","offensive_tool_keyword","ldeep","In-depth ldap enumeration utility","T1087.002 - T1018 - T1482 - T1083","TA0007 - TA0008 - TA0009","N/A","N/A","Reconnaissance","https://github.com/franc-pentest/ldeep","1","1","N/A","N/A","5","5","465","54","2025-03-02T18:43:27Z","2018-10-22T18:21:44Z","37488" +"*cachedump.exe*",".{0,1000}cachedump\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://gitlab.com/kalilinux/packages/windows-binaries/-/tree/kali/master/fgdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","37490" +"*cachedump64.exe*",".{0,1000}cachedump64\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://gitlab.com/kalilinux/packages/windows-binaries/-/tree/kali/master/fgdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","37492" +"*cactusbloguuodvqjmnzlwetjlpj6aggc6iocwhuupb47laukux7ckid.onion*",".{0,1000}cactusbloguuodvqjmnzlwetjlpj6aggc6iocwhuupb47laukux7ckid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","37496" +"*CACTUSTORCH.cna*",".{0,1000}CACTUSTORCH\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","CACTUSTORCH: Payload Generation for Adversary Simulations","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mdsecactivebreach/CACTUSTORCH","1","1","N/A","N/A","10","10","1006","227","2018-07-03T06:47:36Z","2017-07-04T10:20:34Z","37497" +"*CACTUSTORCH.cs*",".{0,1000}CACTUSTORCH\.cs.{0,1000}","offensive_tool_keyword","cobaltstrike","CACTUSTORCH: Payload Generation for Adversary Simulations","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mdsecactivebreach/CACTUSTORCH","1","1","N/A","N/A","10","10","1006","227","2018-07-03T06:47:36Z","2017-07-04T10:20:34Z","37498" +"*CACTUSTORCH.hta*",".{0,1000}CACTUSTORCH\.hta.{0,1000}","offensive_tool_keyword","CACTUSTORCH","A JavaScript and VBScript shellcode launcher. This will spawn a 32 bit version of the binary specified and inject shellcode into it.","T1055.011 - T1059.005 - T1059.007","TA0002 - TA0005","N/A","APT32","Exploitation tool","https://github.com/mdsecactivebreach/CACTUSTORCH","1","1","N/A","N/A","8","10","1006","227","2018-07-03T06:47:36Z","2017-07-04T10:20:34Z","37499" +"*CACTUSTORCH.hta*",".{0,1000}CACTUSTORCH\.hta.{0,1000}","offensive_tool_keyword","cobaltstrike","CACTUSTORCH: Payload Generation for Adversary Simulations","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mdsecactivebreach/CACTUSTORCH","1","1","N/A","N/A","10","10","1006","227","2018-07-03T06:47:36Z","2017-07-04T10:20:34Z","37500" +"*CACTUSTORCH.js*",".{0,1000}CACTUSTORCH\.js.{0,1000}","offensive_tool_keyword","CACTUSTORCH","A JavaScript and VBScript shellcode launcher. This will spawn a 32 bit version of the binary specified and inject shellcode into it.","T1055.011 - T1059.005 - T1059.007","TA0002 - TA0005","N/A","APT32","Exploitation tool","https://github.com/mdsecactivebreach/CACTUSTORCH","1","1","N/A","N/A","8","10","1006","227","2018-07-03T06:47:36Z","2017-07-04T10:20:34Z","37501" +"*CACTUSTORCH.js*",".{0,1000}CACTUSTORCH\.js.{0,1000}","offensive_tool_keyword","cobaltstrike","CACTUSTORCH: Payload Generation for Adversary Simulations","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mdsecactivebreach/CACTUSTORCH","1","1","N/A","N/A","10","10","1006","227","2018-07-03T06:47:36Z","2017-07-04T10:20:34Z","37502" +"*CACTUSTORCH.vba*",".{0,1000}CACTUSTORCH\.vba.{0,1000}","offensive_tool_keyword","CACTUSTORCH","A JavaScript and VBScript shellcode launcher. This will spawn a 32 bit version of the binary specified and inject shellcode into it.","T1055.011 - T1059.005 - T1059.007","TA0002 - TA0005","N/A","APT32","Exploitation tool","https://github.com/mdsecactivebreach/CACTUSTORCH","1","1","N/A","N/A","8","10","1006","227","2018-07-03T06:47:36Z","2017-07-04T10:20:34Z","37503" +"*CACTUSTORCH.vba*",".{0,1000}CACTUSTORCH\.vba.{0,1000}","offensive_tool_keyword","cobaltstrike","CACTUSTORCH: Payload Generation for Adversary Simulations","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mdsecactivebreach/CACTUSTORCH","1","1","N/A","N/A","10","10","1006","227","2018-07-03T06:47:36Z","2017-07-04T10:20:34Z","37504" +"*CACTUSTORCH.vbe*",".{0,1000}CACTUSTORCH\.vbe.{0,1000}","offensive_tool_keyword","CACTUSTORCH","A JavaScript and VBScript shellcode launcher. This will spawn a 32 bit version of the binary specified and inject shellcode into it.","T1055.011 - T1059.005 - T1059.007","TA0002 - TA0005","N/A","APT32","Exploitation tool","https://github.com/mdsecactivebreach/CACTUSTORCH","1","1","N/A","N/A","8","10","1006","227","2018-07-03T06:47:36Z","2017-07-04T10:20:34Z","37505" +"*CACTUSTORCH.vbe*",".{0,1000}CACTUSTORCH\.vbe.{0,1000}","offensive_tool_keyword","cobaltstrike","CACTUSTORCH: Payload Generation for Adversary Simulations","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mdsecactivebreach/CACTUSTORCH","1","1","N/A","N/A","10","10","1006","227","2018-07-03T06:47:36Z","2017-07-04T10:20:34Z","37506" +"*CACTUSTORCH.vbs*",".{0,1000}CACTUSTORCH\.vbs.{0,1000}","offensive_tool_keyword","CACTUSTORCH","A JavaScript and VBScript shellcode launcher. This will spawn a 32 bit version of the binary specified and inject shellcode into it.","T1055.011 - T1059.005 - T1059.007","TA0002 - TA0005","N/A","APT32","Exploitation tool","https://github.com/mdsecactivebreach/CACTUSTORCH","1","1","N/A","N/A","8","10","1006","227","2018-07-03T06:47:36Z","2017-07-04T10:20:34Z","37507" +"*CACTUSTORCH.vbs*",".{0,1000}CACTUSTORCH\.vbs.{0,1000}","offensive_tool_keyword","cobaltstrike","CACTUSTORCH: Payload Generation for Adversary Simulations","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mdsecactivebreach/CACTUSTORCH","1","1","N/A","N/A","10","10","1006","227","2018-07-03T06:47:36Z","2017-07-04T10:20:34Z","37508" +"*calebstewart/bypass-clm*",".{0,1000}calebstewart\/bypass\-clm.{0,1000}","offensive_tool_keyword","bypass-clm","PowerShell Constrained Language Mode Bypass","T1059.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/calebstewart/bypass-clm","1","1","N/A","N/A","8","3","261","38","2021-01-31T19:13:55Z","2021-01-29T04:46:23Z","37526" +"*calebstewart/CVE-2021-1675*",".{0,1000}calebstewart\/CVE\-2021\-1675.{0,1000}","offensive_tool_keyword","PrintNightmare","PrintNightmare exploitation","T1210 - T1059.001 - T1548.002","TA0001 - TA0002 - TA0004","N/A","Dispossessor","Privilege Escalation","https://github.com/calebstewart/CVE-2021-1675","1","1","N/A","N/A","10","10","1049","230","2021-07-05T08:54:06Z","2021-07-01T23:45:58Z","37527" +"*calebstewart/pwncat*",".{0,1000}calebstewart\/pwncat.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","37528" +"*-CalendarNTLMLeak*",".{0,1000}\-CalendarNTLMLeak.{0,1000}","offensive_tool_keyword","POC","CVE-2023-23397 POC Powershell exploit","T1068 - T1557.001 - T1187 - T1212 -T1003.001 - T1550","TA0003 - TA0002 - TA0004","N/A","N/A","Exploitation tool","https://github.com/api0cradle/CVE-2023-23397-POC-Powershell","1","1","N/A","N/A","N/A","4","344","63","2023-03-17T07:47:40Z","2023-03-16T19:43:39Z","37529" +"*CALLBACK_HASHDUMP*",".{0,1000}CALLBACK_HASHDUMP.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","37532" +"*CALLBACK_KEYSTROKES*",".{0,1000}CALLBACK_KEYSTROKES.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","37533" +"*CALLBACK_NETVIEW*",".{0,1000}CALLBACK_NETVIEW.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","37534" +"*CALLBACK_PORTSCAN*",".{0,1000}CALLBACK_PORTSCAN.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","37535" +"*CALLBACK_TOKEN_STOLEN*",".{0,1000}CALLBACK_TOKEN_STOLEN.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","37536" +"*CallBackDump*dumpXor*",".{0,1000}CallBackDump.{0,1000}dumpXor.{0,1000}","offensive_tool_keyword","cobaltstrike","dump lsass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/seventeenman/CallBackDump","1","1","N/A","N/A","10","10","549","76","2023-07-20T09:03:33Z","2022-09-25T08:29:14Z","37537" +"*CallbackDump.exe*",".{0,1000}CallbackDump\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","dump lsass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/seventeenman/CallBackDump","1","1","N/A","N/A","10","10","549","76","2023-07-20T09:03:33Z","2022-09-25T08:29:14Z","37538" +"*CamHacker/releases/latest/download/websites.zip*",".{0,1000}CamHacker\/releases\/latest\/download\/websites\.zip.{0,1000}","offensive_tool_keyword","CamHacker","Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!","T1598 - T1204 - T1566.001","TA0009 - TA0010 - TA0043","N/A","N/A","Phishing","https://github.com/KasRoudra/CamHacker","1","1","N/A","N/A","10","","N/A","","","","37543" +"*cam-hackers.py*",".{0,1000}cam\-hackers\.py.{0,1000}","offensive_tool_keyword","Cam-Hackers","Hack Cameras CCTV FREE","T1125","TA0007","N/A","N/A","Discovery","https://github.com/AngelSecurityTeam/Cam-Hackers","1","1","N/A","N/A","6","10","2025","512","2024-08-06T18:49:02Z","2019-11-16T18:49:35Z","37544" +"*Cam-Hackers-master.zip*",".{0,1000}Cam\-Hackers\-master\.zip.{0,1000}","offensive_tool_keyword","Cam-Hackers","Hack Cameras CCTV FREE","T1125","TA0007","N/A","N/A","Discovery","https://github.com/AngelSecurityTeam/Cam-Hackers","1","1","N/A","N/A","6","10","2025","512","2024-08-06T18:49:02Z","2019-11-16T18:49:35Z","37545" +"*can_flood_frames*",".{0,1000}can_flood_frames.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","37547" +"*canix1/ADACLScanner*",".{0,1000}canix1\/ADACLScanner.{0,1000}","offensive_tool_keyword","ADACLScanner","A tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory .","T1222 - T1069 - T1018","TA0002 - TA0007 - TA0043","N/A","N/A","Discovery","https://github.com/canix1/ADACLScanner","1","1","N/A","AD Enumeration","7","10","1015","173","2025-04-11T14:35:08Z","2017-04-06T12:28:37Z","37550" +"*can-kat/cstealer*",".{0,1000}can\-kat\/cstealer.{0,1000}","offensive_tool_keyword","cstealer","stealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python.","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/can-kat/cstealer","1","1","N/A","N/A","10","","N/A","","","","37551" +"*capcom_sys_exec*",".{0,1000}capcom_sys_exec.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","37564" +"*capcom_sys_exec.x64.dll*",".{0,1000}capcom_sys_exec\.x64\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","37565" +"*CaptainNox/Hypnos*",".{0,1000}CaptainNox\/Hypnos.{0,1000}","offensive_tool_keyword","Hypnos","indirect syscalls - the Win API functions are not hooked by AV/EDR - bypass EDR detections","T1055.012 - T1136.001 - T1070.004 - T1055.001","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/CaptainNox/Hypnos","1","1","N/A","N/A","10","1","49","6","2024-02-12T17:51:24Z","2023-07-11T09:07:10Z","37566" +"*captcha-killer.*.jar*",".{0,1000}captcha\-killer\..{0,1000}\.jar.{0,1000}","offensive_tool_keyword","burpsuite","Collection of burpsuite plugins","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","network exploitation tool","N/A","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","37567" +"*CapturedCredential.cs*",".{0,1000}CapturedCredential\.cs.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","37569" +"*CapturedCredential.exe*",".{0,1000}CapturedCredential\.exe.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","37570" +"*CapturedHashCredential.*",".{0,1000}CapturedHashCredential\..{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","37571" +"*CapturedPasswordCredential.*",".{0,1000}CapturedPasswordCredential\..{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","37572" +"*CapturedTicketCredential.*",".{0,1000}CapturedTicketCredential\..{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","37573" +"*capturetokenphish.ps1*",".{0,1000}capturetokenphish\.ps1.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","37574" +"*capturetokenphish.py*",".{0,1000}capturetokenphish\.py.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","37575" +"*CarbonCopy.py*",".{0,1000}CarbonCopy\.py.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","37577" +"*cardano2john.py*",".{0,1000}cardano2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","37578" +"*careCrow*_linux_amd64*",".{0,1000}careCrow.{0,1000}_linux_amd64.{0,1000}","offensive_tool_keyword","cobaltstrike","ScareCrow - Payload creation framework designed around EDR bypass.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/optiv/ScareCrow","1","1","#linux","N/A","10","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","37579" +"*carlospolop/PEASS-ng*",".{0,1000}carlospolop\/PEASS\-ng.{0,1000}","offensive_tool_keyword","PEASS-ng","PEASS-ng - Privilege Escalation Awesome Scripts suite","T1098","TA0004 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/peass-ng/PEASS-ng","1","1","N/A","N/A","10","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","37584" +"*carlospolop/PurplePanda*",".{0,1000}carlospolop\/PurplePanda.{0,1000}","offensive_tool_keyword","PurplePanda","This tool fetches resources from different cloud/saas applications focusing on permissions in order to identify privilege escalation paths and dangerous permissions in the cloud/saas configurations. Note that PurplePanda searches both privileges escalation paths within a platform and across platforms.","T1595 - T1078 - T1583 - T1087 - T1526","TA0003 - TA0004 - TA0007 - TA0040","N/A","N/A","Exploitation tool","https://github.com/carlospolop/PurplePanda","1","1","N/A","N/A","N/A","7","687","83","2025-04-14T16:23:50Z","2022-01-01T12:10:40Z","37585" +"*cartelirsn5l54ehcbalyyqtfb3j7be2rpvf6ujayaf5qqmg3vlwiayd.onion*",".{0,1000}cartelirsn5l54ehcbalyyqtfb3j7be2rpvf6ujayaf5qqmg3vlwiayd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","37587" +"*catphish.rb*",".{0,1000}catphish\.rb.{0,1000}","offensive_tool_keyword","catphish","Generate similar-looking domains for phishing attacks. Check expired domains and their categorized domain status to evade proxy categorization. Whitelisted domains are perfect for your C2 servers. Perfect for Red Team engagements.","T1565 - T1566 - T1567 - T1596","TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/ring0lab/catphish","1","1","N/A","N/A","N/A","7","612","118","2018-10-16T12:57:25Z","2016-10-24T22:48:51Z","37624" +"*cc2_keystrokes*",".{0,1000}cc2_keystrokes.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","37719" +"*cc2_keystrokes_*",".{0,1000}cc2_keystrokes_.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","37720" +"*cc2_mimipenguin.*",".{0,1000}cc2_mimipenguin\..{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","37721" +"*cc2_portscan*",".{0,1000}cc2_portscan.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","37722" +"*cc2_portscan_*",".{0,1000}cc2_portscan_.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","37723" +"*cc2_rebind_*_get_recv*",".{0,1000}cc2_rebind_.{0,1000}_get_recv.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","37724" +"*cc2_rebind_*_get_send*",".{0,1000}cc2_rebind_.{0,1000}_get_send.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","37725" +"*cc2_rebind_*_post_recv*",".{0,1000}cc2_rebind_.{0,1000}_post_recv.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","37726" +"*cc2_rebind_*_post_send*",".{0,1000}cc2_rebind_.{0,1000}_post_send.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","37727" +"*cc2_udp_server*",".{0,1000}cc2_udp_server.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","37728" +"*cc2FilesColor.*",".{0,1000}cc2FilesColor\..{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","37734" +"*cc2ProcessColor.*",".{0,1000}cc2ProcessColor\..{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","37735" +"*ccache2john.py*",".{0,1000}ccache2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","37779" +"*ccache2john.py*",".{0,1000}ccache2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","37780" +"*cckuailong/reapoc*",".{0,1000}cckuailong\/reapoc.{0,1000}","offensive_tool_keyword","reapoc","OpenSource Poc && Vulnerable-Target Storage Box.","T1552","TA0006","N/A","N/A","Exploitation tool","https://github.com/cckuailong/reapoc","1","1","N/A","N/A","N/A","7","681","219","2023-02-06T08:27:09Z","2021-11-28T00:46:27Z","37810" +"*cclauss/WinPwnage*",".{0,1000}cclauss\/WinPwnage.{0,1000}","offensive_tool_keyword","WinPwnage","various exploitation tools for windows ","T1548.002 - T1546.016 - T1546.003 - T1547.001 - T1053.005 - T1053.003 - T1548 - T1055.011 - T1078","TA0004 - TA0005 - TA0009 - TA0003 - TA0011","N/A","N/A","Exploitation tool","https://github.com/rootm0s/WinPwnage","1","1","N/A","N/A","10","10","2670","385","2023-02-13T09:43:13Z","2018-04-08T18:51:50Z","37811" +"*CCob/BOF.NET*",".{0,1000}CCob\/BOF\.NET.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","37814" +"*CCob/DRSAT*",".{0,1000}CCob\/DRSAT.{0,1000}","offensive_tool_keyword","DRSAT","Disconnected RSAT is a launcher for the official Group Policy Manager - Certificate Authority and Certificate Templates snap-in to bypass the domain joined requirement that is needed when using the official MMC snap-in. The tool works by injecting a C# library into MMC that will hook the various API calls to trick MMC into believing that the logged on user is a domain user. attackers can abuse Disconnected RSAT to interact with Active Directory (AD) environments from non-domain-joined machines","T1559.001 - T1112 - T1078 - T1134.002 - T1055.001","TA0002 - TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/CCob/DRSAT","1","1","N/A","N/A","6","3","233","25","2024-12-27T11:44:18Z","2024-09-04T16:35:02Z","37815" +"*CCob/lsarelayx*",".{0,1000}CCob\/lsarelayx.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","1","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","37816" +"*CCob/MirrorDump*",".{0,1000}CCob\/MirrorDump.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","1","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","37817" +"*CCob/Shwmae*",".{0,1000}CCob\/Shwmae.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","1","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","37818" +"*CCob/SweetPotato*",".{0,1000}CCob\/SweetPotato.{0,1000}","offensive_tool_keyword","SweetPotato","Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019","T1548 - T1055","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/CCob/SweetPotato","1","1","N/A","N/A","10","10","1697","228","2024-09-04T17:09:30Z","2020-04-12T17:40:03Z","37819" +"*CCob/ThreadlessInject*",".{0,1000}CCob\/ThreadlessInject.{0,1000}","offensive_tool_keyword","ThreadlessInject","Threadless Process Injection using remote function hooking.","T1055.012 - T1055.003 - T1177","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/CCob/ThreadlessInject","1","1","N/A","N/A","10","8","751","88","2024-09-04T17:11:58Z","2023-02-05T13:50:15Z","37820" +"*ccpyeuptrlatb2piua4ukhnhi7lrxgerrcrj4p2b5uhbzqm2xgdjaqid.onion*",".{0,1000}ccpyeuptrlatb2piua4ukhnhi7lrxgerrcrj4p2b5uhbzqm2xgdjaqid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","37821" +"*cdimage.kali.org/*",".{0,1000}cdimage\.kali\.org\/.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","37917" +"*cdk-team/CDK*",".{0,1000}cdk\-team\/CDK.{0,1000}","offensive_tool_keyword","CDK","CDK is an open-sourced container penetration toolkit","T1610 - T1611 - T1203 - T1059.004 - T1564.004","TA0001 - TA0002 - TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/cdk-team/CDK","1","1","#linux","N/A","9","10","4164","566","2025-03-08T14:00:06Z","2020-11-05T09:18:51Z","37921" +"*cdn_proxy_burp_ext.py*",".{0,1000}cdn_proxy_burp_ext\.py.{0,1000}","offensive_tool_keyword","cdn-proxy","cdn-proxy is a set of tools for bypassing IP allow listing intended to restrict origin access to requests originating from shared CDNs.","T1100 - T1090 - T1105 - T1133 - T1190","TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/RyanJarv/cdn-proxy","1","1","N/A","N/A","N/A","3","249","24","2022-08-25T00:40:25Z","2022-03-07T21:11:07Z","37924" +"*cdn-proxy.git*",".{0,1000}cdn\-proxy\.git.{0,1000}","offensive_tool_keyword","cdn-proxy","cdn-proxy is a set of tools for bypassing IP allow listing intended to restrict origin access to requests originating from shared CDNs.","T1100 - T1090 - T1105 - T1133 - T1190","TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/RyanJarv/cdn-proxy","1","1","N/A","N/A","N/A","3","249","24","2022-08-25T00:40:25Z","2022-03-07T21:11:07Z","37927" +"*cdn-proxy/burp_extension*",".{0,1000}cdn\-proxy\/burp_extension.{0,1000}","offensive_tool_keyword","cdn-proxy","cdn-proxy is a set of tools for bypassing IP allow listing intended to restrict origin access to requests originating from shared CDNs.","T1100 - T1090 - T1105 - T1133 - T1190","TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/RyanJarv/cdn-proxy","1","1","N/A","N/A","N/A","3","249","24","2022-08-25T00:40:25Z","2022-03-07T21:11:07Z","37928" +"*Cdn-Proxy-Host*",".{0,1000}Cdn\-Proxy\-Host.{0,1000}","offensive_tool_keyword","cdn-proxy","cdn-proxy is a set of tools for bypassing IP allow listing intended to restrict origin access to requests originating from shared CDNs.","T1100 - T1090 - T1105 - T1133 - T1190","TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/RyanJarv/cdn-proxy","1","1","N/A","N/A","N/A","3","249","24","2022-08-25T00:40:25Z","2022-03-07T21:11:07Z","37929" +"*Celesty Binder/Celesty.exe*",".{0,1000}Celesty\sBinder\/Celesty\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","37996" +"*cerberus-rat.com*",".{0,1000}cerberus\-rat\.com.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","37997" +"*cerbrutus.py*",".{0,1000}cerbrutus\.py.{0,1000}","offensive_tool_keyword","cerbrutus","Network brute force tool. written in Python. Faster than other existing solutions (including the main leader in the network brute force market).","T1110 - T1040 - T1496","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/Cerbrutus-BruteForcer/cerbrutus","1","1","N/A","N/A","N/A","4","385","57","2021-08-22T19:05:45Z","2021-07-07T19:11:40Z","37998" +"*Cerbrutus-BruteForcer*",".{0,1000}Cerbrutus\-BruteForcer.{0,1000}","offensive_tool_keyword","cerbrutus","Network brute force tool. written in Python. Faster than other existing solutions (including the main leader in the network brute force market).","T1110 - T1040 - T1496","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/Cerbrutus-BruteForcer/cerbrutus","1","1","N/A","N/A","N/A","4","385","57","2021-08-22T19:05:45Z","2021-07-07T19:11:40Z","37999" +"*certi.py_vulntemplates_output*",".{0,1000}certi\.py_vulntemplates_output.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38002" +"*certi_py_enum*",".{0,1000}certi_py_enum.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38003" +"*Certify.exe*",".{0,1000}Certify\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","38006" +"*certipy_enum*",".{0,1000}certipy_enum.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38024" +"*certipy-master.zip*",".{0,1000}certipy\-master\.zip.{0,1000}","offensive_tool_keyword","Certipy","Tool for Active Directory Certificate Services enumeration and abuse","T1552.003 - T1110.003 - T1550.004 - T1649","TA0006 - TA0008 - TA0003","N/A","Dispossessor","Exploitation tool","https://github.com/ly4k/Certipy","1","1","N/A","N/A","10","10","2704","380","2024-08-19T17:33:04Z","2021-10-06T23:02:40Z","38025" +"*CertStealer.csproj*",".{0,1000}CertStealer\.csproj.{0,1000}","offensive_tool_keyword","CertStealer","A .NET tool for exporting and importing certificates without touching disk.","T1552.001 - T1140 - T1005 - T1649","TA0006 - TA0005","N/A","N/A","Exploitation tool","https://github.com/TheWover/CertStealer","1","1","N/A","N/A","10","5","487","68","2021-10-08T20:48:34Z","2021-04-21T14:20:56Z","38028" +"*CertStealer.exe*",".{0,1000}CertStealer\.exe.{0,1000}","offensive_tool_keyword","CertStealer","A .NET tool for exporting and importing certificates without touching disk.","T1552.001 - T1140 - T1005 - T1649","TA0006 - TA0005","N/A","N/A","Exploitation tool","https://github.com/TheWover/CertStealer","1","1","N/A","N/A","10","5","487","68","2021-10-08T20:48:34Z","2021-04-21T14:20:56Z","38029" +"*CertStealer.sln*",".{0,1000}CertStealer\.sln.{0,1000}","offensive_tool_keyword","CertStealer","A .NET tool for exporting and importing certificates without touching disk.","T1552.001 - T1140 - T1005 - T1649","TA0006 - TA0005","N/A","N/A","Exploitation tool","https://github.com/TheWover/CertStealer","1","1","N/A","N/A","10","5","487","68","2021-10-08T20:48:34Z","2021-04-21T14:20:56Z","38030" +"*certsync_ntds_dump*",".{0,1000}certsync_ntds_dump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38034" +"*certsync-master.zip*",".{0,1000}certsync\-master\.zip.{0,1000}","offensive_tool_keyword","certsync","Dump NTDS with golden certificates and UnPAC the hash","T1553.002 - T1003.001 - T1145 - T1649","TA0002 - TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/zblurx/certsync","1","1","N/A","N/A","10","7","633","66","2024-03-20T10:58:15Z","2023-01-31T15:37:12Z","38035" +"*cfalta/PoshADCS*",".{0,1000}cfalta\/PoshADCS.{0,1000}","offensive_tool_keyword","PoshADCS","attack vectors against Active Directory by abusing Active Directory Certificate Services (ADCS)","T1213.003 - T1213 - T1098.003 - T1098 - T1484.001","TA0002 - TA0003 - TA0040","N/A","N/A","Persistence","https://github.com/cfalta/PoshADCS","1","1","N/A","N/A","7","2","186","17","2021-07-07T16:47:07Z","2019-10-15T15:54:03Z","38085" +"*cfprefsd_race_condition*",".{0,1000}cfprefsd_race_condition.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","38109" +"*cGlwZW5hbWU9*",".{0,1000}cGlwZW5hbWU9.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","38113" +"*ch0sys/DUBrute*",".{0,1000}ch0sys\/DUBrute.{0,1000}","offensive_tool_keyword","DUBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/ch0sys/DUBrute","1","1","N/A","N/A","10","1","37","28","2018-02-19T13:03:14Z","2017-06-15T08:55:46Z","38115" +"*Chachi-Enumerator.ps1*",".{0,1000}Chachi\-Enumerator\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","38117" +"*ChaitanyaHaritash/kimi*",".{0,1000}ChaitanyaHaritash\/kimi.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","38120" +"*changepasswd.py*",".{0,1000}changepasswd\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","38125" +"*charlesnathansmith/whatlicense*",".{0,1000}charlesnathansmith\/whatlicense.{0,1000}","offensive_tool_keyword","whatlicense","WinLicense key extraction via Intel PIN","T1056 - T1056.001 - T1518 - T1518.001","TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/charlesnathansmith/whatlicense","1","1","N/A","N/A","6","2","101","25","2024-04-09T05:30:56Z","2023-07-10T11:57:44Z","38132" +"*charles-proxy*",".{0,1000}charles\-proxy.{0,1000}","offensive_tool_keyword","charles-proxy","A cross-platform GUI web debugging proxy to view intercepted HTTP and HTTPS/SSL live traffic","T1043.002 - T1556.001 - T1573.001","TA0012 - TA0017","N/A","N/A","Sniffing & Spoofing","https://charlesproxy.com/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","38133" +"*charlotte-main.zip*",".{0,1000}charlotte\-main\.zip.{0,1000}","offensive_tool_keyword","charlotte","c++ fully undetected shellcode launcher","T1055.012 - T1059.003 - T1027.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/9emin1/charlotte","1","1","N/A","N/A","10","10","976","211","2021-06-11T04:44:18Z","2021-05-13T07:32:03Z","38134" +"*chatc46k7dqtvvrgfqjs6vxrwnmudko2ptiqvlb7doqxxqtjc22tsiad.onion*",".{0,1000}chatc46k7dqtvvrgfqjs6vxrwnmudko2ptiqvlb7doqxxqtjc22tsiad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","38136" +"*ChatLadon.exe*",".{0,1000}ChatLadon\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","38137" +"*ChatLadon.rar*",".{0,1000}ChatLadon\.rar.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","38138" +"*chaudharyarjun/LooneyPwner*",".{0,1000}chaudharyarjun\/LooneyPwner.{0,1000}","offensive_tool_keyword","POC","Exploit tool for CVE-2023-4911 targeting the 'Looney Tunables' glibc vulnerability in various Linux distributions.","T1068 - T1210 - T1555","TA0001 - TA0003 - TA0005","N/A","N/A","Exploitation tool","https://github.com/chaudharyarjun/LooneyPwner","1","1","#linux","N/A","10","1","38","12","2023-10-18T04:59:50Z","2023-10-17T07:44:16Z","38144" +"*check_and_write_IAT_Hook*",".{0,1000}check_and_write_IAT_Hook.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","38146" +"*check_cve-2020-1472.py*",".{0,1000}check_cve\-2020\-1472\.py.{0,1000}","offensive_tool_keyword","POC","Zerologon CVE exploitation","T1210 - T1072","TA0006 - TA0008","N/A","Dispossessor","Exploitation tool","https://github.com/WiIs0n/Zerologon_CVE-2020-1472","1","1","N/A","N/A","N/A","1","11","5","2020-10-05T07:47:02Z","2020-09-29T18:45:44Z","38147" +"*check_ppl_requirements*",".{0,1000}check_ppl_requirements.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","38149" +"*checkIfHiddenAPICall*",".{0,1000}checkIfHiddenAPICall.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","38151" +"*Check-LocalAdminHash.ps1*",".{0,1000}Check\-LocalAdminHash\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","38152" +"*CheckPort.csproj*",".{0,1000}CheckPort\.csproj.{0,1000}","offensive_tool_keyword","KrbRelay","Relaying 3-headed dogs. More details at https://googleprojectzero.blogspot.com/2021/10/windows-exploitation-tricks-relaying.html and https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html","T1212 - T1558 - T1550","TA0001 - TA0004 -TA0006","N/A","Dispossessor","Exploitation tool","https://github.com/cube0x0/KrbRelay","1","1","N/A","N/A","N/A","10","907","125","2022-05-29T09:45:03Z","2022-02-14T08:21:57Z","38153" +"*CheeseDCOM.exe*",".{0,1000}CheeseDCOM\.exe.{0,1000}","offensive_tool_keyword","CheeseTools","tools for Lateral Movement/Code Execution","T1021.006 - T1059.003 - T1105","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/klezVirus/CheeseTools","1","1","N/A","N/A","10","8","706","143","2021-08-17T20:22:56Z","2020-08-24T01:28:12Z","38155" +"*CheeseExec.csproj*",".{0,1000}CheeseExec\.csproj.{0,1000}","offensive_tool_keyword","CheeseTools","tools for Lateral Movement/Code Execution","T1021.006 - T1059.003 - T1105","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/klezVirus/CheeseTools","1","1","N/A","N/A","10","8","706","143","2021-08-17T20:22:56Z","2020-08-24T01:28:12Z","38156" +"*CheeseExec.exe*",".{0,1000}CheeseExec\.exe.{0,1000}","offensive_tool_keyword","CheeseTools","tools for Lateral Movement/Code Execution","T1021.006 - T1059.003 - T1105","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/klezVirus/CheeseTools","1","1","N/A","N/A","10","8","706","143","2021-08-17T20:22:56Z","2020-08-24T01:28:12Z","38157" +"*CheesePS.csproj*",".{0,1000}CheesePS\.csproj.{0,1000}","offensive_tool_keyword","CheeseTools","tools for Lateral Movement/Code Execution","T1021.006 - T1059.003 - T1105","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/klezVirus/CheeseTools","1","1","N/A","N/A","10","8","706","143","2021-08-17T20:22:56Z","2020-08-24T01:28:12Z","38158" +"*CheesePS.exe*",".{0,1000}CheesePS\.exe.{0,1000}","offensive_tool_keyword","CheeseTools","tools for Lateral Movement/Code Execution","T1021.006 - T1059.003 - T1105","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/klezVirus/CheeseTools","1","1","N/A","N/A","10","8","706","143","2021-08-17T20:22:56Z","2020-08-24T01:28:12Z","38159" +"*CheeseRDP.exe*",".{0,1000}CheeseRDP\.exe.{0,1000}","offensive_tool_keyword","CheeseTools","tools for Lateral Movement/Code Execution","T1021.006 - T1059.003 - T1105","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/klezVirus/CheeseTools","1","1","N/A","N/A","10","8","706","143","2021-08-17T20:22:56Z","2020-08-24T01:28:12Z","38160" +"*CheeseSQL.exe*",".{0,1000}CheeseSQL\.exe.{0,1000}","offensive_tool_keyword","CheeseTools","tools for Lateral Movement/Code Execution","T1021.006 - T1059.003 - T1105","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/klezVirus/CheeseTools","1","1","N/A","N/A","10","8","706","143","2021-08-17T20:22:56Z","2020-08-24T01:28:12Z","38161" +"*CheeseTools.sln*",".{0,1000}CheeseTools\.sln.{0,1000}","offensive_tool_keyword","CheeseTools","tools for Lateral Movement/Code Execution","T1021.006 - T1059.003 - T1105","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/klezVirus/CheeseTools","1","1","N/A","N/A","10","8","706","143","2021-08-17T20:22:56Z","2020-08-24T01:28:12Z","38162" +"*CheeseTools-master*",".{0,1000}CheeseTools\-master.{0,1000}","offensive_tool_keyword","CheeseTools","tools for Lateral Movement/Code Execution","T1021.006 - T1059.003 - T1105","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/klezVirus/CheeseTools","1","1","N/A","N/A","10","8","706","143","2021-08-17T20:22:56Z","2020-08-24T01:28:12Z","38163" +"*chenjiandongx/sniffer*",".{0,1000}chenjiandongx\/sniffer.{0,1000}","offensive_tool_keyword","sniffer","A modern alternative network traffic sniffer.","T1040 - T1052.001 - T1046 - T1552.002","TA0011 - TA0007 - TA0005","N/A","N/A","Sniffing & Spoofing","https://github.com/chenjiandongx/sniffer","1","1","N/A","N/A","N/A","8","769","67","2024-03-02T07:48:19Z","2021-11-08T15:36:03Z","38165" +"*Chimera-main.zip*",".{0,1000}Chimera\-main\.zip.{0,1000}","offensive_tool_keyword","Chimera","Automated DLL Sideloading Tool With EDR Evasion Capabilities","T1574 - T1574.001 - T1218 - T1218.002 - T1070 - T1070.004 - T1036 - T1036.005","TA0005","N/A","N/A","Defense Evasion","https://github.com/georgesotiriadis/Chimera","1","1","N/A","N/A","9","5","469","56","2023-12-19T22:58:03Z","2023-05-15T13:02:54Z","38168" +"*Chimera-master.zip*",".{0,1000}Chimera\-master\.zip.{0,1000}","offensive_tool_keyword","chimera","Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.","T1027.002 - T1059.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/tokyoneon/Chimera/","1","1","N/A","N/A","10","10","1493","252","2021-11-09T12:39:59Z","2020-09-01T07:42:22Z","38169" +"*chisel.jpillora.com*",".{0,1000}chisel\.jpillora\.com.{0,1000}","offensive_tool_keyword","chisel","A fast TCP/UDP tunnel over HTTP","T1090 - T1090.003 - T1572 - T1572.001","TA0042 - TA0011","N/A","BlackSuit - Royal - AvosLocker - Cactus - Yanluowang - Sandworm - KNOTWEED","C2","https://github.com/jpillora/chisel","1","1","N/A","N/A","10","10","14432","1466","2024-09-28T23:35:13Z","2015-02-25T11:42:50Z","38179" +"*chisel_linux_amd64*",".{0,1000}chisel_linux_amd64.{0,1000}","offensive_tool_keyword","chisel","A fast TCP/UDP tunnel over HTTP","T1090 - T1090.003 - T1572 - T1572.001","TA0042 - TA0011","N/A","BlackSuit - Royal - AvosLocker - Cactus - Yanluowang - Sandworm - KNOTWEED","C2","https://github.com/jpillora/chisel","1","1","#linux","N/A","10","10","14432","1466","2024-09-28T23:35:13Z","2015-02-25T11:42:50Z","38182" +"*chisel_windows_amd64.exe*",".{0,1000}chisel_windows_amd64\.exe.{0,1000}","offensive_tool_keyword","chisel","A fast TCP/UDP tunnel over HTTP","T1090 - T1090.003 - T1572 - T1572.001","TA0042 - TA0011","N/A","BlackSuit - Royal - AvosLocker - Cactus - Yanluowang - Sandworm - KNOTWEED","C2","https://github.com/jpillora/chisel","1","1","N/A","N/A","10","10","14432","1466","2024-09-28T23:35:13Z","2015-02-25T11:42:50Z","38183" +"*chisel-master.zip*",".{0,1000}chisel\-master\.zip.{0,1000}","offensive_tool_keyword","chisel","A fast TCP/UDP tunnel over HTTP","T1090 - T1090.003 - T1572 - T1572.001","TA0042 - TA0011","N/A","BlackSuit - Royal - AvosLocker - Cactus - Yanluowang - Sandworm - KNOTWEED","C2","https://github.com/jpillora/chisel","1","1","N/A","N/A","10","10","14432","1466","2024-09-28T23:35:13Z","2015-02-25T11:42:50Z","38184" +"*chknull.zip*",".{0,1000}chknull\.zip.{0,1000}","offensive_tool_keyword","ChkNull","Checks for Users with No passwords","T1078 - T1201","TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/classic_hacking_tools","1","1","N/A","N/A","N/A","1","4","1","2024-06-27T09:35:42Z","2023-04-16T01:49:12Z","38187" +"*chntpw.com/download*",".{0,1000}chntpw\.com\/download.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38201" +"*chocobo_root.c",".{0,1000}chocobo_root\.c","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","38207" +"*chompie1337/Windows_MSKSSRV_LPE_CVE-2023-36802*",".{0,1000}chompie1337\/Windows_MSKSSRV_LPE_CVE\-2023\-36802.{0,1000}","offensive_tool_keyword","Windows_MSKSSRV_LPE_CVE-2023-36802","Complete exploit works on vulnerable Windows 11 22H2 systems CVE-2023-36802 Local Privilege Escalation POC","T1068 - T1548.001","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-36802","1","1","N/A","N/A","10","2","161","38","2023-10-10T17:44:17Z","2023-10-09T17:32:15Z","38209" +"*chrismaddalena/SharpCloud*",".{0,1000}chrismaddalena\/SharpCloud.{0,1000}","offensive_tool_keyword","SharpCloud","Simple C# for checking for the existence of credential files related to AWS - Microsoft Azure and Google Compute.","T1083 - T1059.001 - T1114.002","TA0007 - TA0002 ","N/A","N/A","Credential Access","https://github.com/chrismaddalena/SharpCloud","1","1","N/A","N/A","10","2","171","29","2018-09-18T02:24:10Z","2018-08-20T15:06:22Z","38222" +"*chrispetrou/HRShell*",".{0,1000}chrispetrou\/HRShell.{0,1000}","offensive_tool_keyword","HRShell","HRShell is an HTTPS/HTTP reverse shell built with flask. It is an advanced C2 server with many features & capabilities.","T1021.002 - T1105 - T1059.001 - T1059.003 - T1064","TA0008 - TA0011 - TA0002","N/A","Black Basta","C2","https://github.com/chrispetrou/HRShell","1","1","N/A","N/A","10","10","247","70","2021-09-09T08:26:32Z","2019-08-20T15:24:46Z","38223" +"*christophetd/spoofing-office-macro*",".{0,1000}christophetd\/spoofing\-office\-macro.{0,1000}","offensive_tool_keyword","spoofing-office-macro","PoC of a VBA macro spawning a process with a spoofed parent and command line","T1055.011 - T1127 - T1077","TA0005 - TA0003","N/A","N/A","Sniffing & Spoofing","https://github.com/christophetd/spoofing-office-macro","1","1","N/A","N/A","9","4","381","82","2020-04-28T16:23:43Z","2019-03-11T18:23:39Z","38224" +"*chromecertbeggar.js*",".{0,1000}chromecertbeggar\.js.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","38234" +"*chromecertbeggar2.js*",".{0,1000}chromecertbeggar2\.js.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","38235" +"*chrome-dump.dll*",".{0,1000}chrome\-dump\.dll.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","38239" +"*ChromeDump.git*",".{0,1000}ChromeDump\.git.{0,1000}","offensive_tool_keyword","chromedump","ChromeDump is a small tool to dump all JavaScript and other ressources going through the browser","T1059.007 - T1114.001 - T1518.001 - T1552.002","TA0005 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/g4l4drim/ChromeDump","1","1","N/A","N/A","N/A","1","55","1","2024-10-12T14:07:36Z","2023-01-26T20:44:06Z","38240" +"*chromedump.py*",".{0,1000}chromedump\.py.{0,1000}","offensive_tool_keyword","chromedump","ChromeDump is a small tool to dump all JavaScript and other ressources going through the browser","T1059.007 - T1114.001 - T1518.001 - T1552.002","TA0005 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/g4l4drim/ChromeDump","1","1","N/A","N/A","N/A","1","55","1","2024-10-12T14:07:36Z","2023-01-26T20:44:06Z","38241" +"*chrome-dump.x86.dll*",".{0,1000}chrome\-dump\.x86\.dll.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","38242" +"*ChromeDump-main.zip*",".{0,1000}ChromeDump\-main\.zip.{0,1000}","offensive_tool_keyword","chromedump","ChromeDump is a small tool to dump all JavaScript and other ressources going through the browser","T1059.007 - T1114.001 - T1518.001 - T1552.002","TA0005 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/g4l4drim/ChromeDump","1","1","N/A","N/A","N/A","1","55","1","2024-10-12T14:07:36Z","2023-01-26T20:44:06Z","38243" +"*ChromeKatz/Memory.cpp*",".{0,1000}ChromeKatz\/Memory\.cpp.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38244" +"*ChromeKatz/Process.cpp*",".{0,1000}ChromeKatz\/Process\.cpp.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38245" +"*chromeKey.x64*",".{0,1000}chromeKey\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","38248" +"*chromeKey.x86*",".{0,1000}chromeKey\.x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","38249" +"*chromepass.exe*",".{0,1000}chromepass\.exe.{0,1000}","offensive_tool_keyword","chromepass","ChromePass is a small password recovery tool for Windows that allows you to view the user names and passwords stored by Google Chrome Web browser. For each password entry. the following information is displayed: Origin URL. Action URL. User Name Field. Password Field. User Name. Password. and Created Time. It allows you to get the passwords from your current running system. or from a user profile stored on external drive.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle - GOBLIN PANDA - Loki","Credential Access","https://www.nirsoft.net/utils/chromepass.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38250" +"*chromepass.zip*",".{0,1000}chromepass\.zip.{0,1000}","offensive_tool_keyword","chromepass","ChromePass is a small password recovery tool for Windows that allows you to view the user names and passwords stored by Google Chrome Web browser. For each password entry. the following information is displayed: Origin URL. Action URL. User Name Field. Password Field. User Name. Password. and Created Time. It allows you to get the passwords from your current running system. or from a user profile stored on external drive.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle - GOBLIN PANDA - Loki","Credential Access","https://www.nirsoft.net/utils/chromepass.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38251" +"*ChromeStealer.exe*",".{0,1000}ChromeStealer\.exe.{0,1000}","offensive_tool_keyword","ChromeStealer","extract and decrypt stored passwords from Google Chrome","T1555.003 - T1003.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/BernKing/ChromeStealer","1","1","N/A","N/A","8","2","145","18","2024-07-25T08:27:10Z","2024-07-14T13:27:30Z","38255" +"*chromiumkeydump*",".{0,1000}chromiumkeydump.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files (BOF) for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/crypt0p3g/bof-collection","1","1","N/A","N/A","10","10","175","27","2022-12-05T04:49:33Z","2021-01-20T06:07:38Z","38261" +"*ChromiumKeyDump.cna*",".{0,1000}ChromiumKeyDump\.cna.{0,1000}","offensive_tool_keyword","bof-collection","Collection of Beacon Object Files (BOF) for Cobalt Strike","T1555.003 - T1081 - T1056.004 - T1003","TA0006 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/crypt0p3g/bof-collection","1","1","N/A","N/A","N/A","10","175","27","2022-12-05T04:49:33Z","2021-01-20T06:07:38Z","38262" +"*ChromiumKeyDump.cpp*",".{0,1000}ChromiumKeyDump\.cpp.{0,1000}","offensive_tool_keyword","bof-collection","Collection of Beacon Object Files (BOF) for Cobalt Strike","T1555.003 - T1081 - T1056.004 - T1003","TA0006 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/crypt0p3g/bof-collection","1","1","N/A","N/A","N/A","10","175","27","2022-12-05T04:49:33Z","2021-01-20T06:07:38Z","38263" +"*ChromiumKeyDump.exe*",".{0,1000}ChromiumKeyDump\.exe.{0,1000}","offensive_tool_keyword","bof-collection","Collection of Beacon Object Files (BOF) for Cobalt Strike","T1555.003 - T1081 - T1056.004 - T1003","TA0006 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/crypt0p3g/bof-collection","1","1","N/A","N/A","N/A","10","175","27","2022-12-05T04:49:33Z","2021-01-20T06:07:38Z","38264" +"*Chudry/Xerror*",".{0,1000}Chudry\/Xerror.{0,1000}","offensive_tool_keyword","Xerror","fully automated pentesting tool","T1083 - T1069 - T1204 - T1059 - T1078","TA0007 - TA0005 - TA0002 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Chudry/Xerror","1","1","N/A","N/A","N/A","6","509","110","2022-12-08T04:33:03Z","2019-08-16T21:20:52Z","38266" +"*chunk-Proxy.jar*",".{0,1000}chunk\-Proxy\.jar.{0,1000}","offensive_tool_keyword","chunk-Proxy","A backdoor installed on a web server that allows for the execution of commands and facilitates persistent access.","T1505.003 - T1059 - T1105 - T1071","TA0011 - TA0002 - TA0003","Ghost Ransomware","N/A","C2","https://github.com/BeichenDream/Chunk-Proxy","1","1","N/A","N/A","10","10","283","40","2022-05-07T04:24:50Z","2021-10-28T18:45:21Z","38267" +"*cHux014r17SG3v4gPUrZ0BZjDabMTY2eWDj1tuYdREBg*",".{0,1000}cHux014r17SG3v4gPUrZ0BZjDabMTY2eWDj1tuYdREBg.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","38269" +"*chvancooten/nimbuild*",".{0,1000}chvancooten\/nimbuild.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","38270" +"*chvancooten/NimPlant*",".{0,1000}chvancooten\/NimPlant.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","38271" +"*chvancooten/OSEP-Code-Snippets*",".{0,1000}chvancooten\/OSEP\-Code\-Snippets.{0,1000}","offensive_tool_keyword","OSEP-Code-Snippets","notable code snippets for Offensive Security's PEN-300 (OSEP) course","T1116 - T1204.002 - T1027.009 - T1021.005 - T1560.001 - T1100 - T1003.001 - T1564.001 - T1047 - T1210 - T1134.002 - T1055 - T1055.011 - T1055.012 - T1204","TA0005 - TA0040 - TA0008 - TA0003 - TA0006 - TA0004","N/A","N/A","Exploitation tool","https://github.com/chvancooten/OSEP-Code-Snippets","1","1","N/A","N/A","8","10","1254","444","2024-01-04T15:17:17Z","2021-03-10T21:34:41Z","38272" +"*CICADA8-Research/IHxExec*",".{0,1000}CICADA8\-Research\/IHxExec.{0,1000}","offensive_tool_keyword","IHxExec","Process injection technique","T1055.001 - T1055","TA0005 - TA0004 - TA0003","N/A","N/A","Defense Evasion","https://github.com/CICADA8-Research/IHxExec","1","1","N/A","N/A","8","4","325","46","2024-09-06T07:58:41Z","2024-07-11T09:18:42Z","38274" +"*CICADA8-Research/Spyndicapped*",".{0,1000}CICADA8\-Research\/Spyndicapped.{0,1000}","offensive_tool_keyword","Spyndicapped","COM ViewLogger - keylogger","T1574.001 - T1574.002 - T1574.009","TA0006","N/A","N/A","Credential Access","https://github.com/CICADA8-Research/Spyndicapped","1","1","N/A","N/A","10","4","356","50","2025-01-06T07:31:29Z","2024-12-25T11:47:39Z","38276" +"*CIMplant.sln*",".{0,1000}CIMplant\.sln.{0,1000}","offensive_tool_keyword","CIMplant","C# port of WMImplant which uses either CIM or WMI to query remote systems","T1047 - T1059.001 - T1021.006","TA0002 - TA0007 - TA0008","N/A","Scattered Spider*","Lateral Movement","https://github.com/RedSiege/CIMplant","1","1","N/A","N/A","10","2","199","29","2021-07-14T18:18:42Z","2021-01-29T21:41:58Z","38280" +"*CIMplant-main*",".{0,1000}CIMplant\-main.{0,1000}","offensive_tool_keyword","CIMplant","C# port of WMImplant which uses either CIM or WMI to query remote systems","T1047 - T1059.001 - T1021.006","TA0002 - TA0007 - TA0008","N/A","Scattered Spider*","Lateral Movement","https://github.com/RedSiege/CIMplant","1","1","N/A","N/A","10","2","199","29","2021-07-14T18:18:42Z","2021-01-29T21:41:58Z","38281" +"*Cipher7/ChaiLdr*",".{0,1000}Cipher7\/ChaiLdr.{0,1000}","offensive_tool_keyword","ChaiLdr","Indirect syscalls AV bypass","T1055.011 - T1569 - T1564 - T1213","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Cipher7/ChaiLdr","1","1","N/A","N/A","9","3","220","35","2024-05-17T13:58:04Z","2024-03-29T09:19:10Z","38282" +"*cirt-default-usernames.txt*",".{0,1000}cirt\-default\-usernames\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38283" +"*cirt-fuzzer*",".{0,1000}cirt\-fuzzer.{0,1000}","offensive_tool_keyword","cirt-fuzzer","A simple TCP/UDP protocol fuzzer.","T1046 - T1065 - T1190 - T1219 - T1221 - T1497","TA0001 - TA0002 - TA0003 - TA0008 - TA0011","N/A","N/A","Sniffing & Spoofing","https://www.ecrimelabs.com/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","38284" +"*cisco2john.pl*",".{0,1000}cisco2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","38285" +"*CiscoCXSecurity/creddump7*",".{0,1000}CiscoCXSecurity\/creddump7.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","38286" +"*CiscoCXSecurity/linikatz*",".{0,1000}CiscoCXSecurity\/linikatz.{0,1000}","offensive_tool_keyword","linikatz","linikatz is a tool to attack AD on UNIX","T1003.002 - T1558.003 - T1078 - T1550.001","TA0006 - TA0001 - TA0004 - TA0003","N/A","N/A","Exploitation tool","https://github.com/CiscoCXSecurity/linikatz","1","1","#linux","N/A","10","6","552","79","2023-10-19T17:01:47Z","2018-11-15T22:19:47Z","38287" +"*cisco-phone-query.sh*",".{0,1000}cisco\-phone\-query\.sh.{0,1000}","offensive_tool_keyword","SeeYouCM-Thief","Simple tool to automatically download and parse configuration files from Cisco phone systems searching for SSH credentials","T1110.001 - T1005 - T1071.001","TA0001 - TA0011 - TA0005","N/A","N/A","Discovery","https://github.com/trustedsec/SeeYouCM-Thief","1","1","N/A","N/A","9","2","189","35","2023-05-11T01:04:36Z","2022-01-14T20:12:25Z","38288" +"*citronneur/pamspy*",".{0,1000}citronneur\/pamspy.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","1","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","38289" +"*citronneur/pamspy/releases*",".{0,1000}citronneur\/pamspy\/releases.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","1","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","38290" +"*cjm00n/EvilSln*",".{0,1000}cjm00n\/EvilSln.{0,1000}","offensive_tool_keyword","EvilSln","A New Exploitation Technique for Visual Studio Projects","T1564.001 - T1204.002","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/cjm00n/EvilSln","1","1","N/A","N/A","10","","N/A","","","","38292" +"*cki3klxqycazagx3r5prae3nmfvxmwa34beknr3il4uf76vxd76akqid.onion*",".{0,1000}cki3klxqycazagx3r5prae3nmfvxmwa34beknr3il4uf76vxd76akqid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","38294" +"*Cleanup-57BFF48E-24FB-48E9-A390-AC62ADF38B07.json*",".{0,1000}Cleanup\-57BFF48E\-24FB\-48E9\-A390\-AC62ADF38B07\.json.{0,1000}","offensive_tool_keyword","power-pwn","An offensive and defensive security toolset for Microsoft 365 Power Platform","T1078 - T1078.004 - T1136 - T1136.001 - T1021 - T1021.003 - T1114 - T1114.002","TA0003 - TA0004 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/mbrg/power-pwn","1","1","N/A","N/A","10","10","939","100","2025-03-20T08:54:43Z","2022-06-14T11:40:21Z","38300" +"*clear_command_history.py*",".{0,1000}clear_command_history\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","38302" +"*ClearEventlog.vbs*",".{0,1000}ClearEventlog\.vbs.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","38306" +"*clem9669/hashcat-rule*",".{0,1000}clem9669\/hashcat\-rule.{0,1000}","offensive_tool_keyword","hashcat-rule","Rule for hashcat or john. Aiming to crack how people generate their password","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/clem9669/hashcat-rule","1","1","#linux","N/A","10","5","435","47","2024-09-02T20:14:15Z","2020-03-06T17:20:40Z","38315" +"*clem9669_case.rule*",".{0,1000}clem9669_case\.rule.{0,1000}","offensive_tool_keyword","hashcat-rule","Rule for hashcat or john. Aiming to crack how people generate their password","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/clem9669/hashcat-rule","1","1","#linux","N/A","10","5","435","47","2024-09-02T20:14:15Z","2020-03-06T17:20:40Z","38316" +"*clem9669_large.rule*",".{0,1000}clem9669_large\.rule.{0,1000}","offensive_tool_keyword","hashcat-rule","Rule for hashcat or john. Aiming to crack how people generate their password","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/clem9669/hashcat-rule","1","1","#linux","N/A","10","5","435","47","2024-09-02T20:14:15Z","2020-03-06T17:20:40Z","38317" +"*clem9669_medium.rule*",".{0,1000}clem9669_medium\.rule.{0,1000}","offensive_tool_keyword","hashcat-rule","Rule for hashcat or john. Aiming to crack how people generate their password","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/clem9669/hashcat-rule","1","1","#linux","N/A","10","5","435","47","2024-09-02T20:14:15Z","2020-03-06T17:20:40Z","38318" +"*clem9669_small.rule*",".{0,1000}clem9669_small\.rule.{0,1000}","offensive_tool_keyword","hashcat-rule","Rule for hashcat or john. Aiming to crack how people generate their password","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/clem9669/hashcat-rule","1","1","#linux","N/A","10","5","435","47","2024-09-02T20:14:15Z","2020-03-06T17:20:40Z","38319" +"*clem9669_wordlist_medium.7z*",".{0,1000}clem9669_wordlist_medium\.7z.{0,1000}","offensive_tool_keyword","wordlists","Various wordlists FR & EN - Cracking French passwords","T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/clem9669/wordlists","1","1","N/A","N/A","N/A","3","280","45","2025-04-22T14:34:10Z","2020-10-21T14:37:53Z","38320" +"*clem9669_wordlist_small.7z*",".{0,1000}clem9669_wordlist_small\.7z.{0,1000}","offensive_tool_keyword","wordlists","Various wordlists FR & EN - Cracking French passwords","T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/clem9669/wordlists","1","1","N/A","N/A","N/A","3","280","45","2025-04-22T14:34:10Z","2020-10-21T14:37:53Z","38321" +"*click_to_exploit.docx*",".{0,1000}click_to_exploit\.docx.{0,1000}","offensive_tool_keyword","POC","Just another PoC for the new MSDT-Exploit","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/drgreenthumb93/CVE-2022-30190-follina","1","1","N/A","N/A","N/A","1","8","4","2023-04-20T20:34:05Z","2022-06-01T11:37:08Z","38325" +"*clickjack_attack.html*",".{0,1000}clickjack_attack\.html.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","38326" +"*clickjack_victim.html*",".{0,1000}clickjack_victim\.html.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","38327" +"*clickme*exploit.html*",".{0,1000}clickme.{0,1000}exploit\.html.{0,1000}","offensive_tool_keyword","POC","CVE-2022-30190 Follina POC","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/onecloudemoji/CVE-2022-30190","1","1","N/A","N/A","N/A","2","104","27","2022-05-31T09:35:37Z","2022-05-31T06:45:25Z","38328" +"*clientcuworpelkdwecucgvfhp5uz5n7uohsnokndrlhm2zkntyg3had.onion*",".{0,1000}clientcuworpelkdwecucgvfhp5uz5n7uohsnokndrlhm2zkntyg3had\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","38334" +"*ClipboardImplant*",".{0,1000}ClipboardImplant.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","38335" +"*clipboardinject.*",".{0,1000}clipboardinject\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","38336" +"*clipboardinject.x64*",".{0,1000}clipboardinject\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","38337" +"*clipboardinject.x86*",".{0,1000}clipboardinject\.x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","38338" +"*ClipboardWindow-Inject*",".{0,1000}ClipboardWindow\-Inject.{0,1000}","offensive_tool_keyword","cobaltstrike","CLIPBRDWNDCLASS process injection technique(BOF) - execute beacon shellcode in callback","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BronzeTicket/ClipboardWindow-Inject","1","1","N/A","N/A","10","10","68","12","2022-09-15T01:41:39Z","2022-09-14T15:55:06Z","38340" +"*clipmon.sln*",".{0,1000}clipmon\.sln.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike addons to interact with clipboard","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DallasFR/Cobalt-Clip","1","1","N/A","N/A","10","","N/A","","","","38341" +"*clndh3qilvdv6403g1n0hs3rhd6xpfmjn.oast.online*",".{0,1000}clndh3qilvdv6403g1n0hs3rhd6xpfmjn\.oast\.online.{0,1000}","offensive_tool_keyword","DataBouncing","Data Bouncing is a technique for transmitting data between two endpoints using DNS lookups and HTTP header manipulation","T1048 - T1041","TA0010","N/A","N/A","Data Exfiltration","https://github.com/Unit-259/DataBouncing","1","1","N/A","N/A","9","1","15","0","2025-03-12T07:34:04Z","2025-03-12T06:58:51Z","38344" +"*CloakNDaggerC2-main*",".{0,1000}CloakNDaggerC2\-main.{0,1000}","offensive_tool_keyword","CloakNDaggerC2","A C2 framework designed around the use of public/private RSA key pairs to sign and authenticate commands being executed. This prevents MiTM interception of calls and ensures opsec during delicate operations.","T1090 - T1090.003 - T1071 - T1071.001 - T1553 - T1553.002","TA0011 - TA0042 - TA0003","N/A","N/A","C2","https://github.com/matt-culbert/CloakNDaggerC2","1","1","N/A","N/A","10","10","17","3","2024-10-09T15:36:46Z","2023-04-28T01:58:18Z","38346" +"*cloud_drive_ransomware.py*",".{0,1000}cloud_drive_ransomware\.py.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","38352" +"*cloud_enum-master.zip*",".{0,1000}cloud_enum\-master\.zip.{0,1000}","offensive_tool_keyword","cloud_enum","Multi-cloud OSINT tool. Enumerate public resources in AWS Azure and Google Cloud.","T1596","TA0043","N/A","N/A","Reconnaissance","https://github.com/initstring/cloud_enum","1","1","N/A","N/A","6","10","1794","271","2024-10-10T08:16:59Z","2019-05-31T09:14:05Z","38353" +"*cloudFilterEOP.exe*",".{0,1000}cloudFilterEOP\.exe.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","38355" +"*cloudsploit*cloudtrail*",".{0,1000}cloudsploit.{0,1000}cloudtrail.{0,1000}","offensive_tool_keyword","cloudsploit","CloudSploit by Aqua is an open-source project designed to allow detection of security risks in cloud infrastructure accounts including: Amazon Web Services (AWS) - Microsoft Azure - Google Cloud Platform (GCP) - Oracle Cloud Infrastructure (OCI) and GitHub. These scripts are designed to return a series of potential misconfigurations and security risks.","T1526 - T1534 - T1547 - T1078 - T1046","TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/aquasecurity/cloudsploit","1","1","N/A","N/A","N/A","10","3498","702","2025-03-20T12:01:19Z","2015-06-29T15:33:40Z","38380" +"*cloudsploit/index.js*",".{0,1000}cloudsploit\/index\.js.{0,1000}","offensive_tool_keyword","cloudsploit","CloudSploit by Aqua is an open-source project designed to allow detection of security risks in cloud infrastructure accounts including: Amazon Web Services (AWS) - Microsoft Azure - Google Cloud Platform (GCP) - Oracle Cloud Infrastructure (OCI) and GitHub. These scripts are designed to return a series of potential misconfigurations and security risks.","T1526 - T1534 - T1547 - T1078 - T1046","TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/aquasecurity/cloudsploit","1","1","N/A","N/A","N/A","10","3498","702","2025-03-20T12:01:19Z","2015-06-29T15:33:40Z","38381" +"*cloudsploit/scans*",".{0,1000}cloudsploit\/scans.{0,1000}","offensive_tool_keyword","cloudsploit","CloudSploit by Aqua is an open-source project designed to allow detection of security risks in cloud infrastructure accounts including: Amazon Web Services (AWS) - Microsoft Azure - Google Cloud Platform (GCP) - Oracle Cloud Infrastructure (OCI) and GitHub. These scripts are designed to return a series of potential misconfigurations and security risks.","T1526 - T1534 - T1547 - T1078 - T1046","TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/aquasecurity/cloudsploit","1","1","N/A","N/A","N/A","10","3498","702","2025-03-20T12:01:19Z","2015-06-29T15:33:40Z","38382" +"*CloudSploitSupplemental*",".{0,1000}CloudSploitSupplemental.{0,1000}","offensive_tool_keyword","cloudsploit","CloudSploit by Aqua is an open-source project designed to allow detection of security risks in cloud infrastructure accounts including: Amazon Web Services (AWS) - Microsoft Azure - Google Cloud Platform (GCP) - Oracle Cloud Infrastructure (OCI) and GitHub. These scripts are designed to return a series of potential misconfigurations and security risks.","T1526 - T1534 - T1547 - T1078 - T1046","TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/aquasecurity/cloudsploit","1","1","N/A","N/A","N/A","10","3498","702","2025-03-20T12:01:19Z","2015-06-29T15:33:40Z","38383" +"*clr2of8/DPAT*",".{0,1000}clr2of8\/DPAT.{0,1000}","offensive_tool_keyword","DPAT","Domain Password Audit Tool for Pentesters","T1003 - T1087 - T1110 - T1555","TA0006 - TA0004 - TA0002 - TA0005","N/A","N/A","Credential Access","https://github.com/clr2of8/DPAT","1","1","N/A","N/A","10","10","954","156","2022-06-24T21:41:43Z","2016-11-22T22:00:21Z","38385" +"*clr2of8/GatherContacts*",".{0,1000}clr2of8\/GatherContacts.{0,1000}","offensive_tool_keyword","GatherContacts","A Burp Suite Extension to pull Employee Names from Google and Bing LinkedIn Search Results.As part of reconnaissance when performing a penetration test. it is often useful to gather employee names that can then be massaged into email addresses and usernames. The usernames may come in handy for performing a password spraying attack for example. One easy way to gather employee names is to use the following Burp Suite Pro extension as described below.","T1593 - T1533 - T1087","TA0043 - TA0002","N/A","N/A","Reconnaissance","https://github.com/clr2of8/GatherContacts","1","1","N/A","N/A","N/A","2","193","44","2024-07-06T09:18:54Z","2018-03-29T14:46:14Z","38386" +"*cmars/onionpipe*",".{0,1000}cmars\/onionpipe.{0,1000}","offensive_tool_keyword","onionpipe","onionpipe forwards ports on the local host to remote Onion addresses as Tor hidden services and vice-versa.","T1090.003 - T1573.002","TA0005 - TA0011","N/A","Black Basta","Defense Evasion","https://github.com/cmars/onionpipe","1","1","N/A","N/A","10","6","553","33","2025-04-22T16:34:56Z","2022-01-23T06:52:13Z","38388" +"*cmbndhnoonmghfofefkcccljbkdpamhi_14678.crx*",".{0,1000}cmbndhnoonmghfofefkcccljbkdpamhi_14678\.crx.{0,1000}","offensive_tool_keyword","hack-tools","The all-in-one Red Team browser extension for Web Pentester","T1059.007 - T1505 - T1068 - T1216 - T1547.009","TA0002 - TA0001 - TA0009","N/A","N/A","Vulnerability Scanner","https://github.com/LasCC/Hack-Tools","1","1","N/A","N/A","9","10","6045","678","2025-01-05T23:10:49Z","2020-06-22T21:42:16Z","38389" +"*cmd/bruteforce.go*",".{0,1000}cmd\/bruteforce\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","38470" +"*cmd/bruteuser.go*",".{0,1000}cmd\/bruteuser\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","38471" +"*cmd/ligolo*",".{0,1000}cmd\/ligolo.{0,1000}","offensive_tool_keyword","ligolo","ligolo is a simple and lightweight tool for establishing SOCKS5 or TCP tunnels from a reverse connection in complete safety (TLS certificate with elliptical curve)","T1071 - T1021 - T1573","TA0011 - TA0002","N/A","AvosLocker - LockBit","C2","https://github.com/sysdream/ligolo","1","1","N/A","N/A","10","10","1764","224","2023-01-06T19:49:22Z","2020-05-22T07:58:13Z","38474" +"*cmd/localrelay*",".{0,1000}cmd\/localrelay.{0,1000}","offensive_tool_keyword","ligolo","ligolo is a simple and lightweight tool for establishing SOCKS5 or TCP tunnels from a reverse connection in complete safety (TLS certificate with elliptical curve)","T1071 - T1021 - T1573","TA0011 - TA0002","N/A","AvosLocker - LockBit","C2","https://github.com/sysdream/ligolo","1","1","N/A","N/A","10","10","1764","224","2023-01-06T19:49:22Z","2020-05-22T07:58:13Z","38475" +"*cmd/merlinagent/*",".{0,1000}cmd\/merlinagent\/.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","38476" +"*cmd/merlinagentdll/*",".{0,1000}cmd\/merlinagentdll\/.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","38477" +"*cmd/merlinagentdll/*",".{0,1000}cmd\/merlinagentdll\/.{0,1000}","offensive_tool_keyword","merlin-agent-dll","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent-dll","1","1","N/A","N/A","10","10","51","15","2025-04-17T14:01:36Z","2021-04-17T16:58:24Z","38478" +"*cmd/tshd.go*",".{0,1000}cmd\/tshd\.go.{0,1000}","offensive_tool_keyword","tsh-go","Tiny SHell Go - An open-source backdoor written in Go","T1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009","TA0003 - TA0005 - TA0011 - TA0010","N/A","N/A","Persistence","https://github.com/CykuTW/tsh-go","1","1","N/A","N/A","10","2","161","16","2024-08-29T02:59:37Z","2022-06-13T16:25:30Z","38481" +"*cmd/unix/reverse_bash*",".{0,1000}cmd\/unix\/reverse_bash.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","#linux","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","38482" +"*cmd/unix/reverse_python*",".{0,1000}cmd\/unix\/reverse_python.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","38483" +"*cmd_powershell.cpp*",".{0,1000}cmd_powershell\.cpp.{0,1000}","offensive_tool_keyword","ShadowForgeC2","ShadowForge Command & Control - Harnessing the power of Zoom API - control a compromised Windows Machine from your Zoom Chats.","T1071.001 - T1569.002 - T1059.001","TA0011 - TA0002 - TA0040","N/A","N/A","C2","https://github.com/0xEr3bus/ShadowForgeC2","1","1","N/A","N/A","10","10","47","7","2023-07-15T11:45:36Z","2023-07-13T11:49:36Z","38486" +"*cmd_shellcodex64.*",".{0,1000}cmd_shellcodex64\..{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","38487" +"*cmd_shellcodex86.*",".{0,1000}cmd_shellcodex86\..{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","38488" +"*Cmd-Execute-Assembly.*",".{0,1000}Cmd\-Execute\-Assembly\..{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","38489" +"*Cmd-Inline-Execute.*",".{0,1000}Cmd\-Inline\-Execute\..{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","38490" +"*CmdLineSpoofer.exe*",".{0,1000}CmdLineSpoofer\.exe.{0,1000}","offensive_tool_keyword","CmdLineSpoofer","How to spoof the command line when spawning a new process from C#","T1055 - T1027 - T1036","TA0002 - TA0004 - TA0010","N/A","N/A","Defense Evasion","https://github.com/plackyhacker/CmdLineSpoofer","1","1","N/A","N/A","9","2","106","17","2021-12-28T18:56:25Z","2021-12-27T09:23:45Z","38494" +"*CmdLineSpoofer.sln*",".{0,1000}CmdLineSpoofer\.sln.{0,1000}","offensive_tool_keyword","CmdLineSpoofer","How to spoof the command line when spawning a new process from C#","T1055 - T1027 - T1036","TA0002 - TA0004 - TA0010","N/A","N/A","Defense Evasion","https://github.com/plackyhacker/CmdLineSpoofer","1","1","N/A","N/A","9","2","106","17","2021-12-28T18:56:25Z","2021-12-27T09:23:45Z","38495" +"*CmdLineSpoofer-master*",".{0,1000}CmdLineSpoofer\-master.{0,1000}","offensive_tool_keyword","CmdLineSpoofer","How to spoof the command line when spawning a new process from C#","T1055 - T1027 - T1036","TA0002 - TA0004 - TA0010","N/A","N/A","Defense Evasion","https://github.com/plackyhacker/CmdLineSpoofer","1","1","N/A","N/A","9","2","106","17","2021-12-28T18:56:25Z","2021-12-27T09:23:45Z","38496" +"*Cmd-Shinject.*",".{0,1000}Cmd\-Shinject\..{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","38498" +"*Cmd-Upload.*",".{0,1000}Cmd\-Upload\..{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","38499" +"*cme*-macOS-latest-*",".{0,1000}cme.{0,1000}\-macOS\-latest\-.{0,1000}","offensive_tool_keyword","crackmapexec","macOS default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38502" +"*cme*-ubuntu-latest-*",".{0,1000}cme.{0,1000}\-ubuntu\-latest\-.{0,1000}","offensive_tool_keyword","crackmapexec","ubuntu default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38503" +"*cme*-windows-latest-*",".{0,1000}cme.{0,1000}\-windows\-latest\-.{0,1000}","offensive_tool_keyword","crackmapexec","windows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct lateral move","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38504" +"*cme/cme.conf*",".{0,1000}cme\/cme\.conf.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38505" +"*cme_bloodhound_output_*.txt*",".{0,1000}cme_bloodhound_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38506" +"*cme_dfscoerce_output_*.txt*",".{0,1000}cme_dfscoerce_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38507" +"*cme_get-desc-users_pass_output_*",".{0,1000}cme_get\-desc\-users_pass_output_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38508" +"*cme_get-desc-users_pass_results*",".{0,1000}cme_get\-desc\-users_pass_results.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38509" +"*cme_gpp_output_*.txt*",".{0,1000}cme_gpp_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38510" +"*cme_ldap-checker_output_*",".{0,1000}cme_ldap\-checker_output_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38511" +"*cme_MachineAccountQuota_output_*",".{0,1000}cme_MachineAccountQuota_output_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38512" +"*cme_ms17-010_output_*",".{0,1000}cme_ms17\-010_output_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38513" +"*cme_mssql_priv_output_*.txt*",".{0,1000}cme_mssql_priv_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38514" +"*cme_ntlmv1_output_*",".{0,1000}cme_ntlmv1_output_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38515" +"*cme_passpol_output_*.txt*",".{0,1000}cme_passpol_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38516" +"*cme_petitpotam_output_*.txt*",".{0,1000}cme_petitpotam_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38517" +"*cme_printnightmare_output_*.txt*",".{0,1000}cme_printnightmare_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38518" +"*cme_runasppl_output_*.txt*",".{0,1000}cme_runasppl_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38519" +"*cme_shadowcoerce_output_*.txt*",".{0,1000}cme_shadowcoerce_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38520" +"*cme_smb_enum*",".{0,1000}cme_smb_enum.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38521" +"*cme_smbsigning_output_*.txt*",".{0,1000}cme_smbsigning_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38522" +"*cme_subnets_output_*.txt*",".{0,1000}cme_subnets_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38523" +"*cme_trusted-for-delegation_output_*",".{0,1000}cme_trusted\-for\-delegation_output_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38524" +"*cme_users_auth_ldap_*.txt*",".{0,1000}cme_users_auth_ldap_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38525" +"*cme_users_auth_smb_*.txt*",".{0,1000}cme_users_auth_smb_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38526" +"*cme_users_nullsess_smb_*.txt*",".{0,1000}cme_users_nullsess_smb_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38527" +"*cme_webdav_output_*.txt*",".{0,1000}cme_webdav_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38528" +"*cme_zerologon_output_*.txt*",".{0,1000}cme_zerologon_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","38529" +"*cme-macOS-latest-*.zip*",".{0,1000}cme\-macOS\-latest\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38530" +"*cme-ubuntu-latest-*.zip*",".{0,1000}cme\-ubuntu\-latest\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38531" +"*cme-windows-latest-*.zip*",".{0,1000}cme\-windows\-latest\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38532" +"*CMLoot.psm1*",".{0,1000}CMLoot\.psm1.{0,1000}","offensive_tool_keyword","CMLoot","Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares","T1083 - T1039","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/1njected/CMLoot","1","1","N/A","N/A","8","2","175","22","2023-02-05T00:24:31Z","2022-06-02T10:59:21Z","38533" +"*CMLoot-main*",".{0,1000}CMLoot\-main.{0,1000}","offensive_tool_keyword","CMLoot","Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares","T1083 - T1039","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/1njected/CMLoot","1","1","N/A","N/A","8","2","175","22","2023-02-05T00:24:31Z","2022-06-02T10:59:21Z","38534" +"*cmpivot.py*",".{0,1000}cmpivot\.py.{0,1000}","offensive_tool_keyword","sccmhunter","SCCMHunter is a post-ex tool built to streamline identifying profiling and attacking SCCM related assets in an Active Directory domain","T1087 - T1046 - T1484","TA0003 - TA0006 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/garrettfoster13/sccmhunter","1","1","N/A","N/A","9","8","750","97","2025-04-03T15:58:02Z","2023-02-20T14:09:42Z","38535" +"*cms400net_default_userpass*",".{0,1000}cms400net_default_userpass.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","38536" +"*Cmstp-Bypass.dll*",".{0,1000}Cmstp\-Bypass\.dll.{0,1000}","offensive_tool_keyword","Xworm","Malware with wide range of capabilities ranging from RAT to ransomware","T1562 - T1547 - T1056 - T1125 - T1496 - T1486 - T1219 - T1567 - T1564 - T1027","TA0005 - TA0003 - TA0009 - TA0040 - TA0002 - TA0006 - TA0010 - TA0004 - TA0007 - TA0008 - TA0011","N/A","N/A","Malware","https://github.com/guessthatname99/XWorm-RAT-V2.1","1","1","N/A","N/A","10","","N/A","","","","38537" +"*CmstpElevatedCOM*",".{0,1000}CmstpElevatedCOM.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of UAC Bypass Techniques Weaponized as BOFs","T1548.002 - T1203 - T1055 - T1134.002","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/icyguider/UAC-BOF-Bonanza","1","1","N/A","N/A","10","6","500","65","2024-02-21T22:07:54Z","2024-02-16T14:47:13Z","38539" +"*cmVmbGVjdGl2ZQ==*",".{0,1000}cmVmbGVjdGl2ZQ\=\=.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","38540" +"*CN=PortSwigger*",".{0,1000}CN\=PortSwigger.{0,1000}","offensive_tool_keyword","burpsuite","The class-leading vulnerability scanning. penetration testing. and web app security platform","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://portswigger.net/burp","1","1","N/A","network exploitation tool","N/A","N/A","N/A","N/A","N/A","N/A","38542" +"*cnotin/SplunkWhisperer2*",".{0,1000}cnotin\/SplunkWhisperer2.{0,1000}","offensive_tool_keyword","SplunkWhisperer2","Local privilege escalation or remote code execution through Splunk Universal Forwarder (UF) misconfigurations","T1068 - T1059.003 - T1071.001","TA0004 - TA0003 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/cnotin/SplunkWhisperer2","1","1","N/A","N/A","9","10","250","53","2022-09-30T16:41:17Z","2019-02-24T18:05:51Z","38544" +"*Coalfire-Research/Slackor*",".{0,1000}Coalfire\-Research\/Slackor.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","38545" +"*Coalfire-Research/Slackor*",".{0,1000}Coalfire\-Research\/Slackor.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","38546" +"*cobaltclip.cna*",".{0,1000}cobaltclip\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike addons to interact with clipboard","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DallasFR/Cobalt-Clip","1","1","N/A","N/A","10","","N/A","","","","38549" +"*cobaltclip.exe*",".{0,1000}cobaltclip\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike addons to interact with clipboard","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DallasFR/Cobalt-Clip","1","1","N/A","N/A","10","","N/A","","","","38550" +"*cobaltstrike*",".{0,1000}cobaltstrike.{0,1000}","offensive_tool_keyword","cobaltstrike","cobaltstrike binary for windows - Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network. While penetration tests focus on unpatched vulnerabilities and misconfigurations. these assessments benefit security operations and incident response.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38551" +"*cobalt-strike*",".{0,1000}cobalt\-strike.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38552" +"*cobaltstrike.store*",".{0,1000}cobaltstrike\.store.{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike4.4 one-click deployment script Randomly generate passwords. keys. port numbers. certificates. etc.. to solve the problem that cs4.x cannot run on Linux and report errors Gray often ginkgo design","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/AlphabugX/csOnvps","1","1","N/A","N/A","10","10","286","63","2022-03-19T00:10:03Z","2021-12-02T02:10:42Z","38554" +"*Cobalt-Strike/bof_template*",".{0,1000}Cobalt\-Strike\/bof_template.{0,1000}","offensive_tool_keyword","cobaltstrike","BOF for Kerberos abuse (an implementation of some important features of the Rubeus)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RalfHacker/Kerbeus-BOF","1","1","N/A","N/A","10","10","458","51","2025-03-29T18:15:17Z","2023-11-20T10:01:36Z","38555" +"*cobaltstrike-dist.tgz*",".{0,1000}cobaltstrike\-dist\.tgz.{0,1000}","offensive_tool_keyword","AzureC2Relay","AzureC2Relay is an Azure Function that validates and relays Cobalt Strike beacon traffic by verifying the incoming requests based on a Cobalt Strike Malleable C2 profile.","T1090 - T1090.003 - T1027 - T1027.005 - T1071 - T1071.001","TA0042 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/Flangvik/AzureC2Relay","1","1","N/A","N/A","10","10","220","49","2021-02-15T18:06:38Z","2021-02-14T00:03:52Z","38556" +"*CobblePot59/ADcheck*",".{0,1000}CobblePot59\/ADcheck.{0,1000}","offensive_tool_keyword","Adcheck","Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle","T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009","N/A","N/A","Discovery","https://github.com/CobblePot59/Adcheck","1","1","N/A","N/A","10","4","315","35","2025-04-18T15:17:46Z","2024-05-10T13:54:45Z","38558" +"*cobbr/Covenant*",".{0,1000}cobbr\/Covenant.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38559" +"*cobbr/Elite*",".{0,1000}cobbr\/Elite.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38560" +"*cobbr/PSAmsi*",".{0,1000}cobbr\/PSAmsi.{0,1000}","offensive_tool_keyword","PSAmsi","PSAmsi is a tool for auditing and defeating AMSI signatures.","T1059.001 - T1562.001 - T1070.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/cobbr/PSAmsi","1","1","N/A","N/A","7","4","390","74","2018-04-22T20:56:33Z","2017-09-22T11:48:47Z","38561" +"*cobbr/SharpSploit*",".{0,1000}cobbr\/SharpSploit.{0,1000}","offensive_tool_keyword","SharpSploit","SharpSploit is a .NET post-exploitation library written in C# that aims to highlight the attack surface of .NET and make the use of offensive .NET easier for red teamers.","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/cobbr/SharpSploit","1","1","N/A","N/A","10","10","1789","312","2021-08-12T18:23:15Z","2018-09-20T14:22:37Z","38562" +"*code_execution/*.dll*",".{0,1000}code_execution\/.{0,1000}\.dll.{0,1000}","offensive_tool_keyword","empire","Empire dll paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1075","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","38567" +"*code_execution/*.exe*",".{0,1000}code_execution\/.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","empire","Empire executable paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1135","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","38568" +"*code_execution/*.ps1*",".{0,1000}code_execution\/.{0,1000}\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1136","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","38569" +"*CodeExec-D37DA402-3829-492F-90D0-8EC3909514EB.json*",".{0,1000}CodeExec\-D37DA402\-3829\-492F\-90D0\-8EC3909514EB\.json.{0,1000}","offensive_tool_keyword","power-pwn","An offensive and defensive security toolset for Microsoft 365 Power Platform","T1078 - T1078.004 - T1136 - T1136.001 - T1021 - T1021.003 - T1114 - T1114.002","TA0003 - TA0004 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/mbrg/power-pwn","1","1","N/A","N/A","10","10","939","100","2025-03-20T08:54:43Z","2022-06-14T11:40:21Z","38572" +"*codeLoader/codeLoader.*",".{0,1000}codeLoader\/codeLoader\..{0,1000}","offensive_tool_keyword","C2 related tools","A shellcode loader written using nim","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/aeverj/NimShellCodeLoader","1","1","N/A","N/A","10","10","656","121","2025-02-18T14:31:45Z","2021-01-19T15:57:01Z","38577" +"*codesiddhant/jasmin-ransomware*",".{0,1000}codesiddhant\/jasmin\-ransomware.{0,1000}","offensive_tool_keyword","Jasmin-Ransomware","Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks","T1486","TA0040 - TA0002 - TA0010","N/A","N/A","Ransomware","https://github.com/codesiddhant/Jasmin-Ransomware","1","1","N/A","N/A","10","3","252","80","2021-03-01T14:51:06Z","2021-02-27T07:09:08Z","38578" +"*codewatchorg/bypasswaf*",".{0,1000}codewatchorg\/bypasswaf.{0,1000}","offensive_tool_keyword","bypasswaf","Add headers to all Burp requests to bypass some WAF products","T1090 - T1189 - T1001","TA0002 - TA0040","N/A","N/A","Defense Evasion","https://github.com/codewatchorg/bypasswaf","1","1","N/A","network exploitation tool","N/A","4","331","104","2018-01-28T13:13:39Z","2014-11-17T01:29:35Z","38579" +"*codewatchorg/sqlipy*",".{0,1000}codewatchorg\/sqlipy.{0,1000}","offensive_tool_keyword","sqlipy","SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.","T1190 - T1210 - T1574","TA0002 - TA0040 - TA0043","N/A","N/A","Exploitation tool","https://github.com/codewatchorg/sqlipy","1","1","N/A","network exploitation tool","N/A","3","254","92","2024-06-19T23:38:41Z","2014-09-22T03:25:42Z","38580" +"*codewhitesec/apollon*",".{0,1000}codewhitesec\/apollon.{0,1000}","offensive_tool_keyword","apollon","evade auditd by writing /proc/PID/mem","T1054.001 - T1055.001 - T1012","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/codewhitesec/apollon","1","1","N/A","N/A","8","1","21","7","2023-08-21T05:43:36Z","2023-07-31T11:55:43Z","38581" +"*codewhitesec/daphne*",".{0,1000}codewhitesec\/daphne.{0,1000}","offensive_tool_keyword","daphne","evade auditd by tampering via ptrace","T1054.004 - T1012 - T1057","TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/codewhitesec/daphne","1","1","N/A","N/A","8","1","17","3","2023-08-03T08:31:40Z","2023-07-31T11:57:29Z","38582" +"*codewhitesec/Lastenzug*",".{0,1000}codewhitesec\/Lastenzug.{0,1000}","offensive_tool_keyword","Lastenzug","Socka4a proxy based on websockets","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","Dispossessor","C2","https://github.com/codewhitesec/Lastenzug","1","1","N/A","N/A","10","10","218","33","2022-10-18T08:55:46Z","2022-07-21T12:57:52Z","38583" +"*CoercedPotato.cpp*",".{0,1000}CoercedPotato\.cpp.{0,1000}","offensive_tool_keyword","CoercedPotato","CoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022.","T1548.002 - T1134.002","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/Prepouce/CoercedPotato","1","1","N/A","N/A","10","4","366","66","2024-08-26T08:09:00Z","2023-09-11T19:04:29Z","38586" +"*CoercedPotato.exe*",".{0,1000}CoercedPotato\.exe.{0,1000}","offensive_tool_keyword","CoercedPotato","CoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022.","T1548.002 - T1134.002","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/Prepouce/CoercedPotato","1","1","N/A","N/A","10","4","366","66","2024-08-26T08:09:00Z","2023-09-11T19:04:29Z","38587" +"*CoercedPotato.exe*",".{0,1000}CoercedPotato\.exe.{0,1000}","offensive_tool_keyword","CoercedPotatoRDLL","Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege","T1055 - T1134 - T1548","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/sokaRepo/CoercedPotatoRDLL","1","1","N/A","N/A","10","3","204","31","2023-11-23T18:58:41Z","2023-11-23T13:22:38Z","38588" +"*CoercedPotato.sln*",".{0,1000}CoercedPotato\.sln.{0,1000}","offensive_tool_keyword","CoercedPotato","CoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022.","T1548.002 - T1134.002","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/Prepouce/CoercedPotato","1","1","N/A","N/A","10","4","366","66","2024-08-26T08:09:00Z","2023-09-11T19:04:29Z","38589" +"*CoercedPotato-master*",".{0,1000}CoercedPotato\-master.{0,1000}","offensive_tool_keyword","CoercedPotato","CoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022.","T1548.002 - T1134.002","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/Prepouce/CoercedPotato","1","1","N/A","N/A","10","4","366","66","2024-08-26T08:09:00Z","2023-09-11T19:04:29Z","38590" +"*CoercedPotatoRDLL-main*",".{0,1000}CoercedPotatoRDLL\-main.{0,1000}","offensive_tool_keyword","CoercedPotatoRDLL","Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege","T1055 - T1134 - T1548","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/sokaRepo/CoercedPotatoRDLL","1","1","N/A","N/A","10","3","204","31","2023-11-23T18:58:41Z","2023-11-23T13:22:38Z","38591" +"*coercer/core/loader*",".{0,1000}coercer\/core\/loader.{0,1000}","offensive_tool_keyword","Coercer","A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through many methods.","T1110 - T1021 - T1020","TA0006 - TA0010","N/A","N/A","Exploitation tool","https://github.com/p0dalirius/Coercer","1","1","N/A","N/A","10","10","1945","195","2025-03-21T07:42:42Z","2022-06-30T16:52:33Z","38605" +"*coff_definitions.h*",".{0,1000}coff_definitions\.h.{0,1000}","offensive_tool_keyword","cobaltstrike","Load and execute COFF files and Cobalt Strike BOFs in-memory","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Yaxser/COFFLoader2","1","1","N/A","N/A","10","10","215","44","2022-09-13T14:58:30Z","2021-12-14T07:49:17Z","38607" +"*COFF_Loader.*",".{0,1000}COFF_Loader\..{0,1000}","offensive_tool_keyword","cobaltstrike","Load and execute COFF files and Cobalt Strike BOFs in-memory","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Yaxser/COFFLoader2","1","1","N/A","N/A","10","10","215","44","2022-09-13T14:58:30Z","2021-12-14T07:49:17Z","38608" +"*COFF_PREP_BEACON*",".{0,1000}COFF_PREP_BEACON.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File Loader","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cracked5pider/CoffeeLdr","1","1","N/A","N/A","10","10","286","38","2023-12-03T18:09:34Z","2022-07-18T15:21:11Z","38609" +"*CoffeeLdr.x64.exe*",".{0,1000}CoffeeLdr\.x64\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File Loader","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cracked5pider/CoffeeLdr","1","1","N/A","N/A","10","10","286","38","2023-12-03T18:09:34Z","2022-07-18T15:21:11Z","38611" +"*CoffeeLdr.x86.exe*",".{0,1000}CoffeeLdr\.x86\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File Loader","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cracked5pider/CoffeeLdr","1","1","N/A","N/A","10","10","286","38","2023-12-03T18:09:34Z","2022-07-18T15:21:11Z","38612" +"*COFFELDR_COFFELDR_H*",".{0,1000}COFFELDR_COFFELDR_H.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File Loader","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cracked5pider/CoffeeLdr","1","1","N/A","N/A","10","10","286","38","2023-12-03T18:09:34Z","2022-07-18T15:21:11Z","38613" +"*COFFLdr.cpp*",".{0,1000}COFFLdr\.cpp.{0,1000}","offensive_tool_keyword","Jormungandr","Jormungandr is a kernel implementation of a COFF loader allowing kernel developers to load and execute their COFFs in the kernel","T1215 - T1059.003 - T1547.006","TA0004 - TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Idov31/Jormungandr","1","1","N/A","N/A","N/A","3","228","27","2023-09-26T18:06:53Z","2023-06-25T06:24:16Z","38615" +"*COFFLdr.exe*",".{0,1000}COFFLdr\.exe.{0,1000}","offensive_tool_keyword","Jormungandr","Jormungandr is a kernel implementation of a COFF loader allowing kernel developers to load and execute their COFFs in the kernel","T1215 - T1059.003 - T1547.006","TA0004 - TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Idov31/Jormungandr","1","1","N/A","N/A","N/A","3","228","27","2023-09-26T18:06:53Z","2023-06-25T06:24:16Z","38616" +"*COFFLoader.*",".{0,1000}COFFLoader\..{0,1000}","offensive_tool_keyword","cobaltstrike","This is a quick and dirty COFF loader (AKA Beacon Object Files). Currently can run un-modified BOF's so it can be used for testing without a CS agent running it","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/COFFLoader","1","1","N/A","N/A","10","10","520","78","2025-04-03T14:57:10Z","2021-02-19T19:14:43Z","38617" +"*COFFLoader.x64.dll*",".{0,1000}COFFLoader\.x64\.dll.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","38618" +"*COFFLoader.x86.dll*",".{0,1000}COFFLoader\.x86\.dll.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","38619" +"*COFFLoader64.exe*",".{0,1000}COFFLoader64\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a quick and dirty COFF loader (AKA Beacon Object Files). Currently can run un-modified BOF's so it can be used for testing without a CS agent running it","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/COFFLoader","1","1","N/A","N/A","10","10","520","78","2025-04-03T14:57:10Z","2021-02-19T19:14:43Z","38620" +"*CognisysGroup/HadesLdr*",".{0,1000}CognisysGroup\/HadesLdr.{0,1000}","offensive_tool_keyword","HadesLdr","Shellcode Loader Implementing Indirect Dynamic Syscall - API Hashing - Fileless Shellcode retrieving using Winsock2","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CognisysGroup/HadesLdr","1","1","N/A","N/A","10","3","292","47","2023-07-15T21:23:49Z","2023-07-12T11:44:07Z","38621" +"*coinomi2john.py*",".{0,1000}coinomi2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","38622" +"*coldfusion_dir_traversal_exploit*",".{0,1000}coldfusion_dir_traversal_exploit.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","38623" +"*Coldzer0/ReverseSock5Proxy*",".{0,1000}Coldzer0\/ReverseSock5Proxy.{0,1000}","offensive_tool_keyword","ReverseSock5Proxy","A tiny Reverse Sock5 Proxy","T1090.002 - T1572 - T1071","TA0011 - TA0010","N/A","N/A","C2","https://github.com/Coldzer0/ReverseSock5Proxy","1","1","N/A","N/A","10","10","317","42","2022-11-28T21:18:26Z","2022-11-25T15:12:59Z","38625" +"*ColeHouston/Sunder*",".{0,1000}ColeHouston\/Sunder.{0,1000}","offensive_tool_keyword","Sunder","Windows rootkit designed to work with BYOVD exploits","T1543.003 - T1562.001 - T1547.001 - T1068 - T1548.002","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/ColeHouston/Sunder","1","1","N/A","N/A","10","2","183","20","2025-01-18T10:41:50Z","2025-01-10T03:57:05Z","38626" +"*Collection/MiniDumpWriteDump.*",".{0,1000}Collection\/MiniDumpWriteDump\..{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","38629" +"*Collection_ArchiveCollectedData_ArchiveViaCustomMethod.py*",".{0,1000}Collection_ArchiveCollectedData_ArchiveViaCustomMethod\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","38630" +"*Collection_ArchiveCollectedData_ArchiveViaCustomMethod_7z.py*",".{0,1000}Collection_ArchiveCollectedData_ArchiveViaCustomMethod_7z\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","38631" +"*ColorDataProxyUACBypass*",".{0,1000}ColorDataProxyUACBypass.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of UAC Bypass Techniques Weaponized as BOFs","T1548.002 - T1203 - T1055 - T1134.002","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/icyguider/UAC-BOF-Bonanza","1","1","N/A","N/A","10","6","500","65","2024-02-21T22:07:54Z","2024-02-16T14:47:13Z","38633" +"*com.rastamouse.*",".{0,1000}com\.rastamouse\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38638" +"*com/Anonym0usWork1221/Free-Proxies/main/proxy_files/http_proxies.txt*",".{0,1000}com\/Anonym0usWork1221\/Free\-Proxies\/main\/proxy_files\/http_proxies\.txt.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","38639" +"*com/Anonym0usWork1221/Free-Proxies/main/proxy_files/https_proxies.txt*",".{0,1000}com\/Anonym0usWork1221\/Free\-Proxies\/main\/proxy_files\/https_proxies\.txt.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","38640" +"*com/mmpx12/proxy-list/master/https.txt*",".{0,1000}com\/mmpx12\/proxy\-list\/master\/https\.txt.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","38641" +"*com/monosans/proxy-list/main/proxies/http.txt*",".{0,1000}com\/monosans\/proxy\-list\/main\/proxies\/http\.txt.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","38642" +"*com/MuRongPIG/Proxy-Master/main/http.txt*",".{0,1000}com\/MuRongPIG\/Proxy\-Master\/main\/http\.txt.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","38643" +"*com/officialputuid/KangProxy/KangProxy/http/http.txt*",".{0,1000}com\/officialputuid\/KangProxy\/KangProxy\/http\/http\.txt.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","38644" +"*com/opsxcq/proxy-list/master/list.txt*",".{0,1000}com\/opsxcq\/proxy\-list\/master\/list\.txt.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","38645" +"*com/proxylist-to/proxy-list/main/http.txt*",".{0,1000}com\/proxylist\-to\/proxy\-list\/main\/http\.txt.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","38646" +"*com/prxchk/proxy-list/main/http.txt*",".{0,1000}com\/prxchk\/proxy\-list\/main\/http\.txt.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","38647" +"*com/roosterkid/openproxylist/main/HTTPS_RAW.txt*",".{0,1000}com\/roosterkid\/openproxylist\/main\/HTTPS_RAW\.txt.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","38648" +"*com/ShiftyTR/Proxy-List/master/http.txt*",".{0,1000}com\/ShiftyTR\/Proxy\-List\/master\/http\.txt.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","38649" +"*com/ShiftyTR/Proxy-List/master/https.txt*",".{0,1000}com\/ShiftyTR\/Proxy\-List\/master\/https\.txt.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","38650" +"*com/TheSpeedX/PROXY-List/master/http.txt*",".{0,1000}com\/TheSpeedX\/PROXY\-List\/master\/http\.txt.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","38651" +"*com/yuceltoluyag/GoodProxy/main/raw.txt*",".{0,1000}com\/yuceltoluyag\/GoodProxy\/main\/raw\.txt.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","38652" +"*combine_harvester-main*",".{0,1000}combine_harvester\-main.{0,1000}","offensive_tool_keyword","combine_harvester","Rust in-memory dumper","T1055 - T1055.001 - T1055.012","TA0005 - TA0006","N/A","N/A","Defense Evasion","https://github.com/m3f157O/combine_harvester","1","1","N/A","N/A","10","2","108","17","2023-07-26T07:16:00Z","2023-07-20T07:37:51Z","38654" +"*com-exec.cna*",".{0,1000}com\-exec\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Bloodhound Attack Path Automation in CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/vysecurity/ANGRYPUPPY","1","1","N/A","N/A","10","10","316","87","2020-04-26T17:35:31Z","2017-07-11T14:18:07Z","38655" +"*COMHunter.csproj*",".{0,1000}COMHunter\.csproj.{0,1000}","offensive_tool_keyword","COMHunter","Enumerates COM servers set in LocalServer32 and InProc32 keys on a system using WMI","T1087.002 - T1012 - T1057","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/matterpreter/OffensiveCSharp/tree/master/COMHunter","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","38658" +"*COMHunter.exe*",".{0,1000}COMHunter\.exe.{0,1000}","offensive_tool_keyword","COMHunter","Enumerates COM servers set in LocalServer32 and InProc32 keys on a system using WMI","T1087.002 - T1012 - T1057","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/matterpreter/OffensiveCSharp/tree/master/COMHunter","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","38659" +"*COMHunter.sln*",".{0,1000}COMHunter\.sln.{0,1000}","offensive_tool_keyword","COMHunter","Enumerates COM servers set in LocalServer32 and InProc32 keys on a system using WMI","T1087.002 - T1012 - T1057","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/matterpreter/OffensiveCSharp/tree/master/COMHunter","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","38660" +"*COM-Hunter_v*.zip*",".{0,1000}COM\-Hunter_v.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","COM-Hunter","COM-hunter is a COM Hijacking persistnce tool written in C#","T1122 - T1055.012","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/nickvourd/COM-Hunter","1","1","N/A","N/A","10","3","289","48","2025-03-11T04:49:55Z","2022-05-26T19:34:59Z","38661" +"*COM-Hunter-main*",".{0,1000}COM\-Hunter\-main.{0,1000}","offensive_tool_keyword","COM-Hunter","COM-hunter is a COM Hijacking persistnce tool written in C#","T1122 - T1055.012","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/nickvourd/COM-Hunter","1","1","N/A","N/A","10","3","289","48","2025-03-11T04:49:55Z","2022-05-26T19:34:59Z","38662" +"*COMInjectDotNet.exe*",".{0,1000}COMInjectDotNet\.exe.{0,1000}","offensive_tool_keyword","Accomplice","Tools for discovery and abuse of COM hijacks","T1120 - T1174","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/nccgroup/Accomplice","1","1","N/A","N/A","7","4","303","47","2019-10-15T21:54:09Z","2019-09-04T23:32:09Z","38663" +"*CommandAndControl_*.py*",".{0,1000}CommandAndControl_.{0,1000}\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","38677" +"*CommandCam.exe*",".{0,1000}CommandCam\.exe.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","38679" +"*commandovm.*.installer.fireeye*",".{0,1000}commandovm\..{0,1000}\.installer\.fireeye.{0,1000}","offensive_tool_keyword","commando-vm","CommandoVM - a fully customizable Windows-based security distribution for penetration testing and red teaming.","T1059 - T1053 - T1055 - T1070","TA0002 - TA0004 - TA0008","N/A","N/A","Exploitation OS","https://github.com/mandiant/commando-vm","1","1","N/A","N/A","N/A","10","7168","1313","2024-09-24T19:14:18Z","2019-03-26T22:36:32Z","38681" +"*commando-vm-master*",".{0,1000}commando\-vm\-master.{0,1000}","offensive_tool_keyword","commando-vm","CommandoVM - a fully customizable Windows-based security distribution for penetration testing and red teaming.","T1059 - T1053 - T1055 - T1070","TA0002 - TA0004 - TA0008","N/A","N/A","Exploitation OS","https://github.com/mandiant/commando-vm","1","1","N/A","N/A","N/A","10","7168","1313","2024-09-24T19:14:18Z","2019-03-26T22:36:32Z","38682" +"*Commands/Brute.*",".{0,1000}Commands\/Brute\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","38683" +"*Commands/Createnetonly.*",".{0,1000}Commands\/Createnetonly\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","38684" +"*Commands/DcomCommand.*",".{0,1000}Commands\/DcomCommand\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38685" +"*Commands/DroneCommand.*",".{0,1000}Commands\/DroneCommand\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38686" +"*Commands/ExecuteAssembly.*",".{0,1000}Commands\/ExecuteAssembly\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38687" +"*Commands/KillProcess.*",".{0,1000}Commands\/KillProcess\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38688" +"*Commands/ListProcesses.*",".{0,1000}Commands\/ListProcesses\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38689" +"*Commands/Logonsession.*",".{0,1000}Commands\/Logonsession\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","38690" +"*Commands/PowerShellImport.*",".{0,1000}Commands\/PowerShellImport\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38691" +"*Commands/Preauthscan.*",".{0,1000}Commands\/Preauthscan\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","38692" +"*Commands/PrintWorkingDirectory.*",".{0,1000}Commands\/PrintWorkingDirectory\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38693" +"*Commands/PsExecCommand.*",".{0,1000}Commands\/PsExecCommand\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38694" +"*Commands/RevToSelf.*",".{0,1000}Commands\/RevToSelf\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38695" +"*Commands/RunPe.*",".{0,1000}Commands\/RunPe\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38696" +"*Commands/SetSleep.*",".{0,1000}Commands\/SetSleep\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38697" +"*Commands/Shell.*",".{0,1000}Commands\/Shell\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38698" +"*Commands/ShInject.*",".{0,1000}Commands\/ShInject\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38699" +"*Commands/ShSpawn.*",".{0,1000}Commands\/ShSpawn\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38700" +"*Commands/Silver.*",".{0,1000}Commands\/Silver\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","38701" +"*Commands/StealToken.*",".{0,1000}Commands\/StealToken\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38702" +"*Commands/StopDrone.*",".{0,1000}Commands\/StopDrone\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38703" +"*Commands/TakeScreenshot.*",".{0,1000}Commands\/TakeScreenshot\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38704" +"*Commands/WhoAmI.*",".{0,1000}Commands\/WhoAmI\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38705" +"*Commands/WinRmCommand.*",".{0,1000}Commands\/WinRmCommand\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38706" +"*Commands/WmiCommand.*",".{0,1000}Commands\/WmiCommand\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","38707" +"*commixproject/commix*",".{0,1000}commixproject\/commix.{0,1000}","offensive_tool_keyword","commix","Automated All-in-One OS command injection and exploitation tool.","T1059 - T1053 - T1503","TA0002 - TA0003 - TA0040","N/A","N/A","Exploitation tool","https://github.com/commixproject/commix","1","1","N/A","N/A","N/A","10","5245","872","2025-04-13T08:55:27Z","2015-03-20T08:38:26Z","38708" +"*common.ReflectiveDLL*",".{0,1000}common\.ReflectiveDLL.{0,1000}","offensive_tool_keyword","cobaltstrike","Example code for using named pipe output with beacon ReflectiveDLLs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rxwx/cs-rdll-ipc-example","1","1","N/A","N/A","10","10","116","23","2020-06-24T19:47:35Z","2020-06-24T19:43:56Z","38709" +"*common_passwords.txt*",".{0,1000}common_passwords\.txt.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","38710" +"*communicate_as_backdoor_user.py*",".{0,1000}communicate_as_backdoor_user\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","38712" +"*comnap_##*",".{0,1000}comnap_\#\#.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","38713" +"*comnode_##*",".{0,1000}comnode_\#\#.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","38714" +"*compile_implant*",".{0,1000}compile_implant.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","38723" +"*compress_encode_obfs*",".{0,1000}compress_encode_obfs.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","38729" +"*comsvcs_lsass*",".{0,1000}comsvcs_lsass.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","38743" +"*ComsvcsLSASS*",".{0,1000}ComsvcsLSASS.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","38744" +"*config/51pwn/CVE-*",".{0,1000}config\/51pwn\/CVE\-.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoCs - 23 kinds of application password crack - 7000+Web fingerprints - 146 protocols and 90000+ rules Port scanning - Fuzz - HW - awesome BugBounty","T1046 - T1210.001 - T1059 - T1082 - T1110","TA0007 - TA0001 - TA0009 - TA0002 - TA0004 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","38748" +"*Confuser.CLI.exe*",".{0,1000}Confuser\.CLI\.exe.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","38753" +"*Confuser.DynCipher.dll*",".{0,1000}Confuser\.DynCipher\.dll.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","38754" +"*Confuser.Renamer.dll*",".{0,1000}Confuser\.Renamer\.dll.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","38755" +"*connect.nachovpn.local*",".{0,1000}connect\.nachovpn\.local.{0,1000}","offensive_tool_keyword","NachoVPN","NachoVPN is a Proof of Concept that demonstrates exploitation of SSL-VPN clients using a rogue VPN serve","T1071 - T1027 - T1547 - T1204","TA0003 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/AmberWolfCyber/NachoVPN","1","1","N/A","N/A","7","3","218","28","2024-11-28T12:40:55Z","2024-10-30T15:53:56Z","38766" +"*connormcgarr/tgtdelegation*",".{0,1000}connormcgarr\/tgtdelegation.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","38772" +"*ConPtyShell.cs*",".{0,1000}ConPtyShell\.cs.{0,1000}","offensive_tool_keyword","ConPtyShell","ConPtyShell - Fully Interactive Reverse Shell for Windows","T1059.001 - T1021.004 - T1056.003","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/ConPtyShell","1","1","N/A","N/A","10","10","1102","171","2023-01-20T10:52:52Z","2019-09-13T22:11:18Z","38776" +"*ConPtyShell.exe*",".{0,1000}ConPtyShell\.exe.{0,1000}","offensive_tool_keyword","ConPtyShell","ConPtyShell - Fully Interactive Reverse Shell for Windows","T1059.001 - T1021.004 - T1056.003","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/ConPtyShell","1","1","N/A","N/A","10","10","1102","171","2023-01-20T10:52:52Z","2019-09-13T22:11:18Z","38777" +"*ConPtyShell.git*",".{0,1000}ConPtyShell\.git.{0,1000}","offensive_tool_keyword","ConPtyShell","ConPtyShell - Fully Interactive Reverse Shell for Windows","T1059.001 - T1021.004 - T1056.003","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/ConPtyShell","1","1","N/A","N/A","10","10","1102","171","2023-01-20T10:52:52Z","2019-09-13T22:11:18Z","38778" +"*ConPtyShell.zip*",".{0,1000}ConPtyShell\.zip.{0,1000}","offensive_tool_keyword","ConPtyShell","ConPtyShell - Fully Interactive Reverse Shell for Windows","T1059.001 - T1021.004 - T1056.003","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/ConPtyShell","1","1","N/A","N/A","10","10","1102","171","2023-01-20T10:52:52Z","2019-09-13T22:11:18Z","38779" +"*ConPtyShell.zip*",".{0,1000}ConPtyShell\.zip.{0,1000}","offensive_tool_keyword","ConPtyShell","ConPtyShell - Fully Interactive Reverse Shell for Windows","T1059.001 - T1021.004 - T1056.003","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/ConPtyShell","1","1","N/A","N/A","10","10","1102","171","2023-01-20T10:52:52Z","2019-09-13T22:11:18Z","38780" +"*ConPtyShell_dotnet2.exe*",".{0,1000}ConPtyShell_dotnet2\.exe.{0,1000}","offensive_tool_keyword","ConPtyShell","ConPtyShell - Fully Interactive Reverse Shell for Windows","T1059.001 - T1021.004 - T1056.003","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/ConPtyShell","1","1","N/A","N/A","10","10","1102","171","2023-01-20T10:52:52Z","2019-09-13T22:11:18Z","38781" +"*contact_harvester*",".{0,1000}contact_harvester.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38790" +"*ContainYourself.cpp*",".{0,1000}ContainYourself\.cpp.{0,1000}","offensive_tool_keyword","ContainYourself","Abuses the Windows containers framework to bypass EDRs.","T1562 - T1562.004 - T1212 - T1212.002 - T1055 - T1055.015","TA0005","N/A","N/A","Defense Evasion","https://github.com/deepinstinct/ContainYourself","1","1","N/A","N/A","10","4","310","39","2023-08-31T07:26:22Z","2023-07-12T14:47:24Z","38792" +"*ContainYourself.exe*",".{0,1000}ContainYourself\.exe.{0,1000}","offensive_tool_keyword","ContainYourself","Abuses the Windows containers framework to bypass EDRs.","T1562 - T1562.004 - T1212 - T1212.002 - T1055 - T1055.015","TA0005","N/A","N/A","Defense Evasion","https://github.com/deepinstinct/ContainYourself","1","1","N/A","N/A","10","4","310","39","2023-08-31T07:26:22Z","2023-07-12T14:47:24Z","38793" +"*ContainYourself.sln*",".{0,1000}ContainYourself\.sln.{0,1000}","offensive_tool_keyword","ContainYourself","Abuses the Windows containers framework to bypass EDRs.","T1562 - T1562.004 - T1212 - T1212.002 - T1055 - T1055.015","TA0005","N/A","N/A","Defense Evasion","https://github.com/deepinstinct/ContainYourself","1","1","N/A","N/A","10","4","310","39","2023-08-31T07:26:22Z","2023-07-12T14:47:24Z","38794" +"*ContainYourself-main*",".{0,1000}ContainYourself\-main.{0,1000}","offensive_tool_keyword","ContainYourself","Abuses the Windows containers framework to bypass EDRs.","T1562 - T1562.004 - T1212 - T1212.002 - T1055 - T1055.015","TA0005","N/A","N/A","Defense Evasion","https://github.com/deepinstinct/ContainYourself","1","1","N/A","N/A","10","4","310","39","2023-08-31T07:26:22Z","2023-07-12T14:47:24Z","38795" +"*ContainYourselfPoc.cpp*",".{0,1000}ContainYourselfPoc\.cpp.{0,1000}","offensive_tool_keyword","ContainYourself","Abuses the Windows containers framework to bypass EDRs.","T1562 - T1562.004 - T1212 - T1212.002 - T1055 - T1055.015","TA0005","N/A","N/A","Defense Evasion","https://github.com/deepinstinct/ContainYourself","1","1","N/A","N/A","10","4","310","39","2023-08-31T07:26:22Z","2023-07-12T14:47:24Z","38796" +"*ContainYourselfPoc.exe*",".{0,1000}ContainYourselfPoc\.exe.{0,1000}","offensive_tool_keyword","ContainYourself","Abuses the Windows containers framework to bypass EDRs.","T1562 - T1562.004 - T1212 - T1212.002 - T1055 - T1055.015","TA0005","N/A","N/A","Defense Evasion","https://github.com/deepinstinct/ContainYourself","1","1","N/A","N/A","10","4","310","39","2023-08-31T07:26:22Z","2023-07-12T14:47:24Z","38797" +"*ContainYourselfTempFile.txt*",".{0,1000}ContainYourselfTempFile\.txt.{0,1000}","offensive_tool_keyword","ContainYourself","Abuses the Windows containers framework to bypass EDRs.","T1562 - T1562.004 - T1212 - T1212.002 - T1055 - T1055.015","TA0005","N/A","N/A","Defense Evasion","https://github.com/deepinstinct/ContainYourself","1","1","N/A","N/A","10","4","310","39","2023-08-31T07:26:22Z","2023-07-12T14:47:24Z","38799" +"*ContentHijacking.swf*",".{0,1000}ContentHijacking\.swf.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","38800" +"*contirec7nchr45rx6ympez5rjldibnqzh7lsa56lvjvaeywhvoj3wad.onion*",".{0,1000}contirec7nchr45rx6ympez5rjldibnqzh7lsa56lvjvaeywhvoj3wad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","38801" +"*contirecj4hbzmyzuydyzrvm2c65blmvhoj2cvf25zqj2dwrrqcq5oad.onion*",".{0,1000}contirecj4hbzmyzuydyzrvm2c65blmvhoj2cvf25zqj2dwrrqcq5oad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","38802" +"*contiuevxdgdhn3zl2kubpajtfgqq4ssj2ipv6ujw7fwhggev3rk6hqd.onion*",".{0,1000}contiuevxdgdhn3zl2kubpajtfgqq4ssj2ipv6ujw7fwhggev3rk6hqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","38803" +"*convert_ccache_to_kirbi*",".{0,1000}\?convert_ccache_to_kirbi.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","38807" +"*convert_kirbi_to_ccache*",".{0,1000}\?convert_kirbi_to_ccache.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","38808" +"*ConvertFrom-LDAPLogonHours*",".{0,1000}ConvertFrom\-LDAPLogonHours.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","powerview.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","38812" +"*ConvertFrom-UACValue*",".{0,1000}ConvertFrom\-UACValue.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","38813" +"*Convert-NetToLua.ps1*",".{0,1000}Convert\-NetToLua\.ps1.{0,1000}","offensive_tool_keyword","XiebroC2","Command and control server - multi-person collaborative penetration testing graphical framework","T1105 - T1573.001 - T1055.001 - T1071 - T1041 - T1059.001 - T1059.008 - T1102","TA0011 - TA0003 - TA0005 - TA0007 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/INotGreen/Xiebro-Plugins","1","1","N/A","N/A","10","10","46","8","2025-02-27T09:17:31Z","2024-02-18T02:01:06Z","38816" +"*ConvertTo-Rc4ByteStream*",".{0,1000}ConvertTo\-Rc4ByteStream.{0,1000}","offensive_tool_keyword","empire","empire function name. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1048","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","38820" +"*ConvertTo-ROT13.ps1*",".{0,1000}ConvertTo\-ROT13\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","38821" +"*ConvertToShellcode*",".{0,1000}ConvertToShellcode.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","38824" +"*ConvertTo-Shellcode.*",".{0,1000}ConvertTo\-Shellcode\..{0,1000}","offensive_tool_keyword","sRDI","Shellcode Reflective DLL Injection - Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode","T1620 - T1055.001 - T1059.004 - T1027 - T1105","TA0005 - TA0004 - TA0002","N/A","N/A","Resource Development","https://github.com/monoxgas/sRDI","1","1","N/A","N/A","N/A","10","2262","473","2023-11-15T10:53:00Z","2017-07-28T19:30:53Z","38825" +"*ConvertTo-Shellcode.ps1*",".{0,1000}ConvertTo\-Shellcode\.ps1.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","38826" +"*ConvertToShellcode.py*",".{0,1000}ConvertToShellcode\.py.{0,1000}","offensive_tool_keyword","EvtMute","This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging - mute the event log","T1562.004 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/bats3c/EvtMute","1","1","N/A","N/A","10","3","261","51","2021-04-24T19:23:39Z","2020-08-29T00:13:20Z","38827" +"*ConvertToShellcode.py*",".{0,1000}ConvertToShellcode\.py.{0,1000}","offensive_tool_keyword","sRDI","Shellcode Reflective DLL Injection - Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode","T1620 - T1055.001 - T1059.004 - T1027 - T1105","TA0005 - TA0004 - TA0002","N/A","N/A","Resource Development","https://github.com/monoxgas/sRDI","1","1","N/A","N/A","N/A","10","2262","473","2023-11-15T10:53:00Z","2017-07-28T19:30:53Z","38828" +"*cookie_graber_x64.o*",".{0,1000}cookie_graber_x64\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","C or BOF file to extract WebKit master key to decrypt user cookie. The C code can be used to compile an executable or a bof script for Cobalt Strike.","T1552.002 - T1027.001 - T1059.003 - T1003.001","TA0006 - TA0005 - TA0002 - TA0003","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/Cookie-Graber-BOF","1","1","N/A","N/A","10","10","194","23","2024-04-29T19:08:52Z","2023-05-28T18:30:02Z","38829" +"*cookie-graber.c*",".{0,1000}cookie\-graber\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","C or BOF file to extract WebKit master key to decrypt user cookie. The C code can be used to compile an executable or a bof script for Cobalt Strike.","T1552.002 - T1027.001 - T1059.003 - T1003.001","TA0006 - TA0005 - TA0002 - TA0003","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/Cookie-Graber-BOF","1","1","N/A","N/A","10","10","194","23","2024-04-29T19:08:52Z","2023-05-28T18:30:02Z","38830" +"*cookie-graber_x64.exe*",".{0,1000}cookie\-graber_x64\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","C or BOF file to extract WebKit master key to decrypt user cookie. The C code can be used to compile an executable or a bof script for Cobalt Strike.","T1552.002 - T1027.001 - T1059.003 - T1003.001","TA0006 - TA0005 - TA0002 - TA0003","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/Cookie-Graber-BOF","1","1","N/A","N/A","10","10","194","23","2024-04-29T19:08:52Z","2023-05-28T18:30:02Z","38831" +"*Cookie-Graber-BOF*",".{0,1000}Cookie\-Graber\-BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","C or BOF file to extract WebKit master key to decrypt user cookie. The C code can be used to compile an executable or a bof script for Cobalt Strike.","T1552.002 - T1027.001 - T1059.003 - T1003.001","TA0006 - TA0005 - TA0002 - TA0003","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/Cookie-Graber-BOF","1","1","N/A","N/A","10","10","194","23","2024-04-29T19:08:52Z","2023-05-28T18:30:02Z","38832" +"*CookieKatz.exe*",".{0,1000}CookieKatz\.exe.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38839" +"*CookieKatzBOF.cpp*",".{0,1000}CookieKatzBOF\.cpp.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38840" +"*CookieKatzBOF.x64*",".{0,1000}CookieKatzBOF\.x64.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38841" +"*CookieKatzBOF.zip*",".{0,1000}CookieKatzBOF\.zip.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38842" +"*CookieKatzMinidump.exe*",".{0,1000}CookieKatzMinidump\.exe.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38843" +"*CookieProcessor.exe*",".{0,1000}CookieProcessor\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","C or BOF file to extract WebKit master key to decrypt user cookie. The C code can be used to compile an executable or a bof script for Cobalt Strike.","T1552.002 - T1027.001 - T1059.003 - T1003.001","TA0006 - TA0005 - TA0002 - TA0003","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/Cookie-Graber-BOF","1","1","N/A","N/A","10","10","194","23","2024-04-29T19:08:52Z","2023-05-28T18:30:02Z","38844" +"*cool*/cool.zip*",".{0,1000}cool.{0,1000}\/cool\.zip.{0,1000}","offensive_tool_keyword","C2 related tools","An anti-virus platform written in the Golang-Gin framework with built-in BypassAV methods such as separation and bundling.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Ed1s0nZ/cool","1","1","N/A","N/A","10","10","686","112","2023-07-13T07:04:30Z","2021-11-10T14:32:34Z","38856" +"*CoolerVoid/0d1n*",".{0,1000}CoolerVoid\/0d1n.{0,1000}","offensive_tool_keyword","0d1n","Tool for automating customized attacks against web applications. Fully made in C language with pthreads it has fast performance.","T1583 - T1584 - T1190 - T1133","TA0002 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/CoolerVoid/0d1n","1","1","N/A","N/A","7","","N/A","","","","38857" +"*coolv0.1.exe*",".{0,1000}coolv0\.1\.exe.{0,1000}","offensive_tool_keyword","C2 related tools","An anti-virus platform written in the Golang-Gin framework with built-in BypassAV methods such as separation and bundling.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Ed1s0nZ/cool","1","1","N/A","N/A","10","10","686","112","2023-07-13T07:04:30Z","2021-11-10T14:32:34Z","38858" +"*Cooolis*shellcode*",".{0,1000}Cooolis.{0,1000}shellcode.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","38859" +"*CooolisAdjustTokenPrivileges*",".{0,1000}CooolisAdjustTokenPrivileges.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","38860" +"*CooolisCreateRemoteThread*",".{0,1000}CooolisCreateRemoteThread.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","38861" +"*Cooolis-ExternalC2*",".{0,1000}Cooolis\-ExternalC2.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","38862" +"*Cooolis-ms.exe*",".{0,1000}Cooolis\-ms\.exe.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","38863" +"*Cooolis-msf*",".{0,1000}Cooolis\-msf.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","38864" +"*Cooolis-msX64.zip*",".{0,1000}Cooolis\-msX64\.zip.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","38865" +"*Cooolis-msX86.zip*",".{0,1000}Cooolis\-msX86\.zip.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","38866" +"*Cooolis-Reflective*",".{0,1000}Cooolis\-Reflective.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","38867" +"*Cooolis-Shellcode*",".{0,1000}Cooolis\-Shellcode.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","38868" +"*Cooolis-String.*",".{0,1000}Cooolis\-String\..{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","38869" +"*CooolisVirtualAlloc*",".{0,1000}CooolisVirtualAlloc.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","38870" +"*CopyAndPasteEnum.bat*",".{0,1000}CopyAndPasteEnum\.bat.{0,1000}","offensive_tool_keyword","Windows-Privilege-Escalation","Windows Privilege Escalation Techniques and Scripts","T1055 - T1548 - T1078","TA0004 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/frizb/Windows-Privilege-Escalation","1","1","N/A","N/A","N/A","9","861","190","2020-03-25T22:35:02Z","2017-05-12T13:09:50Z","38886" +"*CopyAndPasteFileDownloader.bat*",".{0,1000}CopyAndPasteFileDownloader\.bat.{0,1000}","offensive_tool_keyword","Windows-Privilege-Escalation","Windows Privilege Escalation Techniques and Scripts","T1055 - T1548 - T1078","TA0004 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/frizb/Windows-Privilege-Escalation","1","1","N/A","N/A","N/A","9","861","190","2020-03-25T22:35:02Z","2017-05-12T13:09:50Z","38887" +"*cordyceps.exe*",".{0,1000}cordyceps\.exe.{0,1000}","offensive_tool_keyword","Cordyceps","C++ self-Injecting dropper based on various EDR evasion techniques","T1055 - T1055.001 - T1070.004 - T1564.001","TA0005 - TA0002 ","N/A","N/A","Defense Evasion","https://github.com/pard0p/Cordyceps","1","1","N/A","N/A","10","","N/A","","","","38892" +"*Cordyceps-main.zip*",".{0,1000}Cordyceps\-main\.zip.{0,1000}","offensive_tool_keyword","Cordyceps","C++ self-Injecting dropper based on various EDR evasion techniques","T1055 - T1055.001 - T1070.004 - T1564.001","TA0005 - TA0002 ","N/A","N/A","Defense Evasion","https://github.com/pard0p/Cordyceps","1","1","N/A","N/A","10","","N/A","","","","38893" +"*core/handler/reverse*",".{0,1000}core\/handler\/reverse.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","38894" +"*core/http_proxy.go*",".{0,1000}core\/http_proxy\.go.{0,1000}","offensive_tool_keyword","evilginx2","Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication","T1557.002 - T1114 - T1539","TA0001","N/A","BlackCat - COLDRIVER","Phishing","https://github.com/kgretzky/evilginx2","1","1","N/A","False positives expected","10","10","12879","2234","2025-01-21T15:16:19Z","2018-07-10T09:59:52Z","38895" +"*core/sprayers/lync.py*",".{0,1000}core\/sprayers\/lync\.py.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","1","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","38896" +"*core/teamserver/stagers/*",".{0,1000}core\/teamserver\/stagers\/.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","38897" +"*Covenant.API*",".{0,1000}Covenant\.API.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38909" +"*Covenant.csproj*",".{0,1000}Covenant\.csproj.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38910" +"*Covenant.exe*",".{0,1000}Covenant\.exe.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38911" +"*Covenant.Models*",".{0,1000}Covenant\.Models.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38912" +"*Covenant.sln*",".{0,1000}Covenant\.sln.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38913" +"*Covenant/Covenant*",".{0,1000}Covenant\/Covenant.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38914" +"*Covenant/wwwroot*",".{0,1000}Covenant\/wwwroot.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38915" +"*CovenantAPI.*",".{0,1000}CovenantAPI\..{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38916" +"*CovenantAPIExtensions.*",".{0,1000}CovenantAPIExtensions\..{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38917" +"*CovenantBaseMenuItem.*",".{0,1000}CovenantBaseMenuItem\..{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38918" +"*CovenantService.cs*",".{0,1000}CovenantService\.cs.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38919" +"*CovenantUser.cs*",".{0,1000}CovenantUser\.cs.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38920" +"*CovenantUserLogin.*",".{0,1000}CovenantUserLogin\..{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38921" +"*CovenantUserLoginResult.*",".{0,1000}CovenantUserLoginResult\..{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38922" +"*CovenantUserRegister.*",".{0,1000}CovenantUserRegister\..{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","38923" +"*covid19_koadic.profile*",".{0,1000}covid19_koadic\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","38924" +"*cow-branded-longhorn.txt*",".{0,1000}cow\-branded\-longhorn\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","38925" +"*Cowpatty*",".{0,1000}Cowpatty.{0,1000}","offensive_tool_keyword","Cowpatty","coWPAtty - Brute-force dictionary attack against WPA-PSK.","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/joswr1ght/cowpatty","1","1","N/A","network exploitation tool","N/A","3","207","51","2018-12-04T22:26:47Z","2017-08-14T20:33:22Z","38927" +"*cpp_test_payload.exe*",".{0,1000}cpp_test_payload\.exe.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","38940" +"*Cr3dOv3r*",".{0,1000}Cr3dOv3r.{0,1000}","offensive_tool_keyword","Cr3dOv3r","Know the dangers of credential reuse attacks.","T1110 - T1555 - T1003","TA0006 - TA0040 - TA0003","N/A","N/A","Credential Access","https://github.com/D4Vinci/Cr3dOv3r","1","1","N/A","N/A","N/A","10","2050","413","2024-10-14T19:20:12Z","2017-11-13T20:49:57Z","38943" +"*cracf2john.py*",".{0,1000}cracf2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","38944" +"*crack_databases.rb*",".{0,1000}crack_databases\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","38945" +"*crack_windows.rb*",".{0,1000}crack_windows\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","38947" +"*Crack-allDBs.git*",".{0,1000}Crack\-allDBs\.git.{0,1000}","offensive_tool_keyword","Crack-allDBs","bruteforce script for various DB","T1110 - T1110.002 - T1210","TA0006 - TA0001","N/A","N/A","Exploitation tool","https://github.com/d3ckx1/Crack-allDBs","1","1","N/A","N/A","8","1","54","18","2021-04-08T06:17:31Z","2021-04-07T11:17:00Z","38948" +"*Crack-allDBs-main*",".{0,1000}Crack\-allDBs\-main.{0,1000}","offensive_tool_keyword","Crack-allDBs","bruteforce script for various DB","T1110 - T1110.002 - T1210","TA0006 - TA0001","N/A","N/A","Exploitation tool","https://github.com/d3ckx1/Crack-allDBs","1","1","N/A","N/A","8","1","54","18","2021-04-08T06:17:31Z","2021-04-07T11:17:00Z","38949" +"*crack-allDBs-v1.py*",".{0,1000}crack\-allDBs\-v1\.py.{0,1000}","offensive_tool_keyword","Crack-allDBs","bruteforce script for various DB","T1110 - T1110.002 - T1210","TA0006 - TA0001","N/A","N/A","Exploitation tool","https://github.com/d3ckx1/Crack-allDBs","1","1","N/A","N/A","8","1","54","18","2021-04-08T06:17:31Z","2021-04-07T11:17:00Z","38950" +"*crack-allDBs-v2.py*",".{0,1000}crack\-allDBs\-v2\.py.{0,1000}","offensive_tool_keyword","Crack-allDBs","bruteforce script for various DB","T1110 - T1110.002 - T1210","TA0006 - TA0001","N/A","N/A","Exploitation tool","https://github.com/d3ckx1/Crack-allDBs","1","1","N/A","N/A","8","1","54","18","2021-04-08T06:17:31Z","2021-04-07T11:17:00Z","38951" +"*Cracked5pider/KaynLdr*",".{0,1000}Cracked5pider\/KaynLdr.{0,1000}","offensive_tool_keyword","KaynLdr","KaynLdr is a Reflective Loader written in C/ASM","T1055 - T1027 - T1055.012","TA0002 - TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/KaynLdr","1","1","N/A","N/A","9","6","532","108","2023-12-03T18:26:04Z","2021-12-26T14:32:11Z","38952" +"*Cracked5pider/KaynStrike*",".{0,1000}Cracked5pider\/KaynStrike.{0,1000}","offensive_tool_keyword","KaynStrike","A User Defined Reflective Loader for Cobalt Strike Beacon that spoofs the thread start address and frees itself after entry point was executed.","T1055 - T1036 - T1070 - T1055.012 - T1055.001","TA0002 - TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/KaynStrike","1","1","N/A","N/A","9","5","422","66","2023-12-03T18:05:11Z","2022-05-30T04:22:59Z","38953" +"*cracklord-master.*",".{0,1000}cracklord\-master\..{0,1000}","offensive_tool_keyword","cracklord","Queue and resource system for cracking passwords","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/jmmcatee/cracklord","1","1","N/A","N/A","10","4","388","70","2022-09-22T09:30:14Z","2013-12-09T23:10:54Z","38955" +"*cracklord-queued*_amd64.deb*",".{0,1000}cracklord\-queued.{0,1000}_amd64\.deb.{0,1000}","offensive_tool_keyword","cracklord","Queue and resource system for cracking passwords","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/jmmcatee/cracklord","1","1","N/A","N/A","10","4","388","70","2022-09-22T09:30:14Z","2013-12-09T23:10:54Z","38956" +"*cracklord-resourced*_amd64.deb*",".{0,1000}cracklord\-resourced.{0,1000}_amd64\.deb.{0,1000}","offensive_tool_keyword","cracklord","Queue and resource system for cracking passwords","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/jmmcatee/cracklord","1","1","N/A","N/A","10","4","388","70","2022-09-22T09:30:14Z","2013-12-09T23:10:54Z","38957" +"*crackmapexec*",".{0,1000}crackmapexec.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec execution name. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks ","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38958" +"*CrackMapExec*",".{0,1000}CrackMapExec.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Exploitation tool","https://github.com/byt3bl33d3r/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38959" +"*crackmapexec.exe*",".{0,1000}crackmapexec\.exe.{0,1000}","offensive_tool_keyword","crackmapexec","windows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38960" +"*crackmapexec.py*",".{0,1000}crackmapexec\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Exploitation tool","https://github.com/byt3bl33d3r/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38961" +"*crackmapexec.py*",".{0,1000}crackmapexec\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","38962" +"*crackmapexec.spec*",".{0,1000}crackmapexec\.spec.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","38963" +"*crackpkcs12*",".{0,1000}crackpkcs12.{0,1000}","offensive_tool_keyword","crackpkcs12","A multithreaded program to crack PKCS#12 files (p12 and pfx extensions) by Aestu","T1110 - T1185 - T1114","TA0002 - TA0003 - TA0007","N/A","N/A","Credential Access","https://github.com/crackpkcs12/crackpkcs12","1","1","N/A","N/A","N/A","2","153","29","2019-04-26T18:38:11Z","2015-03-19T22:26:17Z","38964" +"*Crassus.csproj*",".{0,1000}Crassus\.csproj.{0,1000}","offensive_tool_keyword","Crassus","Crassus Windows privilege escalation discovery tool","T1068 - T1003 - T1003.003 - T1046","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/vu-ls/Crassus","1","1","N/A","N/A","10","6","571","59","2024-11-08T14:11:39Z","2023-01-12T21:01:52Z","38969" +"*Crassus.exe*",".{0,1000}Crassus\.exe.{0,1000}","offensive_tool_keyword","Crassus","Crassus Windows privilege escalation discovery tool","T1068 - T1003 - T1003.003 - T1046","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/vu-ls/Crassus","1","1","N/A","N/A","10","6","571","59","2024-11-08T14:11:39Z","2023-01-12T21:01:52Z","38970" +"*CravateRouge/autobloody*",".{0,1000}CravateRouge\/autobloody.{0,1000}","offensive_tool_keyword","autobloody","Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound","T1078 - T1078.003 - T1021 - T1021.006 - T1076.001","TA0005 - TA0001 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/CravateRouge/autobloody","1","1","#linux","N/A","10","6","545","54","2024-11-14T13:07:54Z","2022-09-07T13:34:30Z","38973" +"*CravateRouge/bloodyAD*",".{0,1000}CravateRouge\/bloodyAD.{0,1000}","offensive_tool_keyword","bloodyAD","BloodyAD is an Active Directory Privilege Escalation Framework","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/CravateRouge/bloodyAD","1","1","N/A","N/A","10","10","1590","145","2025-04-10T10:47:16Z","2021-10-11T15:07:26Z","38974" +"*crawlLdrDllList*",".{0,1000}crawlLdrDllList.{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike BOF - Inject ETW Bypass into Remote Process via Syscalls (HellsGate|HalosGate)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/injectEtwBypass","1","1","N/A","N/A","10","10","279","55","2021-09-28T19:09:38Z","2021-09-21T23:06:42Z","38975" +"*creaktive/tsh*",".{0,1000}creaktive\/tsh.{0,1000}","offensive_tool_keyword","tsh","UNIX backdoor","T1103 - T1105 - T1160 - T1189 - T1496 - T1102","TA0003 - TA0005 - TA0011","N/A","N/A","Persistence","https://github.com/creaktive/tsh","1","1","#linux","N/A","10","6","568","130","2024-02-20T18:07:08Z","2011-05-14T19:15:00Z","38982" +"*create_dummy_dll_file*",".{0,1000}create_dummy_dll_file.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","38993" +"*create_protected_process_as_user*",".{0,1000}create_protected_process_as_user.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","38996" +"*CreateAssignTokenVariant.exe*",".{0,1000}CreateAssignTokenVariant\.exe.{0,1000}","offensive_tool_keyword","PrivFu","get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","KernelWritePoCs","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","38998" +"*create-aws-instance.py*",".{0,1000}create\-aws\-instance\.py.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1024 - T1071 - T1029 - T1569","TA0002 - TA0003 - TA0040","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","38999" +"*createdaisypayload*",".{0,1000}createdaisypayload.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","39004" +"*Create-HotKeyLNK.json*",".{0,1000}Create\-HotKeyLNK\.json.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","39007" +"*CreateImpersonateTokenVariant.exe*",".{0,1000}CreateImpersonateTokenVariant\.exe.{0,1000}","offensive_tool_keyword","PrivFu","get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","KernelWritePoCs","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","39008" +"*createlinuxpayload*",".{0,1000}createlinuxpayload.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","#linux","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","39009" +"*Create-MultipleSessions.ps1*",".{0,1000}Create\-MultipleSessions\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","39010" +"*Create-NamedPipe*",".{0,1000}Create\-NamedPipe.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","39011" +"*createnewshellcode*",".{0,1000}createnewshellcode.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","39013" +"*createpbindpayload*",".{0,1000}createpbindpayload.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","39015" +"*Create-SuspendedWinLogon*",".{0,1000}Create\-SuspendedWinLogon.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","39023" +"*Create-WinLogonProcess*",".{0,1000}Create\-WinLogonProcess.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","39026" +"*credBandit.*",".{0,1000}credBandit\..{0,1000}","offensive_tool_keyword","cobaltstrike","Proof of concept Beacon Object File (BOF) that uses static x64 syscalls to perform a complete in memory dump of a process and send that back through your already existing Beacon communication channel","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/xforcered/CredBandit","1","1","N/A","N/A","10","10","240","26","2021-07-14T17:42:41Z","2021-03-17T15:19:33Z","39033" +"*credBanditx64*",".{0,1000}credBanditx64.{0,1000}","offensive_tool_keyword","cobaltstrike","Proof of concept Beacon Object File (BOF) that uses static x64 syscalls to perform a complete in memory dump of a process and send that back through your already existing Beacon communication channel","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/xforcered/CredBandit","1","1","N/A","N/A","10","10","240","26","2021-07-14T17:42:41Z","2021-03-17T15:19:33Z","39034" +"*creddump.py*",".{0,1000}creddump\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","39035" +"*creddump7.exe*",".{0,1000}creddump7\.exe.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","39037" +"*CredentialAccess_CredentialDumping_BrowserDataCSharp.py*",".{0,1000}CredentialAccess_CredentialDumping_BrowserDataCSharp\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","39040" +"*CredentialAccess_CredentialDumping_KiwiOnLocal.py*",".{0,1000}CredentialAccess_CredentialDumping_KiwiOnLocal\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","39041" +"*CredentialAccess_CredentialDumping_SunLogin.py*",".{0,1000}CredentialAccess_CredentialDumping_SunLogin\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","39042" +"*CredentialAccess_CredentialDumping_WindowsHashDump.py*",".{0,1000}CredentialAccess_CredentialDumping_WindowsHashDump\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","39043" +"*CredentialAccess_CredentialDumping_WindowsWDigestEnable.py*",".{0,1000}CredentialAccess_CredentialDumping_WindowsWDigestEnable\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","39044" +"*CredentialAccess_CredentialInFiles_BrowserData.py*",".{0,1000}CredentialAccess_CredentialInFiles_BrowserData\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","39045" +"*CredentialAccess_CredentialInFiles_WindowsSoftware.py*",".{0,1000}CredentialAccess_CredentialInFiles_WindowsSoftware\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","39046" +"*CredentialAccess_InputCapture_CredUIPromptForWindowsCredentialsW.py*",".{0,1000}CredentialAccess_InputCapture_CredUIPromptForWindowsCredentialsW\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","39047" +"*Credentials*hekatomb_*.txt",".{0,1000}Credentials.{0,1000}hekatomb_.{0,1000}\.txt","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","39050" +"*Credentials/CacheDump.*",".{0,1000}Credentials\/CacheDump\..{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","39051" +"*Credentials/certsync_*",".{0,1000}Credentials\/certsync_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","39052" +"*Credentials/LSASecrets.*",".{0,1000}Credentials\/LSASecrets\..{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","39053" +"*Credentials/SAMDump*",".{0,1000}Credentials\/SAMDump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","39054" +"*CredHistView.exe*",".{0,1000}CredHistView\.exe.{0,1000}","offensive_tool_keyword","credhistview","This tool allows you to decrypt the CREDHIST file and view the SHA1 and NTLM hashes of all previous passwords you used on your system","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/credhist_view.html","1","1","N/A","N/A","9","9","N/A","N/A","N/A","N/A","39055" +"*credhistview.zip*",".{0,1000}credhistview\.zip.{0,1000}","offensive_tool_keyword","credhistview","This tool allows you to decrypt the CREDHIST file and view the SHA1 and NTLM hashes of all previous passwords you used on your system","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/credhist_view.html","1","1","N/A","N/A","9","9","N/A","N/A","N/A","N/A","39056" +"*CredPhisher.csproj*",".{0,1000}CredPhisher\.csproj.{0,1000}","offensive_tool_keyword","CredPhisher","Prompts the current user for their credentials using the CredUIPromptForWindowsCredentials WinAPI function","T1056.002 - T1111","TA0004 ","N/A","N/A","Phishing","https://github.com/matterpreter/OffensiveCSharp/tree/master/CredPhisher","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","39059" +"*CredPhisher.exe*",".{0,1000}CredPhisher\.exe.{0,1000}","offensive_tool_keyword","CredPhisher","Prompts the current user for their credentials using the CredUIPromptForWindowsCredentials WinAPI function","T1056.002 - T1111","TA0004 ","N/A","N/A","Phishing","https://github.com/matterpreter/OffensiveCSharp/tree/master/CredPhisher","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","39060" +"*credphisher.py*",".{0,1000}credphisher\.py.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","39061" +"*CredPrompt/CredPrompt.cna*",".{0,1000}CredPrompt\/CredPrompt\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/guervild/BOFs","1","1","N/A","N/A","10","10","161","27","2022-05-02T16:59:24Z","2021-03-15T23:30:22Z","39063" +"*creds_hunt.exe*",".{0,1000}creds_hunt\.exe.{0,1000}","offensive_tool_keyword","Dinjector","Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL","T1055 - T1055.012 - T1055.001 - T1027.002","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Metro-Holografix/DInjector","1","1","N/A","private github repo","8","","N/A","","","","39064" +"*CredsLeaker*",".{0,1000}CredsLeaker.{0,1000}","offensive_tool_keyword","CredsLeaker","This script used to display a powershell credentials box asked the user for credentials. However. That was highly noticeable. Now its time to utilize Windows Security popup!","T1087 - T1056 - T1003 - T1059 - T1110","TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/Dviros/CredsLeaker","1","1","N/A","N/A","N/A","4","316","68","2021-03-31T11:49:57Z","2018-03-05T07:53:31Z","39065" +"*CredsPhish.ps1*",".{0,1000}CredsPhish\.ps1.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","39066" +"*Credz-Plz.ps1*",".{0,1000}Credz\-Plz\.ps1.{0,1000}","offensive_tool_keyword","OMG-Credz-Plz","A script used to prompt the target to enter their creds to later be exfiltrated with dropbox.","T1056.002 - T1566.001 - T1567.002","TA0004 - TA0040 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/-OMG-Credz-Plz","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","39067" +"*Credz-Plz-Execute.txt*",".{0,1000}Credz\-Plz\-Execute\.txt.{0,1000}","offensive_tool_keyword","OMG-Credz-Plz","A script used to prompt the target to enter their creds to later be exfiltrated with dropbox.","T1056.002 - T1566.001 - T1567.002","TA0004 - TA0040 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/-OMG-Credz-Plz","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","39068" +"*cribdragg3r/Alaris*",".{0,1000}cribdragg3r\/Alaris.{0,1000}","offensive_tool_keyword","cobaltstrike","A protective and Low Level Shellcode Loader that defeats modern EDR systems.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/cribdragg3r/Alaris","1","1","N/A","N/A","10","10","903","142","2024-03-20T15:50:57Z","2020-02-22T15:42:37Z","39069" +"*crimeware*/zeus.profile*",".{0,1000}crimeware.{0,1000}\/zeus\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","39070" +"*crisprss/PrintSpoofer*",".{0,1000}crisprss\/PrintSpoofer.{0,1000}","offensive_tool_keyword","cobaltstrike","Reflection dll implementation of PrintSpoofer used in conjunction with Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/crisprss/PrintSpoofer","1","1","N/A","N/A","10","10","88","12","2021-10-07T17:45:00Z","2021-10-07T17:28:45Z","39073" +"*crk_get_key1*",".{0,1000}crk_get_key1.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","39074" +"*crk_get_key2*",".{0,1000}crk_get_key2.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","39075" +"*crk_max_keys_per_crypt*",".{0,1000}crk_max_keys_per_crypt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","39076" +"*crk_methods.*",".{0,1000}crk_methods\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","39077" +"*crk_password_loop*",".{0,1000}crk_password_loop.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","39078" +"*CronosDebugger.*",".{0,1000}CronosDebugger\..{0,1000}","offensive_tool_keyword","Cronos-Rootkit","Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.","T1055 - T1078 - T1134 - T1562.001","TA0001 - TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/XaFF-XaFF/Cronos-Rootkit","1","1","N/A","N/A","N/A","9","899","186","2022-03-29T08:26:03Z","2021-08-25T08:54:45Z","39083" +"*CronosRootkit.*",".{0,1000}CronosRootkit\..{0,1000}","offensive_tool_keyword","Cronos-Rootkit","Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.","T1055 - T1078 - T1134 - T1562.001","TA0001 - TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/XaFF-XaFF/Cronos-Rootkit","1","1","N/A","N/A","N/A","9","899","186","2022-03-29T08:26:03Z","2021-08-25T08:54:45Z","39084" +"*CrontabPersistence.json*",".{0,1000}CrontabPersistence\.json.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","39086" +"*CroodSolutions/AutoPwnKey*",".{0,1000}CroodSolutions\/AutoPwnKey.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","39087" +"*CrossC2 beacon*",".{0,1000}CrossC2\sbeacon.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39091" +"*CrossC2 framework*",".{0,1000}CrossC2\sframework.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39093" +"*CrossC2.cna*",".{0,1000}CrossC2\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39094" +"*CrossC2.cna*",".{0,1000}CrossC2\.cna.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39095" +"*CrossC2.git*",".{0,1000}CrossC2\.git.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39096" +"*CrossC2.Linux*",".{0,1000}CrossC2\.Linux.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","#linux","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39097" +"*CrossC2.MacOS*",".{0,1000}CrossC2\.MacOS.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39098" +"*CrossC2.Win*",".{0,1000}CrossC2\.Win.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39099" +"*CrossC2_dev_*",".{0,1000}CrossC2_dev_.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39100" +"*crossc2_entry*",".{0,1000}crossc2_entry.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39101" +"*crossc2_portscan.*",".{0,1000}crossc2_portscan\..{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","39102" +"*crossc2_serverscan.*",".{0,1000}crossc2_serverscan\..{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","39103" +"*CrossC2Beacon*",".{0,1000}CrossC2Beacon.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39104" +"*CrossC2-cs*",".{0,1000}CrossC2\-cs.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39105" +"*CrossC2-GithubBot*",".{0,1000}CrossC2\-GithubBot.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39106" +"*CrossC2Kit",".{0,1000}CrossC2Kit","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39107" +"*CrossC2Kit.*",".{0,1000}CrossC2Kit\..{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","39108" +"*CrossC2Kit.*",".{0,1000}CrossC2Kit\..{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","39109" +"*CrossC2Kit.git*",".{0,1000}CrossC2Kit\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","39110" +"*CrossC2Kit_demo*",".{0,1000}CrossC2Kit_demo.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39111" +"*crossc2kit_latest*",".{0,1000}crossc2kit_latest.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39112" +"*CrossC2Kit_Loader*",".{0,1000}CrossC2Kit_Loader.{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","39113" +"*CrossC2Listener*",".{0,1000}CrossC2Listener.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39114" +"*CrossC2MemScriptEng*",".{0,1000}CrossC2MemScriptEng.{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","39115" +"*CrossC2Script*",".{0,1000}CrossC2Script.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","39116" +"*CrossNet.exe*",".{0,1000}CrossNet\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike payload generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dr0op/CrossNet-Beta","1","1","N/A","N/A","10","10","362","58","2024-06-19T07:02:22Z","2021-02-08T10:52:39Z","39118" +"*Cross-Site-Scripting-XSS-Payloads*",".{0,1000}Cross\-Site\-Scripting\-XSS\-Payloads.{0,1000}","offensive_tool_keyword","Offensive-Payloads","List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.","T1210 - T1185 - T1059 - T1400 - T1506 - T1213 ","TA0001 - TA0002 - TA0006 - TA0008 - TA0011 - TA0009","N/A","N/A","Exploitation tool","https://github.com/InfoSecWarrior/Offensive-Payloads/","1","1","N/A","N/A","N/A","4","328","117","2024-09-20T09:59:28Z","2022-11-18T09:43:41Z","39119" +"*CrossTenantSynchronizationBackdoor.ps1*",".{0,1000}CrossTenantSynchronizationBackdoor\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","39120" +"*CroweCybersecurity/ad-ldap-enum*",".{0,1000}CroweCybersecurity\/ad\-ldap\-enum.{0,1000}","offensive_tool_keyword","ad-ldap-enum","An LDAP based Active Directory user and group enumeration tool","T1087 - T1087.001 - T1018 - T1069 - T1069.002","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/CroweCybersecurity/ad-ldap-enum","1","1","N/A","AD Enumeration","6","4","308","66","2023-02-10T19:07:34Z","2015-08-25T19:38:39Z","39123" +"*CRTInjectAsSystem*",".{0,1000}CRTInjectAsSystem.{0,1000}","offensive_tool_keyword","cobaltstrike","EDR Evasion - Combination of SwampThing - TikiTorch","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rkervella/CarbonMonoxide","1","1","N/A","N/A","10","10","25","10","2020-05-28T10:40:20Z","2020-05-15T09:32:25Z","39125" +"*CRTInjectElevated*",".{0,1000}CRTInjectElevated.{0,1000}","offensive_tool_keyword","cobaltstrike","EDR Evasion - Combination of SwampThing - TikiTorch","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rkervella/CarbonMonoxide","1","1","N/A","N/A","10","10","25","10","2020-05-28T10:40:20Z","2020-05-15T09:32:25Z","39126" +"*CRTInjectWithoutPid*",".{0,1000}CRTInjectWithoutPid.{0,1000}","offensive_tool_keyword","cobaltstrike","EDR Evasion - Combination of SwampThing - TikiTorch","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rkervella/CarbonMonoxide","1","1","N/A","N/A","10","10","25","10","2020-05-28T10:40:20Z","2020-05-15T09:32:25Z","39127" +"*crypt0p3g/bof-collection*",".{0,1000}crypt0p3g\/bof\-collection.{0,1000}","offensive_tool_keyword","bof-collection","Collection of Beacon Object Files (BOF) for Cobalt Strike","T1555.003 - T1081 - T1056.004 - T1003","TA0006 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/crypt0p3g/bof-collection","1","1","N/A","N/A","N/A","10","175","27","2022-12-05T04:49:33Z","2021-01-20T06:07:38Z","39130" +"*crypto_identifier*",".{0,1000}crypto_identifier.{0,1000}","offensive_tool_keyword","crypto_identifier","Crypto tool for pentest and ctf : try to uncipher data using multiple algorithms and block chaining modes. Usefull for a quick check on unknown cipher text and key dictionary","T1573 - T1558 - T1112","TA0001","N/A","N/A","Exploitation tool","https://github.com/Acceis/crypto_identifier","1","1","N/A","N/A","N/A","2","124","24","2018-01-04T11:04:56Z","2017-11-30T13:04:49Z","39141" +"*Cryptolocker-1.0.0.rar*",".{0,1000}Cryptolocker\-1\.0\.0\.rar.{0,1000}","offensive_tool_keyword","hidden-tear","open source ransomware - many variant in the wild","T1486 - T1059 - T1485 - T1489 - T1070 - T1488","TA0005 - TA0009 - TA0040 - TA0042","N/A","N/A","Ransomware","https://github.com/goliate/hidden-tear","1","1","N/A","N/A","10","8","765","394","2020-07-08T22:34:01Z","2015-08-19T09:06:51Z","39142" +"*cryptr3fmuv4di5uiczofjuypopr63x2gltlsvhur2ump4ebru2xd3yd.onion*",".{0,1000}cryptr3fmuv4di5uiczofjuypopr63x2gltlsvhur2ump4ebru2xd3yd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","39143" +"*cs2modrewrite.py*",".{0,1000}cs2modrewrite\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Convert Cobalt Strike profiles to modrewrite scripts","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/cs2modrewrite","1","1","N/A","N/A","10","10","599","117","2023-01-30T17:47:51Z","2017-06-06T14:53:57Z","39146" +"*cs2nginx.py*",".{0,1000}cs2nginx\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Convert Cobalt Strike profiles to modrewrite scripts","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/cs2modrewrite","1","1","N/A","N/A","10","10","599","117","2023-01-30T17:47:51Z","2017-06-06T14:53:57Z","39147" +"*csandker/Azure-AccessPermissions*",".{0,1000}csandker\/Azure\-AccessPermissions.{0,1000}","offensive_tool_keyword","Azure-AccessPermissions","Easy to use PowerShell script to enumerate access permissions in an Azure Active Directory environment.","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/csandker/Azure-AccessPermissions","1","1","N/A","AD Enumeration","6","2","108","18","2023-02-21T06:46:24Z","2022-10-19T10:33:24Z","39148" +"*CS-Avoid-killing*",".{0,1000}CS\-Avoid\-killing.{0,1000}","offensive_tool_keyword","cobaltstrike","CS anti-killing including python version and C version","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Gality369/CS-Loader","1","1","N/A","N/A","10","10","829","141","2025-04-02T09:37:10Z","2020-08-17T21:33:06Z","39149" +"*CS-BOFs/lsass*",".{0,1000}CS\-BOFs\/lsass.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of CobaltStrike beacon object files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/pwn1sher/CS-BOFs","1","1","N/A","N/A","10","10","103","22","2022-02-14T09:47:30Z","2021-01-18T08:54:48Z","39150" +"*csc.exe EfsPotato.cs *",".{0,1000}csc\.exe\sEfsPotato\.cs\s.{0,1000}","offensive_tool_keyword","EfsPotato","Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability)","T1068 - T1055.002 - T1070.004","TA0003 - TA0005 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/zcgonvh/EfsPotato","1","1","N/A","N/A","10","8","771","125","2023-12-14T14:30:15Z","2021-07-26T21:36:16Z","39152" +"*CScrandle_fileless.cs*",".{0,1000}CScrandle_fileless\.cs.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","39154" +"*CsEnox/SeManageVolumeExploit*",".{0,1000}CsEnox\/SeManageVolumeExploit.{0,1000}","offensive_tool_keyword","SeManageVolumeExploit","This exploit grants full permission on C:\ drive for all users on the machine","T1046 - T1098 - T1222.002","TA0007 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/CsEnox/SeManageVolumeExploit","1","1","N/A","N/A","10","2","110","17","2023-05-29T05:41:16Z","2021-10-11T01:17:04Z","39158" +"*csharp_inject_bof_inject*",".{0,1000}csharp_inject_bof_inject.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","39160" +"*CSharpNamedPipeLoader*",".{0,1000}CSharpNamedPipeLoader.{0,1000}","offensive_tool_keyword","cobaltstrike","LiquidSnake is a tool that allows operators to perform fileless Lateral Movement using WMI Event Subscriptions and GadgetToJScript","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RiccardoAncarani/LiquidSnake","1","1","N/A","N/A","10","10","332","46","2021-09-01T11:53:30Z","2021-08-31T12:23:01Z","39161" +"*csload.net/*/muma.*",".{0,1000}csload\.net\/.{0,1000}\/muma\..{0,1000}","offensive_tool_keyword","cobaltstrike","A cobaltstrike shellcode loader - past domestic mainstream antivirus software","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/YDHCUI/csload.net","1","1","N/A","N/A","10","10","122","15","2021-05-21T02:36:03Z","2021-05-20T08:24:16Z","39162" +"*csOnvps*teamserver*",".{0,1000}csOnvps.{0,1000}teamserver.{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike4.4 one-click deployment script Randomly generate passwords. keys. port numbers. certificates. etc.. to solve the problem that cs4.x cannot run on Linux and report errors","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/AlphabugX/csOnvps","1","1","N/A","N/A","10","10","286","63","2022-03-19T00:10:03Z","2021-12-02T02:10:42Z","39163" +"*cSploit-*.apk*",".{0,1000}cSploit\-.{0,1000}\.apk.{0,1000}","offensive_tool_keyword","csploit","The most complete and advanced IT security professional toolkit on Android.","T1555 - T1569 - T1210","TA0002 - TA0003 - TA0009","N/A","N/A","Framework","https://github.com/cSploit/android","1","1","N/A","N/A","N/A","10","3437","1117","2024-04-27T22:17:26Z","2014-10-04T05:53:29Z","39164" +"*cSploit/android*",".{0,1000}cSploit\/android.{0,1000}","offensive_tool_keyword","csploit","The most complete and advanced IT security professional toolkit on Android.","T1555 - T1569 - T1210","TA0002 - TA0003 - TA0009","N/A","N/A","Framework","https://github.com/cSploit/android","1","1","N/A","N/A","N/A","10","3437","1117","2024-04-27T22:17:26Z","2014-10-04T05:53:29Z","39165" +"*CS-Remote-OPs-BOF*",".{0,1000}CS\-Remote\-OPs\-BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","39167" +"*csrf_to_beef*",".{0,1000}csrf_to_beef.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","39168" +"*CSSG_load.cna*",".{0,1000}CSSG_load\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Shellcode Generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RCStep/CSSG","1","1","N/A","N/A","10","10","654","112","2025-01-08T23:11:49Z","2021-01-12T14:39:06Z","39169" +"*C-Sto/gosecretsdump*",".{0,1000}C\-Sto\/gosecretsdump.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","39172" +"*C-Sto/goWMIExec*",".{0,1000}C\-Sto\/goWMIExec.{0,1000}","offensive_tool_keyword","goWMIExec","re-implementation of invoke-wmiexec (Lateral Movement)","T1021.005","TA0008","N/A","N/A","Lateral Movement","https://github.com/C-Sto/goWMIExec","1","1","N/A","N/A","10","3","214","42","2023-02-25T01:41:41Z","2019-10-14T22:32:11Z","39173" +"*cs-token-vault.git*",".{0,1000}cs\-token\-vault\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","In-memory token vault BOF for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Henkru/cs-token-vault","1","1","N/A","N/A","10","10","142","25","2022-08-18T11:02:42Z","2022-07-29T17:50:10Z","39174" +"*CT_Indirect_Syscalls.c*",".{0,1000}CT_Indirect_Syscalls\.c.{0,1000}","offensive_tool_keyword","Indirect-Syscalls","Indirect syscalls serve as an evolution of direct syscalls and enable enhanced EDR evasion by legitimizing syscall command execution and return statement within the ntdll.dll memory. This stealthy operation partially implements the syscall stub in the Indirect Syscall assembly itself.","T1055 - T1548.002 - T1129","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Direct-Syscalls-vs-Indirect-Syscalls","1","1","N/A","N/A","N/A","2","186","24","2024-01-20T12:02:18Z","2023-05-23T06:30:54Z","39180" +"*CT_Indirect_Syscalls.exe*",".{0,1000}CT_Indirect_Syscalls\.exe.{0,1000}","offensive_tool_keyword","Indirect-Syscalls","Indirect syscalls serve as an evolution of direct syscalls and enable enhanced EDR evasion by legitimizing syscall command execution and return statement within the ntdll.dll memory. This stealthy operation partially implements the syscall stub in the Indirect Syscall assembly itself.","T1055 - T1548.002 - T1129","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Direct-Syscalls-vs-Indirect-Syscalls","1","1","N/A","N/A","N/A","2","186","24","2024-01-20T12:02:18Z","2023-05-23T06:30:54Z","39181" +"*CT_Indirect_Syscalls.sln*",".{0,1000}CT_Indirect_Syscalls\.sln.{0,1000}","offensive_tool_keyword","Indirect-Syscalls","Indirect syscalls serve as an evolution of direct syscalls and enable enhanced EDR evasion by legitimizing syscall command execution and return statement within the ntdll.dll memory. This stealthy operation partially implements the syscall stub in the Indirect Syscall assembly itself.","T1055 - T1548.002 - T1129","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Direct-Syscalls-vs-Indirect-Syscalls","1","1","N/A","N/A","N/A","2","186","24","2024-01-20T12:02:18Z","2023-05-23T06:30:54Z","39182" +"*CT_Indirect_Syscalls.vcxproj*",".{0,1000}CT_Indirect_Syscalls\.vcxproj.{0,1000}","offensive_tool_keyword","Indirect-Syscalls","Indirect syscalls serve as an evolution of direct syscalls and enable enhanced EDR evasion by legitimizing syscall command execution and return statement within the ntdll.dll memory. This stealthy operation partially implements the syscall stub in the Indirect Syscall assembly itself.","T1055 - T1548.002 - T1129","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Direct-Syscalls-vs-Indirect-Syscalls","1","1","N/A","N/A","N/A","2","186","24","2024-01-20T12:02:18Z","2023-05-23T06:30:54Z","39183" +"*cuba4ikm4jakjgmkezytyawtdgr2xymvy6nvzgw5cglswg3si76icnqd.onion*",".{0,1000}cuba4ikm4jakjgmkezytyawtdgr2xymvy6nvzgw5cglswg3si76icnqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","39185" +"*cube0x0/CVE-2021-1675*",".{0,1000}cube0x0\/CVE\-2021\-1675.{0,1000}","offensive_tool_keyword","PrintNightmare","PrintNightmare exploitation","T1210 - T1059.001 - T1548.002","TA0001 - TA0002 - TA0004","N/A","Dispossessor","Privilege Escalation","https://github.com/cube0x0/CVE-2021-1675","1","1","N/A","N/A","10","10","1879","582","2021-07-20T15:28:13Z","2021-06-29T17:24:14Z","39186" +"*cube0x0/LdapSignCheck*",".{0,1000}cube0x0\/LdapSignCheck.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File & C# project to check LDAP signing","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/cube0x0/LdapSignCheck","1","1","N/A","N/A","10","10","189","25","2024-08-07T09:32:20Z","2022-02-24T20:25:31Z","39187" +"*cube0x0/MiniDump*",".{0,1000}cube0x0\/MiniDump.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","1","N/A","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","39188" +"*cube0x0/MiniDump*",".{0,1000}cube0x0\/MiniDump.{0,1000}","offensive_tool_keyword","onex","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003 - T1021.001 - T1053 - T1055 - T1057 - T1059.003 - T1070 - T1071 - T1078.002 - T1078.003 - T1078.005 - T1106 - T1136 - T1204 - T1218 - T1547 - T1555.003 - T1555.004 - T1573 - T1574 - T1596 - T1543","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","1","N/A","N/A","N/A","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","39189" +"*cube0x0/SharpMapExec*",".{0,1000}cube0x0\/SharpMapExec.{0,1000}","offensive_tool_keyword","SharpMapExec","A sharpen version of CrackMapExec","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/cube0x0/SharpMapExec","1","1","N/A","N/A","10","7","664","124","2021-11-17T17:53:12Z","2020-12-01T13:03:50Z","39190" +"*cuddlephish*stealer.js",".{0,1000}cuddlephish.{0,1000}stealer\.js","offensive_tool_keyword","cuddlephish","Weaponized Browser-in-the-Middle (BitM) for Penetration Testers","T1185 - T1185.002 - T1071 - T1071.001 - T1556 - T1556.001","TA0009 - TA0006","N/A","N/A","Sniffing & Spoofing","https://github.com/fkasler/cuddlephish","1","1","N/A","N/A","10","5","487","51","2024-11-21T17:36:55Z","2023-08-02T14:30:41Z","39191" +"*cuddlephish-main*",".{0,1000}cuddlephish\-main.{0,1000}","offensive_tool_keyword","cuddlephish","Weaponized Browser-in-the-Middle (BitM) for Penetration Testers","T1185 - T1185.002 - T1071 - T1071.001 - T1556 - T1556.001","TA0009 - TA0006","N/A","N/A","Sniffing & Spoofing","https://github.com/fkasler/cuddlephish","1","1","N/A","N/A","10","5","487","51","2024-11-21T17:36:55Z","2023-08-02T14:30:41Z","39192" +"*curl*/tmp/exploit-dirty-pipe*",".{0,1000}curl.{0,1000}\/tmp\/exploit\-dirty\-pipe.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","t1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/carlosevieira/Dirty-Pipe","1","1","N/A","N/A","N/A","1","9","6","2022-03-07T21:01:15Z","2022-03-07T20:57:34Z","39220" +"*curlshell.py*",".{0,1000}curlshell\.py.{0,1000}","offensive_tool_keyword","curlshell","reverse shell using curl","T1105 - T1059.004 - T1140","TA0011 - TA0002 - TA0007","N/A","N/A","C2","https://github.com/irsl/curlshell","1","1","#linux","N/A","10","10","454","73","2024-04-20T15:23:11Z","2023-07-13T19:38:34Z","39222" +"*CursedChrome-master.zip*",".{0,1000}CursedChrome\-master\.zip.{0,1000}","offensive_tool_keyword","CursedChrome","Chrome-extension implant that turns victim Chrome browsers into fully-functional HTTP proxies allowing you to browse sites as your victims","T1176 - T1219 - T1090","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/mandatoryprogrammer/CursedChrome","1","1","N/A","N/A","10","10","1533","226","2024-10-26T19:06:54Z","2020-04-26T20:55:05Z","39229" +"*custom_payload_generator.*",".{0,1000}custom_payload_generator\..{0,1000}","offensive_tool_keyword","cobaltstrike","Various Aggressor Scripts I've Created.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/offsecginger/AggressorScripts","1","1","N/A","N/A","10","10","149","30","2022-01-01T19:04:27Z","2018-11-30T03:14:45Z","39231" +"*CustomKeyboardLayoutPersistence*",".{0,1000}CustomKeyboardLayoutPersistence.{0,1000}","offensive_tool_keyword","cobaltstrike","Achieve execution using a custom keyboard layout","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/NtQuerySystemInformation/CustomKeyboardLayoutPersistence","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","39232" +"*CVE-*.bash*",".{0,1000}CVE\-.{0,1000}\.bash.{0,1000}","offensive_tool_keyword","POC","CVE POCs exploits executables ","T1543 - T1588 - T1211 - T1203","TA0008 - TA0009 - TA0010","N/A","N/A","Exploitation tool","https://github.com/gottburgm/Exploits","1","1","#linux","N/A","N/A","2","193","106","2020-04-17T07:28:55Z","2017-10-13T10:19:55Z","39235" +"*CVE-*.exe*",".{0,1000}CVE\-.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","POC","CVE POCs exploits executables ","T1543 - T1588 - T1211 - T1203","TA0008 - TA0009 - TA0010","N/A","N/A","Exploitation tool","https://github.com/gottburgm/Exploits","1","1","N/A","N/A","N/A","2","193","106","2020-04-17T07:28:55Z","2017-10-13T10:19:55Z","39241" +"*CVE-*.ps1*",".{0,1000}CVE\-.{0,1000}\.ps1.{0,1000}","offensive_tool_keyword","POC","CVE POCs exploits executables ","T1543 - T1588 - T1211 - T1203","TA0008 - TA0009 - TA0010","N/A","N/A","Exploitation tool","https://github.com/gottburgm/Exploits","1","1","N/A","N/A","N/A","2","193","106","2020-04-17T07:28:55Z","2017-10-13T10:19:55Z","39245" +"*CVE-*.py*",".{0,1000}CVE\-.{0,1000}\.py.{0,1000}","offensive_tool_keyword","POC","CVE POCs exploits executables ","T1543 - T1588 - T1211 - T1203","TA0008 - TA0009 - TA0010","N/A","N/A","Exploitation tool","https://github.com/gottburgm/Exploits","1","1","N/A","N/A","N/A","2","193","106","2020-04-17T07:28:55Z","2017-10-13T10:19:55Z","39246" +"*CVE_*_exploited.txt*",".{0,1000}CVE_.{0,1000}_exploited\.txt.{0,1000}","offensive_tool_keyword","POC","A Safer PoC for CVE-2022-22965 (Spring4Shell)","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/colincowie/Safer_PoC_CVE-2022-22965","1","1","N/A","N/A","N/A","1","44","7","2022-05-27T12:56:40Z","2022-03-31T16:58:56Z","39256" +"*cve_2_MSF_exploit_Mapping*",".{0,1000}cve_2_MSF_exploit_Mapping.{0,1000}","offensive_tool_keyword","Xerror","fully automated pentesting tool","T1083 - T1069 - T1204 - T1059 - T1078","TA0007 - TA0005 - TA0002 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Chudry/Xerror","1","1","N/A","N/A","N/A","6","509","110","2022-12-08T04:33:03Z","2019-08-16T21:20:52Z","39257" +"*CVE_20*.dll*",".{0,1000}CVE_20.{0,1000}\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","39258" +"*cve_2019_0708_bluekeep_fail*",".{0,1000}cve_2019_0708_bluekeep_fail.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","39259" +"*cve_2019_0708_bluekeep_pass*",".{0,1000}cve_2019_0708_bluekeep_pass.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","39260" +"*cve_2020_0796_smbghost.*",".{0,1000}cve_2020_0796_smbghost\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","39261" +"*cve-20.x64.dll*",".{0,1000}cve\-20\.x64\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/ElevateKit","1","1","N/A","N/A","10","10","912","203","2020-06-22T21:12:24Z","2016-12-08T03:51:09Z","39263" +"*cve-20.x86.dll*",".{0,1000}cve\-20\.x86\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/ElevateKit","1","1","N/A","N/A","10","10","912","203","2020-06-22T21:12:24Z","2016-12-08T03:51:09Z","39264" +"*CVE-2021-1675.ps1*",".{0,1000}CVE\-2021\-1675\.ps1.{0,1000}","offensive_tool_keyword","PrintNightmare","PrintNightmare exploitation","T1210 - T1059.001 - T1548.002","TA0001 - TA0002 - TA0004","N/A","Dispossessor","Privilege Escalation","https://github.com/calebstewart/CVE-2021-1675","1","1","N/A","N/A","10","10","1049","230","2021-07-05T08:54:06Z","2021-07-01T23:45:58Z","39267" +"*CVE-2021-1675.py*",".{0,1000}CVE\-2021\-1675\.py.{0,1000}","offensive_tool_keyword","PrintNightmare","PrintNightmare exploitation","T1210 - T1059.001 - T1548.002","TA0001 - TA0002 - TA0004","N/A","Dispossessor","Privilege Escalation","https://github.com/cube0x0/CVE-2021-1675","1","1","N/A","N/A","10","10","1879","582","2021-07-20T15:28:13Z","2021-06-29T17:24:14Z","39268" +"*CVE-2021-34527.ps1*",".{0,1000}CVE\-2021\-34527\.ps1.{0,1000}","offensive_tool_keyword","conti","Conti is a Ransomware-as-a-Service (RaaS) that was first observed in December 2019. Conti has been deployed via TrickBot and used against major corporations and government agencies particularly those in North America. As with other ransomware families - actors using Conti steal sensitive files and information from compromised networks and threaten to publish this data unless the ransom is paid","T1059.003 - T1486 - T1140 - T1083 - T1490 - T1106 - T1135 - T1027 - T1057 - T1055.001 - T1021.002 - T1018 - T1489 - T1016 - T1049 - T1080","TA0002 - TA0003 - TA0004 - TA0007 - TA0009 - TA0040","Conti Ransomware","Wizard Spider - Black Basta","Ransomware","https://www.securonix.com/blog/on-conti-ransomware-tradecraft-detection/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","39270" +"*cve-20220-26809_exploit.py*",".{0,1000}cve\-20220\-26809_exploit\.py.{0,1000}","offensive_tool_keyword","POC","Remote Code Execution Exploit in the RPC Library CVE-2022-26809","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/yuanLink/CVE-2022-26809","1","1","N/A","N/A","N/A","1","61","27","2022-05-25T00:57:52Z","2022-05-01T13:19:10Z","39271" +"*CVE-2022-0847-DirtyPipe-Exploits.*",".{0,1000}CVE\-2022\-0847\-DirtyPipe\-Exploits\..{0,1000}","offensive_tool_keyword","POC","exploit the Linux Dirty Pipe vulnerability","T1068 - T1078.003 - T1071.004 - T1072 - T1105","TA0004 - TA0006?","N/A","N/A","Privilege Escalation","https://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits","1","1","#linux","N/A","10","6","595","148","2023-05-20T05:55:45Z","2022-03-12T20:57:24Z","39272" +"*CVE-2022-21882.x64.dll*",".{0,1000}CVE\-2022\-21882\.x64\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","39273" +"*cve-2022-26809-scanVuln.py*",".{0,1000}cve\-2022\-26809\-scanVuln\.py.{0,1000}","offensive_tool_keyword","POC","Remote Code Execution Exploit in the RPC Library CVE-2022-26809","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/yuanLink/CVE-2022-26809","1","1","N/A","N/A","N/A","1","61","27","2022-05-25T00:57:52Z","2022-05-01T13:19:10Z","39275" +"*CVE-2022-30190-follina-Office-MSDT-Fixed*",".{0,1000}CVE\-2022\-30190\-follina\-Office\-MSDT\-Fixed.{0,1000}","offensive_tool_keyword","POC","Just another PoC for the new MSDT-Exploit","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/komomon/CVE-2022-30190-follina-Office-MSDT-Fixed","1","1","N/A","N/A","N/A","4","396","54","2023-04-13T16:46:26Z","2022-06-02T12:33:18Z","39276" +"*CVE-2022-34709-Credential-Guard-EoP-Patch-Downgrade/Config.xml*",".{0,1000}CVE\-2022\-34709\-Credential\-Guard\-EoP\-Patch\-Downgrade\/Config\.xml.{0,1000}","offensive_tool_keyword","WindowsDowndate","A tool that takes over Windows Updates to craft custom downgrades and expose past fixed vulnerabilities","T1072 - T1486 - T1505.002 - T1495 - T1499.004","TA0005 - TA0004 - TA0003 ","N/A","N/A","Defense Evasion","https://github.com/SafeBreach-Labs/WindowsDowndate","1","1","N/A","N/A","10","7","663","88","2024-10-26T10:18:49Z","2024-01-08T19:42:47Z","39277" +"*CVE-2023-20887.git*",".{0,1000}CVE\-2023\-20887\.git.{0,1000}","offensive_tool_keyword","POC","VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)","T1068 - T1190.001 - T1210.002 - T1059.001 - T1059.003 - T1190 - T1569.002","TA0005 - TA0002 - TA0001 - TA0040 - TA0043","N/A","N/A","Exploitation tool","https://github.com/sinsinology/CVE-2023-20887","1","1","N/A","N/A","N/A","3","232","43","2023-06-13T14:39:17Z","2023-06-13T13:17:23Z","39278" +"*cve-2023-21554.nse*",".{0,1000}cve\-2023\-21554\.nse.{0,1000}","offensive_tool_keyword","poc","Windows Message Queuing vulnerability exploitation with custom payloads","T1192 - T1507","TA0002","N/A","N/A","Exploitation tool","https://github.com/Hashi0x/PoC-CVE-2023-21554","1","1","N/A","network exploitation tool","N/A","","N/A","","","","39279" +"*CVE-2023-21768-AFD-Driver-EoP-Patch-Downgrade/Config.xml*",".{0,1000}CVE\-2023\-21768\-AFD\-Driver\-EoP\-Patch\-Downgrade\/Config\.xml.{0,1000}","offensive_tool_keyword","WindowsDowndate","A tool that takes over Windows Updates to craft custom downgrades and expose past fixed vulnerabilities","T1072 - T1486 - T1505.002 - T1495 - T1499.004","TA0005 - TA0004 - TA0003 ","N/A","N/A","Defense Evasion","https://github.com/SafeBreach-Labs/WindowsDowndate","1","1","N/A","N/A","10","7","663","88","2024-10-26T10:18:49Z","2024-01-08T19:42:47Z","39280" +"*CVE-2023-23397.ps1*",".{0,1000}CVE\-2023\-23397\.ps1.{0,1000}","offensive_tool_keyword","POC","CVE-2023-23397 POC Powershell exploit","T1068 - T1557.001 - T1187 - T1212 -T1003.001 - T1550","TA0003 - TA0002 - TA0004","N/A","N/A","Exploitation tool","https://github.com/api0cradle/CVE-2023-23397-POC-Powershell","1","1","N/A","N/A","N/A","4","344","63","2023-03-17T07:47:40Z","2023-03-16T19:43:39Z","39281" +"*CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ*",".{0,1000}CVE\-2023\-46604\-RCE\-Reverse\-Shell\-Apache\-ActiveMQ.{0,1000}","offensive_tool_keyword","POC","Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)","T1190 - T1059 - T1071 - T1105 - T1041","TA0001 - TA0002 - TA0009 - TA0011 - TA0010","N/A","N/A","Exploitation tool","https://github.com/SaumyajeetDas/CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ","1","1","N/A","N/A","9","2","114","39","2024-01-20T16:59:23Z","2023-11-03T22:06:09Z","39282" +"*CVE-2024-1086-1.0.0.zip*",".{0,1000}CVE\-2024\-1086\-1\.0\.0\.zip.{0,1000}","offensive_tool_keyword","POC","local privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6","T1068 - T1548.002","TA0004","N/A","N/A","Privilege Escalation","https://github.com/Notselwyn/CVE-2024-1086","1","1","#linux","CVE-2024-1086 POC","10","10","2357","314","2024-04-17T16:09:54Z","2024-03-20T21:16:41Z","39284" +"*CVE-2024-22274-RCE.py*",".{0,1000}CVE\-2024\-22274\-RCE\.py.{0,1000}","offensive_tool_keyword","POC","PoC - Authenticated Remote Code Execution in VMware vCenter Server (CVE-2024-22274 Exploit)","T1213 - T1059 - T1056 - T1078 - T1578","TA0001 - TA0002 - TA0008 - TA0009","N/A","N/A","Lateral Movement","https://github.com/l0n3m4n/CVE-2024-22274-RCE","1","1","N/A","N/A","10","1","42","8","2024-07-16T23:22:14Z","2024-07-15T07:26:59Z","39285" +"*CVE-2024-49138-POC.exe*",".{0,1000}CVE\-2024\-49138\-POC\.exe.{0,1000}","offensive_tool_keyword","POC","Windows Privilege escalation POC exploitation for CVE-2024-49138","T1068 - T1058 - T1203","TA0004","N/A","N/A","Privilege Escalation","https://github.com/emdnaia/CVE-2024-49138-POC","1","1","N/A","N/A","9","1","1","0","2025-01-15T01:01:21Z","2025-01-15T02:11:49Z","39286" +"*cvescanner.py*",".{0,1000}cvescanner\.py.{0,1000}","offensive_tool_keyword","RedTeam_toolkit","Red Team Toolkit is an Open-Source Django Offensive Web-App which is keeping the useful offensive tools used in the red-teaming together","T1083 - T1065 - T1204 - T1087 - T1203","TA0007 - TA0005 - TA0001","N/A","N/A","Reconnaissance","https://github.com/signorrayan/RedTeam_toolkit","1","1","N/A","N/A","N/A","6","561","121","2025-03-28T06:59:25Z","2021-08-18T08:58:14Z","39288" +"*cyberark/ACLight*",".{0,1000}cyberark\/ACLight.{0,1000}","offensive_tool_keyword","ACLight","A tool for advanced discovery of Privileged Accounts - including Shadow Admins.","T1087 - T1003 - T1208","TA0001 - TA0006 - TA0008","N/A","N/A","Discovery","https://github.com/cyberark/ACLight","1","1","N/A","AD Enumeration","7","9","801","146","2019-09-09T06:48:45Z","2017-05-17T09:29:41Z","39291" +"*cyberark/kubesploit*",".{0,1000}cyberark\/kubesploit.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","39292" +"*cyberark/PipeViewer*",".{0,1000}cyberark\/PipeViewer.{0,1000}","offensive_tool_keyword","PipeViewer ","A tool that shows detailed information about named pipes in Windows","T1022.002 - T1056.002","TA0005 - TA0009","N/A","N/A","discovery","https://github.com/cyberark/PipeViewer","1","1","N/A","N/A","5","7","620","55","2024-11-15T09:55:35Z","2022-12-22T12:35:34Z","39293" +"*cybersectroll/SharpPersistSD*",".{0,1000}cybersectroll\/SharpPersistSD.{0,1000}","offensive_tool_keyword","SharpPersistSD","A Post-Compromise granular .NET library to embed persistency to persistency by abusing Security Descriptors of remote machines","T1547 - T1053 - T1027 - T1028 - T1112","TA0003 - TA0008","N/A","N/A","Persistence","https://github.com/cybersectroll/SharpPersistSD","1","1","N/A","N/A","10","1","87","12","2024-05-15T14:55:14Z","2024-05-13T15:11:12Z","39316" +"*cyclone.hashesorg.hashkiller.combined*",".{0,1000}cyclone\.hashesorg\.hashkiller\.combined.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","39317" +"*CykuTW/tsh-go*",".{0,1000}CykuTW\/tsh\-go.{0,1000}","offensive_tool_keyword","tsh-go","Tiny SHell Go - An open-source backdoor written in Go","T1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009","TA0003 - TA0005 - TA0011 - TA0010","N/A","N/A","Persistence","https://github.com/CykuTW/tsh-go","1","1","N/A","N/A","10","2","161","16","2024-08-29T02:59:37Z","2022-06-13T16:25:30Z","39318" +"*cylance/SMBTrap*",".{0,1000}cylance\/SMBTrap.{0,1000}","offensive_tool_keyword","SMBTrap","tool capturing authentication attempts and performing man-in-the-middle (MitM) attacks leveraging SMB services","T1071.001 - T1557.001 - T1040 - T1070.001 - T1205.001 - T1185","TA0006 - TA0008 - TA0011 - TA0005","N/A","ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/cylance/SMBTrap","1","1","N/A","N/A","8","1","84","38","2015-06-02T17:22:48Z","2015-04-13T07:08:01Z","39319" +"*cyllective/nimproxydll*",".{0,1000}cyllective\/nimproxydll.{0,1000}","offensive_tool_keyword","nimproxydll","A Docker container for byt3bl33d3r/NimDllSideload - DLL sideloading/proxying","T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/cyllective/nimproxydll","1","1","N/A","N/A","9","1","10","0","2024-05-26T17:34:01Z","2024-03-15T15:15:45Z","39320" +"*D00MFist/Mystikal*",".{0,1000}D00MFist\/Mystikal.{0,1000}","offensive_tool_keyword","Mystikal","macOS Initial Access Payload Generator","T1059.005 - T1204.002 - T1566.001","TA0002 - TA0001","N/A","N/A","Exploitation tool","https://github.com/D00MFist/Mystikal","1","1","N/A","N/A","9","4","305","39","2024-01-10T15:48:12Z","2021-05-03T14:46:16Z","39334" +"*D00Movenok/HTMLSmuggler*",".{0,1000}D00Movenok\/HTMLSmuggler.{0,1000}","offensive_tool_keyword","HTMLSmuggler","HTML Smuggling generator&obfuscator for your Red Team operations","T1564.001 - T1027 - T1566","TA0005","N/A","N/A","Phishing","https://github.com/D00Movenok/HTMLSmuggler","1","1","N/A","N/A","10","2","162","19","2024-02-27T23:03:55Z","2023-07-02T08:10:59Z","39335" +"*D1rkInject.cpp*",".{0,1000}D1rkInject\.cpp.{0,1000}","offensive_tool_keyword","D1rkInject","Threadless injection that loads a module into the target process and stomps it and reverting back memory protections and original memory state","T1055 - T1055.012 - T1055.002 - T1574.002","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/D1rkInject","1","1","N/A","N/A","9","2","177","32","2023-08-02T02:45:46Z","2023-08-02T02:13:55Z","39488" +"*D1rkInject.exe*",".{0,1000}D1rkInject\.exe.{0,1000}","offensive_tool_keyword","D1rkInject","Threadless injection that loads a module into the target process and stomps it and reverting back memory protections and original memory state","T1055 - T1055.012 - T1055.002 - T1574.002","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/D1rkInject","1","1","N/A","N/A","9","2","177","32","2023-08-02T02:45:46Z","2023-08-02T02:13:55Z","39489" +"*D1rkInject.iobj*",".{0,1000}D1rkInject\.iobj.{0,1000}","offensive_tool_keyword","D1rkInject","Threadless injection that loads a module into the target process and stomps it and reverting back memory protections and original memory state","T1055 - T1055.012 - T1055.002 - T1574.002","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/D1rkInject","1","1","N/A","N/A","9","2","177","32","2023-08-02T02:45:46Z","2023-08-02T02:13:55Z","39490" +"*D1rkInject.log*",".{0,1000}D1rkInject\.log.{0,1000}","offensive_tool_keyword","D1rkInject","Threadless injection that loads a module into the target process and stomps it and reverting back memory protections and original memory state","T1055 - T1055.012 - T1055.002 - T1574.002","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/D1rkInject","1","1","#logfile","N/A","9","2","177","32","2023-08-02T02:45:46Z","2023-08-02T02:13:55Z","39491" +"*D1rkInject.sln*",".{0,1000}D1rkInject\.sln.{0,1000}","offensive_tool_keyword","D1rkInject","Threadless injection that loads a module into the target process and stomps it and reverting back memory protections and original memory state","T1055 - T1055.012 - T1055.002 - T1574.002","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/D1rkInject","1","1","N/A","N/A","9","2","177","32","2023-08-02T02:45:46Z","2023-08-02T02:13:55Z","39492" +"*D1rkInject.vcxproj*",".{0,1000}D1rkInject\.vcxproj.{0,1000}","offensive_tool_keyword","D1rkInject","Threadless injection that loads a module into the target process and stomps it and reverting back memory protections and original memory state","T1055 - T1055.012 - T1055.002 - T1574.002","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/D1rkInject","1","1","N/A","N/A","9","2","177","32","2023-08-02T02:45:46Z","2023-08-02T02:13:55Z","39493" +"*D1rkInject-main*",".{0,1000}D1rkInject\-main.{0,1000}","offensive_tool_keyword","D1rkInject","Threadless injection that loads a module into the target process and stomps it and reverting back memory protections and original memory state","T1055 - T1055.012 - T1055.002 - T1574.002","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/D1rkInject","1","1","N/A","N/A","9","2","177","32","2023-08-02T02:45:46Z","2023-08-02T02:13:55Z","39494" +"*d3ckx1/Crack-allDBs*",".{0,1000}d3ckx1\/Crack\-allDBs.{0,1000}","offensive_tool_keyword","Crack-allDBs","bruteforce script for various DB","T1110 - T1110.002 - T1210","TA0006 - TA0001","N/A","N/A","Exploitation tool","https://github.com/d3ckx1/Crack-allDBs","1","1","N/A","N/A","8","1","54","18","2021-04-08T06:17:31Z","2021-04-07T11:17:00Z","39624" +"*D3m0n1z3dShell-main*",".{0,1000}D3m0n1z3dShell\-main.{0,1000}","offensive_tool_keyword","D3m0n1z3dShell","Demonized Shell is an Advanced Tool for persistence in linux","T1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037","TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Persistence","https://github.com/MatheuZSecurity/D3m0n1z3dShell","1","1","#linux","N/A","10","4","373","54","2025-01-05T13:56:51Z","2023-05-30T02:30:47Z","39642" +"*D4stiny/ForkPlayground*",".{0,1000}D4stiny\/ForkPlayground.{0,1000}","offensive_tool_keyword","ForkPlayground","proof-of-concept of Process Forking.","T1055 - T1003","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/D4stiny/ForkPlayground","1","1","N/A","N/A","7","3","226","33","2021-11-29T21:42:43Z","2021-11-26T04:21:46Z","39706" +"*d75itpgjjfe2ys2qivqplbvmw3yyx7o5e4ppt2esit2lluhngulz4hqd.onion*",".{0,1000}d75itpgjjfe2ys2qivqplbvmw3yyx7o5e4ppt2esit2lluhngulz4hqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","39872" +"*daem0nc0re/PrivFu*",".{0,1000}daem0nc0re\/PrivFu.{0,1000}","offensive_tool_keyword","PrivFu","Kernel mode WinDbg extension and PoCs for token privilege investigation.","T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001","TA0007 - TA0008 - TA0002 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","40097" +"*daem0nc0re/VectorKernel*",".{0,1000}daem0nc0re\/VectorKernel.{0,1000}","offensive_tool_keyword","VectorKernel","PoCs for Kernelmode rootkit techniques research.","T1543 - T1055 - T1134 - T1564 - T1070 - T1057 - T1574 - T1562 - T1082 - T1518","TA0003 - TA0005 - TA0004 - TA0008 - TA0007","N/A","N/A","Exploitation tool","https://github.com/daem0nc0re/VectorKernel/","1","1","N/A","N/A","10","4","367","60","2025-01-21T08:22:42Z","2023-11-23T12:36:31Z","40098" +"*dafthack/DomainPasswordSpray*",".{0,1000}dafthack\/DomainPasswordSpray.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","1","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","40105" +"*dafthack/GraphRunner*",".{0,1000}dafthack\/GraphRunner.{0,1000}","offensive_tool_keyword","GraphRunner","A Post-exploitation Toolset for Interacting with the Microsoft Graph API","T1059.007 - T1087.001 - T1078.001 - T1585.001 - T1071.001","TA0002 - TA0003 - TA0008 - TA0011","N/A","N/A","Exploitation tool","https://github.com/dafthack/GraphRunner","1","1","N/A","N/A","10","10","1082","127","2024-11-07T04:40:34Z","2023-08-15T17:19:11Z","40106" +"*dafthack/HostRecon*",".{0,1000}dafthack\/HostRecon.{0,1000}","offensive_tool_keyword","HostRecon","Invoke-HostRecon runs a number of checks on a system to help provide situational awareness to a penetration tester during the reconnaissance phase of an engagement. It gathers information about the local system. users. and domain information. It does not use any 'net. 'ipconfig. 'whoami. 'netstat. or other system commands to help avoid detection.","T1082 - T1087 - T1033","TA0001 - TA0007 - ","N/A","N/A","Discovery","https://github.com/dafthack/HostRecon","1","1","N/A","N/A","N/A","5","446","120","2017-10-03T13:25:06Z","2017-03-28T14:53:21Z","40107" +"*dafthack/MailSniper*",".{0,1000}dafthack\/MailSniper.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","40108" +"*dafthack/MFASweep*",".{0,1000}dafthack\/MFASweep.{0,1000}","offensive_tool_keyword","MFASweep","A tool for checking if MFA is enabled on multiple Microsoft Services","T1595 - T1595.002 - T1078.003 - T1621","TA0006 - TA0009","N/A","N/A","Exploitation tool","https://github.com/dafthack/MFASweep","1","1","N/A","N/A","9","10","1484","203","2025-03-04T20:36:41Z","2020-09-22T16:25:03Z","40109" +"*dafthack/RDPSpray*",".{0,1000}dafthack\/RDPSpray.{0,1000}","offensive_tool_keyword","RDPassSpray","Python3 tool to perform password spraying using RDP","T1110.003 - T1059.006 - T1076.001","TA0001 - TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/xFreed0m/RDPassSpray","1","1","N/A","N/A","10","7","648","244","2023-08-17T15:09:50Z","2019-06-05T17:10:42Z","40110" +"*dahvidschloss/PILOT*",".{0,1000}dahvidschloss\/PILOT.{0,1000}","offensive_tool_keyword","PILOT","Pilot is a simplified system designed for the stealthy transfer of files across networks using ICMP","T1048.001 - T1573.001 - T1020","TA0010 - TA0002 - TA0009","N/A","N/A","Data Exfiltration","https://github.com/dahvidschloss/PILOT","1","1","N/A","N/A","9","1","79","7","2024-04-16T18:24:44Z","2024-04-03T15:04:33Z","40112" +"*DallasFR/Cobalt-Clip*",".{0,1000}DallasFR\/Cobalt\-Clip.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike addons to interact with clipboard","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DallasFR/Cobalt-Clip","1","1","N/A","N/A","10","","N/A","","","","40113" +"*DallasFR/WinShellcode*",".{0,1000}DallasFR\/WinShellcode.{0,1000}","offensive_tool_keyword","WinShellcode","It's a C code project created in Visual Studio that helps you generate shellcode from your C code.","T1059.001 - T1059.003 - T1059.005 - T1059.007 - T1059.004 - T1059.006 - T1218 - T1027.001 - T1564.003 - T1027","TA0002 - TA0006","N/A","N/A","Exploitation tool","https://github.com/DallasFR/WinShellcode","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","40114" +"*DAMP-master.zip",".{0,1000}DAMP\-master\.zip","offensive_tool_keyword","DAMP","The Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification.","T1222 - T1222.002 - T1548 - T1548.002","TA0005 ","N/A","N/A","Persistence","https://github.com/HarmJ0y/DAMP","1","1","N/A","N/A","10","4","378","79","2019-07-25T21:18:37Z","2018-04-06T22:13:58Z","40122" +"*DancingRightToLeft.py*",".{0,1000}DancingRightToLeft\.py.{0,1000}","offensive_tool_keyword","phishing-HTML-linter","Phishing and Social-Engineering related scripts","T1566.001 - T1056.001","TA0040 - TA0001","N/A","N/A","Phishing","https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing","1","1","N/A","N/A","10","10","2689","527","2023-06-27T19:16:49Z","2018-02-02T21:24:03Z","40123" +"*danielbohannon/Invoke-Obfuscation*",".{0,1000}danielbohannon\/Invoke\-Obfuscation.{0,1000}","offensive_tool_keyword","Invoke-Obfuscation","Invoke-Obfuscation is a PowerShell v2.0+ compatible PowerShell command and script obfuscator.","T1027 - T1059.001 - T1564.003","TA0005 - TA0002","N/A","Oilrig - Dispossessor","Defense Evasion","https://github.com/danielbohannon/Invoke-Obfuscation","1","1","N/A","N/A","10","10","3935","782","2023-08-10T23:49:06Z","2016-09-25T03:38:02Z","40124" +"*danielmiessler/SecLists*",".{0,1000}danielmiessler\/SecLists.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","40125" +"*danielmiessler/SecLists.git*",".{0,1000}danielmiessler\/SecLists\.git.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","40126" +"*danilovazb/BabyShark*",".{0,1000}danilovazb\/BabyShark.{0,1000}","offensive_tool_keyword","BabyShark","This is a basic C2 generic server written in Python and Flask.","T1547.001 - T1059.003 - T1132.001 - T1140 - T1083 - T1070.004 - T1105 - T1056.001 - T1057 - T1012 - T1053.005 - T1218.005 - T1082 - T1016 - T1033","TA0006 - TA0011 - TA0040","N/A","Kimsuky","C2","https://github.com/UnkL4b/BabyShark","1","1","N/A","N/A","10","10","189","30","2021-07-03T00:18:18Z","2020-06-02T12:27:20Z","40127" +"*DanMcInerney/icebreaker*",".{0,1000}DanMcInerney\/icebreaker.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","40129" +"*DanMcInerney/net-creds*",".{0,1000}DanMcInerney\/net\-creds.{0,1000}","offensive_tool_keyword","net-creds","Thoroughly sniff passwords and hashes from an interface or pcap file. Concatenates fragmented packets and does not rely on ports for service identification.","T1040 - T1039 - T1036 - T1003","TA0006 - TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/DanMcInerney/net-creds","1","1","N/A","N/A","10","10","1746","442","2023-11-02T10:46:03Z","2015-01-07T18:47:46Z","40130" +"*danti1988/adcshunter*",".{0,1000}danti1988\/adcshunter.{0,1000}","offensive_tool_keyword","adcshunter","Uses rpcdump to locate the ADCS server and identify if ESC8 is vulnerable from unauthenticated perspective.","T1018 - T1087 - T1046 - T1201 - T1595","TA0007 - TA0043","N/A","N/A","Discovery","https://github.com/danti1988/adcshunter","1","1","N/A","N/A","7","1","80","7","2024-09-13T12:50:50Z","2023-12-14T14:31:05Z","40132" +"*daphne-main.zip*",".{0,1000}daphne\-main\.zip.{0,1000}","offensive_tool_keyword","daphne","evade auditd by tampering via ptrace","T1054.004 - T1012 - T1057","TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/codewhitesec/daphne","1","1","N/A","N/A","8","1","17","3","2023-08-03T08:31:40Z","2023-07-31T11:57:29Z","40133" +"*dark24zz36xm4y2phwe7yvnkkkkhxionhfrwp67awpb3r3bdcneivoqd.onion*",".{0,1000}dark24zz36xm4y2phwe7yvnkkkkhxionhfrwp67awpb3r3bdcneivoqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","40136" +"*darkarmour.py*",".{0,1000}darkarmour\.py.{0,1000}","offensive_tool_keyword","darkarmour","Store and execute an encrypted windows binary from inside memorywithout a single bit touching disk.","T1055.012 - T1027 - T1564.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/bats3c/darkarmour","1","1","N/A","N/A","10","8","773","122","2020-04-13T10:56:23Z","2020-04-06T20:48:20Z","40138" +"*darkarmour-master*",".{0,1000}darkarmour\-master.{0,1000}","offensive_tool_keyword","darkarmour","Store and execute an encrypted windows binary from inside memorywithout a single bit touching disk.","T1055.012 - T1027 - T1564.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/bats3c/darkarmour","1","1","N/A","N/A","10","8","773","122","2020-04-13T10:56:23Z","2020-04-06T20:48:20Z","40139" +"*DarkCoderSc/SharpShellPipe*",".{0,1000}DarkCoderSc\/SharpShellPipe.{0,1000}","offensive_tool_keyword","SharpShellPipe","interactive remote shell access via named pipes and the SMB protocol.","T1056.002 - T1021.002 - T1059.001","TA0005 - TA0009 - TA0002","N/A","N/A","Lateral Movement","https://github.com/DarkCoderSc/SharpShellPipe","1","1","N/A","N/A","8","2","118","14","2025-02-21T12:33:43Z","2023-08-25T15:18:30Z","40140" +"*DarkHotel C2*",".{0,1000}DarkHotel\sC2.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","40142" +"*DarkLoadLibrary-maser*",".{0,1000}DarkLoadLibrary\-maser.{0,1000}","offensive_tool_keyword","DarkLoadLibrary","LoadLibrary for offensive operations","T1071.001 - T1055.002 - T1055.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bats3c/DarkLoadLibrary","1","1","N/A","N/A","10","10","1133","207","2021-10-22T07:27:58Z","2021-06-17T08:33:47Z","40145" +"*darkr4y/geacon*",".{0,1000}darkr4y\/geacon.{0,1000}","offensive_tool_keyword","cobaltstrike","Practice Go programming and implement CobaltStrike's Beacon in Go","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/darkr4y/geacon","1","1","N/A","N/A","10","10","1189","206","2020-10-02T10:34:37Z","2020-02-14T14:01:29Z","40146" +"*DarkRCovery.exe*",".{0,1000}DarkRCovery\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","40147" +"*DarkRCovery.exe*",".{0,1000}DarkRCovery\.exe.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","40148" +"*Darkside-master.zip*",".{0,1000}Darkside\-master\.zip.{0,1000}","offensive_tool_keyword","Darkside","C# AV/EDR Killer using less-known driver (BYOVD)","T1547.006 - T1055 - T1562.001","TA0005 - TA0003 - TA0004 ","N/A","N/A","Defense Evasion","https://github.com/ph4nt0mbyt3/Darkside","1","1","N/A","N/A","10","2","175","34","2023-11-10T16:01:21Z","2023-11-10T15:34:20Z","40150" +"*DarkWidow-main*",".{0,1000}DarkWidow\-main.{0,1000}","offensive_tool_keyword","DarkWidow","Indirect Dynamic Syscall SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a sacrificial Process as target process + (ACG+BlockDll) mitigation policy on spawned process + PPID spoofing (Emotet method) + Api resolving from TIB + API hashing","T1055 - T1055.012 - T1055.002 - T1098 - T1027 - T1027.001 - T1070.004 - T1036 - T1134 - T1140","TA0005 - TA0003 - TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/reveng007/DarkWidow","1","1","N/A","N/A","10","7","671","91","2025-03-12T21:58:25Z","2023-07-24T13:59:16Z","40152" +"*dashlane2john.py*",".{0,1000}dashlane2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","40159" +"*data/ipwn*",".{0,1000}data\/ipwn.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","40167" +"*data/payloads/stager.ps1*",".{0,1000}data\/payloads\/stager\.ps1.{0,1000}","offensive_tool_keyword","ThunderShell","ThunderShell is a C# RAT that communicates via HTTP requests. All the network traffic is encrypted using a second layer of RC4 to avoid SSL interception and defeat network detection on the target system. RC4 is a weak cipher and is used to help obfuscate the traffic. HTTPS options should be used to provide integrity and strong encryption.","T1021.002 - T1573.002 - T1001.003","TA0008 - TA0011 - TA0040","N/A","LockBit","C2","https://github.com/Mr-Un1k0d3r/ThunderShell","1","1","N/A","N/A","10","10","779","223","2023-03-29T21:57:08Z","2017-09-12T01:11:29Z","40168" +"*data/shell/backdoors*",".{0,1000}data\/shell\/backdoors.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","40169" +"*data/shell/stagers*",".{0,1000}data\/shell\/stagers.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","40170" +"*data/wordlist_256.txt*",".{0,1000}data\/wordlist_256\.txt.{0,1000}","offensive_tool_keyword","dnscat","This tool is designed to create an encrypted command-and-control (C&C) channel over the DNS protocol","T1071.004 - T1102 - T1071.001","TA0002 - TA0003 - TA0008","N/A","EMBER BEAR","C2","https://github.com/iagox86/dnscat2","1","1","#linux","N/A","10","10","3566","618","2024-03-14T11:17:49Z","2013-01-04T23:15:55Z","40171" +"*data/wordlists*",".{0,1000}data\/wordlists.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","40172" +"*DataBouncing-main.zip*",".{0,1000}DataBouncing\-main\.zip.{0,1000}","offensive_tool_keyword","DataBouncing","Data Bouncing is a technique for transmitting data between two endpoints using DNS lookups and HTTP header manipulation","T1048 - T1041","TA0010","N/A","N/A","Data Exfiltration","https://github.com/Unit-259/DataBouncing","1","1","N/A","N/A","9","1","15","0","2025-03-12T07:34:04Z","2025-03-12T06:58:51Z","40177" +"*DataSploit*",".{0,1000}DataSploit.{0,1000}","offensive_tool_keyword","datasploit","Performs OSINT on a domain / email / username / phone and find out information from different sources","T1247 - T1593 - T1271 - T1110 - T1122 - T1123","TA0002 - TA0009","N/A","N/A","Reconnaissance","https://github.com/dvopsway/datasploit","1","1","N/A","N/A","N/A","3","279","674","2022-12-04T16:02:57Z","2016-05-26T03:34:43Z","40180" +"*DavidXanatos/DiskCryptor*",".{0,1000}DavidXanatos\/DiskCryptor.{0,1000}","offensive_tool_keyword","DiskCryptor","DiskCryptor is an open source encryption solution that offers encryption of all disk partitions including system partitions","T1486 ","TA0040","N/A","N/A","Ransomware","https://github.com/DavidXanatos/DiskCryptor","1","1","N/A","N/A","10","5","499","108","2024-07-03T10:05:01Z","2019-04-20T14:51:18Z","40182" +"*DavRelayUp.csproj*",".{0,1000}DavRelayUp\.csproj.{0,1000}","offensive_tool_keyword","DavRelayUp","DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced","T1078 - T1078.004 - T1068","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/ShorSec/DavRelayUp","1","1","N/A","N/A","9","6","542","81","2023-06-05T09:17:06Z","2023-06-05T07:49:39Z","40183" +"*DavRelayUp.exe*",".{0,1000}DavRelayUp\.exe.{0,1000}","offensive_tool_keyword","DavRelayUp","DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced","T1078 - T1078.004 - T1068","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/ShorSec/DavRelayUp","1","1","N/A","N/A","9","6","542","81","2023-06-05T09:17:06Z","2023-06-05T07:49:39Z","40184" +"*DavRelayUp.sln*",".{0,1000}DavRelayUp\.sln.{0,1000}","offensive_tool_keyword","DavRelayUp","DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced","T1078 - T1078.004 - T1068","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/ShorSec/DavRelayUp","1","1","N/A","N/A","9","6","542","81","2023-06-05T09:17:06Z","2023-06-05T07:49:39Z","40185" +"*DavRelayUp-master*",".{0,1000}DavRelayUp\-master.{0,1000}","offensive_tool_keyword","DavRelayUp","DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced","T1078 - T1078.004 - T1068","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/ShorSec/DavRelayUp","1","1","N/A","N/A","9","6","542","81","2023-06-05T09:17:06Z","2023-06-05T07:49:39Z","40186" +"*davtdavm734bl4hkr3sr4dvfzpdzuzei2zrcor4vte4a3xuok2rxcmyd.onion*",".{0,1000}davtdavm734bl4hkr3sr4dvfzpdzuzei2zrcor4vte4a3xuok2rxcmyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","40187" +"*Daybr4ak/C2ReverseProxy*",".{0,1000}Daybr4ak\/C2ReverseProxy.{0,1000}","offensive_tool_keyword","C2ReverseProxy","ReverseProxy C2 - Bring CS online without going offline","T1090 - T1090.002 - T1573 - T1573.001 - T1573.002","TA0011","N/A","N/A","C2","https://github.com/Daybr4ak/C2ReverseProxy","1","1","N/A","N/A","10","10","486","56","2023-04-26T13:16:26Z","2020-01-16T05:43:35Z","40188" +"*dazzleUP.cna*",".{0,1000}dazzleUP\.cna.{0,1000}","offensive_tool_keyword","dazzleUP","A tool that detects the privilege escalation vulnerabilities caused by misconfigurations and missing updates in the Windows operating systems.","T1068 - T1088 - T1210 - T1210.002","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/hlldz/dazzleUP","1","1","N/A","N/A","9","5","490","69","2020-07-23T08:48:43Z","2020-07-21T21:06:46Z","40189" +"*dazzleUP.exe*",".{0,1000}dazzleUP\.exe.{0,1000}","offensive_tool_keyword","dazzleUP","A tool that detects the privilege escalation vulnerabilities caused by misconfigurations and missing updates in the Windows operating systems.","T1068 - T1088 - T1210 - T1210.002","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/hlldz/dazzleUP","1","1","N/A","N/A","9","5","490","69","2020-07-23T08:48:43Z","2020-07-21T21:06:46Z","40190" +"*dazzleUP.sln*",".{0,1000}dazzleUP\.sln.{0,1000}","offensive_tool_keyword","dazzleUP","A tool that detects the privilege escalation vulnerabilities caused by misconfigurations and missing updates in the Windows operating systems.","T1068 - T1088 - T1210 - T1210.002","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/hlldz/dazzleUP","1","1","N/A","N/A","9","5","490","69","2020-07-23T08:48:43Z","2020-07-21T21:06:46Z","40191" +"*dazzleUP.vcxproj*",".{0,1000}dazzleUP\.vcxproj.{0,1000}","offensive_tool_keyword","dazzleUP","A tool that detects the privilege escalation vulnerabilities caused by misconfigurations and missing updates in the Windows operating systems.","T1068 - T1088 - T1210 - T1210.002","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/hlldz/dazzleUP","1","1","N/A","N/A","9","5","490","69","2020-07-23T08:48:43Z","2020-07-21T21:06:46Z","40192" +"*dazzleUP.x32.exe*",".{0,1000}dazzleUP\.x32\.exe.{0,1000}","offensive_tool_keyword","dazzleUP","A tool that detects the privilege escalation vulnerabilities caused by misconfigurations and missing updates in the Windows operating systems.","T1068 - T1088 - T1210 - T1210.002","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/hlldz/dazzleUP","1","1","N/A","N/A","9","5","490","69","2020-07-23T08:48:43Z","2020-07-21T21:06:46Z","40193" +"*dazzleUP.x64.exe*",".{0,1000}dazzleUP\.x64\.exe.{0,1000}","offensive_tool_keyword","dazzleUP","A tool that detects the privilege escalation vulnerabilities caused by misconfigurations and missing updates in the Windows operating systems.","T1068 - T1088 - T1210 - T1210.002","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/hlldz/dazzleUP","1","1","N/A","N/A","9","5","490","69","2020-07-23T08:48:43Z","2020-07-21T21:06:46Z","40194" +"*dazzleUP_Reflective_DLL*",".{0,1000}dazzleUP_Reflective_DLL.{0,1000}","offensive_tool_keyword","dazzleUP","A tool that detects the privilege escalation vulnerabilities caused by misconfigurations and missing updates in the Windows operating systems.","T1068 - T1088 - T1210 - T1210.002","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/hlldz/dazzleUP","1","1","N/A","N/A","9","5","490","69","2020-07-23T08:48:43Z","2020-07-21T21:06:46Z","40195" +"*dazzleUP-master*",".{0,1000}dazzleUP\-master.{0,1000}","offensive_tool_keyword","dazzleUP","A tool that detects the privilege escalation vulnerabilities caused by misconfigurations and missing updates in the Windows operating systems.","T1068 - T1088 - T1210 - T1210.002","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/hlldz/dazzleUP","1","1","N/A","N/A","9","5","490","69","2020-07-23T08:48:43Z","2020-07-21T21:06:46Z","40196" +"*db2_default_pass.txt*",".{0,1000}db2_default_pass\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","40207" +"*db2_default_user.txt*",".{0,1000}db2_default_user\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","40208" +"*DBC2.git*",".{0,1000}DBC2\.git.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","40267" +"*dbc2_agent.cs*",".{0,1000}dbc2_agent\.cs.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","40268" +"*dbc2_agent.exe*",".{0,1000}dbc2_agent\.exe.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","40269" +"*dbc2Loader.dll*",".{0,1000}dbc2Loader\.dll.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","40270" +"*dbc2Loader.exe*",".{0,1000}dbc2Loader\.exe.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","40271" +"*dbc2Loader.tpl*",".{0,1000}dbc2Loader\.tpl.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","40272" +"*dbc2LoaderWrapperCLR.*",".{0,1000}dbc2LoaderWrapperCLR\..{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","40273" +"*dbc2LoaderWrapperCLR_x64.dll*",".{0,1000}dbc2LoaderWrapperCLR_x64\.dll.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","40274" +"*dbc2LoaderWrapperCLR_x86.dll*",".{0,1000}dbc2LoaderWrapperCLR_x86\.dll.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","40275" +"*DBC2-master.zip*",".{0,1000}DBC2\-master\.zip.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","40276" +"*dbGetNimplant*",".{0,1000}dbGetNimplant.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","40293" +"*dcomexec.py*",".{0,1000}dcomexec\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","40367" +"*dcomhijack.cna*",".{0,1000}dcomhijack\.cna.{0,1000}","offensive_tool_keyword","dcomhijack","Lateral Movement Using DCOM and DLL Hijacking","T1021 - T1021.003 - T1574 - T1574.007 - T1574.002","TA0008 - TA0005 - TA0002","N/A","N/A","Lateral Movement","https://github.com/WKL-Sec/dcomhijack","1","1","N/A","N/A","10","3","290","24","2023-06-18T20:34:03Z","2023-06-17T20:23:24Z","40368" +"*dcomhijack.py*",".{0,1000}dcomhijack\.py.{0,1000}","offensive_tool_keyword","dcomhijack","Lateral Movement Using DCOM and DLL Hijacking","T1021 - T1021.003 - T1574 - T1574.007 - T1574.002","TA0008 - TA0005 - TA0002","N/A","N/A","Lateral Movement","https://github.com/WKL-Sec/dcomhijack","1","1","N/A","N/A","10","3","290","24","2023-06-18T20:34:03Z","2023-06-17T20:23:24Z","40370" +"*dcomhijack-main*",".{0,1000}dcomhijack\-main.{0,1000}","offensive_tool_keyword","dcomhijack","Lateral Movement Using DCOM and DLL Hijacking","T1021 - T1021.003 - T1574 - T1574.007 - T1574.002","TA0008 - TA0005 - TA0002","N/A","N/A","Lateral Movement","https://github.com/WKL-Sec/dcomhijack","1","1","N/A","N/A","10","3","290","24","2023-06-18T20:34:03Z","2023-06-17T20:23:24Z","40371" +"*DCOMPotato-master*",".{0,1000}DCOMPotato\-master.{0,1000}","offensive_tool_keyword","DCOMPotato","Service DCOM Object and SeImpersonatePrivilege abuse.","T1548.002 - T1134.002","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/zcgonvh/DCOMPotato","1","1","N/A","N/A","10","4","356","48","2022-12-09T01:57:53Z","2022-12-08T14:56:13Z","40373" +"*DCOMUploadExec-main.zip*",".{0,1000}DCOMUploadExec\-main\.zip.{0,1000}","offensive_tool_keyword","DCOMUploadExec","DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely","T1021.003 - T1570 - T1105 - T1569.002","TA0008 - TA0011 - TA0002","N/A","N/A","Lateral Movement","https://github.com/deepinstinct/DCOMUploadExec","1","1","N/A","N/A","9","4","357","52","2024-12-13T14:03:12Z","2024-11-13T16:05:29Z","40376" +"*DcRat.7z*",".{0,1000}DcRat\.7z.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","40380" +"*DcRat.exe*",".{0,1000}DcRat\.exe.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","40381" +"*DcRat.zip*",".{0,1000}DcRat\.zip.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","40382" +"*DcRat_png.png*",".{0,1000}DcRat_png\.png.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","40383" +"*DcRat-main.zip*",".{0,1000}DcRat\-main\.zip.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","40386" +"*dcrypt_bartpe.zip*",".{0,1000}dcrypt_bartpe\.zip.{0,1000}","offensive_tool_keyword","DiskCryptor","DiskCryptor is an open source encryption solution that offers encryption of all disk partitions including system partitions","T1486 ","TA0040","N/A","N/A","Ransomware","https://github.com/DavidXanatos/DiskCryptor","1","1","N/A","N/A","10","5","499","108","2024-07-03T10:05:01Z","2019-04-20T14:51:18Z","40389" +"*dcrypt_install.iss*",".{0,1000}dcrypt_install\.iss.{0,1000}","offensive_tool_keyword","DiskCryptor","DiskCryptor is an open source encryption solution that offers encryption of all disk partitions including system partitions","T1486 ","TA0040","N/A","N/A","Ransomware","https://github.com/DavidXanatos/DiskCryptor","1","1","N/A","N/A","10","5","499","108","2024-07-03T10:05:01Z","2019-04-20T14:51:18Z","40390" +"*dcrypt_setup_*.exe*",".{0,1000}dcrypt_setup_.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","DiskCryptor","DiskCryptor is an open source encryption solution that offers encryption of all disk partitions including system partitions","T1486 ","TA0040","N/A","N/A","Ransomware","https://github.com/DavidXanatos/DiskCryptor","1","1","N/A","N/A","10","5","499","108","2024-07-03T10:05:01Z","2019-04-20T14:51:18Z","40391" +"*dcrypt_winpe.zip*",".{0,1000}dcrypt_winpe\.zip.{0,1000}","offensive_tool_keyword","DiskCryptor","DiskCryptor is an open source encryption solution that offers encryption of all disk partitions including system partitions","T1486 ","TA0040","N/A","N/A","Ransomware","https://github.com/DavidXanatos/DiskCryptor","1","1","N/A","N/A","10","5","499","108","2024-07-03T10:05:01Z","2019-04-20T14:51:18Z","40392" +"*dcsync.py*",".{0,1000}dcsync\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","40394" +"*dcsync.py*",".{0,1000}dcsync\.py.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","40395" +"*dcsync@protonmail.com*",".{0,1000}dcsync\@protonmail\.com.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","#email","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","40396" +"*dcsyncattack.py*",".{0,1000}dcsyncattack\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","40399" +"*dcsyncattack.py*",".{0,1000}dcsyncattack\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","40400" +"*dcsyncclient.*",".{0,1000}dcsyncclient\..{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","40401" +"*dcsyncclient.py*",".{0,1000}dcsyncclient\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","40402" +"*dcsyncclient.py*",".{0,1000}dcsyncclient\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","40403" +"*DCSyncer.exe*",".{0,1000}DCSyncer\.exe.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","1","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","40404" +"*DCSyncer-master.zip*",".{0,1000}DCSyncer\-master\.zip.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","1","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","40405" +"*DCSyncer-x64.exe*",".{0,1000}DCSyncer\-x64\.exe.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","1","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","40406" +"*DDSpoof-main*",".{0,1000}DDSpoof\-main.{0,1000}","offensive_tool_keyword","DDSpoof","DDSpoof is a tool that enables DHCP DNS Dynamic Update attacks against Microsoft DHCP servers in AD environments.","T1557 - T1584 - T1203","TA0005 - TA0003 TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/akamai/DDSpoof","1","1","N/A","N/A","9","2","122","13","2024-04-12T22:06:02Z","2023-12-14T06:47:45Z","40495" +"*de.mirrors.cicku.me/blackarch/*/os/*",".{0,1000}de\.mirrors\.cicku\.me\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","40496" +"*deadpotato.exe*",".{0,1000}deadpotato\.exe.{0,1000}","offensive_tool_keyword","DeadPotato","DeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privileges","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","N/A","N/A","Privilege Escalation","https://github.com/lypd0/DeadPotato","1","1","N/A","N/A","10","4","382","45","2024-08-17T06:08:29Z","2024-07-31T01:08:30Z","40530" +"*DeadPotato-NET4.exe*",".{0,1000}DeadPotato\-NET4\.exe.{0,1000}","offensive_tool_keyword","DeadPotato","DeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privileges","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","N/A","N/A","Privilege Escalation","https://github.com/lypd0/DeadPotato","1","1","N/A","N/A","10","4","382","45","2024-08-17T06:08:29Z","2024-07-31T01:08:30Z","40531" +"*deb.torproject.org/torproject.org/*",".{0,1000}deb\.torproject\.org\/torproject\.org\/.{0,1000}","offensive_tool_keyword","tor","used for anonymous communication and web browsing. It is designed to protect users' privacy and freedom by preventing surveillance or traffic analysis. Abused by attacker for defense evasion, contacting C2 and data exfiltration","T1573.002 - T1090.003","TA0011 - TA0010 - TA0005","N/A","Dispossessor - APT28 - APT29 - Leviathan","C2","https://deb.torproject.org/torproject.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","40534" +"*deb.torproject.org/torproject.org/*.asc*",".{0,1000}deb\.torproject\.org\/torproject\.org\/.{0,1000}\.asc.{0,1000}","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","40535" +"*deb.torproject.org-keyring*",".{0,1000}deb\.torproject\.org\-keyring.{0,1000}","offensive_tool_keyword","tor","used for anonymous communication and web browsing. It is designed to protect users' privacy and freedom by preventing surveillance or traffic analysis. Abused by attacker for defense evasion, contacting C2 and data exfiltration","T1573.002 - T1090.003","TA0011 - TA0010 - TA0005","N/A","Dispossessor - APT28 - APT29 - Leviathan","C2","https://deb.torproject.org/torproject.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","40536" +"*debian.org/pkg-security-team/creddump7*",".{0,1000}debian\.org\/pkg\-security\-team\/creddump7.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","40541" +"*DebugAmsi.exe*",".{0,1000}DebugAmsi\.exe.{0,1000}","offensive_tool_keyword","DebugAmsi","DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.","T1562.001 - T1050.005","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/MzHmO/DebugAmsi","1","1","N/A","N/A","10","1","97","22","2023-09-18T17:17:26Z","2023-08-28T07:32:54Z","40543" +"*DebugAmsi.sln*",".{0,1000}DebugAmsi\.sln.{0,1000}","offensive_tool_keyword","DebugAmsi","DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.","T1562.001 - T1050.005","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/MzHmO/DebugAmsi","1","1","N/A","N/A","10","1","97","22","2023-09-18T17:17:26Z","2023-08-28T07:32:54Z","40544" +"*DebugAmsi.vcxproj*",".{0,1000}DebugAmsi\.vcxproj.{0,1000}","offensive_tool_keyword","DebugAmsi","DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.","T1562.001 - T1050.005","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/MzHmO/DebugAmsi","1","1","N/A","N/A","10","1","97","22","2023-09-18T17:17:26Z","2023-08-28T07:32:54Z","40545" +"*DebugAmsi-main*",".{0,1000}DebugAmsi\-main.{0,1000}","offensive_tool_keyword","DebugAmsi","DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.","T1562.001 - T1050.005","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/MzHmO/DebugAmsi","1","1","N/A","N/A","10","1","97","22","2023-09-18T17:17:26Z","2023-08-28T07:32:54Z","40546" +"*DebugAmsix64.exe*",".{0,1000}DebugAmsix64\.exe.{0,1000}","offensive_tool_keyword","DebugAmsi","DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.","T1562.001 - T1050.005","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/MzHmO/DebugAmsi","1","1","N/A","N/A","10","1","97","22","2023-09-18T17:17:26Z","2023-08-28T07:32:54Z","40547" +"*DebugAmsix86.exe*",".{0,1000}DebugAmsix86\.exe.{0,1000}","offensive_tool_keyword","DebugAmsi","DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.","T1562.001 - T1050.005","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/MzHmO/DebugAmsi","1","1","N/A","N/A","10","1","97","22","2023-09-18T17:17:26Z","2023-08-28T07:32:54Z","40548" +"*DebugInjectionVariant.exe*",".{0,1000}DebugInjectionVariant\.exe.{0,1000}","offensive_tool_keyword","PrivFu","get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","KernelWritePoCs","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","40550" +"*DEBUG-preobfuscation.vba*",".{0,1000}DEBUG\-preobfuscation\.vba.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","40551" +"*DebugUpdateProcVariant.exe*",".{0,1000}DebugUpdateProcVariant\.exe.{0,1000}","offensive_tool_keyword","PrivFu","get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","KernelWritePoCs","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","40552" +"*Dec0ne/KrbRelayUp*",".{0,1000}Dec0ne\/KrbRelayUp.{0,1000}","offensive_tool_keyword","KrbRelayUp","a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).","T1558 - T1210","TA0004 - TA0003","N/A","Dispossessor - Back Basta","Privilege Escalation","https://github.com/Dec0ne/KrbRelayUp","1","1","N/A","N/A","10","10","1580","209","2022-08-06T12:23:58Z","2022-04-24T21:33:00Z","40553" +"*Dec0ne/ShadowSpray*",".{0,1000}Dec0ne\/ShadowSpray.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","1","N/A","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","40554" +"*decipher_mremoteng.jar*",".{0,1000}decipher_mremoteng\.jar.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","1","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","40567" +"*DecodeRDPCache.ps1*",".{0,1000}DecodeRDPCache\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","40570" +"*decoder-it/ADCSCoercePotato*",".{0,1000}decoder\-it\/ADCSCoercePotato.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","1","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","40571" +"*decoder-it/KrbRelay-SMBServer*",".{0,1000}decoder\-it\/KrbRelay\-SMBServer.{0,1000}","offensive_tool_keyword","KrbRelay-SMBServer","acts as an SMB server (instead of DCOM) to relay Kerberos AP-REQ to CIFS or HTTP","T1557 - T1021 - T1205 - T1071","TA0006 - TA0008 - TA0010","N/A","Black Basta","Lateral Movement","https://github.com/decoder-it/KrbRelay-SMBServer","1","1","N/A","N/A","9","3","215","26","2024-10-08T14:55:59Z","2024-10-05T12:28:55Z","40572" +"*decoder-it/LocalPotato*",".{0,1000}decoder\-it\/LocalPotato.{0,1000}","offensive_tool_keyword","localpotato","The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.","T1550.002 - T1078.003 - T1005 - T1070.004","TA0004 - TA0006 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/decoder-it/LocalPotato","1","1","N/A","N/A","10","7","691","92","2023-11-07T01:09:08Z","2023-01-04T18:22:29Z","40573" +"*decoder-it/psgetsystem*",".{0,1000}decoder\-it\/psgetsystem.{0,1000}","offensive_tool_keyword","psgetsystem","getsystem via parent process using ps1 & embeded c#","T1134 - T1548","TA0004","N/A","N/A","Privilege Escalation","https://github.com/decoder-it/psgetsystem","1","1","N/A","N/A","10","5","406","88","2023-10-26T07:13:08Z","2018-02-02T11:28:22Z","40574" +"*decoder-it/TokenStealer*",".{0,1000}decoder\-it\/TokenStealer.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","1","N/A","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","40575" +"*decoy_document.xls*",".{0,1000}decoy_document\.xls.{0,1000}","offensive_tool_keyword","Macrome","An Excel Macro Document Reader/Writer for Red Teamers & Analysts. Blog posts describing what this tool actually does can be found https://malware.pizza/2020/05/12/evading-av-with-excel-macros-and-biff8-xls/ and https://malware.pizza/2020/06/19/further-evasion-in-the-forgotten-corners-of-ms-xls/","T1140","TA0005","N/A","N/A","Exploitation tool","https://github.com/michaelweber/Macrome","1","1","N/A","N/A","N/A","6","520","79","2022-02-01T16:26:13Z","2020-05-07T22:44:11Z","40577" +"*decrypt_chrome_password.py*",".{0,1000}decrypt_chrome_password\.py.{0,1000}","offensive_tool_keyword","decrypt-chrome-passwords","A simple program to decrypt chrome password saved on your machine.","T1555.003 - T1112 - T1056.001","TA0006 - TA0009 - TA0040","N/A","N/A","Credential Access","https://github.com/ohyicong/decrypt-chrome-passwords","1","1","N/A","N/A","10","10","966","211","2024-07-31T14:08:55Z","2020-12-28T15:11:12Z","40580" +"*decrypt_chrome_v20_cookie.py*",".{0,1000}decrypt_chrome_v20_cookie\.py.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","1","N/A","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","40581" +"*decrypt-chrome-passwords-main*",".{0,1000}decrypt\-chrome\-passwords\-main.{0,1000}","offensive_tool_keyword","decrypt-chrome-passwords","A simple program to decrypt chrome password saved on your machine.","T1555.003 - T1112 - T1056.001","TA0006 - TA0009 - TA0040","N/A","N/A","Credential Access","https://github.com/ohyicong/decrypt-chrome-passwords","1","1","N/A","N/A","10","10","966","211","2024-07-31T14:08:55Z","2020-12-28T15:11:12Z","40582" +"*DecryptNextCharacterWinSCP*",".{0,1000}DecryptNextCharacterWinSCP.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","40585" +"*Decrypt-RDCMan.ps1*",".{0,1000}Decrypt\-RDCMan\.ps1.{0,1000}","offensive_tool_keyword","DecryptRDCManager","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/mez-0/DecryptRDCManager","1","1","N/A","N/A","8","1","73","7","2020-09-29T10:12:58Z","2020-09-29T08:53:46Z","40587" +"*DecryptRDCManager.exe*",".{0,1000}DecryptRDCManager\.exe.{0,1000}","offensive_tool_keyword","DecryptRDCManager","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/mez-0/DecryptRDCManager","1","1","N/A","N/A","8","1","73","7","2020-09-29T10:12:58Z","2020-09-29T08:53:46Z","40588" +"*DecryptTeamViewer-master.zip*",".{0,1000}DecryptTeamViewer\-master\.zip.{0,1000}","offensive_tool_keyword","DecryptTeamViewer","Enumerate and decrypt TeamViewer credentials from Windows registry","T1552.001 - T1003 - T1119 - T1012","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/V1V1/DecryptTeamViewer","1","1","N/A","N/A","7","3","241","62","2021-12-05T09:19:56Z","2020-02-07T07:50:47Z","40591" +"*decrypttozxybarc.dconnect.eu*",".{0,1000}decrypttozxybarc\.dconnect\.eu.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","40592" +"*decrypttozxybarc.onion*",".{0,1000}decrypttozxybarc\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","40593" +"*decrypttozxybarc.onion.cab*",".{0,1000}decrypttozxybarc\.onion\.cab.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","40594" +"*decrypttozxybarc.onion.link*",".{0,1000}decrypttozxybarc\.onion\.link.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","40595" +"*decrypttozxybarc.onion.to*",".{0,1000}decrypttozxybarc\.onion\.to.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","40596" +"*decrypttozxybarc.tor2web.org*",".{0,1000}decrypttozxybarc\.tor2web\.org.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","40597" +"*DecryptWinSCPPassword*",".{0,1000}DecryptWinSCPPassword.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","40599" +"*DEDSEC-RANSOMWARE.py*",".{0,1000}DEDSEC\-RANSOMWARE\.py.{0,1000}","offensive_tool_keyword","DEDSEC-RANSOMWARE","dedsec ransomware","T1486 - T1489 - T1490 - T1495 - T1488 - T1482","TA0040 - TA0043 - TA0042 - TA0009 - TA0010","N/A","N/A","Ransomware","https://github.com/xelroth/DEDSEC-RANSOMWARE","1","1","N/A","N/A","10","1","7","1","2024-05-17T11:12:23Z","2024-05-17T10:34:03Z","40609" +"*DeEpinGh0st/Erebus*",".{0,1000}DeEpinGh0st\/Erebus.{0,1000}","offensive_tool_keyword","cobaltstrike","Erebus CobaltStrike post penetration testing plugin","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DeEpinGh0st/Erebus","1","1","N/A","N/A","10","10","1518","221","2021-10-28T06:20:51Z","2019-09-26T09:32:00Z","40613" +"*deepinstinct/ContainYourself*",".{0,1000}deepinstinct\/ContainYourself.{0,1000}","offensive_tool_keyword","ContainYourself","Abuses the Windows containers framework to bypass EDRs.","T1562 - T1562.004 - T1212 - T1212.002 - T1055 - T1055.015","TA0005","N/A","N/A","Defense Evasion","https://github.com/deepinstinct/ContainYourself","1","1","N/A","N/A","10","4","310","39","2023-08-31T07:26:22Z","2023-07-12T14:47:24Z","40614" +"*deepinstinct/DCOMUploadExec*",".{0,1000}deepinstinct\/DCOMUploadExec.{0,1000}","offensive_tool_keyword","DCOMUploadExec","DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely","T1021.003 - T1570 - T1105 - T1569.002","TA0008 - TA0011 - TA0002","N/A","N/A","Lateral Movement","https://github.com/deepinstinct/DCOMUploadExec","1","1","N/A","N/A","9","4","357","52","2024-12-13T14:03:12Z","2024-11-13T16:05:29Z","40615" +"*deepinstinct/Dirty-Vanity*",".{0,1000}deepinstinct\/Dirty\-Vanity.{0,1000}","offensive_tool_keyword","Dirty-Vanity","injection technique abusing windows fork API to evade EDRs","T1055 - T1562 - T1070 - T1027","TA0005 - TA0006","N/A","N/A","Defense Evasion","https://github.com/deepinstinct/Dirty-Vanity","1","1","N/A","N/A","10","7","633","86","2022-12-23T10:54:10Z","2022-11-24T10:54:00Z","40616" +"*deepinstinct/Lsass-Shtinkering*",".{0,1000}deepinstinct\/Lsass\-Shtinkering.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","1","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","40617" +"*deepinstinct/LsassSilentProcessExit*",".{0,1000}deepinstinct\/LsassSilentProcessExit.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","1","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","40618" +"*deepinstinct/NoFilter*",".{0,1000}deepinstinct\/NoFilter.{0,1000}","offensive_tool_keyword","NoFilter","Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.","T1548 - T1548.002 - T1055 - T1055.004","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/deepinstinct/NoFilter","1","1","N/A","N/A","9","3","298","48","2024-10-29T07:30:35Z","2023-07-30T09:25:38Z","40619" +"*deepinstinct/ShimMe*",".{0,1000}deepinstinct\/ShimMe.{0,1000}","offensive_tool_keyword","ShimMe","Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.","T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070","TA0004 - TA0005 - TA0006 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/deepinstinct/ShimMe","1","1","N/A","N/A","9","2","140","20","2024-10-29T07:33:38Z","2024-08-04T10:03:28Z","40620" +"*deepsound2john.py*",".{0,1000}deepsound2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","40621" +"*default_userpass_for_services_unhash*",".{0,1000}default_userpass_for_services_unhash.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","40635" +"*default_users_for_services_unhash.txt*",".{0,1000}default_users_for_services_unhash\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","40636" +"*DefaultBeaconApi*",".{0,1000}DefaultBeaconApi.{0,1000}","offensive_tool_keyword","cobaltstrike","A .NET Runtime for Cobalt Strike's Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CCob/BOF.NET","1","1","N/A","N/A","10","10","709","105","2024-09-04T17:10:23Z","2020-11-02T20:02:55Z","40637" +"*DefaultCreds-cheat-sheet*",".{0,1000}DefaultCreds\-cheat\-sheet.{0,1000}","offensive_tool_keyword","DefaultCreds-cheat-sheet","One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password","T1110.001 - T1110.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/ihebski/DefaultCreds-cheat-sheet","1","1","N/A","N/A","N/A","10","6048","726","2025-04-15T13:13:19Z","2021-01-01T19:02:36Z","40638" +"*Defeat-Defender.bat*",".{0,1000}Defeat\-Defender\.bat.{0,1000}","offensive_tool_keyword","Defeat-Defender","script to dismantle complete windows defender protection and even bypass tamper protection - Disable Windows-Defender Permanently.","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/swagkarna/Defeat-Defender-V1.2.0","1","1","N/A","N/A","10","10","1530","316","2023-10-20T17:55:09Z","2020-12-10T07:22:06Z","40643" +"*defeat-defender.py*",".{0,1000}defeat\-defender\.py.{0,1000}","offensive_tool_keyword","Defeat-Defender","script to dismantle complete windows defender protection and even bypass tamper protection - Disable Windows-Defender Permanently.","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/swagkarna/Defeat-Defender-V1.2.0","1","1","N/A","N/A","10","10","1530","316","2023-10-20T17:55:09Z","2020-12-10T07:22:06Z","40644" +"*Defeat-Defender-V1.3.ahk*",".{0,1000}Defeat\-Defender\-V1\.3\.ahk.{0,1000}","offensive_tool_keyword","Defeat-Defender","script to dismantle complete windows defender protection and even bypass tamper protection - Disable Windows-Defender Permanently.","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/swagkarna/Defeat-Defender-V1.2.0","1","1","N/A","N/A","10","10","1530","316","2023-10-20T17:55:09Z","2020-12-10T07:22:06Z","40645" +"*Defender.Remover.exe*",".{0,1000}Defender\.Remover\.exe.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40647" +"*DefenderCheck.exe*",".{0,1000}DefenderCheck\.exe.{0,1000}","offensive_tool_keyword","DefenderCheck","Identifies the bytes that Microsoft Defender flags on","T1059.001 - T1059.005 - T1027.002 - T1070.004","TA0002 - TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/ThreatCheck","1","1","N/A","N/A","N/A","10","1185","143","2024-06-01T16:46:57Z","2020-10-08T11:22:26Z","40649" +"*DefenderRemover.Phase1.exe*",".{0,1000}DefenderRemover\.Phase1\.exe.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40650" +"*DefenderRemover.Phase2.exe*",".{0,1000}DefenderRemover\.Phase2\.exe.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40651" +"*DefenderRemover.Phase3.exe*",".{0,1000}DefenderRemover\.Phase3\.exe.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40652" +"*DefenderRemover.Phase4.exe*",".{0,1000}DefenderRemover\.Phase4\.exe.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40653" +"*DefenderRemover.Phase5.exe*",".{0,1000}DefenderRemover\.Phase5\.exe.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40654" +"*DefenseEvasion_CodeSigning_PeSigningAuthHijack.py*",".{0,1000}DefenseEvasion_CodeSigning_PeSigningAuthHijack\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","40655" +"*DefenseEvasion_CodeSigning_StolenMircosoftWindowsSignature.py*",".{0,1000}DefenseEvasion_CodeSigning_StolenMircosoftWindowsSignature\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","40656" +"*DefenseEvasion_ProcessInjection_CobaltStrikeOnline.py*",".{0,1000}DefenseEvasion_ProcessInjection_CobaltStrikeOnline\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","40657" +"*DefenseEvasion_ProcessInjection_CsharpAssemblyLoader.py*",".{0,1000}DefenseEvasion_ProcessInjection_CsharpAssemblyLoader\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","40658" +"*DefenseEvasion_ProcessInjection_CsharpAssemblyLoaderPlus.py*",".{0,1000}DefenseEvasion_ProcessInjection_CsharpAssemblyLoaderPlus\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","40659" +"*DefenseEvasion_ProcessInjection_ExampleModule.py*",".{0,1000}DefenseEvasion_ProcessInjection_ExampleModule\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","40660" +"*DefenseEvasion_ProcessInjection_PeLoader.py*",".{0,1000}DefenseEvasion_ProcessInjection_PeLoader\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","40661" +"*DefenseEvasion_ProcessInjection_PowershellRunInMem.py*",".{0,1000}DefenseEvasion_ProcessInjection_PowershellRunInMem\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","40662" +"*DefenseEvasion_ProcessInjection_ProcessHandle.py*",".{0,1000}DefenseEvasion_ProcessInjection_ProcessHandle\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","40663" +"*DefenseEvasion_ProcessInjection_PythonRunInMem.py*",".{0,1000}DefenseEvasion_ProcessInjection_PythonRunInMem\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","40664" +"*DefenseEvasion_ProcessInjection_SessionClone.py*",".{0,1000}DefenseEvasion_ProcessInjection_SessionClone\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","40665" +"*DefenseEvasion_ProcessInjection_ShellcodeLoader.py*",".{0,1000}DefenseEvasion_ProcessInjection_ShellcodeLoader\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","40666" +"*DefenseEvasion_ProcessInjection_WindowsSystem.py*",".{0,1000}DefenseEvasion_ProcessInjection_WindowsSystem\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","40667" +"*DefenseEvasion_SubvertTrustControls_CloneSSLPem.py*",".{0,1000}DefenseEvasion_SubvertTrustControls_CloneSSLPem\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","40668" +"*dekrypted/Fentanyl*",".{0,1000}dekrypted\/Fentanyl.{0,1000}","offensive_tool_keyword","Fentanyl","Stealer Malware - Steal Discord Tokens (+ Much More Info) - Steal Passwords/Cookies/History/Credit Cards/Phone Numbers and Addresses from all Browsers (Profile Support) - Steal PC Info - Steal Video Game Accounts (Adding more games + wallets and VPN's) - Low Detections - Anti VM - Sort of Fast - Startup - IP Logger","T1547.001 - T1552.001 - T1552.005 - T1110.001 - T1082 - T1562.001 - T1574.002 - T1529 - T1497.001 - T1543.003 - T1592.001","TA0005 - TA0006 - TA0040 - TA0003 - TA0009","N/A","N/A","Malware","https://github.com/dekrypted/Fentanyl","1","1","N/A","N/A","10","","N/A","","","","40672" +"*deleg_enum_imp*",".{0,1000}deleg_enum_imp.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","40717" +"*Delegation/delegation.py*",".{0,1000}Delegation\/delegation\.py.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","40718" +"*delegation_unconstrained_objects.txt*",".{0,1000}delegation_unconstrained_objects\.txt.{0,1000}","offensive_tool_keyword","adhunt","Tool for exploiting Active Directory Enviroments - enumeration","T1018 - T1087 - T1087.002 - T1069 - T1069.002","TA0007 - TA0003 - TA0001","N/A","N/A","Discovery","https://github.com/karendm/ADHunt","1","1","N/A","AD Enumeration","7","1","46","10","2023-08-10T18:55:39Z","2023-06-20T13:24:10Z","40722" +"*DelegationBOF.*",".{0,1000}DelegationBOF\..{0,1000}","offensive_tool_keyword","DelegationBOF","This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently. it supports RBCD. Constrained. Constrained w/Protocol Transition. and Unconstrained Delegation checks.","T1098 - T1214 - T1552","TA0006","N/A","N/A","Credential Access","https://github.com/IcebreakerSecurity/DelegationBOF","1","1","N/A","N/A","N/A","10","141","23","2022-05-04T14:00:36Z","2022-03-28T20:14:24Z","40723" +"*DeletePSscriptSignning.bat*",".{0,1000}DeletePSscriptSignning\.bat.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","40730" +"*demo-bof.cna*",".{0,1000}demo\-bof\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","A Visual Studio template used to create Cobalt Strike BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/securifybv/Visual-Studio-BOF-template","1","1","N/A","N/A","10","10","304","55","2021-11-17T12:03:42Z","2021-11-13T13:44:01Z","40737" +"*demonizedshell.sh*",".{0,1000}demonizedshell\.sh.{0,1000}","offensive_tool_keyword","D3m0n1z3dShell","Demonized Shell is an Advanced Tool for persistence in linux","T1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037","TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Persistence","https://github.com/MatheuZSecurity/D3m0n1z3dShell","1","1","#linux","N/A","10","4","373","54","2025-01-05T13:56:51Z","2023-05-30T02:30:47Z","40740" +"*demonizedshell_static.sh*",".{0,1000}demonizedshell_static\.sh.{0,1000}","offensive_tool_keyword","D3m0n1z3dShell","Demonized Shell is an Advanced Tool for persistence in linux","T1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037","TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Persistence","https://github.com/MatheuZSecurity/D3m0n1z3dShell","1","1","#linux","N/A","10","4","373","54","2025-01-05T13:56:51Z","2023-05-30T02:30:47Z","40741" +"*denandz/KeeFarce*",".{0,1000}denandz\/KeeFarce.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","1","N/A","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","40742" +"*denandz/SecretServerSecretStealer*",".{0,1000}denandz\/SecretServerSecretStealer.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","1","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","40743" +"*Dendrobate-master*",".{0,1000}Dendrobate\-master.{0,1000}","offensive_tool_keyword","Dendrobate","Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code","T1055.012 - T1059.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Dendrobate","1","1","N/A","N/A","10","2","131","27","2021-11-19T12:18:50Z","2021-02-15T11:15:51Z","40744" +"*dendron*FileMonInject.dll*",".{0,1000}dendron.{0,1000}FileMonInject\.dll.{0,1000}","offensive_tool_keyword","Dendrobate","Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code","T1055.012 - T1059.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Dendrobate","1","1","N/A","N/A","10","2","131","27","2021-11-19T12:18:50Z","2021-02-15T11:15:51Z","40745" +"*DeNiSe-master.zip*",".{0,1000}DeNiSe\-master\.zip.{0,1000}","offensive_tool_keyword","DeNiSe","DeNiSe is a proof of concept for tunneling TCP over DNS in Python","T1071.004 - T1048.003","TA0011 - TA0010 - TA0001","N/A","N/A","C2","https://github.com/mdornseif/DeNiSe","1","1","N/A","N/A","10","10","28","13","2021-12-17T18:03:33Z","2010-01-15T07:43:14Z","40746" +"*DeNiSePkg.py*",".{0,1000}DeNiSePkg\.py.{0,1000}","offensive_tool_keyword","DeNiSe","DeNiSe is a proof of concept for tunneling TCP over DNS in Python","T1071.004 - T1048.003","TA0011 - TA0010 - TA0001","N/A","N/A","C2","https://github.com/mdornseif/DeNiSe","1","1","N/A","N/A","10","10","28","13","2021-12-17T18:03:33Z","2010-01-15T07:43:14Z","40747" +"*deploycaptureserver.ps1*",".{0,1000}deploycaptureserver\.ps1.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","40748" +"*DeployPrinterNightmare.exe*",".{0,1000}DeployPrinterNightmare\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","40750" +"*DesertNut.csproj*",".{0,1000}DesertNut\.csproj.{0,1000}","offensive_tool_keyword","DesertNut","DesertNut is a proof-of-concept for code injection using subclassed window callbacks (more commonly known as PROPagate)","T1055.012 - T1546.008","TA0005 - TA0004","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Sharp-Suite/tree/master/DesertNut","1","1","N/A","N/A","N/A","10","1131","203","2022-12-22T23:57:19Z","2018-12-10T00:08:37Z","40758" +"*DesertNut.exe*",".{0,1000}DesertNut\.exe.{0,1000}","offensive_tool_keyword","DesertNut","DesertNut is a proof-of-concept for code injection using subclassed window callbacks (more commonly known as PROPagate)","T1055.012 - T1546.008","TA0005 - TA0004","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Sharp-Suite/tree/master/DesertNut","1","1","N/A","N/A","N/A","10","1131","203","2022-12-22T23:57:19Z","2018-12-10T00:08:37Z","40759" +"*DesertNut.sln*",".{0,1000}DesertNut\.sln.{0,1000}","offensive_tool_keyword","DesertNut","DesertNut is a proof-of-concept for code injection using subclassed window callbacks (more commonly known as PROPagate)","T1055.012 - T1546.008","TA0005 - TA0004","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Sharp-Suite/tree/master/DesertNut","1","1","N/A","N/A","N/A","10","1131","203","2022-12-22T23:57:19Z","2018-12-10T00:08:37Z","40760" +"*DesertNut_h.cs*",".{0,1000}DesertNut_h\.cs.{0,1000}","offensive_tool_keyword","DesertNut","DesertNut is a proof-of-concept for code injection using subclassed window callbacks (more commonly known as PROPagate)","T1055.012 - T1546.008","TA0005 - TA0004","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Sharp-Suite/tree/master/DesertNut","1","1","N/A","N/A","N/A","10","1131","203","2022-12-22T23:57:19Z","2018-12-10T00:08:37Z","40761" +"*details-c80a6994018b23dc.js*",".{0,1000}details\-c80a6994018b23dc\.js.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","40768" +"*detect-hooksx64.*",".{0,1000}detect\-hooksx64\..{0,1000}","offensive_tool_keyword","cobaltstrike","Proof of concept Beacon Object File (BOF) that attempts to detect userland hooks in place by AV/EDR","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/anthemtotheego/Detect-Hooks","1","1","N/A","N/A","10","10","158","30","2021-07-22T20:13:16Z","2021-07-22T18:58:23Z","40772" +"*dev.l1qu1d.net/wraith-labs/wraith*",".{0,1000}dev\.l1qu1d\.net\/wraith\-labs\/wraith.{0,1000}","offensive_tool_keyword","wraith","A free and open-source, modular Remote Administration Tool (RAT) / Payload Dropper written in Go(lang) with a flexible command and control (C2) system.","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/wraith-labs/wraith","1","1","N/A","N/A","10","10","223","49","2023-12-03T22:16:27Z","2020-01-23T17:09:23Z","40774" +"*dev-2null/ADCollector*",".{0,1000}dev\-2null\/ADCollector.{0,1000}","offensive_tool_keyword","ADCollector","ADCollector is a lightweight tool that enumerates the Active Directory environment","T1087 - T1018 - T1069 - T1482","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/dev-2null/ADCollector","1","1","N/A","N/A","7","7","629","81","2022-07-30T05:27:15Z","2019-05-15T06:42:20Z","40775" +"*dfscoerce.py*",".{0,1000}dfscoerce\.py.{0,1000}","offensive_tool_keyword","DFSCoerce","PoC for MS-DFSNM coerce authentication using NetrDfsRemoveStdRoot and NetrDfsAddStdRoot?","T1550.001 - T1078.003 - T1046","TA0002 - TA0007 - TA0040","N/A","Dispossessor","Exploitation tool","https://github.com/Wh04m1001/DFSCoerce","1","1","N/A","N/A","10","8","769","98","2022-09-09T17:45:41Z","2022-06-18T12:38:37Z","40858" +"*dgnh6p5uq234zry7qx7bh73hj5ht3jqisgfet6s7j7uyas5i46xfdkyd.onion*",".{0,1000}dgnh6p5uq234zry7qx7bh73hj5ht3jqisgfet6s7j7uyas5i46xfdkyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","40865" +"*dhcp_sniffer.py*",".{0,1000}dhcp_sniffer\.py.{0,1000}","offensive_tool_keyword","DDSpoof","DDSpoof is a tool that enables DHCP DNS Dynamic Update attacks against Microsoft DHCP servers in AD environments.","T1557 - T1584 - T1203","TA0005 - TA0003 TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/akamai/DDSpoof","1","1","N/A","N/A","9","2","122","13","2024-04-12T22:06:02Z","2023-12-14T06:47:45Z","40868" +"*dhcp6.spoof.*",".{0,1000}dhcp6\.spoof\..{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","40869" +"*Dialupass.exe*",".{0,1000}Dialupass\.exe.{0,1000}","offensive_tool_keyword","dialupass","This utility enumerates all dialup/VPN entries on your computers. and displays their logon details: User Name. Password. and Domain. You can use it to recover a lost password of your Internet connection or VPN.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/dialupass.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","40872" +"*Dialupass.zip*",".{0,1000}Dialupass\.zip.{0,1000}","offensive_tool_keyword","dialupass","This utility enumerates all dialup/VPN entries on your computers. and displays their logon details: User Name. Password. and Domain. You can use it to recover a lost password of your Internet connection or VPN.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/dialupass.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","40873" +"*Diamond RAT Builder.exe*",".{0,1000}Diamond\sRAT\sBuilder\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","40874" +"*dicts/ftp_pswd.txt*",".{0,1000}dicts\/ftp_pswd\.txt.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoCs - 23 kinds of application password crack - 7000+Web fingerprints - 146 protocols and 90000+ rules Port scanning - Fuzz - HW - awesome BugBounty","T1046 - T1210.001 - T1059 - T1082 - T1110","TA0007 - TA0001 - TA0009 - TA0002 - TA0004 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","40877" +"*dicts/ssh_default.txt*",".{0,1000}dicts\/ssh_default\.txt.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoCs - 23 kinds of application password crack - 7000+Web fingerprints - 146 protocols and 90000+ rules Port scanning - Fuzz - HW - awesome BugBounty","T1046 - T1210.001 - T1059 - T1082 - T1110","TA0007 - TA0001 - TA0009 - TA0002 - TA0004 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","40878" +"*dicts/ssh_pswd.txt*",".{0,1000}dicts\/ssh_pswd\.txt.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoCs - 23 kinds of application password crack - 7000+Web fingerprints - 146 protocols and 90000+ rules Port scanning - Fuzz - HW - awesome BugBounty","T1046 - T1210.001 - T1059 - T1082 - T1110","TA0007 - TA0001 - TA0009 - TA0002 - TA0004 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","40879" +"*diego-treitos/linux-smart-enumeration*",".{0,1000}diego\-treitos\/linux\-smart\-enumeration.{0,1000}","offensive_tool_keyword","linux-smart-enumeration","Linux enumeration tool for privilege escalation and discovery","T1087.004 - T1016 - T1548.001 - T1046","TA0007 - TA0004 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/diego-treitos/linux-smart-enumeration","1","1","#linux","N/A","9","10","3575","584","2023-12-25T14:46:47Z","2019-02-13T11:02:21Z","40880" +"*dievus/lnkbomb*",".{0,1000}dievus\/lnkbomb.{0,1000}","offensive_tool_keyword","lnkbomb","Malicious shortcut generator for collecting NTLM hashes from insecure file shares.","T1023.003 - T1557.002 - T1046","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/dievus/lnkbomb","1","1","N/A","N/A","10","4","327","58","2024-10-22T17:51:10Z","2022-01-03T04:17:11Z","40881" +"*dievus/PowerShellRunner*",".{0,1000}dievus\/PowerShellRunner.{0,1000}","offensive_tool_keyword","PowerShellRunner","PowerShell runner for executing malicious payloads in order to bypass Windows Defender","T1059.001 - T1562.001 - T1218.005","TA0002 - TA0005","N/A","Turla","Defense Evasion","https://github.com/dievus/PowerShellRunner","1","1","N/A","N/A","9","1","70","20","2021-11-22T18:43:16Z","2021-08-03T01:29:34Z","40882" +"*digitalocean-droplet-openvpn-all.jar*",".{0,1000}digitalocean\-droplet\-openvpn\-all\.jar.{0,1000}","offensive_tool_keyword","burpsuite","A BurpSuite extension to deploy an OpenVPN config file to DigitalOcean and set up a SOCKS proxy to route traffic through it","T1592 - T1021 - T1573 - T1090 - T1071","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/honoki/burp-digitalocean-openvpn-socks","1","1","N/A","N/A","10","1","49","9","2024-02-26T13:59:20Z","2024-02-26T13:59:17Z","40886" +"*DigitalSignature-Hijack.ps1*",".{0,1000}DigitalSignature\-Hijack\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","40888" +"*DInjector.csproj*",".{0,1000}DInjector\.csproj.{0,1000}","offensive_tool_keyword","Dinjector","Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL","T1055 - T1055.012 - T1055.001 - T1027.002","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Metro-Holografix/DInjector","1","1","N/A","private github repo","8","","N/A","","","","40891" +"*DInjector.dll*",".{0,1000}DInjector\.dll.{0,1000}","offensive_tool_keyword","Dinjector","Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL","T1055 - T1055.012 - T1055.001 - T1027.002","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Metro-Holografix/DInjector","1","1","N/A","private github repo","8","","N/A","","","","40893" +"*DInjector/Dinjector*",".{0,1000}DInjector\/Dinjector.{0,1000}","offensive_tool_keyword","Dinjector","Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL","T1055 - T1055.012 - T1055.001 - T1027.002","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Metro-Holografix/DInjector","1","1","N/A","private github repo","8","","N/A","","","","40894" +"*Dinjector-main*",".{0,1000}Dinjector\-main.{0,1000}","offensive_tool_keyword","Dinjector","Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL","T1055 - T1055.012 - T1055.001 - T1027.002","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Metro-Holografix/DInjector","1","1","N/A","private github repo","8","","N/A","","","","40895" +"*Dionach*PassHunt*",".{0,1000}Dionach.{0,1000}PassHunt.{0,1000}","offensive_tool_keyword","PassHunt","PassHunt searches drives for documents that contain passwords or any other regular expression. Its designed to be a simple. standalone tool that can be run from a USB stick.","T1081 - T1083 - T1003 - T1039 - T1213","TA0003 - TA0010","N/A","N/A","Discovery","https://github.com/Dionach/PassHunt","1","1","N/A","N/A","N/A","1","63","30","2014-07-11T09:08:02Z","2014-07-11T08:46:20Z","40896" +"*dionach/ShareAudit*",".{0,1000}dionach\/ShareAudit.{0,1000}","offensive_tool_keyword","ShareAudit","A tool for auditing network shares in an Active Directory environment","T1135 - T1005 - T1083 - T1210","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/dionach/ShareAudit","1","1","N/A","N/A","8","1","42","15","2019-04-29T10:07:57Z","2019-02-26T16:00:15Z","40899" +"*dir_create2system.txt*",".{0,1000}dir_create2system\.txt.{0,1000}","offensive_tool_keyword","DirCreate2System","Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting","T1068 - T1059.001 - T1070.004","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/binderlabs/DirCreate2System","1","1","N/A","N/A","8","4","357","38","2022-12-19T17:00:43Z","2022-12-15T03:49:55Z","40910" +"*dirb/wordlists*",".{0,1000}dirb\/wordlists.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","40912" +"*dircreate2system.cpp*",".{0,1000}dircreate2system\.cpp.{0,1000}","offensive_tool_keyword","DirCreate2System","Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting","T1068 - T1059.001 - T1070.004","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/binderlabs/DirCreate2System","1","1","N/A","N/A","8","4","357","38","2022-12-19T17:00:43Z","2022-12-15T03:49:55Z","40913" +"*dircreate2system.exe*",".{0,1000}dircreate2system\.exe.{0,1000}","offensive_tool_keyword","DirCreate2System","Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting","T1068 - T1059.001 - T1070.004","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/binderlabs/DirCreate2System","1","1","N/A","N/A","8","4","357","38","2022-12-19T17:00:43Z","2022-12-15T03:49:55Z","40914" +"*dircreate2system.vcxproj*",".{0,1000}dircreate2system\.vcxproj.{0,1000}","offensive_tool_keyword","DirCreate2System","Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting","T1068 - T1059.001 - T1070.004","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/binderlabs/DirCreate2System","1","1","N/A","N/A","8","4","357","38","2022-12-19T17:00:43Z","2022-12-15T03:49:55Z","40915" +"*DirCreate2System-main*",".{0,1000}DirCreate2System\-main.{0,1000}","offensive_tool_keyword","DirCreate2System","Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting","T1068 - T1059.001 - T1070.004","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/binderlabs/DirCreate2System","1","1","N/A","N/A","8","4","357","38","2022-12-19T17:00:43Z","2022-12-15T03:49:55Z","40916" +"*Direct_Syscalls_Create_Thread.c*",".{0,1000}Direct_Syscalls_Create_Thread\.c.{0,1000}","offensive_tool_keyword","Direct-Syscalls","Direct-Syscalls technique is a method employed by malware to hide its malicious behavior and avoid detection. This technique involves executing system calls directly thus bypassing the Windows API (Application Programming Interface) which is typically monitored by EDRs","T1055 - T1548.002 - T1129","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Direct-Syscalls-vs-Indirect-Syscalls","1","1","N/A","N/A","N/A","2","186","24","2024-01-20T12:02:18Z","2023-05-23T06:30:54Z","40918" +"*Direct_Syscalls_Create_Thread.exe*",".{0,1000}Direct_Syscalls_Create_Thread\.exe.{0,1000}","offensive_tool_keyword","Direct-Syscalls","Direct-Syscalls technique is a method employed by malware to hide its malicious behavior and avoid detection. This technique involves executing system calls directly thus bypassing the Windows API (Application Programming Interface) which is typically monitored by EDRs","T1055 - T1548.002 - T1129","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Direct-Syscalls-vs-Indirect-Syscalls","1","1","N/A","N/A","N/A","2","186","24","2024-01-20T12:02:18Z","2023-05-23T06:30:54Z","40919" +"*Direct_Syscalls_Create_Thread.sln*",".{0,1000}Direct_Syscalls_Create_Thread\.sln.{0,1000}","offensive_tool_keyword","Direct-Syscalls","Direct-Syscalls technique is a method employed by malware to hide its malicious behavior and avoid detection. This technique involves executing system calls directly thus bypassing the Windows API (Application Programming Interface) which is typically monitored by EDRs","T1055 - T1548.002 - T1129","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Direct-Syscalls-vs-Indirect-Syscalls","1","1","N/A","N/A","N/A","2","186","24","2024-01-20T12:02:18Z","2023-05-23T06:30:54Z","40920" +"*Direct_Syscalls_Create_Thread.vcxproj*",".{0,1000}Direct_Syscalls_Create_Thread\.vcxproj.{0,1000}","offensive_tool_keyword","Direct-Syscalls","Direct-Syscalls technique is a method employed by malware to hide its malicious behavior and avoid detection. This technique involves executing system calls directly thus bypassing the Windows API (Application Programming Interface) which is typically monitored by EDRs","T1055 - T1548.002 - T1129","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Direct-Syscalls-vs-Indirect-Syscalls","1","1","N/A","N/A","N/A","2","186","24","2024-01-20T12:02:18Z","2023-05-23T06:30:54Z","40921" +"*Directory-Traversal-Payloads.*",".{0,1000}Directory\-Traversal\-Payloads\..{0,1000}","offensive_tool_keyword","Offensive-Payloads","List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.","T1210 - T1185 - T1059 - T1400 - T1506 - T1213 ","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/InfoSecWarrior/Offensive-Payloads/","1","1","N/A","N/A","N/A","4","328","117","2024-09-20T09:59:28Z","2022-11-18T09:43:41Z","40922" +"*Direct-Syscalls-vs-Indirect-Syscalls.git*",".{0,1000}Direct\-Syscalls\-vs\-Indirect\-Syscalls\.git.{0,1000}","offensive_tool_keyword","Indirect-Syscalls","Indirect syscalls serve as an evolution of direct syscalls and enable enhanced EDR evasion by legitimizing syscall command execution and return statement within the ntdll.dll memory. This stealthy operation partially implements the syscall stub in the Indirect Syscall assembly itself.","T1055 - T1548.002 - T1129","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Direct-Syscalls-vs-Indirect-Syscalls","1","1","N/A","N/A","N/A","2","186","24","2024-01-20T12:02:18Z","2023-05-23T06:30:54Z","40923" +"*dirkjan@sanoweb.nl*",".{0,1000}dirkjan\@sanoweb\.nl.{0,1000}","offensive_tool_keyword","ldapdomaindump","Active Directory information dumper via LDAP","T1087 - T1005 - T1016","TA0007","N/A","EMBER BEAR","Discovery","https://github.com/dirkjanm/ldapdomaindump","1","1","#email","N/A","10","10","1242","201","2025-04-06T13:31:57Z","2016-05-24T18:46:56Z","40925" +"*dirkjanm/adidnsdump*",".{0,1000}dirkjanm\/adidnsdump.{0,1000}","offensive_tool_keyword","adidnsdump","By default any user in Active Directory can enumerate all DNS records in the Domain or Forest DNS zones. similar to a zone transfer. This tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks.","T1018 - T1087 - T1201 - T1056 - T1039","TA0005 - TA0009","N/A","N/A","Discovery","https://github.com/dirkjanm/adidnsdump","1","1","N/A","N/A","N/A","10","997","118","2025-04-04T09:28:20Z","2019-04-24T17:18:46Z","40926" +"*dirkjanm/ldapdomaindump*",".{0,1000}dirkjanm\/ldapdomaindump.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","40927" +"*dirkjanm/PKINITtools*",".{0,1000}dirkjanm\/PKINITtools.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","40928" +"*dirkjanm/PKINITtools*",".{0,1000}dirkjanm\/PKINITtools.{0,1000}","offensive_tool_keyword","PKINITtools","Tools for Kerberos PKINIT and relaying to AD CS","T1550.003 - T1557.002 - T1552.004 - T1212 - T1550","TA0009 - TA0008","N/A","N/A","Lateral Movement","https://github.com/dirkjanm/PKINITtools","1","1","N/A","N/A","N/A","8","737","82","2025-01-03T14:25:52Z","2021-07-27T19:06:09Z","40929" +"*dirkjanm/PrivExchange*",".{0,1000}dirkjanm\/PrivExchange.{0,1000}","offensive_tool_keyword","privexchange","Exchange your privileges for Domain Admin privs by abusing Exchange","T1053.005 - T1078 - T1069.002","TA0002 - TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/dirkjanm/PrivExchange","1","1","N/A","N/A","N/A","10","1011","173","2020-01-23T19:48:51Z","2019-01-21T17:39:47Z","40930" +"*dirkjanm/ROADtoken*",".{0,1000}dirkjanm\/ROADtoken.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","1","N/A","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","40931" +"*dirscanner.py*",".{0,1000}dirscanner\.py.{0,1000}","offensive_tool_keyword","RedTeam_toolkit","Red Team Toolkit is an Open-Source Django Offensive Web-App which is keeping the useful offensive tools used in the red-teaming together","T1083 - T1065 - T1204 - T1087 - T1203","TA0007 - TA0005 - TA0001","N/A","N/A","Reconnaissance","https://github.com/signorrayan/RedTeam_toolkit","1","1","N/A","N/A","N/A","6","561","121","2025-03-28T06:59:25Z","2021-08-18T08:58:14Z","40932" +"*dirscraper*",".{0,1000}dirscraper.{0,1000}","offensive_tool_keyword","dirscraper","Dirscraper is an OSINT scanning tool which assists penetration testers in identifying hidden. or previously unknown. directories on a domain or subdomain. This helps greatly in the recon stage of pentesting as it provide pentesters with a larger attack surface for the specific domain.","T1596 - T1530 - T1201","TA0040 - ","N/A","N/A","Reconnaissance","https://github.com/Cillian-Collins/dirscraper","1","1","N/A","N/A","N/A","3","227","32","2019-02-24T12:22:47Z","2019-02-21T23:06:58Z","40933" +"*dirTraversal.txt*",".{0,1000}dirTraversal\.txt.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","40935" +"*dirTraversal-nix.txt*",".{0,1000}dirTraversal\-nix\.txt.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","40936" +"*dirTraversal-win.txt*",".{0,1000}dirTraversal\-win\.txt.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","40937" +"*dirty_sock*",".{0,1000}dirty_sock.{0,1000}","offensive_tool_keyword","POC","dirty_sock: Linux Privilege Escalation (via snapd) In January 2019. current versions of Ubuntu Linux were found to be vulnerable to local privilege escalation due to a bug in the snapd API. This repository contains the original exploit POC","T1210 - T1211 - T1212 - T1547","TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/initstring/dirty_sock","1","1","#linux","N/A","N/A","7","671","147","2019-05-09T21:34:26Z","2019-02-12T06:02:06Z","40938" +"*dirty_sock/archive/master.zip*",".{0,1000}dirty_sock\/archive\/master\.zip.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","40939" +"*dirtypipe.cm4all.com*",".{0,1000}dirtypipe\.cm4all\.com.{0,1000}","offensive_tool_keyword","POC","exploit the Linux Dirty Pipe vulnerability","T1068 - T1078.003 - T1071.004 - T1072 - T1105","TA0004 - TA0006?","N/A","N/A","Privilege Escalation","https://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits","1","1","#linux","N/A","10","6","595","148","2023-05-20T05:55:45Z","2022-03-12T20:57:24Z","40941" +"*Dirty-Pipe/exploit-static*",".{0,1000}Dirty\-Pipe\/exploit\-static.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","t1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/carlosevieira/Dirty-Pipe","1","1","N/A","N/A","N/A","1","9","6","2022-03-07T21:01:15Z","2022-03-07T20:57:34Z","40942" +"*dirtypipe-exploit/blob/main/dirtypipe.c*",".{0,1000}dirtypipe\-exploit\/blob\/main\/dirtypipe\.c.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/rahul1406/cve-2022-0847dirtypipe-exploit","1","1","N/A","N/A","N/A","","N/A","","","","40943" +"*-DirtyPipe-Exploits*",".{0,1000}\-DirtyPipe\-Exploits.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","t1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits","1","1","N/A","N/A","N/A","6","595","148","2023-05-20T05:55:45Z","2022-03-12T20:57:24Z","40944" +"*DirtyVanity.exe*",".{0,1000}DirtyVanity\.exe.{0,1000}","offensive_tool_keyword","Dirty-Vanity","injection technique abusing windows fork API to evade EDRs","T1055 - T1562 - T1070 - T1027","TA0005 - TA0006","N/A","N/A","Defense Evasion","https://github.com/deepinstinct/Dirty-Vanity","1","1","N/A","N/A","10","7","633","86","2022-12-23T10:54:10Z","2022-11-24T10:54:00Z","40945" +"*dirwalk.py*",".{0,1000}dirwalk\.py.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","40946" +"*disable_clamav.*",".{0,1000}disable_clamav\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","40948" +"*disable_clamav.rb*",".{0,1000}disable_clamav\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","40949" +"*DisableAllWindowsSoftwareFirewalls*",".{0,1000}DisableAllWindowsSoftwareFirewalls.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to interact with COM objects associated with the Windows software firewall.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/Firewall_Walker_BOF","1","1","N/A","N/A","10","10","103","15","2021-10-10T03:28:27Z","2021-10-09T05:17:10Z","40952" +"*Disable-AMS1.ps1*",".{0,1000}Disable\-AMS1\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","40953" +"*DisableAntiPhishing*",".{0,1000}DisableAntiPhishing.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","40955" +"*DisableAntiPhishing.ps1*",".{0,1000}DisableAntiPhishing\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","40956" +"*DisableAntivirusProtection.reg*",".{0,1000}DisableAntivirusProtection\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40957" +"*DisableBitdefenderAV.exe*",".{0,1000}DisableBitdefenderAV\.exe.{0,1000}","offensive_tool_keyword","Dispossessor","tool used by Dispossessor ransomware group to remove AV","T1562.001 - T1112 - T1059 - T1036","TA0005 - TA0040","N/A","Dispossessor","Defense Evasion","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","40958" +"*DisableCylance.ps1*",".{0,1000}DisableCylance\.ps1.{0,1000}","offensive_tool_keyword","RandomPS-Scripts","PowerShell wrapper for a Cylance Bypass","T1055 - T1068 - T1562.001","TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/xorrior/RandomPS-Scripts","1","1","N/A","N/A","8","4","318","86","2017-12-29T17:16:42Z","2015-02-25T04:52:01Z","40968" +"*DisableDefender.ps1*",".{0,1000}DisableDefender\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","40969" +"*DisableDefenderandSecurityCenterNotifications.reg*",".{0,1000}DisableDefenderandSecurityCenterNotifications\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40970" +"*DisableDefenderPolicies.reg*",".{0,1000}DisableDefenderPolicies\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40971" +"*DisableDevDriveProtection.reg*",".{0,1000}DisableDevDriveProtection\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40972" +"*disableeventvwr/*.ps1*",".{0,1000}disableeventvwr\/.{0,1000}\.ps1.{0,1000}","offensive_tool_keyword","cobaltstrike","Aggressor script to integrate Phant0m with Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/p292/Phant0m_cobaltstrike","1","1","N/A","N/A","10","10","27","13","2017-06-08T06:42:18Z","2017-06-08T06:39:07Z","40973" +"*DisableKerberosSigning*",".{0,1000}DisableKerberosSigning.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","40974" +"*DisableLSAProtection.reg*",".{0,1000}DisableLSAProtection\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40976" +"*DisableMailboxAuditing.ps1*",".{0,1000}DisableMailboxAuditing\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","40977" +"*DisableMaintenanceTaskreportinginSecurityHealthUI.reg*",".{0,1000}DisableMaintenanceTaskreportinginSecurityHealthUI\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40978" +"*DisableMFA.ps1*",".{0,1000}DisableMFA\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","40979" +"*DisableMicrosoftVulnerabileDriverBlocklist.reg*",".{0,1000}DisableMicrosoftVulnerabileDriverBlocklist\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40980" +"*DisableSmartScreen.reg*",".{0,1000}DisableSmartScreen\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40982" +"*DisableSpyNetTelemetry.reg*",".{0,1000}DisableSpyNetTelemetry\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40983" +"*DisableSystemMitigations.reg*",".{0,1000}DisableSystemMitigations\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40984" +"*Disable-TamperProtection.cpp*",".{0,1000}Disable\-TamperProtection\.cpp.{0,1000}","offensive_tool_keyword","Disable-TamperProtection","disable TamperProtection and other Defender / MDE components","T1562.001 - T1562.007","TA0005","N/A","N/A","Defense Evasion","https://github.com/AlteredSecurity/Disable-TamperProtection","1","1","N/A","N/A","10","3","208","35","2024-06-06T14:44:59Z","2024-06-05T12:48:56Z","40985" +"*Disable-TamperProtection.exe*",".{0,1000}Disable\-TamperProtection\.exe.{0,1000}","offensive_tool_keyword","Disable-TamperProtection","disable TamperProtection and other Defender / MDE components","T1562.001 - T1562.007","TA0005","N/A","N/A","Defense Evasion","https://github.com/AlteredSecurity/Disable-TamperProtection","1","1","N/A","N/A","10","3","208","35","2024-06-06T14:44:59Z","2024-06-05T12:48:56Z","40986" +"*DisableTamperProtection.reg*",".{0,1000}DisableTamperProtection\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40987" +"*DisableUAC.reg*",".{0,1000}DisableUAC\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40988" +"*DisableVBS.reg*",".{0,1000}DisableVBS\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","40989" +"*disableWinDef.cpp*",".{0,1000}disableWinDef\.cpp.{0,1000}","offensive_tool_keyword","WinDefenderKiller","Windows Defender Killer | C++ Code Disabling Permanently Windows Defender using Registry Keys","T1562.001 - T1055.002 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/S12cybersecurity/WinDefenderKiller","1","1","N/A","N/A","10","5","448","67","2023-07-27T11:06:24Z","2023-07-25T10:32:25Z","40990" +"*discordapp.com/attachments/*/AnyDesk.exe*",".{0,1000}discordapp\.com\/attachments\/.{0,1000}\/AnyDesk\.exe.{0,1000}","offensive_tool_keyword","anydesk","Fake Anydesk distributed by discord - mars stealer","T1021 - T1071 - T1090","TA0008 - TA0011","N/A","BlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - Dispossessor","RMM","https://www.virustotal.com/gui/url/f83616f0f9cd2337ed40e22b0a675a99d58edf004b31645f56f28f020f5e4f46/detection","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","40994" +"*discordapp.com/attachments/*/BOINCPortable_*.exe*",".{0,1000}discordapp\.com\/attachments\/.{0,1000}\/BOINCPortable_.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","BOINC","Fake BOINC software distributed by discord - mars stealer","T1566 - T1587","N/A","N/A","N/A","Malware","https://cyberint.com/wp-content/uploads/2022/02/Mars-Stealer-7.png.webp","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","40995" +"*Discord-RAT-2.0-discordrat.zip*",".{0,1000}Discord\-RAT\-2\.0\-discordrat\.zip.{0,1000}","offensive_tool_keyword","Discord-RAT-2.0","Discord Remote Administration Tool fully written in c#, stub size of ~75kb with over 40 post exploitations modules","T1059.005 - T1105 - T1569.002 - T1027.001","TA0011 - TA0003 - TA0006 - TA0009 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/moom825/Discord-RAT-2.0","1","1","N/A","N/A","10","10","512","115","2023-11-03T01:15:38Z","2022-07-15T20:09:56Z","40997" +"*Discord-RAT-2.0-master.zip*",".{0,1000}Discord\-RAT\-2\.0\-master\.zip.{0,1000}","offensive_tool_keyword","Discord-RAT-2.0","Discord Remote Administration Tool fully written in c#, stub size of ~75kb with over 40 post exploitations modules","T1059.005 - T1105 - T1569.002 - T1027.001","TA0011 - TA0003 - TA0006 - TA0009 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/moom825/Discord-RAT-2.0","1","1","N/A","N/A","10","10","512","115","2023-11-03T01:15:38Z","2022-07-15T20:09:56Z","40998" +"*Discord-RAT-by-Biscuit-main*",".{0,1000}Discord\-RAT\-by\-Biscuit\-main.{0,1000}","offensive_tool_keyword","Discord-RAT-2.0","Discord Remote Administration Tool fully written in c#, stub size of ~75kb with over 40 post exploitations modules","T1059.005 - T1105 - T1569.002 - T1027.001","TA0011 - TA0003 - TA0006 - TA0009 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/moom825/Discord-RAT-2.0","1","1","N/A","N/A","10","10","512","115","2023-11-03T01:15:38Z","2022-07-15T20:09:56Z","40999" +"*DiscoverBasicHostRecon.ahk*",".{0,1000}DiscoverBasicHostRecon\.ahk.{0,1000}","offensive_tool_keyword","AutoPwnKey","red teaming framework and testing tool using AutoHotKey","T1059.007 - T1204.002 - T1564.004 - T1105 - T1087 - T1069 - T1027 - T1218 - T1548.002 - T1547 - T1056.001 - T1021.001 - T1102 - T1573 - T1499 - T1565","TA0001 - TA0007 - TA0005 - TA0004 - TA0003 - TA0006 - TA0008 - TA0011 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CroodSolutions/AutoPwnKey","1","1","N/A","N/A","10","1","25","5","2025-04-11T21:52:48Z","2024-08-14T05:05:33Z","41000" +"*Discover-PSMSExchangeServers*",".{0,1000}Discover\-PSMSExchangeServers.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","41002" +"*Discover-PSMSSQLServers*",".{0,1000}Discover\-PSMSSQLServers.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","41003" +"*Discovery_AccountDiscovery_GetNetDomainUser.py*",".{0,1000}Discovery_AccountDiscovery_GetNetDomainUser\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41004" +"*Discovery_AccountDiscovery_PowerView.py*",".{0,1000}Discovery_AccountDiscovery_PowerView\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41005" +"*Discovery_ApplicationWindowDiscovery_EnumApplication.py*",".{0,1000}Discovery_ApplicationWindowDiscovery_EnumApplication\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41006" +"*Discovery_Microphone_CallInfo.py*",".{0,1000}Discovery_Microphone_CallInfo\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41007" +"*Discovery_Microphone_camera.py*",".{0,1000}Discovery_Microphone_camera\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41008" +"*Discovery_Microphone_record_mic.py*",".{0,1000}Discovery_Microphone_record_mic\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41009" +"*Discovery_NetworkServiceScanning_ARPScan.py*",".{0,1000}Discovery_NetworkServiceScanning_ARPScan\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41010" +"*Discovery_NetworkServiceScanning_NbtScanByPython.py*",".{0,1000}Discovery_NetworkServiceScanning_NbtScanByPython\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41011" +"*Discovery_NetworkServiceScanning_NextnetByPE.py*",".{0,1000}Discovery_NetworkServiceScanning_NextnetByPE\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41012" +"*Discovery_NetworkServiceScanning_PingByPython.py*",".{0,1000}Discovery_NetworkServiceScanning_PingByPython\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41013" +"*Discovery_NetworkServiceScanning_PortScanByPython.py*",".{0,1000}Discovery_NetworkServiceScanning_PortScanByPython\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41014" +"*Discovery_NetworkServiceScanning_PortScanWithServiceByPython.py*",".{0,1000}Discovery_NetworkServiceScanning_PortScanWithServiceByPython\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41015" +"*Discovery_NetworkShareDiscovery_PowerView.py*",".{0,1000}Discovery_NetworkShareDiscovery_PowerView\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41016" +"*Discovery_PermissionGroupsDiscovery_PowerView.py*",".{0,1000}Discovery_PermissionGroupsDiscovery_PowerView\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41017" +"*Discovery_QueryRegistry_GetDotNetVersions.py*",".{0,1000}Discovery_QueryRegistry_GetDotNetVersions\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41019" +"*Discovery_QueryRegistry_GetRDPPort.py*",".{0,1000}Discovery_QueryRegistry_GetRDPPort\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41020" +"*Discovery_RemoteSystemDiscovery_GetDomainIPAddress.py*",".{0,1000}Discovery_RemoteSystemDiscovery_GetDomainIPAddress\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41021" +"*Discovery_RemoteSystemDiscovery_GetNetComputer.py*",".{0,1000}Discovery_RemoteSystemDiscovery_GetNetComputer\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41022" +"*Discovery_RemoteSystemDiscovery_GetNetDomain.py*",".{0,1000}Discovery_RemoteSystemDiscovery_GetNetDomain\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41023" +"*Discovery_RemoteSystemDiscovery_GetNetDomainController.py*",".{0,1000}Discovery_RemoteSystemDiscovery_GetNetDomainController\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41024" +"*Discovery_SecuritySoftwareDiscovery_ListAVByTasklist.py*",".{0,1000}Discovery_SecuritySoftwareDiscovery_ListAVByTasklist\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41025" +"*Discovery_SystemNetworkConnectionsDiscovery_GetPublicIP.py*",".{0,1000}Discovery_SystemNetworkConnectionsDiscovery_GetPublicIP\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41026" +"*Discovery_SystemUserDiscovery_GetLastLoggedOn.py*",".{0,1000}Discovery_SystemUserDiscovery_GetLastLoggedOn\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41027" +"*Discovery_SystemUserDiscovery_GetLoggedOnLocal.py*",".{0,1000}Discovery_SystemUserDiscovery_GetLoggedOnLocal\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41028" +"*disctopia-c2.git*",".{0,1000}disctopia\-c2\.git.{0,1000}","offensive_tool_keyword","disctopia-c2","Windows Remote Administration Tool that uses Discord Telegram and GitHub as C2s","T1105 - T1102","TA0003 - TA0008 - TA0002","N/A","N/A","C2","https://github.com/3ct0s/disctopia-c2","1","1","N/A","N/A","10","10","609","139","2024-07-18T10:16:19Z","2022-01-02T22:03:10Z","41030" +"*disctopia-c2-main.zip*",".{0,1000}disctopia\-c2\-main\.zip.{0,1000}","offensive_tool_keyword","disctopia-c2","Windows Remote Administration Tool that uses Discord Telegram and GitHub as C2s","T1105 - T1102","TA0003 - TA0008 - TA0002","N/A","N/A","C2","https://github.com/3ct0s/disctopia-c2","1","1","N/A","N/A","10","10","609","139","2024-07-18T10:16:19Z","2022-01-02T22:03:10Z","41031" +"*diskcryptor2john.py*",".{0,1000}diskcryptor2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","41038" +"*DiskCryptor-master*",".{0,1000}DiskCryptor\-master.{0,1000}","offensive_tool_keyword","DiskCryptor","DiskCryptor is an open source encryption solution that offers encryption of all disk partitions including system partitions","T1486 ","TA0040","N/A","N/A","Ransomware","https://github.com/DavidXanatos/DiskCryptor","1","1","N/A","N/A","10","5","499","108","2024-07-03T10:05:01Z","2019-04-20T14:51:18Z","41039" +"*dist/agent.upx.exe*",".{0,1000}dist\/agent\.upx\.exe.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","41062" +"*dist/agent.windows.exe*",".{0,1000}dist\/agent\.windows\.exe.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","41063" +"*dist/nanorobeus_cs.*",".{0,1000}dist\/nanorobeus_cs\..{0,1000}","offensive_tool_keyword","nanorobeus","COFF file (BOF) for managing Kerberos tickets.","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","C2","https://github.com/wavvs/nanorobeus","1","1","N/A","N/A","10","10","294","31","2023-07-02T12:56:27Z","2022-07-04T00:33:30Z","41065" +"*dist/shadow.exe*",".{0,1000}dist\/shadow\.exe.{0,1000}","offensive_tool_keyword","ShadowForgeC2","ShadowForge Command & Control - Harnessing the power of Zoom API - control a compromised Windows Machine from your Zoom Chats.","T1071.001 - T1569.002 - T1059.001","TA0011 - TA0002 - TA0040","N/A","N/A","C2","https://github.com/0xEr3bus/ShadowForgeC2","1","1","N/A","N/A","10","10","47","7","2023-07-15T11:45:36Z","2023-07-13T11:49:36Z","41066" +"*distro.ibiblio.org/blackarch/*/os/*",".{0,1000}distro\.ibiblio\.org\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","41069" +"*DitExplorer-v1.0-win64-release.zip*",".{0,1000}DitExplorer\-v1\.0\-win64\-release\.zip.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","1","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","41078" +"*DitExplorer-v1.0-win64-release-standalone.zip*",".{0,1000}DitExplorer\-v1\.0\-win64\-release\-standalone\.zip.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","1","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","41079" +"*ditty/ditty.c*",".{0,1000}ditty\/ditty\.c.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SimoneLazzaris/ditty","1","1","N/A","N/A","N/A","1","2","1","2022-03-10T16:15:14Z","2022-03-09T09:20:27Z","41080" +"*diversenok/TokenUniverse*",".{0,1000}diversenok\/TokenUniverse.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","1","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","41082" +"*Diverto/IPPrintC2*",".{0,1000}Diverto\/IPPrintC2.{0,1000}","offensive_tool_keyword","IPPrintC2","PoC for using MS Windows printers for persistence / command and control via Internet Printing","T1090 - T1133 - T1547.012 - T1572","TA0011 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/Diverto/IPPrintC2","1","1","N/A","lolc2","10","10","146","20","2024-05-03T11:13:38Z","2024-05-03T09:13:10Z","41083" +"*djhohnstein/SharpChromium*",".{0,1000}djhohnstein\/SharpChromium.{0,1000}","offensive_tool_keyword","SharpChromium",".NET 4.0 CLR Project to retrieve Chromium data such as cookies - history and saved logins.","T1555.003 - T1114.001 - T1555.004","TA0006 - TA0003","N/A","COZY BEAR","Credential Access","https://github.com/djhohnstein/SharpChromium","1","1","N/A","N/A","10","8","712","100","2020-10-23T22:28:13Z","2018-08-06T21:25:21Z","41084" +"*djhohnstein/SharpLogger*",".{0,1000}djhohnstein\/SharpLogger.{0,1000}","offensive_tool_keyword","SharpLogger","Keylogger written in C#","T1056.001 - T1056.003","TA0005 - TA0006 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/djhohnstein/SharpLogger","1","1","N/A","N/A","10","2","126","41","2019-12-13T04:40:56Z","2018-12-18T01:45:17Z","41085" +"*djhohnstein/SharpSC*",".{0,1000}djhohnstein\/SharpSC.{0,1000}","offensive_tool_keyword","SharpSC",".NET assembly to interact with services. (included in powershell empire)","T1543.003","TA0003","N/A","N/A","Persistence","https://github.com/djhohnstein/SharpSC","1","1","N/A","N/A","8","1","40","6","2019-09-27T23:04:24Z","2019-09-24T21:05:38Z","41086" +"*DKMC-master.zip*",".{0,1000}DKMC\-master\.zip.{0,1000}","offensive_tool_keyword","DKMC","Malicious payload evasion tool","T1027 - T1055.012","TA0005 - TA0040","N/A","Molerats","Defense Evasion","https://github.com/Mr-Un1k0d3r/DKMC","1","1","N/A","N/A","10","10","1392","290","2020-07-20T03:36:56Z","2016-12-05T03:44:07Z","41087" +"*dlink_central_wifimanager_rce.*",".{0,1000}dlink_central_wifimanager_rce\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","41092" +"*dlink_sharecenter_cmd_exec*",".{0,1000}dlink_sharecenter_cmd_exec.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","41093" +"*dlink_telnet_backdoor_userpass*",".{0,1000}dlink_telnet_backdoor_userpass.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","41094" +"*Dliv3/Venom*",".{0,1000}Dliv3\/Venom.{0,1000}","offensive_tool_keyword","venom","Venom - A Multi-hop Proxy for Penetration Testers","T1090","TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/Dliv3/Venom","1","1","N/A","N/A","10","10","2070","357","2022-05-11T03:13:20Z","2019-01-13T07:35:29Z","41095" +"*dll_generator.py*",".{0,1000}dll_generator\.py.{0,1000}","offensive_tool_keyword","CSExec","An alternative to *exec.py from impacket with some builtin tricks","T1059.001 - T1059.005 - T1071.001","TA0002","N/A","N/A","Lateral Movement","https://github.com/Metro-Holografix/CSExec.py","1","1","N/A","private github repo","10","","N/A","","","","41100" +"*dll_hijack_detect_x64*",".{0,1000}dll_hijack_detect_x64.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","41101" +"*dll_hijack_detect_x86*",".{0,1000}dll_hijack_detect_x86.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","41102" +"*dll_hijack_hunter*",".{0,1000}dll_hijack_hunter.{0,1000}","offensive_tool_keyword","cobaltstrike","DLL Hijack Search Order Enumeration BOF","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/DLL-Hijack-Search-Order-BOF","1","1","N/A","N/A","10","10","147","21","2021-11-03T17:39:32Z","2021-11-02T03:47:31Z","41103" +"*DLL_Imports_BOF*",".{0,1000}DLL_Imports_BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to parse the imports of a provided PE-file. optionally extracting symbols on a per-dll basis.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/DLL_Imports_BOF","1","1","N/A","N/A","10","10","85","11","2021-10-28T18:07:09Z","2021-10-27T21:02:44Z","41104" +"*dll_inject.rb*",".{0,1000}dll_inject\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","41106" +"*dll_spawn_cmd.cpp*",".{0,1000}dll_spawn_cmd\.cpp.{0,1000}","offensive_tool_keyword","DirCreate2System","Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting","T1068 - T1059.001 - T1070.004","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/binderlabs/DirCreate2System","1","1","N/A","N/A","8","4","357","38","2022-12-19T17:00:43Z","2022-12-15T03:49:55Z","41108" +"*dll_spawn_cmd.exe*",".{0,1000}dll_spawn_cmd\.exe.{0,1000}","offensive_tool_keyword","DirCreate2System","Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting","T1068 - T1059.001 - T1070.004","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/binderlabs/DirCreate2System","1","1","N/A","N/A","8","4","357","38","2022-12-19T17:00:43Z","2022-12-15T03:49:55Z","41109" +"*DLL_TO_HIJACK_WIN10*",".{0,1000}DLL_TO_HIJACK_WIN10.{0,1000}","offensive_tool_keyword","cobaltstrike","A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/PPLDump_BOF","1","1","N/A","N/A","10","10","140","25","2021-09-24T07:10:04Z","2021-09-24T07:05:59Z","41110" +"*dllexploit.*",".{0,1000}dllexploit\..{0,1000}","offensive_tool_keyword","ppldump","Dump the memory of a PPL with a userland exploit","T1003 - T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/itm4n/PPLdump","1","1","N/A","N/A","10","9","868","140","2022-07-24T14:03:14Z","2021-04-07T13:12:47Z","41111" +"*DLLHijackAuditKit*",".{0,1000}DLLHijackAuditKit.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","41114" +"*DLLHijackAuditKit.zip*",".{0,1000}DLLHijackAuditKit\.zip.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","41115" +"*DLL-Hijack-Search-Order-BOF*",".{0,1000}DLL\-Hijack\-Search\-Order\-BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","DLL Hijack Search Order Enumeration BOF","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/DLL-Hijack-Search-Order-BOF","1","1","N/A","N/A","10","10","147","21","2021-11-03T17:39:32Z","2021-11-02T03:47:31Z","41116" +"*DLLHijackTest.dll*",".{0,1000}DLLHijackTest\.dll.{0,1000}","offensive_tool_keyword","DLLHijackTest","DLL and PowerShell script to assist with finding DLL hijacks","T1574.002 - T1055.001 - T1059.001 - T1036.005","TA0005 - TA0004 - TA0002","N/A","N/A","Defense Evasion","https://github.com/slyd0g/DLLHijackTest","1","1","N/A","N/A","9","4","335","62","2020-10-01T22:37:36Z","2020-06-20T04:33:01Z","41117" +"*DLLHijackTest.sln*",".{0,1000}DLLHijackTest\.sln.{0,1000}","offensive_tool_keyword","DLLHijackTest","DLL and PowerShell script to assist with finding DLL hijacks","T1574.002 - T1055.001 - T1059.001 - T1036.005","TA0005 - TA0004 - TA0002","N/A","N/A","Defense Evasion","https://github.com/slyd0g/DLLHijackTest","1","1","N/A","N/A","9","4","335","62","2020-10-01T22:37:36Z","2020-06-20T04:33:01Z","41118" +"*DLLHijackTest-master*",".{0,1000}DLLHijackTest\-master.{0,1000}","offensive_tool_keyword","DLLHijackTest","DLL and PowerShell script to assist with finding DLL hijacks","T1574.002 - T1055.001 - T1059.001 - T1036.005","TA0005 - TA0004 - TA0002","N/A","N/A","Defense Evasion","https://github.com/slyd0g/DLLHijackTest","1","1","N/A","N/A","9","4","335","62","2020-10-01T22:37:36Z","2020-06-20T04:33:01Z","41119" +"*dllinject.py*",".{0,1000}dllinject\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","41121" +"*-DllInjection.ps1*",".{0,1000}\-DllInjection\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1138","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","41123" +"*dllKitten.dll*",".{0,1000}dllKitten\.dll.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","41125" +"*DllLdr.x64.bin*",".{0,1000}DllLdr\.x64\.bin.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","41126" +"*DllLoaderLoader.exe*",".{0,1000}DllLoaderLoader\.exe.{0,1000}","offensive_tool_keyword","Ebowla","Framework for Making Environmental Keyed Payloads","T1027.002 - T1059.003 - T1140","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/Genetic-Malware/Ebowla","1","1","N/A","N/A","10","8","748","171","2019-01-28T10:45:15Z","2016-04-07T22:29:58Z","41130" +"*DllNotificationInjection.cpp*",".{0,1000}DllNotificationInjection\.cpp.{0,1000}","offensive_tool_keyword","DllNotificationInjection","A POC of a new threadless process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote processes.","T1055.011 - T1055.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/ShorSec/DllNotificationInjection","1","1","N/A","N/A","10","1","23","3","2023-08-23T13:50:27Z","2023-12-01T12:47:43Z","41132" +"*DllNotificationInjection.exe*",".{0,1000}DllNotificationInjection\.exe.{0,1000}","offensive_tool_keyword","DllNotificationInjection","A POC of a new threadless process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote processes.","T1055.011 - T1055.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/ShorSec/DllNotificationInjection","1","1","N/A","N/A","10","1","23","3","2023-08-23T13:50:27Z","2023-12-01T12:47:43Z","41133" +"*DllNotificationInjection.sln*",".{0,1000}DllNotificationInjection\.sln.{0,1000}","offensive_tool_keyword","DllNotificationInjection","A POC of a new threadless process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote processes.","T1055.011 - T1055.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/ShorSec/DllNotificationInjection","1","1","N/A","N/A","10","1","23","3","2023-08-23T13:50:27Z","2023-12-01T12:47:43Z","41134" +"*DllNotificationInjection.vcxproj*",".{0,1000}DllNotificationInjection\.vcxproj.{0,1000}","offensive_tool_keyword","DllNotificationInjection","A POC of a new threadless process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote processes.","T1055.011 - T1055.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/ShorSec/DllNotificationInjection","1","1","N/A","N/A","10","1","23","3","2023-08-23T13:50:27Z","2023-12-01T12:47:43Z","41135" +"*DllNotificationInjection-master*",".{0,1000}DllNotificationInjection\-master.{0,1000}","offensive_tool_keyword","DllNotificationInjection","A POC of a new threadless process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote processes.","T1055.011 - T1055.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/ShorSec/DllNotificationInjection","1","1","N/A","N/A","10","1","23","3","2023-08-23T13:50:27Z","2023-12-01T12:47:43Z","41136" +"*dllproxy.py*",".{0,1000}dllproxy\.py.{0,1000}","offensive_tool_keyword","DllProxy","Proxy your dll exports and add some spicy content at the same time","T1574.002 - T1036.005","TA0005 - TA0004","N/A","N/A","Exploitation tool","https://github.com/Iansus/DllProxy/","1","1","N/A","N/A","N/A","1","17","5","2023-06-28T14:19:36Z","2021-05-04T19:38:42Z","41137" +"*DllProxy-main*",".{0,1000}DllProxy\-main.{0,1000}","offensive_tool_keyword","DllProxy","Proxy your dll exports and add some spicy content at the same time","T1574.002 - T1036.005","TA0005 - TA0004","N/A","N/A","Exploitation tool","https://github.com/Iansus/DllProxy/","1","1","N/A","N/A","N/A","1","17","5","2023-06-28T14:19:36Z","2021-05-04T19:38:42Z","41138" +"*DLL-Spoofer-main*",".{0,1000}DLL\-Spoofer\-main.{0,1000}","offensive_tool_keyword","DLL-Spoofer","POC for a DLL spoofer to determine DLL Hijacking","T1574.002","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/MitchHS/DLL-Spoofer","1","1","N/A","N/A","9","1","60","7","2025-03-04T14:14:15Z","2023-10-18T14:34:38Z","41141" +"*dlyo7r3n4qy5fzv4645nddjwarj7wjdd6wzckomcyc7akskkxp4glcad.onion*",".{0,1000}dlyo7r3n4qy5fzv4645nddjwarj7wjdd6wzckomcyc7akskkxp4glcad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","41142" +"*dmcxblue/SharpBlackout*",".{0,1000}dmcxblue\/SharpBlackout.{0,1000}","offensive_tool_keyword","SharpBlackout","Terminate AV/EDR leveraging BYOVD attack","T1562.001 - T1050.005","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/dmcxblue/SharpBlackout","1","1","N/A","N/A","10","1","83","20","2025-03-21T16:33:42Z","2023-08-23T14:16:40Z","41143" +"*dmg2john.py*",".{0,1000}dmg2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","41145" +"*dnpscnbaix6nkwvystl3yxglz7nteicqrou3t75tpcc5532cztc46qyd.onion*",".{0,1000}dnpscnbaix6nkwvystl3yxglz7nteicqrou3t75tpcc5532cztc46qyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","41159" +"*dns.msfncsi.com*",".{0,1000}dns\.msfncsi\.com.{0,1000}","offensive_tool_keyword","BrowserSnatch","steals important data from all chromium and gecko browsers installed in the system and gather the data in a stealer db to be exfiltrated out. A powerful Browser Stealer","T1081 - T1074 - T1114 - T1005 - T1041 - T1027","TA0006 - TA0009 - TA0010","N/A","N/A","Data Exfiltration","https://github.com/shaddy43/BrowserSnatch","1","1","N/A","N/A","10","3","246","39","2025-03-31T21:04:30Z","2024-08-26T18:38:42Z","41162" +"*dns.spoof.address*",".{0,1000}dns\.spoof\.address.{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","41164" +"*dns.spoof.all*",".{0,1000}dns\.spoof\.all.{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","41165" +"*dns.spoof.domains*",".{0,1000}dns\.spoof\.domains.{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","41166" +"*dns.spoof.hosts*",".{0,1000}dns\.spoof\.hosts.{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","41167" +"*dns_beacon_beacon*",".{0,1000}dns_beacon_beacon.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","41168" +"*dns_beacon_dns_idle*",".{0,1000}dns_beacon_dns_idle.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","41169" +"*dns_beacon_dns_sleep*",".{0,1000}dns_beacon_dns_sleep.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","41170" +"*dns_beacon_dns_stager_prepend*",".{0,1000}dns_beacon_dns_stager_prepend.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","41171" +"*dns_beacon_dns_stager_subhost*",".{0,1000}dns_beacon_dns_stager_subhost.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","41172" +"*dns_beacon_dns_ttl*",".{0,1000}dns_beacon_dns_ttl.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","41173" +"*dns_beacon_get_A*",".{0,1000}dns_beacon_get_A.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","41174" +"*dns_beacon_get_TXT*",".{0,1000}dns_beacon_get_TXT.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","41175" +"*dns_beacon_maxdns*",".{0,1000}dns_beacon_maxdns.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","41176" +"*dns_beacon_ns_response*",".{0,1000}dns_beacon_ns_response.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","41177" +"*dns_beacon_put_metadata*",".{0,1000}dns_beacon_put_metadata.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","41178" +"*dns_beacon_put_output*",".{0,1000}dns_beacon_put_output.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","41179" +"*dns_bruteforce.rb*",".{0,1000}dns_bruteforce\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","41180" +"*dns_spoof.*",".{0,1000}dns_spoof\..{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","41183" +"*dns_stager_prepend*",".{0,1000}dns_stager_prepend.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","41184" +"*'dns_stager_prepend'*",".{0,1000}\'dns_stager_prepend\'.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","41185" +"*'dns_stager_subhost'*",".{0,1000}\'dns_stager_subhost\'.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","41186" +"*dns2tcp-*.zip*",".{0,1000}dns2tcp\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","dns2tcp","Dns2tcp is a tool for relaying TCP connections over DNS","T1071.004 - T1048.003","TA0011 - TA0001","N/A","N/A","C2","https://github.com/alex-sector/dns2tcp","1","1","N/A","N/A","10","10","191","60","2024-06-08T09:40:52Z","2017-11-23T11:19:53Z","41189" +"*dns2tcp.exe*",".{0,1000}dns2tcp\.exe.{0,1000}","offensive_tool_keyword","dns2tcp","Dns2tcp is a tool for relaying TCP connections over DNS","T1071.004 - T1048.003","TA0011 - TA0001","N/A","N/A","C2","https://github.com/alex-sector/dns2tcp","1","1","N/A","N/A","10","10","191","60","2024-06-08T09:40:52Z","2017-11-23T11:19:53Z","41190" +"*dns2tcp.hsc.fr*",".{0,1000}dns2tcp\.hsc\.fr.{0,1000}","offensive_tool_keyword","dns2tcp","Dns2tcp is a tool for relaying TCP connections over DNS","T1071.004 - T1048.003","TA0011 - TA0001","N/A","N/A","C2","https://github.com/alex-sector/dns2tcp","1","1","N/A","N/A","10","10","191","60","2024-06-08T09:40:52Z","2017-11-23T11:19:53Z","41191" +"*dns2tcp.kali.org*",".{0,1000}dns2tcp\.kali\.org.{0,1000}","offensive_tool_keyword","dns2tcp","Dns2tcp is a tool for relaying TCP connections over DNS","T1071.004 - T1048.003","TA0011 - TA0001","N/A","N/A","C2","https://github.com/alex-sector/dns2tcp","1","1","N/A","N/A","10","10","191","60","2024-06-08T09:40:52Z","2017-11-23T11:19:53Z","41192" +"*dns2tcpc.exe*",".{0,1000}dns2tcpc\.exe.{0,1000}","offensive_tool_keyword","dns2tcp","Dns2tcp is a tool for relaying TCP connections over DNS","T1071.004 - T1048.003","TA0011 - TA0001","N/A","N/A","C2","https://github.com/alex-sector/dns2tcp","1","1","N/A","N/A","10","10","191","60","2024-06-08T09:40:52Z","2017-11-23T11:19:53Z","41195" +"*dns2tcp-master*",".{0,1000}dns2tcp\-master.{0,1000}","offensive_tool_keyword","dns2tcp","Dns2tcp is a tool for relaying TCP connections over DNS","T1071.004 - T1048.003","TA0011 - TA0001","N/A","N/A","C2","https://github.com/alex-sector/dns2tcp","1","1","N/A","N/A","10","10","191","60","2024-06-08T09:40:52Z","2017-11-23T11:19:53Z","41198" +"*dnsadmin_serverlevelplugindll.*",".{0,1000}dnsadmin_serverlevelplugindll\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","41199" +"*DNSAES256Handler.*",".{0,1000}DNSAES256Handler\..{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","41200" +"*dns-black-cat-main*",".{0,1000}dns\-black\-cat\-main.{0,1000}","offensive_tool_keyword","dns-black-cat","Multi platform toolkit for an interactive DNS shell commands exfiltration - by using DNS-Cat you will be able to execute system commands in shell mode over DNS protocol","T1140 - T1048.003 - T1071.004","TA0011 - TA0040 - TA0001","N/A","N/A","C2","https://github.com/lawrenceamer/dns-black-cat","1","1","N/A","N/A","10","10","114","20","2022-09-15T18:07:05Z","2021-02-13T11:31:22Z","41202" +"*dnscan-master*",".{0,1000}dnscan\-master.{0,1000}","offensive_tool_keyword","dnscan","dnscan is a python wordlist-based DNS subdomain scanner.","T1595 - T1595.002 - T1018 - T1046","TA0007 - TA0043","N/A","N/A","Reconnaissance","https://github.com/rbsec/dnscan","1","1","N/A","N/A","6","10","1193","410","2024-12-17T15:29:50Z","2013-03-13T10:42:07Z","41204" +"*dnscat2*.tar.bz2*",".{0,1000}dnscat2.{0,1000}\.tar\.bz2.{0,1000}","offensive_tool_keyword","dnscat","This tool is designed to create an encrypted command-and-control (C&C) channel over the DNS protocol","T1071.004 - T1102 - T1071.001","TA0002 - TA0003 - TA0008","N/A","EMBER BEAR","C2","https://github.com/iagox86/dnscat2","1","1","#linux","N/A","10","10","3566","618","2024-03-14T11:17:49Z","2013-01-04T23:15:55Z","41210" +"*dnscat2-*.zip*",".{0,1000}dnscat2\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","dnscat","This tool is designed to create an encrypted command-and-control (C&C) channel over the DNS protocol","T1071.004 - T1102 - T1071.001","TA0002 - TA0003 - TA0008","N/A","EMBER BEAR","C2","https://github.com/iagox86/dnscat2","1","1","#linux","N/A","10","10","3566","618","2024-03-14T11:17:49Z","2013-01-04T23:15:55Z","41211" +"*dnscat2.*",".{0,1000}dnscat2\..{0,1000}","offensive_tool_keyword","dnscat","This tool is designed to create an encrypted command-and-control (C&C) channel over the DNS protocol","T1071.004 - T1102 - T1071.001","TA0002 - TA0003 - TA0008","N/A","EMBER BEAR","C2","https://github.com/iagox86/dnscat2","1","1","#linux","N/A","10","10","3566","618","2024-03-14T11:17:49Z","2013-01-04T23:15:55Z","41212" +"*dnscat2.ps1*",".{0,1000}dnscat2\.ps1.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","41213" +"*dnscat2/*",".{0,1000}dnscat2\/.{0,1000}","offensive_tool_keyword","dnscat","This tool is designed to create an encrypted command-and-control (C&C) channel over the DNS protocol","T1071.004 - T1102 - T1071.001","TA0002 - TA0003 - TA0008","N/A","EMBER BEAR","C2","https://github.com/iagox86/dnscat2","1","1","#linux","N/A","10","10","3566","618","2024-03-14T11:17:49Z","2013-01-04T23:15:55Z","41214" +"*dnscat2-server*",".{0,1000}dnscat2\-server.{0,1000}","offensive_tool_keyword","dnscat","This tool is designed to create an encrypted command-and-control (C&C) channel over the DNS protocol","T1071.004 - T1102 - T1071.001","TA0002 - TA0003 - TA0008","N/A","EMBER BEAR","C2","https://github.com/iagox86/dnscat2","1","1","N/A","N/A","10","10","3566","618","2024-03-14T11:17:49Z","2013-01-04T23:15:55Z","41215" +"*dnscat2-win32.exe*",".{0,1000}dnscat2\-win32\.exe.{0,1000}","offensive_tool_keyword","dnscat","This tool is designed to create an encrypted command-and-control (C&C) channel over the DNS protocol","T1071.004 - T1102 - T1071.001","TA0002 - TA0003 - TA0008","N/A","EMBER BEAR","C2","https://github.com/iagox86/dnscat2","1","1","N/A","N/A","10","10","3566","618","2024-03-14T11:17:49Z","2013-01-04T23:15:55Z","41216" +"*dnschef-ng-main*",".{0,1000}dnschef\-ng\-main.{0,1000}","offensive_tool_keyword","dnschef-ng","DNSChef is a highly configurable DNS proxy for Penetration Testers and Malware Analysts. A DNS proxy (aka ""Fake DNS"") is a tool used for application network traffic analysis among other uses. For example - a DNS proxy can be used to fake requests for ""badguy.com"" to point to a local machine for termination or interception instead of a real host somewhere on the Internet.","T1568 - T1583 - T1071","TA0001 - TA0042 - TA0005","N/A","N/A","Sniffing & Spoofing","https://github.com/byt3bl33d3r/dnschef-ng","1","1","N/A","N/A","8","2","153","14","2023-11-26T06:57:04Z","2021-12-24T21:07:29Z","41222" +"*DNSCrypt/dnscrypt-proxy*",".{0,1000}DNSCrypt\/dnscrypt\-proxy.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41226" +"*dnscryptproxy.exe*",".{0,1000}dnscryptproxy\.exe.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41230" +"*dnscrypt-proxy.exe*",".{0,1000}dnscrypt\-proxy\.exe.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41231" +"*dnscrypt-proxy-android_arm-*.zip*",".{0,1000}dnscrypt\-proxy\-android_arm\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41234" +"*dnscrypt-proxy-android_arm64-*.zip*",".{0,1000}dnscrypt\-proxy\-android_arm64\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41235" +"*dnscrypt-proxy-android_i386-*.zip*",".{0,1000}dnscrypt\-proxy\-android_i386\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41236" +"*dnscrypt-proxy-android_x86_64-*.zip*",".{0,1000}dnscrypt\-proxy\-android_x86_64\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41237" +"*dnscrypt-proxy-dragonflybsd_amd64-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-dragonflybsd_amd64\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41238" +"*dnscrypt-proxy-freebsd_amd64-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-freebsd_amd64\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41239" +"*dnscrypt-proxy-freebsd_arm-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-freebsd_arm\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41240" +"*dnscrypt-proxy-freebsd_i386-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-freebsd_i386\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41241" +"*dnscrypt-proxy-linux_arm-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-linux_arm\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","#linux","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41242" +"*dnscrypt-proxy-linux_arm64-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-linux_arm64\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","#linux","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41243" +"*dnscrypt-proxy-linux_i386-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-linux_i386\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","#linux","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41244" +"*dnscrypt-proxy-linux_mips-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-linux_mips\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","#linux","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41245" +"*dnscrypt-proxy-linux_mips64-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-linux_mips64\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","#linux","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41246" +"*dnscrypt-proxy-linux_mips64le-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-linux_mips64le\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","#linux","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41247" +"*dnscrypt-proxy-linux_mipsle-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-linux_mipsle\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","#linux","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41248" +"*dnscrypt-proxy-linux_riscv64-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-linux_riscv64\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","#linux","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41249" +"*dnscrypt-proxy-linux_x86_64-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-linux_x86_64\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","#linux","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41250" +"*dnscrypt-proxy-macos_arm64-*.zip*",".{0,1000}dnscrypt\-proxy\-macos_arm64\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41251" +"*dnscrypt-proxy-macos_x86_64-*.zip*",".{0,1000}dnscrypt\-proxy\-macos_x86_64\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41252" +"*dnscrypt-proxy-master*",".{0,1000}dnscrypt\-proxy\-master.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41253" +"*dnscrypt-proxy-netbsd_amd64-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-netbsd_amd64\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41254" +"*dnscrypt-proxy-netbsd_i386-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-netbsd_i386\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41255" +"*dnscrypt-proxy-openbsd_amd64-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-openbsd_amd64\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41256" +"*dnscrypt-proxy-openbsd_i386-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-openbsd_i386\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41257" +"*dnscrypt-proxy-solaris_amd64-*.tar.gz*",".{0,1000}dnscrypt\-proxy\-solaris_amd64\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41258" +"*dnscrypt-proxy-win32-*.zip*",".{0,1000}dnscrypt\-proxy\-win32\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41259" +"*dnscrypt-proxy-win64-*.zip*",".{0,1000}dnscrypt\-proxy\-win64\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","41260" +"*dnsenum.pl*",".{0,1000}dnsenum\.pl.{0,1000}","offensive_tool_keyword","dnsenum","multithreaded perl script to enumerate DNS information of a domain and to discover non-contiguous ip blocks.","T1218 - T1018 - T1190 - T1590 - T1012","TA0002 - TA0007","N/A","N/A","Reconnaissance","https://github.com/fwaeytens/dnsenum","1","1","#linux","N/A","N/A","7","634","139","2019-10-08T19:58:40Z","2014-01-10T14:47:09Z","41262" +"*dnsExfiltrator.exe*",".{0,1000}dnsExfiltrator\.exe.{0,1000}","offensive_tool_keyword","DNSExfiltrator","DNSExfiltrator allows for transfering (exfiltrate) a file over a DNS request covert channel. This is basically a data leak testing tool allowing to exfiltrate data over a covert channel.","T1041 - T1048","TA0010 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/Arno0x/DNSExfiltrator","1","1","N/A","N/A","10","9","867","188","2024-04-29T20:20:43Z","2017-12-20T13:58:09Z","41263" +"*DNSExfiltratorLib*",".{0,1000}DNSExfiltratorLib.{0,1000}","offensive_tool_keyword","DNSExfiltrator","DNSExfiltrator allows for transfering (exfiltrate) a file over a DNS request covert channel. This is basically a data leak testing tool allowing to exfiltrate data over a covert channel.","T1041 - T1048","TA0010 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/Arno0x/DNSExfiltrator","1","1","N/A","N/A","10","9","867","188","2024-04-29T20:20:43Z","2017-12-20T13:58:09Z","41264" +"*DNSListener.py*",".{0,1000}DNSListener\.py.{0,1000}","offensive_tool_keyword","DNS-Persist","DNS-Persist is a post-exploitation agent which uses DNS for command and control.","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/0x09AL/DNS-Persist","1","1","N/A","N/A","10","10","211","65","2017-11-20T08:53:25Z","2017-11-10T15:23:49Z","41269" +"*dnslog--airvent.txt*",".{0,1000}dnslog\-\-airvent\.txt.{0,1000}","offensive_tool_keyword","DeNiSe","DeNiSe is a proof of concept for tunneling TCP over DNS in Python","T1071.004 - T1048.003","TA0011 - TA0010 - TA0001","N/A","N/A","C2","https://github.com/mdornseif/DeNiSe","1","1","N/A","N/A","10","10","28","13","2021-12-17T18:03:33Z","2010-01-15T07:43:14Z","41270" +"*dnsmastermind.rb*",".{0,1000}dnsmastermind\.rb.{0,1000}","offensive_tool_keyword","dnscat","This tool is designed to create an encrypted command-and-control (C&C) channel over the DNS protocol","T1071.004 - T1102 - T1071.001","TA0002 - TA0003 - TA0008","N/A","EMBER BEAR","C2","https://github.com/iagox86/dnscat2","1","1","#linux","N/A","10","10","3566","618","2024-03-14T11:17:49Z","2013-01-04T23:15:55Z","41272" +"*dnsmorph*",".{0,1000}dnsmorph.{0,1000}","offensive_tool_keyword","dnsmorph","DNSMORPH is a domain name permutation engine. inspired by dnstwist. It is written in Go making for a compact and very fast tool. It robustly handles any domain or subdomain supplied and provides a number of configuration options to tune permutation runs.","T1568.002 - T1568.003 - T1568.001 - T1568.004","TA0009 - TA0011","N/A","N/A","Phishing","https://github.com/netevert/dnsmorph","1","1","N/A","N/A","N/A","3","266","43","2023-08-08T06:38:59Z","2018-02-20T19:13:35Z","41273" +"*dnspayload.bin*",".{0,1000}dnspayload\.bin.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike payload generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dr0op/CrossNet-Beta","1","1","N/A","N/A","10","10","362","58","2024-06-19T07:02:22Z","2021-02-08T10:52:39Z","41274" +"*DNS-Persist.git*",".{0,1000}DNS\-Persist\.git.{0,1000}","offensive_tool_keyword","DNS-Persist","DNS-Persist is a post-exploitation agent which uses DNS for command and control.","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/0x09AL/DNS-Persist","1","1","N/A","N/A","10","10","211","65","2017-11-20T08:53:25Z","2017-11-10T15:23:49Z","41275" +"*dnspot-agent-cli-*",".{0,1000}dnspot\-agent\-cli\-.{0,1000}","offensive_tool_keyword","dnspot","End-to-end Encrypted DNS Tunnelling and C2 framework","T1071.004 - T1090.002 - T1573.002","TA0011 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/mosajjal/dnspot","1","1","N/A","N/A","10","10","73","16","2025-02-01T08:13:29Z","2021-09-25T08:49:43Z","41276" +"*dnspot-server-cli-*",".{0,1000}dnspot\-server\-cli\-.{0,1000}","offensive_tool_keyword","dnspot","End-to-end Encrypted DNS Tunnelling and C2 framework","T1071.004 - T1090.002 - T1573.002","TA0011 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/mosajjal/dnspot","1","1","N/A","N/A","10","10","73","16","2025-02-01T08:13:29Z","2021-09-25T08:49:43Z","41277" +"*dnspot-server-tui-*",".{0,1000}dnspot\-server\-tui\-.{0,1000}","offensive_tool_keyword","dnspot","End-to-end Encrypted DNS Tunnelling and C2 framework","T1071.004 - T1090.002 - T1573.002","TA0011 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/mosajjal/dnspot","1","1","N/A","N/A","10","10","73","16","2025-02-01T08:13:29Z","2021-09-25T08:49:43Z","41278" +"*dnsrecon*",".{0,1000}dnsrecon.{0,1000}","offensive_tool_keyword","dnsrecon","DNSRecon is a Python port of a Ruby script that I wrote to learn the language and about DNS in early 2007. This time I wanted to learn about Python and extend the functionality of the original tool and in the process re-learn how DNS works and how could it be used in the process of a security assessment and network troubleshooting.","T1590 - T1590.001","TA0001 - TA0007","N/A","N/A","Discovery","https://github.com/darkoperator/dnsrecon","1","1","#linux","N/A","6","10","2755","556","2025-04-18T05:31:08Z","2010-12-16T03:25:49Z","41281" +"*DnsSpoof.ps1*",".{0,1000}DnsSpoof\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","41283" +"*dnsteal.git*",".{0,1000}dnsteal\.git.{0,1000}","offensive_tool_keyword","dnsteal","This is a fake DNS server that allows you to stealthily extract files from a victim machine through DNS requests.","T1048.003 - T1568.002 - T1573.002","TA0010 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/m57/dnsteal","1","1","N/A","N/A","3","10","1694","231","2022-02-03T11:04:49Z","2015-08-11T17:02:58Z","41286" +"*dnsteal.py*",".{0,1000}dnsteal\.py.{0,1000}","offensive_tool_keyword","dnsteal","This is a fake DNS server that allows you to stealthily extract files from a victim machine through DNS requests.","T1048.003 - T1568.002 - T1573.002","TA0010 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/m57/dnsteal","1","1","N/A","N/A","3","10","1694","231","2022-02-03T11:04:49Z","2015-08-11T17:02:58Z","41287" +"*dnsteal-master*",".{0,1000}dnsteal\-master.{0,1000}","offensive_tool_keyword","dnsteal","This is a fake DNS server that allows you to stealthily extract files from a victim machine through DNS requests.","T1048.003 - T1568.002 - T1573.002","TA0010 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/m57/dnsteal","1","1","N/A","N/A","3","10","1694","231","2022-02-03T11:04:49Z","2015-08-11T17:02:58Z","41288" +"*DNS-Tunnel-Keylogger*",".{0,1000}DNS\-Tunnel\-Keylogger.{0,1000}","offensive_tool_keyword","DNS-Tunnel-Keylogger","Keylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokes","T1056.001 - T1048.003","TA0009 - TA0011","N/A","N/A","Collection","https://github.com/Geeoon/DNS-Tunnel-Keylogger","1","1","N/A","N/A","9","3","273","40","2024-06-16T19:47:36Z","2024-01-10T17:25:58Z","41290" +"*Do-AltShiftEsc*",".{0,1000}Do\-AltShiftEsc.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-MS16135.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","41305" +"*Do-AltShiftTab*",".{0,1000}Do\-AltShiftTab.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-MS16135.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","41306" +"*doc/extras/HACKING.*",".{0,1000}doc\/extras\/HACKING\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","41307" +"*docker/gsocket*",".{0,1000}docker\/gsocket.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","41347" +"*DocPlz-main.zip*",".{0,1000}DocPlz\-main\.zip.{0,1000}","offensive_tool_keyword","DocPlz","Documents Exfiltration and C2 project","T1105 - T1567 - T1071","TA0011 - TA0010 - TA0009","N/A","N/A","Data Exfiltration","https://github.com/TheD1rkMtr/DocPlz","1","1","N/A","N/A","10","2","145","30","2023-10-10T19:01:42Z","2023-10-02T20:49:22Z","41351" +"*docs.mythic-c2.net*",".{0,1000}docs\.mythic\-c2\.net.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","N/A","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","41352" +"*docs.mythic-c2.net*",".{0,1000}docs\.mythic\-c2\.net.{0,1000}","offensive_tool_keyword","mythic","Thanatos is a Windows and Linux C2 agent written in rust.","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/thanatos","1","1","N/A","N/A","10","10","333","49","2024-12-19T19:07:03Z","2022-03-07T20:35:33Z","41353" +"*Do-Exfiltration.ps1*",".{0,1000}Do\-Exfiltration\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","41357" +"*Doge-Loader*xor.go*",".{0,1000}Doge\-Loader.{0,1000}xor\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Shellcode Loader by Golang","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/timwhitez/Doge-Loader","1","1","N/A","N/A","10","10","280","57","2021-04-22T08:24:59Z","2020-10-09T04:47:54Z","41358" +"*DoHC2*BeaconConnector*",".{0,1000}DoHC2.{0,1000}BeaconConnector.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","41359" +"*DoHC2.exe*",".{0,1000}DoHC2\.exe.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","41360" +"*DoHC2.py*",".{0,1000}DoHC2\.py.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","41361" +"*DoHC2Runner.*",".{0,1000}DoHC2Runner\..{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","41362" +"*DoHC2Runner.exe*",".{0,1000}DoHC2Runner\.exe.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","41363" +"*DoHC2Runner.pdb*",".{0,1000}DoHC2Runner\.pdb.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","41364" +"*Domain/CommandCollection*",".{0,1000}Domain\/CommandCollection.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","41369" +"*domain_analyzer.py*",".{0,1000}domain_analyzer\.py.{0,1000}","offensive_tool_keyword","domain_analyzer","Analyze the security of any domain by finding all the information possible","T1560 - T1590 - T1200 - T1213 - T1057","TA0002 - TA0009","N/A","N/A","Reconnaissance","https://github.com/eldraco/domain_analyzer","1","1","N/A","N/A","6","10","1858","241","2022-12-29T10:57:33Z","2017-08-08T18:52:34Z","41371" +"*domain_analyzer-master*",".{0,1000}domain_analyzer\-master.{0,1000}","offensive_tool_keyword","domain_analyzer","Analyze the security of any domain by finding all the information possible","T1560 - T1590 - T1200 - T1213 - T1057","TA0002 - TA0009","N/A","N/A","Reconnaissance","https://github.com/eldraco/domain_analyzer","1","1","N/A","N/A","6","10","1858","241","2022-12-29T10:57:33Z","2017-08-08T18:52:34Z","41372" +"*domain_hunter-v*.jar",".{0,1000}domain_hunter\-v.{0,1000}\.jar","offensive_tool_keyword","burpsuite","Collection of burpsuite plugins","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","network exploitation tool","N/A","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","41373" +"*domainDumpConfig*",".{0,1000}domainDumpConfig.{0,1000}","offensive_tool_keyword","ldapdomaindump","Active Directory information dumper via LDAP","T1087 - T1005 - T1016","TA0007","N/A","EMBER BEAR","Discovery","https://github.com/dirkjanm/ldapdomaindump","1","1","N/A","N/A","10","10","1242","201","2025-04-06T13:31:57Z","2016-05-24T18:46:56Z","41374" +"*DomainEnumerator*",".{0,1000}DomainEnumerator.{0,1000}","offensive_tool_keyword","BloodHound","A Python based ingestor for BloodHound","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/fox-it/BloodHound.py","1","1","N/A","N/A","10","10","2088","343","2025-03-28T11:19:13Z","2018-02-26T14:44:20Z","41375" +"*domainhunter.py*",".{0,1000}domainhunter\.py.{0,1000}","offensive_tool_keyword","domainhunter","Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names ","T1583.002 - T1568.002","TA0011 - TA0009","N/A","N/A","Phishing","https://github.com/threatexpress/domainhunter","1","1","N/A","N/A","N/A","10","1587","292","2024-06-06T21:01:21Z","2017-03-01T11:16:26Z","41377" +"*Domaininfo/Domaininfo.py*",".{0,1000}Domaininfo\/Domaininfo\.py.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","41378" +"*Domainpassspray*",".{0,1000}Domainpassspray.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","41379" +"*DomainPasswordSpray*",".{0,1000}DomainPasswordSpray.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAREFUL NOT TO LOCKOUT ACCOUNTS!","t1110 - T1114 - T1555","TA0006 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","1","N/A","N/A","N/A","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","41380" +"*DomainPasswordSpray.ps1*",".{0,1000}DomainPasswordSpray\.ps1.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","1","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","41381" +"*DomainPasswordSpray.ps1*",".{0,1000}DomainPasswordSpray\.ps1.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","1","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","41382" +"*DomainRecon*ridbrute*",".{0,1000}DomainRecon.{0,1000}ridbrute.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","41384" +"*DomainRecon/ADCS*",".{0,1000}DomainRecon\/ADCS.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","41385" +"*DomainRecon/BloodHound*",".{0,1000}DomainRecon\/BloodHound.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","41386" +"*DomainRecon/SilentHound*",".{0,1000}DomainRecon\/SilentHound.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","41387" +"*DomainTrustDiscovery_PowerView.py*",".{0,1000}DomainTrustDiscovery_PowerView\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","41393" +"*domcachedump.py*",".{0,1000}domcachedump\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41394" +"*domcachedumplive.py*",".{0,1000}domcachedumplive\.py.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","1","N/A","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","41395" +"*DominicBreuker/pspy*",".{0,1000}DominicBreuker\/pspy.{0,1000}","offensive_tool_keyword","pspy","Monitor linux processes without root permissions","T1057 - T1514 - T1082","TA0007 - TA0009 - TA0003","N/A","N/A","Discovery","https://github.com/DominicBreuker/pspy","1","1","#linux","N/A","6","10","5370","538","2023-01-17T21:09:22Z","2018-02-08T21:41:37Z","41397" +"*DominicBreuker/pspy*",".{0,1000}DominicBreuker\/pspy.{0,1000}","offensive_tool_keyword","pspy","Monitor linux processes without root permissions","T1057 - T1082 - T1518.001","TA0007","N/A","N/A","Discovery","https://github.com/DominicBreuker/pspy","1","1","#linux","N/A","8","10","5370","538","2023-01-17T21:09:22Z","2018-02-08T21:41:37Z","41398" +"*donpapi_dump*",".{0,1000}donpapi_dump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","41412" +"*donpapi-master.zip*",".{0,1000}donpapi\-master\.zip.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41413" +"*DONUT_BYPASS_CONTINUE*",".{0,1000}DONUT_BYPASS_CONTINUE.{0,1000}","offensive_tool_keyword","donut","Donut is a position-independent code that enables in-memory execution of VBScript. JScript. EXE. DLL files and dotNET assemblies. A module created by Donut can either be staged from a HTTP server or embedded directly in the loader itself","T1071.001 - T1059 - T1059.001 - T1059.005 - T1059.006 - T1059.007 - T1562.001 - T1070 - T1105 - T1106 - T1027 - T1027.002 - T1057 - T1055 - T1620","TA0011 - TA0002 - TA0005 - TA0008 - TA0004 - TA0007 - TA0003 - TA0006 - TA0010","N/A","Indrik Spider","Exploitation tool","https://github.com/TheWover/donut","1","1","N/A","N/A","N/A","10","3882","667","2024-10-23T12:19:13Z","2019-03-27T23:24:44Z","41423" +"*DonutLoader.cs*",".{0,1000}DonutLoader\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","41427" +"*donut-payload.*",".{0,1000}donut\-payload\..{0,1000}","offensive_tool_keyword","donut","Donut is a position-independent code that enables in-memory execution of VBScript. JScript. EXE. DLL files and dotNET assemblies. A module created by Donut can either be staged from a HTTP server or embedded directly in the loader itself","T1071.001 - T1059 - T1059.001 - T1059.005 - T1059.006 - T1059.007 - T1562.001 - T1070 - T1105 - T1106 - T1027 - T1027.002 - T1057 - T1055 - T1620","TA0011 - TA0002 - TA0005 - TA0008 - TA0004 - TA0007 - TA0003 - TA0006 - TA0010","N/A","Indrik Spider","Exploitation tool","https://github.com/TheWover/donut","1","1","N/A","N/A","N/A","10","3882","667","2024-10-23T12:19:13Z","2019-03-27T23:24:44Z","41430" +"*donut-shellcode*",".{0,1000}donut\-shellcode.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","41431" +"*donut-shellcode*",".{0,1000}donut\-shellcode.{0,1000}","offensive_tool_keyword","donut","Donut is a position-independent code that enables in-memory execution of VBScript. JScript. EXE. DLL files and dotNET assemblies. A module created by Donut can either be staged from a HTTP server or embedded directly in the loader itself","T1071.001 - T1059 - T1059.001 - T1059.005 - T1059.006 - T1059.007 - T1562.001 - T1070 - T1105 - T1106 - T1027 - T1027.002 - T1057 - T1055 - T1620","TA0011 - TA0002 - TA0005 - TA0008 - TA0004 - TA0007 - TA0003 - TA0006 - TA0010","N/A","Indrik Spider","Exploitation tool","https://github.com/TheWover/donut","1","1","N/A","N/A","N/A","10","3882","667","2024-10-23T12:19:13Z","2019-03-27T23:24:44Z","41432" +"*donut-shellcode*",".{0,1000}donut\-shellcode.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","41433" +"*doredry/TokenFinder*",".{0,1000}doredry\/TokenFinder.{0,1000}","offensive_tool_keyword","TokenFinder","Tool to extract powerful tokens from Office desktop apps memory","T1003 - T1081 - T1110","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/doredry/TokenFinder","1","1","N/A","N/A","9","1","71","10","2024-03-01T14:27:34Z","2022-09-21T14:21:07Z","41434" +"*dotnet_serve_payload*",".{0,1000}dotnet_serve_payload.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","41442" +"*DotNet2JSImplant*",".{0,1000}DotNet2JSImplant.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","41443" +"*DotNetArtifactGenerator.py*",".{0,1000}DotNetArtifactGenerator\.py.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","41444" +"*DoubleAgent.sln*",".{0,1000}DoubleAgent\.sln.{0,1000}","offensive_tool_keyword","DoubleAgent","DoubleAgent gives the attacker the ability to inject any DLL into any process. The code injection occurs extremely early during the victims process boot. giving the attacker full control over the process and no way for the process to protect itself. The code injection technique is so unique that its not detected or blocked by any antivirus.DoubleAgent can continue injecting code even after reboot making it a perfect persistence technique to survive reboots/updates/reinstalls/patches/etc. Once the attacker decides to inject a DLL into a process. they are forcefully bounded forever. Even if the victim would completely uninstall and reinstall its program. the attackers DLL would still be injected every time the process executes.","T1055 - T1059 - T1053","TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/Cybellum/DoubleAgent","1","1","N/A","N/A","N/A","10","1228","414","2022-08-24T10:32:36Z","2017-03-12T17:05:57Z","41445" +"*download keylog.exe*",".{0,1000}download\skeylog\.exe.{0,1000}","offensive_tool_keyword","Powershell-Scripts-for-Hackers-and-Pentesters","","T1059.001 - T1119 - T1027 - T1016 - T1056.001","TA0002 - TA0009 - TA0005 - TA0007 - TA0010","N/A","N/A","Collection","https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters","1","1","N/A","N/A","10","5","415","49","2025-02-23T09:05:44Z","2023-02-27T14:27:32Z","41454" +"*download.nus.edu.sg/mirror/blackarch/*/os/*",".{0,1000}download\.nus\.edu\.sg\/mirror\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","41459" +"*download.weakpass.com/*",".{0,1000}download\.weakpass\.com\/.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","41464" +"*Download:Cradle.js*",".{0,1000}Download\:Cradle\.js.{0,1000}","offensive_tool_keyword","Payload-Download-Cradles","This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context of download cradle detections.","T1105 - T1203 - T1221 - T1027 - T1036","TA0005 - TA0002 - TA0011 - TA0009","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Payload-Download-Cradles","1","1","N/A","N/A","N/A","3","256","51","2022-07-07T07:20:36Z","2021-05-14T08:56:54Z","41466" +"*Download_Cradles.*",".{0,1000}Download_Cradles\..{0,1000}","offensive_tool_keyword","Payload-Download-Cradles","This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context of download cradle detections.","T1105 - T1203 - T1221 - T1027 - T1036","TA0005 - TA0002 - TA0011 - TA0009","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Payload-Download-Cradles","1","1","N/A","N/A","N/A","3","256","51","2022-07-07T07:20:36Z","2021-05-14T08:56:54Z","41467" +"*Download_Execute*",".{0,1000}Download_Execute.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","41468" +"*DownloadAndExtractFromRemoteRegistry*",".{0,1000}DownloadAndExtractFromRemoteRegistry.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","41470" +"*DownloadAndExtractFromRemoteRegistry*",".{0,1000}DownloadAndExtractFromRemoteRegistry.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","41471" +"*Download-Cradles.cmd*",".{0,1000}Download\-Cradles\.cmd.{0,1000}","offensive_tool_keyword","Payload-Download-Cradles","This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context of download cradle detections.","T1105 - T1203 - T1221 - T1027 - T1036","TA0005 - TA0002 - TA0011 - TA0009","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Payload-Download-Cradles","1","1","N/A","N/A","N/A","3","256","51","2022-07-07T07:20:36Z","2021-05-14T08:56:54Z","41472" +"*downloadexec_UACbypass.lua*",".{0,1000}downloadexec_UACbypass\.lua.{0,1000}","offensive_tool_keyword","OffensiveLua","Offensive Lua is a collection of offensive security scripts written in Lua with FFI","T1059 - T1218.011 - T1105 - T1021.002 - T1564.001 - T1112 - T1113 - T1204.002 - T1547.002","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hackerhouse-opensource/OffensiveLua","1","1","N/A","N/A","8","2","184","25","2023-11-17T00:35:10Z","2023-10-25T17:21:13Z","41473" +"*Download-Execute-PS*",".{0,1000}Download\-Execute\-PS.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","41474" +"*DownloadFileImplant*",".{0,1000}DownloadFileImplant.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","41475" +"*downloadshellcodebin.c*",".{0,1000}downloadshellcodebin\.c.{0,1000}","offensive_tool_keyword","DKMC","Malicious payload evasion tool","T1027 - T1055.012","TA0005 - TA0040","N/A","Molerats","Defense Evasion","https://github.com/Mr-Un1k0d3r/DKMC","1","1","N/A","N/A","10","10","1392","290","2020-07-20T03:36:56Z","2016-12-05T03:44:07Z","41493" +"*downloadshellcodebin.exe*",".{0,1000}downloadshellcodebin\.exe.{0,1000}","offensive_tool_keyword","DKMC","Malicious payload evasion tool","T1027 - T1055.012","TA0005 - TA0040","N/A","Molerats","Defense Evasion","https://github.com/Mr-Un1k0d3r/DKMC","1","1","N/A","N/A","10","10","1392","290","2020-07-20T03:36:56Z","2016-12-05T03:44:07Z","41494" +"*dpapi/decryptor.py*",".{0,1000}dpapi\/decryptor\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","10","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","41499" +"*dpapi_dump*",".{0,1000}dpapi_dump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","41521" +"*dpapi_dump_*.txt*",".{0,1000}dpapi_dump_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","41522" +"*dpapi_pick/credhist.py*",".{0,1000}dpapi_pick\/credhist\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41523" +"*DPAPImk2john.py*",".{0,1000}DPAPImk2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","41524" +"*dpl4hydra.sh*",".{0,1000}dpl4hydra\.sh.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","41526" +"*dpl4hydra_*.csv*",".{0,1000}dpl4hydra_.{0,1000}\.csv.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","41527" +"*dpl4hydra_*.tmp*",".{0,1000}dpl4hydra_.{0,1000}\.tmp.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","41528" +"*dpl4hydra_linksys*",".{0,1000}dpl4hydra_linksys.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","41529" +"*dploot*backupkey*",".{0,1000}dploot.{0,1000}backupkey.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41532" +"*dploot*browser*",".{0,1000}dploot.{0,1000}browser.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41533" +"*dploot*certificates*",".{0,1000}dploot.{0,1000}certificates.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41534" +"*dploot*credentials*",".{0,1000}dploot.{0,1000}credentials.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41535" +"*dploot*machinecertificates*",".{0,1000}dploot.{0,1000}machinecertificates.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41536" +"*dploot*machinecredentials*",".{0,1000}dploot.{0,1000}machinecredentials.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41537" +"*dploot*machinemasterkeys*",".{0,1000}dploot.{0,1000}machinemasterkeys.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41538" +"*dploot*machinevaults*",".{0,1000}dploot.{0,1000}machinevaults.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41539" +"*dploot*masterkeys*",".{0,1000}dploot.{0,1000}masterkeys.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41540" +"*dploot*vaults*",".{0,1000}dploot.{0,1000}vaults.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41541" +"*dploot*wifi*",".{0,1000}dploot.{0,1000}wifi.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41542" +"*dploot/releases/download/*/dploot*",".{0,1000}dploot\/releases\/download\/.{0,1000}\/dploot.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41547" +"*dploot_linux_adm64*",".{0,1000}dploot_linux_adm64.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","#linux","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41548" +"*dploot-main.zip*",".{0,1000}dploot\-main\.zip.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41549" +"*dr0op/CrossNet*",".{0,1000}dr0op\/CrossNet.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike payload generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dr0op/CrossNet-Beta","1","1","N/A","N/A","10","10","362","58","2024-06-19T07:02:22Z","2021-02-08T10:52:39Z","41553" +"*Dr0p1t-Framework*",".{0,1000}Dr0p1t\-Framework.{0,1000}","offensive_tool_keyword","Dr0p1t-Framework","Have you ever heard about trojan droppers ? In short dropper is type of malware that downloads other malwares and Dr0p1t gives you the chance to create a stealthy dropper that bypass most AVs and have a lot of tricks ( Trust me :D ) .)","T1203 - T1005 - T1064","TA0002 - TA0003 - TA0040","N/A","N/A","Exploitation tool","https://github.com/D4Vinci/Dr0p1t-Framework","1","1","N/A","N/A","N/A","10","1409","377","2018-11-03T19:00:12Z","2017-02-11T21:24:11Z","41554" +"*dr4k0nia/NixImports*",".{0,1000}dr4k0nia\/NixImports.{0,1000}","offensive_tool_keyword","NixImports","A .NET malware loader using API-Hashing to evade static analysis","T1055.012 - T1562.001 - T1140","TA0005 - TA0003 - TA0040","N/A","N/A","Defense Evasion","https://github.com/dr4k0nia/NixImports","1","1","N/A","N/A","N/A","3","207","23","2023-05-30T14:14:21Z","2023-05-22T18:32:01Z","41555" +"*DReverseProxy.git*",".{0,1000}DReverseProxy\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool that can perform reverse proxy and cs online without going online","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Daybr4ak/C2ReverseProxy","1","1","N/A","N/A","10","10","486","56","2023-04-26T13:16:26Z","2020-01-16T05:43:35Z","41559" +"*DReverseServer.go*",".{0,1000}DReverseServer\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool that can perform reverse proxy and cs online without going online","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Daybr4ak/C2ReverseProxy","1","1","N/A","N/A","10","10","486","56","2023-04-26T13:16:26Z","2020-01-16T05:43:35Z","41560" +"*drgreenthumb93/CVE-2022-30190-follina*",".{0,1000}drgreenthumb93\/CVE\-2022\-30190\-follina.{0,1000}","offensive_tool_keyword","POC","Just another PoC for the new MSDT-Exploit","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/drgreenthumb93/CVE-2022-30190-follina","1","1","N/A","N/A","N/A","1","8","4","2023-04-20T20:34:05Z","2022-06-01T11:37:08Z","41561" +"*drk1wi/Modlishka*",".{0,1000}drk1wi\/Modlishka.{0,1000}","offensive_tool_keyword","Modlishka ","Modlishka is a powerful and flexible HTTP reverse proxy. It implements an entirely new and interesting approach of handling browser-based HTTP traffic flow. which allows to transparently proxy multi-domain destination traffic. both TLS and non-TLS. over a single domain. without a requirement of installing any additional certificate on the client.","T1090.001 - T1071.001 - T1556.001 - T1204.001 - T1568.002","TA0011 - TA0001 - TA0002 - TA0005 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/drk1wi/Modlishka","1","1","N/A","network exploitation tool","5","10","4967","897","2024-04-19T12:23:00Z","2018-12-19T15:59:54Z","41563" +"*drop_malleable_unknown_*",".{0,1000}drop_malleable_unknown_.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","41566" +"*drop_malleable_with_invalid_*",".{0,1000}drop_malleable_with_invalid_.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","41567" +"*drop_malleable_without_*",".{0,1000}drop_malleable_without_.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","41568" +"*dropboxC2.py*",".{0,1000}dropboxC2\.py.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","41572" +"*dropper_cs.exe*",".{0,1000}dropper_cs\.exe.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","41573" +"*dropper32.exe*",".{0,1000}dropper32\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","41574" +"*dropper64.exe*",".{0,1000}dropper64\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","41575" +"*drunkpotato.x64.dll*",".{0,1000}drunkpotato\.x64\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","41578" +"*drunkpotato.x86.dll*",".{0,1000}drunkpotato\.x86\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","41579" +"*drupal_enum.py*",".{0,1000}drupal_enum\.py.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","41580" +"*dsbqrprgkqqifztta6h3w7i2htjhnq7d3qkh3c7gvc35e66rrcv66did.onion*",".{0,1000}dsbqrprgkqqifztta6h3w7i2htjhnq7d3qkh3c7gvc35e66rrcv66did\.onion.{0,1000}","offensive_tool_keyword","onionpipe","onionpipe forwards ports on the local host to remote Onion addresses as Tor hidden services and vice-versa.","T1090.003 - T1573.002","TA0005 - TA0011","N/A","Black Basta","Defense Evasion","https://github.com/cmars/onionpipe","1","1","N/A","N/A","10","6","553","33","2025-04-22T16:34:56Z","2022-01-23T06:52:13Z","41582" +"*dsnezhkov/shutter*",".{0,1000}dsnezhkov\/shutter.{0,1000}","offensive_tool_keyword","shutter","The goal of Shutter is to manage windows network stack communication via Windows Filtering Platform. Management can include blocking or permiting traffic based on IP or an executable that initiates or receives the traffic.","T1562 - T1027","TA0005 - TA0007","N/A","N/A","Defense Evasion","https://github.com/dsnezhkov/shutter","1","1","N/A","N/A","10","2","116","15","2021-05-12T19:05:14Z","2021-05-12T18:51:03Z","41591" +"*dswmiexec.exe*",".{0,1000}dswmiexec\.exe.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","41595" +"*dtmsecurity/bof_helper*",".{0,1000}dtmsecurity\/bof_helper.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) Creation Helper","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dtmsecurity/bof_helper","1","1","N/A","N/A","10","10","228","43","2022-05-03T18:56:14Z","2020-07-01T14:50:29Z","41597" +"*dubrute.exe*",".{0,1000}dubrute\.exe.{0,1000}","offensive_tool_keyword","DUBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/ch0sys/DUBrute","1","1","N/A","N/A","10","1","37","28","2018-02-19T13:03:14Z","2017-06-15T08:55:46Z","41607" +"*DuckDuckC2-main*",".{0,1000}DuckDuckC2\-main.{0,1000}","offensive_tool_keyword","DuckDuckC2","A proof-of-concept C2 channel through DuckDuckGo's image proxy service","T1071.001 - T1090.003","TA0011 - TA0042","N/A","N/A","C2","https://github.com/nopcorn/DuckDuckC2","1","1","N/A","N/A","10","10","74","6","2023-11-12T10:24:59Z","2023-09-23T20:00:09Z","41609" +"*DueDLLigence.cs*",".{0,1000}DueDLLigence\.cs.{0,1000}","offensive_tool_keyword","DueDLLigence","Shellcode runner framework for application whitelisting bypasses and DLL side-loading","T1055.012 - T1218.011","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/mandiant/DueDLLigence","1","1","N/A","N/A","10","5","469","89","2023-06-02T14:24:43Z","2019-10-04T18:34:27Z","41611" +"*DueDLLigence.sln*",".{0,1000}DueDLLigence\.sln.{0,1000}","offensive_tool_keyword","DueDLLigence","Shellcode runner framework for application whitelisting bypasses and DLL side-loading","T1055.012 - T1218.011","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/mandiant/DueDLLigence","1","1","N/A","N/A","10","5","469","89","2023-06-02T14:24:43Z","2019-10-04T18:34:27Z","41612" +"*DueDLLigence-master*",".{0,1000}DueDLLigence\-master.{0,1000}","offensive_tool_keyword","DueDLLigence","Shellcode runner framework for application whitelisting bypasses and DLL side-loading","T1055.012 - T1218.011","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/mandiant/DueDLLigence","1","1","N/A","N/A","10","5","469","89","2023-06-02T14:24:43Z","2019-10-04T18:34:27Z","41613" +"*dump_chrome_user*",".{0,1000}dump_chrome_user.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41625" +"*dump_domain*",".{0,1000}dump_domain.{0,1000}","offensive_tool_keyword","BloodHound","A Python based ingestor for BloodHound","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/fox-it/BloodHound.py","1","1","N/A","N/A","10","10","2088","343","2025-03-28T11:19:13Z","2018-02-26T14:44:20Z","41630" +"*dump_firefox_user*",".{0,1000}dump_firefox_user.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41632" +"*dump_jenkins*",".{0,1000}dump_jenkins.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41634" +"*dump_keepassx*",".{0,1000}dump_keepassx.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41635" +"*dump_lsass*",".{0,1000}dump_lsass.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","41637" +"*dump_lsass.js*",".{0,1000}dump_lsass\.js.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","41638" +"*dump_sam(*",".{0,1000}dump_sam\(.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","41641" +"*dump_secrets.py*",".{0,1000}dump_secrets\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","41642" +"*dump_ssh_keys*",".{0,1000}dump_ssh_keys.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41643" +"*dump_tomcat*",".{0,1000}dump_tomcat.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41644" +"*dump_webconf*",".{0,1000}dump_webconf.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41648" +"*dump_webpass*",".{0,1000}dump_webpass.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41649" +"*dump_wifi_wpa_*",".{0,1000}dump_wifi_wpa_.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41650" +"*DumpAADSyncCreds.csproj*",".{0,1000}DumpAADSyncCreds\.csproj.{0,1000}","offensive_tool_keyword","DumpAADSyncCreds","C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.","T1555 - T1110","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Hagrid29/DumpAADSyncCreds","1","1","N/A","N/A","10","1","39","3","2023-06-24T16:17:36Z","2022-03-27T18:43:44Z","41653" +"*DumpAADSyncCreds.exe*",".{0,1000}DumpAADSyncCreds\.exe.{0,1000}","offensive_tool_keyword","DumpAADSyncCreds","C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.","T1555 - T1110","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Hagrid29/DumpAADSyncCreds","1","1","N/A","N/A","10","1","39","3","2023-06-24T16:17:36Z","2022-03-27T18:43:44Z","41654" +"*DumpAADSyncCreds.sln*",".{0,1000}DumpAADSyncCreds\.sln.{0,1000}","offensive_tool_keyword","DumpAADSyncCreds","C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.","T1555 - T1110","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Hagrid29/DumpAADSyncCreds","1","1","N/A","N/A","10","1","39","3","2023-06-24T16:17:36Z","2022-03-27T18:43:44Z","41655" +"*DumpChromePasswords.ps1*",".{0,1000}DumpChromePasswords\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","41659" +"*DumpCreds*",".{0,1000}DumpCreds.{0,1000}","offensive_tool_keyword","DumpCreds","Dumpcreds is a tool that may be used to extract various credentials from running processes. I just take a look at mimipenguin(https://github.com/huntergregal/mimipenguin) and tried to improve it a bit","T1055 - T1003 - T1216 - T1002 - T1552","TA0002 - TA0003 - TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/ponypot/dumpcreds","1","1","N/A","N/A","N/A","1","6","1","2019-10-08T07:26:31Z","2017-10-10T12:57:42Z","41660" +"*dumpCredStore.ps1*",".{0,1000}dumpCredStore\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1060","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","41663" +"*Dumpert.bin*",".{0,1000}Dumpert\.bin.{0,1000}","offensive_tool_keyword","cobaltstrike","LSASS memory dumper using direct system calls and API unhooking.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Dumpert/tree/master/Dumpert-Aggressor","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","41667" +"*dumpert.dmp*",".{0,1000}dumpert\.dmp.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","41668" +"*Dumpert.exe*",".{0,1000}Dumpert\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","LSASS memory dumper using direct system calls and API unhooking.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Dumpert/tree/master/Dumpert-Aggressor","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","41669" +"*Dumpert.exe*",".{0,1000}Dumpert\.exe.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","41670" +"*Dumpert.git*",".{0,1000}Dumpert\.git.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","41671" +"*dumpert.py*",".{0,1000}dumpert\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","41672" +"*dumpert_path=*",".{0,1000}dumpert_path\=.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","41673" +"*Dumpert-Aggressor*",".{0,1000}Dumpert\-Aggressor.{0,1000}","offensive_tool_keyword","cobaltstrike","LSASS memory dumper using direct system calls and API unhooking.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Dumpert/tree/master/Dumpert-Aggressor","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","41674" +"*Dumpert-Aggressor*",".{0,1000}Dumpert\-Aggressor.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","41675" +"*dumpertdll*",".{0,1000}dumpertdll.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","41676" +"*Dumpert-DLL*",".{0,1000}Dumpert\-DLL.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","41677" +"*dumpertdll.py*",".{0,1000}dumpertdll\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","41678" +"*DumpKernel-S1.ps1*",".{0,1000}DumpKernel\-S1\.ps1.{0,1000}","offensive_tool_keyword","DumpKernel-S1.ps1","SentinelHelper to perform a live kernel dump in a Windows environment","T1055 - T1003 - T1112","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://gist.github.com/adamsvoboda/8f29e09d74b73e1dec3f9049c4358e80","1","1","N/A","N/A","10","8","N/A","N/A","N/A","N/A","41684" +"*DumpLSASS-main.zip*",".{0,1000}DumpLSASS\-main\.zip.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","1","N/A","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","41686" +"*DumpNParse-main.zip*",".{0,1000}DumpNParse\-main\.zip.{0,1000}","offensive_tool_keyword","DumpNParse","A Combination LSASS Dumper and LSASS Parser","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/icyguider/DumpNParse","1","1","N/A","N/A","10","2","150","24","2021-11-21T14:25:24Z","2021-11-21T14:18:42Z","41688" +"*dumpntlm.py*",".{0,1000}dumpntlm\.py.{0,1000}","offensive_tool_keyword","BloodHound","A Python based ingestor for BloodHound","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/fox-it/BloodHound.py","1","1","N/A","N/A","10","10","2088","343","2025-03-28T11:19:13Z","2018-02-26T14:44:20Z","41689" +"*DumpNTLMInfo.py*",".{0,1000}DumpNTLMInfo\.py.{0,1000}","offensive_tool_keyword","conpass","Continuous password spraying tool","T1110.001 - T1110 - T1078.001 - T1201","TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://github.com/login-securite/conpass","1","1","N/A","N/A","10","2","181","17","2025-03-03T15:05:25Z","2022-12-15T18:03:42Z","41690" +"*DumpNTLMInfo.py*",".{0,1000}DumpNTLMInfo\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","41691" +"*DumpPEFromMemory.cpp*",".{0,1000}DumpPEFromMemory\.cpp.{0,1000}","offensive_tool_keyword","InflativeLoading","Dynamically convert a native EXE to PIC shellcode by prepending a shellcode stub","T1027 - T1055 - T1140","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/senzee1984/InflativeLoading","1","1","N/A","N/A","10","4","309","64","2024-04-12T17:14:07Z","2024-01-05T03:59:33Z","41692" +"*DumpPEFromMemory.exe*",".{0,1000}DumpPEFromMemory\.exe.{0,1000}","offensive_tool_keyword","InflativeLoading","Dynamically convert a native EXE to PIC shellcode by prepending a shellcode stub","T1027 - T1055 - T1140","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/senzee1984/InflativeLoading","1","1","N/A","N/A","10","4","309","64","2024-04-12T17:14:07Z","2024-01-05T03:59:33Z","41693" +"*DumpPEFromMemoryMemory.exe*",".{0,1000}DumpPEFromMemoryMemory\.exe.{0,1000}","offensive_tool_keyword","InflativeLoading","Dynamically convert a native EXE to PIC shellcode by prepending a shellcode stub","T1027 - T1055 - T1140","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/senzee1984/InflativeLoading","1","1","N/A","N/A","10","4","309","64","2024-04-12T17:14:07Z","2024-01-05T03:59:33Z","41694" +"*DumpShellcode.*",".{0,1000}DumpShellcode\..{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","41697" +"*DumpShellcode.exe*",".{0,1000}DumpShellcode\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Takes the original PPLFault and the original included DumpShellcode and combinds it all into a BOF targeting cobalt strike.","T1055 - T1078.003","TA0002 - TA0006","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Credential Access","https://github.com/trustedsec/PPLFaultDumpBOF","1","1","N/A","N/A","N/A","2","140","11","2023-05-17T12:57:20Z","2023-05-16T13:02:22Z","41698" +"*DumpSMSAPassword*",".{0,1000}DumpSMSAPassword.{0,1000}","offensive_tool_keyword","BloodHound","an adversary with local admin access to an AD-joined computer can dump the cleartext password from LSA secrets of any sMSAs installed on this computer","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound","1","1","N/A","AD Enumeration","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","41700" +"*dumpVaultCredentials.py*",".{0,1000}dumpVaultCredentials\.py.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","41701" +"*DyeKuu/DNS-Hijacking*",".{0,1000}DyeKuu\/DNS\-Hijacking.{0,1000}","offensive_tool_keyword","DNS-Hijacking","DNS Hijacking in UNIX/Linux System by using raw socket and pcap","T1496 - T1040 - T1071.004 - T1090","TA0040 - TA0002 - TA0009","N/A","Sea Turtle","Sniffing & Spoofing","https://github.com/DyeKuu/DNS-Hijacking","1","1","#linux","N/A","9","1","5","2","2020-05-31T23:03:34Z","2020-05-02T08:49:22Z","41712" +"*dynasty_rce/rce.php*",".{0,1000}dynasty_rce\/rce\.php.{0,1000}","offensive_tool_keyword","DynastyPersist","Linux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd Service","T1055 - T1037 - T1078 - T1547 - T1546 - T1556","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/Trevohack/DynastyPersist","1","1","#linux","N/A","9","2","153","17","2024-05-16T05:19:48Z","2023-08-13T15:05:42Z","41714" +"*DynastyPersist-main.zip*",".{0,1000}DynastyPersist\-main\.zip.{0,1000}","offensive_tool_keyword","DynastyPersist","Linux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd Service","T1055 - T1037 - T1078 - T1547 - T1546 - T1556","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/Trevohack/DynastyPersist","1","1","#linux","N/A","9","2","153","17","2024-05-16T05:19:48Z","2023-08-13T15:05:42Z","41715" +"*e3v6tjarcltwc4hdkn6fxnpkzq42ul7swf5cfqw6jzvic4577vxsxhid.onion*",".{0,1000}e3v6tjarcltwc4hdkn6fxnpkzq42ul7swf5cfqw6jzvic4577vxsxhid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","42013" +"*eapmd5tojohn*",".{0,1000}eapmd5tojohn.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","42521" +"*EasyHook-Managed*InjectionLoader.cs*",".{0,1000}EasyHook\-Managed.{0,1000}InjectionLoader\.cs.{0,1000}","offensive_tool_keyword","Dendrobate","Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code","T1055.012 - T1059.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Dendrobate","1","1","N/A","N/A","10","2","131","27","2021-11-19T12:18:50Z","2021-02-15T11:15:51Z","42528" +"*EasyHook-Managed*WOW64Bypass.*",".{0,1000}EasyHook\-Managed.{0,1000}WOW64Bypass\..{0,1000}","offensive_tool_keyword","Dendrobate","Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code","T1055.012 - T1059.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Dendrobate","1","1","N/A","N/A","10","2","131","27","2021-11-19T12:18:50Z","2021-02-15T11:15:51Z","42529" +"*EasyHook-Managed/LocalHook.cs*",".{0,1000}EasyHook\-Managed\/LocalHook\.cs.{0,1000}","offensive_tool_keyword","Dendrobate","Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code","T1055.012 - T1059.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Dendrobate","1","1","N/A","N/A","10","2","131","27","2021-11-19T12:18:50Z","2021-02-15T11:15:51Z","42530" +"*EasyPersistent.cna*",".{0,1000}EasyPersistent\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","42531" +"*ebljej7okwfnx5hdfikqqt2uqehihqv3yns3ziij5clqpklwb3i2cxad.onion*",".{0,1000}ebljej7okwfnx5hdfikqqt2uqehihqv3yns3ziij5clqpklwb3i2cxad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","42604" +"*Ebowla-master.zip*",".{0,1000}Ebowla\-master\.zip.{0,1000}","offensive_tool_keyword","Ebowla","Framework for Making Environmental Keyed Payloads","T1027.002 - T1059.003 - T1140","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/Genetic-Malware/Ebowla","1","1","N/A","N/A","10","8","748","171","2019-01-28T10:45:15Z","2016-04-07T22:29:58Z","42605" +"*ebwexiymbsib4rmw.onion*",".{0,1000}ebwexiymbsib4rmw\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","42606" +"*echoac-poc-main*",".{0,1000}echoac\-poc\-main.{0,1000}","offensive_tool_keyword","echoac-poc","poc stealing the Kernel's KPROCESS/EPROCESS block and writing it to a newly spawned shell to elevate its privileges to the highest possible - nt authority\system","T1068 - T1203 - T1059.003","TA0002 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/kite03/echoac-poc","1","1","N/A","N/A","8","2","138","25","2024-01-09T16:44:00Z","2023-06-28T00:52:22Z","42742" +"*ecryptfs2john.py*",".{0,1000}ecryptfs2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","42745" +"*Ed1s0nZ/cool/*",".{0,1000}Ed1s0nZ\/cool\/.{0,1000}","offensive_tool_keyword","C2 related tools","An anti-virus platform written in the Golang-Gin framework with built-in BypassAV methods such as separation and bundling.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Ed1s0nZ/cool","1","1","N/A","N/A","10","10","686","112","2023-07-13T07:04:30Z","2021-11-10T14:32:34Z","42760" +"*edge_wscript_wsh_injection*",".{0,1000}edge_wscript_wsh_injection.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","42818" +"*edge1.parrot.run*",".{0,1000}edge1\.parrot\.run.{0,1000}","offensive_tool_keyword","parrot os","Parrot OS is a Debian-based. security-oriented Linux distribution that is designed for ethical hacking. penetration testing and digital forensics.","T1590 - T1200 - T1027 - T1578 - T1003 - T1001 - T1046 - T1570 - T1114 - T1105","TA0043 - TA0002 - TA0003 - TA0004 - TA0006 - TA0005 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation OS","https://www.parrotsec.org/download/","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","42819" +"*EDR_Detection.exe*",".{0,1000}EDR_Detection\.exe.{0,1000}","offensive_tool_keyword","EDR_Detector","detect EDR agents on a machine","T1518.001 - T1063","TA0007 - TA0009","N/A","N/A","Collection","https://github.com/trickster0/EDR_Detector","1","1","N/A","N/A","7","1","93","14","2021-11-05T08:10:05Z","2019-08-24T20:50:09Z","42824" +"*EDR_Detector.7z*",".{0,1000}EDR_Detector\.7z.{0,1000}","offensive_tool_keyword","EDR_Detector","detect EDR agents on a machine","T1518.001 - T1063","TA0007 - TA0009","N/A","N/A","Collection","https://github.com/trickster0/EDR_Detector","1","1","N/A","N/A","7","1","93","14","2021-11-05T08:10:05Z","2019-08-24T20:50:09Z","42825" +"*EDR_Detector-master*",".{0,1000}EDR_Detector\-master.{0,1000}","offensive_tool_keyword","EDR_Detector","detect EDR agents on a machine","T1518.001 - T1063","TA0007 - TA0009","N/A","N/A","Collection","https://github.com/trickster0/EDR_Detector","1","1","N/A","N/A","7","1","93","14","2021-11-05T08:10:05Z","2019-08-24T20:50:09Z","42826" +"*EDRaser-main*",".{0,1000}EDRaser\-main.{0,1000}","offensive_tool_keyword","EDRaser","EDRaser is a powerful tool for remotely deleting access logs & Windows event logs & databases and other files on remote machines.","T1070.004 - T1027 - T1564.001","TA0005 - TA0040 - TA0003","N/A","N/A","Defense Evasion","https://github.com/SafeBreach-Labs/EDRaser","1","1","N/A","N/A","10","4","363","49","2024-04-06T17:42:40Z","2023-08-10T04:30:45Z","42828" +"*EDRSandblast.exe*",".{0,1000}EDRSandblast\.exe.{0,1000}","offensive_tool_keyword","EDRSandBlast","EDRSandBlast is a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/wavestone-cdt/EDRSandblast","1","1","N/A","N/A","10","10","1633","292","2024-08-30T20:30:31Z","2021-11-02T15:02:42Z","42830" +"*EDRSandblast.exe*",".{0,1000}EDRSandblast\.exe.{0,1000}","offensive_tool_keyword","EDRSandblast-GodFault","Integrates GodFault into EDR Sandblast achieving the same result without the use of any vulnerable drivers.","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/gabriellandau/EDRSandblast-GodFault","1","1","N/A","N/A","10","3","260","48","2023-08-28T18:14:20Z","2023-06-01T19:32:09Z","42831" +"*edrsandblast.py*",".{0,1000}edrsandblast\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","42833" +"*EDRSandblast.sln*",".{0,1000}EDRSandblast\.sln.{0,1000}","offensive_tool_keyword","EDRSandBlast","EDRSandBlast is a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/wavestone-cdt/EDRSandblast","1","1","N/A","N/A","10","10","1633","292","2024-08-30T20:30:31Z","2021-11-02T15:02:42Z","42834" +"*EDRSandblast.sln*",".{0,1000}EDRSandblast\.sln.{0,1000}","offensive_tool_keyword","EDRSandblast-GodFault","Integrates GodFault into EDR Sandblast achieving the same result without the use of any vulnerable drivers.","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/gabriellandau/EDRSandblast-GodFault","1","1","N/A","N/A","10","3","260","48","2023-08-28T18:14:20Z","2023-06-01T19:32:09Z","42835" +"*EDRSandblast.vcxproj*",".{0,1000}EDRSandblast\.vcxproj.{0,1000}","offensive_tool_keyword","EDRSandblast-GodFault","Integrates GodFault into EDR Sandblast achieving the same result without the use of any vulnerable drivers.","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/gabriellandau/EDRSandblast-GodFault","1","1","N/A","N/A","10","3","260","48","2023-08-28T18:14:20Z","2023-06-01T19:32:09Z","42836" +"*EDRSandblast_API.c*",".{0,1000}EDRSandblast_API\.c.{0,1000}","offensive_tool_keyword","EDRSandblast-GodFault","Integrates GodFault into EDR Sandblast achieving the same result without the use of any vulnerable drivers.","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/gabriellandau/EDRSandblast-GodFault","1","1","N/A","N/A","10","3","260","48","2023-08-28T18:14:20Z","2023-06-01T19:32:09Z","42837" +"*EDRSandblast_API.exe*",".{0,1000}EDRSandblast_API\.exe.{0,1000}","offensive_tool_keyword","EDRSandblast-GodFault","Integrates GodFault into EDR Sandblast achieving the same result without the use of any vulnerable drivers.","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/gabriellandau/EDRSandblast-GodFault","1","1","N/A","N/A","10","3","260","48","2023-08-28T18:14:20Z","2023-06-01T19:32:09Z","42838" +"*EDRSandblast_API.h*",".{0,1000}EDRSandblast_API\.h.{0,1000}","offensive_tool_keyword","EDRSandblast-GodFault","Integrates GodFault into EDR Sandblast achieving the same result without the use of any vulnerable drivers.","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/gabriellandau/EDRSandblast-GodFault","1","1","N/A","N/A","10","3","260","48","2023-08-28T18:14:20Z","2023-06-01T19:32:09Z","42839" +"*EDRSandblast_CLI*",".{0,1000}EDRSandblast_CLI.{0,1000}","offensive_tool_keyword","EDRSandBlast","EDRSandBlast is a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/wavestone-cdt/EDRSandblast","1","1","N/A","N/A","10","10","1633","292","2024-08-30T20:30:31Z","2021-11-02T15:02:42Z","42840" +"*EDRSandblast_LsassDump*",".{0,1000}EDRSandblast_LsassDump.{0,1000}","offensive_tool_keyword","EDRSandBlast","EDRSandBlast is a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/wavestone-cdt/EDRSandblast","1","1","N/A","N/A","10","10","1633","292","2024-08-30T20:30:31Z","2021-11-02T15:02:42Z","42841" +"*EDRSandblast_LsassDump.c*",".{0,1000}EDRSandblast_LsassDump\.c.{0,1000}","offensive_tool_keyword","EDRSandblast-GodFault","Integrates GodFault into EDR Sandblast achieving the same result without the use of any vulnerable drivers.","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/gabriellandau/EDRSandblast-GodFault","1","1","N/A","N/A","10","3","260","48","2023-08-28T18:14:20Z","2023-06-01T19:32:09Z","42842" +"*EDRSandblast_LsassDump.exe*",".{0,1000}EDRSandblast_LsassDump\.exe.{0,1000}","offensive_tool_keyword","EDRSandblast-GodFault","Integrates GodFault into EDR Sandblast achieving the same result without the use of any vulnerable drivers.","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/gabriellandau/EDRSandblast-GodFault","1","1","N/A","N/A","10","3","260","48","2023-08-28T18:14:20Z","2023-06-01T19:32:09Z","42843" +"*EDRSandblast_StaticLibrary*",".{0,1000}EDRSandblast_StaticLibrary.{0,1000}","offensive_tool_keyword","EDRSandBlast","EDRSandBlast is a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/wavestone-cdt/EDRSandblast","1","1","N/A","N/A","10","10","1633","292","2024-08-30T20:30:31Z","2021-11-02T15:02:42Z","42844" +"*EDRSandblast-GodFault*",".{0,1000}EDRSandblast\-GodFault.{0,1000}","offensive_tool_keyword","EDRSandblast-GodFault","Integrates GodFault into EDR Sandblast achieving the same result without the use of any vulnerable drivers.","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/gabriellandau/EDRSandblast-GodFault","1","1","N/A","N/A","10","3","260","48","2023-08-28T18:14:20Z","2023-06-01T19:32:09Z","42845" +"*EDRSandblast-master*",".{0,1000}EDRSandblast\-master.{0,1000}","offensive_tool_keyword","EDRSandBlast","EDRSandBlast is a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/wavestone-cdt/EDRSandblast","1","1","N/A","N/A","10","10","1633","292","2024-08-30T20:30:31Z","2021-11-02T15:02:42Z","42846" +"*EDRSilencer.exe*",".{0,1000}EDRSilencer\.exe.{0,1000}","offensive_tool_keyword","EDRSilencer","A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server","T1562.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/netero1010/EDRSilencer","1","1","N/A","N/A","10","10","1645","209","2024-11-03T16:05:14Z","2023-12-26T04:15:39Z","42847" +"*eeriedusk/nysm*",".{0,1000}eeriedusk\/nysm.{0,1000}","offensive_tool_keyword","nysm","nysm is a stealth post-exploitation container","T1610 - T1057 - T1570","TA0005 - TA0002 - TA0008","N/A","N/A","Defense Evasion","https://github.com/eeriedusk/nysm","1","1","N/A","N/A","10","3","246","39","2023-12-20T13:59:17Z","2023-09-25T10:03:52Z","42921" +"*efchatz/pandora*",".{0,1000}efchatz\/pandora.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","1","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","42978" +"*EfiGuard-v1.1.zip*",".{0,1000}EfiGuard\-v1\.1\.zip.{0,1000}","offensive_tool_keyword","EfiGuard","EfiGuard is a portable x64 UEFI bootkit that patches the Windows boot manager - boot loader and kernel at boot time in order to disable PatchGuard and Driver Signature Enforcement (DSE).","T1542.002 - T1542.003 - T1542.004","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Mattiwatti/EfiGuard","1","1","N/A","N/A","10","10","1977","354","2025-02-24T11:57:36Z","2019-03-25T19:47:39Z","42998" +"*EfiGuard-v1.2.zip*",".{0,1000}EfiGuard\-v1\.2\.zip.{0,1000}","offensive_tool_keyword","EfiGuard","EfiGuard is a portable x64 UEFI bootkit that patches the Windows boot manager - boot loader and kernel at boot time in order to disable PatchGuard and Driver Signature Enforcement (DSE).","T1542.002 - T1542.003 - T1542.004","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Mattiwatti/EfiGuard","1","1","N/A","N/A","10","10","1977","354","2025-02-24T11:57:36Z","2019-03-25T19:47:39Z","42999" +"*EfiGuard-v1.3.zip*",".{0,1000}EfiGuard\-v1\.3\.zip.{0,1000}","offensive_tool_keyword","EfiGuard","EfiGuard is a portable x64 UEFI bootkit that patches the Windows boot manager - boot loader and kernel at boot time in order to disable PatchGuard and Driver Signature Enforcement (DSE).","T1542.002 - T1542.003 - T1542.004","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Mattiwatti/EfiGuard","1","1","N/A","N/A","10","10","1977","354","2025-02-24T11:57:36Z","2019-03-25T19:47:39Z","43000" +"*EfiGuard-v1.4.zip*",".{0,1000}EfiGuard\-v1\.4\.zip.{0,1000}","offensive_tool_keyword","EfiGuard","EfiGuard is a portable x64 UEFI bootkit that patches the Windows boot manager - boot loader and kernel at boot time in order to disable PatchGuard and Driver Signature Enforcement (DSE).","T1542.002 - T1542.003 - T1542.004","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Mattiwatti/EfiGuard","1","1","N/A","N/A","10","10","1977","354","2025-02-24T11:57:36Z","2019-03-25T19:47:39Z","43001" +"*EfiGuard-v1.5.zip*",".{0,1000}EfiGuard\-v1\.5\.zip.{0,1000}","offensive_tool_keyword","EfiGuard","EfiGuard is a portable x64 UEFI bootkit that patches the Windows boot manager - boot loader and kernel at boot time in order to disable PatchGuard and Driver Signature Enforcement (DSE).","T1542.002 - T1542.003 - T1542.004","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Mattiwatti/EfiGuard","1","1","N/A","N/A","10","10","1977","354","2025-02-24T11:57:36Z","2019-03-25T19:47:39Z","43002" +"*EfsPotato-*.exe*",".{0,1000}EfsPotato\-.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","43003" +"*EfsPotato*efsrpc*",".{0,1000}EfsPotato.{0,1000}efsrpc.{0,1000}","offensive_tool_keyword","EfsPotato","Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability)","T1068 - T1055.002 - T1070.004","TA0003 - TA0005 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/zcgonvh/EfsPotato","1","1","N/A","N/A","10","8","771","125","2023-12-14T14:30:15Z","2021-07-26T21:36:16Z","43004" +"*EfsPotato*lsarpc*",".{0,1000}EfsPotato.{0,1000}lsarpc.{0,1000}","offensive_tool_keyword","EfsPotato","Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability)","T1068 - T1055.002 - T1070.004","TA0003 - TA0005 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/zcgonvh/EfsPotato","1","1","N/A","N/A","10","8","771","125","2023-12-14T14:30:15Z","2021-07-26T21:36:16Z","43005" +"*EfsPotato*lsarpc*",".{0,1000}EfsPotato.{0,1000}lsarpc.{0,1000}","offensive_tool_keyword","EfsPotato","Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability)","T1068 - T1055.002 - T1070.004","TA0003 - TA0005 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/zcgonvh/EfsPotato","1","1","N/A","N/A","10","8","771","125","2023-12-14T14:30:15Z","2021-07-26T21:36:16Z","43006" +"*EfsPotato*lsass*",".{0,1000}EfsPotato.{0,1000}lsass.{0,1000}","offensive_tool_keyword","EfsPotato","Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability)","T1068 - T1055.002 - T1070.004","TA0003 - TA0005 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/zcgonvh/EfsPotato","1","1","N/A","N/A","10","8","771","125","2023-12-14T14:30:15Z","2021-07-26T21:36:16Z","43007" +"*EfsPotato*netlogon*",".{0,1000}EfsPotato.{0,1000}netlogon.{0,1000}","offensive_tool_keyword","EfsPotato","Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability)","T1068 - T1055.002 - T1070.004","TA0003 - TA0005 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/zcgonvh/EfsPotato","1","1","N/A","N/A","10","8","771","125","2023-12-14T14:30:15Z","2021-07-26T21:36:16Z","43008" +"*EfsPotato*samr*",".{0,1000}EfsPotato.{0,1000}samr.{0,1000}","offensive_tool_keyword","EfsPotato","Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability)","T1068 - T1055.002 - T1070.004","TA0003 - TA0005 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/zcgonvh/EfsPotato","1","1","N/A","N/A","10","8","771","125","2023-12-14T14:30:15Z","2021-07-26T21:36:16Z","43009" +"*EfsPotato.exe*",".{0,1000}EfsPotato\.exe.{0,1000}","offensive_tool_keyword","PrivFu","ArtsOfGetSystem privesc tools","T1134 - T1134.001 - T1078 - T1059 - T1075","TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu/","1","1","N/A","ArtsOfGetSystem","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","43010" +"*EfsPotato-main*",".{0,1000}EfsPotato\-main.{0,1000}","offensive_tool_keyword","EfsPotato","Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability)","T1068 - T1055.002 - T1070.004","TA0003 - TA0005 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/zcgonvh/EfsPotato","1","1","N/A","N/A","10","8","771","125","2023-12-14T14:30:15Z","2021-07-26T21:36:16Z","43011" +"*EgeBalci/sgn*",".{0,1000}EgeBalci\/sgn.{0,1000}","offensive_tool_keyword","sgn","polymorphic encoder used in to obfuscate payloads","T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/EgeBalci/sgn","1","1","N/A","N/A","8","10","1681","224","2024-02-22T17:35:59Z","2019-10-30T10:20:01Z","43015" +"*EgeBalci/WSAAcceptBackdoor*",".{0,1000}EgeBalci\/WSAAcceptBackdoor.{0,1000}","offensive_tool_keyword","WSAAcceptBackdoor","Winsock accept() Backdoor Implant","T1574.001 - T1059 - T1213 - T1105 - T1546","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/EgeBalci/WSAAcceptBackdoor","1","1","N/A","N/A","10","2","112","23","2021-02-13T19:18:41Z","2021-02-13T15:59:01Z","43016" +"*EggShell.py*",".{0,1000}EggShell\.py.{0,1000}","offensive_tool_keyword","Eggshell","EggShell is a post exploitation surveillance tool written in Python. It gives you a command line session with extra functionality between you and a target machine. EggShell gives you the power and convenience of uploading/downloading files. tab completion. taking pictures. location tracking. shell command execution. persistence. escalating privileges. password retrieval. and much more. This is project is a proof of concept. intended for use on machines you own","T1027 - T1553 - T1003 - T1059 - T1558.001","TA0002 - TA0006 - TA0008","N/A","N/A","Data Exfiltration","https://github.com/neoneggplant/EggShell","1","1","N/A","N/A","N/A","10","1693","384","2021-03-25T22:04:52Z","2015-07-02T16:58:30Z","43017" +"*Egress-Assess.*",".{0,1000}Egress\-Assess\..{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","43023" +"*EgressAssess.ps1*",".{0,1000}EgressAssess\.ps1.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","43024" +"*Egress-Assess-master*",".{0,1000}Egress\-Assess\-master.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","43025" +"*egressbuster*",".{0,1000}egressbuster.{0,1000}","offensive_tool_keyword","egressbuster","EgressBuster is a way to test the effectiveness of egress filtering for an individual area. When performing a penetration test. often times companies leverage egress filtering in order to prevent access to the outside Internet. Most companies have special exceptions and allow ports but they may be difficult to find.","T1046 - T1570 - T1590","TA0001 - TA0007","N/A","N/A","Exploitation tool","https://github.com/trustedsec/egressbuster","1","1","N/A","N/A","N/A","4","365","108","2024-07-30T16:17:48Z","2015-05-14T02:19:26Z","43026" +"*egresscheck-framework*",".{0,1000}egresscheck\-framework.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-EgressCheck.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","43027" +"*ehang-io/nps*",".{0,1000}ehang\-io\/nps.{0,1000}","offensive_tool_keyword","nps","chinese intranet penetration proxy server","T1090 - T1071 - T1102 - T1075 - T1133","TA0002 - TA0011 - TA0010","N/A","N/A","Defense Evasion","https://github.com/yisier/nps","1","1","N/A","N/A","9","10","2674","327","2025-04-17T09:43:50Z","2022-09-14T06:24:00Z","43028" +"*ejabberd2john.py*",".{0,1000}ejabberd2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","43035" +"*eladshamir/BadWindowsService*",".{0,1000}eladshamir\/BadWindowsService.{0,1000}","offensive_tool_keyword","BadWindowsService","An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities","T1068 - T1211 - T1050","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/eladshamir/BadWindowsService","1","1","N/A","N/A","10","1","58","10","2022-08-25T14:22:25Z","2022-08-19T15:38:05Z","43042" +"*eladshamir/RPC-Backdoor*",".{0,1000}eladshamir\/RPC\-Backdoor.{0,1000}","offensive_tool_keyword","RPC-Backdoor","A basic emulation of an ""RPC Backdoor""","T1071.004","TA0011","N/A","N/A","C2","https://github.com/eladshamir/RPC-Backdoor","1","1","N/A","N/A","10","10","240","45","2022-08-25T14:37:41Z","2022-08-16T13:12:05Z","43043" +"*eladshamir/SharpElevator*",".{0,1000}eladshamir\/SharpElevator.{0,1000}","offensive_tool_keyword","SharpElevator","SharpElevator is a C# implementation of Elevator for UAC bypass","T1548.002 - T1548","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/eladshamir/SharpElevator","1","1","N/A","N/A","10","1","51","12","2022-08-31T18:09:10Z","2022-08-29T19:52:53Z","43044" +"*eldraco/domain_analyzer*",".{0,1000}eldraco\/domain_analyzer.{0,1000}","offensive_tool_keyword","domain_analyzer","Analyze the security of any domain by finding all the information possible","T1560 - T1590 - T1200 - T1213 - T1057","TA0002 - TA0009","N/A","N/A","Reconnaissance","https://github.com/eldraco/domain_analyzer","1","1","N/A","N/A","6","10","1858","241","2022-12-29T10:57:33Z","2017-08-08T18:52:34Z","43047" +"*electrum2john.py*",".{0,1000}electrum2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","43048" +"*elementalsouls/DumpLSASS*",".{0,1000}elementalsouls\/DumpLSASS.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","1","N/A","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","43049" +"*elevationstation.cpp*",".{0,1000}elevationstation\.cpp.{0,1000}","offensive_tool_keyword","elevationstation","elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","43056" +"*elevationstation.exe*",".{0,1000}elevationstation\.exe.{0,1000}","offensive_tool_keyword","elevationstation","elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","43057" +"*elevationstation.git*",".{0,1000}elevationstation\.git.{0,1000}","offensive_tool_keyword","elevationstation","elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","43058" +"*elevationstation.sln*",".{0,1000}elevationstation\.sln.{0,1000}","offensive_tool_keyword","elevationstation","elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","43059" +"*elevationstation-main*",".{0,1000}elevationstation\-main.{0,1000}","offensive_tool_keyword","elevationstation","elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","43060" +"*ELFLoader.c*",".{0,1000}ELFLoader\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a ELF object in memory loader/runner. The goal is to create a single elf loader that can be used to run follow on capabilities across all x86_64 and x86 nix operating systems.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/ELFLoader","1","1","N/A","N/A","10","10","268","45","2022-05-16T17:48:40Z","2022-04-26T19:18:20Z","43064" +"*ELFLoader.h*",".{0,1000}ELFLoader\.h.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a ELF object in memory loader/runner. The goal is to create a single elf loader that can be used to run follow on capabilities across all x86_64 and x86 nix operating systems.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/ELFLoader","1","1","N/A","N/A","10","10","268","45","2022-05-16T17:48:40Z","2022-04-26T19:18:20Z","43065" +"*ELFLoader.out*",".{0,1000}ELFLoader\.out.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a ELF object in memory loader/runner. The goal is to create a single elf loader that can be used to run follow on capabilities across all x86_64 and x86 nix operating systems.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/ELFLoader","1","1","N/A","N/A","10","10","268","45","2022-05-16T17:48:40Z","2022-04-26T19:18:20Z","43066" +"*EliteLoser/PSnmap*",".{0,1000}EliteLoser\/PSnmap.{0,1000}","offensive_tool_keyword","Psnmap","Powershell scanner (nmap like)","T1086 - T1046 - T1059","TA0007","N/A","Black Basta","Discovery","https://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps1","1","1","N/A","N/A","7","2","178","64","2024-08-23T18:24:20Z","2015-01-24T10:46:41Z","43068" +"*elite-proxy-finder*",".{0,1000}elite\-proxy\-finder.{0,1000}","offensive_tool_keyword","elite-proxy-finder","Finds elite anonymity (L1) HTTP proxies then tests them all in parallel. Tests each proxy against 3 IP checking URLs including one which is HTTPS to make sure it can handle HTTPS requests. Then checks the proxy headers to confirm its an elite L1 proxy that will not leak any extra info. By default the script will only print the proxy IP. request time. and country code of proxies that pass all four tests but you can see all the results including errors in any of the tests with the -a (--all) option.","T1586.001 - T1041.002 - T1105.002 - T1573.001 - T1135.002 - T1134.002 - T1016.001","TA0011 - TA0010 - TA0005 - TA0003","N/A","N/A","Data Exfiltration","https://github.com/DanMcInerney/elite-proxy-finder","1","1","N/A","N/A","N/A","3","251","96","2016-11-23T10:31:33Z","2014-04-17T11:23:20Z","43069" +"*ElJaviLuki/CobaltStrike_OpenBeacon*",".{0,1000}ElJaviLuki\/CobaltStrike_OpenBeacon.{0,1000}","offensive_tool_keyword","cobaltstrike","alternative to the Cobalt Strike Beacon","T1071.001 - T1041 - T1219 - T1105","TA0011","N/A","N/A","C2","https://github.com/ElJaviLuki/CobaltStrike_OpenBeacon","1","1","N/A","N/A","10","10","225","40","2024-03-13T04:32:57Z","2023-12-27T18:37:46Z","43070" +"*ElliotKillick/LdrLockLiberator*",".{0,1000}ElliotKillick\/LdrLockLiberator.{0,1000}","offensive_tool_keyword","LdrLockLiberator","LdrLockLiberator is a collection of techniques for escaping or otherwise forgoing Loader Lock while executing your code from DllMain or anywhere else the lock may be present.","T1574.002 - T1055","TA0005","N/A","N/A","Defense Evasion","https://github.com/ElliotKillick/LdrLockLiberator","1","1","N/A","N/A","9","4","375","65","2024-10-29T23:05:45Z","2023-10-31T10:11:16Z","43072" +"*elnerd/Get-NetNTLM*",".{0,1000}elnerd\/Get\-NetNTLM.{0,1000}","offensive_tool_keyword","Get-NetNTLM","Powershell module to get the NetNTLMv2 hash of the current user","T1110.003 - T1557.001 - T1040","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/elnerd/Get-NetNTLM","1","1","N/A","N/A","7","1","93","18","2022-07-05T20:55:33Z","2019-02-11T23:09:54Z","43073" +"*elusiveMice.x64.o*",".{0,1000}elusiveMice\.x64\.o.{0,1000}","offensive_tool_keyword","ElusiveMice","Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind","T1620 - T1055.012 - T1202","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/mgeeky/ElusiveMice","1","1","N/A","N/A","10","5","449","78","2023-07-12T17:54:07Z","2021-08-27T19:22:20Z","43074" +"*elusiveMice.x86.o*",".{0,1000}elusiveMice\.x86\.o.{0,1000}","offensive_tool_keyword","ElusiveMice","Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind","T1620 - T1055.012 - T1202","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/mgeeky/ElusiveMice","1","1","N/A","N/A","10","5","449","78","2023-07-12T17:54:07Z","2021-08-27T19:22:20Z","43075" +"*EmailAll-master.*",".{0,1000}EmailAll\-master\..{0,1000}","offensive_tool_keyword","EmailAll","EmailAll is a powerful Email Collect tool","T1114.001 - T1113 - T1087.003","TA0009 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Taonn/EmailAll","1","1","N/A","N/A","6","8","715","117","2022-03-04T10:36:41Z","2022-02-14T06:55:30Z","43080" +"*embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion*",".{0,1000}embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","43081" +"*embedInHTML.html*",".{0,1000}embedInHTML\.html.{0,1000}","offensive_tool_keyword","EmbedInHTML","What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.","T1027 - T1566.001","TA0005 - TA0002","N/A","N/A","Phishing","https://github.com/Arno0x/EmbedInHTML","1","1","N/A","N/A","N/A","5","485","119","2017-09-27T13:16:06Z","2017-09-11T07:17:20Z","43082" +"*embedInHTML.py*",".{0,1000}embedInHTML\.py.{0,1000}","offensive_tool_keyword","EmbedInHTML","What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.","T1027 - T1566.001","TA0005 - TA0002","N/A","N/A","Phishing","https://github.com/Arno0x/EmbedInHTML","1","1","N/A","N/A","10","5","485","119","2017-09-27T13:16:06Z","2017-09-11T07:17:20Z","43083" +"*EmbedInHTML-master*",".{0,1000}EmbedInHTML\-master.{0,1000}","offensive_tool_keyword","EmbedInHTML","What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.","T1027 - T1566.001","TA0005 - TA0002","N/A","N/A","Phishing","https://github.com/Arno0x/EmbedInHTML","1","1","N/A","N/A","10","5","485","119","2017-09-27T13:16:06Z","2017-09-11T07:17:20Z","43084" +"*emdnaia/RustPotato*",".{0,1000}emdnaia\/RustPotato.{0,1000}","offensive_tool_keyword","RustPotato","A Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privileges","T1134.001 - T1055.011","TA0004","N/A","N/A","Privilege Escalation","https://github.com/emdnaia/RustPotato","1","1","N/A","N/A","10","1","0","0","2025-01-06T18:10:17Z","2025-01-06T19:44:57Z","43085" +"*emilarner/revsocks*",".{0,1000}emilarner\/revsocks.{0,1000}","offensive_tool_keyword","revsocks","Cross-platform SOCKS5 proxy server program/library written in C that can also reverse itself over a firewall.","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/emilarner/revsocks","1","1","N/A","https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/iran-apt-seedworm-africa-telecoms","10","10","31","4","2022-08-08T07:59:16Z","2022-03-29T22:12:18Z","43088" +"*Empire.Agent.Coms.*",".{0,1000}Empire\.Agent\.Coms\..{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","43093" +"*empire/client/*.py*",".{0,1000}empire\/client\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","43098" +"*empire/server/*.py*",".{0,1000}empire\/server\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","43099" +"*empire/server/downloads/*",".{0,1000}empire\/server\/downloads\/.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","43100" +"*empire/server/downloads/logs/*",".{0,1000}empire\/server\/downloads\/logs\/.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","43102" +"*empire_exec.py*",".{0,1000}empire_exec\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","43104" +"*empire_server.*",".{0,1000}empire_server\..{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","43105" +"*empireadmin*",".{0,1000}empireadmin.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","43106" +"*empire-chain.pem*",".{0,1000}empire\-chain\.pem.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","43107" +"*EmpireCORSMiddleware*",".{0,1000}EmpireCORSMiddleware.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","43108" +"*Empire-GUI.git*",".{0,1000}Empire\-GUI\.git.{0,1000}","offensive_tool_keyword","empire","The Empire Multiuser GUI is a graphical interface to the Empire post-exploitation Framework","T1059.003 - T1071.001 - T1543.003 - T1041 - T1562.001","TA0002 - TA0010 - TA0011 ","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","C2","https://github.com/EmpireProject/Empire-GUI","1","1","N/A","N/A","10","5","495","146","2022-03-10T11:34:46Z","2018-04-20T21:59:52Z","43109" +"*Empire-master*",".{0,1000}Empire\-master.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","43110" +"*empire-priv.key*",".{0,1000}empire\-priv\.key.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","43111" +"*EmpireProject*",".{0,1000}EmpireProject.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation framework that includes a pure-PowerShell2.0 Windows agent. and a pure Python 2.6/2.7 Linux/OS X agent. It is the merge of the previous PowerShell Empire and Python EmPyre projects. The framework offers cryptologically-secure communications and a flexible architecture. On the PowerShell side. Empire implements the ability to run PowerShell agents without needing powershell.exe. rapidly deployable post-exploitation modules ranging from key loggers to Mimikatz. and adaptable communications to evade network detection. all wrapped up in a usability-focused framework. PowerShell Empire premiered at BSidesLV in 2015 and Python EmPyre premeiered at HackMiami 2016.","T1027 - T1059 - T1071 - T1070 - T1072","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","43112" +"*Empire-Sponsors.git*",".{0,1000}Empire\-Sponsors\.git.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","43113" +"*empire-test-kalirolling*",".{0,1000}empire\-test\-kalirolling.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","43114" +"*emptybowl.py*",".{0,1000}emptybowl\.py.{0,1000}","offensive_tool_keyword","EQGRP tools","Equation Group hack tool leaked by ShadowBrokers- file emptybowl.py RCE for MailCenter Gateway (mcgate) - an application that comes with Asia Info Message Center mailserver buffer overflow allows a string passed to popen() call to be controlled by an attacker arbitraty cmd execute known to work only for AIMC Version 2.9.5.1","T1053 - T1064 - T1059 - T1218","TA0002 - TA0007","N/A","N/A","Exploitation tool","https://github.com/x0rz/EQGRP/blob/master/Linux/bin/emptybowl.py","1","1","N/A","N/A","N/A","10","4124","2071","2017-05-24T21:12:59Z","2017-04-08T14:03:59Z","43115" +"*enable_persistence.py*",".{0,1000}enable_persistence\.py.{0,1000}","offensive_tool_keyword","FudgeC2","FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.","T1021.002 - T1105 - T1059.001 - T1059.003","TA0008 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/Ziconius/FudgeC2","1","1","N/A","N/A","10","10","253","54","2023-05-01T21:13:56Z","2018-09-09T21:05:21Z","43118" +"*EnableAllParentPrivileges.c*",".{0,1000}EnableAllParentPrivileges\.c.{0,1000}","offensive_tool_keyword","PSBits","Simple tool enabling all privileges in the parent process (usually cmd.exe) token. Useful if you have SeBackup or SeRestore and need a cmd.exe ignoring all ACLs","T1105 - T1203 - T1221 - T1027 - T1036","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/gtworek/PSBits/tree/master/EnableAllParentPrivileges","1","1","N/A","N/A","N/A","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","43121" +"*EnableAllParentPrivileges.exe*",".{0,1000}EnableAllParentPrivileges\.exe.{0,1000}","offensive_tool_keyword","PSBits","Simple tool enabling all privileges in the parent process (usually cmd.exe) token. Useful if you have SeBackup or SeRestore and need a cmd.exe ignoring all ACLs","T1105 - T1203 - T1221 - T1027 - T1036","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/gtworek/PSBits/tree/master/EnableAllParentPrivileges","1","1","N/A","N/A","N/A","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","43122" +"*Enabled_Users1.txt*",".{0,1000}Enabled_Users1\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","43124" +"*Enable-DuplicateToken*",".{0,1000}Enable\-DuplicateToken.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","43125" +"*EnableRDesktopImplant*",".{0,1000}EnableRDesktopImplant.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","43127" +"*Enable-SeAssignPrimaryTokenPrivilege*",".{0,1000}Enable\-SeAssignPrimaryTokenPrivilege.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","43128" +"*Enable-SeDebugPrivilege*",".{0,1000}Enable\-SeDebugPrivilege.{0,1000}","offensive_tool_keyword","mimikatz","Invoke-Mimikatz.ps1 function name","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Invoke-Mimikatz.ps1","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","43130" +"*encdatavault2john.py*",".{0,1000}encdatavault2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","43136" +"*encfs2john.py*",".{0,1000}encfs2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","43137" +"*EncodeGroup/AggressiveProxy*",".{0,1000}EncodeGroup\/AggressiveProxy.{0,1000}","offensive_tool_keyword","cobaltstrike","Project to enumerate proxy configurations and generate shellcode from CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EncodeGroup/AggressiveProxy","1","1","N/A","N/A","10","10","141","25","2020-11-04T16:08:11Z","2020-11-04T12:53:00Z","43143" +"*EncodeGroup/UAC-SilentClean*",".{0,1000}EncodeGroup\/UAC\-SilentClean.{0,1000}","offensive_tool_keyword","cobaltstrike","New UAC bypass for Silent Cleanup for CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EncodeGroup/UAC-SilentClean","1","1","N/A","N/A","10","10","192","31","2021-07-14T13:51:02Z","2020-10-07T13:25:21Z","43144" +"*encodeScriptPolyglot*",".{0,1000}encodeScriptPolyglot.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","43145" +"*encrypt/encryptFile.go*",".{0,1000}encrypt\/encryptFile\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","Implement load Cobalt Strike & Metasploit&Sliver shellcode with golang","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/zha0gongz1/DesertFox","1","1","N/A","N/A","10","10","125","26","2023-02-02T07:02:12Z","2021-02-04T09:04:13Z","43149" +"*encrypt/encryptUrl.go*",".{0,1000}encrypt\/encryptUrl\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","Implement load Cobalt Strike & Metasploit&Sliver shellcode with golang","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/zha0gongz1/DesertFox","1","1","N/A","N/A","10","10","125","26","2023-02-02T07:02:12Z","2021-02-04T09:04:13Z","43150" +"*EncryptedZIP.csproj*",".{0,1000}EncryptedZIP\.csproj.{0,1000}","offensive_tool_keyword","EncryptedZIP","Compresses a directory or file and then encrypts the ZIP file with a supplied key using AES256 CFB. This assembly also clears the key out of memory using RtlZeroMemory","T1564.001 - T1027 - T1214.001","TA0005 - TA0010","N/A","N/A","Defense Evasion","https://github.com/matterpreter/OffensiveCSharp/tree/master/EncryptedZIP","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","43156" +"*EncryptedZIP.exe*",".{0,1000}EncryptedZIP\.exe.{0,1000}","offensive_tool_keyword","EncryptedZIP","Compresses a directory or file and then encrypts the ZIP file with a supplied key using AES256 CFB. This assembly also clears the key out of memory using RtlZeroMemory","T1564.001 - T1027 - T1214.001","TA0005 - TA0010","N/A","N/A","Defense Evasion","https://github.com/matterpreter/OffensiveCSharp/tree/master/EncryptedZIP","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","43157" +"*endpoint_takeover.exe*",".{0,1000}endpoint_takeover\.exe.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","43163" +"*Endpoint-EE15B860-9EEC-EC11-BB3D-0022482CA4A7.json*",".{0,1000}Endpoint\-EE15B860\-9EEC\-EC11\-BB3D\-0022482CA4A7\.json.{0,1000}","offensive_tool_keyword","power-pwn","An offensive and defensive security toolset for Microsoft 365 Power Platform","T1078 - T1078.004 - T1136 - T1136.001 - T1021 - T1021.003 - T1114 - T1114.002","TA0003 - TA0004 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/mbrg/power-pwn","1","1","N/A","N/A","10","10","939","100","2025-03-20T08:54:43Z","2022-06-14T11:40:21Z","43164" +"*Enelg52/KittyStager*",".{0,1000}Enelg52\/KittyStager.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","43168" +"*engineseller/localtonet*",".{0,1000}engineseller\/localtonet.{0,1000}","offensive_tool_keyword","localtonet","LocaltoNet is a reverse proxy that enables you to expose your localhost services to the internet","T1090 - T1102 - T1071 - T1105","TA0010 - TA0011 - TA0009 - TA0003 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/engineseller/localtonet","1","1","N/A","N/A","10","1","6","4","2022-01-31T03:19:25Z","2022-01-31T03:17:18Z","43170" +"*engjibo/NetUser*",".{0,1000}engjibo\/NetUser.{0,1000}","offensive_tool_keyword","cobaltstrike","Use windows api to add users which can be used when net is unavailable","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/lengjibo/NetUser","1","1","N/A","N/A","10","10","420","90","2021-09-29T14:22:09Z","2020-01-09T08:33:27Z","43171" +"*enigma_fileless_uac_bypass*",".{0,1000}enigma_fileless_uac_bypass.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","43172" +"*enjoiz/Privesc*",".{0,1000}enjoiz\/Privesc.{0,1000}","offensive_tool_keyword","Privesc","Windows PowerShell script that finds misconfiguration issues which can lead to privilege escalation","T1068 - T1548 - T1082 - T1078","TA0004","N/A","N/A","Privilege Escalation","https://github.com/enjoiz/Privesc","1","1","N/A","N/A","10","6","595","97","2024-12-01T15:24:41Z","2015-11-19T13:22:01Z","43173" +"*enkomio/AlanFramework*",".{0,1000}enkomio\/AlanFramework.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","43174" +"*enpass2john.py*",".{0,1000}enpass2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","43175" +"*enpass5tojohn.py*",".{0,1000}enpass5tojohn\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","43176" +"*Enter-WmiShell.ps1*",".{0,1000}Enter\-WmiShell\.ps1.{0,1000}","offensive_tool_keyword","Wmisploit","WmiSploit is a small set of PowerShell scripts that leverage the WMI service for post-exploitation use.","T1087 - T1059.001 - T1047","TA0003 - TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/secabstraction/WmiSploit","1","1","N/A","N/A","N/A","2","164","34","2015-08-28T23:56:00Z","2015-03-15T03:30:02Z","43182" +"*enum_artifacts_list.txt*",".{0,1000}enum_artifacts_list\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43185" +"*enum_av_excluded.rb*",".{0,1000}enum_av_excluded\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43186" +"*enum_avproducts.py*",".{0,1000}enum_avproducts\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","43187" +"*enum_brocade.md*",".{0,1000}enum_brocade\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43188" +"*enum_domain_info.py*",".{0,1000}enum_domain_info\.py.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","43189" +"*enum_firefox.rb*",".{0,1000}enum_firefox\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43191" +"*enum_hostfile.md*",".{0,1000}enum_hostfile\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43192" +"*enum_logged_on_users*",".{0,1000}enum_logged_on_users.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43193" +"*enum_logged_on_users.*",".{0,1000}enum_logged_on_users\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43194" +"*enum_mikrotik.md*",".{0,1000}enum_mikrotik\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43195" +"*enum_ms_product_keys.*",".{0,1000}enum_ms_product_keys\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43196" +"*enum_printers.py*",".{0,1000}enum_printers\.py.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","43197" +"*enum_shares.py*",".{0,1000}enum_shares\.py.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","43198" +"*enum_shares.rb*",".{0,1000}enum_shares\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43199" +"*enum_vmware.rb*",".{0,1000}enum_vmware\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43200" +"*enum_vyos.md*",".{0,1000}enum_vyos\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43201" +"*enum4linux_*.txt*",".{0,1000}enum4linux_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","43203" +"*EnumCLR.exe*",".{0,1000}EnumCLR\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF to identify processes with the CLR loaded with a goal of identifying SpawnTo / injection candidates.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://gist.github.com/G0ldenGunSec/8ca0e853dd5637af2881697f8de6aecc","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","43206" +"*Enum-Creds*",".{0,1000}Enum\-Creds.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","43207" +"*enumerate.cna*",".{0,1000}enumerate\.cna.{0,1000}","offensive_tool_keyword","red-team-scripts","Cobalt Strike Aggressor script function and alias to perform some rudimentary Windows host enumeration with Beacon built-in commands (i.e. no Powershell. binary calls. or process injection). Additionally. adds a basic enumerate alias for Linux based systems in SSH sessions.","T1595","TA0007","N/A","N/A","Reconnaissance","https://github.com/threatexpress/red-team-scripts","1","1","N/A","N/A","N/A","10","1122","195","2024-11-19T19:39:01Z","2017-05-01T13:53:05Z","43211" +"*Enumeration/DesktopACL*",".{0,1000}Enumeration\/DesktopACL.{0,1000}","offensive_tool_keyword","Tokenvator","A tool to elevate privilege with Windows Tokens","T1134 - T1078","TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/0xbadjuju/Tokenvator","1","1","N/A","N/A","N/A","10","1038","201","2023-10-06T13:17:05Z","2017-12-08T01:29:11Z","43219" +"*eo.oe.kiwi*",".{0,1000}eo\.oe\.kiwi.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","43224" +"*eop_pdfwkrnl.py*",".{0,1000}eop_pdfwkrnl\.py.{0,1000}","offensive_tool_keyword","VDR","Vulnerable driver research tool - result and exploit PoCs","T1547.009 - T1210 - T1068 - T1055","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/TakahiroHaruyama/VDR","1","1","N/A","N/A","10","2","192","29","2023-11-01T00:06:55Z","2023-10-23T08:34:44Z","43227" +"*eop_pdfwkrnl_loop.py*",".{0,1000}eop_pdfwkrnl_loop\.py.{0,1000}","offensive_tool_keyword","VDR","Vulnerable driver research tool - result and exploit PoCs","T1547.009 - T1210 - T1068 - T1055","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/TakahiroHaruyama/VDR","1","1","N/A","N/A","10","2","192","29","2023-11-01T00:06:55Z","2023-10-23T08:34:44Z","43228" +"*eop_rtport.py*",".{0,1000}eop_rtport\.py.{0,1000}","offensive_tool_keyword","VDR","Vulnerable driver research tool - result and exploit PoCs","T1547.009 - T1210 - T1068 - T1055","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/TakahiroHaruyama/VDR","1","1","N/A","N/A","10","2","192","29","2023-11-01T00:06:55Z","2023-10-23T08:34:44Z","43229" +"*eop_stdcdrvws64.py*",".{0,1000}eop_stdcdrvws64\.py.{0,1000}","offensive_tool_keyword","VDR","Vulnerable driver research tool - result and exploit PoCs","T1547.009 - T1210 - T1068 - T1055","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/TakahiroHaruyama/VDR","1","1","N/A","N/A","10","2","192","29","2023-11-01T00:06:55Z","2023-10-23T08:34:44Z","43230" +"*epinna/weevely3*",".{0,1000}\/Weevely3.{0,1000}","offensive_tool_keyword","Weevely3","Weevely is a web shell designed for post-exploitation purposes that can be extended over the network at runtime","T1059.003 - T1100 - T1071.001 - T1219 - T1078","TA0002 - TA0003 - TA0005 - TA0011 - TA0008","N/A","Sandworm","Resource Development","https://github.com/epinna/weevely3","1","1","N/A","N/A","8","10","3292","612","2024-10-18T04:32:13Z","2014-09-20T10:16:49Z","43232" +"*erebe/wstunnel*",".{0,1000}erebe\/wstunnel.{0,1000}","offensive_tool_keyword","wstunnel","Tunnel all your traffic over websocket protocol - Bypass firewalls/DPI - Static binary available","T1572 - T1090 - T1071","TA0005- TA0010 - TA0011","N/A","Scattered Spider*","Data Exfiltration","https://github.com/erebe/wstunnel","1","1","N/A","N/A","10","10","4759","404","2025-04-15T11:07:11Z","2016-05-14T23:58:43Z","43236" +"*Erebus/*spacerunner*",".{0,1000}Erebus\/.{0,1000}spacerunner.{0,1000}","offensive_tool_keyword","cobaltstrike","Erebus CobaltStrike post penetration testing plugin","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DeEpinGh0st/Erebus","1","1","N/A","N/A","10","10","1518","221","2021-10-28T06:20:51Z","2019-09-26T09:32:00Z","43237" +"*ERPScan-tockenchpoken.zip*",".{0,1000}ERPScan\-tockenchpoken\.zip.{0,1000}","offensive_tool_keyword","linikatz","linikatz is a tool to attack AD on UNIX","T1003.002 - T1558.003 - T1078 - T1550.001","TA0006 - TA0001 - TA0004 - TA0003","N/A","N/A","Exploitation tool","https://github.com/CiscoCXSecurity/linikatz","1","1","#linux","N/A","10","6","552","79","2023-10-19T17:01:47Z","2018-11-15T22:19:47Z","43238" +"*eRv6yTYhShell*",".{0,1000}eRv6yTYhShell.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","43242" +"*erwan2212/NTHASH-FPC*",".{0,1000}erwan2212\/NTHASH\-FPC.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","43243" +"*ES.Alan.Core/*",".{0,1000}ES\.Alan\.Core\/.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","43244" +"*es3n1n/no-defender*",".{0,1000}es3n1n\/no\-defender.{0,1000}","offensive_tool_keyword","no_defender","disable windows defender. (through the WSC api)","T1089","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/es3n1n/no-defender","1","1","N/A","N/A","10","10","1907","13","2024-06-08T01:29:18Z","2024-05-23T05:18:38Z","43245" +"*EspressoCake/PPLDump_BOF*",".{0,1000}EspressoCake\/PPLDump_BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/PPLDump_BOF","1","1","N/A","N/A","10","10","140","25","2021-09-24T07:10:04Z","2021-09-24T07:05:59Z","43251" +"*et22fibzuzfyzgurm35sttm52qbzvdgzy5qhzy46a3gmkrrht3lec5ad.onion*",".{0,1000}et22fibzuzfyzgurm35sttm52qbzvdgzy5qhzy46a3gmkrrht3lec5ad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","43266" +"*Eternalblue-*.exe*",".{0,1000}Eternalblue\-.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","43268" +"*EternalBlue.ps1*",".{0,1000}EternalBlue\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1064","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","43269" +"*eternalblue.rb*",".{0,1000}eternalblue\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43270" +"*eternalblue_exploit10.py*",".{0,1000}eternalblue_exploit10\.py.{0,1000}","offensive_tool_keyword","AutoBlue-MS17-010","automated exploit code for MS17-010","T1210 - T1040 - T1059.001","TA0001 - TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/3ndG4me/AutoBlue-MS17-010","1","1","N/A","N/A","6","10","1240","317","2023-12-24T19:22:26Z","2017-11-25T09:03:38Z","43271" +"*eternalblue_exploit7.py*",".{0,1000}eternalblue_exploit7\.py.{0,1000}","offensive_tool_keyword","AutoBlue-MS17-010","automated exploit code for MS17-010","T1210 - T1040 - T1059.001","TA0001 - TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/3ndG4me/AutoBlue-MS17-010","1","1","N/A","N/A","6","10","1240","317","2023-12-24T19:22:26Z","2017-11-25T09:03:38Z","43272" +"*eternalblue_exploit8.py*",".{0,1000}eternalblue_exploit8\.py.{0,1000}","offensive_tool_keyword","AutoBlue-MS17-010","automated exploit code for MS17-010","T1210 - T1040 - T1059.001","TA0001 - TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/3ndG4me/AutoBlue-MS17-010","1","1","N/A","N/A","6","10","1240","317","2023-12-24T19:22:26Z","2017-11-25T09:03:38Z","43273" +"*eternalblue_kshellcode_x64.asm*",".{0,1000}eternalblue_kshellcode_x64\.asm.{0,1000}","offensive_tool_keyword","AutoBlue-MS17-010","automated exploit code for MS17-010","T1210 - T1040 - T1059.001","TA0001 - TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/3ndG4me/AutoBlue-MS17-010","1","1","N/A","N/A","6","10","1240","317","2023-12-24T19:22:26Z","2017-11-25T09:03:38Z","43274" +"*eternalblue_kshellcode_x86.asm*",".{0,1000}eternalblue_kshellcode_x86\.asm.{0,1000}","offensive_tool_keyword","AutoBlue-MS17-010","automated exploit code for MS17-010","T1210 - T1040 - T1059.001","TA0001 - TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/3ndG4me/AutoBlue-MS17-010","1","1","N/A","N/A","6","10","1240","317","2023-12-24T19:22:26Z","2017-11-25T09:03:38Z","43275" +"*eternalblue_poc.py*",".{0,1000}eternalblue_poc\.py.{0,1000}","offensive_tool_keyword","AutoBlue-MS17-010","automated exploit code for MS17-010","T1210 - T1040 - T1059.001","TA0001 - TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/3ndG4me/AutoBlue-MS17-010","1","1","N/A","N/A","6","10","1240","317","2023-12-24T19:22:26Z","2017-11-25T09:03:38Z","43276" +"*eternalblue_sc_merge.py*",".{0,1000}eternalblue_sc_merge\.py.{0,1000}","offensive_tool_keyword","AutoBlue-MS17-010","automated exploit code for MS17-010","T1210 - T1040 - T1059.001","TA0001 - TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/3ndG4me/AutoBlue-MS17-010","1","1","N/A","N/A","6","10","1240","317","2023-12-24T19:22:26Z","2017-11-25T09:03:38Z","43277" +"*Eternalblue-Doublepulsar*",".{0,1000}Eternalblue\-Doublepulsar.{0,1000}","offensive_tool_keyword","Eternalblue-Doublepulsar-Metasploit","doublepulsa vulnerability exploit DoublePulsar is a backdoor implant tool developed by the U.S. National Security Agencys (NSA) Equation Group that was leaked by The Shadow Brokers in early 2017.[3] The tool infected more than 200.000 Microsoft Windows computers in only a few weeks.[4][5][3][6][7] and was used alongside EternalBlue in the May 2017 WannaCry ransomware attack.[8][9][10] A variant of DoublePulsar was first seen in the wild in March 2016. as discovered by Symantec. [11]","T1055 - T1218","TA0002 - TA0003","N/A","APT15 - Calypso - Equation Group","Exploitation tool","https://github.com/Telefonica/Eternalblue-Doublepulsar-Metasploit","1","1","N/A","N/A","N/A","10","1115","520","2021-03-31T09:44:10Z","2017-04-24T12:41:56Z","43278" +"*EternalHushFramework-*-SNAPSHOT.jar*",".{0,1000}EternalHushFramework\-.{0,1000}\-SNAPSHOT\.jar.{0,1000}","offensive_tool_keyword","EternalHushFramework","EternalHush Framework is a new open source project that is an advanced C&C framework. Designed specifically for Windows operating systems","T1071.001 - T1132.001 - T1059.003 - T1547.001","TA0011 - TA0005 - TA0010 - TA0002","N/A","Equation Group","C2","https://github.com/APT64/EternalHushFramework","1","1","N/A","N/A","10","10","11","1","2023-10-28T13:08:06Z","2023-07-09T09:13:21Z","43279" +"*EternalHushFramework-main*",".{0,1000}EternalHushFramework\-main.{0,1000}","offensive_tool_keyword","EternalHushFramework","EternalHush Framework is a new open source project that is an advanced C&C framework. Designed specifically for Windows operating systems","T1071.001 - T1132.001 - T1059.003 - T1547.001","TA0011 - TA0005 - TA0010 - TA0002","N/A","Equation Group","C2","https://github.com/APT64/EternalHushFramework","1","1","N/A","N/A","10","10","11","1","2023-10-28T13:08:06Z","2023-07-09T09:13:21Z","43280" +"*EternalHushMain.java*",".{0,1000}EternalHushMain\.java.{0,1000}","offensive_tool_keyword","EternalHushFramework","EternalHush Framework is a new open source project that is an advanced C&C framework. Designed specifically for Windows operating systems","T1071.001 - T1132.001 - T1059.003 - T1547.001","TA0011 - TA0005 - TA0010 - TA0002","N/A","Equation Group","C2","https://github.com/APT64/EternalHushFramework","1","1","N/A","N/A","10","10","11","1","2023-10-28T13:08:06Z","2023-07-09T09:13:21Z","43281" +"*EternalHushWindow.java*",".{0,1000}EternalHushWindow\.java.{0,1000}","offensive_tool_keyword","EternalHushFramework","EternalHush Framework is a new open source project that is an advanced C&C framework. Designed specifically for Windows operating systems","T1071.001 - T1132.001 - T1059.003 - T1547.001","TA0011 - TA0005 - TA0010 - TA0002","N/A","Equation Group","C2","https://github.com/APT64/EternalHushFramework","1","1","N/A","N/A","10","10","11","1","2023-10-28T13:08:06Z","2023-07-09T09:13:21Z","43282" +"*ethereum2john.py*",".{0,1000}ethereum2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","43283" +"*ETWEventSubscription*Program.cs*",".{0,1000}ETWEventSubscription.{0,1000}Program\.cs.{0,1000}","offensive_tool_keyword","ETWEventSubscription","Similar to WMI event subscriptions but leverages Event Tracing for Windows. When the event on the system occurs currently either when any user logs in or a specified process is started - the DoEvil() method is executed.","T1053.005 - T1546.003 - T1055.001","TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/matterpreter/OffensiveCSharp/tree/master/ETWEventSubscription","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","43285" +"*EtwHash.exe*",".{0,1000}EtwHash\.exe.{0,1000}","offensive_tool_keyword","ETWHash","C# POC to extract NetNTLMv1/v2 hashes from ETW provider","T1556.001","TA0009 ","N/A","N/A","Credential Access","https://github.com/nettitude/ETWHash","1","1","N/A","N/A","N/A","3","256","29","2023-05-10T06:45:06Z","2023-04-26T15:53:01Z","43289" +"*EtwHash.git*",".{0,1000}EtwHash\.git.{0,1000}","offensive_tool_keyword","ETWHash","C# POC to extract NetNTLMv1/v2 hashes from ETW provider","T1556.001","TA0009 ","N/A","N/A","Credential Access","https://github.com/nettitude/ETWHash","1","1","N/A","N/A","N/A","3","256","29","2023-05-10T06:45:06Z","2023-04-26T15:53:01Z","43290" +"*ETWHash.sln*",".{0,1000}ETWHash\.sln.{0,1000}","offensive_tool_keyword","ETWHash","C# POC to extract NetNTLMv1/v2 hashes from ETW provider","T1556.001","TA0009 ","N/A","N/A","Credential Access","https://github.com/nettitude/ETWHash","1","1","N/A","N/A","N/A","3","256","29","2023-05-10T06:45:06Z","2023-04-26T15:53:01Z","43291" +"*etwti-hook.*",".{0,1000}etwti\-hook\..{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","43292" +"*eu.mirrors.cicku.me/blackarch/*/os/*",".{0,1000}eu\.mirrors\.cicku\.me\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","43293" +"*eu1-etc.ethermine.org*",".{0,1000}eu1\-etc\.ethermine\.org.{0,1000}","offensive_tool_keyword","lolminer","NVIDIA+AMD GPU Miner","T1496","TA0040","N/A","N/A","Cryptomining","https://github.com/Lolliedieb/lolMiner-releases","1","1","N/A","N/A","9","10","2781","601","2025-02-01T20:03:57Z","2018-10-27T20:35:03Z","43294" +"*europe.equihash-hub.miningpoolhub.com*",".{0,1000}europe\.equihash\-hub\.miningpoolhub\.com.{0,1000}","offensive_tool_keyword","lolminer","NVIDIA+AMD GPU Miner","T1496","TA0040","N/A","N/A","Cryptomining","https://github.com/Lolliedieb/lolMiner-releases","1","1","N/A","N/A","9","10","2781","601","2025-02-01T20:03:57Z","2018-10-27T20:35:03Z","43296" +"*evallen/ntpescape*",".{0,1000}evallen\/ntpescape.{0,1000}","offensive_tool_keyword","ntpescape","ntpescape is a tool that can stealthily (but slowly) exfiltrate data from a computer using the Network Time Protocol (NTP).","T1048 - T1071.004","TA0010 - TA0009","N/A","Black Basta","Data Exfiltration","https://github.com/evallen/ntpescape","1","1","N/A","N/A","10","2","138","15","2023-11-14T18:54:14Z","2022-09-22T16:25:15Z","43300" +"*evasion_shellcode.js*",".{0,1000}evasion_shellcode\.js.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43303" +"*EventAggregation.dll.bak*",".{0,1000}EventAggregation\.dll\.bak.{0,1000}","offensive_tool_keyword","cobaltstrike","Takes the original PPLFault and the original included DumpShellcode and combinds it all into a BOF targeting cobalt strike.","T1055 - T1078.003","TA0002 - TA0006","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Credential Access","https://github.com/trustedsec/PPLFaultDumpBOF","1","1","N/A","N/A","N/A","2","140","11","2023-05-17T12:57:20Z","2023-05-16T13:02:22Z","43305" +"*EventAggregation.dll.bak*",".{0,1000}EventAggregation\.dll\.bak.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","43306" +"*EventAggregation.dll.patched*",".{0,1000}EventAggregation\.dll\.patched.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","43307" +"*EventAggregationPH.dll*",".{0,1000}EventAggregationPH\.dll.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","43308" +"*eventlog_dos.exe*",".{0,1000}eventlog_dos\.exe.{0,1000}","offensive_tool_keyword","EventLogCrasher","crash the Windows Event Log service of any other Windows 10/Windows Server 2022 machine on the same domain","T1562.002 - T1489","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/floesen/EventLogCrasher","1","1","N/A","N/A","10","2","186","34","2024-01-23T14:04:23Z","2024-01-23T09:27:27Z","43315" +"*eventlog_fucker.py*",".{0,1000}eventlog_fucker\.py.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","43316" +"*EventLogCrasher.exe*",".{0,1000}EventLogCrasher\.exe.{0,1000}","offensive_tool_keyword","EventLogCrasher","crash the Windows Event Log service of any other Windows 10/Windows Server 2022 machine on the same domain","T1562.002 - T1489","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/floesen/EventLogCrasher","1","1","N/A","N/A","10","2","186","34","2024-01-23T14:04:23Z","2024-01-23T09:27:27Z","43317" +"*EventLogCrasher-main*",".{0,1000}EventLogCrasher\-main.{0,1000}","offensive_tool_keyword","EventLogCrasher","crash the Windows Event Log service of any other Windows 10/Windows Server 2022 machine on the same domain","T1562.002 - T1489","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/floesen/EventLogCrasher","1","1","N/A","N/A","10","2","186","34","2024-01-23T14:04:23Z","2024-01-23T09:27:27Z","43318" +"*Eventlogedit-evtx--Evolution-master-v1.1.zip*",".{0,1000}Eventlogedit\-evtx\-\-Evolution\-master\-v1\.1\.zip.{0,1000}","offensive_tool_keyword","Eventlogedit-evtx--Evolution","","T1070.001 - T1564.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/3gstudent/Eventlogedit-evtx--Evolution","1","1","N/A","N/A","9","3","267","62","2021-04-17T01:28:00Z","2018-06-05T01:21:20Z","43319" +"*eventlog-fucker.py*",".{0,1000}eventlog\-fucker\.py.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","43320" +"*eventspy.cna*",".{0,1000}eventspy\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Bloodhound Attack Path Automation in CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/vysecurity/ANGRYPUPPY","1","1","N/A","N/A","10","10","316","87","2020-04-26T17:35:31Z","2017-07-11T14:18:07Z","43321" +"*EventSub-Aggressor.*",".{0,1000}EventSub\-Aggressor\..{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of beacon BOF written to learn windows and cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Yaxser/CobaltStrike-BOF","1","1","N/A","N/A","10","10","347","57","2023-02-24T13:12:14Z","2020-10-08T01:12:41Z","43322" +"*EventViewerRCE.ps1*",".{0,1000}EventViewerRCE\.ps1.{0,1000}","offensive_tool_keyword","EventViewer-UACBypass","RCE through Unsafe .Net Deserialization in Windows Event Viewer which leads to UAC bypass","T1078.004 - T1216 - T1068","TA0004 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/CsEnox/EventViewer-UACBypass","1","1","N/A","N/A","10","2","184","21","2022-04-29T09:42:37Z","2022-04-27T12:56:59Z","43323" +"*EventViewerUAC.*",".{0,1000}EventViewerUAC\..{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File implementation of Event Viewer deserialization UAC bypass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/TrustedPath-UACBypass-BOF","1","1","N/A","N/A","10","10","133","40","2021-08-16T07:49:55Z","2021-08-07T03:40:33Z","43324" +"*EventViewerUAC.*",".{0,1000}EventViewerUAC\..{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File implementation of Event Viewer deserialization UAC bypass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Octoberfest7/EventViewerUAC_BOF","1","1","N/A","N/A","10","10","131","31","2022-05-06T17:43:05Z","2022-05-02T02:08:52Z","43325" +"*EventViewerUAC.x64*",".{0,1000}EventViewerUAC\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File implementation of Event Viewer deserialization UAC bypass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/TrustedPath-UACBypass-BOF","1","1","N/A","N/A","10","10","133","40","2021-08-16T07:49:55Z","2021-08-07T03:40:33Z","43326" +"*EventViewerUAC.x86*",".{0,1000}EventViewerUAC\.x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File implementation of Event Viewer deserialization UAC bypass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/TrustedPath-UACBypass-BOF","1","1","N/A","N/A","10","10","133","40","2021-08-16T07:49:55Z","2021-08-07T03:40:33Z","43327" +"*EventViewerUAC_BOF*",".{0,1000}EventViewerUAC_BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File implementation of Event Viewer deserialization UAC bypass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Octoberfest7/EventViewerUAC_BOF","1","1","N/A","N/A","10","10","131","31","2022-05-06T17:43:05Z","2022-05-02T02:08:52Z","43328" +"*eventvwr_elevator*",".{0,1000}eventvwr_elevator.{0,1000}","offensive_tool_keyword","cobaltstrike","The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/ElevateKit","1","1","N/A","N/A","10","10","912","203","2020-06-22T21:12:24Z","2016-12-08T03:51:09Z","43329" +"*-EventVwrBypass*",".{0,1000}\-EventVwrBypass.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1118","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","43330" +"*eversinc33/1.6-C2*",".{0,1000}eversinc33\/1\.6\-C2.{0,1000}","offensive_tool_keyword","1.6-C2","Using the Counter Strike 1.6 RCON protocol as a C2 Channel","T1071 - T1095 - T1572","TA0011 - TA0010","N/A","N/A","C2","https://github.com/eversinc33/1.6-C2","1","1","N/A","N/A","6","10","78","5","2025-02-19T15:34:37Z","2024-01-23T18:30:00Z","43331" +"*EvilClippy.exe*",".{0,1000}EvilClippy\.exe.{0,1000}","offensive_tool_keyword","EvilClippy","A cross-platform assistant for creating malicious MS Office documents","T1566.001 - T1059.001 - T1204.002","TA0004 - TA0002","N/A","N/A","Phishing","https://github.com/outflanknl/EvilClippy","1","1","N/A","N/A","10","10","2165","402","2023-12-27T12:37:47Z","2019-03-26T12:14:03Z","43333" +"*EvilClippy.exe*",".{0,1000}EvilClippy\.exe.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","43334" +"*EvilClippyManager.*",".{0,1000}EvilClippyManager\..{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","43335" +"*EvilClippy-master*",".{0,1000}EvilClippy\-master.{0,1000}","offensive_tool_keyword","EvilClippy","A cross-platform assistant for creating malicious MS Office documents","T1566.001 - T1059.001 - T1204.002","TA0004 - TA0002","N/A","N/A","Phishing","https://github.com/outflanknl/EvilClippy","1","1","N/A","N/A","10","10","2165","402","2023-12-27T12:37:47Z","2019-03-26T12:14:03Z","43336" +"*evilfeed.go*",".{0,1000}evilfeed\.go.{0,1000}","offensive_tool_keyword","gophish","Combination of evilginx2 and GoPhish","T1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113","TA0002 - TA0003","N/A","Black Basta","Phishing","https://github.com/fin3ss3g0d/evilgophish","1","1","N/A","N/A","10","10","1762","340","2024-06-15T17:48:11Z","2022-09-07T02:47:43Z","43338" +"*evilginx.exe*",".{0,1000}evilginx\.exe.{0,1000}","offensive_tool_keyword","evilginx2","Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication","T1557.002 - T1114 - T1539","TA0001","N/A","BlackCat - COLDRIVER - Black Basta","Phishing","https://github.com/kgretzky/evilginx2","1","1","N/A","N/A","10","10","12879","2234","2025-01-21T15:16:19Z","2018-07-10T09:59:52Z","43342" +"*evilginx2*",".{0,1000}evilginx2.{0,1000}","offensive_tool_keyword","evilginx2","Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication","T1557.002 - T1114 - T1539","TA0001","N/A","BlackCat - COLDRIVER - Black Basta","Phishing","https://github.com/kgretzky/evilginx2","1","1","N/A","N/A","10","10","12879","2234","2025-01-21T15:16:19Z","2018-07-10T09:59:52Z","43345" +"*evilginx2/releases/*",".{0,1000}evilginx2\/releases\/.{0,1000}","offensive_tool_keyword","evilginx2","Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication","T1557.002 - T1114 - T1539","TA0001","N/A","BlackCat - COLDRIVER - Black Basta","Phishing","https://github.com/kgretzky/evilginx2","1","1","N/A","N/A","10","10","12879","2234","2025-01-21T15:16:19Z","2018-07-10T09:59:52Z","43346" +"*evilginx-linux*",".{0,1000}evilginx\-linux.{0,1000}","offensive_tool_keyword","gophish","Combination of evilginx2 and GoPhish","T1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113","TA0002 - TA0003","N/A","Black Basta","Phishing","https://github.com/fin3ss3g0d/evilgophish","1","1","#linux","N/A","10","10","1762","340","2024-06-15T17:48:11Z","2022-09-07T02:47:43Z","43348" +"*evilginx-mastery*",".{0,1000}evilginx\-mastery.{0,1000}","offensive_tool_keyword","evilginx2","Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication","T1557.002 - T1114 - T1539","TA0001","N/A","BlackCat - COLDRIVER - Black Basta","Phishing","https://github.com/kgretzky/evilginx2","1","1","N/A","N/A","10","10","12879","2234","2025-01-21T15:16:19Z","2018-07-10T09:59:52Z","43349" +"*evilgophish*",".{0,1000}evilgophish.{0,1000}","offensive_tool_keyword","gophish","Combination of evilginx2 and GoPhish","T1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113","TA0002 - TA0003","N/A","Black Basta","Phishing","https://github.com/fin3ss3g0d/evilgophish","1","1","N/A","N/A","10","10","1762","340","2024-06-15T17:48:11Z","2022-09-07T02:47:43Z","43351" +"*EvilLsassTwin.exe*",".{0,1000}EvilLsassTwin\.exe.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43353" +"*EvilLsassTwin.exe*",".{0,1000}EvilLsassTwin\.exe.{0,1000}","offensive_tool_keyword","EvilLsassTwin","attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.","T1003.001 - T1055 - T1093","TA0006 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","9","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43354" +"*EvilLsassTwin.nim*",".{0,1000}EvilLsassTwin\.nim.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43355" +"*EvilLsassTwin.nim*",".{0,1000}EvilLsassTwin\.nim.{0,1000}","offensive_tool_keyword","EvilLsassTwin","attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.","T1003.001 - T1055 - T1093","TA0006 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","9","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43356" +"*evilmog/ntlmv1-multi*",".{0,1000}evilmog\/ntlmv1\-multi.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","43357" +"*EvilnoVNC-main*",".{0,1000}EvilnoVNC\-main.{0,1000}","offensive_tool_keyword","EvilnoVNC","EvilnoVNC is a Ready to go Phishing Platform","T1566 - T1110 - T1555 - T1204 - T1592","TA0001 - TA0006 - TA0009","N/A","N/A","Phishing","https://github.com/JoelGMSec/EvilnoVNC","1","1","N/A","N/A","9","10","960","169","2025-03-04T15:59:27Z","2022-09-04T10:48:49Z","43364" +"*eviloffice.exe*",".{0,1000}eviloffice\.exe.{0,1000}","offensive_tool_keyword","EvilClippy","A cross-platform assistant for creating malicious MS Office documents","T1566.001 - T1059.001 - T1204.002","TA0004 - TA0002","N/A","N/A","Phishing","https://github.com/outflanknl/EvilClippy","1","1","N/A","N/A","10","10","2165","402","2023-12-27T12:37:47Z","2019-03-26T12:14:03Z","43366" +"*evil-proxy.gemspec*",".{0,1000}evil\-proxy\.gemspec.{0,1000}","offensive_tool_keyword","evil-proxy","A ruby http/https proxy to do EVIL things","T1557 - T1110.001 - T1563.001","TA0006 - TA0001 - TA0009 - TA0040","N/A","N/A","Phishing","https://github.com/bbtfr/evil-proxy","1","1","N/A","N/A","9","2","172","96","2023-10-30T07:49:40Z","2015-07-30T01:54:40Z","43369" +"*evil-proxy-0.1.0*",".{0,1000}evil\-proxy\-0\.1\.0.{0,1000}","offensive_tool_keyword","evil-proxy","A ruby http/https proxy to do EVIL things","T1557 - T1110.001 - T1563.001","TA0006 - TA0001 - TA0009 - TA0040","N/A","N/A","Phishing","https://github.com/bbtfr/evil-proxy","1","1","N/A","N/A","9","2","172","96","2023-10-30T07:49:40Z","2015-07-30T01:54:40Z","43376" +"*evil-proxy-0.2.0*",".{0,1000}evil\-proxy\-0\.2\.0.{0,1000}","offensive_tool_keyword","evil-proxy","A ruby http/https proxy to do EVIL things","T1557 - T1110.001 - T1563.001","TA0006 - TA0001 - TA0009 - TA0040","N/A","N/A","Phishing","https://github.com/bbtfr/evil-proxy","1","1","N/A","N/A","9","2","172","96","2023-10-30T07:49:40Z","2015-07-30T01:54:40Z","43377" +"*evilqr-main*",".{0,1000}evilqr\-main.{0,1000}","offensive_tool_keyword","evilqr","Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice","T1566.002 - T1204.001 - T1192","TA0001 - TA0005","N/A","N/A","Phishing","https://github.com/kgretzky/evilqr","1","1","N/A","N/A","N/A","3","292","45","2024-06-18T11:27:23Z","2023-06-20T12:58:09Z","43379" +"*evilqr-phishing*",".{0,1000}evilqr\-phishing.{0,1000}","offensive_tool_keyword","evilqr","Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice","T1566.002 - T1204.001 - T1192","TA0001 - TA0005","N/A","N/A","Phishing","https://github.com/kgretzky/evilqr","1","1","N/A","N/A","N/A","3","292","45","2024-06-18T11:27:23Z","2023-06-20T12:58:09Z","43380" +"*evilqr-server*",".{0,1000}evilqr\-server.{0,1000}","offensive_tool_keyword","evilqr","Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice","T1566.002 - T1204.001 - T1192","TA0001 - TA0005","N/A","N/A","Phishing","https://github.com/kgretzky/evilqr","1","1","N/A","N/A","N/A","3","292","45","2024-06-18T11:27:23Z","2023-06-20T12:58:09Z","43381" +"*evilrdp.exe*",".{0,1000}evilrdp\.exe.{0,1000}","offensive_tool_keyword","evilrdp","Th evil twin of aardwolfgui using the aardwolf RDP client library that gives you extended control over the target and additional scripting capabilities from the command line.","T1021.001 - T1056.001 - T1113 - T1078.002 - T1105 - T1090.002 - T1059.001","TA0008 - TA0002 - TA0005 - TA0001 - TA0009 - TA0010 - TA0011","N/A","Black Basta","C2","https://github.com/skelsec/evilrdp","1","1","N/A","N/A","10","10","299","31","2025-03-15T13:37:21Z","2023-11-29T13:44:58Z","43382" +"*evilrdp-main*",".{0,1000}evilrdp\-main.{0,1000}","offensive_tool_keyword","evilrdp","Th evil twin of aardwolfgui using the aardwolf RDP client library that gives you extended control over the target and additional scripting capabilities from the command line.","T1021.001 - T1056.001 - T1113 - T1078.002 - T1105 - T1090.002 - T1059.001","TA0008 - TA0002 - TA0005 - TA0001 - TA0009 - TA0010 - TA0011","N/A","Black Basta","C2","https://github.com/skelsec/evilrdp","1","1","N/A","N/A","10","10","299","31","2025-03-15T13:37:21Z","2023-11-29T13:44:58Z","43383" +"*EvilSln-main*",".{0,1000}EvilSln\-main.{0,1000}","offensive_tool_keyword","EvilSln","A New Exploitation Technique for Visual Studio Projects","T1564.001 - T1204.002","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/cjm00n/EvilSln","1","1","N/A","N/A","10","","N/A","","","","43384" +"*evilsocket/legba*",".{0,1000}evilsocket\/legba.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","1","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","43385" +"*evilsocket@gmail.com*",".{0,1000}evilsocket\@gmail\.com.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","0","1","#email","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","43386" +"*eviltree_x64.exe*",".{0,1000}eviltree_x64\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","43387" +"*EvilTwin.bin*",".{0,1000}EvilTwin\.bin.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43388" +"*EvilTwin.dmp*",".{0,1000}EvilTwin\.dmp.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43390" +"*EvilTwin.dmp*",".{0,1000}EvilTwin\.dmp.{0,1000}","offensive_tool_keyword","EvilLsassTwin","attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.","T1003.001 - T1055 - T1093","TA0006 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","9","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43391" +"*EvilTwinServer.nim*",".{0,1000}EvilTwinServer\.nim.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43392" +"*EvilTwinServer.nim*",".{0,1000}EvilTwinServer\.nim.{0,1000}","offensive_tool_keyword","EvilLsassTwin","attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.","T1003.001 - T1055 - T1093","TA0006 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","9","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43393" +"*evil-winrm*",".{0,1000}evil\-winrm.{0,1000}","offensive_tool_keyword","evil-winrm","This shell is the ultimate WinRM shell for hacking/pentesting.WinRM (Windows Remote Management) is the Microsoft implementation of WS-Management Protocol. A standard SOAP based protocol that allows hardware and operating systems from different vendors to interoperate. Microsoft included it in their Operating Systems in order to make life easier to system administrators.This program can be used on any Microsoft Windows Servers with this feature enabled (usually at port 5985). of course only if you have credentials and permissions to use it. So we can say that it could be used in a post-exploitation hacking/pentesting phase. The purpose of this program is to provide nice and easy-to-use features for hacking. It can be used with legitimate purposes by system administrators as well but the most of its features are focused on hacking/pentesting stuff.","T1021 - T1028 - T1046 - T1078 - T1091 - T1219","TA0003 - TA0008 - TA0009","N/A","Turla","Exploitation tool","https://github.com/Hackplayers/evil-winrm","1","1","N/A","N/A","10","10","4804","626","2024-12-02T08:52:41Z","2019-05-28T10:53:00Z","43396" +"*EvtMuteHook.dll*",".{0,1000}EvtMuteHook\.dll.{0,1000}","offensive_tool_keyword","EvtMute","This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging - mute the event log","T1562.004 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/bats3c/EvtMute","1","1","N/A","N/A","10","3","261","51","2021-04-24T19:23:39Z","2020-08-29T00:13:20Z","43397" +"*EvtMuteHook.dll*",".{0,1000}EvtMuteHook\.dll.{0,1000}","offensive_tool_keyword","EvtMute","This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging - mute the event log","T1562.004 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/bats3c/EvtMute","1","1","N/A","N/A","10","3","261","51","2021-04-24T19:23:39Z","2020-08-29T00:13:20Z","43398" +"*EvtMuteHook.iobj*",".{0,1000}EvtMuteHook\.iobj.{0,1000}","offensive_tool_keyword","EvtMute","This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging - mute the event log","T1562.004 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/bats3c/EvtMute","1","1","N/A","N/A","10","3","261","51","2021-04-24T19:23:39Z","2020-08-29T00:13:20Z","43399" +"*EvtMuteHook.ipdb*",".{0,1000}EvtMuteHook\.ipdb.{0,1000}","offensive_tool_keyword","EvtMute","This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging - mute the event log","T1562.004 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/bats3c/EvtMute","1","1","N/A","N/A","10","3","261","51","2021-04-24T19:23:39Z","2020-08-29T00:13:20Z","43400" +"*EvtMuteHook.pdb*",".{0,1000}EvtMuteHook\.pdb.{0,1000}","offensive_tool_keyword","EvtMute","This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging - mute the event log","T1562.004 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/bats3c/EvtMute","1","1","N/A","N/A","10","3","261","51","2021-04-24T19:23:39Z","2020-08-29T00:13:20Z","43401" +"*EvtMuteHook.sln*",".{0,1000}EvtMuteHook\.sln.{0,1000}","offensive_tool_keyword","EvtMute","This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging - mute the event log","T1562.004 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/bats3c/EvtMute","1","1","N/A","N/A","10","3","261","51","2021-04-24T19:23:39Z","2020-08-29T00:13:20Z","43402" +"*EvtMute-master*",".{0,1000}EvtMute\-master.{0,1000}","offensive_tool_keyword","EvtMute","This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging - mute the event log","T1562.004 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/bats3c/EvtMute","1","1","N/A","N/A","10","3","261","51","2021-04-24T19:23:39Z","2020-08-29T00:13:20Z","43403" +"*ewby/Mockingjay_BOF*",".{0,1000}ewby\/Mockingjay_BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object File (BOF) Conversion of the Mockingjay Process Injection Technique","T1055.012 - T1059.001 - T1027.002","TA0002 - TA0005","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ewby/Mockingjay_BOF","1","1","N/A","N/A","9","10","151","18","2023-11-07T19:04:03Z","2023-08-27T06:01:28Z","43405" +"*example-bof.sln*",".{0,1000}example\-bof\.sln.{0,1000}","offensive_tool_keyword","cobaltstrike","A Visual Studio template used to create Cobalt Strike BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/securifybv/Visual-Studio-BOF-template","1","1","N/A","N/A","10","10","304","55","2021-11-17T12:03:42Z","2021-11-13T13:44:01Z","43408" +"*examples/netview.py*",".{0,1000}examples\/netview\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","43409" +"*Excel-Exploit.git*",".{0,1000}Excel\-Exploit\.git.{0,1000}","offensive_tool_keyword","Excel-Exploit","MacroExploit use in excel sheet","T1137.001 - T1203 - T1059.007 - T1566.001 - T1564.003","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Mr-Cyb3rgh0st/Excel-Exploit/tree/main","1","1","N/A","N/A","N/A","1","20","3","2023-06-12T11:47:52Z","2023-06-12T11:46:53Z","43410" +"*Excel-Exploit-main*",".{0,1000}Excel\-Exploit\-main.{0,1000}","offensive_tool_keyword","Excel-Exploit","MacroExploit use in excel sheet","T1137.001 - T1203 - T1059.007 - T1566.001 - T1564.003","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Mr-Cyb3rgh0st/Excel-Exploit/tree/main","1","1","N/A","N/A","N/A","1","20","3","2023-06-12T11:47:52Z","2023-06-12T11:46:53Z","43411" +"*ExcelReflectImplant*",".{0,1000}ExcelReflectImplant.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","43412" +"*excelshellinject.*",".{0,1000}excelshellinject\..{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","43413" +"*exchange_proxylogon_rce.*",".{0,1000}exchange_proxylogon_rce\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43414" +"*exchange_proxynotshell_rce.*",".{0,1000}exchange_proxynotshell_rce\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43415" +"*exe_stager.exe*",".{0,1000}exe_stager\.exe.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","43423" +"*exe_to_dll.exe*",".{0,1000}exe_to_dll\.exe.{0,1000}","offensive_tool_keyword","exe_to_dll","Converts a EXE into DLL","T1027.004 - T1059.001","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/hasherezade/exe_to_dll","1","1","N/A","N/A","5","10","1297","197","2023-07-26T11:41:27Z","2020-04-16T16:27:00Z","43424" +"*exe_to_dll.exe*",".{0,1000}exe_to_dll\.exe.{0,1000}","offensive_tool_keyword","exe_to_dll","Converts an EXE so that it can be loaded like a DLL.","T1055.002 - T1073.001 - T1027","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/hasherezade/exe_to_dll","1","1","N/A","N/A","8","10","1297","197","2023-07-26T11:41:27Z","2020-04-16T16:27:00Z","43425" +"*exe_to_dll_*.zip*",".{0,1000}exe_to_dll_.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","exe_to_dll","Converts a EXE into DLL","T1027.004 - T1059.001","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/hasherezade/exe_to_dll","1","1","N/A","N/A","5","10","1297","197","2023-07-26T11:41:27Z","2020-04-16T16:27:00Z","43426" +"*exe_to_dll_*_32bit.zip*",".{0,1000}exe_to_dll_.{0,1000}_32bit\.zip.{0,1000}","offensive_tool_keyword","exe_to_dll","Converts an EXE so that it can be loaded like a DLL.","T1055.002 - T1073.001 - T1027","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/hasherezade/exe_to_dll","1","1","N/A","N/A","8","10","1297","197","2023-07-26T11:41:27Z","2020-04-16T16:27:00Z","43427" +"*exe_to_dll_*_64bit.zip*",".{0,1000}exe_to_dll_.{0,1000}_64bit\.zip.{0,1000}","offensive_tool_keyword","exe_to_dll","Converts an EXE so that it can be loaded like a DLL.","T1055.002 - T1073.001 - T1027","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/hasherezade/exe_to_dll","1","1","N/A","N/A","8","10","1297","197","2023-07-26T11:41:27Z","2020-04-16T16:27:00Z","43428" +"*exe_to_dll-master*",".{0,1000}exe_to_dll\-master.{0,1000}","offensive_tool_keyword","exe_to_dll","Converts a EXE into DLL","T1027.004 - T1059.001","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/hasherezade/exe_to_dll","1","1","N/A","N/A","5","10","1297","197","2023-07-26T11:41:27Z","2020-04-16T16:27:00Z","43429" +"*exe_to_dll-master*",".{0,1000}exe_to_dll\-master.{0,1000}","offensive_tool_keyword","exe_to_dll","Converts an EXE so that it can be loaded like a DLL.","T1055.002 - T1073.001 - T1027","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/hasherezade/exe_to_dll","1","1","N/A","N/A","8","10","1297","197","2023-07-26T11:41:27Z","2020-04-16T16:27:00Z","43430" +"*exe2bat.cpp*",".{0,1000}exe2bat\.cpp.{0,1000}","offensive_tool_keyword","exe2powershell","exe2powershell is used to convert any binary file to a bat/powershell file","T1059.001 - T1027.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/yanncam/exe2powershell","1","1","N/A","N/A","6","2","172","44","2020-10-15T08:22:30Z","2016-03-02T11:23:32Z","43431" +"*exe2bat.exe*",".{0,1000}exe2bat\.exe.{0,1000}","offensive_tool_keyword","exe2powershell","exe2powershell is used to convert any binary file to a bat/powershell file","T1059.001 - T1027.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/yanncam/exe2powershell","1","1","N/A","N/A","6","2","172","44","2020-10-15T08:22:30Z","2016-03-02T11:23:32Z","43432" +"*exe2powershell.cpp*",".{0,1000}exe2powershell\.cpp.{0,1000}","offensive_tool_keyword","exe2powershell","exe2powershell is used to convert any binary file to a bat/powershell file","T1059.001 - T1027.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/yanncam/exe2powershell","1","1","N/A","N/A","6","2","172","44","2020-10-15T08:22:30Z","2016-03-02T11:23:32Z","43433" +"*exe2powershell.exe*",".{0,1000}exe2powershell\.exe.{0,1000}","offensive_tool_keyword","exe2powershell","exe2powershell is used to convert any binary file to a bat/powershell file","T1059.001 - T1027.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/yanncam/exe2powershell","1","1","N/A","N/A","6","2","172","44","2020-10-15T08:22:30Z","2016-03-02T11:23:32Z","43434" +"*exe2powershell-master*",".{0,1000}exe2powershell\-master.{0,1000}","offensive_tool_keyword","exe2powershell","exe2powershell is used to convert any binary file to a bat/powershell file","T1059.001 - T1027.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/yanncam/exe2powershell","1","1","N/A","N/A","6","2","172","44","2020-10-15T08:22:30Z","2016-03-02T11:23:32Z","43435" +"*Exec_Command_Silent.vbs*",".{0,1000}Exec_Command_Silent\.vbs.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","43444" +"*Exec_Command_WithOutput.vbs*",".{0,1000}Exec_Command_WithOutput\.vbs.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","43445" +"*exec_payload_msi*",".{0,1000}exec_payload_msi.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43446" +"*exec_shellcode.rb*",".{0,1000}exec_shellcode\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43447" +"*ExecCmdImplant*",".{0,1000}ExecCmdImplant.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","43448" +"*Exec-Command-Silent.vbs*",".{0,1000}Exec\-Command\-Silent\.vbs.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","43449" +"*Exec-Command-Silent.vbs*",".{0,1000}Exec\-Command\-Silent\.vbs.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","43450" +"*execmethod*PowerPick*",".{0,1000}execmethod.{0,1000}PowerPick.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","43452" +"*execmethod*PowerShell*",".{0,1000}execmethod.{0,1000}PowerShell.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","43453" +"*execPayloads.txt*",".{0,1000}execPayloads\.txt.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","43454" +"*exec-sc-rand.ps1*",".{0,1000}exec\-sc\-rand\.ps1.{0,1000}","offensive_tool_keyword","DKMC","Malicious payload evasion tool","T1027 - T1055.012","TA0005 - TA0040","N/A","Molerats","Defense Evasion","https://github.com/Mr-Un1k0d3r/DKMC","1","1","N/A","N/A","10","10","1392","290","2020-07-20T03:36:56Z","2016-12-05T03:44:07Z","43455" +"*Executable_Files-main.zip*",".{0,1000}Executable_Files\-main\.zip.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","43457" +"*execute_dotnet_assembly.*",".{0,1000}execute_dotnet_assembly\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43465" +"*execute_Pezor*",".{0,1000}execute_Pezor.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","43469" +"*Execute-ACLight.bat*",".{0,1000}Execute\-ACLight\.bat.{0,1000}","offensive_tool_keyword","ACLight","A tool for advanced discovery of Privileged Accounts - including Shadow Admins.","T1087 - T1003 - T1208","TA0001 - TA0006 - TA0008","N/A","N/A","Discovery","https://github.com/cyberark/ACLight","1","1","N/A","AD Enumeration","7","9","801","146","2019-09-09T06:48:45Z","2017-05-17T09:29:41Z","43471" +"*Execute-ACLight2.bat*",".{0,1000}Execute\-ACLight2\.bat.{0,1000}","offensive_tool_keyword","ACLight","A tool for advanced discovery of Privileged Accounts - including Shadow Admins.","T1087 - T1003 - T1208","TA0001 - TA0006 - TA0008","N/A","N/A","Discovery","https://github.com/cyberark/ACLight","1","1","N/A","AD Enumeration","7","9","801","146","2019-09-09T06:48:45Z","2017-05-17T09:29:41Z","43472" +"*execute-assembly*Seatbelt*",".{0,1000}execute\-assembly.{0,1000}Seatbelt.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","43481" +"*execute-assembly*sharpcookiemonster*",".{0,1000}execute\-assembly.{0,1000}sharpcookiemonster.{0,1000}","offensive_tool_keyword","SharpCookieMonster","This C# project will dump cookies for all sites. even those with httpOnly/secure/session","T1539 - T1606","TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/m0rv4i/SharpCookieMonster","1","1","N/A","N/A","N/A","3","202","44","2023-03-15T09:51:09Z","2020-01-22T18:39:49Z","43482" +"*execute-assembly*sigflip*",".{0,1000}execute\-assembly.{0,1000}sigflip.{0,1000}","offensive_tool_keyword","C2 related tools","SigFlip is a tool for patching authenticode signed PE files (exe. dll. sys ..etc) without invalidating or breaking the existing signature.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/med0x2e/SigFlip","1","1","N/A","N/A","10","10","1139","197","2023-08-27T18:27:50Z","2021-08-08T15:59:19Z","43483" +"*executeAssembly.nim*",".{0,1000}executeAssembly\.nim.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","43484" +"*execute-assembly.py*",".{0,1000}execute\-assembly\.py.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","43485" +"*Execute-Command-MSSQL*",".{0,1000}Execute\-Command\-MSSQL.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","43486" +"*Execute-DNSTXT-Code*",".{0,1000}Execute\-DNSTXT\-Code.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","43487" +"*execute-dotnet-assembly*",".{0,1000}execute\-dotnet\-assembly.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43488" +"*execute-pe.py*",".{0,1000}execute\-pe\.py.{0,1000}","offensive_tool_keyword","mythic","Cross-platform post-exploitation HTTP Command & Control agent written in golang","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/merlin","1","1","N/A","N/A","10","10","94","16","2025-04-16T13:05:47Z","2021-01-25T12:36:46Z","43490" +"*executepersistence*",".{0,1000}executepersistence.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike kit for Persistence","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/0xthirteen/StayKit","1","1","N/A","N/A","10","10","475","73","2020-01-27T14:53:31Z","2020-01-24T22:20:20Z","43491" +"*execute-Pezor*",".{0,1000}execute\-Pezor.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","43492" +"*execute-shellcode.py*",".{0,1000}execute\-shellcode\.py.{0,1000}","offensive_tool_keyword","mythic","Cross-platform post-exploitation HTTP Command & Control agent written in golang","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/merlin","1","1","N/A","N/A","10","10","94","16","2025-04-16T13:05:47Z","2021-01-25T12:36:46Z","43496" +"*Execution_CommandAndScriptingInterpreter_UploadAndExec.py*",".{0,1000}Execution_CommandAndScriptingInterpreter_UploadAndExec\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","43498" +"*Execution_UserExecution_CallbackCreateThreadpoolWait.py*",".{0,1000}Execution_UserExecution_CallbackCreateThreadpoolWait\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","43499" +"*Execution_UserExecution_CallbackCreateTimerQueue.py*",".{0,1000}Execution_UserExecution_CallbackCreateTimerQueue\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","43500" +"*Execution_UserExecution_CallbackEnumChildWindows.py*",".{0,1000}Execution_UserExecution_CallbackEnumChildWindows\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","43501" +"*Execution_UserExecution_CallbackEnumWindows.py*",".{0,1000}Execution_UserExecution_CallbackEnumWindows\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","43502" +"*Execution_UserExecution_DirectConnectReverseHTTPS.py*",".{0,1000}Execution_UserExecution_DirectConnectReverseHTTPS\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","43503" +"*Execution_UserExecution_DirectConnectReverseTCPRc4.py*",".{0,1000}Execution_UserExecution_DirectConnectReverseTCPRc4\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","43504" +"*Execution_UserExecution_FakePPID.py*",".{0,1000}Execution_UserExecution_FakePPID\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","43505" +"*Execution_UserExecution_LinuxBaseShellcodeLoader.py*",".{0,1000}Execution_UserExecution_LinuxBaseShellcodeLoader\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","#linux","N/A","10","","N/A","","","","43506" +"*Execution_UserExecution_LinuxSelfGuardLoader.py*",".{0,1000}Execution_UserExecution_LinuxSelfGuardLoader\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","#linux","N/A","10","","N/A","","","","43507" +"*Execution_UserExecution_NtCreateSection.py*",".{0,1000}Execution_UserExecution_NtCreateSection\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","43508" +"*Execution_UserExecution_Syscall_inject.py*",".{0,1000}Execution_UserExecution_Syscall_inject\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","43509" +"*Execution_UserExecution_VSSyscallProject.py*",".{0,1000}Execution_UserExecution_VSSyscallProject\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","43510" +"*ExeStager.csproj*",".{0,1000}ExeStager\.csproj.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","43522" +"*ExetoText.ps1*",".{0,1000}ExetoText\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","43525" +"*ExfilDataToGitHub*",".{0,1000}ExfilDataToGitHub.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-ExfilDataToGitHub.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","43527" +"*Exfil-EC266392-D6BC-4F7B-A4D1-410166D30B55.json*",".{0,1000}Exfil\-EC266392\-D6BC\-4F7B\-A4D1\-410166D30B55\.json.{0,1000}","offensive_tool_keyword","power-pwn","An offensive and defensive security toolset for Microsoft 365 Power Platform","T1078 - T1078.004 - T1136 - T1136.001 - T1021 - T1021.003 - T1114 - T1114.002","TA0003 - TA0004 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/mbrg/power-pwn","1","1","N/A","N/A","10","10","939","100","2025-03-20T08:54:43Z","2022-06-14T11:40:21Z","43528" +"*exfiltrate_via_post.exe*",".{0,1000}exfiltrate_via_post\.exe.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","43530" +"*existing_auto_target.rb*",".{0,1000}existing_auto_target\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43534" +"*exit_nimbo*",".{0,1000}exit_nimbo.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","43535" +"*EXOCET-AV-Evasion-master*",".{0,1000}EXOCET\-AV\-Evasion\-master.{0,1000}","offensive_tool_keyword","EXOCET-AV-Evasion","EXOCET - AV-evading undetectable payload delivery tool","T1055 - T1218.011 - T1027.009 - T1027 - T1105 - T1102.001","TA0005 - TA0001 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/tanc7/EXOCET-AV-Evasion","1","1","N/A","N/A","10","9","840","147","2022-08-16T02:58:39Z","2020-07-15T06:55:13Z","43536" +"*exocet-shellcode-exec-redo.go*",".{0,1000}exocet\-shellcode\-exec\-redo\.go.{0,1000}","offensive_tool_keyword","EXOCET-AV-Evasion","EXOCET - AV-evading undetectable payload delivery tool","T1055 - T1218.011 - T1027.009 - T1027 - T1105 - T1102.001","TA0005 - TA0001 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/tanc7/EXOCET-AV-Evasion","1","1","N/A","N/A","10","9","840","147","2022-08-16T02:58:39Z","2020-07-15T06:55:13Z","43537" +"*explib2_ie11_exec_test_case.rb*",".{0,1000}explib2_ie11_exec_test_case\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43541" +"*exploit*wordpress_add_admin*",".{0,1000}exploit.{0,1000}wordpress_add_admin.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","43544" +"*exploit.exe*",".{0,1000}exploit\.exe.{0,1000}","offensive_tool_keyword","POC","CVE POCs exploits executables ","T1543 - T1588 - T1211 - T1203","TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/lcashdol/Exploits","1","1","N/A","N/A","N/A","3","210","69","2020-07-14T15:41:00Z","2015-02-16T20:06:37Z","43551" +"*exploit.ps1*",".{0,1000}exploit\.ps1.{0,1000}","offensive_tool_keyword","POC","CVE POCs exploits executables ","T1543 - T1588 - T1211 - T1203","TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/lcashdol/Exploits","1","1","N/A","N/A","N/A","3","210","69","2020-07-14T15:41:00Z","2015-02-16T20:06:37Z","43554" +"*exploit.py*",".{0,1000}exploit\.py.{0,1000}","offensive_tool_keyword","POC","CVE POCs exploits executables ","T1543 - T1588 - T1211 - T1203","TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/lcashdol/Exploits","1","1","N/A","N/A","N/A","3","210","69","2020-07-14T15:41:00Z","2015-02-16T20:06:37Z","43555" +"*exploit.vbs*",".{0,1000}exploit\.vbs.{0,1000}","offensive_tool_keyword","POC","CVE POCs exploits executables ","T1543 - T1588 - T1211 - T1203","TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/lcashdol/Exploits","1","1","N/A","N/A","N/A","3","210","69","2020-07-14T15:41:00Z","2015-02-16T20:06:37Z","43561" +"*exploit/windows/smb/ms08_067_netapi*",".{0,1000}exploit\/windows\/smb\/ms08_067_netapi.{0,1000}","offensive_tool_keyword","metasploit","exploits often used by ransomware groups","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven - Dispossessor","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43564" +"*exploit/windows/smb/ms17_010_eternalblue*",".{0,1000}exploit\/windows\/smb\/ms17_010_eternalblue.{0,1000}","offensive_tool_keyword","metasploit","exploits often used by ransomware groups","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven - Dispossessor","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43565" +"*exploit/windows/smb/ms17_010_psexec*",".{0,1000}exploit\/windows\/smb\/ms17_010_psexec.{0,1000}","offensive_tool_keyword","metasploit","exploits often used by ransomware groups","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven - Dispossessor","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43566" +"*exploit_frameworks.py*",".{0,1000}exploit_frameworks\.py.{0,1000}","offensive_tool_keyword","hackingtool","ALL IN ONE Hacking Tool For Hackers","T1059 - T1078 - T1105 - T1110 - T1566","TA0002 - TA0008 - TA0009 - TA0005 - TA0007","N/A","N/A","Exploitation tool","https://github.com/Z4nzu/hackingtool","1","1","N/A","N/A","N/A","10","52217","5629","2025-03-03T15:17:19Z","2020-04-11T09:21:31Z","43570" +"*exploit_oneline.md*",".{0,1000}exploit_oneline\.md.{0,1000}","offensive_tool_keyword","POC","Just another PoC for the new MSDT-Exploit","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/drgreenthumb93/CVE-2022-30190-follina","1","1","N/A","N/A","N/A","1","8","4","2023-04-20T20:34:05Z","2022-06-01T11:37:08Z","43573" +"*exploit_suggester.*",".{0,1000}exploit_suggester\..{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","43575" +"*exploit_suggester.py*",".{0,1000}exploit_suggester\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","43576" +"*exploit-database-bin-sploits/*",".{0,1000}exploit\-database\-bin\-sploits\/.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","43579" +"*Exploit-EternalBlue.ps1*",".{0,1000}Exploit\-EternalBlue\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","43580" +"*Exploit-JBoss.ps1*",".{0,1000}Exploit\-JBoss\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-JBoss.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","43583" +"*Exploit-Jenkins*",".{0,1000}Exploit\-Jenkins.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-Jenkins.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","43584" +"*Exploit-Jenkins.ps1*",".{0,1000}Exploit\-Jenkins\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1063","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","43585" +"*Exploit-JMXConsole*",".{0,1000}Exploit\-JMXConsole.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-JBoss.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","43586" +"*exploits*_csrf/*.js*",".{0,1000}exploits.{0,1000}_csrf\/.{0,1000}\.js.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","43587" +"*exploits*_csrf/*.rb*",".{0,1000}exploits.{0,1000}_csrf\/.{0,1000}\.rb.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","43588" +"*exploits-forsale/prefetch-tool*",".{0,1000}exploits\-forsale\/prefetch\-tool.{0,1000}","offensive_tool_keyword","prefetch-tool","Windows KASLR bypass using prefetch side-channel CVE-2024-21345 exploitation","T1564.007","TA0004","N/A","N/A","Privilege Escalation","https://github.com/exploits-forsale/prefetch-tool","1","1","N/A","N/A","8","1","90","10","2024-04-26T05:40:32Z","2024-04-26T05:00:27Z","43591" +"*exploit-suggester*",".{0,1000}exploit\-suggester.{0,1000}","offensive_tool_keyword","Windows-Exploit-Suggester","This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on the target. It also notifies the user if there are public exploits and Metasploit modules available for the missing bulletins","T1199 - T1082 - T1210","TA0006 - TA0008 - TA0011","N/A","N/A","Exploitation tool","https://github.com/AonCyberLabs/Windows-Exploit-Suggester","1","1","N/A","N/A","N/A","10","4055","1036","2023-05-11T12:44:55Z","2014-07-08T13:16:28Z","43592" +"*Export-PowerViewCSV*",".{0,1000}Export\-PowerViewCSV.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","43622" +"*Export-PowerViewCSV*",".{0,1000}Export\-PowerViewCSV.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","powerview.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","43623" +"*Export-PowerViewCSV*",".{0,1000}Export\-PowerViewCSV.{0,1000}","offensive_tool_keyword","powerview","PowerView is a PowerShell tool to gain network situational awareness on Windows domains","T1046 - T1087.001 - T1016","TA0007 - TA0008 - TA0009","N/A","Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA","Discovery","https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","43624" +"*exposed_get_password*",".{0,1000}exposed_get_password.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","43628" +"*exrienz/DirtyCow*",".{0,1000}exrienz\/DirtyCow.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirtycow vulnerability","t1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/exrienz/DirtyCow","1","1","N/A","N/A","N/A","1","28","25","2018-07-23T02:07:24Z","2017-05-12T10:38:20Z","43629" +"*extensions/sniffer*",".{0,1000}extensions\/sniffer.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","43631" +"*ExtensionSpoofer-1.zip*",".{0,1000}ExtensionSpoofer\-1\.zip.{0,1000}","offensive_tool_keyword","ExtensionSpoofer","Spoof file icons and extensions in Windows","T1036 - T1027.005 - T1218","TA0005 - TA0040","N/A","N/A","Phishing","https://github.com/henriksb/ExtensionSpoofer","1","1","N/A","N/A","9","2","179","65","2024-12-12T18:05:28Z","2017-11-11T16:02:17Z","43634" +"*external_c2.cna*",".{0,1000}external_c2\.cna.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","43636" +"*ExternalC2.*",".{0,1000}ExternalC2\..{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","43637" +"*ExternalC2.dll*",".{0,1000}ExternalC2\.dll.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","43638" +"*ExternalC2.Net*",".{0,1000}ExternalC2\.Net.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","43639" +"*ExternalC2.Net.*",".{0,1000}ExternalC2\.Net\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","43640" +"*externalc2.py*",".{0,1000}externalc2\.py.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","43641" +"*ExternalC2Core*",".{0,1000}ExternalC2Core.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","43644" +"*ExternalC2-master*",".{0,1000}ExternalC2\-master.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","43645" +"*ExternalC2Tests*",".{0,1000}ExternalC2Tests.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","43646" +"*ExternalC2Web*",".{0,1000}ExternalC2Web.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","43647" +"*ExternalRecon.ps1*",".{0,1000}ExternalRecon\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","43649" +"*ExtPassword.exe*",".{0,1000}ExtPassword\.exe.{0,1000}","offensive_tool_keyword","ExtPassword.exe","Nirsoft tool for Windows that allows you to recover passwords stored on external drive plugged to your computer","T1081 - T1003 - T1212","TA0006 - TA0009","N/A","LockBit","Credential Access","https://www.nirsoft.net/utils/external_drive_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","43650" +"*extract_cmd_exec*.js*",".{0,1000}extract_cmd_exec.{0,1000}\.js.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","43651" +"*extract_cmd_exec*.rb*",".{0,1000}extract_cmd_exec.{0,1000}\.rb.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","43652" +"*extract_reflective_loader*",".{0,1000}extract_reflective_loader.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","43653" +"*ExtractBitlockerKeys.ps1*",".{0,1000}ExtractBitlockerKeys\.ps1.{0,1000}","offensive_tool_keyword","ExtractBitlockerKeys","A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.","T1003.002 - T1039 - T1087.002","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/p0dalirius/ExtractBitlockerKeys","1","1","N/A","N/A","10","4","368","54","2025-01-31T09:39:55Z","2023-09-19T07:28:11Z","43655" +"*ExtractBitlockerKeys.py*",".{0,1000}ExtractBitlockerKeys\.py.{0,1000}","offensive_tool_keyword","ExtractBitlockerKeys","A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.","T1003.002 - T1039 - T1087.002","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/p0dalirius/ExtractBitlockerKeys","1","1","N/A","N/A","10","4","368","54","2025-01-31T09:39:55Z","2023-09-19T07:28:11Z","43656" +"*ExtractBitlockerKeys-main*",".{0,1000}ExtractBitlockerKeys\-main.{0,1000}","offensive_tool_keyword","ExtractBitlockerKeys","A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.","T1003.002 - T1039 - T1087.002","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/p0dalirius/ExtractBitlockerKeys","1","1","N/A","N/A","10","4","368","54","2025-01-31T09:39:55Z","2023-09-19T07:28:11Z","43657" +"*extracttgsrepfrompcap.py*",".{0,1000}extracttgsrepfrompcap\.py.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/xan7r/kerberoast","1","1","N/A","N/A","N/A","1","73","18","2017-07-22T22:28:12Z","2016-06-08T22:58:45Z","43664" +"*extra-scripts*timecrack.py*",".{0,1000}extra\-scripts.{0,1000}timecrack\.py.{0,1000}","offensive_tool_keyword","Timeroast","Timeroasting takes advantage of Windows NTP authentication mechanism allowing unauthenticated attackers to effectively request a password hash of any computer or trust account by sending an NTP request with that account's RID","T1558.003 - T1059.003 - T1078.004","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/SecuraBV/Timeroast","1","1","N/A","N/A","10","3","282","28","2023-07-04T07:12:57Z","2023-01-18T09:04:05Z","43665" +"*f1zm0/acheron*",".{0,1000}f1zm0\/acheron.{0,1000}","offensive_tool_keyword","acheron","indirect syscalls for AV/EDR evasion in Go assembly","T1055.012 - T1059.001 - T1059.003","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/f1zm0/acheron","1","1","N/A","N/A","N/A","4","326","39","2023-06-13T19:20:33Z","2023-04-07T10:40:33Z","43805" +"*f1zm0/hades*",".{0,1000}f1zm0\/hades.{0,1000}","offensive_tool_keyword","hades","Go shellcode loader that combines multiple evasion techniques","T1055 - T1027 - T1218 - T1027.001 - T1036","TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/f1zm0/hades","1","1","N/A","N/A","N/A","4","364","47","2023-06-21T19:22:57Z","2022-10-11T08:16:24Z","43806" +"*f4081a8e30f75d46.js*",".{0,1000}f4081a8e30f75d46\.js.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","43934" +"*Fadi002/unshackle*",".{0,1000}Fadi002\/unshackle.{0,1000}","offensive_tool_keyword","unshackle","Unshackle is an open-source tool to bypass Windows and Linux user passwords from a bootable USB based on Linux","T1110.004 - T1059.004 - T1070.004","TA0006 - TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Fadi002/unshackle","1","1","#linux #windows","N/A","10","10","1899","125","2023-11-10T19:48:10Z","2023-07-19T22:30:28Z","44399" +"*Fahrj/reverse-ssh*",".{0,1000}Fahrj\/reverse\-ssh.{0,1000}","offensive_tool_keyword","reverse-ssh","Statically-linked ssh server with reverse shell functionality for CTFs and such","T1105 - T1572 - T1569.002 - T1090","TA0001 - TA0002 - TA0003 - TA0010 - TA0011 - TA0005 ","N/A","N/A","C2","https://github.com/Fahrj/reverse-ssh","1","1","N/A","N/A","10","10","961","141","2023-02-15T00:16:25Z","2021-07-12T18:26:29Z","44408" +"*fake_ap.py*",".{0,1000}fake_ap\.py.{0,1000}","offensive_tool_keyword","Rudrastra","Make a Fake wireless access point aka Evil Twin","T1491 - T1090.004 - T1557.001","TA0040 - TA0011 - TA0002","N/A","N/A","Sniffing & Spoofing","https://github.com/SxNade/Rudrastra","1","1","N/A","N/A","8","1","67","21","2023-04-22T15:10:42Z","2020-11-05T09:38:15Z","44425" +"*fake_common_roots.txt*",".{0,1000}fake_common_roots\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","44426" +"*fake_default_wordlist.txt*",".{0,1000}fake_default_wordlist\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","44427" +"*fake_evernote_clipper*",".{0,1000}fake_evernote_clipper.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","44428" +"*fake_lastpass/*",".{0,1000}fake_lastpass\/.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","44431" +"*fake_notification_ff/*",".{0,1000}fake_notification_ff\/.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","44432" +"*FakeAMSI.c*",".{0,1000}FakeAMSI\.c.{0,1000}","offensive_tool_keyword","FakeAMSI","Technically. AMSI is a set of DLLs being asked for a buffer evaluation (saying it's safe/unsafe). It means. processes (such as powershell.exe) load such DLLs when want to use AMSI. And it sounds like perfect opportunity to misuse such DLL as a method of persistence","T1117 - T1027","TA0003 ","N/A","N/A","Persistence","https://github.com/gtworek/PSBits/tree/master/FakeAMSI","1","1","N/A","N/A","N/A","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","44433" +"*FakeAMSI.dll*",".{0,1000}FakeAMSI\.dll.{0,1000}","offensive_tool_keyword","FakeAMSI","Technically. AMSI is a set of DLLs being asked for a buffer evaluation (saying it's safe/unsafe). It means. processes (such as powershell.exe) load such DLLs when want to use AMSI. And it sounds like perfect opportunity to misuse such DLL as a method of persistence","T1117 - T1027","TA0003 ","N/A","N/A","Persistence","https://github.com/gtworek/PSBits/tree/master/FakeAMSI","1","1","N/A","N/A","N/A","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","44434" +"*FakeAMSI.exe*",".{0,1000}FakeAMSI\.exe.{0,1000}","offensive_tool_keyword","FakeAMSI","Technically. AMSI is a set of DLLs being asked for a buffer evaluation (saying it's safe/unsafe). It means. processes (such as powershell.exe) load such DLLs when want to use AMSI. And it sounds like perfect opportunity to misuse such DLL as a method of persistence","T1117 - T1027","TA0003 ","N/A","N/A","Persistence","https://github.com/gtworek/PSBits/tree/master/FakeAMSI","1","1","N/A","N/A","N/A","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","44435" +"*FakeCmdLine.*",".{0,1000}FakeCmdLine\..{0,1000}","offensive_tool_keyword","FakeCmdLine","Simple demonstration (C source code and compiled .exe) of a less-known (but documented) behavior of CreateProcess() function. Effectively you can put any string into the child process Command Line field.","T1059 - T1036","TA0003","N/A","N/A","Defense Evasion","https://github.com/gtworek/PSBits/tree/master/FakeCmdLine","1","1","N/A","N/A","N/A","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","44436" +"*FakeCmdLine.exe*",".{0,1000}FakeCmdLine\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","44437" +"*Fake-Cmdline.exe*",".{0,1000}Fake\-Cmdline\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","44438" +"*FakeDriver.java*",".{0,1000}FakeDriver\.java.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","44439" +"*FakeDriver2.java*",".{0,1000}FakeDriver2\.java.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","44440" +"*FakeImageExploiter*",".{0,1000}FakeImageExploiter.{0,1000}","offensive_tool_keyword","FakeImageExploiter","This module takes one existing image.jpg and one payload.ps1 (input by user) and builds a new payload (agent.jpg.exe) that if executed it will trigger the download of the 2 previous files stored into apache2 (image.jpg + payload.ps1) and execute them.","T1564 - T1218 - T1204 - T1558.001","TA0002 - TA0008 - TA0010","N/A","N/A","Phishing","https://github.com/r00t-3xp10it/FakeImageExploiter","1","1","N/A","N/A","N/A","10","912","338","2019-12-06T20:59:26Z","2017-04-04T20:53:47Z","44443" +"*fakelogonscreen*.zip*",".{0,1000}fakelogonscreen.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","44444" +"*FakeLogonScreen.csproj*",".{0,1000}FakeLogonScreen\.csproj.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","44445" +"*FakeLogonScreen_trunk.zip*",".{0,1000}FakeLogonScreen_trunk\.zip.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","44447" +"*FakeLogonScreenToFile.exe*",".{0,1000}FakeLogonScreenToFile\.exe.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","44448" +"*fakepath31337*",".{0,1000}fakepath31337.{0,1000}","offensive_tool_keyword","ysoserial.net","Deserialization payload generator for a variety of .NET formatters","T1059.007 - T1027.002 - T1059.001","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/pwntester/ysoserial.net","1","1","N/A","N/A","10","10","3385","493","2024-12-23T20:59:47Z","2017-09-18T17:48:08Z","44449" +"*FakePPID.*",".{0,1000}FakePPID\..{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","44450" +"*fake-sms-main*",".{0,1000}fake\-sms\-main.{0,1000}","offensive_tool_keyword","fake-sms","A simple command line tool using which you can skip phone number based SMS verification by using a temporary phone number that acts like a proxy.","T1598.003 - T1514","TA0003 - TA0009","N/A","N/A","Defense Evasion","https://github.com/Narasimha1997/fake-sms","1","1","N/A","N/A","8","10","2745","176","2023-08-01T15:34:41Z","2021-02-18T15:18:50Z","44451" +"*FalconForceTeam/SOAPHound*",".{0,1000}FalconForceTeam\/SOAPHound.{0,1000}","offensive_tool_keyword","SOAPHound","enumerate Active Directory environments via the Active Directory Web Services (ADWS)","T1018 - T1087.002 - T1649","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/FalconForceTeam/SOAPHound","1","1","N/A","N/A","8","8","736","76","2024-02-03T08:52:49Z","2024-01-25T09:11:12Z","44453" +"*Farmer-main.zip*",".{0,1000}Farmer\-main\.zip.{0,1000}","offensive_tool_keyword","Farmer","Farmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.","T1557.001 - T1056.004 - T1078.003","TA0006 - TA0004 - TA0001","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/Farmer","1","1","N/A","N/A","10","4","379","61","2021-04-28T15:27:24Z","2021-02-22T14:32:29Z","44457" +"*fastfuz-chrome-ext*files.txt*",".{0,1000}fastfuz\-chrome\-ext.{0,1000}files\.txt.{0,1000}","offensive_tool_keyword","fastfuzz","Fast fuzzing websites with chrome extension","T1110","TA0006","N/A","N/A","Vulnerability Scanner","https://github.com/tismayil/fastfuz-chrome-ext","1","1","N/A","N/A","N/A","1","25","5","2022-02-04T02:15:51Z","2022-02-04T00:22:51Z","44461" +"*FastjsonScan.jar*",".{0,1000}FastjsonScan\.jar.{0,1000}","offensive_tool_keyword","burpsuite","Collection of burpsuite plugins","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","network exploitation tool","N/A","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","44462" +"*fasttrack/wordlist.txt*",".{0,1000}fasttrack\/wordlist\.txt.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","44463" +"*f-bader/TokenTacticsV2*",".{0,1000}f\-bader\/TokenTacticsV2.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","1","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","44514" +"*fcjam663uvgid2xbar24kab2vt4hjzsn6o77glh35jscuo567b2mnyqd.onion*",".{0,1000}fcjam663uvgid2xbar24kab2vt4hjzsn6o77glh35jscuo567b2mnyqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","44618" +"*fde1b109f9704ff7.css*",".{0,1000}fde1b109f9704ff7\.css.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","44695" +"*feeds.dev.pico.sh*",".{0,1000}feeds\.dev\.pico\.sh.{0,1000}","offensive_tool_keyword","pico","hacker labs - open source and managed web services leveraging SSH","T1021.005 - T1078 - T1105 - T1109 - T1197 - T1213","TA0005 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/picosh/pico","1","1","N/A","N/A","10","10","1129","36","2025-04-22T17:33:17Z","2022-08-24T03:14:52Z","44779" +"*feeds.pico.sh*",".{0,1000}feeds\.pico\.sh.{0,1000}","offensive_tool_keyword","pico","hacker labs - open source and managed web services leveraging SSH","T1021.005 - T1078 - T1105 - T1109 - T1197 - T1213","TA0005 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/picosh/pico","1","1","N/A","N/A","10","10","1129","36","2025-04-22T17:33:17Z","2022-08-24T03:14:52Z","44780" +"*Fentanyl/fenty.py*",".{0,1000}Fentanyl\/fenty\.py.{0,1000}","offensive_tool_keyword","Fentanyl","Stealer Malware - Steal Discord Tokens (+ Much More Info) - Steal Passwords/Cookies/History/Credit Cards/Phone Numbers and Addresses from all Browsers (Profile Support) - Steal PC Info - Steal Video Game Accounts (Adding more games + wallets and VPN's) - Low Detections - Anti VM - Sort of Fast - Startup - IP Logger","T1547.001 - T1552.001 - T1552.005 - T1110.001 - T1082 - T1562.001 - T1574.002 - T1529 - T1497.001 - T1543.003 - T1592.001","TA0005 - TA0006 - TA0040 - TA0003 - TA0009","N/A","N/A","Malware","https://github.com/dekrypted/Fentanyl","1","1","N/A","N/A","10","","N/A","","","","44785" +"*Fetch-And-Brute-Local-Accounts.ps1*",".{0,1000}Fetch\-And\-Brute\-Local\-Accounts\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","44788" +"*ff_osx_extension-dropper*",".{0,1000}ff_osx_extension\-dropper.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","44791" +"*ffdfgdfg/nps:latest*",".{0,1000}ffdfgdfg\/nps\:latest.{0,1000}","offensive_tool_keyword","nps","chinese intranet penetration proxy server","T1090 - T1071 - T1102 - T1075 - T1133","TA0002 - TA0011 - TA0010","N/A","N/A","Defense Evasion","https://github.com/yisier/nps","1","1","N/A","N/A","9","10","2674","327","2025-04-17T09:43:50Z","2022-09-14T06:24:00Z","44849" +"*ffuf.exe*",".{0,1000}ffuf\.exe.{0,1000}","offensive_tool_keyword","ffuf","Fast web fuzzer written in Go","T1110 - T1550","TA0006 - TA0008","N/A","N/A","Reconnaissance","https://github.com/ffuf/ffuf","1","1","#linux","N/A","N/A","10","13818","1373","2025-04-05T17:35:17Z","2018-11-08T09:25:49Z","44869" +"*ffuf/ffuf*",".{0,1000}ffuf\/ffuf.{0,1000}","offensive_tool_keyword","ffuf","Fast web fuzzer written in Go","T1110 - T1550","TA0006 - TA0008","N/A","N/A","Reconnaissance","https://github.com/ffuf/ffuf","1","1","#linux","N/A","N/A","10","13818","1373","2025-04-05T17:35:17Z","2018-11-08T09:25:49Z","44870" +"*ffuf_*_freebsd_*.tar.gz*",".{0,1000}ffuf_.{0,1000}_freebsd_.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","ffuf","Fast web fuzzer written in Go","T1110 - T1550","TA0006 - TA0008","N/A","N/A","Reconnaissance","https://github.com/ffuf/ffuf","1","1","#linux","N/A","N/A","10","13818","1373","2025-04-05T17:35:17Z","2018-11-08T09:25:49Z","44871" +"*ffuf_*_linux_*.tar.gz*",".{0,1000}ffuf_.{0,1000}_linux_.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","ffuf","Fast web fuzzer written in Go","T1110 - T1550","TA0006 - TA0008","N/A","N/A","Reconnaissance","https://github.com/ffuf/ffuf","1","1","#linux","N/A","N/A","10","13818","1373","2025-04-05T17:35:17Z","2018-11-08T09:25:49Z","44872" +"*ffuf_*_macOS_*.tar.gz*",".{0,1000}ffuf_.{0,1000}_macOS_.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","ffuf","Fast web fuzzer written in Go","T1110 - T1550","TA0006 - TA0008","N/A","N/A","Reconnaissance","https://github.com/ffuf/ffuf","1","1","#linux","N/A","N/A","10","13818","1373","2025-04-05T17:35:17Z","2018-11-08T09:25:49Z","44873" +"*ffuf_*_openbsd_*.tar.gz*",".{0,1000}ffuf_.{0,1000}_openbsd_.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","ffuf","Fast web fuzzer written in Go","T1110 - T1550","TA0006 - TA0008","N/A","N/A","Reconnaissance","https://github.com/ffuf/ffuf","1","1","#linux","N/A","N/A","10","13818","1373","2025-04-05T17:35:17Z","2018-11-08T09:25:49Z","44874" +"*ffuf_*_windows_*.zip*",".{0,1000}ffuf_.{0,1000}_windows_.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","ffuf","Fast web fuzzer written in Go","T1110 - T1550","TA0006 - TA0008","N/A","N/A","Reconnaissance","https://github.com/ffuf/ffuf","1","1","#linux","N/A","N/A","10","13818","1373","2025-04-05T17:35:17Z","2018-11-08T09:25:49Z","44875" +"*ffuf-master.zip*",".{0,1000}ffuf\-master\.zip.{0,1000}","offensive_tool_keyword","ffuf","Fast web fuzzer written in Go","T1110 - T1550","TA0006 - TA0008","N/A","N/A","Reconnaissance","https://github.com/ffuf/ffuf","1","1","#linux","N/A","N/A","10","13818","1373","2025-04-05T17:35:17Z","2018-11-08T09:25:49Z","44876" +"*fgdump.exe*",".{0,1000}fgdump\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://gitlab.com/kalilinux/packages/windows-binaries/-/tree/kali/master/fgdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","44878" +"*fgexec.exe*",".{0,1000}fgexec\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://gitlab.com/kalilinux/packages/windows-binaries/-/tree/kali/master/fgdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","44880" +"*fiddyschmitt/File-Tunnel*",".{0,1000}fiddyschmitt\/File\-Tunnel.{0,1000}","offensive_tool_keyword","File-Tunnel","Tunnel TCP connections through a file","T1071 - T1105 - T1090","TA0005 - TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/fiddyschmitt/File-Tunnel","1","1","N/A","N/A","10","10","925","82","2025-04-19T15:06:09Z","2023-02-05T12:57:45Z","44884" +"*FiercePhish*",".{0,1000}FiercePhish.{0,1000}","offensive_tool_keyword","FiercePhish","FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns. schedule sending of emails. and much more. The features will continue to be expanded and will include website spoofing. click tracking. and extensive notification options. ","T1566 - T1566.001 - T1566.002 - T1566.003","TA0001 - TA0002 - TA0003 - TA0006","N/A","N/A","Phishing","https://github.com/Raikia/FiercePhish","1","1","N/A","N/A","N/A","10","1351","255","2024-01-09T02:59:26Z","2016-12-31T19:41:24Z","44886" +"*File_Smuggler_Http_Handler*",".{0,1000}File_Smuggler_Http_Handler.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","44896" +"*FileControler/FileControler_x64.dll*",".{0,1000}FileControler\/FileControler_x64\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","44898" +"*FileControler/FileControler_x86.dll*",".{0,1000}FileControler\/FileControler_x86\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","44899" +"*File-Extensions-Wordlist.txt*",".{0,1000}File\-Extensions\-Wordlist\.txt.{0,1000}","offensive_tool_keyword","Offensive-Payloads","List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.","T1210 - T1185 - T1059 - T1400 - T1506 - T1213 ","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/InfoSecWarrior/Offensive-Payloads/","1","1","N/A","N/A","N/A","4","328","117","2024-09-20T09:59:28Z","2022-11-18T09:43:41Z","44900" +"*fileless-elf-exec*",".{0,1000}fileless\-elf\-exec.{0,1000}","offensive_tool_keyword","fileless-elf-exec","Execute ELF files without dropping them on disk","T1059.003 - T1055.012 - T1027.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/nnsee/fileless-elf-exec","1","1","N/A","N/A","8","5","491","49","2024-06-28T15:23:21Z","2020-01-06T12:19:34Z","44902" +"*FilelessPELoader.cpp*",".{0,1000}FilelessPELoader\.cpp.{0,1000}","offensive_tool_keyword","FilelessPELoader","Loading Remote AES Encrypted PE in memory - Decrypted it and run it","T1027.001 - T1059.001 - T1071","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/FilelessPELoader","1","1","N/A","N/A","10","10","933","196","2023-08-29T21:46:11Z","2023-02-08T16:59:33Z","44903" +"*FilelessPELoader.exe*",".{0,1000}FilelessPELoader\.exe.{0,1000}","offensive_tool_keyword","FilelessPELoader","Loading Remote AES Encrypted PE in memory - Decrypted it and run it","T1027.001 - T1059.001 - T1071","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/FilelessPELoader","1","1","N/A","N/A","10","10","933","196","2023-08-29T21:46:11Z","2023-02-08T16:59:33Z","44904" +"*FilelessPELoader.vcxproj*",".{0,1000}FilelessPELoader\.vcxproj.{0,1000}","offensive_tool_keyword","FilelessPELoader","Loading Remote AES Encrypted PE in memory - Decrypted it and run it","T1027.001 - T1059.001 - T1071","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/FilelessPELoader","1","1","N/A","N/A","10","10","933","196","2023-08-29T21:46:11Z","2023-02-08T16:59:33Z","44906" +"*FilelessPELoader-main*",".{0,1000}FilelessPELoader\-main.{0,1000}","offensive_tool_keyword","FilelessPELoader","Loading Remote AES Encrypted PE in memory - Decrypted it and run it","T1027.001 - T1059.001 - T1071","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/FilelessPELoader","1","1","N/A","N/A","10","10","933","196","2023-08-29T21:46:11Z","2023-02-08T16:59:33Z","44907" +"*FilelessShellcode.cpp*",".{0,1000}FilelessShellcode\.cpp.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","44908" +"*FilelessShellcode.exe*",".{0,1000}FilelessShellcode\.exe.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","44909" +"*FilelessShellcode.sln*",".{0,1000}FilelessShellcode\.sln.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","44910" +"*FilelessShellcode.vcxproj*",".{0,1000}FilelessShellcode\.vcxproj.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","44911" +"*filemsf.py*",".{0,1000}filemsf\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","44913" +"*files/BindShell.exe*",".{0,1000}files\/BindShell\.exe.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","N/A","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","44918" +"*files/team-edward.py*",".{0,1000}files\/team\-edward\.py.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","44919" +"*filezilla2john.py*",".{0,1000}filezilla2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","44926" +"*fin3ss3g0d/ASPJinjaObfuscator*",".{0,1000}fin3ss3g0d\/ASPJinjaObfuscator.{0,1000}","offensive_tool_keyword","ASPJinjaObfuscator","Heavily obfuscated ASP web shell generation tool.","T1100 - T1027","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/fin3ss3g0d/ASPJinjaObfuscator","1","1","N/A","N/A","8","2","160","21","2024-04-26T01:27:42Z","2024-04-23T01:01:53Z","44934" +"*find_and_load_coerce_methods*",".{0,1000}find_and_load_coerce_methods.{0,1000}","offensive_tool_keyword","Coercer","A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through many methods.","T1110 - T1021 - T1020","TA0006 - TA0010","N/A","N/A","Exploitation tool","https://github.com/p0dalirius/Coercer","1","1","N/A","N/A","10","10","1945","195","2025-03-21T07:42:42Z","2022-06-30T16:52:33Z","45017" +"*Find-4624Logons*",".{0,1000}Find\-4624Logons.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-ComputerDetails.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45020" +"*Find-4648Logons*",".{0,1000}Find\-4648Logons.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-ComputerDetails.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45021" +"*Find-ADInterestingACL.ps1*",".{0,1000}Find\-ADInterestingACL\.ps1.{0,1000}","offensive_tool_keyword","PowershellTools","Powershell tools used for Red Team / Pentesting","T1087.002 - T1069.001 - T1069.002 - T1598.002 - T1083 - T1558.003 - T1564.001 - T1112","TA0007 - TA0003 - TA0006 - TA0040 - TA0005 - TA0003","N/A","N/A","Exploitation tool","https://github.com/gustanini/PowershellTools","1","1","N/A","N/A","10","1","76","13","2024-01-08T10:33:20Z","2023-10-26T16:49:59Z","45023" +"*Find-AdminLogonScripts.ps1*",".{0,1000}Find\-AdminLogonScripts\.ps1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","45025" +"*Find-AmsiSignatures.ps1*",".{0,1000}Find\-AmsiSignatures\.ps1.{0,1000}","offensive_tool_keyword","PSAmsi","PSAmsi is a tool for auditing and defeating AMSI signatures.","T1059.001 - T1562.001 - T1070.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/cobbr/PSAmsi","1","1","N/A","N/A","7","4","390","74","2018-04-22T20:56:33Z","2017-09-22T11:48:47Z","45030" +"*Find-AppLockerLogs*",".{0,1000}Find\-AppLockerLogs.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-ComputerDetails.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45031" +"*FindAvailablePort.exe*",".{0,1000}FindAvailablePort\.exe.{0,1000}","offensive_tool_keyword","RemoteKrbRelay","similar to KrbRelay and KrbRelayUp but With RemoteKrbRelay this can be done remotely","T1550.004 - T1557.001 - T1021.005 - T1105","TA0008 - TA0005","N/A","N/A","Lateral Movement","https://github.com/CICADA8-Research/RemoteKrbRelay","1","1","N/A","N/A","10","6","581","90","2024-06-30T14:08:50Z","2024-06-24T17:38:46Z","45032" +"*Find-BadPrivileges-DomainComputers.ps1*",".{0,1000}Find\-BadPrivileges\-DomainComputers\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","45035" +"*Find-ComputersWithRemoteAccessPolicies.json*",".{0,1000}Find\-ComputersWithRemoteAccessPolicies\.json.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","45036" +"*Find-ComputersWithRemoteAccessPolicies.ps1*",".{0,1000}Find\-ComputersWithRemoteAccessPolicies\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","45037" +"*Find-DangerousACLPermissions*",".{0,1000}Find\-DangerousACLPermissions.{0,1000}","offensive_tool_keyword","adaudit","Powershell script to do domain auditing automation","T1087 - T1069 - T1046 - T1057 - T1114 - T1018","TA0007 - TA0003 - TA0004 - TA0006","N/A","N/A","Discovery","https://github.com/phillips321/adaudit","1","1","N/A","N/A","5","4","389","106","2025-04-08T06:17:54Z","2018-04-20T11:29:06Z","45038" +"*findDelegation.py*",".{0,1000}findDelegation\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","45041" +"*Find-DLLHijack*",".{0,1000}Find\-DLLHijack.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45042" +"*Find-Fruit.*",".{0,1000}Find\-Fruit\..{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Find-Fruit.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45046" +"*Find-Fruit.ps1*",".{0,1000}Find\-Fruit\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1108","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45047" +"*findgpocomputeradmin*",".{0,1000}findgpocomputeradmin.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","45048" +"*Find-GPOComputerAdmin*",".{0,1000}Find\-GPOComputerAdmin.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","45049" +"*Find-GPOComputerAdmin*",".{0,1000}Find\-GPOComputerAdmin.{0,1000}","offensive_tool_keyword","powerview","PowerView is a PowerShell tool to gain network situational awareness on Windows domains","T1046 - T1087.001 - T1016","TA0007 - TA0008 - TA0009","N/A","Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA","Discovery","https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","45051" +"*Find-GPOComputerAdmin*",".{0,1000}Find\-GPOComputerAdmin.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","45052" +"*Find-InterestingDomainAcl*",".{0,1000}Find\-InterestingDomainAcl.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Lateral Movement Enumeration With PowerView","T1595 - T1590 - T1591 - T1213 - T1039 - T1592","N/A","N/A","Black Basta","Lateral Movement","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","45054" +"*Find-InterestingDomainAcl*",".{0,1000}Find\-InterestingDomainAcl.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","45056" +"*Find-InterestingDomainAcl*",".{0,1000}Find\-InterestingDomainAcl.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","powerview.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45057" +"*findinterestingdomainsharefile*",".{0,1000}findinterestingdomainsharefile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","45059" +"*Find-InterestingDomainShareFile*",".{0,1000}Find\-InterestingDomainShareFile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","45061" +"*Find-InterestingDomainShareFile*",".{0,1000}Find\-InterestingDomainShareFile.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","powerview.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45062" +"*Find-InterestingFile*",".{0,1000}Find\-InterestingFile.{0,1000}","offensive_tool_keyword","powerview","PowerView is a PowerShell tool to gain network situational awareness on Windows domains","T1046 - T1087.001 - T1016","TA0007 - TA0008 - TA0009","N/A","Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA","Discovery","https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","45066" +"*Find-InterestingFile*",".{0,1000}Find\-InterestingFile.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","45067" +"*Find-KeePassconfig*",".{0,1000}Find\-KeePassconfig.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45071" +"*Find-KeePassconfig*",".{0,1000}Find\-KeePassconfig.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","45072" +"*findlocaladminaccess*",".{0,1000}findlocaladminaccess.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","45077" +"*findlocaladminaccess*",".{0,1000}findlocaladminaccess.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","45078" +"*Find-LocalAdminAccess*",".{0,1000}Find\-LocalAdminAccess.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Lateral Movement Enumeration With PowerView","T1595 - T1590 - T1591 - T1213 - T1039 - T1592","N/A","N/A","Black Basta","Lateral Movement","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","45079" +"*Find-LocalAdminAccess*",".{0,1000}Find\-LocalAdminAccess.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","45080" +"*Find-LocalAdminAccess*",".{0,1000}Find\-LocalAdminAccess.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","45081" +"*Find-LocalAdminAccess*",".{0,1000}Find\-LocalAdminAccess.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","powerview.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45082" +"*Find-LocalAdminAccess*",".{0,1000}Find\-LocalAdminAccess.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","45085" +"*Find-LocalAdminAccess*",".{0,1000}Find\-LocalAdminAccess.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","45086" +"*Find-LogonScriptCredentials.ps1*",".{0,1000}Find\-LogonScriptCredentials\.ps1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","45089" +"*FindObjects-BOF*",".{0,1000}FindObjects\-BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or process handles.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/FindObjects-BOF","1","1","N/A","N/A","10","10","268","47","2023-05-03T19:52:08Z","2021-01-11T09:38:52Z","45091" +"*Find-PathDLLHijack*",".{0,1000}Find\-PathDLLHijack.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerUp.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45092" +"*Find-PathHijack*",".{0,1000}Find\-PathHijack.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45095" +"*Find-PotentiallyCrackableAccounts.json*",".{0,1000}Find\-PotentiallyCrackableAccounts\.json.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","45096" +"*Find-ProcessDLLHijack*",".{0,1000}Find\-ProcessDLLHijack.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerUp.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45097" +"*FindProcessTokenAndDuplicate*",".{0,1000}FindProcessTokenAndDuplicate.{0,1000}","offensive_tool_keyword","cobaltstrike","A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/PPLDump_BOF","1","1","N/A","N/A","10","10","140","25","2021-09-24T07:10:04Z","2021-09-24T07:05:59Z","45100" +"*Find-ProtectionSoftware*",".{0,1000}Find\-ProtectionSoftware.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","45102" +"*Find-PSScriptsInPSAppLog*",".{0,1000}Find\-PSScriptsInPSAppLog.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-ComputerDetails.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45103" +"*Find-PSServiceAccounts.ps1*",".{0,1000}Find\-PSServiceAccounts\.ps1.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1024 - T1071 - T1029 - T1569","TA0002 - TA0003 - TA0040","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","45104" +"*Find-RDPClientConnections*",".{0,1000}Find\-RDPClientConnections.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-ComputerDetails.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45105" +"*FindSMB2UPTime.py*",".{0,1000}FindSMB2UPTime\.py.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","N/A","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","45107" +"*Findsploit*",".{0,1000}Findsploit.{0,1000}","offensive_tool_keyword","Findsploit","Finsploit is a simple bash script to quickly and easily search both local and online exploit databases. This repository also includes copysploit to copy any exploit-db exploit to the current directory and compilesploit to automatically compile and run any C exploit (ie. ./copysploit 1337.c && ./compilesploit 1337.c)","T1210 - T1105 - T1218","TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/1N3/Findsploit","1","1","N/A","N/A","N/A","10","1729","330","2021-09-27T01:43:24Z","2015-03-16T16:15:55Z","45108" +"*Find-TrustedDocuments*",".{0,1000}Find\-TrustedDocuments.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Find-TrustedDocuments.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45122" +"*Find-TrustedDocuments.ps1*",".{0,1000}Find\-TrustedDocuments\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1076","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45123" +"*FindUncommonShares.git*",".{0,1000}FindUncommonShares\.git.{0,1000}","offensive_tool_keyword","FindUncommonShares","FindUncommonShares.py is a Python equivalent of PowerView's Invoke-ShareFinder.ps1 allowing to quickly find uncommon shares in vast Windows Domains","T1135","TA0007","N/A","N/A","Discovery","https://github.com/p0dalirius/FindUncommonShares","1","1","N/A","N/A","N/A","","N/A","","","","45124" +"*FindUncommonShares-main*",".{0,1000}FindUncommonShares\-main.{0,1000}","offensive_tool_keyword","FindUncommonShares","FindUncommonShares.py is a Python equivalent of PowerView's Invoke-ShareFinder.ps1 allowing to quickly find uncommon shares in vast Windows Domains","T1135","TA0007","N/A","N/A","Discovery","https://github.com/p0dalirius/FindUncommonShares","1","1","N/A","N/A","N/A","","N/A","","","","45127" +"*finduncshar_scan*",".{0,1000}finduncshar_scan.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","45128" +"*Find-UnsafeLogonScriptPermissions.ps1*",".{0,1000}Find\-UnsafeLogonScriptPermissions\.ps1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","45129" +"*Find-UnsafeUNCPermissions.ps1*",".{0,1000}Find\-UnsafeUNCPermissions\.ps1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","45131" +"*Find-WMILocalAdminAccess*",".{0,1000}Find\-WMILocalAdminAccess.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","powerview.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45134" +"*fir3d0g/mimidogz*",".{0,1000}fir3d0g\/mimidogz.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","1","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","45136" +"*FireBuster.ps1*",".{0,1000}FireBuster\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","45137" +"*fireeye*commando*",".{0,1000}fireeye.{0,1000}commando.{0,1000}","offensive_tool_keyword","commando-vm","CommandoVM - a fully customizable Windows-based security distribution for penetration testing and red teaming.","T1059 - T1053 - T1055 - T1070","TA0002 - TA0004 - TA0008","N/A","N/A","Exploitation OS","https://github.com/mandiant/commando-vm","1","1","N/A","N/A","N/A","10","7168","1313","2024-09-24T19:14:18Z","2019-03-26T22:36:32Z","45138" +"*FireFart*dirtycow*",".{0,1000}FireFart.{0,1000}dirtycow.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirtycow vulnerability","T1533","TA0003","N/A","N/A","Exploitation tool","https://github.com/FireFart/dirtycow","1","1","N/A","N/A","N/A","9","884","428","2021-04-08T11:35:12Z","2016-11-25T21:08:01Z","45139" +"*firefox/FakeUpdate_files/*",".{0,1000}firefox\/FakeUpdate_files\/.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","45140" +"*firefox_decrypt.py*",".{0,1000}firefox_decrypt\.py.{0,1000}","offensive_tool_keyword","firefox_decrypt","Firefox Decrypt is a tool to extract passwords from Mozilla","T1555.003 - T1112 - T1056.001","TA0006 - TA0009 - TA0040","N/A","N/A","Credential Access","https://github.com/unode/firefox_decrypt","1","1","N/A","N/A","10","10","2172","317","2024-11-08T13:52:34Z","2014-01-17T13:25:02Z","45141" +"*firefox_decrypt-main*",".{0,1000}firefox_decrypt\-main.{0,1000}","offensive_tool_keyword","firefox_decrypt","Firefox Decrypt is a tool to extract passwords from Mozilla","T1555.003 - T1112 - T1056.001","TA0006 - TA0009 - TA0040","N/A","N/A","Credential Access","https://github.com/unode/firefox_decrypt","1","1","N/A","N/A","10","10","2172","317","2024-11-08T13:52:34Z","2014-01-17T13:25:02Z","45142" +"*firefox_extension_bindshell*",".{0,1000}firefox_extension_bindshell.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","45143" +"*firefox_extension_reverse_shell*",".{0,1000}firefox_extension_reverse_shell.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","45144" +"*firefox_privilege_escalation.rb*",".{0,1000}firefox_privilege_escalation\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","45145" +"*firefox_privilege_escalation_spec.rb*",".{0,1000}firefox_privilege_escalation_spec\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","45146" +"*firefox_smil_uaf*",".{0,1000}firefox_smil_uaf.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","45147" +"*FireListener.ps1*",".{0,1000}FireListener\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","45148" +"*Firewall_Walker_BOF*",".{0,1000}Firewall_Walker_BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to interact with COM objects associated with the Windows software firewall.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/Firewall_Walker_BOF","1","1","N/A","N/A","10","10","103","15","2021-10-10T03:28:27Z","2021-10-09T05:17:10Z","45157" +"*fishing_with_hollowing*",".{0,1000}fishing_with_hollowing.{0,1000}","offensive_tool_keyword","cobaltstrike","A cobaltstrike shellcode loader - past domestic mainstream antivirus software","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/YDHCUI/csload.net","1","1","N/A","N/A","10","10","122","15","2021-05-21T02:36:03Z","2021-05-20T08:24:16Z","45158" +"*fkasler/cuddlephish*",".{0,1000}fkasler\/cuddlephish.{0,1000}","offensive_tool_keyword","cuddlephish","Weaponized Browser-in-the-Middle (BitM) for Penetration Testers","T1185 - T1185.002 - T1071 - T1071.001 - T1556 - T1556.001","TA0009 - TA0006","N/A","N/A","Sniffing & Spoofing","https://github.com/fkasler/cuddlephish","1","1","N/A","N/A","10","5","487","51","2024-11-21T17:36:55Z","2023-08-02T14:30:41Z","45161" +"*Flangvik/NetLoader*",".{0,1000}Flangvik\/NetLoader.{0,1000}","offensive_tool_keyword","NetLoader","Loads any C# binary in memory - patching AMSI + ETW","T1055.012 - T1112 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Flangvik/NetLoader","1","1","N/A","N/A","10","9","820","147","2021-10-03T16:41:03Z","2020-05-05T15:20:16Z","45162" +"*Flangvik/ObfuscatedSharpCollection*",".{0,1000}Flangvik\/ObfuscatedSharpCollection.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","45163" +"*Flangvik/SharpAppLocker*",".{0,1000}Flangvik\/SharpAppLocker.{0,1000}","offensive_tool_keyword","SharpAppLocker","Useful when you already bypassed AppLocker initially and you don't want to leave PS logs","T1086 - T1569.002 - T1070.003","TA0005 - TA0006","N/A","N/A","Defense Evasion","https://github.com/Flangvik/SharpAppLocker","1","1","N/A","N/A","7","1","99","16","2022-12-08T11:06:40Z","2020-08-01T12:58:36Z","45164" +"*Flangvik/SharpCollection*",".{0,1000}Flangvik\/SharpCollection.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","45165" +"*Flangvik/SharpExfiltrate*",".{0,1000}Flangvik\/SharpExfiltrate.{0,1000}","offensive_tool_keyword","SharpExfiltrate","Modular C# framework to exfiltrate loot over secure and trusted channels.","T1027 - T1567 - T1561","TA0010 - TA0040 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/Flangvik/SharpExfiltrate","1","1","N/A","N/A","10","2","126","37","2021-09-12T17:08:02Z","2021-09-08T13:17:00Z","45166" +"*Flangvik/TeamFiltration*",".{0,1000}Flangvik\/TeamFiltration.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","45167" +"*flashupdate.ps1*",".{0,1000}flashupdate\.ps1.{0,1000}","offensive_tool_keyword","Zloader","Zloader Installs Remote Access Backdoors and Delivers Cobalt Strike","T1059 - T1220 - T1566.001 - T1059.005 - T1218.011 - T1562.001 - T1204","TA0002 - TA0008 - TA0006 - TA0001 - TA0010 - TA0003","N/A","N/A","Exploitation tool","https://news.sophos.com/en-us/2022/01/19/zloader-installs-remote-access-backdoors-and-delivers-cobalt-strike/","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","45168" +"*flipt-io/reverst*",".{0,1000}flipt\-io\/reverst.{0,1000}","offensive_tool_keyword","reverst","Reverse Tunnels in Go over HTTP/3 and QUIC","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","N/A","C2","https://github.com/flipt-io/reverst","1","1","N/A","N/A","10","10","953","39","2025-04-16T22:33:32Z","2024-04-03T13:32:11Z","45177" +"*flipt-io/reverst*",".{0,1000}flipt\-io\/reverst.{0,1000}","offensive_tool_keyword","reverst","Reverse Tunnels in Go over HTTP/3 and QUIC","T1572 - T1071.001 - T1105","TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/flipt-io/reverst","1","1","N/A","N/A","10","10","953","39","2025-04-16T22:33:32Z","2024-04-03T13:32:11Z","45178" +"*floesen/EventLogCrasher*",".{0,1000}floesen\/EventLogCrasher.{0,1000}","offensive_tool_keyword","EventLogCrasher","crash the Windows Event Log service of any other Windows 10/Windows Server 2022 machine on the same domain","T1562.002 - T1489","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/floesen/EventLogCrasher","1","1","N/A","N/A","10","2","186","34","2024-01-23T14:04:23Z","2024-01-23T09:27:27Z","45179" +"*floesen/KExecDD*",".{0,1000}floesen\/KExecDD.{0,1000}","offensive_tool_keyword","KExecDD","Admin to Kernel code execution using the KSecDD driver","T1068 - T1055.011","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/floesen/KExecDD","1","1","N/A","N/A","8","3","244","41","2024-04-19T09:58:14Z","2024-04-19T08:54:49Z","45180" +"*florylsk/NtRemoteLoad*",".{0,1000}florylsk\/NtRemoteLoad.{0,1000}","offensive_tool_keyword","NtRemoteLoad","Remote Shellcode Injector","T1055 - T1027 - T1218.010","TA0002 - TA0005 - TA0010","N/A","N/A","Exploitation tool","https://github.com/florylsk/NtRemoteLoad","1","1","N/A","N/A","10","3","213","37","2023-08-27T17:14:44Z","2023-08-27T16:52:31Z","45181" +"*FluxionNetwork*",".{0,1000}FluxionNetwork.{0,1000}","offensive_tool_keyword","FluxionNetwork","Fluxion is a security auditing and social-engineering research tool. It is a remake of linset by vk496 with (hopefully) fewer bugs and more functionality. The script attempts to retrieve the WPA/WPA2 key from a target access point by means of a social engineering (phishing) attack. Its compatible with the latest release of Kali (rolling). Fluxions attacks' setup is mostly manual. but experimental auto-mode handles some of the attacks' setup parameters. Read the FAQ before requesting issues","T1559 - T1189 - T1059 - T1566 - T1056","TA0001 - TA0002 - TA0009","N/A","N/A","Phishing","https://github.com/FluxionNetwork/fluxion","1","1","N/A","N/A","N/A","10","5207","1430","2023-11-03T23:16:30Z","2017-04-29T10:22:27Z","45183" +"*fodhelperUACBypass*",".{0,1000}fodhelperUACBypass.{0,1000}","offensive_tool_keyword","Earth Lusca Operations Tools ","Earth Lusca Operations Tools and commands","T1203 - T1218 - T1027 - T1064 - T1029 - T1210 - T1090","TA0007 - TA0008","N/A","Earth Lusca - Black Basta","Exploitation tool","https://www.trendmicro.com/content/dam/trendmicro/global/en/research/22/a/earth-lusca-employs-sophisticated-infrastructure-varied-tools-and-techniques/technical-brief-delving-deep-an-analysis-of-earth-lusca-operations.pdf https://github.com/winscripting/UAC-bypass/blob/master/FodhelperBypass.ps1","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","45187" +"*Follina.Ninja*",".{0,1000}Follina\.Ninja.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","45189" +"*follina.py*muban.docx*",".{0,1000}follina\.py.{0,1000}muban\.docx.{0,1000}","offensive_tool_keyword","POC","Just another PoC for the new MSDT-Exploit","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/komomon/CVE-2022-30190-follina-Office-MSDT-Fixed","1","1","N/A","N/A","N/A","4","396","54","2023-04-13T16:46:26Z","2022-06-02T12:33:18Z","45190" +"*Follina/follina.html*",".{0,1000}Follina\/follina\.html.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","45191" +"*Follina/Follinadoc*",".{0,1000}Follina\/Follinadoc.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","45192" +"*follow_attacker_commands.exe*",".{0,1000}follow_attacker_commands\.exe.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","45193" +"*follow_attacker_commands.py*",".{0,1000}follow_attacker_commands\.py.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","45194" +"*foreign_access.cna*",".{0,1000}foreign_access\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","LSASS Dumping With Foreign Handles","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/alfarom256/BOF-ForeignLsass","1","1","N/A","N/A","10","10","100","25","2021-08-23T16:57:08Z","2021-08-21T00:19:29Z","45209" +"*foreign_lsass.c*",".{0,1000}foreign_lsass\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","LSASS Dumping With Foreign Handles","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/alfarom256/BOF-ForeignLsass","1","1","N/A","N/A","10","10","100","25","2021-08-23T16:57:08Z","2021-08-21T00:19:29Z","45211" +"*foreign_lsass.x64*",".{0,1000}foreign_lsass\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","LSASS Dumping With Foreign Handles","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/alfarom256/BOF-ForeignLsass","1","1","N/A","N/A","10","10","100","25","2021-08-23T16:57:08Z","2021-08-21T00:19:29Z","45212" +"*foreign_lsass.x86*",".{0,1000}foreign_lsass\.x86.{0,1000}","offensive_tool_keyword","cobaltstrike","LSASS Dumping With Foreign Handles","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/alfarom256/BOF-ForeignLsass","1","1","N/A","N/A","10","10","100","25","2021-08-23T16:57:08Z","2021-08-21T00:19:29Z","45213" +"*forge_ticket.rb*",".{0,1000}forge_ticket\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","45216" +"*forge_ticket_spec.rb*",".{0,1000}forge_ticket_spec\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","45217" +"*ForgeCert.exe*",".{0,1000}ForgeCert\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","45218" +"*ForgeCert-main*",".{0,1000}ForgeCert\-main.{0,1000}","offensive_tool_keyword","ForgeCert","ForgeCert uses the BouncyCastle C# API and a stolen Certificate Authority (CA) certificate + private key to forge certificates for arbitrary users capable of authentication to Active Directory.","T1553.002 - T1136.003 - T1059.001 - T1649","TA0006 - TA0002","N/A","N/A","Defense Evasion","https://github.com/GhostPack/ForgeCert","1","1","N/A","N/A","10","7","671","109","2024-08-17T16:40:07Z","2021-06-09T22:04:18Z","45219" +"*forkatz.exe*",".{0,1000}forkatz\.exe.{0,1000}","offensive_tool_keyword","forkatz","credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege","T1003.002 - T1558.002 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/Barbarisch/forkatz","1","1","N/A","N/A","10","2","124","16","2021-05-22T00:23:04Z","2021-05-21T18:42:22Z","45221" +"*forkatz.sln*",".{0,1000}forkatz\.sln.{0,1000}","offensive_tool_keyword","forkatz","credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege","T1003.002 - T1558.002 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/Barbarisch/forkatz","1","1","N/A","N/A","10","2","124","16","2021-05-22T00:23:04Z","2021-05-21T18:42:22Z","45222" +"*forkatz.vcxproj*",".{0,1000}forkatz\.vcxproj.{0,1000}","offensive_tool_keyword","forkatz","credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege","T1003.002 - T1558.002 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/Barbarisch/forkatz","1","1","N/A","N/A","10","2","124","16","2021-05-22T00:23:04Z","2021-05-21T18:42:22Z","45223" +"*forkatz-main*",".{0,1000}forkatz\-main.{0,1000}","offensive_tool_keyword","forkatz","credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege","T1003.002 - T1558.002 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/Barbarisch/forkatz","1","1","N/A","N/A","10","2","124","16","2021-05-22T00:23:04Z","2021-05-21T18:42:22Z","45224" +"*ForkDump-x64.exe*",".{0,1000}ForkDump\-x64\.exe.{0,1000}","offensive_tool_keyword","ForkPlayground","proof-of-concept of Process Forking.","T1055 - T1003","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/D4stiny/ForkPlayground","1","1","N/A","N/A","7","3","226","33","2021-11-29T21:42:43Z","2021-11-26T04:21:46Z","45225" +"*ForkDump-x64.pdb*",".{0,1000}ForkDump\-x64\.pdb.{0,1000}","offensive_tool_keyword","ForkPlayground","proof-of-concept of Process Forking.","T1055 - T1003","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/D4stiny/ForkPlayground","1","1","N/A","N/A","7","3","226","33","2021-11-29T21:42:43Z","2021-11-26T04:21:46Z","45226" +"*ForkDump-x86.exe*",".{0,1000}ForkDump\-x86\.exe.{0,1000}","offensive_tool_keyword","ForkPlayground","proof-of-concept of Process Forking.","T1055 - T1003","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/D4stiny/ForkPlayground","1","1","N/A","N/A","7","3","226","33","2021-11-29T21:42:43Z","2021-11-26T04:21:46Z","45227" +"*ForkDump-x86.pdb*",".{0,1000}ForkDump\-x86\.pdb.{0,1000}","offensive_tool_keyword","ForkPlayground","proof-of-concept of Process Forking.","T1055 - T1003","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/D4stiny/ForkPlayground","1","1","N/A","N/A","7","3","226","33","2021-11-29T21:42:43Z","2021-11-26T04:21:46Z","45228" +"*ForkPlayground-master*",".{0,1000}ForkPlayground\-master.{0,1000}","offensive_tool_keyword","ForkPlayground","proof-of-concept of Process Forking.","T1055 - T1003","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/D4stiny/ForkPlayground","1","1","N/A","N/A","7","3","226","33","2021-11-29T21:42:43Z","2021-11-26T04:21:46Z","45229" +"*fortalice/bofhound*",".{0,1000}fortalice\/bofhound.{0,1000}","offensive_tool_keyword","bofhound","Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel","T1046 - T1087 - T1003","TA0007 - TA0009 - TA0001","N/A","N/A","Discovery","https://github.com/fortalice/bofhound","1","1","N/A","N/A","5","4","328","56","2024-02-23T15:36:24Z","2022-05-10T17:41:53Z","45234" +"*fortra/CVE-2024-6768*",".{0,1000}fortra\/CVE\-2024\-6768.{0,1000}","offensive_tool_keyword","POC","CVE-2024-6768: Improper validation of specified quantity in input produces an unrecoverable state in CLFS.sys causing a BSoD","T1499 - T1485","TA0043 - TA0042 - TA0005","N/A","N/A","Impact","https://github.com/fortra/CVE-2024-6768","1","1","N/A","N/A","10","1","16","4","2024-08-12T20:48:52Z","2024-07-18T07:52:46Z","45235" +"*fortra/impacket*",".{0,1000}fortra\/impacket.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","45236" +"*fortra/No-Consolation*",".{0,1000}fortra\/No\-Consolation.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a Beacon Object File (BOF) that executes unmanaged PEs inline and retrieves their output without allocating a console (i.e spawning conhost.exe)","T1055 - T1129","TA0005 - TA0003","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Defense Evasion","https://github.com/fortra/No-Consolation","1","1","N/A","N/A","9","6","593","68","2024-10-23T16:25:21Z","2023-11-06T22:01:42Z","45237" +"*FortyNorthSecurity/CIMplant*",".{0,1000}FortyNorthSecurity\/CIMplant.{0,1000}","offensive_tool_keyword","CIMplant","C# port of WMImplant which uses either CIM or WMI to query remote systems","T1047 - T1059.001 - T1021.006","TA0002 - TA0007 - TA0008","N/A","Scattered Spider*","Lateral Movement","https://github.com/RedSiege/CIMplant","1","1","N/A","N/A","10","2","199","29","2021-07-14T18:18:42Z","2021-01-29T21:41:58Z","45238" +"*FortyNorthSecurity/FunctionalC2*",".{0,1000}FortyNorthSecurity\/FunctionalC2.{0,1000}","offensive_tool_keyword","FunctionalC2","A small POC of using Azure Functions to relay communications","T1021.006 - T1132.002 - T1071.001","TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/FortyNorthSecurity/FunctionalC2","1","1","N/A","N/A","10","10","74","17","2023-03-30T20:27:38Z","2020-03-12T17:54:50Z","45239" +"*FourEye-main*",".{0,1000}FourEye\-main.{0,1000}","offensive_tool_keyword","FourEye","AV Evasion Tool","T1059 - T1059.001 - T1059.005 - T1027 - T1027.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/lengjibo/FourEye","1","1","N/A","N/A","10","8","758","152","2021-12-08T11:55:15Z","2020-12-11T01:29:58Z","45244" +"*foxglovesec/Potato*",".{0,1000}foxglovesec\/Potato.{0,1000}","offensive_tool_keyword","potato","Potato Privilege Escalation on Windows","T1134.001 - T1068 - T1055 - T1546.015","TA0004","N/A","N/A","Privilege Escalation","https://github.com/foxglovesec/Potato","1","1","N/A","N/A","7","8","721","165","2021-01-16T20:34:04Z","2016-02-09T11:28:17Z","45245" +"*fox-it/adconnectdump*",".{0,1000}fox\-it\/adconnectdump.{0,1000}","offensive_tool_keyword","adconnectdump","Dump Azure AD Connect credentials for Azure AD and Active Directory","T1003.004 - T1059.001 - T1082","TA0006 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/fox-it/adconnectdump","1","1","N/A","N/A","10","7","668","88","2024-11-10T22:00:16Z","2019-04-09T07:41:42Z","45246" +"*fox-it/BloodHound*",".{0,1000}fox\-it\/BloodHound.{0,1000}","offensive_tool_keyword","BloodHound","A Python based ingestor for BloodHound","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/fox-it/BloodHound.py","1","1","N/A","N/A","10","10","2088","343","2025-03-28T11:19:13Z","2018-02-26T14:44:20Z","45247" +"*foxlox/hypobrychium*",".{0,1000}foxlox\/hypobrychium.{0,1000}","offensive_tool_keyword","hypobrychium","hypobrychium AV/EDR Bypass","T1562.001 - T1070.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/foxlox/hypobrychium","1","1","N/A","N/A","8","1","72","21","2023-07-21T21:13:20Z","2023-07-18T09:55:07Z","45248" +"*FrameManagementAssociationRequest.py*",".{0,1000}FrameManagementAssociationRequest\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","45250" +"*FrameManagementDeauthentication.py*",".{0,1000}FrameManagementDeauthentication\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","45251" +"*FrameManagementProbeRequest.py*",".{0,1000}FrameManagementProbeRequest\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","45252" +"*FrameManagementReassociationResponse.py*",".{0,1000}FrameManagementReassociationResponse\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","45253" +"*framework/obfuscation/*",".{0,1000}framework\/obfuscation\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","45258" +"*Framework-MobSF*",".{0,1000}Framework\-MobSF.{0,1000}","offensive_tool_keyword","Mobile-Security-Framework-MobSF","Mobile Security Framework (MobSF) is an automated. all-in-one mobile application (Android/iOS/Windows) pen-testing. malware analysis and security assessment framework capable of performing static and dynamic analysis. MobSF support mobile app binaries (APK. XAPK. IPA & APPX) along with zipped source code and provides REST APIs for seamless integration with your CI/CD or DevSecOps pipeline.The Dynamic Analyzer helps you to perform runtime security assessment and interactive instrumented testing.","T1565.001 - T1565.002 - T1565.003 - T1565.004 - T1523","TA0007 - TA0010 - TA0003","N/A","N/A","Framework","https://github.com/MobSF/Mobile-Security-Framework-MobSF","1","1","N/A","N/A","N/A","10","18450","3353","2025-03-29T17:57:28Z","2015-01-31T04:36:01Z","45259" +"*frampton.py*",".{0,1000}frampton\.py.{0,1000}","offensive_tool_keyword","frampton","PE Binary Shellcode Injector - Automated code cave discovery. shellcode injection - ASLR bypass - x86/x64 compatible","T1055 - T1548.002 - T1129 - T1001","TA0002 - TA0003- TA0004 -TA0011","N/A","N/A","Exploitation tool","https://github.com/ins1gn1a/Frampton","1","1","N/A","N/A","N/A","1","75","19","2019-11-24T22:34:48Z","2019-10-29T00:22:14Z","45260" +"*Freakboy/Godzilla*",".{0,1000}Freakboy\/Godzilla.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","45261" +"*freenas_reverse_root_shell_csrf*",".{0,1000}freenas_reverse_root_shell_csrf.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","45262" +"*Freeze_*_darwin_amd64*",".{0,1000}Freeze_.{0,1000}_darwin_amd64.{0,1000}","offensive_tool_keyword","Freeze","Freeze is a payload toolkit for bypassing EDRs using suspended processes. direct syscalls. and alternative execution methods","T1055 - T1055.001 - T1055.003 - T1055.004 - T1055.005 - T1055.006 - T1055.007 - T1055.008 - T1055.012 - T1055.013 - T1055.014 - T1055.015 - T1055.016 - T1055.017 - T1055.018 - T1055.019 - T1055.020 - T1055.021 - T1055.022 - T1055.023 - T1055.024 - T1055.025 - T1112","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/optiv/Freeze","1","1","#linux","N/A","N/A","10","1437","187","2023-08-18T17:25:07Z","2022-09-21T14:40:59Z","45263" +"*Freeze_*_linux_amd64*",".{0,1000}Freeze_.{0,1000}_linux_amd64.{0,1000}","offensive_tool_keyword","Freeze","Freeze is a payload toolkit for bypassing EDRs using suspended processes. direct syscalls. and alternative execution methods","T1055 - T1055.001 - T1055.003 - T1055.004 - T1055.005 - T1055.006 - T1055.007 - T1055.008 - T1055.012 - T1055.013 - T1055.014 - T1055.015 - T1055.016 - T1055.017 - T1055.018 - T1055.019 - T1055.020 - T1055.021 - T1055.022 - T1055.023 - T1055.024 - T1055.025 - T1112","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/optiv/Freeze","1","1","#linux","N/A","N/A","10","1437","187","2023-08-18T17:25:07Z","2022-09-21T14:40:59Z","45264" +"*Freeze-rs.exe*",".{0,1000}Freeze\-rs\.exe.{0,1000}","offensive_tool_keyword","Freeze.rs","Freeze.rs is a payload toolkit for bypassing EDRs using suspended processes. direct syscalls written in RUST","T1548.004","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/optiv/Freeze.rs","1","1","N/A","N/A","N/A","8","716","84","2023-08-18T17:26:44Z","2023-05-03T16:04:47Z","45266" +"*Freeze-rs_darwin_amd64*",".{0,1000}Freeze\-rs_darwin_amd64.{0,1000}","offensive_tool_keyword","Freeze.rs","Freeze.rs is a payload toolkit for bypassing EDRs using suspended processes. direct syscalls written in RUST","T1548.004","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/optiv/Freeze.rs","1","1","#linux","N/A","N/A","8","716","84","2023-08-18T17:26:44Z","2023-05-03T16:04:47Z","45267" +"*Freeze-rs_linux_amd64*",".{0,1000}Freeze\-rs_linux_amd64.{0,1000}","offensive_tool_keyword","Freeze.rs","Freeze.rs is a payload toolkit for bypassing EDRs using suspended processes. direct syscalls written in RUST","T1548.004","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/optiv/Freeze.rs","1","1","#linux","N/A","N/A","8","716","84","2023-08-18T17:26:44Z","2023-05-03T16:04:47Z","45268" +"*Freeze-rs_windows_amd64.exe*",".{0,1000}Freeze\-rs_windows_amd64\.exe.{0,1000}","offensive_tool_keyword","Freeze.rs","Freeze.rs is a payload toolkit for bypassing EDRs using suspended processes. direct syscalls written in RUST","T1548.004","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/optiv/Freeze.rs","1","1","N/A","N/A","N/A","8","716","84","2023-08-18T17:26:44Z","2023-05-03T16:04:47Z","45269" +"*Friends-Security/ShadowHound*",".{0,1000}Friends\-Security\/ShadowHound.{0,1000}","offensive_tool_keyword","ShadowHound","set of PowerShell scripts for Active Directory enumeration","T1087 - T1018 - T1482 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/Friends-Security/ShadowHound","1","1","N/A","N/A","8","4","345","36","2024-12-01T08:06:02Z","2024-11-21T15:01:14Z","45273" +"*Frissi0n/GTFONow*",".{0,1000}Frissi0n\/GTFONow.{0,1000}","offensive_tool_keyword","GTFONow","Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.","T1548.003 - T1548.002 - T1548.001","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/Frissi0n/GTFONow","1","1","N/A","N/A","6","6","566","73","2024-11-10T08:38:30Z","2021-01-18T21:16:40Z","45274" +"*frkngksl/NimExec*",".{0,1000}frkngksl\/NimExec.{0,1000}","offensive_tool_keyword","NimExec","Fileless Command Execution for Lateral Movement in Nim","T1021.006 - T1059.005 - T1564.001","TA0008 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/frkngksl/NimExec","1","1","N/A","N/A","N/A","4","372","38","2023-12-12T06:59:59Z","2023-04-21T19:46:53Z","45275" +"*frkngksl/Shoggoth*",".{0,1000}frkngksl\/Shoggoth.{0,1000}","offensive_tool_keyword","Shoggoth","Shoggoth: Asmjit Based Polymorphic Encryptor","T1027 - T1045","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/frkngksl/Shoggoth","1","1","N/A","N/A","8","8","724","92","2024-04-10T03:04:04Z","2021-12-03T11:55:22Z","45276" +"*frkngksl/UnlinkDLL*",".{0,1000}frkngksl\/UnlinkDLL.{0,1000}","offensive_tool_keyword","UnlinkDLL","DLL Unlinking from InLoadOrderModuleList - InMemoryOrderModuleList - InInitializationOrderModuleList and LdrpHashTable","T1055 - T1027 - T1070","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/frkngksl/UnlinkDLL","1","1","N/A","N/A","7","1","57","13","2023-12-15T12:04:00Z","2023-12-13T14:37:33Z","45277" +"*FruityC2.py*",".{0,1000}FruityC2\.py.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","45366" +"*ftp.cc.uoc.gr/mirrors/linux/blackarch/*/os/*",".{0,1000}ftp\.cc\.uoc\.gr\/mirrors\/linux\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","45372" +"*ftp.halifax.rwth-aachen.de/blackarch/*/os/*",".{0,1000}ftp\.halifax\.rwth\-aachen\.de\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","45373" +"*ftp.icm.edu.pl/pub/Linux/dist/blackarch/*/os/*",".{0,1000}ftp\.icm\.edu\.pl\/pub\/Linux\/dist\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","45374" +"*ftp.kddilabs.jp/Linux/packages/blackarch/*/os/*",".{0,1000}ftp\.kddilabs\.jp\/Linux\/packages\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","45375" +"*ftp.linux.org.tr/blackarch/*/os/*",".{0,1000}ftp\.linux\.org\.tr\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","45376" +"*FtpC2.exe*",".{0,1000}FtpC2\.exe.{0,1000}","offensive_tool_keyword","SharpFtpC2","A Streamlined FTP-Driven Command and Control Conduit for Interconnecting Remote Systems.","T1572 - T1041 - T1105","TA0011 - TA0002 - TA0040","N/A","N/A","C2","https://github.com/DarkCoderSc/SharpFtpC2","1","1","N/A","N/A","10","10","88","15","2023-11-09T10:37:20Z","2023-06-09T12:41:28Z","45377" +"*fucksetuptools*",".{0,1000}fucksetuptools.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","45388" +"*FuckThatPacker.*",".{0,1000}FuckThatPacker\..{0,1000}","offensive_tool_keyword","cobaltstrike","A simple python packer to easily bypass Windows Defender","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Unknow101/FuckThatPacker","1","1","N/A","N/A","10","10","637","84","2022-04-03T18:20:01Z","2020-08-13T07:26:07Z","45389" +"*FudgeC2Viewer.py*",".{0,1000}FudgeC2Viewer\.py.{0,1000}","offensive_tool_keyword","FudgeC2","FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.","T1021.002 - T1105 - T1059.001 - T1059.003","TA0008 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/Ziconius/FudgeC2","1","1","N/A","N/A","10","10","253","54","2023-05-01T21:13:56Z","2018-09-09T21:05:21Z","45394" +"*fugawi/EASSniper*",".{0,1000}fugawi\/EASSniper.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","1","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","45402" +"*FULLSHADE/WindowsExploitationResources*",".{0,1000}FULLSHADE\/WindowsExploitationResources.{0,1000}","offensive_tool_keyword","WindowsExploitationResources","Resources for Windows exploit development","T1203 - T1210 - T1212 - T1216 - T1218","TA0002 - TA0007","N/A","N/A","Exploitation tool","https://github.com/FULLSHADE/WindowsExploitationResources","1","1","N/A","N/A","N/A","10","1569","322","2021-12-20T00:21:07Z","2020-05-26T07:19:54Z","45405" +"*func_get_powershell_dll*",".{0,1000}func_get_powershell_dll.{0,1000}","offensive_tool_keyword","GreatSCT","The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This tool is intended for BOTH red and blue team.","T1055 - T1112 - T1189 - T1205","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/GreatSCT/GreatSCT","1","1","N/A","N/A","N/A","10","1127","202","2021-02-10T22:05:27Z","2017-05-12T03:30:41Z","45408" +"*func_install_wine_dotnettojscript*",".{0,1000}func_install_wine_dotnettojscript.{0,1000}","offensive_tool_keyword","GreatSCT","The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This tool is intended for BOTH red and blue team.","T1055 - T1112 - T1189 - T1205","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/GreatSCT/GreatSCT","1","1","N/A","N/A","N/A","10","1127","202","2021-02-10T22:05:27Z","2017-05-12T03:30:41Z","45409" +"*FunnyWolf/pystinger*",".{0,1000}FunnyWolf\/pystinger.{0,1000}","offensive_tool_keyword","cobaltstrike","Bypass firewall for traffic forwarding using webshell. Pystinger implements SOCK4 proxy and port mapping through webshell. It can be directly used by metasploit-framework - viper- cobalt strike for session online.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/FunnyWolf/pystinger","1","1","N/A","N/A","10","10","1397","205","2021-09-29T13:13:43Z","2019-09-29T05:23:54Z","45431" +"*fuse_evil.*",".{0,1000}fuse_evil\..{0,1000}","offensive_tool_keyword","POC","Exploit for CVE-2022-27666","T1550 - T1555 - T1212 - T1558","TA0005","N/A","N/A","Exploitation tool","https://github.com/plummm/CVE-2022-27666","1","1","N/A","N/A","N/A","3","204","39","2022-03-28T18:21:00Z","2022-03-23T22:54:28Z","45432" +"*fuzz_option.pl*",".{0,1000}fuzz_option\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","45436" +"*fuzzers/rippackets.pl*",".{0,1000}fuzzers\/rippackets\.pl.{0,1000}","offensive_tool_keyword","linikatz","linikatz is a tool to attack AD on UNIX","T1003.002 - T1558.003 - T1078 - T1550.001","TA0006 - TA0001 - TA0004 - TA0003","N/A","N/A","Exploitation tool","https://github.com/CiscoCXSecurity/linikatz","1","1","#linux","N/A","10","6","552","79","2023-10-19T17:01:47Z","2018-11-15T22:19:47Z","45438" +"*fuzzfactory.py*",".{0,1000}fuzzfactory\.py.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","45439" +"*fuzzrequest.py*",".{0,1000}fuzzrequest\.py.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","45440" +"*FuzzySecurity/Dendrobate*",".{0,1000}FuzzySecurity\/Dendrobate.{0,1000}","offensive_tool_keyword","Dendrobate","Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code","T1055.012 - T1059.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Dendrobate","1","1","N/A","N/A","10","2","131","27","2021-11-19T12:18:50Z","2021-02-15T11:15:51Z","45441" +"*FuzzySecurity/StandIn*",".{0,1000}FuzzySecurity\/StandIn.{0,1000}","offensive_tool_keyword","StandIn","StandIn is a small .NET35/45 AD post-exploitation toolkit","T1087 - T1069 - T1558 - T1204 - T1136 - T1482","TA0007 - TA0003 - TA0006 - TA0004","N/A","N/A","Discovery","https://github.com/FuzzySecurity/StandIn","1","1","N/A","N/A","9","8","761","129","2023-12-02T21:20:09Z","2020-11-05T22:49:27Z","45443" +"*g_hookedSleep.*",".{0,1000}g_hookedSleep\..{0,1000}","offensive_tool_keyword","C2 related tools","An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/mgeeky/ShellcodeFluctuation","1","1","N/A","N/A","10","10","1012","160","2022-06-17T18:07:33Z","2021-09-29T10:24:52Z","45446" +"*g0h4n/RDE1*",".{0,1000}g0h4n\/RDE1.{0,1000}","offensive_tool_keyword","RDE1","RDE1 (Rusty Data Exfiltrator) is client and server tool allowing auditor to extract files from DNS and HTTPS protocols written in Rust","T1048.003 - T1567.001 - T1020","TA0011 - TA0010 - TA0040","N/A","N/A","C2","https://github.com/g0h4n/RDE1","1","1","N/A","N/A","10","10","39","6","2025-04-04T18:54:54Z","2023-09-25T20:29:08Z","45447" +"*g0h4n/REC2*",".{0,1000}g0h4n\/REC2.{0,1000}","offensive_tool_keyword","REC2 ","REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in Rust.","T1105 - T1132 - T1071.001","TA0011 - TA0009 - TA0002","N/A","N/A","C2","https://github.com/g0h4n/REC2","1","1","N/A","N/A","10","10","153","23","2024-02-22T14:02:24Z","2023-09-25T20:39:59Z","45448" +"*G0ldenGunSec/GetWebDAVStatus*",".{0,1000}G0ldenGunSec\/GetWebDAVStatus.{0,1000}","offensive_tool_keyword","cobaltstrike","Determine if the WebClient Service (WebDAV) is running on a remote system","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/G0ldenGunSec/GetWebDAVStatus","1","1","N/A","N/A","10","10","133","27","2024-03-09T22:49:45Z","2021-09-29T17:31:21Z","45449" +"*G0ldenGunSec/SharpSecDump*",".{0,1000}G0ldenGunSec\/SharpSecDump.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","1","N/A","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","45450" +"*g3tsyst3m/undertheradar*",".{0,1000}g3tsyst3m\/undertheradar.{0,1000}","offensive_tool_keyword","undertheradar","scripts that afford the pentester AV bypass techniques","T1055.005 - T1027 - T1116 - T1070.004","TA0040 - TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/g3tsyst3m/undertheradar","1","1","N/A","N/A","9","1","11","2","2023-10-08T23:31:33Z","2023-07-01T17:59:20Z","45471" +"*gabriellandau/PPLFault*",".{0,1000}gabriellandau\/PPLFault.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","45473" +"*GadgetToJScript.csproj*",".{0,1000}GadgetToJScript\.csproj.{0,1000}","offensive_tool_keyword","GadgetToJScript","A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.","T1059.001 - T1078 - T1059.005","TA0002 - TA0004 - TA0001","N/A","N/A","Exploitation tool","https://github.com/med0x2e/GadgetToJScript","1","1","N/A","N/A","10","10","942","168","2021-07-26T17:35:40Z","2019-10-05T12:27:19Z","45474" +"*GadgetToJScript.sln*",".{0,1000}GadgetToJScript\.sln.{0,1000}","offensive_tool_keyword","GadgetToJScript","A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.","T1059.001 - T1078 - T1059.005","TA0002 - TA0004 - TA0001","N/A","N/A","Exploitation tool","https://github.com/med0x2e/GadgetToJScript","1","1","N/A","N/A","10","10","942","168","2021-07-26T17:35:40Z","2019-10-05T12:27:19Z","45476" +"*GadgetToJScript-master*",".{0,1000}GadgetToJScript\-master.{0,1000}","offensive_tool_keyword","GadgetToJScript","A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.","T1059.001 - T1078 - T1059.005","TA0002 - TA0004 - TA0001","N/A","N/A","Exploitation tool","https://github.com/med0x2e/GadgetToJScript","1","1","N/A","N/A","10","10","942","168","2021-07-26T17:35:40Z","2019-10-05T12:27:19Z","45477" +"*Gality369/CS-Loader*",".{0,1000}Gality369\/CS\-Loader.{0,1000}","offensive_tool_keyword","cobaltstrike","CS anti-killing including python version and C version","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Gality369/CS-Loader","1","1","N/A","N/A","10","10","829","141","2025-04-02T09:37:10Z","2020-08-17T21:33:06Z","45478" +"*gamol6n6p2p4c3ad7gxmx3ur7wwdwlywebo2azv3vv5qlmjmole2zbyd.onion*",".{0,1000}gamol6n6p2p4c3ad7gxmx3ur7wwdwlywebo2azv3vv5qlmjmole2zbyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","45479" +"*gandcrabmfe6mnef.onion*",".{0,1000}gandcrabmfe6mnef\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","45480" +"*GateTrampolin.asm*",".{0,1000}GateTrampolin\.asm.{0,1000}","offensive_tool_keyword","RecycledInjector","Native Syscalls Shellcode Injector","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/florylsk/RecycledInjector","1","1","N/A","N/A","N/A","3","266","43","2023-07-02T11:04:28Z","2023-06-23T16:14:56Z","45481" +"*gather/keylogger*",".{0,1000}gather\/keylogger.{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","45496" +"*gather/ldap_query*",".{0,1000}gather\/ldap_query.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","45497" +"*gather/peass.rb*",".{0,1000}gather\/peass\.rb.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","45498" +"*gather/user_hunter*",".{0,1000}gather\/user_hunter.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","45499" +"*gatherer/gatherer.py*",".{0,1000}gatherer\/gatherer\.py.{0,1000}","offensive_tool_keyword","jackdaw","Jackdaw is here to collect all information in your domain. store it in a SQL database and show you nice graphs on how your domain objects interact with each-other an how a potential attacker may exploit these interactions. It also comes with a handy feature to help you in a password-cracking project by storing/looking up/reporting hashes/passowrds/users.","T1087 - T1482 - T1201 - T1213 - T1003","TA0007 - TA0008 - TA0009 - TA0006","N/A","N/A","Reconnaissance","https://github.com/skelsec/jackdaw","1","1","N/A","N/A","N/A","6","576","89","2025-03-15T13:37:50Z","2019-03-27T18:36:41Z","45500" +"*gato_x-0.5.3-py3-none-any.whl*",".{0,1000}gato_x\-0\.5\.3\-py3\-none\-any\.whl.{0,1000}","offensive_tool_keyword","Gato-X","automate advanced enumeration and exploitation techniques against GitHub repositories and organizations","T1190 - T1083 - T1588 - T1587","TA0001 - TA0007 - TA0005","N/A","N/A","Reconnaissance","https://github.com/adnanekhan/Gato-X","1","1","N/A","N/A","7","3","270","35","2025-04-21T17:57:09Z","2024-01-27T18:55:16Z","45505" +"*gc2-sheet.go*",".{0,1000}gc2\-sheet\.go.{0,1000}","offensive_tool_keyword","GC2-sheet","GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet and exfiltrate data using Google Drive.","T1071.002 - T1560 - T1105","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/looCiprian/GC2-sheet","1","1","N/A","N/A","10","10","578","111","2025-03-28T19:48:36Z","2021-09-15T19:06:12Z","45517" +"*GC2-sheet/cmd*",".{0,1000}GC2\-sheet\/cmd.{0,1000}","offensive_tool_keyword","GC2-sheet","GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet and exfiltrate data using Google Drive.","T1071.002 - T1560 - T1105","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/looCiprian/GC2-sheet","1","1","N/A","N/A","10","10","578","111","2025-03-28T19:48:36Z","2021-09-15T19:06:12Z","45518" +"*gcat*implant.py*",".{0,1000}gcat.{0,1000}implant\.py.{0,1000}","offensive_tool_keyword","gcat","A PoC backdoor that uses Gmail as a C&C server","T1071.001 - T1094 - T1102.002","TA0011 - TA0010 - TA0008","N/A","Sandworm","C2","https://github.com/byt3bl33d3r/gcat","1","1","N/A","N/A","10","10","1332","425","2018-11-16T13:43:15Z","2015-06-03T01:28:00Z","45519" +"*gcp_functionalc2.profile*",".{0,1000}gcp_functionalc2\.profile.{0,1000}","offensive_tool_keyword","FunctionalC2","A small POC of using Azure Functions to relay communications","T1021.006 - T1132.002 - T1071.001","TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/FortyNorthSecurity/FunctionalC2","1","1","N/A","N/A","10","10","74","17","2023-03-30T20:27:38Z","2020-03-12T17:54:50Z","45529" +"*GCR-Google-Calendar-RAT*",".{0,1000}GCR\-Google\-Calendar\-RAT.{0,1000}","offensive_tool_keyword","GCR-Google-Calendar-RAT","Google Calendar RAT is a PoC of Command&Control over Google Calendar Events","T1071.001 - T1021.002 - T1059","TA0002 - TA0005","N/A","N/A","C2","https://github.com/MrSaighnal/GCR-Google-Calendar-RAT","1","1","N/A","N/A","10","10","215","41","2024-04-11T18:06:02Z","2023-06-18T13:23:31Z","45532" +"*GDSSecurity/PSAttack*",".{0,1000}GDSSecurity\/PSAttack.{0,1000}","offensive_tool_keyword","PSAttack","PSAttack contains over 100 commands for Privilege Escalation - Recon and Data Exfilitration","T1059 - T1212 - T1012 - T1087 - T1005 - T1041 - T1020","TA0002 - TA0004 - TA0005 - TA0007 - TA0010 - TA0008","N/A","N/A","Exploitation tool","https://github.com/GDSSecurity/PSAttack","1","1","N/A","N/A","10","1","45","15","2017-04-04T20:37:33Z","2016-02-22T23:45:22Z","45534" +"*geacon*/cmd/*",".{0,1000}geacon.{0,1000}\/cmd\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Practice Go programming and implement CobaltStrike's Beacon in Go","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/darkr4y/geacon","1","1","N/A","N/A","10","10","1189","206","2020-10-02T10:34:37Z","2020-02-14T14:01:29Z","45535" +"*geli2john.py*",".{0,1000}geli2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","45540" +"*gemailhack.py*",".{0,1000}gemailhack\.py.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/Ha3MrX/Gemail-Hack","1","1","N/A","N/A","7","10","1062","400","2024-01-17T15:12:44Z","2018-04-19T13:48:41Z","45542" +"*genCrossC2.*",".{0,1000}genCrossC2\..{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","45547" +"*genCrossC2.Win.exe*",".{0,1000}genCrossC2\.Win\.exe.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","45548" +"*generate/canaries.go*",".{0,1000}generate\/canaries\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","45559" +"*generate/implants.go*",".{0,1000}generate\/implants\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","45560" +"*generate_beacon*",".{0,1000}generate_beacon.{0,1000}","offensive_tool_keyword","cobaltstrike","beacon generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/eddiezab/aggressor-scripts/tree/master","1","1","N/A","N/A","10","10","1","0","2021-01-29T21:01:58Z","2021-01-29T21:00:26Z","45561" +"*generate_golden_saml*",".{0,1000}generate_golden_saml.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","45564" +"*generate_loader_cmd*",".{0,1000}generate_loader_cmd.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","45567" +"*generate_powershell_exe*",".{0,1000}generate_powershell_exe.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","45572" +"*generate_powershell_shellcode*",".{0,1000}generate_powershell_shellcode.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","45574" +"*generate_python_exe*",".{0,1000}generate_python_exe.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","45575" +"*generate_python_shellcode*",".{0,1000}generate_python_shellcode.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","45576" +"*generate_raw_payload*",".{0,1000}generate_raw_payload.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","45577" +"*generate_spoofed_args_exe*",".{0,1000}generate_spoofed_args_exe.{0,1000}","offensive_tool_keyword","octopus","Octopus is an open source. pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S.","T1059.001 - T1105 - T1071.001 - T1219 - T1573","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/mhaskar/Octopus","1","1","N/A","N/A","10","10","750","156","2021-07-06T23:52:37Z","2019-08-30T21:09:07Z","45578" +"*generate_stageless*",".{0,1000}generate_stageless.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","45579" +"*generate_x64_shellcode*",".{0,1000}generate_x64_shellcode.{0,1000}","offensive_tool_keyword","octopus","Octopus is an open source. pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S.","T1059.001 - T1105 - T1071.001 - T1219 - T1573","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/mhaskar/Octopus","1","1","N/A","N/A","10","10","750","156","2021-07-06T23:52:37Z","2019-08-30T21:09:07Z","45581" +"*generate_x86_shellcode*",".{0,1000}generate_x86_shellcode.{0,1000}","offensive_tool_keyword","octopus","Octopus is an open source. pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S.","T1059.001 - T1105 - T1071.001 - T1219 - T1573","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/mhaskar/Octopus","1","1","N/A","N/A","10","10","750","156","2021-07-06T23:52:37Z","2019-08-30T21:09:07Z","45582" +"*GenerateDllBase64Hta*",".{0,1000}GenerateDllBase64Hta.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","45585" +"*GenerateExeBase64*",".{0,1000}GenerateExeBase64.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","45586" +"*GenerateForcedBrowseWordlist.py*",".{0,1000}GenerateForcedBrowseWordlist\.py.{0,1000}","offensive_tool_keyword","burpsuite","A collection of scripts to extend Burp Suite","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Discovery","https://github.com/laconicwolf/burp-extensions","1","1","N/A","network exploitation tool","N/A","2","142","31","2019-04-08T00:49:45Z","2018-03-23T16:05:01Z","45587" +"*generateInjectBinFile*",".{0,1000}generateInjectBinFile.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","45588" +"*Generate-Macro.ps1*",".{0,1000}Generate\-Macro\.ps1.{0,1000}","offensive_tool_keyword","Generate-Macro","Generate-Macro is a standalone PowerShell script that will generate a malicious Microsoft Office document with a specified payload and persistence method.","T1566 - T1059 - T1086 - T1056 - T1567","TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/enigma0x3/Generate-Macro","1","1","N/A","N/A","N/A","7","677","210","2016-10-27T20:48:59Z","2015-01-09T01:34:22Z","45589" +"*GenerateParameterWordlist.py*",".{0,1000}GenerateParameterWordlist\.py.{0,1000}","offensive_tool_keyword","burpsuite","A collection of scripts to extend Burp SuiteExtracts the parameters from URLs in scope or from a selected host","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Discovery","https://github.com/laconicwolf/burp-extensions","1","1","N/A","network exploitation tool","N/A","2","142","31","2019-04-08T00:49:45Z","2018-03-23T16:05:01Z","45590" +"*GenerateReverseTcpDrone*",".{0,1000}GenerateReverseTcpDrone.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","45591" +"*generate-rotating-beacon.*",".{0,1000}generate\-rotating\-beacon\..{0,1000}","offensive_tool_keyword","cobaltstrike","beacon generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/eddiezab/aggressor-scripts/tree/master","1","1","N/A","N/A","10","10","1","0","2021-01-29T21:01:58Z","2021-01-29T21:00:26Z","45592" +"*GeneratesShellcodeFromPEorDll*",".{0,1000}GeneratesShellcodeFromPEorDll.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","45593" +"*Genetic-Malware/Ebowla*",".{0,1000}Genetic\-Malware\/Ebowla.{0,1000}","offensive_tool_keyword","Ebowla","Framework for Making Environmental Keyed Payloads","T1027.002 - T1059.003 - T1140","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/Genetic-Malware/Ebowla","1","1","N/A","N/A","10","8","748","171","2019-01-28T10:45:15Z","2016-04-07T22:29:58Z","45602" +"*GeorgePatsias/ScareCrow*",".{0,1000}GeorgePatsias\/ScareCrow.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike script for ScareCrow payloads intergration (EDR/AV evasion)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/GeorgePatsias/ScareCrow-CobaltStrike","1","1","N/A","N/A","10","10","462","68","2022-07-15T09:39:18Z","2021-06-24T10:04:01Z","45611" +"*georgesotiriadis/Chimera*",".{0,1000}georgesotiriadis\/Chimera.{0,1000}","offensive_tool_keyword","Chimera","Automated DLL Sideloading Tool With EDR Evasion Capabilities","T1574 - T1574.001 - T1218 - T1218.002 - T1070 - T1070.004 - T1036 - T1036.005","TA0005","N/A","N/A","Defense Evasion","https://github.com/georgesotiriadis/Chimera","1","1","N/A","N/A","9","5","469","56","2023-12-19T22:58:03Z","2023-05-15T13:02:54Z","45612" +"*get_beacon(*",".{0,1000}get_beacon\(.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","45621" +"*get_BeaconHealthCheck_settings*",".{0,1000}get_BeaconHealthCheck_settings.{0,1000}","offensive_tool_keyword","cobaltstrike","This aggressor script uses a beacon's note field to indicate the health status of a beacon.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/beacon_health_check","1","1","N/A","N/A","10","10","142","21","2021-09-29T20:20:52Z","2021-07-08T13:28:11Z","45622" +"*get_c2_messages*",".{0,1000}get_c2_messages.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","45623" +"*get_c2server_all*",".{0,1000}get_c2server_all.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","45624" +"*get_cmd_from_task_id*",".{0,1000}get_cmd_from_task_id.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","45625" +"*get_dns_dnsidle*",".{0,1000}get_dns_dnsidle.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","45629" +"*get_dns_sleep*",".{0,1000}get_dns_sleep.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","45630" +"*get_filezilla_creds.rb*",".{0,1000}get_filezilla_creds\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","45633" +"*get_hijackeable_dllname*",".{0,1000}get_hijackeable_dllname.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","45634" +"*get_implants_all*",".{0,1000}get_implants_all.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","45635" +"*get_injection_techniques*",".{0,1000}get_injection_techniques.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","45636" +"*get_keystrokes.py*",".{0,1000}get_keystrokes\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Exploitation tool","https://github.com/byt3bl33d3r/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","45637" +"*get_newimplanturl*",".{0,1000}get_newimplanturl.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","45640" +"*get_password_policy.x64.*",".{0,1000}get_password_policy\.x64\..{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","45642" +"*get_password_policy.x86.*",".{0,1000}get_password_policy\.x86\..{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","45643" +"*get_post_ex_pipename_list*",".{0,1000}get_post_ex_pipename_list.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","45644" +"*get_post_ex_spawnto_x*",".{0,1000}get_post_ex_spawnto_x.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","45645" +"*get_process_inject_allocator*",".{0,1000}get_process_inject_allocator.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","45648" +"*get_process_inject_bof_allocator*",".{0,1000}get_process_inject_bof_allocator.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","45649" +"*get_process_inject_execute*",".{0,1000}get_process_inject_execute.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","45650" +"*get_rooot.c*",".{0,1000}get_rooot\.c.{0,1000}","offensive_tool_keyword","POC","Exploit for CVE-2022-27666","T1550 - T1555 - T1212 - T1558","TA0005","N/A","N/A","Exploitation tool","https://github.com/plummm/CVE-2022-27666","1","1","N/A","N/A","N/A","3","204","39","2022-03-28T18:21:00Z","2022-03-23T22:54:28Z","45651" +"*get_sharpurls*",".{0,1000}get_sharpurls.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","45652" +"*get_stage_allocator*",".{0,1000}get_stage_allocator.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","45653" +"*get_stage_magic_mz_64*",".{0,1000}get_stage_magic_mz_64.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","45654" +"*get_stage_magic_mz_86*",".{0,1000}get_stage_magic_mz_86.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","45655" +"*get_stage_magic_pe*",".{0,1000}get_stage_magic_pe.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","45656" +"*get_virtual_Hook_address*",".{0,1000}get_virtual_Hook_address.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","45657" +"*Get_WinPwn_Repo.sh*",".{0,1000}Get_WinPwn_Repo\.sh.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","45658" +"*Get-AccessTokenWithPRT*",".{0,1000}Get\-AccessTokenWithPRT.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","45827" +"*Get-AccountPassDontExpire*",".{0,1000}Get\-AccountPassDontExpire.{0,1000}","offensive_tool_keyword","adaudit","Powershell script to do domain auditing automation","T1087 - T1069 - T1046 - T1057 - T1114 - T1018","TA0007 - TA0003 - TA0004 - TA0006","N/A","N/A","Discovery","https://github.com/phillips321/adaudit","1","1","N/A","N/A","5","4","389","106","2025-04-08T06:17:54Z","2018-04-20T11:29:06Z","45828" +"*Get-AclModificationRights*",".{0,1000}Get\-AclModificationRights.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","45829" +"*Get-ActiveTCPConnections*",".{0,1000}Get\-ActiveTCPConnections.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Start-MonitorTCPConnections.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45830" +"*Get-ADCSVulns*",".{0,1000}Get\-ADCSVulns.{0,1000}","offensive_tool_keyword","adaudit","Powershell script to do domain auditing automation","T1087 - T1069 - T1046 - T1057 - T1114 - T1018","TA0007 - TA0003 - TA0004 - TA0006","N/A","N/A","Discovery","https://github.com/phillips321/adaudit","1","1","N/A","N/A","5","4","389","106","2025-04-08T06:17:54Z","2018-04-20T11:29:06Z","45836" +"*Get-adPEASAccounts*",".{0,1000}Get\-adPEASAccounts.{0,1000}","offensive_tool_keyword","adPEAS","adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others","T1016 - T1087.002 - T1482 - T1207 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/61106960/adPEAS","1","1","N/A","N/A","8","10","1095","132","2025-04-01T16:16:15Z","2020-12-23T08:10:19Z","45848" +"*Get-adPEASADCS*",".{0,1000}Get\-adPEASADCS.{0,1000}","offensive_tool_keyword","adPEAS","adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others","T1016 - T1087.002 - T1482 - T1207 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/61106960/adPEAS","1","1","N/A","N/A","8","10","1095","132","2025-04-01T16:16:15Z","2020-12-23T08:10:19Z","45849" +"*Get-adPEASBloodhound*",".{0,1000}Get\-adPEASBloodhound.{0,1000}","offensive_tool_keyword","adPEAS","adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others","T1016 - T1087.002 - T1482 - T1207 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/61106960/adPEAS","1","1","N/A","N/A","8","10","1095","132","2025-04-01T16:16:15Z","2020-12-23T08:10:19Z","45850" +"*Get-adPEASComputer*",".{0,1000}Get\-adPEASComputer.{0,1000}","offensive_tool_keyword","adPEAS","adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others","T1016 - T1087.002 - T1482 - T1207 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/61106960/adPEAS","1","1","N/A","N/A","8","10","1095","132","2025-04-01T16:16:15Z","2020-12-23T08:10:19Z","45851" +"*Get-adPEASCreds*",".{0,1000}Get\-adPEASCreds.{0,1000}","offensive_tool_keyword","adPEAS","adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others","T1016 - T1087.002 - T1482 - T1207 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/61106960/adPEAS","1","1","N/A","N/A","8","10","1095","132","2025-04-01T16:16:15Z","2020-12-23T08:10:19Z","45852" +"*Get-adPEASDelegation*",".{0,1000}Get\-adPEASDelegation.{0,1000}","offensive_tool_keyword","adPEAS","adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others","T1016 - T1087.002 - T1482 - T1207 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/61106960/adPEAS","1","1","N/A","N/A","8","10","1095","132","2025-04-01T16:16:15Z","2020-12-23T08:10:19Z","45853" +"*Get-adPEASDomain*",".{0,1000}Get\-adPEASDomain.{0,1000}","offensive_tool_keyword","adPEAS","adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others","T1016 - T1087.002 - T1482 - T1207 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/61106960/adPEAS","1","1","N/A","N/A","8","10","1095","132","2025-04-01T16:16:15Z","2020-12-23T08:10:19Z","45854" +"*Get-adPEASGPO*",".{0,1000}Get\-adPEASGPO.{0,1000}","offensive_tool_keyword","adPEAS","adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others","T1016 - T1087.002 - T1482 - T1207 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/61106960/adPEAS","1","1","N/A","N/A","8","10","1095","132","2025-04-01T16:16:15Z","2020-12-23T08:10:19Z","45855" +"*Get-adPEASRights*",".{0,1000}Get\-adPEASRights.{0,1000}","offensive_tool_keyword","adPEAS","adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others","T1016 - T1087.002 - T1482 - T1207 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/61106960/adPEAS","1","1","N/A","N/A","8","10","1095","132","2025-04-01T16:16:15Z","2020-12-23T08:10:19Z","45856" +"*Get-ADUsernameFromEWS*",".{0,1000}Get\-ADUsernameFromEWS.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","45862" +"*GetADUsers.py*",".{0,1000}GetADUsers\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","45863" +"*Get-ADUsersWithoutPreAuth*",".{0,1000}Get\-ADUsersWithoutPreAuth.{0,1000}","offensive_tool_keyword","adaudit","Powershell script to do domain auditing automation","T1087 - T1069 - T1046 - T1057 - T1114 - T1018","TA0007 - TA0003 - TA0004 - TA0006","N/A","N/A","Discovery","https://github.com/phillips321/adaudit","1","1","N/A","N/A","5","4","389","106","2025-04-08T06:17:54Z","2018-04-20T11:29:06Z","45864" +"*getAggressorClient*",".{0,1000}getAggressorClient.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","45867" +"*getAllUserSpns*",".{0,1000}getAllUserSpns.{0,1000}","offensive_tool_keyword","ldapdomaindump","Active Directory information dumper via LDAP","T1087 - T1005 - T1016","TA0007","N/A","EMBER BEAR","Discovery","https://github.com/dirkjanm/ldapdomaindump","1","1","N/A","N/A","10","10","1242","201","2025-04-06T13:31:57Z","2016-05-24T18:46:56Z","45868" +"*Get-and-Brute-LocalAccount.ps1*",".{0,1000}Get\-and\-Brute\-LocalAccount\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","45869" +"*Get-AppLockerConfig.ps1*",".{0,1000}Get\-AppLockerConfig\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","45882" +"*Get-ASREPHash*",".{0,1000}Get\-ASREPHash.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","AS-REP roasting Get the hash for a roastable user using ASREPRoast.ps1","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","45884" +"*Get-AzAutomationAccountCredsREST.ps1*",".{0,1000}Get\-AzAutomationAccountCredsREST\.ps1.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","45886" +"*Get-AzDomainInfo*",".{0,1000}Get\-AzDomainInfo.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","45887" +"*Get-AzDomainInfoREST.ps1*",".{0,1000}Get\-AzDomainInfoREST\.ps1.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","45888" +"*Get-AzKeyVaultKeysREST.ps1*",".{0,1000}Get\-AzKeyVaultKeysREST\.ps1.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","45889" +"*Get-AzKeyVaultSecretsREST.ps1*",".{0,1000}Get\-AzKeyVaultSecretsREST\.ps1.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","45890" +"*Get-AzPasswords*",".{0,1000}Get\-AzPasswords.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","45891" +"*Get-AZStorageKeysREST.ps1*",".{0,1000}Get\-AZStorageKeysREST\.ps1.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","45892" +"*Get-AzureADDomainInfo*",".{0,1000}Get\-AzureADDomainInfo.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","45893" +"*Get-AzureADDomainInfo.ps1*",".{0,1000}Get\-AzureADDomainInfo\.ps1.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","45894" +"*Get-AzurePasswords*",".{0,1000}Get\-AzurePasswords.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","45896" +"*Get-AzUserAssignedIdentity*",".{0,1000}Get\-AzUserAssignedIdentity.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","45899" +"*Get-BaseLineResponseTimeEAS*",".{0,1000}Get\-BaseLineResponseTimeEAS.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","45900" +"*Get-BeaconAPI*",".{0,1000}Get\-BeaconAPI.{0,1000}","offensive_tool_keyword","cobaltstrike","Load any Beacon Object File using Powershell!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/airbus-cert/Invoke-Bof","1","1","N/A","N/A","10","10","250","35","2021-12-09T15:10:41Z","2021-12-09T15:09:22Z","45901" +"*Get-BloodHoundData*",".{0,1000}Get\-BloodHoundData.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-SPN.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45903" +"*Get-BrowserData.ps1*",".{0,1000}Get\-BrowserData\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1153","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45905" +"*Get-CachedGPPPassword*",".{0,1000}Get\-CachedGPPPassword.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerUp.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45908" +"*Get-CachedRDPConnection*",".{0,1000}Get\-CachedRDPConnection.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","45909" +"*Get-ChromeDump*",".{0,1000}Get\-ChromeDump.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1150","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45918" +"*Get-ChromeDump*",".{0,1000}Get\-ChromeDump.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","45919" +"*Get-ChromeDump.ps1*",".{0,1000}Get\-ChromeDump\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","45920" +"*Get-ChromePasswords.ps1*",".{0,1000}Get\-ChromePasswords\.ps1.{0,1000}","offensive_tool_keyword","Dispossessor","credential scripts used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","45922" +"*Get-ClipboardContents*",".{0,1000}Get\-ClipboardContents.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45925" +"*Get-ClipboardContents.ps1*",".{0,1000}Get\-ClipboardContents\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1070","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45926" +"*Get-CompressedAgent.ps1*",".{0,1000}Get\-CompressedAgent\.ps1.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","45930" +"*Get-CompressedShellcode.ps1*",".{0,1000}Get\-CompressedShellcode\.ps1.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","45932" +"*Get-ComputerDetails*",".{0,1000}Get\-ComputerDetails.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","45933" +"*Get-ComputerDetails.ps1*",".{0,1000}Get\-ComputerDetails\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","45934" +"*Get-CredPersist*",".{0,1000}Get\-CredPersist.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","45941" +"*getCrossC2Beacon*",".{0,1000}getCrossC2Beacon.{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","45948" +"*getCrossC2Site*",".{0,1000}getCrossC2Site.{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","45949" +"*Get-DCBadPwdCount*",".{0,1000}Get\-DCBadPwdCount.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-SMBAutoBrute.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45950" +"*Get-DCsNotOwnedByDA*",".{0,1000}Get\-DCsNotOwnedByDA.{0,1000}","offensive_tool_keyword","adaudit","Powershell script to do domain auditing automation","T1087 - T1069 - T1046 - T1057 - T1114 - T1018","TA0007 - TA0003 - TA0004 - TA0006","N/A","N/A","Discovery","https://github.com/phillips321/adaudit","1","1","N/A","N/A","5","4","389","106","2025-04-08T06:17:54Z","2018-04-20T11:29:06Z","45951" +"*Get-DecodedPassword*",".{0,1000}Get\-DecodedPassword.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","45952" +"*Get-DecodedPassword*",".{0,1000}Get\-DecodedPassword.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","45953" +"*Get-DecryptedCpassword*",".{0,1000}Get\-DecryptedCpassword.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","45954" +"*Get-DecryptedCpassword*",".{0,1000}Get\-DecryptedCpassword.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-SiteListPassword.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45955" +"*Get-DecryptedPassword*",".{0,1000}Get\-DecryptedPassword.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","45956" +"*Get-DecryptedPassword*",".{0,1000}Get\-DecryptedPassword.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","45957" +"*Get-DecryptedSitelistPassword*",".{0,1000}Get\-DecryptedSitelistPassword.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-SiteListPassword.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45958" +"*Get-DiscosdurosGet-PSDrive*",".{0,1000}Get\-DiscosdurosGet\-PSDrive.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","45963" +"*getdllbaseaddress*",".{0,1000}getdllbaseaddress.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","45964" +"*get-dodgyprocesses*",".{0,1000}get\-dodgyprocesses.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","45965" +"*Get-DomainDFSshare*",".{0,1000}Get\-DomainDFSshare.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45970" +"*Get-DomainDFSShareV1*",".{0,1000}Get\-DomainDFSShareV1.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","powerview.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45971" +"*Get-DomainDFSShareV2*",".{0,1000}Get\-DomainDFSShareV2.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","powerview.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45972" +"*Get-DomainFileServer*",".{0,1000}Get\-DomainFileServer.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45973" +"*Get-DomainForeignGroupMember*",".{0,1000}Get\-DomainForeignGroupMember.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Abusing inter-forest trust Powersploit","T1550 - T1555 - T1212 - T1558","N/A","N/A","Black Basta","Exploitation tool","https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainForeignGroupMember/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","45974" +"*Get-DomainForeignUser*",".{0,1000}Get\-DomainForeignUser.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45975" +"*Get-DomainGPOComputerLocalGroupMapping*",".{0,1000}Get\-DomainGPOComputerLocalGroupMapping.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45976" +"*Get-DomainGPOUserLocalGroupMapping*",".{0,1000}Get\-DomainGPOUserLocalGroupMapping.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45977" +"*Get-DomainManagedSecurityGroup*",".{0,1000}Get\-DomainManagedSecurityGroup.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","powerview.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45981" +"*Get-DomainSearcher*",".{0,1000}Get\-DomainSearcher.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45983" +"*GetDomainsForEnumeration*",".{0,1000}GetDomainsForEnumeration.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","45984" +"*Get-DomainSpn*",".{0,1000}Get\-DomainSpn.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-SQLInstanceDomain.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45985" +"*getdomainspnticket*",".{0,1000}getdomainspnticket.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","45988" +"*Get-DomainSPNTicket*",".{0,1000}Get\-DomainSPNTicket.{0,1000}","offensive_tool_keyword","BloodHound","Kerberoasting With PowerView","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors","1","1","N/A","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","45989" +"*Get-DomainSPNTicket*",".{0,1000}Get\-DomainSPNTicket.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","45990" +"*Get-DomainSPNTicket*",".{0,1000}Get\-DomainSPNTicket.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","powerview.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","45991" +"*Get-DomainSPNTicket*",".{0,1000}Get\-DomainSPNTicket.{0,1000}","offensive_tool_keyword","powerview","PowerView is a PowerShell tool to gain network situational awareness on Windows domains","T1046 - T1087.001 - T1016","TA0007 - TA0008 - TA0009","N/A","Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA","Discovery","https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","45992" +"*Get-DXWebcamVideo.ps1*",".{0,1000}Get\-DXWebcamVideo\.ps1.{0,1000}","offensive_tool_keyword","SharpDXWebcam","Utilizing DirectX and DShowNET assemblies to record video from a host's webcam","T1123 - T1059.001 - T1027.002","TA0009 - TA0005 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/snovvcrash/SharpDXWebcam","1","1","N/A","N/A","8","1","87","10","2023-07-19T21:09:00Z","2023-07-12T03:26:24Z","45999" +"*getEnvExitPtr.exe*",".{0,1000}getEnvExitPtr\.exe.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","46002" +"*Get-ExchangeAccessToken*",".{0,1000}Get\-ExchangeAccessToken.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","46003" +"*Get-ExoPsAccessToken*",".{0,1000}Get\-ExoPsAccessToken.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","46004" +"*getExploit.py*",".{0,1000}getExploit\.py.{0,1000}","offensive_tool_keyword","getExploit","Python script to explore exploits from exploit-db.com. Exist a similar script in Kali Linux. but in difference this python script will have provide more flexibility at search and download time.","T1587 - T1068 - T1211 - T1210 - T1588","TA0006 - TA0002 - TA0009 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/Gioyik/getExploit","1","1","#linux","N/A","N/A","1","43","27","2015-06-26T16:38:55Z","2015-01-03T03:26:21Z","46005" +"*getexploitablesystem*",".{0,1000}getexploitablesystem.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","46007" +"*Get-ExploitableSystem*",".{0,1000}Get\-ExploitableSystem.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","46008" +"*Get-ExploitableSystem.psm1*",".{0,1000}Get\-ExploitableSystem\.psm1.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","46012" +"*Get-ExploitableSystems.psm1*",".{0,1000}Get\-ExploitableSystems\.psm1.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","46013" +"*Get-ExploitableUnquotedPath*",".{0,1000}Get\-ExploitableUnquotedPath.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","46014" +"*Get-FirefoxPasswords.ps1*",".{0,1000}Get\-FirefoxPasswords\.ps1.{0,1000}","offensive_tool_keyword","Dispossessor","credential scripts used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","46019" +"*Get-ForgedUserAgent.ps1*",".{0,1000}Get\-ForgedUserAgent\.ps1.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","1","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","46021" +"*Get-FoxDump*",".{0,1000}Get\-FoxDump.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46023" +"*Get-FoxDump.ps1*",".{0,1000}Get\-FoxDump\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","46024" +"*GetFullPrivsClient.exe*",".{0,1000}GetFullPrivsClient\.exe.{0,1000}","offensive_tool_keyword","VectorKernel","PoCs for Kernelmode rootkit techniques research.","T1543 - T1055 - T1134 - T1564 - T1070 - T1057 - T1574 - T1562 - T1082 - T1518","TA0003 - TA0005 - TA0004 - TA0008 - TA0007","N/A","N/A","Exploitation tool","https://github.com/daem0nc0re/VectorKernel/","1","1","N/A","N/A","10","4","367","60","2025-01-21T08:22:42Z","2023-11-23T12:36:31Z","46025" +"*GetFullPrivsDrv_x64.sys*",".{0,1000}GetFullPrivsDrv_x64\.sys.{0,1000}","offensive_tool_keyword","VectorKernel","PoCs for Kernelmode rootkit techniques research.","T1543 - T1055 - T1134 - T1564 - T1070 - T1057 - T1574 - T1562 - T1082 - T1518","TA0003 - TA0005 - TA0004 - TA0008 - TA0007","N/A","N/A","Exploitation tool","https://github.com/daem0nc0re/VectorKernel/","1","1","N/A","N/A","10","4","367","60","2025-01-21T08:22:42Z","2023-11-23T12:36:31Z","46026" +"*get-get-get-get/PowerProxy*",".{0,1000}get\-get\-get\-get\/PowerProxy.{0,1000}","offensive_tool_keyword","PowerProxy","PowerShell SOCKS proxy with reverse proxy capabilities","T1090.003 - T1059.001 - T1105","TA0011 - TA0005 - TA0008","N/A","Dispossessor","C2","https://github.com/get-get-get-get/PowerProxy","1","1","N/A","N/A","10","10","80","10","2021-04-23T16:51:28Z","2020-01-03T18:18:58Z","46027" +"*Get-GPOEnum*",".{0,1000}Get\-GPOEnum.{0,1000}","offensive_tool_keyword","adaudit","Powershell script to do domain auditing automation","T1087 - T1069 - T1046 - T1057 - T1114 - T1018","TA0007 - TA0003 - TA0004 - TA0006","N/A","N/A","Discovery","https://github.com/phillips321/adaudit","1","1","N/A","N/A","5","4","389","106","2025-04-08T06:17:54Z","2018-04-20T11:29:06Z","46029" +"*Get-GPOsPerOU*",".{0,1000}Get\-GPOsPerOU.{0,1000}","offensive_tool_keyword","adaudit","Powershell script to do domain auditing automation","T1087 - T1069 - T1046 - T1057 - T1114 - T1018","TA0007 - TA0003 - TA0004 - TA0006","N/A","N/A","Discovery","https://github.com/phillips321/adaudit","1","1","N/A","N/A","5","4","389","106","2025-04-08T06:17:54Z","2018-04-20T11:29:06Z","46030" +"*Get-GPOtoFile*",".{0,1000}Get\-GPOtoFile.{0,1000}","offensive_tool_keyword","adaudit","Powershell script to do domain auditing automation","T1087 - T1069 - T1046 - T1057 - T1114 - T1018","TA0007 - TA0003 - TA0004 - TA0006","N/A","N/A","Discovery","https://github.com/phillips321/adaudit","1","1","N/A","N/A","5","4","389","106","2025-04-08T06:17:54Z","2018-04-20T11:29:06Z","46031" +"*Get-GPPInnerFields*",".{0,1000}Get\-GPPInnerFields.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46036" +"*Get-GPPPassword*",".{0,1000}Get\-GPPPassword.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-SiteListPassword.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46040" +"*Get-GPPPassword.*",".{0,1000}Get\-GPPPassword\..{0,1000}","offensive_tool_keyword","adaudit","Powershell script to do domain auditing automation","T1087 - T1069 - T1046 - T1057 - T1114 - T1018","TA0007 - TA0003 - TA0004 - TA0006","N/A","N/A","Discovery","https://github.com/phillips321/adaudit","1","1","N/A","N/A","5","4","389","106","2025-04-08T06:17:54Z","2018-04-20T11:29:06Z","46042" +"*Get-GPPPassword.json*",".{0,1000}Get\-GPPPassword\.json.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","46043" +"*Get-GPPPassword.ps1*",".{0,1000}Get\-GPPPassword\.ps1.{0,1000}","offensive_tool_keyword","ADAPE-Script","Active Directory Assessment and Privilege Escalation Script","T1178 - T1087 - T1482","TA0002 - TA0004 - TA0007","N/A","Black Basta","Privilege Escalation","https://github.com/cjoan75/ADAPE-Script","1","1","N/A","N/A","8","1","0","0","2020-07-11T00:53:24Z","2020-08-09T16:52:35Z","46044" +"*Get-GPPPassword.ps1*",".{0,1000}Get\-GPPPassword\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1124","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46045" +"*Get-GPPPassword.py*",".{0,1000}Get\-GPPPassword\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","46046" +"*Get-HeadersWithPrtCookies*",".{0,1000}Get\-HeadersWithPrtCookies.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","46053" +"*GetHijackableDllName*",".{0,1000}GetHijackableDllName.{0,1000}","offensive_tool_keyword","cobaltstrike","A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/PPLDump_BOF","1","1","N/A","N/A","10","10","140","25","2021-09-24T07:10:04Z","2021-09-24T07:05:59Z","46054" +"*get-implantworkingdirectory*",".{0,1000}get\-implantworkingdirectory.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","46057" +"*Get-IndexedItem.ps1*",".{0,1000}Get\-IndexedItem\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","46059" +"*Get-Information_exfil.ps1*",".{0,1000}Get\-Information_exfil\.ps1.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","46060" +"*Get-KeePassconfig*",".{0,1000}Get\-KeePassconfig.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46068" +"*Get-KeePassConfigTrigger*",".{0,1000}Get\-KeePassConfigTrigger.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","46070" +"*Get-KeePassDatabaseKey*",".{0,1000}Get\-KeePassDatabaseKey.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46073" +"*Get-KeePassDatabaseKey*",".{0,1000}Get\-KeePassDatabaseKey.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","46074" +"*Get-KeePassINIFields*",".{0,1000}Get\-KeePassINIFields.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46075" +"*Get-KeePassXMLFields*",".{0,1000}Get\-KeePassXMLFields.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46076" +"*Get-KerberosServiceTicket.ps1*",".{0,1000}Get\-KerberosServiceTicket\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","46078" +"*Get-KeystrokeData*",".{0,1000}Get\-KeystrokeData.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","46080" +"*Get-Keystrokes*",".{0,1000}Get\-Keystrokes.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1067","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46082" +"*get-keystrokes*",".{0,1000}get\-keystrokes.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","46083" +"*Get-Keystrokes.ps1*",".{0,1000}Get\-Keystrokes\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","46085" +"*get-killdate*",".{0,1000}get\-killdate.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","46087" +"*Get-LAPSPasswords*",".{0,1000}Get\-LAPSPasswords.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","46089" +"*Get-LAPSPasswords.ps1*",".{0,1000}Get\-LAPSPasswords\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","46091" +"*GetLoggedOnUsersRegistry.cs*",".{0,1000}GetLoggedOnUsersRegistry\.cs.{0,1000}","offensive_tool_keyword","GetLoggedOnUsersRegistry","PoC To enumerate logged on users on a remote system using the winreg named pipe","T1087 - T1018 - T1057","TA0007 - TA0008","N/A","N/A","Discovery","https://gist.github.com/RalphDesmangles/22f580655f479f189c1de9e7720776f1","1","1","N/A","N/A","8","8","N/A","N/A","N/A","N/A","46099" +"*Get-LsaRunAsPPLStatus*",".{0,1000}Get\-LsaRunAsPPLStatus.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","46102" +"*Get-LSASecret*",".{0,1000}Get\-LSASecret.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","46105" +"*Get-LSASecret.ps1*",".{0,1000}Get\-LSASecret\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","46106" +"*Get-LSASecret.ps1*",".{0,1000}Get\-LSASecret\.ps1.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","46107" +"*Get-LSASecrets.ps1*",".{0,1000}Get\-LSASecrets\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","46108" +"*Get-ModifiableRegistryAutoRun*",".{0,1000}Get\-ModifiableRegistryAutoRun.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerUp.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46112" +"*Get-ModifiableScheduledTaskFile*",".{0,1000}Get\-ModifiableScheduledTaskFile.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerUp.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46114" +"*Get-MSSQLAllCredentials*",".{0,1000}Get\-MSSQLAllCredentials.{0,1000}","offensive_tool_keyword","PowerUpSQL","NetSPI powershell modules to gather credentials","T1552.001 - T1555.004 - T1003","TA0006 - TA0009 - TA0010","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/NetSPI/Powershell-Modules","1","1","N/A","N/A","10","2","168","101","2019-06-06T15:54:47Z","2014-02-28T21:24:21Z","46121" +"*Get-MSSQLCredentialPasswords*",".{0,1000}Get\-MSSQLCredentialPasswords.{0,1000}","offensive_tool_keyword","PowerUpSQL","NetSPI powershell modules to gather credentials","T1552.001 - T1555.004 - T1003","TA0006 - TA0009 - TA0010","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/NetSPI/Powershell-Modules","1","1","N/A","N/A","10","2","168","101","2019-06-06T15:54:47Z","2014-02-28T21:24:21Z","46122" +"*Get-MSSQLCredentialPasswords*",".{0,1000}Get\-MSSQLCredentialPasswords.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46123" +"*Get-MSSQLLinkPasswords*",".{0,1000}Get\-MSSQLLinkPasswords.{0,1000}","offensive_tool_keyword","PowerUpSQL","NetSPI powershell modules to gather credentials","T1552.001 - T1555.004 - T1003","TA0006 - TA0009 - TA0010","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/NetSPI/Powershell-Modules","1","1","N/A","N/A","10","2","168","101","2019-06-06T15:54:47Z","2014-02-28T21:24:21Z","46124" +"*Get-NestedGroupMembership.ps1*",".{0,1000}Get\-NestedGroupMembership\.ps1.{0,1000}","offensive_tool_keyword","PowershellTools","Powershell tools used for Red Team / Pentesting","T1087.002 - T1069.001 - T1069.002 - T1598.002 - T1083 - T1558.003 - T1564.001 - T1112","TA0007 - TA0003 - TA0006 - TA0040 - TA0005 - TA0003","N/A","N/A","Exploitation tool","https://github.com/gustanini/PowershellTools","1","1","N/A","N/A","10","1","76","13","2024-01-08T10:33:20Z","2023-10-26T16:49:59Z","46126" +"*Get-NetFileServer*",".{0,1000}Get\-NetFileServer.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","powerview.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46131" +"*Get-NetLocalGroupMember*",".{0,1000}Get\-NetLocalGroupMember.{0,1000}","offensive_tool_keyword","powerview","PowerView is a PowerShell tool to gain network situational awareness on Windows domains","T1046 - T1087.001 - T1016","TA0007 - TA0008 - TA0009","N/A","Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA","Discovery","https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","46142" +"*Get-NetLoggedon*",".{0,1000}Get\-NetLoggedon.{0,1000}","offensive_tool_keyword","powerview","PowerView is a PowerShell tool to gain network situational awareness on Windows domains","T1046 - T1087.001 - T1016","TA0007 - TA0008 - TA0009","N/A","Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA","Discovery","https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","46145" +"*Get-NetRDPSession*",".{0,1000}Get\-NetRDPSession.{0,1000}","offensive_tool_keyword","powerview","PowerView is a PowerShell tool to gain network situational awareness on Windows domains","T1046 - T1087.001 - T1016","TA0007 - TA0008 - TA0009","N/A","Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA","Discovery","https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","46149" +"*Get-NetSessionEnum.ps1*",".{0,1000}Get\-NetSessionEnum\.ps1.{0,1000}","offensive_tool_keyword","NetSess","Command line tool to enumerate NetBIOS sessions on a specified local or remote machine. ","T1016 - T1046 - T1087","TA0007 - TA0043","N/A","MUSTANG PANDA","Discovery","https://www.joeware.net/freetools/tools/netsess/","1","1","N/A","N/A","7","9","N/A","N/A","N/A","N/A","46151" +"*getNimplantByGuid*",".{0,1000}getNimplantByGuid.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","46157" +"*GetNPUsers.py*",".{0,1000}GetNPUsers\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","46159" +"*Get-NTDSdit*",".{0,1000}Get\-NTDSdit.{0,1000}","offensive_tool_keyword","adaudit","Powershell script to do domain auditing automation","T1087 - T1069 - T1046 - T1057 - T1114 - T1018","TA0007 - TA0003 - TA0004 - TA0006","N/A","N/A","Discovery","https://github.com/phillips321/adaudit","1","1","N/A","N/A","5","4","389","106","2025-04-08T06:17:54Z","2018-04-20T11:29:06Z","46160" +"*getnthash.py*",".{0,1000}getnthash\.py.{0,1000}","offensive_tool_keyword","PKINITtools","Tools for Kerberos PKINIT and relaying to AD CS","T1550.003 - T1557.002 - T1552.004 - T1212 - T1550","TA0009 - TA0008","N/A","N/A","Lateral Movement","https://github.com/dirkjanm/PKINITtools","1","1","N/A","N/A","N/A","8","737","82","2025-01-03T14:25:52Z","2021-07-27T19:06:09Z","46163" +"*Get-NTLM.ps1*",".{0,1000}Get\-NTLM\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","46164" +"*GetNTLMChallengeBase64*",".{0,1000}GetNTLMChallengeBase64.{0,1000}","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","46165" +"*Get-NTLMLocalPasswordHashes*",".{0,1000}Get\-NTLMLocalPasswordHashes.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","46166" +"*Get-PacketNetBIOSSessionService*",".{0,1000}Get\-PacketNetBIOSSessionService.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-InveighRelay.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46168" +"*Get-PacketNTLMSSPAuth*",".{0,1000}Get\-PacketNTLMSSPAuth.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-InveighRelay.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46169" +"*Get-PacketNTLMSSPNegotiate*",".{0,1000}Get\-PacketNTLMSSPNegotiate.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-InveighRelay.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46170" +"*Get-PacketRPCBind*",".{0,1000}Get\-PacketRPCBind.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-InveighRelay.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46171" +"*Get-PacketRPCRequest*",".{0,1000}Get\-PacketRPCRequest.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-InveighRelay.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46172" +"*Get-PacketSMB*",".{0,1000}Get\-PacketSMB.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-InveighRelay.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46173" +"*Get-PassHashes*",".{0,1000}Get\-PassHashes.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","46174" +"*Get-PassHashes.ps1*",".{0,1000}Get\-PassHashes\.ps1.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","46175" +"*Get-PassHashes.ps1*",".{0,1000}Get\-PassHashes\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","46176" +"*Get-PassHints*",".{0,1000}Get\-PassHints.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","46177" +"*get-passnotexp*",".{0,1000}get\-passnotexp.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","46178" +"*get-password-policy.py*",".{0,1000}get\-password\-policy\.py.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","46179" +"*Get-PEHeader.ps1*",".{0,1000}Get\-PEHeader\.ps1.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","46181" +"*getPositionImplant*",".{0,1000}getPositionImplant.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","46182" +"*Get-PotentialDLLHijack*",".{0,1000}Get\-PotentialDLLHijack.{0,1000}","offensive_tool_keyword","DLLHijackTest","DLL and PowerShell script to assist with finding DLL hijacks","T1574.002 - T1055.001 - T1059.001 - T1036.005","TA0005 - TA0004 - TA0002","N/A","N/A","Defense Evasion","https://github.com/slyd0g/DLLHijackTest","1","1","N/A","N/A","9","4","335","62","2020-10-01T22:37:36Z","2020-06-20T04:33:01Z","46183" +"*Get-PrivilegedGroupAccounts*",".{0,1000}Get\-PrivilegedGroupAccounts.{0,1000}","offensive_tool_keyword","adaudit","Powershell script to do domain auditing automation","T1087 - T1069 - T1046 - T1057 - T1114 - T1018","TA0007 - TA0003 - TA0004 - TA0006","N/A","N/A","Discovery","https://github.com/phillips321/adaudit","1","1","N/A","N/A","5","4","389","106","2025-04-08T06:17:54Z","2018-04-20T11:29:06Z","46184" +"*Get-PrivilegedGroupMembership*",".{0,1000}Get\-PrivilegedGroupMembership.{0,1000}","offensive_tool_keyword","adaudit","Powershell script to do domain auditing automation","T1087 - T1069 - T1046 - T1057 - T1114 - T1018","TA0007 - TA0003 - TA0004 - TA0006","N/A","N/A","Discovery","https://github.com/phillips321/adaudit","1","1","N/A","N/A","5","4","389","106","2025-04-08T06:17:54Z","2018-04-20T11:29:06Z","46185" +"*getprivs.bin*",".{0,1000}getprivs\.bin.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","46186" +"*getprivs.exe*",".{0,1000}getprivs\.exe.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","46187" +"*Get-RBCD-Threaded*",".{0,1000}Get\-RBCD\-Threaded.{0,1000}","offensive_tool_keyword","Get-RBCD-Threaded","Tool to discover Resource-Based Constrained Delegation attack paths in Active Directory Environments","T1558 - T1208 - T1550 - T1484 - T1486","TA0007 - TA0008","N/A","N/A","Exploitation tool","https://github.com/FatRodzianko/Get-RBCD-Threaded","1","1","N/A","N/A","N/A","2","121","19","2021-08-10T23:29:48Z","2019-12-21T00:08:28Z","46194" +"*Get-RegAlwaysInstallElevated*",".{0,1000}Get\-RegAlwaysInstallElevated.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46195" +"*Get-RegAutoLogon*",".{0,1000}Get\-RegAutoLogon.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46196" +"*Get-RegistryAlwaysInstallElevated*",".{0,1000}Get\-RegistryAlwaysInstallElevated.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerUp.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46197" +"*Get-RegistryAutoLogon*",".{0,1000}Get\-RegistryAutoLogon.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerUp.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46199" +"*GetRektBoy724/SharpUnhooker*",".{0,1000}GetRektBoy724\/SharpUnhooker.{0,1000}","offensive_tool_keyword","SharpUnhooker","C# Based Universal API Unhooker","T1055.012 - T1070.004 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/GetRektBoy724/SharpUnhooker","1","1","N/A","N/A","9","5","400","80","2022-02-18T13:11:11Z","2021-05-17T01:33:38Z","46204" +"*Get-RemoteCachedCredential*",".{0,1000}Get\-RemoteCachedCredential.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Get cached credentials (if any)","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","46205" +"*Get-RemoteCachedCredential*",".{0,1000}Get\-RemoteCachedCredential.{0,1000}","offensive_tool_keyword","DAMP","The Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification.","T1222 - T1222.002 - T1548 - T1548.002","TA0005 ","N/A","N/A","Persistence","https://github.com/HarmJ0y/DAMP","1","1","N/A","N/A","10","4","378","79","2019-07-25T21:18:37Z","2018-04-06T22:13:58Z","46206" +"*Get-RemoteCachedCredential*",".{0,1000}Get\-RemoteCachedCredential.{0,1000}","offensive_tool_keyword","DAMP","The Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification.","T1222 - T1222.002 - T1548 - T1548.002","TA0005 ","N/A","N/A","Persistence","https://github.com/HarmJ0y/DAMP","1","1","N/A","N/A","10","4","378","79","2019-07-25T21:18:37Z","2018-04-06T22:13:58Z","46207" +"*Get-RemoteDesktopUserSessionList*",".{0,1000}Get\-RemoteDesktopUserSessionList.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","46208" +"*Get-RemoteDesktopUserSessionList.*",".{0,1000}Get\-RemoteDesktopUserSessionList\..{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","46209" +"*Get-RemoteLocalAccountHash*",".{0,1000}Get\-RemoteLocalAccountHash.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Get local account hashes","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","46210" +"*Get-RemoteLocalAccountHash*",".{0,1000}Get\-RemoteLocalAccountHash.{0,1000}","offensive_tool_keyword","DAMP","The Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification.","T1222 - T1222.002 - T1548 - T1548.002","TA0005 ","N/A","N/A","Persistence","https://github.com/HarmJ0y/DAMP","1","1","N/A","N/A","10","4","378","79","2019-07-25T21:18:37Z","2018-04-06T22:13:58Z","46211" +"*Get-RemoteLocalAccountHash*",".{0,1000}Get\-RemoteLocalAccountHash.{0,1000}","offensive_tool_keyword","DAMP","The Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification.","T1222 - T1222.002 - T1548 - T1548.002","TA0005 ","N/A","N/A","Persistence","https://github.com/HarmJ0y/DAMP","1","1","N/A","N/A","10","4","378","79","2019-07-25T21:18:37Z","2018-04-06T22:13:58Z","46212" +"*Get-RemoteMachineAccountHash*",".{0,1000}Get\-RemoteMachineAccountHash.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Get machine account hash for silver ticket attack","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","46214" +"*Get-RemoteMachineAccountHash*",".{0,1000}Get\-RemoteMachineAccountHash.{0,1000}","offensive_tool_keyword","DAMP","The Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification.","T1222 - T1222.002 - T1548 - T1548.002","TA0005 ","N/A","N/A","Persistence","https://github.com/HarmJ0y/DAMP","1","1","N/A","N/A","10","4","378","79","2019-07-25T21:18:37Z","2018-04-06T22:13:58Z","46215" +"*Get-RemoteMachineAccountHash.json*",".{0,1000}Get\-RemoteMachineAccountHash\.json.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","46216" +"*getremoteprocesslisting*",".{0,1000}getremoteprocesslisting.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","46217" +"*Get-RickAstley*",".{0,1000}Get\-RickAstley.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-RickAstley.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46218" +"*Get-RickAstley.ps1*",".{0,1000}Get\-RickAstley\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1053","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46219" +"*Get-RubeusForgeryArgs*",".{0,1000}Get\-RubeusForgeryArgs.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","46220" +"*gets4uticket.py*",".{0,1000}gets4uticket\.py.{0,1000}","offensive_tool_keyword","PKINITtools","Tools for Kerberos PKINIT and relaying to AD CS","T1550.003 - T1557.002 - T1552.004 - T1212 - T1550","TA0009 - TA0008","N/A","N/A","Lateral Movement","https://github.com/dirkjanm/PKINITtools","1","1","N/A","N/A","N/A","8","737","82","2025-01-03T14:25:52Z","2021-07-27T19:06:09Z","46221" +"*Get-SccmCacheFolder*",".{0,1000}Get\-SccmCacheFolder.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","46222" +"*Get-Screenshot.ps1*",".{0,1000}Get\-Screenshot\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","46225" +"*Get-Screenshot.ps1*",".{0,1000}Get\-Screenshot\.ps1.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","46226" +"*get-screenshotallwindows*",".{0,1000}get\-screenshotallwindows.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","46227" +"*Get-SecurityPackages.ps1*",".{0,1000}Get\-SecurityPackages\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-Vnc.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46228" +"*Get-ServiceUnquoted*",".{0,1000}Get\-ServiceUnquoted.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46229" +"*Get-ShadowCopies*",".{0,1000}Get\-ShadowCopies.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","46230" +"*Get-SharpChromium.ps1*",".{0,1000}Get\-SharpChromium\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","46233" +"*Get-SitelistFields*",".{0,1000}Get\-SitelistFields.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-SiteListPassword.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46235" +"*Get-SiteListPassword*",".{0,1000}Get\-SiteListPassword.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-SiteListPassword.ps1 PowerUp.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46236" +"*Get-SiteListPassword.ps1*",".{0,1000}Get\-SiteListPassword\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","46238" +"*Get-SPN.ps1*",".{0,1000}Get\-SPN\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1114","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46241" +"*Get-SPN-FruityC2.ps1*",".{0,1000}Get\-SPN\-FruityC2\.ps1.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","46242" +"*Get-SQLC2Agent*",".{0,1000}Get\-SQLC2Agent.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46246" +"*Get-SQLC2ComputerNameFromInstance*",".{0,1000}Get\-SQLC2ComputerNameFromInstance.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46248" +"*Get-SQLC2Connection*",".{0,1000}Get\-SQLC2Connection.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46249" +"*Get-SQLC2Query*",".{0,1000}Get\-SQLC2Query.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46250" +"*Get-SQLC2Result*",".{0,1000}Get\-SQLC2Result.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46251" +"*Get-SQLDomainPasswordsLAPS*",".{0,1000}Get\-SQLDomainPasswordsLAPS.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46252" +"*Get-SQLFuzzDatabaseName*",".{0,1000}Get\-SQLFuzzDatabaseName.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46253" +"*Get-SQLFuzzDomainAccount*",".{0,1000}Get\-SQLFuzzDomainAccount.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46254" +"*Get-SQLFuzzObjectName*",".{0,1000}Get\-SQLFuzzObjectName.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46255" +"*Get-SQLFuzzServerLogin'*",".{0,1000}Get\-SQLFuzzServerLogin\'.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46256" +"*Get-SQLLocalAdminCheck*",".{0,1000}Get\-SQLLocalAdminCheck.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46259" +"*Get-SQLOleDbProvder*",".{0,1000}Get\-SQLOleDbProvder.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46260" +"*Get-SQLPersistRegDebugger*",".{0,1000}Get\-SQLPersistRegDebugger.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46261" +"*Get-SQLPersistRegRun*",".{0,1000}Get\-SQLPersistRegRun.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46262" +"*Get-SQLPersistTriggerDDL*",".{0,1000}Get\-SQLPersistTriggerDDL.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46263" +"*Get-SQLQuery.ps1*",".{0,1000}Get\-SQLQuery\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","46264" +"*Get-SQLRecoverPwAutoLogon*",".{0,1000}Get\-SQLRecoverPwAutoLogon.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46265" +"*Get-SQLServerCredential*",".{0,1000}Get\-SQLServerCredential.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46266" +"*Get-SqlServerLinkCrawl*",".{0,1000}Get\-SqlServerLinkCrawl.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Automatically find all linked databases","T1550 - T1555 - T1212 - T1558","N/A","N/A","Black Basta","Exploitation tool","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","46267" +"*Get-SQLServerLinkCrawl*",".{0,1000}Get\-SQLServerLinkCrawl.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46268" +"*Get-SQLServerLoginDefaultPw*",".{0,1000}Get\-SQLServerLoginDefaultPw.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-SQLServerLoginDefaultPw.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46269" +"*Get-SQLServerLoginDefaultPw*",".{0,1000}Get\-SQLServerLoginDefaultPw.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46270" +"*Get-SQLServerPasswordHash*",".{0,1000}Get\-SQLServerPasswordHash.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46271" +"*Get-SQLServerPriv*",".{0,1000}Get\-SQLServerPriv.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46272" +"*Get-SQLServiceAccountPwHashes*",".{0,1000}Get\-SQLServiceAccountPwHashes.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46274" +"*Get-SQLSysadminCheck*",".{0,1000}Get\-SQLSysadminCheck.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-SQLServerLoginDefaultPw.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46275" +"*Get-SQLTriggerDdl*",".{0,1000}Get\-SQLTriggerDdl.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46277" +"*Get-SQLTriggerDml*",".{0,1000}Get\-SQLTriggerDml.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","46278" +"*GetSyscallStub.nim*",".{0,1000}GetSyscallStub\.nim.{0,1000}","offensive_tool_keyword","Nimcrypt2",".NET PE & Raw Shellcode Packer/Loader Written in Nim","T1027 - T1202 - T1059.005 - T1105 - T1045","TA0005 - TA0011 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/icyguider/Nimcrypt2","1","1","N/A","N/A","N/A","8","771","124","2023-01-20T22:07:15Z","2022-02-23T15:43:16Z","46283" +"*Get-System.ps1*",".{0,1000}Get\-System\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-System.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46284" +"*Get-SystemDNSServer.ps1*",".{0,1000}Get\-SystemDNSServer\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-SystemDNSServer.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46285" +"*Get-SystemNamedPipe*",".{0,1000}Get\-SystemNamedPipe.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Get-System.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46286" +"*getTGT.py*",".{0,1000}getTGT\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","46291" +"*gettgtpkinit.py*",".{0,1000}gettgtpkinit\.py.{0,1000}","offensive_tool_keyword","PKINITtools","Tools for Kerberos PKINIT and relaying to AD CS","T1550.003 - T1557.002 - T1552.004 - T1212 - T1550","TA0009 - TA0008","N/A","N/A","Lateral Movement","https://github.com/dirkjanm/PKINITtools","1","1","N/A","N/A","N/A","8","737","82","2025-01-03T14:25:52Z","2021-07-27T19:06:09Z","46295" +"*Get-TimedScreenshot.ps1*",".{0,1000}Get\-TimedScreenshot\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","46297" +"*Get-TrustTicket.ps1*",".{0,1000}Get\-TrustTicket\.ps1.{0,1000}","offensive_tool_keyword","PowershellTools","Powershell tools used for Red Team / Pentesting","T1087.002 - T1069.001 - T1069.002 - T1598.002 - T1083 - T1558.003 - T1564.001 - T1112","TA0007 - TA0003 - TA0006 - TA0040 - TA0005 - TA0003","N/A","N/A","Exploitation tool","https://github.com/gustanini/PowershellTools","1","1","N/A","N/A","10","1","76","13","2024-01-08T10:33:20Z","2023-10-26T16:49:59Z","46300" +"*Get-UnattendSensitiveData*",".{0,1000}Get\-UnattendSensitiveData.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","46301" +"*Get-UniqueTokens*",".{0,1000}Get\-UniqueTokens.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46302" +"*get-unixUserPassword.py*",".{0,1000}get\-unixUserPassword\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","46303" +"*Get-USBKeystrokes*",".{0,1000}Get\-USBKeystrokes.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1152","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46305" +"*Get-UserBadPwdCount*",".{0,1000}Get\-UserBadPwdCount.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-SMBAutoBrute.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46306" +"*get-userPassword.py*",".{0,1000}get\-userPassword\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","46307" +"*Get-UserPrivileges*",".{0,1000}Get\-UserPrivileges.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","46308" +"*Get-UserPRTToken*",".{0,1000}Get\-UserPRTToken.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","46309" +"*GetUserSPNs.*",".{0,1000}GetUserSPNs\..{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","46310" +"*GetUserSPNs.ps1*",".{0,1000}GetUserSPNs\.ps1.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","46311" +"*GetUserSPNs.ps1*",".{0,1000}GetUserSPNs\.ps1.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","46312" +"*GetUserSPNs.vbs*",".{0,1000}GetUserSPNs\.vbs.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","1","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","46314" +"*Get-VaultCredential*",".{0,1000}Get\-VaultCredential.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46316" +"*Get-VaultCredential.ps1*",".{0,1000}Get\-VaultCredential\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1055","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46318" +"*Get-VaultCreds*",".{0,1000}Get\-VaultCreds.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","46319" +"*Get-VulnAutoRun*",".{0,1000}Get\-VulnAutoRun.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46322" +"*Get-VulnSchTask*",".{0,1000}Get\-VulnSchTask.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46323" +"*Get-WebCredentials*",".{0,1000}Get\-WebCredentials.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","46324" +"*Get-WebCredentials.ps1*",".{0,1000}Get\-WebCredentials\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","46325" +"*GetWebDAVStatus.csproj*",".{0,1000}GetWebDAVStatus\.csproj.{0,1000}","offensive_tool_keyword","cobaltstrike","Determine if the WebClient Service (WebDAV) is running on a remote system","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/G0ldenGunSec/GetWebDAVStatus","1","1","N/A","N/A","10","10","133","27","2024-03-09T22:49:45Z","2021-09-29T17:31:21Z","46326" +"*GetWebDAVStatus.sln*",".{0,1000}GetWebDAVStatus\.sln.{0,1000}","offensive_tool_keyword","cobaltstrike","Determine if the WebClient Service (WebDAV) is running on a remote system","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/G0ldenGunSec/GetWebDAVStatus","1","1","N/A","N/A","10","10","133","27","2024-03-09T22:49:45Z","2021-09-29T17:31:21Z","46327" +"*GetWebDAVStatus_DotNet*",".{0,1000}GetWebDAVStatus_DotNet.{0,1000}","offensive_tool_keyword","cobaltstrike","Determine if the WebClient Service (WebDAV) is running on a remote system","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/G0ldenGunSec/GetWebDAVStatus","1","1","N/A","N/A","10","10","133","27","2024-03-09T22:49:45Z","2021-09-29T17:31:21Z","46328" +"*GetWebDAVStatus_x64.o*",".{0,1000}GetWebDAVStatus_x64\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Determine if the WebClient Service (WebDAV) is running on a remote system","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/G0ldenGunSec/GetWebDAVStatus","1","1","N/A","N/A","10","10","133","27","2024-03-09T22:49:45Z","2021-09-29T17:31:21Z","46329" +"*GetWhoamiCommand*",".{0,1000}GetWhoamiCommand.{0,1000}","offensive_tool_keyword","C2 related tools","PowerShell rebuilt in C# for Red Teaming purposes","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","46330" +"*GetWindowsCredentials.exe*",".{0,1000}GetWindowsCredentials\.exe.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","46332" +"*Get-Wlan-Keys*",".{0,1000}Get\-Wlan\-Keys.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","46334" +"*Get-WLAN-Keys*",".{0,1000}Get\-WLAN\-Keys.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","46335" +"*Get-WLAN-Keys.ps1*",".{0,1000}Get\-WLAN\-Keys\.ps1.{0,1000}","offensive_tool_keyword","chimera","Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.","T1027.002 - T1059.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/tokyoneon/Chimera/","1","1","N/A","N/A","10","10","1493","252","2021-11-09T12:39:59Z","2020-09-01T07:42:22Z","46336" +"*Get-WLAN-Keys.ps1*",".{0,1000}Get\-WLAN\-Keys\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","46337" +"*Get-Wlan-Keys.ps1*",".{0,1000}Get\-Wlan\-Keys\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","46338" +"*getwmiregcachedrdpconnection*",".{0,1000}getwmiregcachedrdpconnection.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","46345" +"*Get-WMIRegCachedRDPConnection*",".{0,1000}Get\-WMIRegCachedRDPConnection.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","46346" +"*Get-WMIRegCachedRDPConnection*",".{0,1000}Get\-WMIRegCachedRDPConnection.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","powerview.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46347" +"*get-wmiregcachedrdpconnection*",".{0,1000}get\-wmiregcachedrdpconnection.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","46348" +"*getwmireglastloggedon*",".{0,1000}getwmireglastloggedon.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","46350" +"*Get-WMIRegLastLoggedOn*",".{0,1000}Get\-WMIRegLastLoggedOn.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","46351" +"*Get-WMIRegLastLoggedOn*",".{0,1000}Get\-WMIRegLastLoggedOn.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","powerview.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46352" +"*get-wmireglastloggedon*",".{0,1000}get\-wmireglastloggedon.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","46353" +"*Get-WMIRegMountedDrive*",".{0,1000}Get\-WMIRegMountedDrive.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","powerview.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","46355" +"*get-wmiregmounteddrive*",".{0,1000}get\-wmiregmounteddrive.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","46356" +"*Get-WMIRegProxy*",".{0,1000}Get\-WMIRegProxy.{0,1000}","offensive_tool_keyword","adPEAS","adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others","T1016 - T1087.002 - T1482 - T1207 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/61106960/adPEAS","1","1","N/A","N/A","8","10","1095","132","2025-04-01T16:16:15Z","2020-12-23T08:10:19Z","46358" +"*gexplorer.exe*",".{0,1000}gexplorer\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","A protective and Low Level Shellcode Loader that defeats modern EDR systems.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/cribdragg3r/Alaris","1","1","N/A","N/A","10","10","903","142","2024-03-20T15:50:57Z","2020-02-22T15:42:37Z","46360" +"*ghauri-main.zip*",".{0,1000}ghauri\-main\.zip.{0,1000}","offensive_tool_keyword","ghauri","A cross-platform python based advanced sql injections detection & exploitation tool","T1190 - T1210 - T1095","TA0001 - TA0002 - TA0009","N/A","N/A","Vulnerability Scanner","https://github.com/r0oth3x49/ghauri","1","1","N/A","N/A","8","10","3483","361","2025-02-25T19:09:50Z","2022-10-01T11:21:50Z","46377" +"*ghcr.io/picosh/pico/*",".{0,1000}ghcr\.io\/picosh\/pico\/.{0,1000}","offensive_tool_keyword","pico","hacker labs - open source and managed web services leveraging SSH","T1021.005 - T1078 - T1105 - T1109 - T1197 - T1213","TA0005 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/picosh/pico","1","1","N/A","N/A","10","10","1129","36","2025-04-22T17:33:17Z","2022-08-24T03:14:52Z","46381" +"*ghost01.hwtxt*",".{0,1000}ghost01\.hwtxt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","46385" +"*GhostDriver-main.zip*",".{0,1000}GhostDriver\-main\.zip.{0,1000}","offensive_tool_keyword","GhostDriver","GhostDriver is a Rust-built AV killer tool using BYOVD","T1562.001 - T1211 - T1055.001","TA0005 - TA0002","N/A","Black Basta","Defense Evasion","https://github.com/BlackSnufkin/GhostDriver","1","1","N/A","N/A","9","3","270","38","2023-12-12T13:52:32Z","2023-12-02T23:56:13Z","46387" +"*GhostMapper-main.*",".{0,1000}GhostMapper\-main\..{0,1000}","offensive_tool_keyword","GhostMapper","GhostMapper involves modifying Windows system ""dump_"" prefix drivers to exploit crash handling mechanisms for malicious purposes.","T1014 - T1070.004 - T1055.011","TA0003 - TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/Oliver-1-1/GhostMapper","1","1","N/A","N/A","8","3","279","62","2025-04-12T19:17:46Z","2023-10-31T11:26:33Z","46391" +"*GhostPack/ForgeCert*",".{0,1000}GhostPack\/ForgeCert.{0,1000}","offensive_tool_keyword","ForgeCert","ForgeCert uses the BouncyCastle C# API and a stolen Certificate Authority (CA) certificate + private key to forge certificates for arbitrary users capable of authentication to Active Directory.","T1553.002 - T1136.003 - T1059.001 - T1649","TA0006 - TA0002","N/A","N/A","Defense Evasion","https://github.com/GhostPack/ForgeCert","1","1","N/A","N/A","10","7","671","109","2024-08-17T16:40:07Z","2021-06-09T22:04:18Z","46393" +"*GhostPack/KeeThief*",".{0,1000}GhostPack\/KeeThief.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","46394" +"*GhostPack/Koh*",".{0,1000}GhostPack\/Koh.{0,1000}","offensive_tool_keyword","cobaltstrike","Koh is a C# and Beacon Object File (BOF) toolset that allows for the capture of user credential material via purposeful token/logon session leakage.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/GhostPack/Koh","1","1","N/A","N/A","10","10","492","66","2022-07-13T23:41:38Z","2022-07-07T17:14:09Z","46395" +"*GhostPack/Lockless*",".{0,1000}GhostPack\/Lockless.{0,1000}","offensive_tool_keyword","Lockless","Lockless allows for the copying of locked files.","T1074 - T1020 - T1055","TA0009 - TA0010 - TA0005","N/A","N/A","Defense Evasion","https://github.com/GhostPack/Lockless","1","1","N/A","N/A","8","3","245","57","2021-04-30T17:51:41Z","2020-03-28T20:57:25Z","46396" +"*GhostPack/Rubeus*",".{0,1000}GhostPack\/Rubeus.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","46397" +"*GhostPack/Rubeus*",".{0,1000}GhostPack\/Rubeus.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","46398" +"*GhostPack/SafetyKatz*",".{0,1000}GhostPack\/SafetyKatz.{0,1000}","offensive_tool_keyword","SafetyKatz","SafetyKatz is a combination of slightly modified version of @gentilkiwis Mimikatz project and @subtees .NET PE Loader. First. the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to C:\Windows\Temp\debug.bin. Then @subtees PELoader is used to load a customized version of Mimikatz that runs sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file. removing the file after execution is complete","T1003 - T1055 - T1059 - T1574","TA0002 - TA0003 - TA0008","N/A","APT39","Credential Access","https://github.com/GhostPack/SafetyKatz","1","1","N/A","N/A","10","10","1257","247","2019-10-01T16:47:21Z","2018-07-24T17:44:15Z","46399" +"*GhostPack/Seatbelt*",".{0,1000}GhostPack\/Seatbelt.{0,1000}","offensive_tool_keyword","seatbelt","Seatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many others","T1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518","TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011","N/A","Dispossessor","Persistence","https://github.com/GhostPack/Seatbelt","1","1","N/A","N/A","10","10","4047","722","2025-01-10T20:12:49Z","2018-07-24T17:38:51Z","46400" +"*GhostPack/SharpDPAPI*",".{0,1000}GhostPack\/SharpDPAPI.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","46401" +"*GhostPack/SharpDump*",".{0,1000}GhostPack\/SharpDump.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","1","N/A","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","46402" +"*GhostPack/SharpUp*",".{0,1000}GhostPack\/SharpUp.{0,1000}","offensive_tool_keyword","SharpUp","SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.","T1003 - T1082 - T1057 - T1069 - T1083","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/GhostPack/SharpUp","1","1","N/A","N/A","N/A","10","1344","253","2024-02-14T16:38:26Z","2018-07-24T17:39:33Z","46403" +"*Ghostpack-CompiledBinaries*",".{0,1000}Ghostpack\-CompiledBinaries.{0,1000}","offensive_tool_keyword","Ghostpack-CompiledBinaries","Compiled Binaries for Ghostpack","T1140 - T1559.002 - T1547.002 - T1055 - T1036.004","TA0005 - TA0002 - TA0040 - TA0036","N/A","N/A","Exploitation tool","https://github.com/r3motecontrol/Ghostpack-CompiledBinaries","1","1","N/A","N/A","N/A","10","1313","237","2024-10-24T21:58:54Z","2018-07-25T23:38:15Z","46404" +"*GhostTask.exe*",".{0,1000}GhostTask\.exe.{0,1000}","offensive_tool_keyword","GhostTask","Creates scheduled tasks with a restrictive security descriptor - making them invisible to all users. - Establishes scheduled tasks directly via the registry - bypassing the generation of standard Windows event logs. - Provides support to modify existing scheduled tasks without generating Windows event logs. - Supports remote scheduled task creation (by using specially crafted Silver Ticket). - Supports to run in C2 with in-memory PE execution module (e.g. - BruteRatel's memexec)","T1053.005 - T1112 - T1078","TA0003 - TA0005 - TA0007","N/A","N/A","Defense Evasion","https://github.com/netero1010/GhostTask","1","1","N/A","N/A","10","6","549","63","2025-01-02T15:26:01Z","2023-10-23T13:05:00Z","46407" +"*GhostWebShell.cs*",".{0,1000}GhostWebShell\.cs.{0,1000}","offensive_tool_keyword","ysoserial.net","Deserialization payload generator for a variety of .NET formatters","T1059.007 - T1027.002 - T1059.001","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/pwntester/ysoserial.net","1","1","N/A","N/A","10","10","3385","493","2024-12-23T20:59:47Z","2017-09-18T17:48:08Z","46409" +"*gianlucaborello/libprocesshider*",".{0,1000}gianlucaborello\/libprocesshider.{0,1000}","offensive_tool_keyword","libprocesshider","Hide a process under Linux using the ld preloader","T1055 - T1564 - T1620","TA0005 ","N/A","Sandworm","Defense Evasion","https://github.com/gianlucaborello/libprocesshider","1","1","#linux","N/A","9","10","1061","320","2019-08-02T14:28:28Z","2014-08-16T01:09:30Z","46410" +"*gimmecredz*",".{0,1000}gimmecredz.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","46412" +"*ginuerzh/gost*",".{0,1000}ginuerzh\/gost.{0,1000}","offensive_tool_keyword","gost","Ransomware operators actively use Gost capabilities () in order to communicate with their remote server. using the command below. To hide the software in plain sight. they rename it to `System.exe` or `update.exe`.","T1568 - T1001 - T1027 - T1041","TA0002 - TA0011","N/A","Dispossessor - EMBER BEAR","Data Exfiltration","https://github.com/ginuerzh/gost","1","1","N/A","N/A","N/A","10","16646","2539","2024-12-31T13:08:51Z","2015-03-20T09:45:08Z","46414" +"*Gioyik/getExploit*",".{0,1000}Gioyik\/getExploit.{0,1000}","offensive_tool_keyword","getExploit","Python script to explore exploits from exploit-db.com. Exist a similar script in Kali Linux. but in difference this python script will have provide more flexibility at search and download time.","T1587 - T1068 - T1211 - T1210 - T1588","TA0006 - TA0002 - TA0009 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/Gioyik/getExploit","1","1","#linux","N/A","N/A","1","43","27","2015-06-26T16:38:55Z","2015-01-03T03:26:21Z","46415" +"*gist.github.com/byt3bl33d3r/19a48fff8fdc34cc1dd1f1d2807e1b7f*",".{0,1000}gist\.github\.com\/byt3bl33d3r\/19a48fff8fdc34cc1dd1f1d2807e1b7f.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","46416" +"*github*/COMHunter/*",".{0,1000}github.{0,1000}\/COMHunter\/.{0,1000}","offensive_tool_keyword","COMHunter","Enumerates COM servers set in LocalServer32 and InProc32 keys on a system using WMI","T1087.002 - T1012 - T1057","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/matterpreter/OffensiveCSharp/tree/master/COMHunter","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","46421" +"*github*/dropper.git*",".{0,1000}github.{0,1000}\/dropper\.git.{0,1000}","offensive_tool_keyword","dropper","Generates Malicious Office Macro Enabled Dropper for DLL SideLoading and Embed it in Lnk file to bypass MOTW","T1059 - T1574.002 - T1218 - T1559.003","TA0002 - TA0005 - TA0009","N/A","N/A","Resource Development","https://github.com/SaadAhla/dropper","1","1","N/A","N/A","10","","N/A","","","","46423" +"*github*/MoveKit.git*",".{0,1000}github.{0,1000}\/MoveKit\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike kit for Lateral Movement","T1021.002 - T1021.006 - T1021.004","TA0008 - TA0002","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Lateral Movement","https://github.com/0xthirteen/MoveKit","1","1","N/A","N/A","10","7","666","109","2020-02-21T20:23:45Z","2020-01-24T22:19:16Z","46424" +"*github*/Mr-xn/*",".{0,1000}github.{0,1000}\/Mr\-xn\/.{0,1000}","offensive_tool_keyword","spring-core-rce","github user infosec hosting exploitation tools","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/Mr-xn/spring-core-rce","1","1","N/A","N/A","N/A","1","50","18","2022-04-01T15:34:03Z","2022-03-30T14:35:00Z","46425" +"*github*/padre.git*",".{0,1000}github.{0,1000}\/padre\.git.{0,1000}","offensive_tool_keyword","padre","padre?is an advanced exploiter for Padding Oracle attacks against CBC mode encryption","T1203 - T1059.003 - T1027.002","TA0005 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/glebarez/padre","1","1","N/A","N/A","8","3","253","24","2024-05-13T14:28:25Z","2019-12-30T13:52:03Z","46426" +"*github.com/*Reaper.exe*",".{0,1000}github\.com\/.{0,1000}Reaper\.exe.{0,1000}","offensive_tool_keyword","reaper","Reaper is a proof-of-concept designed to exploit BYOVD (Bring Your Own Vulnerable Driver) driver vulnerability. This malicious technique involves inserting a legitimate - vulnerable driver into a target system - which allows attackers to exploit the driver to perform malicious actions.","T1547.009 - T1215 - T1129 - T1548.002","TA0002 - TA0003 - TA0040 - TA0005","N/A","N/A","Defense Evasion","https://github.com/MrEmpy/Reaper","1","1","N/A","N/A","10","2","158","34","2024-12-07T01:52:58Z","2023-09-21T02:09:48Z","46431" +"*github.com/bishopfox/*",".{0,1000}github\.com\/bishopfox\/.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","46432" +"*github.com/g3tsyst3m*",".{0,1000}github\.com\/g3tsyst3m.{0,1000}","offensive_tool_keyword","elevationstation","github user hosting multiple exploitation tools","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","46433" +"*github.com/k8gege*",".{0,1000}github\.com\/k8gege.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","46434" +"*github.com/MythicAgents/*",".{0,1000}github\.com\/MythicAgents\/.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","46435" +"*github.com/postrequest/link*",".{0,1000}github\.com\/postrequest\/link.{0,1000}","offensive_tool_keyword","link","link is a command and control framework written in rust","T1071 - T1094 - T1132 - T1008 - T1024","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/postrequest/link","1","1","N/A","N/A","10","10","575","90","2021-08-18T11:53:55Z","2021-02-02T11:15:43Z","46436" +"*github.com/rasta-mouse/*",".{0,1000}github\.com\/rasta\-mouse\/.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","46437" +"*github.com/rossja/TinyNuke*",".{0,1000}github\.com\/rossja\/TinyNuke.{0,1000}","offensive_tool_keyword","HVNC","Standalone HVNC Client & Server Coded in C++ (Modified Tinynuke)","T1021.005 - T1071 - T1563.002 - T1219","TA0001 - TA0002 - TA0008","N/A","N/A","RMM","https://github.com/Meltedd/HVNC","1","1","N/A","N/A","10","5","445","133","2025-03-27T21:20:10Z","2021-09-03T17:34:44Z","46438" +"*github.com/SafeJKA/Kidlogger*",".{0,1000}github\.com\/SafeJKA\/Kidlogger.{0,1000}","offensive_tool_keyword","kiglogger","malware parental control software - keylogger","T1056.001 - T1113 - T1056.004","TA0006 - TA0009","N/A","N/A","Collection","https://kidlogger.net/download.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","46439" +"*github.com/SpiderLabs/*",".{0,1000}github\.com\/SpiderLabs\/.{0,1000}","offensive_tool_keyword","cobaltstrike","SharpCompile is an aggressor script for Cobalt Strike which allows you to compile and execute C# in realtime. This is a more slick approach than manually compiling an .NET assembly and loading it into Cobalt Strike. The project aims to make it easier to move away from adhoc PowerShell execution instead creating a temporary assembly and executing ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/SpiderLabs/SharpCompile","1","1","N/A","N/A","10","10","291","58","2020-08-07T12:49:36Z","2018-11-01T17:18:52Z","46440" +"*github.io/weakpass/generator/*",".{0,1000}github\.io\/weakpass\/generator\/.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","46442" +"*GithubC2-main*",".{0,1000}GithubC2\-main.{0,1000}","offensive_tool_keyword","GithubC2","Github as C2","T1095 - T1071.001","TA0011","N/A","N/A","C2","https://github.com/TheD1rkMtr/GithubC2","1","1","N/A","N/A","10","10","136","37","2023-08-02T02:26:05Z","2023-02-15T00:50:59Z","46443" +"*gitjdm/dumper2020*",".{0,1000}gitjdm\/dumper2020.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","1","N/A","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","46444" +"*gitleaks*",".{0,1000}gitleaks.{0,1000}","offensive_tool_keyword","Gitleaks","Gitleaks is a SAST tool for detecting hardcoded secrets like passwords. api keys. and tokens in git repos. Gitleaks aims to be the easy-to-use. all-in-one solution for finding secrets. past or present. in your code.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/zricethezav/gitleaks","1","1","N/A","N/A","N/A","10","19587","1590","2025-04-16T21:10:47Z","2018-01-27T18:19:31Z","46447" +"*Git-Scanner*",".{0,1000}Git\-Scanner.{0,1000}","offensive_tool_keyword","Git-Scanner","A tool for bug hunting or pentesting for targeting websites that have open .git repositories available in public","T1213 - T1596 - T1190 - T1590","TA0007 - TA0009 - TA0001","N/A","N/A","Reconnaissance","https://github.com/HightechSec/git-scanner","1","1","N/A","N/A","N/A","4","352","91","2020-06-23T05:44:26Z","2020-05-17T14:30:19Z","46448" +"*GIUDA-main.zip*",".{0,1000}GIUDA\-main\.zip.{0,1000}","offensive_tool_keyword","GIUDA","Ask a TGS on behalf of another user without password","T1558.003 - T1059.003","TA0006 - TA0002","N/A","N/A","Exploitation tool","https://github.com/foxlox/GIUDA","1","1","N/A","N/A","9","5","469","68","2025-03-30T20:42:43Z","2023-07-19T15:37:07Z","46450" +"*give_dcsync.py*",".{0,1000}give_dcsync\.py.{0,1000}","offensive_tool_keyword","acltoolkit","acltoolkit is an ACL abuse swiss-army knife. It implements multiple ACL abuses","T1222.001 - T1222.002 - T1046","TA0007 - TA0040","N/A","N/A","Exploitation tool","https://github.com/zblurx/acltoolkit","1","1","N/A","N/A","N/A","2","120","12","2023-02-03T10:27:45Z","2022-01-12T22:45:49Z","46451" +"*glassfish_war_upload_xsrf*",".{0,1000}glassfish_war_upload_xsrf.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","46454" +"*glebarez/padre*",".{0,1000}glebarez\/padre.{0,1000}","offensive_tool_keyword","padre","padre?is an advanced exploiter for Padding Oracle attacks against CBC mode encryption","T1203 - T1059.003 - T1027.002","TA0005 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/glebarez/padre","1","1","N/A","N/A","8","3","253","24","2024-05-13T14:28:25Z","2019-12-30T13:52:03Z","46456" +"*glit-i686-pc-windows-msvc*",".{0,1000}glit\-i686\-pc\-windows\-msvc.{0,1000}","offensive_tool_keyword","glit","Retrieve all mails of users related to a git repository a git user or a git organization","T1583 - T1059.001 - T1059.003","TA0002 - TA0003","N/A","N/A","Reconnaissance","https://github.com/shadawck/glit","1","1","N/A","N/A","8","1","49","7","2024-05-01T15:07:51Z","2022-11-14T11:25:10Z","46463" +"*glit-main.zip*",".{0,1000}glit\-main\.zip.{0,1000}","offensive_tool_keyword","glit","Retrieve all mails of users related to a git repository a git user or a git organization","T1583 - T1059.001 - T1059.003","TA0002 - TA0003","N/A","N/A","Reconnaissance","https://github.com/shadawck/glit","1","1","N/A","N/A","8","1","49","7","2024-05-01T15:07:51Z","2022-11-14T11:25:10Z","46464" +"*glit-x86_64-apple-darwin*",".{0,1000}glit\-x86_64\-apple\-darwin.{0,1000}","offensive_tool_keyword","glit","Retrieve all mails of users related to a git repository a git user or a git organization","T1583 - T1059.001 - T1059.003","TA0002 - TA0003","N/A","N/A","Reconnaissance","https://github.com/shadawck/glit","1","1","#linux","N/A","8","1","49","7","2024-05-01T15:07:51Z","2022-11-14T11:25:10Z","46465" +"*glit-x86_64-pc-windows-msvc*",".{0,1000}glit\-x86_64\-pc\-windows\-msvc.{0,1000}","offensive_tool_keyword","glit","Retrieve all mails of users related to a git repository a git user or a git organization","T1583 - T1059.001 - T1059.003","TA0002 - TA0003","N/A","N/A","Reconnaissance","https://github.com/shadawck/glit","1","1","N/A","N/A","8","1","49","7","2024-05-01T15:07:51Z","2022-11-14T11:25:10Z","46466" +"*glit-x86_64-unknown-linux-gnu*",".{0,1000}glit\-x86_64\-unknown\-linux\-gnu.{0,1000}","offensive_tool_keyword","glit","Retrieve all mails of users related to a git repository a git user or a git organization","T1583 - T1059.001 - T1059.003","TA0002 - TA0003","N/A","N/A","Reconnaissance","https://github.com/shadawck/glit","1","1","#linux","N/A","8","1","49","7","2024-05-01T15:07:51Z","2022-11-14T11:25:10Z","46467" +"*globaleaks/Tor2web*",".{0,1000}globaleaks\/Tor2web.{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","46470" +"*GlobalUnProtect.exe*",".{0,1000}GlobalUnProtect\.exe.{0,1000}","offensive_tool_keyword","GlobalUnProtect","Decrypt GlobalProtect configuration and cookie files.","T1552 - T1003 - T1555","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rotarydrone/GlobalUnProtect","1","1","N/A","N/A","9","2","147","19","2024-09-10T20:19:24Z","2024-09-04T15:31:52Z","46471" +"*gloxec/CrossC2*",".{0,1000}gloxec\/CrossC2.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","46472" +"*gloxec/CrossC2*",".{0,1000}gloxec\/CrossC2.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","46473" +"*GmailC2.csproj*",".{0,1000}GmailC2\.csproj.{0,1000}","offensive_tool_keyword","SharpGmailC2","Gmail will act as Server and implant will exfiltrate data via smtp and will read commands from C2 (Gmail) via imap protocol","T1071 - T1071.004 - T1568 - T1568.002 - T1114 - T1114.001","TA0011 - TA0040 - TA0001","N/A","N/A","C2","https://github.com/reveng007/SharpGmailC2","1","1","N/A","N/A","10","10","260","47","2022-12-27T01:45:46Z","2022-11-10T06:48:15Z","46475" +"*gmsa_dump*",".{0,1000}gmsa_dump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","46476" +"*gMSADumper.py*",".{0,1000}gMSADumper\.py.{0,1000}","offensive_tool_keyword","gMSADumper","Lists who can read any gMSA password blobs and parses them if the current user has access.","T1552.001 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/micahvandeusen/gMSADumper","1","1","N/A","N/A","N/A","3","274","51","2024-02-12T02:15:32Z","2021-04-10T00:15:24Z","46478" +"*GMSAPasswordReader.exe*",".{0,1000}GMSAPasswordReader\.exe.{0,1000}","offensive_tool_keyword","GMSAPasswordReader","Reads the password blob from a GMSA account using LDAP and parses the values into hashes for re-use.","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/rvazarkar/GMSAPasswordReader","1","1","N/A","N/A","7","3","219","34","2023-02-17T14:37:40Z","2020-01-19T19:06:20Z","46480" +"*GMSAPasswordReader.exe*",".{0,1000}GMSAPasswordReader\.exe.{0,1000}","offensive_tool_keyword","GMSAPasswordReader","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","GMSAPasswordReader","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","46481" +"*GMSAPasswordReader.exe*",".{0,1000}GMSAPasswordReader\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","GMSAPasswordReader","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","46482" +"*GMSAPasswordReader-master*",".{0,1000}GMSAPasswordReader\-master.{0,1000}","offensive_tool_keyword","GMSAPasswordReader","Reads the password blob from a GMSA account using LDAP and parses the values into hashes for re-use.","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/rvazarkar/GMSAPasswordReader","1","1","N/A","N/A","7","3","219","34","2023-02-17T14:37:40Z","2020-01-19T19:06:20Z","46483" +"*GMShellcode*",".{0,1000}GMShellcode.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","46484" +"*GMShellcode.*",".{0,1000}GMShellcode\..{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","46485" +"*go.flipt.io/reverst/*",".{0,1000}go\.flipt\.io\/reverst\/.{0,1000}","offensive_tool_keyword","reverst","Reverse Tunnels in Go over HTTP/3 and QUIC","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","N/A","C2","https://github.com/flipt-io/reverst","1","1","N/A","N/A","10","10","953","39","2025-04-16T22:33:32Z","2024-04-03T13:32:11Z","46502" +"*go.flipt.io/reverst/*",".{0,1000}go\.flipt\.io\/reverst\/.{0,1000}","offensive_tool_keyword","reverst","Reverse Tunnels in Go over HTTP/3 and QUIC","T1572 - T1071.001 - T1105","TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/flipt-io/reverst","1","1","N/A","N/A","10","10","953","39","2025-04-16T22:33:32Z","2024-04-03T13:32:11Z","46503" +"*go_shellcode_encode.py*",".{0,1000}go_shellcode_encode\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","bypassAV cobaltstrike shellcode","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/jas502n/bypassAV-1","1","1","N/A","N/A","10","10","17","9","2021-03-04T01:51:14Z","2021-03-03T11:33:38Z","46504" +"*GoAWSConsoleSpray.exe*",".{0,1000}GoAWSConsoleSpray\.exe.{0,1000}","offensive_tool_keyword","GoAWSConsoleSpray","brute-force AWS IAM Console credentials to discover valid logins for user accounts","T1078 - T1110 - T1187 - T1110.001","TA0006 - TA0007 - TA0003 - TA0001","N/A","N/A","Credential Access","https://github.com/WhiteOakSecurity/GoAWSConsoleSpray","1","1","N/A","N/A","9","1","29","5","2022-06-15T18:16:21Z","2022-06-15T18:11:39Z","46506" +"*GoAWSConsoleSpray-master.zip*",".{0,1000}GoAWSConsoleSpray\-master\.zip.{0,1000}","offensive_tool_keyword","GoAWSConsoleSpray","brute-force AWS IAM Console credentials to discover valid logins for user accounts","T1078 - T1110 - T1187 - T1110.001","TA0006 - TA0007 - TA0003 - TA0001","N/A","N/A","Credential Access","https://github.com/WhiteOakSecurity/GoAWSConsoleSpray","1","1","N/A","N/A","9","1","29","5","2022-06-15T18:16:21Z","2022-06-15T18:11:39Z","46508" +"*gobuster*",".{0,1000}gobuster.{0,1000}","offensive_tool_keyword","gobuster","Gobuster is a tool used to brute-force","T1046 - T1590.002 - T1590.005","TA0007 - TA0043 - TA0006","N/A","Volatile Cedar","Exploitation tool","https://github.com/OJ/gobuster","1","1","#linux","N/A","N/A","10","11434","1338","2025-04-17T06:41:43Z","2014-11-14T13:18:35Z","46519" +"*gobuster_*.tar.gz*",".{0,1000}gobuster_.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","gobuster","Directory/File DNS and VHost busting tool written in Go","T1046 - T1590.002 - T1590.005","TA0007 - TA0043 - TA0006","N/A","Volatile Cedar","Reconnaissance","https://github.com/OJ/gobuster","1","1","#linux","network exploitation tool","N/A","10","11434","1338","2025-04-17T06:41:43Z","2014-11-14T13:18:35Z","46520" +"*gobuster_*.zip*",".{0,1000}gobuster_.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","gobuster","Directory/File DNS and VHost busting tool written in Go","T1046 - T1590.002 - T1590.005","TA0007 - TA0043 - TA0006","N/A","Volatile Cedar","Reconnaissance","https://github.com/OJ/gobuster","1","1","#linux","network exploitation tool","N/A","10","11434","1338","2025-04-17T06:41:43Z","2014-11-14T13:18:35Z","46521" +"*gobusterfuzz*",".{0,1000}gobusterfuzz.{0,1000}","offensive_tool_keyword","gobuster","Directory/File DNS and VHost busting tool written in Go","T1046 - T1590.002 - T1590.005","TA0007 - TA0043 - TA0006","N/A","Volatile Cedar","Reconnaissance","https://github.com/OJ/gobuster","1","1","#linux","network exploitation tool","N/A","10","11434","1338","2025-04-17T06:41:43Z","2014-11-14T13:18:35Z","46522" +"*gobustertftp*",".{0,1000}gobustertftp.{0,1000}","offensive_tool_keyword","gobuster","Directory/File DNS and VHost busting tool written in Go","T1046 - T1590.002 - T1590.005","TA0007 - TA0043 - TA0006","N/A","Volatile Cedar","Reconnaissance","https://github.com/OJ/gobuster","1","1","#linux","network exploitation tool","N/A","10","11434","1338","2025-04-17T06:41:43Z","2014-11-14T13:18:35Z","46523" +"*gocrack_v*_darwin_x64_hashcat_v3_6_0.zip*",".{0,1000}gocrack_v.{0,1000}_darwin_x64_hashcat_v3_6_0\.zip.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","1","#linux","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","46525" +"*gocrack_v*_linux_x64_hashcat_v3_6_0.zip*",".{0,1000}gocrack_v.{0,1000}_linux_x64_hashcat_v3_6_0\.zip.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","1","#linux","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","46526" +"*GodFault.exe*",".{0,1000}GodFault\.exe.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","46527" +"*godoh-darwin64*",".{0,1000}godoh\-darwin64.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071 - T1001 - T1008 - T1070 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","#linux","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","46542" +"*godoh-darwin64*",".{0,1000}godoh\-darwin64.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071.004 - T1568.002 - T1105 ","TA0011 - TA0005","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","#linux","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","46543" +"*godoh-linux64*",".{0,1000}godoh\-linux64.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071 - T1001 - T1008 - T1070 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","#linux","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","46544" +"*godoh-linux64*",".{0,1000}godoh\-linux64.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071.004 - T1568.002 - T1105 ","TA0011 - TA0005","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","#linux","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","46545" +"*godoh-windows32.*",".{0,1000}godoh\-windows32\..{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071 - T1001 - T1008 - T1070 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","N/A","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","46546" +"*godoh-windows32.exe*",".{0,1000}godoh\-windows32\.exe.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071.004 - T1568.002 - T1105 ","TA0011 - TA0005","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","N/A","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","46547" +"*godoh-windows64.*",".{0,1000}godoh\-windows64\..{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071 - T1001 - T1008 - T1070 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","N/A","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","46548" +"*godoh-windows64.exe*",".{0,1000}godoh\-windows64\.exe.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071.004 - T1568.002 - T1105 ","TA0011 - TA0005","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","N/A","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","46549" +"*go-donut/*.exe*",".{0,1000}go\-donut\/.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","donut","Donut is a position-independent code that enables in-memory execution of VBScript. JScript. EXE. DLL files and dotNET assemblies. A module created by Donut can either be staged from a HTTP server or embedded directly in the loader itself","T1071.001 - T1059 - T1059.001 - T1059.005 - T1059.006 - T1059.007 - T1562.001 - T1070 - T1105 - T1106 - T1027 - T1027.002 - T1057 - T1055 - T1620","TA0011 - TA0002 - TA0005 - TA0008 - TA0004 - TA0007 - TA0003 - TA0006 - TA0010","N/A","Indrik Spider","Exploitation tool","https://github.com/TheWover/donut","1","1","N/A","N/A","N/A","10","3882","667","2024-10-23T12:19:13Z","2019-03-27T23:24:44Z","46550" +"*go-donut/*.go*",".{0,1000}go\-donut\/.{0,1000}\.go.{0,1000}","offensive_tool_keyword","donut","Donut is a position-independent code that enables in-memory execution of VBScript. JScript. EXE. DLL files and dotNET assemblies. A module created by Donut can either be staged from a HTTP server or embedded directly in the loader itself","T1071.001 - T1059 - T1059.001 - T1059.005 - T1059.006 - T1059.007 - T1562.001 - T1070 - T1105 - T1106 - T1027 - T1027.002 - T1057 - T1055 - T1620","TA0011 - TA0002 - TA0005 - TA0008 - TA0004 - TA0007 - TA0003 - TA0006 - TA0010","N/A","Indrik Spider","Exploitation tool","https://github.com/TheWover/donut","1","1","N/A","N/A","N/A","10","3882","667","2024-10-23T12:19:13Z","2019-03-27T23:24:44Z","46551" +"*GodPotato.exe*",".{0,1000}GodPotato\.exe.{0,1000}","offensive_tool_keyword","DeadPotato","DeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privileges","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","N/A","N/A","Privilege Escalation","https://github.com/lypd0/DeadPotato","1","1","N/A","N/A","10","4","382","45","2024-08-17T06:08:29Z","2024-07-31T01:08:30Z","46555" +"*godpotato.exe*",".{0,1000}godpotato\.exe.{0,1000}","offensive_tool_keyword","godpotato","GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","Ghost Ransomware","N/A","Privilege Escalation","https://github.com/BeichenDream/GodPotato","1","1","N/A","N/A","10","10","1938","236","2023-11-24T19:22:31Z","2022-12-23T14:37:00Z","46556" +"*GodPotato.git*",".{0,1000}GodPotato\.git.{0,1000}","offensive_tool_keyword","godpotato","GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","Ghost Ransomware","N/A","Privilege Escalation","https://github.com/BeichenDream/GodPotato","1","1","N/A","N/A","10","10","1938","236","2023-11-24T19:22:31Z","2022-12-23T14:37:00Z","46557" +"*GodPotato-Aggressor-Script*",".{0,1000}GodPotato\-Aggressor\-Script.{0,1000}","offensive_tool_keyword","godpotato","GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","N/A","N/A","Privilege Escalation","https://github.com/weaselsec/GodPotato-Aggressor-Script","1","1","N/A","N/A","9","1","85","9","2024-01-02T00:22:03Z","2024-01-02T00:02:54Z","46558" +"*GodPotato-master.zip*",".{0,1000}GodPotato\-master\.zip.{0,1000}","offensive_tool_keyword","godpotato","GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","Ghost Ransomware","N/A","Privilege Escalation","https://github.com/BeichenDream/GodPotato","1","1","N/A","N/A","10","10","1938","236","2023-11-24T19:22:31Z","2022-12-23T14:37:00Z","46562" +"*GodPotato-NET*.exe*",".{0,1000}GodPotato\-NET.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","godpotato","GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","Ghost Ransomware","N/A","Privilege Escalation","https://github.com/BeichenDream/GodPotato","1","1","N/A","N/A","10","10","1938","236","2023-11-24T19:22:31Z","2022-12-23T14:37:00Z","46563" +"*GodPotato-NET2.exe*",".{0,1000}GodPotato\-NET2\.exe.{0,1000}","offensive_tool_keyword","godpotato","GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","Ghost Ransomware","N/A","Privilege Escalation","https://github.com/BeichenDream/GodPotato","1","1","N/A","N/A","10","10","1938","236","2023-11-24T19:22:31Z","2022-12-23T14:37:00Z","46564" +"*GodPotato-NET35.exe*",".{0,1000}GodPotato\-NET35\.exe.{0,1000}","offensive_tool_keyword","godpotato","GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","Ghost Ransomware","N/A","Privilege Escalation","https://github.com/BeichenDream/GodPotato","1","1","N/A","N/A","10","10","1938","236","2023-11-24T19:22:31Z","2022-12-23T14:37:00Z","46565" +"*GodPotato-NET4.exe*",".{0,1000}GodPotato\-NET4\.exe.{0,1000}","offensive_tool_keyword","godpotato","GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","Ghost Ransomware","N/A","Privilege Escalation","https://github.com/BeichenDream/GodPotato","1","1","N/A","N/A","10","10","1938","236","2023-11-24T19:22:31Z","2022-12-23T14:37:00Z","46566" +"*GodPotato-NET4.exe*",".{0,1000}GodPotato\-NET4\.exe.{0,1000}","offensive_tool_keyword","godpotato","GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","N/A","N/A","Privilege Escalation","https://github.com/weaselsec/GodPotato-Aggressor-Script","1","1","N/A","N/A","10","1","85","9","2024-01-02T00:22:03Z","2024-01-02T00:02:54Z","46567" +"*GodPotatoUnmarshalTrigger.cs*",".{0,1000}GodPotatoUnmarshalTrigger\.cs.{0,1000}","offensive_tool_keyword","godpotato","GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","Ghost Ransomware","N/A","Privilege Escalation","https://github.com/BeichenDream/GodPotato","1","1","N/A","N/A","10","10","1938","236","2023-11-24T19:22:31Z","2022-12-23T14:37:00Z","46568" +"*Godzilla-1.0.jar*",".{0,1000}Godzilla\-1\.0\.jar.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","46569" +"*go-external-c2*",".{0,1000}go\-external\-c2.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","46570" +"*GoFetchAD/GoFetch*",".{0,1000}GoFetchAD\/GoFetch.{0,1000}","offensive_tool_keyword","GoFetch","GoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application.","T1078 - T1078.003 - T1021 - T1021.006 - T1076.001","TA0005 - TA0001 - TA0003","N/A","Dispossessor","Discovery","https://github.com/GoFetchAD/GoFetch","1","1","N/A","N/A","10","7","633","99","2017-06-20T14:15:10Z","2017-04-11T10:45:23Z","46571" +"*golang_c2-master*",".{0,1000}golang_c2\-master.{0,1000}","offensive_tool_keyword","golang_c2","C2 written in Go for red teams aka gorfice2k","T1071 - T1021 - T1090","TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/m00zh33/golang_c2","1","1","N/A","N/A","10","10","6","8","2019-03-18T00:46:41Z","2019-03-19T02:39:59Z","46575" +"*golden_ticket.py*",".{0,1000}golden_ticket\.py.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","46576" +"*golden_ticket.rb*",".{0,1000}golden_ticket\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","46577" +"*GoldenGMSA.exe*",".{0,1000}GoldenGMSA\.exe.{0,1000}","offensive_tool_keyword","GoldenGMSA","GolenGMSA tool for working with GMSA passwords","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/Semperis/GoldenGMSA","1","1","N/A","N/A","7","2","144","22","2024-04-11T07:51:57Z","2022-02-03T10:32:05Z","46579" +"*GoldenGMSA-main*",".{0,1000}GoldenGMSA\-main.{0,1000}","offensive_tool_keyword","GoldenGMSA","GolenGMSA tool for working with GMSA passwords","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/Semperis/GoldenGMSA","1","1","N/A","N/A","7","2","144","22","2024-04-11T07:51:57Z","2022-02-03T10:32:05Z","46580" +"*goliate/hidden-tear*",".{0,1000}goliate\/hidden\-tear.{0,1000}","offensive_tool_keyword","hidden-tear","open source ransomware - many variant in the wild","T1486 - T1059 - T1485 - T1489 - T1070 - T1488","TA0005 - TA0009 - TA0040 - TA0042","N/A","N/A","Ransomware","https://github.com/goliate/hidden-tear","1","1","N/A","N/A","10","8","765","394","2020-07-08T22:34:01Z","2015-08-19T09:06:51Z","46582" +"*goMatrixC2.go*",".{0,1000}goMatrixC2\.go.{0,1000}","offensive_tool_keyword","goMatrixC2","C2 leveraging Matrix/Element Messaging Platform as Backend to control Implants in goLang.","T1090 - T1027 - T1071","TA0011 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/n1k7l4i/goMatrixC2","1","1","N/A","N/A","10","","N/A","","","","46584" +"*goMatrixC2-main*",".{0,1000}goMatrixC2\-main.{0,1000}","offensive_tool_keyword","goMatrixC2","C2 leveraging Matrix/Element Messaging Platform as Backend to control Implants in goLang.","T1090 - T1027 - T1071","TA0011 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/n1k7l4i/goMatrixC2","1","1","N/A","N/A","10","","N/A","","","","46585" +"*google_drive_doubledrive.exe*",".{0,1000}google_drive_doubledrive\.exe.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","46588" +"*google_drive_ransomware.py*",".{0,1000}google_drive_ransomware\.py.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","46589" +"*googlechromeauto.serveirc.com*",".{0,1000}googlechromeauto\.serveirc\.com.{0,1000}","offensive_tool_keyword","Python-Rootkit","full undetectable python RAT which can bypass almost all antivirus and open a backdoor inside any windows machine which will establish a reverse https Metasploit connection to your listening machine","T1100 - T1027 - T1219 - T1560.001 - T1021.005","TA0005 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/0xIslamTaha/Python-Rootkit","1","1","N/A","N/A","10","10","606","145","2024-10-29T16:56:39Z","2016-06-09T10:49:54Z","46598" +"*goPassGen-master*",".{0,1000}goPassGen\-master.{0,1000}","offensive_tool_keyword","goPassGen","Easily-guessable Password Generator for Password Spray Attack","T1110 - T1110.003","TA0006 ","N/A","N/A","Exploitation tool","https://github.com/bigb0sss/goPassGen","1","1","N/A","N/A","8","1","21","1","2020-06-04T23:13:44Z","2020-06-04T22:33:37Z","46603" +"*gophish*phish.go*",".{0,1000}gophish.{0,1000}phish\.go.{0,1000}","offensive_tool_keyword","gophish","Gophish is an open-source phishing toolkit designed for businesses and penetration testers. It provides the ability to quickly and easily setup and execute phishing engagements and security awareness training.","T1566 - T1598","TA0008 - TA0009","N/A","Black Basta","Phishing","https://github.com/gophish/gophish","1","1","N/A","N/A","10","10","12483","2528","2024-09-23T04:24:43Z","2013-11-18T23:26:43Z","46605" +"*gophish.go*",".{0,1000}gophish\.go.{0,1000}","offensive_tool_keyword","gophish","Open-Source Phishing Toolkit","T1566-001 - T1566-002 - T1566-003 - T1056-001 - T1113 - T1567-001","TA0002 - TA0003","N/A","Black Basta","Phishing","https://github.com/gophish/gophish","1","1","N/A","N/A","10","10","12483","2528","2024-09-23T04:24:43Z","2013-11-18T23:26:43Z","46606" +"*gophish/gophish*",".{0,1000}gophish\/gophish.{0,1000}","offensive_tool_keyword","gophish","Gophish is an open-source phishing toolkit designed for businesses and penetration testers. It provides the ability to quickly and easily setup and execute phishing engagements and security awareness training.","T1566 - T1598","TA0008 - TA0009","N/A","Black Basta","Phishing","https://github.com/gophish/gophish","1","1","N/A","N/A","10","10","12483","2528","2024-09-23T04:24:43Z","2013-11-18T23:26:43Z","46607" +"*gophish-send-mail.py*",".{0,1000}gophish\-send\-mail\.py.{0,1000}","offensive_tool_keyword","phishing-HTML-linter","Phishing and Social-Engineering related scripts","T1566.001 - T1056.001","TA0040 - TA0001","N/A","N/A","Phishing","https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing","1","1","N/A","N/A","10","10","2689","527","2023-06-27T19:16:49Z","2018-02-02T21:24:03Z","46608" +"*GoRelayServer.dll*",".{0,1000}GoRelayServer\.dll.{0,1000}","offensive_tool_keyword","DavRelayUp","DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced","T1078 - T1078.004 - T1068","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/ShorSec/DavRelayUp","1","1","N/A","N/A","9","6","542","81","2023-06-05T09:17:06Z","2023-06-05T07:49:39Z","46609" +"*go-secdump.exe*",".{0,1000}go\-secdump\.exe.{0,1000}","offensive_tool_keyword","go-secdump","Tool to remotely dump secrets from the Windows registry","T1003.002 - T1012 - T1059.003","TA0006 - TA0003 - TA0002","N/A","N/A","Credential Access","https://github.com/jfjallid/go-secdump","1","1","N/A","N/A","10","5","457","51","2025-02-21T19:16:11Z","2023-02-23T17:02:50Z","46612" +"*go-secdump-main*",".{0,1000}go\-secdump\-main.{0,1000}","offensive_tool_keyword","go-secdump","Tool to remotely dump secrets from the Windows registry","T1003.002 - T1012 - T1059.003","TA0006 - TA0003 - TA0002","N/A","N/A","Credential Access","https://github.com/jfjallid/go-secdump","1","1","N/A","N/A","10","5","457","51","2025-02-21T19:16:11Z","2023-02-23T17:02:50Z","46613" +"*gosecretsdump/cmd*",".{0,1000}gosecretsdump\/cmd.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","46616" +"*gosecure/pyrdp*",".{0,1000}gosecure\/pyrdp.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","N/A","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","46618" +"*GoSecure/pyrdp*",".{0,1000}GoSecure\/pyrdp.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","N/A","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","46619" +"*go-shellcode.py*",".{0,1000}go\-shellcode\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","bypassAV cobaltstrike shellcode","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/jas502n/bypassAV-1","1","1","N/A","N/A","10","10","17","9","2021-03-04T01:51:14Z","2021-03-03T11:33:38Z","46620" +"*goShellCodeByPassVT*",".{0,1000}goShellCodeByPassVT.{0,1000}","offensive_tool_keyword","cobaltstrike","generate shellcode","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/fcre1938/goShellCodeByPassVT","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","46621" +"*Gotato-main.*",".{0,1000}Gotato\-main\..{0,1000}","offensive_tool_keyword","Gotato","Generic impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported.","T1003.003 - T1056.002 - T1550.001 - T1090","TA0005 - TA0004 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/iammaguire/Gotato","1","1","N/A","N/A","9","2","112","16","2021-06-07T21:19:58Z","2021-06-05T22:32:48Z","46640" +"*govolution/avet*",".{0,1000}govolution\/avet.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","46651" +"*goWMIExec/pkg*",".{0,1000}goWMIExec\/pkg.{0,1000}","offensive_tool_keyword","goWMIExec","re-implementation of invoke-wmiexec (Lateral Movement)","T1021.005","TA0008","N/A","N/A","Lateral Movement","https://github.com/C-Sto/goWMIExec","1","1","N/A","N/A","10","3","214","42","2023-02-25T01:41:41Z","2019-10-14T22:32:11Z","46653" +"*goZulipC2.go*",".{0,1000}goZulipC2\.go.{0,1000}","offensive_tool_keyword","goZulipC2","C2 leveraging Zulip Messaging Platform as Backend.","T1090 - T1090.003 - T1071 - T1071.001","TA0011 - TA0009","N/A","N/A","C2","https://github.com/n1k7l4i/goZulipC2","1","1","N/A","N/A","10","","N/A","","","","46654" +"*goZulipC2-main*",".{0,1000}goZulipC2\-main.{0,1000}","offensive_tool_keyword","goZulipC2","C2 leveraging Zulip Messaging Platform as Backend.","T1090 - T1090.003 - T1071 - T1071.001","TA0011 - TA0009","N/A","N/A","C2","https://github.com/n1k7l4i/goZulipC2","1","1","N/A","N/A","10","","N/A","","","","46655" +"*gpg2john.*",".{0,1000}gpg2john\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","46659" +"*gpoddity.py*",".{0,1000}gpoddity\.py.{0,1000}","offensive_tool_keyword","GPOddity","GPO attack vectors through NTLM relaying","T1558.001 - T1552.001","TA0003 - TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/synacktiv/GPOddity","1","1","N/A","N/A","9","3","297","26","2024-11-08T15:14:06Z","2023-09-01T08:13:25Z","46660" +"*gpoddity_smbserver.py*",".{0,1000}gpoddity_smbserver\.py.{0,1000}","offensive_tool_keyword","GPOddity","GPO attack vectors through NTLM relaying","T1558.001 - T1552.001","TA0003 - TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/synacktiv/GPOddity","1","1","N/A","N/A","9","3","297","26","2024-11-08T15:14:06Z","2023-09-01T08:13:25Z","46661" +"*GPOddity-master*",".{0,1000}GPOddity\-master.{0,1000}","offensive_tool_keyword","GPOddity","GPO attack vectors through NTLM relaying","T1558.001 - T1552.001","TA0003 - TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/synacktiv/GPOddity","1","1","N/A","N/A","9","3","297","26","2024-11-08T15:14:06Z","2023-09-01T08:13:25Z","46662" +"*GPO-RemoteAccess.txt*",".{0,1000}GPO\-RemoteAccess\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","46663" +"*gpp_autologin.py*",".{0,1000}gpp_autologin\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","46664" +"*gpp_password.py*",".{0,1000}gpp_password\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","46665" +"*GPP_Passwords.txt*",".{0,1000}GPP_Passwords\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","46666" +"*gppassword.py*",".{0,1000}gppassword\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","46667" +"*gpp-decrypt.rb*",".{0,1000}gpp\-decrypt\.rb.{0,1000}","offensive_tool_keyword","gpp-decrypt","Decrypt the given Group Policy Preferences","T1552.002 - T1212","TA0009 - TA0006","N/A","N/A","Credential Access","https://gitlab.com/kalilinux/packages/gpp-decrypt","1","1","N/A","N/A","6","10","N/A","N/A","N/A","N/A","46670" +"*GPSCoordinates.exe*",".{0,1000}GPSCoordinates\.exe.{0,1000}","offensive_tool_keyword","GPSCoordinates","Tracks the system's GPS coordinates (accurate within 1km currently) if Location Services are enabled","T1018 - T1059.001","TA0001 - TA0002","N/A","N/A","Reconnaissance","https://github.com/matterpreter/OffensiveCSharp/tree/master/GPSCoordinates","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","46671" +"*Gr1mmie/AtlasC2*",".{0,1000}Gr1mmie\/AtlasC2.{0,1000}","offensive_tool_keyword","AtlasC2","C# C2 Framework centered around Stage 1 operations","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/Gr1mmie/AtlasC2","1","1","N/A","N/A","10","10","211","41","2022-04-04T16:16:15Z","2021-12-27T01:40:52Z","46672" +"*grahamhelton/IMDSpoof*",".{0,1000}grahamhelton\/IMDSpoof.{0,1000}","offensive_tool_keyword","IMDSpoof","IMDSPOOF is a cyber deception tool that spoofs the AWS IMDS service to return HoneyTokens that can be alerted on.","T1584 - T1204 - T1078 - T1558","TA0007 - TA0001 - TA0002 - TA0004","N/A","N/A","Sniffing & Spoofing","https://github.com/grahamhelton/IMDSpoof","1","1","N/A","N/A","8","2","101","3","2023-11-24T23:42:48Z","2023-11-24T23:21:21Z","46678" +"*GrantMailboxAccess.ps1*",".{0,1000}GrantMailboxAccess\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","46681" +"*GrantSamAccessPermission.vbs*",".{0,1000}GrantSamAccessPermission\.vbs.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","46682" +"*GrantSamAccessPermission.vbs*",".{0,1000}GrantSamAccessPermission\.vbs.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","46683" +"*GraphLdr.x64.bin*",".{0,1000}GraphLdr\.x64\.bin.{0,1000}","offensive_tool_keyword","GraphStrike","Cobalt Strike HTTPS beaconing over Microsoft Graph API","T1102 - T1071.001 ","TA0002 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/RedSiege/GraphStrike","1","1","N/A","N/A","10","10","585","95","2024-06-25T11:18:19Z","2024-01-02T00:18:44Z","46684" +"*GraphLdr.x64.exe*",".{0,1000}GraphLdr\.x64\.exe.{0,1000}","offensive_tool_keyword","GraphStrike","Cobalt Strike HTTPS beaconing over Microsoft Graph API","T1102 - T1071.001 ","TA0002 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/RedSiege/GraphStrike","1","1","N/A","N/A","10","10","585","95","2024-06-25T11:18:19Z","2024-01-02T00:18:44Z","46685" +"*GraphSpy-master.zip*",".{0,1000}GraphSpy\-master\.zip.{0,1000}","offensive_tool_keyword","GraphSpy","Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI","T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656","TA0001 - TA0006 - TA0003 - TA0005 - TA0008","N/A","N/A","Collection","https://github.com/RedByte1337/GraphSpy","1","1","N/A","N/A","10","7","680","72","2025-04-15T21:07:15Z","2024-02-07T19:47:15Z","46695" +"*grayhatkiller/SharpExShell*",".{0,1000}grayhatkiller\/SharpExShell.{0,1000}","offensive_tool_keyword","SharpExShell","SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application","T1021.003 - T1218.007 - T1127.001","TA0008 - TA0009 - TA0005","N/A","N/A","Lateral Movement","https://github.com/grayhatkiller/SharpExShell","1","1","N/A","N/A","8","1","70","15","2024-05-01T23:17:25Z","2023-10-30T18:16:41Z","46698" +"*GreatSCT.git*",".{0,1000}GreatSCT\.git.{0,1000}","offensive_tool_keyword","GreatSCT","The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This tool is intended for BOTH red and blue team.","T1055 - T1112 - T1189 - T1205","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/GreatSCT/GreatSCT","1","1","N/A","N/A","N/A","10","1127","202","2021-02-10T22:05:27Z","2017-05-12T03:30:41Z","46700" +"*GreatSCT.py*",".{0,1000}GreatSCT\.py.{0,1000}","offensive_tool_keyword","GreatSCT","The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This tool is intended for BOTH red and blue team.","T1055 - T1112 - T1189 - T1205","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/GreatSCT/GreatSCT","1","1","N/A","N/A","N/A","10","1127","202","2021-02-10T22:05:27Z","2017-05-12T03:30:41Z","46701" +"*gremwell/o365enum*",".{0,1000}gremwell\/o365enum.{0,1000}","offensive_tool_keyword","o365enum","Enumerate valid usernames from Office 365 using ActiveSync - Autodiscover v1 or office.com login page.","T1595 - T1595.002 - T1114 - T1114.001 - T1087 - T1087.002","TA0040 - TA0010 - TA0007","N/A","N/A","Exploitation tool","https://github.com/gremwell/o365enum","1","1","N/A","N/A","7","3","267","39","2024-05-02T07:45:31Z","2020-02-18T12:22:50Z","46704" +"*Group3r.cs*",".{0,1000}Group3r\.cs.{0,1000}","offensive_tool_keyword","Group3r","Find vulnerabilities in AD Group Policy","T1484.002 - T1069.002 - T1087.002","TA0007 - TA0040","N/A","KNOTWEED","Discovery","https://github.com/Group3r/Group3r","1","1","N/A","AD Enumeration","7","8","781","68","2025-04-08T05:03:34Z","2021-07-05T05:05:42Z","46716" +"*Group3r.exe*",".{0,1000}Group3r\.exe.{0,1000}","offensive_tool_keyword","Group3r","Find vulnerabilities in AD Group Policy","T1484.002 - T1069.002 - T1087.002","TA0007 - TA0040","N/A","KNOTWEED","Discovery","https://github.com/Group3r/Group3r","1","1","N/A","AD Enumeration","7","8","781","68","2025-04-08T05:03:34Z","2021-07-05T05:05:42Z","46717" +"*Group3r/Group3r*",".{0,1000}Group3r\/Group3r.{0,1000}","offensive_tool_keyword","Group3r","Find vulnerabilities in AD Group Policy","T1484.002 - T1069.002 - T1087.002","TA0007 - TA0040","N/A","KNOTWEED","Discovery","https://github.com/Group3r/Group3r","1","1","N/A","AD Enumeration","7","8","781","68","2025-04-08T05:03:34Z","2021-07-05T05:05:42Z","46719" +"*Group3r/Group3r*",".{0,1000}Group3r\/Group3r.{0,1000}","offensive_tool_keyword","Group3r","Find vulnerabilities in AD Group Policy","T1484.002 - T1069.002 - T1087.002","TA0007 - TA0040","N/A","KNOTWEED","Discovery","https://github.com/Group3r/Group3r","1","1","N/A","AD Enumeration","7","8","781","68","2025-04-08T05:03:34Z","2021-07-05T05:05:42Z","46720" +"*GruntInjection.exe*",".{0,1000}GruntInjection\.exe.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","46722" +"*gruntstager.cs*",".{0,1000}gruntstager\.cs.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","46723" +"*GruntStager.exe*",".{0,1000}GruntStager\.exe.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","46724" +"*gsecdump-v2b5.exe*",".{0,1000}gsecdump\-v2b5\.exe.{0,1000}","offensive_tool_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","46727" +"*gserver/gServer.go*",".{0,1000}gserver\/gServer\.go.{0,1000}","offensive_tool_keyword","gTunnel","tunelling solution written in golang","T1573.002 - T1071 - T1090 - T1105 - T1020","TA0005 - TA0010 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hotnops/gTunnel","1","1","N/A","N/A","10","10","266","49","2023-05-17T05:24:58Z","2020-03-09T02:52:48Z","46729" +"*gsmith257-cyber/better-sliver*",".{0,1000}gsmith257\-cyber\/better\-sliver.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/gsmith257-cyber/better-sliver","1","1","N/A","N/A","10","10","98","10","2024-07-22T12:32:16Z","2023-12-12T02:04:36Z","46732" +"*gs-netcat_freebsd-x86_64*",".{0,1000}gs\-netcat_freebsd\-x86_64.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46740" +"*gs-netcat_linux-aarch64*",".{0,1000}gs\-netcat_linux\-aarch64.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46741" +"*gs-netcat_linux-arm*",".{0,1000}gs\-netcat_linux\-arm.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46742" +"*gs-netcat_linux-armhf*",".{0,1000}gs\-netcat_linux\-armhf.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46743" +"*gs-netcat_linux-armv6*",".{0,1000}gs\-netcat_linux\-armv6.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46744" +"*gs-netcat_linux-armv7l*",".{0,1000}gs\-netcat_linux\-armv7l.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46745" +"*gs-netcat_linux-i686*",".{0,1000}gs\-netcat_linux\-i686.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46746" +"*gs-netcat_linux-mips32*",".{0,1000}gs\-netcat_linux\-mips32.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46747" +"*gs-netcat_linux-mips64*",".{0,1000}gs\-netcat_linux\-mips64.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46748" +"*gs-netcat_linux-mipsel*",".{0,1000}gs\-netcat_linux\-mipsel.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46749" +"*gs-netcat_linux-x86_64*",".{0,1000}gs\-netcat_linux\-x86_64.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46750" +"*gs-netcat_macOS*",".{0,1000}gs\-netcat_macOS.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46751" +"*gs-netcat_openbsd-x86_64*",".{0,1000}gs\-netcat_openbsd\-x86_64.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46752" +"*gsocket.1.html*",".{0,1000}gsocket\.1\.html.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46762" +"*gsocket.io/deploy*",".{0,1000}gsocket\.io\/deploy.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46763" +"*gsocket.io/deploy*",".{0,1000}gsocket\.io\/deploy.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46764" +"*gsocket.io/install.sh*",".{0,1000}gsocket\.io\/install\.sh.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46765" +"*gsocket_1.*.deb*",".{0,1000}gsocket_1\..{0,1000}\.deb.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46767" +"*gsocket_linux-aarch64.tar.gz*",".{0,1000}gsocket_linux\-aarch64\.tar\.gz.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46769" +"*gsocket_linux-arm.tar.gz*",".{0,1000}gsocket_linux\-arm\.tar\.gz.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46770" +"*gsocket_linux-armv6.tar.gz*",".{0,1000}gsocket_linux\-armv6\.tar\.gz.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46771" +"*gsocket_linux-armv7l.tar.gz*",".{0,1000}gsocket_linux\-armv7l\.tar\.gz.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46772" +"*gsocket_linux-i686.tar.gz*",".{0,1000}gsocket_linux\-i686\.tar\.gz.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46773" +"*gsocket_linux-mips32.tar.gz*",".{0,1000}gsocket_linux\-mips32\.tar\.gz.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46774" +"*gsocket_linux-mips64.tar.gz*",".{0,1000}gsocket_linux\-mips64\.tar\.gz.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46775" +"*gsocket_linux-mipsel.tar.gz*",".{0,1000}gsocket_linux\-mipsel\.tar\.gz.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46776" +"*gsocket_linux-x86_64.tar.gz*",".{0,1000}gsocket_linux\-x86_64\.tar\.gz.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46777" +"*gsocket_macOS.tar.gz*",".{0,1000}gsocket_macOS\.tar\.gz.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46779" +"*gsocket_openbsd-x86_x64.tar.gz*",".{0,1000}gsocket_openbsd\-x86_x64\.tar\.gz.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46780" +"*gsocket-1.*.tar.gz*",".{0,1000}gsocket\-1\..{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46786" +"*gsocket-relay/monitor/*",".{0,1000}gsocket\-relay\/monitor\/.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46787" +"*gsocket-tor/*",".{0,1000}gsocket\-tor\/.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46788" +"*gs-root-shell-key.txt*",".{0,1000}gs\-root\-shell\-key\.txt.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46790" +"*GTFOBLookup*",".{0,1000}GTFOBLookup.{0,1000}","offensive_tool_keyword","GTFOBLookup","Offline command line lookup utility for GTFOBins and LOLBAS.","T1059 - T1110 - T1216 - T1220","TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/nccgroup/GTFOBLookup","1","1","N/A","N/A","N/A","3","277","39","2023-06-16T22:01:43Z","2019-09-23T16:00:18Z","46794" +"*gtworek/Priv2Admin*",".{0,1000}gtworek\/Priv2Admin.{0,1000}","offensive_tool_keyword","Priv2Admin","Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS.","T1543 - T1068 - T1078","TA0003 - TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/gtworek/Priv2Admin","1","1","N/A","N/A","N/A","10","2124","286","2023-02-24T13:31:23Z","2019-08-14T11:50:17Z","46797" +"*guardicore/monkey*",".{0,1000}guardicore\/monkey.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","46799" +"*gunyhng6pabzcurl7ipx2pbmjxpvqnu6mxf2h3vdeenam34inj4ndryd.onion*",".{0,1000}gunyhng6pabzcurl7ipx2pbmjxpvqnu6mxf2h3vdeenam34inj4ndryd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","46804" +"*Gupt-Backdoor.ps1*",".{0,1000}Gupt\-Backdoor\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","46805" +"*gustanini/PowershellTools*",".{0,1000}gustanini\/PowershellTools.{0,1000}","offensive_tool_keyword","PowershellTools","Powershell tools used for Red Team / Pentesting","T1087.002 - T1069.001 - T1069.002 - T1598.002 - T1083 - T1558.003 - T1564.001 - T1112","TA0007 - TA0003 - TA0006 - TA0040 - TA0005 - TA0003","N/A","N/A","Exploitation tool","https://github.com/gustanini/PowershellTools","1","1","N/A","N/A","10","1","76","13","2024-01-08T10:33:20Z","2023-10-26T16:49:59Z","46807" +"*gvka2m4qt5fod2fltkjmdk4gxh5oxemhpgmnmtjptms6fkgfzdd62tad.onion*",".{0,1000}gvka2m4qt5fod2fltkjmdk4gxh5oxemhpgmnmtjptms6fkgfzdd62tad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","46808" +"*gwisin4yznpdtzq424i3la6oqy5evublod4zbhddzuxcnr34kgfokwad.onion*",".{0,1000}gwisin4yznpdtzq424i3la6oqy5evublod4zbhddzuxcnr34kgfokwad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","46810" +"*gwvueqclwkz3h7u75cks2wmrwymg3qemfyoyqs7vexkx7lhlteagmsyd.onion*",".{0,1000}gwvueqclwkz3h7u75cks2wmrwymg3qemfyoyqs7vexkx7lhlteagmsyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","46811" +"*h3xduck/TripleCross*",".{0,1000}h3xduck\/TripleCross.{0,1000}","offensive_tool_keyword","TripleCross","A Linux eBPF rootkit with a backdoor - C2 - library injection - execution hijacking - persistence and stealth capabilities.","T1055 - T1021.005 - T1055.011 - T1055.003 - T1547 - T1574 - T1027 - T1070.004 - T1562.001","TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/h3xduck/TripleCross","1","1","#linux","N/A","10","10","1838","232","2024-04-07T02:06:19Z","2021-10-27T17:47:58Z","46818" +"*Ha3MrX/Gemail-Hack*",".{0,1000}Ha3MrX\/Gemail\-Hack.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/Ha3MrX/Gemail-Hack","1","1","N/A","N/A","7","10","1062","400","2024-01-17T15:12:44Z","2018-04-19T13:48:41Z","46830" +"*haad/proxychains*",".{0,1000}haad\/proxychains.{0,1000}","offensive_tool_keyword","proxychains","proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4 SOCKS5 or HTTP(S) proxy","T1090.004 - T1090.003 - T1027 - T1573 - T1095","TA0005 - TA0011 - TA0010","N/A","Vice Society - Qilin - Black Basta - Dispossessor - EMBER BEAR","Defense Evasion","https://github.com/haad/proxychains","1","1","N/A","N/A","8","10","7142","647","2024-06-08T02:20:54Z","2011-02-25T12:27:05Z","46831" +"*hackbrowersdata.cna*",".{0,1000}hackbrowersdata\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","reflective module for HackBrowserData","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/idiotc4t/Reflective-HackBrowserData","1","1","N/A","N/A","10","10","175","25","2021-03-13T08:42:18Z","2021-03-13T08:35:01Z","46832" +"*hack-browser-data.exe*",".{0,1000}hack\-browser\-data\.exe.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555 - T1189 - T1217 - T1185","TA0002 - TA0009 - TA0001 - TA0010","N/A","N/A","Exploitation tool","https://github.com/moonD4rk/HackBrowserData","1","1","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","46833" +"*hack-browser-data/*",".{0,1000}hack\-browser\-data\/.{0,1000}","offensive_tool_keyword","cobaltstrike","C# binary with embeded golang hack-browser-data","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/S3cur3Th1sSh1t/Sharp-HackBrowserData","1","1","N/A","N/A","10","10","96","17","2021-12-09T18:58:27Z","2020-12-06T12:28:47Z","46834" +"*hackbuildrepeat/SharpView*",".{0,1000}hackbuildrepeat\/SharpView.{0,1000}","offensive_tool_keyword","SharpView","C# implementation of harmj0y's PowerView","T1018 - T1482 - T1087.002 - T1069.002","TA0007 - TA0003 - TA0001","N/A","Conti - APT29","Discovery","https://github.com/tevora-threat/SharpView/","1","1","N/A","N/A","10","10","1032","196","2024-03-22T16:34:09Z","2018-07-24T21:15:04Z","46835" +"*Hackcraft-Labs/ScheduleRunner*",".{0,1000}Hackcraft\-Labs\/ScheduleRunner.{0,1000}","offensive_tool_keyword","ScheduleRunner","A C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operation","T1210 - T1570 - T1021 - T1550","TA0008","N/A","N/A","Persistence","https://github.com/netero1010/ScheduleRunner","1","1","N/A","N/A","9","4","336","46","2025-01-22T02:06:59Z","2021-10-12T15:27:32Z","46836" +"*Hackcraft-Labs/SharpShares*",".{0,1000}Hackcraft\-Labs\/SharpShares.{0,1000}","offensive_tool_keyword","SharpShares","Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain","T1046 - T1135","TA0007 - TA0001","N/A","BlackSuit - Royal - BianLian - Fog","Discovery","https://github.com/Hackcraft-Labs/SharpShares","1","1","N/A","N/A","10","1","33","7","2023-11-13T14:08:07Z","2023-10-25T10:34:18Z","46837" +"*HACKER*FUCKER*Xeroxxx*",".{0,1000}HACKER.{0,1000}FUCKER.{0,1000}Xeroxxx.{0,1000}","offensive_tool_keyword","conti","Conti is a Ransomware-as-a-Service (RaaS) that was first observed in December 2019. Conti has been deployed via TrickBot and used against major corporations and government agencies particularly those in North America. As with other ransomware families - actors using Conti steal sensitive files and information from compromised networks and threaten to publish this data unless the ransom is paid","T1059.003 - T1486 - T1140 - T1083 - T1490 - T1106 - T1135 - T1027 - T1057 - T1055.001 - T1021.002 - T1018 - T1489 - T1016 - T1049 - T1080","TA0002 - TA0003 - TA0004 - TA0007 - TA0009 - TA0040","Conti Ransomware","Wizard Spider - Black Basta","Ransomware","https://www.securonix.com/blog/on-conti-ransomware-tradecraft-detection/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","46841" +"*hackerhouse-opensource/OffensiveLua*",".{0,1000}hackerhouse\-opensource\/OffensiveLua.{0,1000}","offensive_tool_keyword","OffensiveLua","Offensive Lua is a collection of offensive security scripts written in Lua with FFI","T1059 - T1218.011 - T1105 - T1021.002 - T1564.001 - T1112 - T1113 - T1204.002 - T1547.002","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hackerhouse-opensource/OffensiveLua","1","1","N/A","N/A","8","2","184","25","2023-11-17T00:35:10Z","2023-10-25T17:21:13Z","46842" +"*hackerhouse-opensource/SignToolEx*",".{0,1000}hackerhouse\-opensource\/SignToolEx.{0,1000}","offensive_tool_keyword","SignToolEx","Patching signtool.exe to accept expired certificates for code-signing","T1553.002 - T1649","TA0005","N/A","N/A","Defense Evasion","https://github.com/hackerhouse-opensource/SignToolEx","1","1","N/A","N/A","8","3","275","47","2024-07-19T17:22:28Z","2023-12-29T14:26:45Z","46843" +"*hackerschoice/gsocket*",".{0,1000}hackerschoice\/gsocket.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46844" +"*hackerschoice/gsocket-relay*",".{0,1000}hackerschoice\/gsocket\-relay.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","46845" +"*hackerschoice/hackshell*",".{0,1000}hackerschoice\/hackshell.{0,1000}","offensive_tool_keyword","hackshell","Make BASH stealthy and hacker friendly with lots of bash functions","T1070.003 - T1059.004 - T1564.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/hackerschoice/hackshell","1","1","N/A","N/A","9","3","251","28","2025-04-21T11:23:41Z","2024-07-16T15:56:11Z","46846" +"*hackingtool.py*",".{0,1000}hackingtool\.py.{0,1000}","offensive_tool_keyword","hackingtool","ALL IN ONE Hacking Tool For Hackers","T1059 - T1078 - T1105 - T1110 - T1566","TA0002 - TA0008 - TA0009 - TA0005 - TA0007","N/A","N/A","Exploitation tool","https://github.com/Z4nzu/hackingtool","1","1","N/A","N/A","N/A","10","52217","5629","2025-03-03T15:17:19Z","2020-04-11T09:21:31Z","46849" +"*Hackndo/conpass*",".{0,1000}Hackndo\/conpass.{0,1000}","offensive_tool_keyword","conpass","Continuous password spraying tool","T1110.001 - T1110 - T1078.001 - T1201","TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://github.com/login-securite/conpass","1","1","N/A","N/A","10","2","181","17","2025-03-03T15:05:25Z","2022-12-15T18:03:42Z","46850" +"*Hackndo/sprayhound*",".{0,1000}Hackndo\/sprayhound.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","46851" +"*Hackndo/sprayhound*",".{0,1000}Hackndo\/sprayhound.{0,1000}","offensive_tool_keyword","sprayhound","Password spraying tool and Bloodhound integration","T1110.003 - T1210.001 - T1069.002","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/Hackndo/sprayhound","1","1","N/A","N/A","N/A","3","231","19","2024-12-31T08:09:37Z","2020-02-06T17:45:37Z","46852" +"*Hackplayers/evil-winrm*",".{0,1000}Hackplayers\/evil\-winrm.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","46854" +"*hackshell-main.zip*",".{0,1000}hackshell\-main\.zip.{0,1000}","offensive_tool_keyword","hackshell","Make BASH stealthy and hacker friendly with lots of bash functions","T1070.003 - T1059.004 - T1564.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/hackerschoice/hackshell","1","1","N/A","N/A","9","3","251","28","2025-04-21T11:23:41Z","2024-07-16T15:56:11Z","46856" +"*hacksysteam/CVE-2023-*",".{0,1000}hacksysteam\/CVE\-2023\-.{0,1000}","offensive_tool_keyword","POC","Adobe Acrobat Reader - CVE-2023-21608 - Remote Code Execution Exploit ","T1203 - T1218 - T1059 - T1064 - T1204","TA0001 - TA0002","N/A","N/A","Exploitation tool","https://github.com/hacksysteam/CVE-2023-21608","1","1","N/A","N/A","N/A","3","272","58","2023-12-05T12:21:02Z","2023-01-30T12:57:48Z","46857" +"*hacktools-*.xpi*",".{0,1000}hacktools\-.{0,1000}\.xpi.{0,1000}","offensive_tool_keyword","hack-tools","The all-in-one Red Team browser extension for Web Pentester","T1059.007 - T1505 - T1068 - T1216 - T1547.009","TA0002 - TA0001 - TA0009","N/A","N/A","Vulnerability Scanner","https://github.com/LasCC/Hack-Tools","1","1","N/A","N/A","9","10","6045","678","2025-01-05T23:10:49Z","2020-06-22T21:42:16Z","46968" +"*hack-tools/cmbndhnoonmghfofefkcccljbkdpamhi*",".{0,1000}hack\-tools\/cmbndhnoonmghfofefkcccljbkdpamhi.{0,1000}","offensive_tool_keyword","hack-tools","The all-in-one Red Team browser extension for Web Pentester","T1059.007 - T1505 - T1068 - T1216 - T1547.009","TA0002 - TA0001 - TA0009","N/A","N/A","Vulnerability Scanner","https://github.com/LasCC/Hack-Tools","1","1","N/A","N/A","9","10","6045","678","2025-01-05T23:10:49Z","2020-06-22T21:42:16Z","46969" +"*Hack-Tools-master*",".{0,1000}Hack\-Tools\-master.{0,1000}","offensive_tool_keyword","hack-tools","The all-in-one Red Team browser extension for Web Pentester","T1059.007 - T1505 - T1068 - T1216 - T1547.009","TA0002 - TA0001 - TA0009","N/A","N/A","Vulnerability Scanner","https://github.com/LasCC/Hack-Tools","1","1","N/A","N/A","9","10","6045","678","2025-01-05T23:10:49Z","2020-06-22T21:42:16Z","46970" +"*hades_directsys.exe*",".{0,1000}hades_directsys\.exe.{0,1000}","offensive_tool_keyword","hades","Go shellcode loader that combines multiple evasion techniques","T1055 - T1027 - T1218 - T1027.001 - T1036","TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/f1zm0/hades","1","1","N/A","N/A","7","4","364","47","2023-06-21T19:22:57Z","2022-10-11T08:16:24Z","46971" +"*HadesLdr-main*",".{0,1000}HadesLdr\-main.{0,1000}","offensive_tool_keyword","HadesLdr","Shellcode Loader Implementing Indirect Dynamic Syscall - API Hashing - Fileless Shellcode retrieving using Winsock2","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CognisysGroup/HadesLdr","1","1","N/A","N/A","10","3","292","47","2023-07-15T21:23:49Z","2023-07-12T11:44:07Z","46972" +"*Hagrid29/DumpAADSyncCreds*",".{0,1000}Hagrid29\/DumpAADSyncCreds.{0,1000}","offensive_tool_keyword","DumpAADSyncCreds","C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.","T1555 - T1110","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Hagrid29/DumpAADSyncCreds","1","1","N/A","N/A","10","1","39","3","2023-06-24T16:17:36Z","2022-03-27T18:43:44Z","46973" +"*hak5/omg-payloads*",".{0,1000}hak5\/omg\-payloads.{0,1000}","offensive_tool_keyword","omg-payloads","Official payload library for the O.MG line of products from Mischief Gadgets","T1200 - T1095 - T1059.006 - T1027","TA0010 - TA0011","N/A","N/A","Hardware","https://github.com/hak5/omg-payloads","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","46975" +"*hakaioffsec/CVE-2024-21338*",".{0,1000}hakaioffsec\/CVE\-2024\-21338.{0,1000}","offensive_tool_keyword","POC","Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.","T1055.011 - T1548.002","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/hakaioffsec/CVE-2024-21338","1","1","N/A","N/A","9","3","292","60","2024-04-16T21:00:14Z","2024-04-13T05:53:02Z","46976" +"*haKCers.txt*",".{0,1000}haKCers\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","46977" +"*hakivvi/proxylogon*",".{0,1000}hakivvi\/proxylogon.{0,1000}","offensive_tool_keyword","ProxyLogon","ProxyLogon exploitation","T1190 - T1210 - T1213 - T1003 - T1059.003","TA0001 - TA0002 - TA0006 - TA0007","N/A","Dispossessor","Exploitation tool","https://github.com/hakivvi/proxylogon","1","1","N/A","N/A","10","1","20","6","2022-04-23T03:21:44Z","2021-03-14T13:04:07Z","46978" +"*hakluke/hakrawler*",".{0,1000}hakluke\/hakrawler.{0,1000}","offensive_tool_keyword","hakrawler","Simple fast web crawler designed for easy and quick discovery of endpoints and assets within a web application","T1190 - T1212 - T1087.001","TA0007 - TA0003 - TA0009","N/A","N/A","Vulnerability Scanner","https://github.com/hakluke/hakrawler","1","1","#linux","N/A","6","10","4683","520","2024-12-21T20:40:03Z","2019-12-15T13:54:43Z","46979" +"*hakrawler.go*",".{0,1000}hakrawler\.go.{0,1000}","offensive_tool_keyword","hakrawler","Simple fast web crawler designed for easy and quick discovery of endpoints and assets within a web application","T1190 - T1212 - T1087.001","TA0007 - TA0003 - TA0009","N/A","N/A","Vulnerability Scanner","https://github.com/hakluke/hakrawler","1","1","#linux","N/A","6","10","4683","520","2024-12-21T20:40:03Z","2019-12-15T13:54:43Z","46981" +"*hakrawler-ip-range*",".{0,1000}hakrawler\-ip\-range.{0,1000}","offensive_tool_keyword","thoth","Automate recon for red team assessments.","T1190 - T1083 - T1018","TA0007 - TA0043 - TA0001","N/A","N/A","Reconnaissance","https://github.com/r1cksec/thoth","1","1","N/A","N/A","7","1","95","10","2025-02-03T12:05:52Z","2021-11-15T13:40:56Z","46983" +"*hakrawler-master*",".{0,1000}hakrawler\-master.{0,1000}","offensive_tool_keyword","hakrawler","Simple fast web crawler designed for easy and quick discovery of endpoints and assets within a web application","T1190 - T1212 - T1087.001","TA0007 - TA0003 - TA0009","N/A","N/A","Vulnerability Scanner","https://github.com/hakluke/hakrawler","1","1","#linux","N/A","6","10","4683","520","2024-12-21T20:40:03Z","2019-12-15T13:54:43Z","46984" +"*Hakumarachi/Bropper*",".{0,1000}Hakumarachi\/Bropper.{0,1000}","offensive_tool_keyword","bropper","An automatic Blind ROP exploitation tool ","T1068 - T1059.003 - T1140","TA0002 - TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/Hakumarachi/Bropper","1","1","N/A","N/A","8","3","201","19","2023-06-09T12:40:05Z","2023-01-20T14:09:19Z","46986" +"*handlekatz.py*",".{0,1000}handlekatz\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","46991" +"*handlekatz.x64.*",".{0,1000}handlekatz\.x64\..{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF port of the research of @thefLinkk and @codewhitesec","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com//EspressoCake/HandleKatz_BOF","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","46992" +"*handlekatz_bof.*",".{0,1000}handlekatz_bof\..{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF port of the research of @thefLinkk and @codewhitesec","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com//EspressoCake/HandleKatz_BOF","1","1","N/A","N/A","10","","N/A","","","","46993" +"*handlekatz_dump*",".{0,1000}handlekatz_dump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","46994" +"*Hangingsword/HouQing*",".{0,1000}Hangingsword\/HouQing.{0,1000}","offensive_tool_keyword","cobaltstrike","Hou Qing-Advanced AV Evasion Tool For Red Team Ops","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Hangingsword/HouQing","1","1","N/A","N/A","10","10","205","60","2021-01-14T08:38:12Z","2021-01-14T07:13:21Z","46998" +"*HarmJ0y/DAMP*",".{0,1000}HarmJ0y\/DAMP.{0,1000}","offensive_tool_keyword","DAMP","The Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification.","T1222 - T1222.002 - T1548 - T1548.002","TA0005 ","N/A","N/A","Persistence","https://github.com/HarmJ0y/DAMP","1","1","N/A","N/A","10","4","378","79","2019-07-25T21:18:37Z","2018-04-06T22:13:58Z","47004" +"*HarvestBrowserPasswords.exe*",".{0,1000}HarvestBrowserPasswords\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","47005" +"*HarvestBrowserPasswords.pdb*",".{0,1000}HarvestBrowserPasswords\.pdb.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","47006" +"*hash3liZer/SillyRAT*",".{0,1000}hash3liZer\/SillyRAT.{0,1000}","offensive_tool_keyword","SillyRAT","A Cross Platform multifunctional (Windows/Linux/Mac) RAT.","T1055.003 - T1027 - T1105 - T1005","TA0002 - TA0003 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hash3liZer/SillyRAT","1","1","N/A","N/A","N/A","10","792","162","2023-12-09T00:42:07Z","2020-05-10T17:37:37Z","47010" +"*hash3liZer/wifijammer*",".{0,1000}hash3liZer\/wifijammer.{0,1000}","offensive_tool_keyword","wifijammer","wifijammer","T1497 - T1498 - T1499","TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/hash3liZer/wifijammer","1","1","N/A","N/A","N/A","3","202","44","2021-06-10T12:33:49Z","2018-01-20T16:26:45Z","47011" +"*Hash-Buster*",".{0,1000}Hash\-Buster.{0,1000}","offensive_tool_keyword","Hash-Buster","hash cracking tool ","T1201 - T1110 - T1021","TA0001 - TA0002 - TA0006","N/A","N/A","Credential Access","https://github.com/s0md3v/Hash-Buster","1","1","N/A","N/A","N/A","10","1809","401","2024-12-10T13:50:26Z","2017-07-03T17:28:51Z","47012" +"*hashcat-*.7z*",".{0,1000}hashcat\-.{0,1000}\.7z.{0,1000}","offensive_tool_keyword","hashcat","Worlds fastest and most advanced password recovery utility.","T1110.001 - T1003.001 - T1021.001","TA0006 - TA0009 - TA0010","N/A","Black Basta","Credential Access","https://github.com/hashcat/hashcat","1","1","#linux","N/A","10","10","22481","3046","2024-08-16T23:50:35Z","2015-12-04T14:46:51Z","47014" +"*hashcat.git*",".{0,1000}hashcat\.git.{0,1000}","offensive_tool_keyword","hashcat","Worlds fastest and most advanced password recovery utility.","T1110.001 - T1003.001 - T1021.001","TA0006 - TA0009 - TA0010","N/A","Black Basta","Credential Access","https://github.com/hashcat/hashcat","1","1","#linux","N/A","10","10","22481","3046","2024-08-16T23:50:35Z","2015-12-04T14:46:51Z","47015" +"*hashcat/hashcat*",".{0,1000}hashcat\/hashcat.{0,1000}","offensive_tool_keyword","hashcat","Worlds fastest and most advanced password recovery utility.","T1110.001 - T1003.001 - T1021.001","TA0006 - TA0009 - TA0010","N/A","Black Basta","Credential Access","https://github.com/hashcat/hashcat","1","1","#linux","N/A","10","10","22481","3046","2024-08-16T23:50:35Z","2015-12-04T14:46:51Z","47016" +"*hashcat-rule-master*",".{0,1000}hashcat\-rule\-master.{0,1000}","offensive_tool_keyword","hashcat-rule","Rule for hashcat or john. Aiming to crack how people generate their password","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/clem9669/hashcat-rule","1","1","#linux","N/A","10","5","435","47","2024-09-02T20:14:15Z","2020-03-06T17:20:40Z","47017" +"*hashdump.rb*",".{0,1000}hashdump\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","47019" +"*hashdump.x64.dll*",".{0,1000}hashdump\.x64\.dll.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","47020" +"*hashdump_sam*",".{0,1000}hashdump_sam.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","47021" +"*HashDumpDCImplant*",".{0,1000}HashDumpDCImplant.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","47022" +"*HashDumpSAMImplant*",".{0,1000}HashDumpSAMImplant.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","47023" +"*hasherezade/exe_to_dll*",".{0,1000}hasherezade\/exe_to_dll.{0,1000}","offensive_tool_keyword","exe_to_dll","Converts a EXE into DLL","T1027.004 - T1059.001","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/hasherezade/exe_to_dll","1","1","N/A","N/A","5","10","1297","197","2023-07-26T11:41:27Z","2020-04-16T16:27:00Z","47025" +"*hasherezade/exe_to_dll*",".{0,1000}hasherezade\/exe_to_dll.{0,1000}","offensive_tool_keyword","exe_to_dll","Converts an EXE so that it can be loaded like a DLL.","T1055.002 - T1073.001 - T1027","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/hasherezade/exe_to_dll","1","1","N/A","N/A","8","10","1297","197","2023-07-26T11:41:27Z","2020-04-16T16:27:00Z","47026" +"*hasherezade/persistence_demos*",".{0,1000}hasherezade\/persistence_demos.{0,1000}","offensive_tool_keyword","persistence_demos","Demos of various (also non standard) persistence methods used by malware","T1546 - T1547 - T1133 - T1053 - T1037","TA0003 ","N/A","N/A","Persistence","https://github.com/hasherezade/persistence_demos","1","1","N/A","N/A","7","3","221","47","2023-03-05T17:01:14Z","2017-05-16T09:08:47Z","47027" +"*HashPals/Name-That-Hash*",".{0,1000}HashPals\/Name\-That\-Hash.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","47030" +"*hashview*@*localhost*",".{0,1000}hashview.{0,1000}\@.{0,1000}localhost.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","47032" +"*hashview/config.conf*",".{0,1000}hashview\/config\.conf.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","47033" +"*hashview/hashview*",".{0,1000}hashview\/hashview.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","47034" +"*hashview-agent.*.tgz*",".{0,1000}hashview\-agent\..{0,1000}\.tgz.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","47035" +"*hashview-agent.py*",".{0,1000}hashview\-agent\.py.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","47036" +"*hatlord/snmpwn*",".{0,1000}hatlord\/snmpwn.{0,1000}","offensive_tool_keyword","snmpwn","SNMPwn is an SNMPv3 user enumerator and attack tool. It is a legitimate security tool designed to be used by security professionals and penetration testers against hosts you have permission to test. It takes advantage of the fact that SNMPv3 systems will respond with Unknown user name when an SNMP user does not exist. allowing us to cycle through large lists of users to find the ones that do","T1210 - T1212 - T1558","TA0001 - TA0002","N/A","N/A","Exploitation tool","https://github.com/hatlord/snmpwn","1","1","N/A","N/A","N/A","3","253","43","2020-08-23T10:41:38Z","2016-06-16T10:31:13Z","47038" +"*hausec/ADAPE-Script*",".{0,1000}hausec\/ADAPE\-Script.{0,1000}","offensive_tool_keyword","ADAPE-Script","Active Directory Assessment and Privilege Escalation Script","T1178 - T1087 - T1482","TA0002 - TA0004 - TA0007","N/A","Black Basta","Privilege Escalation","https://github.com/cjoan75/ADAPE-Script","1","1","N/A","N/A","8","1","0","0","2020-07-11T00:53:24Z","2020-08-09T16:52:35Z","47039" +"*hausec/ProxyLogon*",".{0,1000}hausec\/ProxyLogon.{0,1000}","offensive_tool_keyword","ProxyLogon","ProxyLogon exploitation","T1190 - T1210 - T1213 - T1003 - T1059.003","TA0001 - TA0002 - TA0006 - TA0007","N/A","Dispossessor","Exploitation tool","https://github.com/hausec/ProxyLogon","1","1","N/A","N/A","10","3","293","76","2024-07-02T10:00:00Z","2021-03-15T14:37:57Z","47040" +"*havoc.agent*",".{0,1000}havoc\.agent.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47043" +"*Havoc.git*",".{0,1000}Havoc\.git.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47044" +"*Havoc.hpp*",".{0,1000}Havoc\.hpp.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47045" +"*havoc.service*",".{0,1000}havoc\.service.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47046" +"*havoc.yaotl*",".{0,1000}havoc\.yaotl.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47047" +"*Havoc/Client*",".{0,1000}Havoc\/Client.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47048" +"*Havoc/cmd/*",".{0,1000}Havoc\/cmd\/.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47049" +"*Havoc/payloads*",".{0,1000}Havoc\/payloads.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47050" +"*Havoc/pkg*",".{0,1000}Havoc\/pkg.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47051" +"*Havoc/Teamserver*",".{0,1000}Havoc\/Teamserver.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47052" +"*havoc_agent.py*",".{0,1000}havoc_agent\.py.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47053" +"*havoc_agent_talon.*",".{0,1000}havoc_agent_talon\..{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47054" +"*havoc_default.yaotl*",".{0,1000}havoc_default\.yaotl.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47055" +"*havoc_externalc2*",".{0,1000}havoc_externalc2.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47056" +"*havoc_service_connect*",".{0,1000}havoc_service_connect.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47057" +"*havoc-c2-client*",".{0,1000}havoc\-c2\-client.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47058" +"*havoc-c2-data*",".{0,1000}havoc\-c2\-data.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47059" +"*havocframework.com*",".{0,1000}havocframework\.com.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47060" +"*HavocService*",".{0,1000}HavocService.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47061" +"*HavocTalonInteract*",".{0,1000}HavocTalonInteract.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47062" +"*Havoc-UACBypass.py*",".{0,1000}Havoc\-UACBypass\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of UAC Bypass Techniques Weaponized as BOFs","T1548.002 - T1203 - T1055 - T1134.002","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/icyguider/UAC-BOF-Bonanza","1","1","N/A","N/A","10","6","500","65","2024-02-21T22:07:54Z","2024-02-16T14:47:13Z","47063" +"*HavocUi.cpp*",".{0,1000}HavocUi\.cpp.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47064" +"*HavocUi.h*",".{0,1000}HavocUi\.h.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47065" +"*HavocUI.hpp*",".{0,1000}HavocUI\.hpp.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47066" +"*hccapx2john.py*",".{0,1000}hccapx2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","47067" +"*hci_oracle_passwords*",".{0,1000}hci_oracle_passwords.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","47068" +"*hcxdumptool*",".{0,1000}hcxdumptool.{0,1000}","offensive_tool_keyword","hcxdumptool","Small tool to capture packets from wlan devices. After capturing. upload the uncleaned pcapng here (https://wpa-sec.stanev.org/?submit) to see if your ACCESS POINT or the CLIENT is vulnerable by using common wordlists. Convert the pcapng file to WPA-PBKDF2-PMKID+EAPOL hashline (22000) with hcxpcapngtool (hcxtools) and check if PreSharedKey or PlainMasterKey was transmitted unencrypted","T1040 - T1560 - T1539","TA0001 - TA0002 - TA0007","N/A","N/A","Sniffing & Spoofing","https://github.com/ZerBea/hcxdumptool","1","1","N/A","N/A","N/A","10","1949","407","2025-04-19T07:25:39Z","2018-02-25T08:18:40Z","47070" +"*headers/exploit.h*",".{0,1000}headers\/exploit\.h.{0,1000}","offensive_tool_keyword","cobaltstrike","A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/PPLDump_BOF","1","1","N/A","N/A","10","10","140","25","2021-09-24T07:10:04Z","2021-09-24T07:05:59Z","47075" +"*headers/HandleKatz.h*",".{0,1000}headers\/HandleKatz\.h.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF port of the research of @thefLinkk and @codewhitesec","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com//EspressoCake/HandleKatz_BOF","1","1","N/A","N/A","10","","N/A","","","","47076" +"*HeapCrypt-main*",".{0,1000}HeapCrypt\-main.{0,1000}","offensive_tool_keyword","HeapCrypt","Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap","T1055.001 - T1027 - T1146","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/HeapCrypt","1","1","N/A","N/A","9","3","239","44","2023-08-02T02:24:42Z","2023-03-25T05:19:52Z","47078" +"*HeapEncryptDecrypt.cpp*",".{0,1000}HeapEncryptDecrypt\.cpp.{0,1000}","offensive_tool_keyword","HeapCrypt","Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap","T1055.001 - T1027 - T1146","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/HeapCrypt","1","1","N/A","N/A","9","3","239","44","2023-08-02T02:24:42Z","2023-03-25T05:19:52Z","47079" +"*HeapEncryptDecrypt.exe*",".{0,1000}HeapEncryptDecrypt\.exe.{0,1000}","offensive_tool_keyword","HeapCrypt","Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap","T1055.001 - T1027 - T1146","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/HeapCrypt","1","1","N/A","N/A","9","3","239","44","2023-08-02T02:24:42Z","2023-03-25T05:19:52Z","47080" +"*HeapEncryptDecrypt.sln*",".{0,1000}HeapEncryptDecrypt\.sln.{0,1000}","offensive_tool_keyword","HeapCrypt","Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap","T1055.001 - T1027 - T1146","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/HeapCrypt","1","1","N/A","N/A","9","3","239","44","2023-08-02T02:24:42Z","2023-03-25T05:19:52Z","47081" +"*HeapEncryptDecrypt.vcxproj*",".{0,1000}HeapEncryptDecrypt\.vcxproj.{0,1000}","offensive_tool_keyword","HeapCrypt","Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap","T1055.001 - T1027 - T1146","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/HeapCrypt","1","1","N/A","N/A","9","3","239","44","2023-08-02T02:24:42Z","2023-03-25T05:19:52Z","47082" +"*hekatomb-*.tar.gz*",".{0,1000}hekatomb\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/Processus-Thief/HEKATOMB","1","1","N/A","N/A","10","","N/A","","","","47085" +"*hekatomb-*-py3-none-any.whl*",".{0,1000}hekatomb\-.{0,1000}\-py3\-none\-any\.whl.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/Processus-Thief/HEKATOMB","1","1","N/A","N/A","10","","N/A","","","","47087" +"*hekatomb@thiefin.fr*",".{0,1000}hekatomb\@thiefin\.fr.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/Processus-Thief/HEKATOMB","1","1","#email","N/A","10","","N/A","","","","47089" +"*hekatomb_dump*",".{0,1000}hekatomb_dump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","47090" +"*HellHall-main.zip*",".{0,1000}HellHall\-main\.zip.{0,1000}","offensive_tool_keyword","HellsHall","Performing Indirect Clean Syscalls","T1106","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Maldev-Academy/HellHall","1","1","N/A","N/A","8","6","535","71","2023-04-19T06:10:47Z","2023-01-03T04:43:05Z","47091" +"*HelloReflectionWorld.exe*",".{0,1000}HelloReflectionWorld\.exe.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","47101" +"*hellsgate.asm*",".{0,1000}hellsgate\.asm.{0,1000}","offensive_tool_keyword","HellsGate","The Hell's Gate technique is a method employed by malware to hide its malicious behavior and avoid detection. This technique involves executing system calls directly thus bypassing the Windows API (Application Programming Interface) which is typically monitored by EDRs","T1055 - T1548.002 - T1129","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/am0nsec/HellsGate","1","1","N/A","N/A","N/A","10","1028","121","2021-06-28T15:42:36Z","2020-06-02T17:10:21Z","47102" +"*HellsGate.exe*",".{0,1000}HellsGate\.exe.{0,1000}","offensive_tool_keyword","HellsGate","The Hell's Gate technique is a method employed by malware to hide its malicious behavior and avoid detection. This technique involves executing system calls directly thus bypassing the Windows API (Application Programming Interface) which is typically monitored by EDRs","T1055 - T1548.002 - T1129","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/am0nsec/HellsGate","1","1","N/A","N/A","N/A","10","1028","121","2021-06-28T15:42:36Z","2020-06-02T17:10:21Z","47103" +"*HellsGate.sln*",".{0,1000}HellsGate\.sln.{0,1000}","offensive_tool_keyword","HellsGate","The Hell's Gate technique is a method employed by malware to hide its malicious behavior and avoid detection. This technique involves executing system calls directly thus bypassing the Windows API (Application Programming Interface) which is typically monitored by EDRs","T1055 - T1548.002 - T1129","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/am0nsec/HellsGate","1","1","N/A","N/A","N/A","10","1028","121","2021-06-28T15:42:36Z","2020-06-02T17:10:21Z","47104" +"*HellsGate.vcxproj*",".{0,1000}HellsGate\.vcxproj.{0,1000}","offensive_tool_keyword","HellsGate","The Hell's Gate technique is a method employed by malware to hide its malicious behavior and avoid detection. This technique involves executing system calls directly thus bypassing the Windows API (Application Programming Interface) which is typically monitored by EDRs","T1055 - T1548.002 - T1129","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/am0nsec/HellsGate","1","1","N/A","N/A","N/A","10","1028","121","2021-06-28T15:42:36Z","2020-06-02T17:10:21Z","47105" +"*helviojunior/hookchain*",".{0,1000}helviojunior\/hookchain.{0,1000}","offensive_tool_keyword","hookchain","Bypassing EDR Solutions","T1055.011 - T1564.001 - T1070.004 - T1562.001 - T1222","TA0005","N/A","N/A","Defense Evasion","https://github.com/helviojunior/hookchain","1","1","N/A","N/A","9","6","513","85","2025-01-05T22:00:17Z","2024-03-22T13:18:02Z","47114" +"*helviojunior/knowsmore*",".{0,1000}helviojunior\/knowsmore.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","1","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","47115" +"*Henkru/cs-token-vault*",".{0,1000}Henkru\/cs\-token\-vault.{0,1000}","offensive_tool_keyword","cobaltstrike","In-memory token vault BOF for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Henkru/cs-token-vault","1","1","N/A","N/A","10","10","142","25","2022-08-18T11:02:42Z","2022-07-29T17:50:10Z","47116" +"*henry-richard7/Browser-password-stealer*",".{0,1000}henry\-richard7\/Browser\-password\-stealer.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","1","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","47119" +"*hereiam.tuns.sh*",".{0,1000}hereiam\.tuns\.sh.{0,1000}","offensive_tool_keyword","sish","An open source serveo/ngrok alternative. HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH","T1572 - T1090.002","TA0010 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antoniomika/sish","1","1","N/A","N/A","10","10","4203","325","2025-04-10T20:04:08Z","2019-02-15T15:36:23Z","47122" +"*HernanRodriguez1/SharpBruteForceSSH*","HernanRodriguez1\/SharpBruteForceSSH","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","1","N/A","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","47124" +"*heroinn_client*",".{0,1000}heroinn_client.{0,1000}","offensive_tool_keyword","Heroinn","A cross platform C2/post-exploitation framework implementation by Rust.","T1027 - T1033 - T1055 - T1071 - T1082 - T1105 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/b23r0/Heroinn","1","1","N/A","N/A","10","10","672","215","2022-10-08T07:27:38Z","2015-05-16T14:54:19Z","47126" +"*heroinn_core*",".{0,1000}heroinn_core.{0,1000}","offensive_tool_keyword","Heroinn","A cross platform C2/post-exploitation framework implementation by Rust.","T1027 - T1033 - T1055 - T1071 - T1082 - T1105 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/b23r0/Heroinn","1","1","N/A","N/A","10","10","672","215","2022-10-08T07:27:38Z","2015-05-16T14:54:19Z","47127" +"*heroinn_ftp*",".{0,1000}heroinn_ftp.{0,1000}","offensive_tool_keyword","Heroinn","A cross platform C2/post-exploitation framework implementation by Rust.","T1027 - T1033 - T1055 - T1071 - T1082 - T1105 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/b23r0/Heroinn","1","1","N/A","N/A","10","10","672","215","2022-10-08T07:27:38Z","2015-05-16T14:54:19Z","47128" +"*heroinn_shell*",".{0,1000}heroinn_shell.{0,1000}","offensive_tool_keyword","Heroinn","A cross platform C2/post-exploitation framework implementation by Rust.","T1027 - T1033 - T1055 - T1071 - T1082 - T1105 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/b23r0/Heroinn","1","1","N/A","N/A","10","10","672","215","2022-10-08T07:27:38Z","2015-05-16T14:54:19Z","47129" +"*heroinn_util*",".{0,1000}heroinn_util.{0,1000}","offensive_tool_keyword","Heroinn","A cross platform C2/post-exploitation framework implementation by Rust.","T1027 - T1033 - T1055 - T1071 - T1082 - T1105 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/b23r0/Heroinn","1","1","N/A","N/A","10","10","672","215","2022-10-08T07:27:38Z","2015-05-16T14:54:19Z","47130" +"*HeroinnApp*",".{0,1000}HeroinnApp.{0,1000}","offensive_tool_keyword","Heroinn","A cross platform C2/post-exploitation framework implementation by Rust.","T1027 - T1033 - T1055 - T1071 - T1082 - T1105 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/b23r0/Heroinn","1","1","N/A","N/A","10","10","672","215","2022-10-08T07:27:38Z","2015-05-16T14:54:19Z","47131" +"*HeroinnProtocol*",".{0,1000}HeroinnProtocol.{0,1000}","offensive_tool_keyword","Heroinn","A cross platform C2/post-exploitation framework implementation by Rust.","T1027 - T1033 - T1055 - T1071 - T1082 - T1105 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/b23r0/Heroinn","1","1","N/A","N/A","10","10","672","215","2022-10-08T07:27:38Z","2015-05-16T14:54:19Z","47132" +"*HeroinnServerCommand*",".{0,1000}HeroinnServerCommand.{0,1000}","offensive_tool_keyword","Heroinn","A cross platform C2/post-exploitation framework implementation by Rust.","T1027 - T1033 - T1055 - T1071 - T1082 - T1105 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/b23r0/Heroinn","1","1","N/A","N/A","10","10","672","215","2022-10-08T07:27:38Z","2015-05-16T14:54:19Z","47133" +"*herrcore/LocalShellExtParse*",".{0,1000}herrcore\/LocalShellExtParse.{0,1000}","offensive_tool_keyword","LocalShellExtParse","Script to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User.","T1547.009 - T1129","TA0003 - TA0007","N/A","N/A","Discovery","https://github.com/herrcore/LocalShellExtParse","1","1","N/A","N/A","9","1","20","4","2015-06-08T16:55:38Z","2015-06-05T03:23:13Z","47134" +"*hfiref0x.github.io/Beacon/uac/exec*",".{0,1000}hfiref0x\.github\.io\/Beacon\/uac\/exec.{0,1000}","offensive_tool_keyword","UACME","Defeating Windows User Account Control by abusing built-in Windows AutoElevate backdoor.","T1548 - T1547 - T1218","TA0002 - TA0005 - TA0004","N/A","Evilnum","Defense Evasion","https://github.com/hfiref0x/UACME","1","1","N/A","N/A","10","10","6711","1348","2025-03-09T03:33:26Z","2015-03-28T12:04:33Z","47143" +"*hfiref0x/WDExtract*",".{0,1000}hfiref0x\/WDExtract.{0,1000}","offensive_tool_keyword","WDExtract","Extract Windows Defender database from vdm files and unpack it","T1059 - T1005 - T1119","TA0002 - TA0009 - TA0003","N/A","N/A","Defense Evasion","https://github.com/hfiref0x/WDExtract/","1","1","N/A","N/A","8","5","440","61","2020-02-10T06:53:43Z","2019-04-19T17:33:48Z","47145" +"*Hibr2Dmp.exe*",".{0,1000}Hibr2Dmp\.exe.{0,1000}","offensive_tool_keyword","Hibr2Dmp","Convert hiberfil.sys to a dump file with hibr2dmp (can be used with windbg to exploit lsass dump)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/mthcht/Purpleteam/blob/main/Simulation/Windows/System/dump_lsass_by_converting_hiberfil_to_dmp.ps1","1","1","N/A","N/A","N/A","2","184","19","2024-12-20T10:22:25Z","2022-12-05T12:40:02Z","47147" +"*Hidden.Desktop.mp4*",".{0,1000}Hidden\.Desktop\.mp4.{0,1000}","offensive_tool_keyword","cobaltstrike","Hidden Desktop (often referred to as HVNC) is a tool that allows operators to interact with a remote desktop session without the user knowing. The VNC protocol is not involved but the result is a similar experience. This Cobalt Strike BOF implementation was created as an alternative to TinyNuke/forks that are written in C++","T1021.001 - T1133","TA0005 - TA0002","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/WKL-Sec/HiddenDesktop","1","1","N/A","N/A","10","10","1213","187","2023-12-07T17:15:48Z","2023-05-21T00:57:43Z","47152" +"*HiddenDesktop.*",".{0,1000}HiddenDesktop\..{0,1000}","offensive_tool_keyword","cobaltstrike","Hidden Desktop (often referred to as HVNC) is a tool that allows operators to interact with a remote desktop session without the user knowing. The VNC protocol is not involved but the result is a similar experience. This Cobalt Strike BOF implementation was created as an alternative to TinyNuke/forks that are written in C++","T1021.001 - T1133","TA0005 - TA0002","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/WKL-Sec/HiddenDesktop","1","1","N/A","N/A","10","10","1213","187","2023-12-07T17:15:48Z","2023-05-21T00:57:43Z","47155" +"*HiddenDesktop.exe*",".{0,1000}HiddenDesktop\.exe.{0,1000}","offensive_tool_keyword","HVNC","Standalone HVNC Client & Server Coded in C++ (Modified Tinynuke)","T1021.005 - T1071 - T1563.002 - T1219","TA0001 - TA0002 - TA0008","N/A","N/A","RMM","https://github.com/Meltedd/HVNC","1","1","N/A","N/A","10","5","445","133","2025-03-27T21:20:10Z","2021-09-03T17:34:44Z","47157" +"*HiddenDesktop.x64.bin*",".{0,1000}HiddenDesktop\.x64\.bin.{0,1000}","offensive_tool_keyword","cobaltstrike","Hidden Desktop (often referred to as HVNC) is a tool that allows operators to interact with a remote desktop session without the user knowing. The VNC protocol is not involved but the result is a similar experience. This Cobalt Strike BOF implementation was created as an alternative to TinyNuke/forks that are written in C++","T1021.001 - T1133","TA0005 - TA0002","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/WKL-Sec/HiddenDesktop","1","1","N/A","N/A","10","10","1213","187","2023-12-07T17:15:48Z","2023-05-21T00:57:43Z","47158" +"*HiddenDesktop.x86.bin*",".{0,1000}HiddenDesktop\.x86\.bin.{0,1000}","offensive_tool_keyword","cobaltstrike","Hidden Desktop (often referred to as HVNC) is a tool that allows operators to interact with a remote desktop session without the user knowing. The VNC protocol is not involved but the result is a similar experience. This Cobalt Strike BOF implementation was created as an alternative to TinyNuke/forks that are written in C++","T1021.001 - T1133","TA0005 - TA0002","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/WKL-Sec/HiddenDesktop","1","1","N/A","N/A","10","10","1213","187","2023-12-07T17:15:48Z","2023-05-21T00:57:43Z","47159" +"*HiddenDesktop.zip*",".{0,1000}HiddenDesktop\.zip.{0,1000}","offensive_tool_keyword","cobaltstrike","Hidden Desktop (often referred to as HVNC) is a tool that allows operators to interact with a remote desktop session without the user knowing. The VNC protocol is not involved but the result is a similar experience. This Cobalt Strike BOF implementation was created as an alternative to TinyNuke/forks that are written in C++","T1021.001 - T1133","TA0005 - TA0002","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/WKL-Sec/HiddenDesktop","1","1","N/A","N/A","10","10","1213","187","2023-12-07T17:15:48Z","2023-05-21T00:57:43Z","47160" +"*hidden-tear-1-master.zip*",".{0,1000}hidden\-tear\-1\-master\.zip.{0,1000}","offensive_tool_keyword","hidden-tear","open source ransomware - many variant in the wild","T1486 - T1059 - T1485 - T1489 - T1070 - T1488","TA0005 - TA0009 - TA0040 - TA0042","N/A","N/A","Ransomware","https://github.com/goliate/hidden-tear","1","1","N/A","N/A","10","8","765","394","2020-07-08T22:34:01Z","2015-08-19T09:06:51Z","47164" +"*hidden-tear-decrypter.csproj*",".{0,1000}hidden\-tear\-decrypter\.csproj.{0,1000}","offensive_tool_keyword","hidden-tear","open source ransomware - many variant in the wild","T1486 - T1059 - T1485 - T1489 - T1070 - T1488","TA0005 - TA0009 - TA0040 - TA0042","N/A","N/A","Ransomware","https://github.com/goliate/hidden-tear","1","1","N/A","N/A","10","8","765","394","2020-07-08T22:34:01Z","2015-08-19T09:06:51Z","47165" +"*hidden-tear-decrypter.exe*",".{0,1000}hidden\-tear\-decrypter\.exe.{0,1000}","offensive_tool_keyword","hidden-tear","open source ransomware - many variant in the wild","T1486 - T1059 - T1485 - T1489 - T1070 - T1488","TA0005 - TA0009 - TA0040 - TA0042","N/A","N/A","Ransomware","https://github.com/goliate/hidden-tear","1","1","N/A","N/A","10","8","765","394","2020-07-08T22:34:01Z","2015-08-19T09:06:51Z","47166" +"*hidden-tear-decrypter.pdb*",".{0,1000}hidden\-tear\-decrypter\.pdb.{0,1000}","offensive_tool_keyword","hidden-tear","open source ransomware - many variant in the wild","T1486 - T1059 - T1485 - T1489 - T1070 - T1488","TA0005 - TA0009 - TA0040 - TA0042","N/A","N/A","Ransomware","https://github.com/goliate/hidden-tear","1","1","N/A","N/A","10","8","765","394","2020-07-08T22:34:01Z","2015-08-19T09:06:51Z","47167" +"*hidden-tear-master.zip*",".{0,1000}hidden\-tear\-master\.zip.{0,1000}","offensive_tool_keyword","hidden-tear","open source ransomware - many variant in the wild","T1486 - T1059 - T1485 - T1489 - T1070 - T1488","TA0005 - TA0009 - TA0040 - TA0042","N/A","N/A","Ransomware","https://github.com/goliate/hidden-tear","1","1","N/A","N/A","10","8","765","394","2020-07-08T22:34:01Z","2015-08-19T09:06:51Z","47168" +"*hidden-tear-remake.zip*",".{0,1000}hidden\-tear\-remake\.zip.{0,1000}","offensive_tool_keyword","hidden-tear","open source ransomware - many variant in the wild","T1486 - T1059 - T1485 - T1489 - T1070 - T1488","TA0005 - TA0009 - TA0040 - TA0042","N/A","N/A","Ransomware","https://github.com/goliate/hidden-tear","1","1","N/A","N/A","10","8","765","394","2020-07-08T22:34:01Z","2015-08-19T09:06:51Z","47169" +"*HiddenUser.ps1*",".{0,1000}HiddenUser\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","47170" +"*hijack_remote_thread*",".{0,1000}hijack_remote_thread.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","47176" +"*hijackCLSIDpersistence.*",".{0,1000}hijackCLSIDpersistence\..{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","47179" +"*HijackHunter.csproj*",".{0,1000}HijackHunter\.csproj.{0,1000}","offensive_tool_keyword","HijackHunter","Parses a target's PE header in order to find lined DLLs vulnerable to hijacking. Provides reasoning and abuse techniques for each detected hijack opportunity","T1574.002 - T1059.003 - T1078.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/matterpreter/OffensiveCSharp/tree/master/HijackHunter","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","47183" +"*HijackHunter.exe*",".{0,1000}HijackHunter\.exe.{0,1000}","offensive_tool_keyword","HijackHunter","Parses a target's PE header in order to find lined DLLs vulnerable to hijacking. Provides reasoning and abuse techniques for each detected hijack opportunity","T1574.002 - T1059.003 - T1078.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/matterpreter/OffensiveCSharp/tree/master/HijackHunter","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","47184" +"*HijackShellLib.dll*",".{0,1000}HijackShellLib\.dll.{0,1000}","offensive_tool_keyword","PrivFu","get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","KernelWritePoCs","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","47187" +"*HInvokeHashGen.cs*",".{0,1000}HInvokeHashGen\.cs.{0,1000}","offensive_tool_keyword","NixImports","A .NET malware loader using API-Hashing to evade static analysis","T1055.012 - T1562.001 - T1140","TA0005 - TA0003 - TA0040","N/A","N/A","Defense Evasion","https://github.com/dr4k0nia/NixImports","1","1","N/A","N/A","N/A","3","207","23","2023-05-30T14:14:21Z","2023-05-22T18:32:01Z","47189" +"*hiphp-0.3.4.deb*",".{0,1000}hiphp\-0\.3\.4\.deb.{0,1000}","offensive_tool_keyword","hiphp","The BackDoor of HIPHP gives you the power to control websites based on PHP using HTTP/HTTPS protocol. By sending files - tokens and commands through port 80s POST/GET method - users can access a range of activities such as downloading and editing files. It also allows for connecting to Tor networks with password protection for extra security.","T1105 - T1071.001 - T1132 - T1505 - T1608 - T1560 ","TA0011 - TA0001 - TA0002 - TA0009","N/A","N/A","C2","https://github.com/yasserbdj96/hiphp","1","1","N/A","N/A","10","10","217","33","2025-04-19T07:05:12Z","2021-04-05T20:29:57Z","47193" +"*hiphp-0.3.5.deb*",".{0,1000}hiphp\-0\.3\.5\.deb.{0,1000}","offensive_tool_keyword","hiphp","The BackDoor of HIPHP gives you the power to control websites based on PHP using HTTP/HTTPS protocol. By sending files - tokens and commands through port 80s POST/GET method - users can access a range of activities such as downloading and editing files. It also allows for connecting to Tor networks with password protection for extra security.","T1105 - T1071.001 - T1132 - T1505 - T1608 - T1560 ","TA0011 - TA0001 - TA0002 - TA0009","N/A","N/A","C2","https://github.com/yasserbdj96/hiphp","1","1","N/A","N/A","10","10","217","33","2025-04-19T07:05:12Z","2021-04-05T20:29:57Z","47194" +"*hiphp-0.3.6.deb*",".{0,1000}hiphp\-0\.3\.6\.deb.{0,1000}","offensive_tool_keyword","hiphp","The BackDoor of HIPHP gives you the power to control websites based on PHP using HTTP/HTTPS protocol. By sending files - tokens and commands through port 80s POST/GET method - users can access a range of activities such as downloading and editing files. It also allows for connecting to Tor networks with password protection for extra security.","T1105 - T1071.001 - T1132 - T1505 - T1608 - T1560 ","TA0011 - TA0001 - TA0002 - TA0009","N/A","N/A","C2","https://github.com/yasserbdj96/hiphp","1","1","N/A","N/A","10","10","217","33","2025-04-19T07:05:12Z","2021-04-05T20:29:57Z","47195" +"*hiphp-1.*.*.deb*",".{0,1000}hiphp\-1\..{0,1000}\..{0,1000}\.deb.{0,1000}","offensive_tool_keyword","hiphp","The BackDoor of HIPHP gives you the power to control websites based on PHP using HTTP/HTTPS protocol. By sending files - tokens and commands through port 80s POST/GET method - users can access a range of activities such as downloading and editing files. It also allows for connecting to Tor networks with password protection for extra security.","T1105 - T1071.001 - T1132 - T1505 - T1608 - T1560 ","TA0011 - TA0001 - TA0002 - TA0009","N/A","N/A","C2","https://github.com/yasserbdj96/hiphp","1","1","N/A","N/A","10","10","217","33","2025-04-19T07:05:12Z","2021-04-05T20:29:57Z","47196" +"*hiphp-cli.bat*",".{0,1000}hiphp\-cli\.bat.{0,1000}","offensive_tool_keyword","hiphp","The BackDoor of HIPHP gives you the power to control websites based on PHP using HTTP/HTTPS protocol. By sending files - tokens and commands through port 80s POST/GET method - users can access a range of activities such as downloading and editing files. It also allows for connecting to Tor networks with password protection for extra security.","T1105 - T1071.001 - T1132 - T1505 - T1608 - T1560 ","TA0011 - TA0001 - TA0002 - TA0009","N/A","N/A","C2","https://github.com/yasserbdj96/hiphp","1","1","N/A","N/A","10","10","217","33","2025-04-19T07:05:12Z","2021-04-05T20:29:57Z","47197" +"*hiphp-desktop.bat*",".{0,1000}hiphp\-desktop\.bat.{0,1000}","offensive_tool_keyword","hiphp","The BackDoor of HIPHP gives you the power to control websites based on PHP using HTTP/HTTPS protocol. By sending files - tokens and commands through port 80s POST/GET method - users can access a range of activities such as downloading and editing files. It also allows for connecting to Tor networks with password protection for extra security.","T1105 - T1071.001 - T1132 - T1505 - T1608 - T1560 ","TA0011 - TA0001 - TA0002 - TA0009","N/A","N/A","C2","https://github.com/yasserbdj96/hiphp","1","1","N/A","N/A","10","10","217","33","2025-04-19T07:05:12Z","2021-04-05T20:29:57Z","47198" +"*hiphp-termux.sh*",".{0,1000}hiphp\-termux\.sh.{0,1000}","offensive_tool_keyword","hiphp","The BackDoor of HIPHP gives you the power to control websites based on PHP using HTTP/HTTPS protocol. By sending files - tokens and commands through port 80s POST/GET method - users can access a range of activities such as downloading and editing files. It also allows for connecting to Tor networks with password protection for extra security.","T1105 - T1071.001 - T1132 - T1505 - T1608 - T1560 ","TA0011 - TA0001 - TA0002 - TA0009","N/A","N/A","C2","https://github.com/yasserbdj96/hiphp","1","1","N/A","N/A","10","10","217","33","2025-04-19T07:05:12Z","2021-04-05T20:29:57Z","47199" +"*hiphp-tk.bat*",".{0,1000}hiphp\-tk\.bat.{0,1000}","offensive_tool_keyword","hiphp","The BackDoor of HIPHP gives you the power to control websites based on PHP using HTTP/HTTPS protocol. By sending files - tokens and commands through port 80s POST/GET method - users can access a range of activities such as downloading and editing files. It also allows for connecting to Tor networks with password protection for extra security.","T1105 - T1071.001 - T1132 - T1505 - T1608 - T1560 ","TA0011 - TA0001 - TA0002 - TA0009","N/A","N/A","C2","https://github.com/yasserbdj96/hiphp","1","1","N/A","N/A","10","10","217","33","2025-04-19T07:05:12Z","2021-04-05T20:29:57Z","47200" +"*hivecust6vhekztbqgdnkks64ucehqacge3dij3gyrrpdp57zoq3ooqd.onion*",".{0,1000}hivecust6vhekztbqgdnkks64ucehqacge3dij3gyrrpdp57zoq3ooqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","47210" +"*HiveJack-Console.exe*",".{0,1000}HiveJack\-Console\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Erebus CobaltStrike post penetration testing plugin","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DeEpinGh0st/Erebus","1","1","N/A","N/A","10","10","1518","221","2021-10-28T06:20:51Z","2019-09-26T09:32:00Z","47211" +"*hiveleakdbtnp76ulyhi52eag6c6tyc3xw7ez7iqy6wc34gd2nekazyd.onion*",".{0,1000}hiveleakdbtnp76ulyhi52eag6c6tyc3xw7ez7iqy6wc34gd2nekazyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","47212" +"*HiwinCN/Htran*",".{0,1000}HiwinCN\/Htran.{0,1000}","offensive_tool_keyword","htran","proxies connections through intermediate hops and aids users in disguising their true geographical location. It can be used by adversaries to hide their location when interacting with the victim networks","T1055 - T1090 - T1014","TA0003 - TA0005 - TA0011","N/A","GALLIUM - APT10 - APT12 - Deep Panda - MenuPass","C2","https://github.com/HiwinCN/Htran","1","1","N/A","N/A","9","10","256","88","2021-04-25T09:57:46Z","2015-12-03T04:54:53Z","47213" +"*hktalent/scan4all*",".{0,1000}hktalent\/scan4all.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoC","T1595 - T1190 - T1068","TA0001 - TA0007 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","47236" +"*hktalent/scan4all*",".{0,1000}hktalent\/scan4all.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoCs - 23 kinds of application password crack - 7000+Web fingerprints - 146 protocols and 90000+ rules Port scanning - Fuzz - HW - awesome BugBounty","T1046 - T1210.001 - T1059 - T1082 - T1110","TA0007 - TA0001 - TA0009 - TA0002 - TA0004 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","47237" +"*hlldz/dazzleUP*",".{0,1000}hlldz\/dazzleUP.{0,1000}","offensive_tool_keyword","dazzleUP","A tool that detects the privilege escalation vulnerabilities caused by misconfigurations and missing updates in the Windows operating systems.","T1068 - T1088 - T1210 - T1210.002","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/hlldz/dazzleUP","1","1","N/A","N/A","9","5","490","69","2020-07-23T08:48:43Z","2020-07-21T21:06:46Z","47244" +"*hlldz/Phant0m*",".{0,1000}hlldz\/Phant0m.{0,1000}","offensive_tool_keyword","Phant0m","Windows Event Log Killer","T1070.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/hlldz/Phant0m","1","1","N/A","N/A","N/A","10","1781","301","2023-09-21T16:08:18Z","2017-05-02T17:19:30Z","47245" +"*hlldz/RefleXXion*",".{0,1000}hlldz\/RefleXXion.{0,1000}","offensive_tool_keyword","RefleXXion","RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks. it first collects the syscall numbers of the NtOpenFile. NtCreateSection. NtOpenSection and NtMapViewOfSection found in the LdrpThunkSignature array.","T1055.004 - T1562.004 - T1070.004","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/hlldz/RefleXXion","1","1","N/A","N/A","10","5","490","105","2022-01-25T17:06:21Z","2022-01-25T16:50:34Z","47246" +"*hmaverickadams/autoNTDS*",".{0,1000}hmaverickadams\/autoNTDS.{0,1000}","offensive_tool_keyword","autoNTDS","autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat","T1003 - T1059 - T1021.002 - T1213","TA0006 - TA0008 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/hmaverickadams/autoNTDS","1","1","N/A","N/A","10","2","109","14","2023-10-31T22:03:58Z","2023-10-30T23:10:58Z","47247" +"*hoangprod/AndrewSpecial*",".{0,1000}hoangprod\/AndrewSpecial.{0,1000}","offensive_tool_keyword","AndrewSpecial","AndrewSpecial - dumping lsass memory stealthily","T1003.001 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/hoangprod/AndrewSpecial","1","1","N/A","N/A","10","4","386","98","2019-06-02T02:49:28Z","2019-01-18T19:12:09Z","47251" +"*Hoaxshell.exe*",".{0,1000}Hoaxshell\.exe.{0,1000}","offensive_tool_keyword","hoaxshell","An unconventional Windows reverse shell. currently undetected by Microsoft Defender and various other AV solutions. solely based on http(s) traffic","T1059 - T1071 - T1071.001 - T1203","TA0002 - TA0011","N/A","N/A","C2","https://github.com/t3l3machus/hoaxshell","1","1","N/A","N/A","N/A","10","3212","499","2025-01-19T12:29:35Z","2022-07-10T15:36:24Z","47253" +"*hoaxshell.py*",".{0,1000}hoaxshell\.py.{0,1000}","offensive_tool_keyword","hoaxshell","An unconventional Windows reverse shell. currently undetected by Microsoft Defender and various other AV solutions. solely based on http(s) traffic","T1059 - T1071 - T1071.001 - T1203","TA0002 - TA0011","N/A","N/A","C2","https://github.com/t3l3machus/hoaxshell","1","1","N/A","N/A","N/A","10","3212","499","2025-01-19T12:29:35Z","2022-07-10T15:36:24Z","47254" +"*hoaxshell-listener.py*",".{0,1000}hoaxshell\-listener\.py.{0,1000}","offensive_tool_keyword","hoaxshell","An unconventional Windows reverse shell. currently undetected by Microsoft Defender and various other AV solutions. solely based on http(s) traffic","T1059 - T1071 - T1071.001 - T1203","TA0002 - TA0011","N/A","N/A","C2","https://github.com/t3l3machus/hoaxshell","1","1","N/A","N/A","N/A","10","3212","499","2025-01-19T12:29:35Z","2022-07-10T15:36:24Z","47255" +"*holehe-master.*",".{0,1000}holehe\-master\..{0,1000}","offensive_tool_keyword","holehe","holehe allows you to check if the mail is used on different sites like twitter instagram and will retrieve information on sites with the forgotten password function.","T1598.004 - T1592.002 - T1598.001","TA0003 - TA0009","N/A","N/A","Reconnaissance","https://github.com/megadose/holehe","1","1","#linux","N/A","6","10","8656","981","2024-09-10T20:24:32Z","2020-06-25T23:03:02Z","47259" +"*hookedbrowsers.rb*",".{0,1000}hookedbrowsers\.rb.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","47266" +"*hook-infection_monkey.exploit.py*",".{0,1000}hook\-infection_monkey\.exploit\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","47267" +"*hook-infection_monkey.network.py*",".{0,1000}hook\-infection_monkey\.network\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","47268" +"*hook-infection_monkey.post_breach.actions.py*",".{0,1000}hook\-infection_monkey\.post_breach\.actions\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","47269" +"*hook-infection_monkey.post_breach.py*",".{0,1000}hook\-infection_monkey\.post_breach\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","47270" +"*hook-infection_monkey.ransomware.py*",".{0,1000}hook\-infection_monkey\.ransomware\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","47271" +"*hook-infection_monkey.system_info.collectors.py*",".{0,1000}hook\-infection_monkey\.system_info\.collectors\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","47272" +"*hook-lsassy.py*",".{0,1000}hook\-lsassy\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","47273" +"*hook-lsassy.py*",".{0,1000}hook\-lsassy\.py.{0,1000}","offensive_tool_keyword","crackmapexec","hook script for lsassy from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","47274" +"*hook-lsassy.py*",".{0,1000}hook\-lsassy\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Exploitation tool","https://github.com/byt3bl33d3r/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","47275" +"*hook-lsassy.py*",".{0,1000}hook\-lsassy\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","47276" +"*hook-pypsrp.py*",".{0,1000}hook\-pypsrp\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","47277" +"*hook-pypykatz.py*",".{0,1000}hook\-pypykatz\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","47278" +"*HostEnum.ps1*",".{0,1000}HostEnum\.ps1.{0,1000}","offensive_tool_keyword","red-team-scripts","script comprised of multiple system enumeration / situational awareness techniques collected over time. If system is a member of a Windows domain. it can also perform limited domain enumeration with the -Domain switch","T1016 - T1087.001 - T1049 - T1069","TA0007 - TA0003 - TA0006","N/A","N/A","Discovery","https://github.com/threatexpress/red-team-scripts","1","1","N/A","N/A","N/A","10","1122","195","2024-11-19T19:39:01Z","2017-05-01T13:53:05Z","47285" +"*HostExploiter.py*",".{0,1000}HostExploiter\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","47286" +"*HostingCLR_inject*",".{0,1000}HostingCLR_inject.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","47287" +"*HostingCLRx64.dll*",".{0,1000}HostingCLRx64\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","47288" +"*hotnops.gitbook.io/gtunnel*",".{0,1000}hotnops\.gitbook\.io\/gtunnel.{0,1000}","offensive_tool_keyword","gTunnel","tunelling solution written in golang","T1573.002 - T1071 - T1090 - T1105 - T1020","TA0005 - TA0010 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hotnops/gTunnel","1","1","N/A","N/A","10","10","266","49","2023-05-17T05:24:58Z","2020-03-09T02:52:48Z","47290" +"*hotnops/gTunnel*",".{0,1000}hotnops\/gTunnel.{0,1000}","offensive_tool_keyword","gTunnel","tunelling solution written in golang","T1573.002 - T1071 - T1090 - T1105 - T1020","TA0005 - TA0010 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hotnops/gTunnel","1","1","N/A","N/A","10","10","266","49","2023-05-17T05:24:58Z","2020-03-09T02:52:48Z","47291" +"*houqingv1.0.zip*",".{0,1000}houqingv1\.0\.zip.{0,1000}","offensive_tool_keyword","cobaltstrike","Hou Qing-Advanced AV Evasion Tool For Red Team Ops","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Hangingsword/HouQing","1","1","N/A","N/A","10","10","205","60","2021-01-14T08:38:12Z","2021-01-14T07:13:21Z","47292" +"*How-to-bypass-UAC-in-newer-Windows-versions.html*",".{0,1000}How\-to\-bypass\-UAC\-in\-newer\-Windows\-versions\.html.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","47296" +"*hpe_sim_76_amf_deserialization*",".{0,1000}hpe_sim_76_amf_deserialization.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","47298" +"*hpoo4dosa3x4ognfxpqcrjwnsigvslm7kv6hvmhh2yqczaxy3j6qnwad.onion*",".{0,1000}hpoo4dosa3x4ognfxpqcrjwnsigvslm7kv6hvmhh2yqczaxy3j6qnwad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","47303" +"*HRShell*client.py*",".{0,1000}HRShell.{0,1000}client\.py.{0,1000}","offensive_tool_keyword","HRShell","HRShell is an HTTPS/HTTP reverse shell built with flask. It is an advanced C2 server with many features & capabilities.","T1021.002 - T1105 - T1059.001 - T1059.003 - T1064","TA0008 - TA0011 - TA0002","N/A","Black Basta","C2","https://github.com/chrispetrou/HRShell","1","1","N/A","N/A","10","10","247","70","2021-09-09T08:26:32Z","2019-08-20T15:24:46Z","47305" +"*HRShell*server.py*",".{0,1000}HRShell.{0,1000}server\.py.{0,1000}","offensive_tool_keyword","HRShell","HRShell is an HTTPS/HTTP reverse shell built with flask. It is an advanced C2 server with many features & capabilities.","T1021.002 - T1105 - T1059.001 - T1059.003 - T1064","TA0008 - TA0011 - TA0002","N/A","Black Basta","C2","https://github.com/chrispetrou/HRShell","1","1","N/A","N/A","10","10","247","70","2021-09-09T08:26:32Z","2019-08-20T15:24:46Z","47306" +"*hta_evasion.hta*",".{0,1000}hta_evasion\.hta.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","47307" +"*HtaPowershellGenerator.*",".{0,1000}HtaPowershellGenerator\..{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","47308" +"*hta-to-javascript-crypter*",".{0,1000}hta\-to\-javascript\-crypter.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","47309" +"*HtaVBSGenerator.*",".{0,1000}HtaVBSGenerator\..{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","47310" +"*htdigest2john.py*",".{0,1000}htdigest2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","47311" +"*html/js/beacons.js*",".{0,1000}html\/js\/beacons\.js.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","47313" +"*html/scripts/merlin.js*",".{0,1000}html\/scripts\/merlin\.js.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","47314" +"*Html-Injection-Payloads.*",".{0,1000}Html\-Injection\-Payloads\..{0,1000}","offensive_tool_keyword","Offensive-Payloads","List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.","T1210 - T1185 - T1059 - T1400 - T1506 - T1213 ","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/InfoSecWarrior/Offensive-Payloads/","1","1","N/A","N/A","N/A","4","328","117","2024-09-20T09:59:28Z","2022-11-18T09:43:41Z","47315" +"*Html-Injection-Read-File-Payloads.*",".{0,1000}Html\-Injection\-Read\-File\-Payloads\..{0,1000}","offensive_tool_keyword","Offensive-Payloads","List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.","T1210 - T1185 - T1059 - T1400 - T1506 - T1213 ","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/InfoSecWarrior/Offensive-Payloads/","1","1","N/A","N/A","N/A","4","328","117","2024-09-20T09:59:28Z","2022-11-18T09:43:41Z","47316" +"*HTMLSmuggler-main*",".{0,1000}HTMLSmuggler\-main.{0,1000}","offensive_tool_keyword","HTMLSmuggler","HTML Smuggling generator&obfuscator for your Red Team operations","T1564.001 - T1027 - T1566","TA0005","N/A","N/A","Phishing","https://github.com/D00Movenok/HTMLSmuggler","1","1","N/A","N/A","10","2","162","19","2024-02-27T23:03:55Z","2023-07-02T08:10:59Z","47317" +"*htrgouvea/nipe*",".{0,1000}htrgouvea\/nipe.{0,1000}","offensive_tool_keyword","nipe","An engine to make Tor network your default gateway","T1090 - T1095 - T1573","TA0005","N/A","N/A","Defense Evasion","https://github.com/GouveaHeitor/nipe","1","1","N/A","N/A","9","10","2029","321","2025-04-03T13:57:13Z","2015-09-07T18:47:10Z","47328" +"*htrgouvea/nipe*",".{0,1000}htrgouvea\/nipe.{0,1000}","offensive_tool_keyword","nipe","An engine to make Tor Network your default gateway.","T1560 - T1573 - T1578","TA0005 - TA0007","N/A","N/A","Data Exfiltration","https://github.com/htrgouvea/nipe","1","1","N/A","N/A","N/A","10","2029","321","2025-04-03T13:57:13Z","2015-09-07T18:47:10Z","47329" +"*htshells-master*",".{0,1000}htshells\-master.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","47330" +"*http*/127.0.0.1*:1337*",".{0,1000}http.{0,1000}\/127\.0\.0\.1.{0,1000}\:1337.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","47333" +"*http*/alertmsg.zip*",".{0,1000}http.{0,1000}\/alertmsg\.zip.{0,1000}","offensive_tool_keyword","Jasmin-Ransomware","Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks","T1486","TA0040 - TA0002 - TA0010","N/A","N/A","Ransomware","https://github.com/codesiddhant/Jasmin-Ransomware","1","1","N/A","N/A","10","3","252","80","2021-03-01T14:51:06Z","2021-02-27T07:09:08Z","47335" +"*http*/charlotte.dll*",".{0,1000}http.{0,1000}\/charlotte\.dll.{0,1000}","offensive_tool_keyword","charlotte","c++ fully undetected shellcode launcher","T1055.012 - T1059.003 - T1027.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/9emin1/charlotte","1","1","N/A","N/A","10","10","976","211","2021-06-11T04:44:18Z","2021-05-13T07:32:03Z","47336" +"*http*/demon.dll",".{0,1000}http.{0,1000}\/demon\.dll","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47337" +"*http*/demon.exe",".{0,1000}http.{0,1000}\/demon\.exe","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","47338" +"*http*/demos/butcher/index.html*",".{0,1000}http.{0,1000}\/demos\/butcher\/index\.html.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","47339" +"*http*/john/Test/raw/master/*",".{0,1000}http.{0,1000}\/john\/Test\/raw\/master\/.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","47340" +"*http*/localhost*:1337*",".{0,1000}http.{0,1000}\/localhost.{0,1000}\:1337.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","47341" +"*http*/zha0gongz1*",".{0,1000}http.{0,1000}\/zha0gongz1.{0,1000}","offensive_tool_keyword","cobaltstrike","Implement load Cobalt Strike & Metasploit&Sliver shellcode with golang","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/zha0gongz1/DesertFox","1","1","N/A","N/A","10","10","125","26","2023-02-02T07:02:12Z","2021-02-04T09:04:13Z","47342" +"*http*://*/Terminator.sys",".{0,1000}http.{0,1000}\:\/\/.{0,1000}\/Terminator\.sys","offensive_tool_keyword","SharpTerminator","Terminate AV/EDR Processes using kernel driver","T1055.003 - T1547.001 - T1053.005 - T1091 - T1014 - T1053.006 - T1053.004 - T1112 - T1112.001","TA0007 - TA0008 - TA0006 - TA0002","N/A","N/A","Exploitation tool","https://github.com/mertdas/SharpTerminator","1","1","N/A","N/A","10","4","341","66","2023-06-12T00:38:54Z","2023-06-11T06:35:51Z","47343" +"*http*://127.0.0.1:4433*",".{0,1000}http.{0,1000}\:\/\/127\.0\.0\.1\:4433.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","47344" +"*http*://127.0.0.1:5556*",".{0,1000}http.{0,1000}\:\/\/127\.0\.0\.1\:5556.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","47345" +"*http*://localhost:4433*",".{0,1000}http.{0,1000}\:\/\/localhost\:4433.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","47346" +"*http*://localhost:5556*",".{0,1000}http.{0,1000}\:\/\/localhost\:5556.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","47347" +"*http*:3000/hook.js*",".{0,1000}http.{0,1000}\:3000\/hook\.js.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","47348" +"*http*:3200/manjusaka*",".{0,1000}http.{0,1000}\:3200\/manjusaka.{0,1000}","offensive_tool_keyword","cobaltstrike","Chinese clone of cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/YDHCUI/manjusaka","1","1","N/A","N/A","10","10","818","150","2023-05-09T03:31:53Z","2022-03-18T08:16:04Z","47349" +"*http*:801/bq1iFEP2*",".{0,1000}http.{0,1000}\:801\/bq1iFEP2.{0,1000}","offensive_tool_keyword","cobaltstrike","Chinese clone of cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/YDHCUI/manjusaka","1","1","N/A","N/A","10","10","818","150","2023-05-09T03:31:53Z","2022-03-18T08:16:04Z","47350" +"*http*127.0.0.1:21802*",".{0,1000}http.{0,1000}127\.0\.0\.1\:21802.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","47351" +"*http*127.0.0.1:3030*",".{0,1000}http.{0,1000}127\.0\.0\.1\:3030.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","47352" +"*http*127.0.0.1:5000*",".{0,1000}http.{0,1000}127\.0\.0\.1\:5000.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","47353" +"*http*127.0.0.1:50050*",".{0,1000}http.{0,1000}127\.0\.0\.1\:50050.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","47354" +"*http*127.0.0.1:5096*",".{0,1000}http.{0,1000}127\.0\.0\.1\:5096.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","47355" +"*http*127.0.0.1:57230*",".{0,1000}http.{0,1000}127\.0\.0\.1\:57230.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","47356" +"*http*127.0.0.1:7096*",".{0,1000}http.{0,1000}127\.0\.0\.1\:7096.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","47357" +"*http*127.0.0.1:8080/*.dll*",".{0,1000}http.{0,1000}127\.0\.0\.1\:8080\/.{0,1000}\.dll.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","47358" +"*http*127.0.0.1:8080/*.exe*",".{0,1000}http.{0,1000}127\.0\.0\.1\:8080\/.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","47359" +"*http*127.0.0.1:8080/*.ps1*",".{0,1000}http.{0,1000}127\.0\.0\.1\:8080\/.{0,1000}\.ps1.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","47360" +"*http*127.0.0.1:9631*",".{0,1000}http.{0,1000}127\.0\.0\.1\:9631.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","47361" +"*http*localhost:21802*",".{0,1000}http.{0,1000}localhost\:21802.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","47363" +"*http*localhost:3030*",".{0,1000}http.{0,1000}localhost\:3030.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","47364" +"*http*localhost:5000*",".{0,1000}http.{0,1000}localhost\:5000.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","47365" +"*http*localhost:50050*",".{0,1000}http.{0,1000}localhost\:50050.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","47366" +"*http*localhost:5096*",".{0,1000}http.{0,1000}localhost\:5096.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","47367" +"*http*localhost:57230*",".{0,1000}http.{0,1000}localhost\:57230.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","47368" +"*http*localhost:7096*",".{0,1000}http.{0,1000}localhost\:7096.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","47369" +"*http*localhost:9631*",".{0,1000}http.{0,1000}localhost\:9631.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","47370" +"*http://*.oast.fun/*",".{0,1000}http\:\/\/.{0,1000}\.oast\.fun\/.{0,1000}","offensive_tool_keyword","burpsuite","domains used by burp collaborator - abused for payload callback","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","FP Risk","9","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","47376" +"*http://*.oast.live/*",".{0,1000}http\:\/\/.{0,1000}\.oast\.live\/.{0,1000}","offensive_tool_keyword","burpsuite","domains used by burp collaborator - abused for payload callback","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","FP Risk","9","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","47377" +"*http://*.oast.me/*",".{0,1000}http\:\/\/.{0,1000}\.oast\.me\/.{0,1000}","offensive_tool_keyword","burpsuite","domains used by burp collaborator - abused for payload callback","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","FP Risk","9","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","47378" +"*http://*.oast.online/*",".{0,1000}http\:\/\/.{0,1000}\.oast\.online\/.{0,1000}","offensive_tool_keyword","burpsuite","domains used by burp collaborator - abused for payload callback","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","FP Risk","9","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","47379" +"*http://*.oast.pro/*",".{0,1000}http\:\/\/.{0,1000}\.oast\.pro\/.{0,1000}","offensive_tool_keyword","burpsuite","domains used by burp collaborator - abused for payload callback","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","FP Risk","9","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","47380" +"*http://*.oast.site/*",".{0,1000}http\:\/\/.{0,1000}\.oast\.site\/.{0,1000}","offensive_tool_keyword","burpsuite","domains used by burp collaborator - abused for payload callback","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","FP Risk","9","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","47381" +"*http://*.oastify.com/*",".{0,1000}http\:\/\/.{0,1000}\.oastify\.com\/.{0,1000}","offensive_tool_keyword","burpsuite","domains used by burp collaborator - abused for payload callback","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","FP Risk","9","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","47382" +"*http://*.onion*",".{0,1000}[a-z0-9]{16,56}\.(onion|tor2web|torlink).{0,1000}","offensive_tool_keyword","torproject","Detects suspicious TOR usage which anonymizes user's web traffic through a relay network","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","47383" +"*http://*.tor2web*",".{0,1000}[a-z0-9]{16,56}\.(onion|tor2web|torlink).{0,1000}","offensive_tool_keyword","torproject","Detects suspicious TOR usage which anonymizes user's web traffic through a relay network","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","47388" +"*http://*.torlink*",".{0,1000}[a-z0-9]{16,56}\.(onion|tor2web|torlink).{0,1000}","offensive_tool_keyword","torproject","Detects suspicious TOR usage which anonymizes user's web traffic through a relay network","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","47389" +"*http://*/FortyNorth/GetIt*",".{0,1000}http\:\/\/.{0,1000}\/FortyNorth\/GetIt.{0,1000}","offensive_tool_keyword","FunctionalC2","A small POC of using Azure Functions to relay communications","T1021.006 - T1132.002 - T1071.001","TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/FortyNorthSecurity/FunctionalC2","1","1","N/A","N/A","10","10","74","17","2023-03-30T20:27:38Z","2020-03-12T17:54:50Z","47395" +"*http://*/FortyNorth/PostIt*",".{0,1000}http\:\/\/.{0,1000}\/FortyNorth\/PostIt.{0,1000}","offensive_tool_keyword","FunctionalC2","A small POC of using Azure Functions to relay communications","T1021.006 - T1132.002 - T1071.001","TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/FortyNorthSecurity/FunctionalC2","1","1","N/A","N/A","10","10","74","17","2023-03-30T20:27:38Z","2020-03-12T17:54:50Z","47396" +"*http://*:*/down/*/host.ps1*",".{0,1000}http\:\/\/.{0,1000}\:.{0,1000}\/down\/.{0,1000}\/host\.ps1.{0,1000}","offensive_tool_keyword","PickleC2","PickleC2 is a post-exploitation and Lateral Movements framework","T1059.006 - T1021 - T1071 - T1550 - T1560 - T1570","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/xRET2pwn/PickleC2","1","1","N/A","N/A","10","10","91","20","2021-07-26T21:12:04Z","2021-07-13T09:16:19Z","47397" +"*http://*Microsoft.ActiveDirectory.Management.dll*",".{0,1000}http\:\/\/.{0,1000}Microsoft\.ActiveDirectory\.Management\.dll.{0,1000}","offensive_tool_keyword","powershell","redteam technique - import the ActiveDirectory module without the need to install it on the current computer - the dll has been extracted from a Windows 10 x64 with RSAT installed","T1110.001 - T1110.003 - T1110.004","TA0006","N/A","N/A","Credential Access","https://github.com/mthcht/Purpleteam/blob/main/Simulation/Windows/ActiveDirectory/Bruteforce.ps1","1","1","N/A","N/A","N/A","2","184","19","2024-12-20T10:22:25Z","2022-12-05T12:40:02Z","47399" +"*http://0hRIb4t1fWNPYBVA.net/index.php*",".{0,1000}http\:\/\/0hRIb4t1fWNPYBVA\.net\/index\.php.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","47400" +"*http://0x0.st/tm*",".{0,1000}http\:\/\/0x0\.st\/tm.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","1","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","47401" +"*http://101.251.217.210*",".{0,1000}http\:\/\/101\.251\.217\.210.{0,1000}","offensive_tool_keyword","evil-proxy","A ruby http/https proxy to do EVIL things","T1557 - T1110.001 - T1563.001","TA0006 - TA0001 - TA0009 - TA0040","N/A","N/A","Phishing","https://github.com/bbtfr/evil-proxy","1","1","N/A","N/A","9","2","172","96","2023-10-30T07:49:40Z","2015-07-30T01:54:40Z","47403" +"*http://127.0.0.1*/nlaksnfaobcaowb*",".{0,1000}http\:\/\/127\.0\.0\.1.{0,1000}\/nlaksnfaobcaowb.{0,1000}","offensive_tool_keyword","FudgeC2","FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.","T1021.002 - T1105 - T1059.001 - T1059.003","TA0008 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/Ziconius/FudgeC2","1","1","N/A","N/A","10","10","253","54","2023-05-01T21:13:56Z","2018-09-09T21:05:21Z","47404" +"*http://127.0.0.1/CrossC2*",".{0,1000}http\:\/\/127\.0\.0\.1\/CrossC2.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","47405" +"*http://127.0.0.1/FUZZ*",".{0,1000}http\:\/\/127\.0\.0\.1\/FUZZ.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","47406" +"*http://127.0.0.1/handshake.php*",".{0,1000}http\:\/\/127\.0\.0\.1\/handshake\.php.{0,1000}","offensive_tool_keyword","Jasmin-Ransomware","Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks","T1486","TA0040 - TA0002 - TA0010","N/A","N/A","Ransomware","https://github.com/codesiddhant/Jasmin-Ransomware","1","1","N/A","N/A","10","3","252","80","2021-03-01T14:51:06Z","2021-02-27T07:09:08Z","47407" +"*http://127.0.0.1/ntdll.dll*",".{0,1000}http\:\/\/127\.0\.0\.1\/ntdll\.dll.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","1","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","47408" +"*http://127.0.0.1/proxy.php*",".{0,1000}http\:\/\/127\.0\.0\.1\/proxy\.php.{0,1000}","offensive_tool_keyword","C2ReverseProxy","ReverseProxy C2 - Bring CS online without going offline","T1090 - T1090.002 - T1573 - T1573.001 - T1573.002","TA0011","N/A","N/A","C2","https://github.com/Daybr4ak/C2ReverseProxy","1","1","N/A","N/A","10","10","486","56","2023-04-26T13:16:26Z","2020-01-16T05:43:35Z","47409" +"*http://127.0.0.1/rat/*",".{0,1000}http\:\/\/127\.0\.0\.1\/rat\/.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","47410" +"*http://127.0.0.1/Renge_x64.exe*",".{0,1000}http\:\/\/127\.0\.0\.1\/Renge_x64\.exe.{0,1000}","offensive_tool_keyword","OffensiveLua","Offensive Lua is a collection of offensive security scripts written in Lua with FFI","T1059 - T1218.011 - T1105 - T1021.002 - T1564.001 - T1112 - T1113 - T1204.002 - T1547.002","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hackerhouse-opensource/OffensiveLua","1","1","N/A","N/A","8","2","184","25","2023-11-17T00:35:10Z","2023-10-25T17:21:13Z","47411" +"*http://127.0.0.1/shell.jsp*",".{0,1000}http\:\/\/127\.0\.0\.1\/shell\.jsp.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","47412" +"*http://127.0.0.1:3000/ui/panel*",".{0,1000}http\:\/\/127\.0\.0\.1\:3000\/ui\/panel.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","47416" +"*http://127.0.0.1:35000*",".{0,1000}http\:\/\/127\.0\.0\.1\:35000.{0,1000}","offensive_tool_keyword","evilqr","Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice","T1566.002 - T1204.001 - T1192","TA0001 - TA0005","N/A","N/A","Phishing","https://github.com/kgretzky/evilqr","1","1","N/A","N/A","N/A","3","292","45","2024-06-18T11:27:23Z","2023-06-20T12:58:09Z","47418" +"*http://127.0.0.1:443/aaaaaaaaa*",".{0,1000}http\:\/\/127\.0\.0\.1\:443\/aaaaaaaaa.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","47422" +"*http://127.0.0.1:443/bbbbbbbbb*",".{0,1000}http\:\/\/127\.0\.0\.1\:443\/bbbbbbbbb.{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","47423" +"*http://127.0.0.1:50000/payload/upload*",".{0,1000}http\:\/\/127\.0\.0\.1\:50000\/payload\/upload.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","47424" +"*http://127.0.0.1:7444*",".{0,1000}http\:\/\/127\.0\.0\.1\:7444.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","47425" +"*http://127.0.0.1:7474/browser/*",".{0,1000}http\:\/\/127\.0\.0\.1\:7474\/browser\/.{0,1000}","offensive_tool_keyword","BloodHound","A Python based ingestor for BloodHound","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/fox-it/BloodHound.py","1","1","N/A","neo4j default local url","10","10","2088","343","2025-03-28T11:19:13Z","2018-02-26T14:44:20Z","47426" +"*http://127.0.0.1:80/file.exe*",".{0,1000}http\:\/\/127\.0\.0\.1\:80\/file\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","47427" +"*http://127.0.0.1:8070*",".{0,1000}http\:\/\/127\.0\.0\.1\:8070.{0,1000}","offensive_tool_keyword","WebSocketReverseShellDotNet","A .NET-based Reverse Shell, it establishes a link to the command and control for subsequent guidance.","T1071 - T1105","TA0011 - TA0002","N/A","N/A","C2","https://github.com/The-Hustler-Hattab/WebSocketReverseShellDotNet","1","1","N/A","N/A","10","10","1","0","2024-04-18T01:00:48Z","2023-12-03T03:35:24Z","47430" +"*http://127.0.0.1:8080/invoker/JMXInvokerServlet*",".{0,1000}http\:\/\/127\.0\.0\.1\:8080\/invoker\/JMXInvokerServlet.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","47431" +"*http://127.0.0.1:8080/shellcode.bin*",".{0,1000}http\:\/\/127\.0\.0\.1\:8080\/shellcode\.bin.{0,1000}","offensive_tool_keyword","Rust-for-Malware-Development","malware development using Rust","T1055.001 - T1027 - T1204 - T1518 - T1056 - T1021 - T1587/001","TA0005 - TA0003 - TA0007 - TA0009 - TA0004 - TA0008 - TA0042","N/A","N/A","Exploitation tool","https://github.com/Whitecat18/Rust-for-Malware-Development","1","1","N/A","N/A","8","10","2123","53","2025-04-22T18:09:57Z","2024-02-12T16:55:06Z","47432" +"*http://127.0.0.1:8080/target.dll*",".{0,1000}http\:\/\/127\.0\.0\.1\:8080\/target\.dll.{0,1000}","offensive_tool_keyword","winsos-poc","A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.","T1574.002","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/thiagopeixoto/winsos-poc","1","1","N/A","N/A","10","2","111","26","2024-03-10T22:15:50Z","2024-03-10T21:35:08Z","47433" +"*http://127.0.0.1:81/test.exe*",".{0,1000}http\:\/\/127\.0\.0\.1\:81\/test\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","47434" +"*http://127.0.0.1:9090/*",".{0,1000}http\:\/\/127\.0\.0\.1\:9090\/.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","47436" +"*http://161.35.200.18*",".{0,1000}http\:\/\/161\.35\.200\.18.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","47438" +"*http://192.168.1.179:8000/session*",".{0,1000}http\:\/\/192\.168\.1\.179\:8000\/session.{0,1000}","offensive_tool_keyword","CloakNDaggerC2","A C2 framework designed around the use of public/private RSA key pairs to sign and authenticate commands being executed. This prevents MiTM interception of calls and ensures opsec during delicate operations.","T1090 - T1090.003 - T1071 - T1071.001 - T1553 - T1553.002","TA0011 - TA0042 - TA0003","N/A","N/A","C2","https://github.com/matt-culbert/CloakNDaggerC2","1","1","N/A","N/A","10","10","17","3","2024-10-09T15:36:46Z","2023-04-28T01:58:18Z","47439" +"*http://192.168.126.130/upload.php*",".{0,1000}http\:\/\/192\.168\.126\.130\/upload\.php.{0,1000}","offensive_tool_keyword","Tsunami","another C2 framework","T1573 - T1027 - T1059 - T1071 ","TA0011 - TA0009 - TA0003 - TA0007 - TA0008","N/A","N/A","C2","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","47440" +"*http://212.111.43.206:9090/pk.html*",".{0,1000}http\:\/\/212\.111\.43\.206\:9090\/pk\.html.{0,1000}","offensive_tool_keyword","ruler","A tool to abuse Exchange services","T1087 - T1110 - T1133 - T1064 - T1204","TA0007 - TA0006 - TA0003 - TA0002 - TA0005","N/A","APT33","Persistence","https://github.com/sensepost/ruler","1","1","N/A","N/A","10","10","2222","362","2024-06-10T11:03:07Z","2016-08-18T15:05:13Z","47441" +"*http://37.120.235.188/blah.tar.gz*",".{0,1000}http\:\/\/37\.120\.235\.188\/blah\.tar\.gz.{0,1000}","offensive_tool_keyword","hackshell","Make BASH stealthy and hacker friendly with lots of bash functions","T1070.003 - T1059.004 - T1564.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/hackerschoice/hackshell","1","1","N/A","N/A","9","3","251","28","2025-04-21T11:23:41Z","2024-07-16T15:56:11Z","47442" +"*http://3wifi.stascorp.com/3wifi.php*",".{0,1000}http\:\/\/3wifi\.stascorp\.com\/3wifi\.php.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","1","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","47443" +"*http://adzok.net/downloadfree.php*",".{0,1000}http\:\/\/adzok\.net\/downloadfree\.php.{0,1000}","offensive_tool_keyword","Adzok","RAT tool - a variant of Adwind abused by TA","T1219 - T1105 - T1027 - T1059 - T1204","TA0011 - TA0005 - TA0002 - TA0008","N/A","Packrat","Malware","https://sourceforge.net/projects/adzok/files/Adzok_Open_v1.0.0.2.jar/download","1","1","N/A","N/A","8","8","N/A","N/A","N/A","N/A","47444" +"*http://bit.ly/1qMn59d*",".{0,1000}http\:\/\/bit\.ly\/1qMn59d.{0,1000}","offensive_tool_keyword","Arbitrium-RAT","cross-platform fully undetectable remote access trojan to control Android Windows and Linux","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","N/A","Malware","https://github.com/im-hanzou/Arbitrium-RAT","1","1","N/A","N/A","10","4","355","309","2021-01-15T23:21:13Z","2021-01-16T03:03:11Z","47448" +"*http://bit.ly/2TxpA4h*",".{0,1000}http\:\/\/bit\.ly\/2TxpA4h.{0,1000}","offensive_tool_keyword","spoofing-office-macro","PoC of a VBA macro spawning a process with a spoofed parent and command line","T1055.011 - T1127 - T1077","TA0005 - TA0003","N/A","N/A","Sniffing & Spoofing","https://github.com/christophetd/spoofing-office-macro","1","1","N/A","N/A","9","4","381","82","2020-04-28T16:23:43Z","2019-03-11T18:23:39Z","47449" +"*http://blog.gentilkiwi.com/mimikatz*",".{0,1000}http\:\/\/blog\.gentilkiwi\.com\/mimikatz.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","https://www.virustotal.com/gui/file/5191200b2b3d20b4e970acc72cca38d318ca463a88230580a426975a6f73bb49?nocache=1","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","47450" +"*http://blog.sevagas.com/?Hacking-around-HTA-files*",".{0,1000}http\:\/\/blog\.sevagas\.com\/\?Hacking\-around\-HTA\-files.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","47451" +"*http://blog.sevagas.com/?My-VBA-Bot*",".{0,1000}http\:\/\/blog\.sevagas\.com\/\?My\-VBA\-Bot.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","47452" +"*http://bshades.eu*",".{0,1000}http\:\/\/bshades\.eu.{0,1000}","offensive_tool_keyword","BlackShades","remote access trojan (RAT) used by attackers to gain unauthorized control over a victim's computer","T1012 - T1059.001 - T1071.001 - T1105 - T1113 - T1125","TA0003 - TA0005 - TA0008 - TA0010 - TA0011","N/A","N/A","Malware","https://github.com/yuankong666/Ultimate-RAT-Collection/tree/main/BlackShades","1","1","N/A","N/A","10","10","2468","431","2025-04-15T16:14:10Z","2023-09-12T00:41:11Z","47454" +"*http://ec2-52-90-251-67.compute-1.amazonaws.com/GoogleChromeAutoLaunch.exe*",".{0,1000}http\:\/\/ec2\-52\-90\-251\-67\.compute\-1\.amazonaws\.com\/GoogleChromeAutoLaunch\.exe.{0,1000}","offensive_tool_keyword","Python-Rootkit","full undetectable python RAT which can bypass almost all antivirus and open a backdoor inside any windows machine which will establish a reverse https Metasploit connection to your listening machine","T1100 - T1027 - T1219 - T1560.001 - T1021.005","TA0005 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/0xIslamTaha/Python-Rootkit","1","1","N/A","N/A","10","10","606","145","2024-10-29T16:56:39Z","2016-06-09T10:49:54Z","47459" +"*http://go.mail.ru/search?gay.ru.query=1&q=?abc.r&q=*",".{0,1000}http\:\/\/go\.mail\.ru\/search\?gay\.ru\.query\=1\&q\=\?abc\.r\&q\=.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","47464" +"*http://hashcrack.com*",".{0,1000}http\:\/\/hashcrack\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47465" +"*http://hashtoolkit.com*",".{0,1000}http\:\/\/hashtoolkit\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47466" +"*http://king-hrdevil.rhcloud.com/f5ddos3.html?v=*",".{0,1000}http\:\/\/king\-hrdevil\.rhcloud\.com\/f5ddos3\.html\?v\=.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","47467" +"*http://knight*.onion*",".{0,1000}http\:\/\/knight.{0,1000}\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","ransomware note from knight ransomware","T1486","TA0040","N/A","N/A","Ransomware","https://tria.ge/230901-c2fbqacb36","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","47468" +"*http://LhOsT/FiLNaMe.*",".{0,1000}http\:\/\/LhOsT\/FiLNaMe\..{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","47469" +"*http://localhost/shell.jsp?pwd=System.out.println(*",".{0,1000}http\:\/\/localhost\/shell\.jsp\?pwd\=System\.out\.println\(.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","1","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","47470" +"*http://localhost/stager.php*",".{0,1000}http\:\/\/localhost\/stager\.php.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","47471" +"*http://localhost:3000/ui/panel*",".{0,1000}http\:\/\/localhost\:3000\/ui\/panel.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","47474" +"*http://localhost:42969/easy.aspx*",".{0,1000}http\:\/\/localhost\:42969\/easy\.aspx.{0,1000}","offensive_tool_keyword","chunk-Proxy","A backdoor installed on a web server that allows for the execution of commands and facilitates persistent access.","T1505.003 - T1059 - T1105 - T1071","TA0011 - TA0002 - TA0003","Ghost Ransomware","N/A","C2","https://github.com/BeichenDream/Chunk-Proxy","1","1","N/A","N/A","10","10","283","40","2022-05-07T04:24:50Z","2021-10-28T18:45:21Z","47475" +"*http://localhost:4430/hello*",".{0,1000}http\:\/\/localhost\:4430\/hello.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","47476" +"*http://localhost:52935*",".{0,1000}http\:\/\/localhost\:52935.{0,1000}","offensive_tool_keyword","C3","Framework designed for red teams to create and manage custom C2 (Command and Control) channels. Unlike traditional C2 frameworks that rely on typical communication methods like HTTP/S DNS or TCP - C3 allows for the creation of non-traditional and esoteric C2 channels using platforms like Slack Dropbox GitHub OneDrive and more.","T1071 - T1102 - T1090 - T1573 - T1048","TA0011 - TA0002 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/WithSecureLabs/C3","1","1","N/A","N/A","9","10","1602","276","2023-03-04T20:32:13Z","2019-08-30T11:21:04Z","47477" +"*http://localhost:58082/broadcast?id=*",".{0,1000}http\:\/\/localhost\:58082\/broadcast\?id\=.{0,1000}","offensive_tool_keyword","cuddlephish","Weaponized Browser-in-the-Middle (BitM) for Penetration Testers","T1185 - T1185.002 - T1071 - T1071.001 - T1556 - T1556.001","TA0009 - TA0006","N/A","N/A","Sniffing & Spoofing","https://github.com/fkasler/cuddlephish","1","1","N/A","N/A","10","5","487","51","2024-11-21T17:36:55Z","2023-08-02T14:30:41Z","47478" +"*http://localhost:7474/browser/*",".{0,1000}http\:\/\/localhost\:7474\/browser\/.{0,1000}","offensive_tool_keyword","BloodHound","A Python based ingestor for BloodHound","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/fox-it/BloodHound.py","1","1","N/A","neo4j default local url","10","10","2088","343","2025-03-28T11:19:13Z","2018-02-26T14:44:20Z","47479" +"*http://localhost:80/bcsjngnk*",".{0,1000}http\:\/\/localhost\:80\/bcsjngnk.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","47482" +"*http://localhost:8000/emailviewer.html*",".{0,1000}http\:\/\/localhost\:8000\/emailviewer\.html.{0,1000}","offensive_tool_keyword","GraphRunner","A Post-exploitation Toolset for Interacting with the Microsoft Graph API","T1059.007 - T1087.001 - T1078.001 - T1585.001 - T1071.001","TA0002 - TA0003 - TA0008 - TA0011","N/A","N/A","Exploitation tool","https://github.com/dafthack/GraphRunner","1","1","N/A","N/A","10","10","1082","127","2024-11-07T04:40:34Z","2023-08-15T17:19:11Z","47483" +"*http://localhost:8118*",".{0,1000}http\:\/\/localhost\:8118.{0,1000}","offensive_tool_keyword","CursedChrome","Chrome-extension implant that turns victim Chrome browsers into fully-functional HTTP proxies allowing you to browse sites as your victims","T1176 - T1219 - T1090","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/mandatoryprogrammer/CursedChrome","1","1","N/A","privproxy port also web panel for victims","10","10","1533","226","2024-10-26T19:06:54Z","2020-04-26T20:55:05Z","47484" +"*http://localhost:9090/*",".{0,1000}http\:\/\/localhost\:9090\/.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","47485" +"*http://localhost:9999/portal*",".{0,1000}http\:\/\/localhost\:9999\/portal.{0,1000}","offensive_tool_keyword","pac2","PAC2 is a framework that generates arbitrary flows and sends and executes them on the Power Automate Platform - using Power automate as a C2","T1550.001 - T1204.002 - T1102 - T1071.001","TA0005 - TA0008 - TA0010- TA0011","N/A","N/A","C2","https://github.com/NTT-Security-Japan/pac2","1","1","N/A","N/A","6","10","6","1","2024-04-16T11:58:54Z","2024-03-01T08:06:32Z","47486" +"*http://louis-ddosvn.rhcloud.com/f5.html?v=*",".{0,1000}http\:\/\/louis\-ddosvn\.rhcloud\.com\/f5\.html\?v\=.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","47488" +"*http://md5.80p.cn*",".{0,1000}http\:\/\/md5\.80p\.cn.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47489" +"*http://md5.gongjuji.net*",".{0,1000}http\:\/\/md5\.gongjuji\.net.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47490" +"*http://md5.gromweb.com*",".{0,1000}http\:\/\/md5\.gromweb\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47491" +"*http://md5.my-addr.com*",".{0,1000}http\:\/\/md5\.my\-addr\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47492" +"*http://md5.tellyou.top*",".{0,1000}http\:\/\/md5\.tellyou\.top.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47493" +"*http://mirror.archlinux.no*",".{0,1000}http\:\/\/mirror\.archlinux\.no.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","47494" +"*http://nemesis/file*",".{0,1000}http\:\/\/nemesis\/file.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","47495" +"*http://nemesis/yara*",".{0,1000}http\:\/\/nemesis\/yara.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","47496" +"*http://nemesis-es-http.default.svc.cluster.local:9200*",".{0,1000}http\:\/\/nemesis\-es\-http\.default\.svc\.cluster\.local\:9200.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","47497" +"*http://nemesis-es-internal-http:9200*",".{0,1000}http\:\/\/nemesis\-es\-internal\-http\:9200.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","47498" +"*http://nemesis-kb-http.default.svc.cluster.local:5601*",".{0,1000}http\:\/\/nemesis\-kb\-http\.default\.svc\.cluster\.local\:5601.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","47499" +"*http://nemesis-kb-http:5601*",".{0,1000}http\:\/\/nemesis\-kb\-http\:5601.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","47500" +"*http://nova.rambler.ru/search?btnG=%D0%9D%?D0%B0%D0%B&q=*",".{0,1000}http\:\/\/nova\.rambler\.ru\/search\?btnG\=\%D0\%9D\%\?D0\%B0\%D0\%B\&q\=.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","47501" +"*http://page-xirusteam.rhcloud.com/f5ddos3.html?v=*",".{0,1000}http\:\/\/page\-xirusteam\.rhcloud\.com\/f5ddos3\.html\?v\=.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","47502" +"*http://php-hrdevil.rhcloud.com/f5ddos3.html?v=*",".{0,1000}http\:\/\/php\-hrdevil\.rhcloud\.com\/f5ddos3\.html\?v\=.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","47505" +"*http://rainbowtables.it64.com*",".{0,1000}http\:\/\/rainbowtables\.it64\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47506" +"*http://shell:7681/token*",".{0,1000}http\:\/\/shell\:7681\/token.{0,1000}","offensive_tool_keyword","supershell","Supershell is a C2 remote control platform accessed through WEB services. By establishing a reverse SSH tunnel it obtains a fully interactive Shell and supports multi-platform architecture Payload","T1090 - T1059 - T1021","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/tdragon6/Supershell","1","1","N/A","N/A","10","10","1561","196","2023-09-26T13:53:55Z","2023-03-25T15:02:43Z","47511" +"*http://sniff.su/*.gz*",".{0,1000}http\:\/\/sniff\.su\/.{0,1000}\.gz.{0,1000}","offensive_tool_keyword","Intercepter-NG","android wifi sniffer","T1433","TA0006","N/A","N/A","Sniffing & Spoofing","https://github.com/intercepter-ng","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","47512" +"*http://sniff.su/*.zip*",".{0,1000}http\:\/\/sniff\.su\/.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","Intercepter-NG","android wifi sniffer","T1433","TA0006","N/A","N/A","Sniffing & Spoofing","https://github.com/intercepter-ng","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","47513" +"*http://sourceforge.net/projects/adzok/files/Adzok_Open_v1.0.0.2.jar/download*",".{0,1000}http\:\/\/sourceforge\.net\/projects\/adzok\/files\/Adzok_Open_v1\.0\.0\.2\.jar\/download.{0,1000}","offensive_tool_keyword","Adzok","RAT tool - a variant of Adwind abused by TA","T1219 - T1105 - T1027 - T1059 - T1204","TA0011 - TA0005 - TA0002 - TA0008","N/A","Packrat","Malware","https://sourceforge.net/projects/adzok/files/Adzok_Open_v1.0.0.2.jar/download","1","1","N/A","N/A","8","8","N/A","N/A","N/A","N/A","47514" +"*http://tarantula.by.ru/localroot/*",".{0,1000}http\:\/\/tarantula\.by\.ru\/localroot\/.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","47516" +"*http://tarantula.by.ru/localroot/2.6.x/h00lyshit*",".{0,1000}http\:\/\/tarantula\.by\.ru\/localroot\/2\.6\.x\/h00lyshit.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","47517" +"*http://tor2web.*","http\:\/\/tor2web\..{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","47520" +"*http://ttmd5.com*",".{0,1000}http\:\/\/ttmd5\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47521" +"*http://utkusen.com/hidden-tear/*",".{0,1000}http\:\/\/utkusen\.com\/hidden\-tear\/.{0,1000}","offensive_tool_keyword","hidden-tear","open source ransomware - many variant in the wild","T1486 - T1059 - T1485 - T1489 - T1070 - T1488","TA0005 - TA0009 - TA0040 - TA0042","N/A","N/A","Ransomware","https://github.com/goliate/hidden-tear","1","1","N/A","N/A","10","8","765","394","2020-07-08T22:34:01Z","2015-08-19T09:06:51Z","47524" +"*http://wfuzz.org*",".{0,1000}http\:\/\/wfuzz\.org.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","47526" +"*http://www.ampliasecurity.com/research/wcefaq.html*",".{0,1000}http\:\/\/www\.ampliasecurity\.com\/research\/wcefaq\.html.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","1","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","47528" +"*http://www.chamd5.org/*",".{0,1000}http\:\/\/www\.chamd5\.org\/.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47529" +"*http://www.dmd5.com*",".{0,1000}http\:\/\/www\.dmd5\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47530" +"*http://www.exploit-db.com/exploits/*",".{0,1000}http\:\/\/www\.exploit\-db\.com\/exploits\/.{0,1000}","offensive_tool_keyword","linuxprivchecker","search for common privilege escalation vectors such as world writable files. misconfigurations. clear-text passwords and applicable exploits","T1210.001 - T1082 - T1088 - T1547.001","TA0002 - TA0004 - TA0006 - TA0007 - TA0008","N/A","N/A","Privilege Escalation","https://github.com/sleventyeleven/linuxprivchecker/blob/master/linuxprivchecker.py","1","1","N/A","N/A","7","10","1645","524","2022-01-31T10:32:08Z","2016-04-19T13:31:46Z","47533" +"*http://www.gmer.net/#files*",".{0,1000}http\:\/\/www\.gmer\.net\/\#files.{0,1000}","offensive_tool_keyword","gmer","rootkit detector abused by attackers to disable security software","T1014 - T1562.001","TA0005","N/A","BlackSuit - Royal - PLAY - LockBit - Bassterlord* - Conti - 8BASE - TargetCompany - Hive - Avaddon","Defense Evasion","gmer.net","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","47534" +"*http://www.insecam.org/en/jsoncountries/*",".{0,1000}http\:\/\/www\.insecam\.org\/en\/jsoncountries\/.{0,1000}","offensive_tool_keyword","Cam-Hackers","Hack Cameras CCTV FREE","T1125","TA0007","N/A","N/A","Discovery","https://github.com/AngelSecurityTeam/Cam-Hackers","1","1","N/A","N/A","6","10","2025","512","2024-08-06T18:49:02Z","2019-11-16T18:49:35Z","47535" +"*http://www.md5cracker.com*",".{0,1000}http\:\/\/www\.md5cracker\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47536" +"*http://www.nirsoft.net/password_test*",".{0,1000}http\:\/\/www\.nirsoft\.net\/password_test.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","47537" +"*http://www2.gmer.net/download*",".{0,1000}http\:\/\/www2\.gmer\.net\/download.{0,1000}","offensive_tool_keyword","gmer","rootkit detector abused by attackers to disable security software","T1014 - T1562.001","TA0005","N/A","BlackSuit - Royal - PLAY - LockBit - Bassterlord* - Conti - 8BASE - TargetCompany - Hive - Avaddon","Defense Evasion","gmer.net","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","47542" +"*http://www2.gmer.net/gmer.zip*",".{0,1000}http\:\/\/www2\.gmer\.net\/gmer\.zip.{0,1000}","offensive_tool_keyword","gmer","rootkit detector abused by attackers to disable security software","T1014 - T1562.001","TA0005","N/A","BlackSuit - Royal - PLAY - LockBit - Bassterlord* - Conti - 8BASE - TargetCompany - Hive - Avaddon","Defense Evasion","gmer.net","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","47543" +"*http://xmd5.com*",".{0,1000}http\:\/\/xmd5\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47544" +"*http_default_pass.txt*",".{0,1000}http_default_pass\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","47546" +"*http_default_users.txt*",".{0,1000}http_default_users\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","47547" +"*http_malleable.py*",".{0,1000}http_malleable\.py.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","47548" +"*http_ntlmrelay.*",".{0,1000}http_ntlmrelay\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","47549" +"*http_owa_common.txt*",".{0,1000}http_owa_common\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","47550" +"*http_stager_client_header*",".{0,1000}http_stager_client_header.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","47551" +"*http_stager_server_append*",".{0,1000}http_stager_server_append.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","47552" +"*http_stager_server_header*",".{0,1000}http_stager_server_header.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","47553" +"*http_stager_server_prepend*",".{0,1000}http_stager_server_prepend.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","47554" +"*http_stager_uri_x64*",".{0,1000}http_stager_uri_x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","47555" +"*http_stager_uri_x86*",".{0,1000}http_stager_uri_x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","47556" +"*http1.x64.bin*",".{0,1000}http1\.x64\.bin.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","47557" +"*http1.x64.dll*",".{0,1000}http1\.x64\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","47558" +"*HTTPAES256Handler.*",".{0,1000}HTTPAES256Handler\..{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","47559" +"*httpattack.py*",".{0,1000}httpattack\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","47560" +"*httpattack.py*",".{0,1000}httpattack\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","47561" +"*httpattack.py*",".{0,1000}httpattack\.py.{0,1000}","offensive_tool_keyword","PrivExchange","Exchange your privileges for Domain Admin privs by abusing Exchange","T1091.001 - T1101 - T1201 - T1570","TA0006","N/A","N/A","Exploitation tool","https://github.com/dirkjanm/PrivExchange","1","1","N/A","N/A","N/A","10","1011","173","2020-01-23T19:48:51Z","2019-01-21T17:39:47Z","47562" +"*httpattack.py*",".{0,1000}httpattack\.py.{0,1000}","offensive_tool_keyword","privexchange","Exchange your privileges for Domain Admin privs by abusing Exchange","T1053.005 - T1078 - T1069.002","TA0002 - TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/dirkjanm/PrivExchange","1","1","N/A","N/A","N/A","10","1011","173","2020-01-23T19:48:51Z","2019-01-21T17:39:47Z","47563" +"*httpattacks/*.py*",".{0,1000}httpattacks\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","47564" +"*HTTP-Backdoor.ps1*",".{0,1000}HTTP\-Backdoor\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","47565" +"*HTTP-Backdoor.ps1*",".{0,1000}HTTP\-Backdoor\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","47566" +"*HTTP-Backdoor.ps1*",".{0,1000}HTTP\-Backdoor\.ps1.{0,1000}","offensive_tool_keyword","webshell","collection of webshell - observed used by famous webshells","T1100 - T1027 - T1059 - T1105","TA0003 - TA0005 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/tennc/webshell","1","1","N/A","N/A","9","10","10344","5595","2024-12-24T15:37:05Z","2013-05-23T07:37:56Z","47567" +"*httpbrute.py*",".{0,1000}httpbrute\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","47568" +"*http-c2_test.go*",".{0,1000}http\-c2_test\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","47569" +"*HttpEvilClippyController*",".{0,1000}HttpEvilClippyController.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","47572" +"*HTTP-Login.ps1*",".{0,1000}HTTP\-Login\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","HTTP-Login.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","47573" +"*httppayload.bin*",".{0,1000}httppayload\.bin.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike payload generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dr0op/CrossNet-Beta","1","1","N/A","N/A","10","10","362","58","2024-06-19T07:02:22Z","2021-02-08T10:52:39Z","47576" +"*HttpProxyScan_Log4J2.py*",".{0,1000}HttpProxyScan_Log4J2\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","47577" +"*http-redwarden*",".{0,1000}http\-redwarden.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","47578" +"*httprelayclient.py*",".{0,1000}httprelayclient\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","47579" +"*httprelayclient.py*",".{0,1000}httprelayclient\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","47580" +"*httprelayserver.py*",".{0,1000}httprelayserver\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","47581" +"*httprelayserver.py*",".{0,1000}httprelayserver\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","47582" +"*http-request-smuggler-all.jar*",".{0,1000}http\-request\-smuggler\-all\.jar.{0,1000}","offensive_tool_keyword","burpsuite","Collection of burpsuite plugins","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","network exploitation tool","N/A","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","47583" +"*https://*.gofile.io/uploadFile*",".{0,1000}https\:\/\/.{0,1000}\.gofile\.io\/uploadFile.{0,1000}","offensive_tool_keyword","Fentanyl","Stealer Malware - Steal Discord Tokens (+ Much More Info) - Steal Passwords/Cookies/History/Credit Cards/Phone Numbers and Addresses from all Browsers (Profile Support) - Steal PC Info - Steal Video Game Accounts (Adding more games + wallets and VPN's) - Low Detections - Anti VM - Sort of Fast - Startup - IP Logger","T1547.001 - T1552.001 - T1552.005 - T1110.001 - T1082 - T1562.001 - T1574.002 - T1529 - T1497.001 - T1543.003 - T1592.001","TA0005 - TA0006 - TA0040 - TA0003 - TA0009","N/A","N/A","Malware","https://github.com/dekrypted/Fentanyl","1","1","N/A","N/A","10","","N/A","","","","47598" +"*https://*.onion*",".{0,1000}[a-z0-9]{16,56}\.(onion|tor2web|torlink).{0,1000}","offensive_tool_keyword","torproject","Detects suspicious TOR usage which anonymizes user's web traffic through a relay network","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","47603" +"*https://*.tor2web*",".{0,1000}[a-z0-9]{16,56}\.(onion|tor2web|torlink).{0,1000}","offensive_tool_keyword","torproject","Detects suspicious TOR usage which anonymizes user's web traffic through a relay network","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","47614" +"*https://*.torlink*",".{0,1000}[a-z0-9]{16,56}\.(onion|tor2web|torlink).{0,1000}","offensive_tool_keyword","torproject","Detects suspicious TOR usage which anonymizes user's web traffic through a relay network","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","47615" +"*https://*.tuns.sh*",".{0,1000}https\:\/\/.{0,1000}\.tuns\.sh.{0,1000}","offensive_tool_keyword","sish","An open source serveo/ngrok alternative. HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH","T1572 - T1090.002","TA0010 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antoniomika/sish","1","1","N/A","N/A","10","10","4203","325","2025-04-10T20:04:08Z","2019-02-15T15:36:23Z","47619" +"*https://*/releases/download/*/lse.sh*",".{0,1000}https\:\/\/.{0,1000}\/releases\/download\/.{0,1000}\/lse\.sh.{0,1000}","offensive_tool_keyword","linux-smart-enumeration","Linux enumeration tool for privilege escalation and discovery","T1087.004 - T1016 - T1548.001 - T1046","TA0007 - TA0004 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/diego-treitos/linux-smart-enumeration","1","1","#linux","N/A","9","10","3575","584","2023-12-25T14:46:47Z","2019-02-13T11:02:21Z","47626" +"*https://*Microsoft.ActiveDirectory.Management.dll*",".{0,1000}https\:\/\/.{0,1000}Microsoft\.ActiveDirectory\.Management\.dll.{0,1000}","offensive_tool_keyword","powershell","redteam technique - import the ActiveDirectory module without the need to install it on the current computer - the dll has been extracted from a Windows 10 x64 with RSAT installed","T1110.001 - T1110.003 - T1110.004","TA0006","N/A","N/A","Credential Access","https://github.com/mthcht/Purpleteam/blob/main/Simulation/Windows/ActiveDirectory/Bruteforce.ps1","1","1","N/A","N/A","N/A","2","184","19","2024-12-20T10:22:25Z","2022-12-05T12:40:02Z","47628" +"*https://0.0.0.0:1337*",".{0,1000}https\:\/\/0\.0\.0\.0\:1337.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","47630" +"*https://0day.today/exploit/*",".{0,1000}https\:\/\/0day\.today\/exploit\/.{0,1000}","offensive_tool_keyword","0day.today","a platform providing exploit code (free and paid)","T1588.002 - T1587.001 - T1190","TA0042 - TA0009","N/A","N/A","Exploitation tool","https://0day.today/","1","1","N/A","N/A","7","6","N/A","N/A","N/A","N/A","47633" +"*https://0x00sec.org/t/malware-development-1-password-stealers-chrome/33571*",".{0,1000}https\:\/\/0x00sec\.org\/t\/malware\-development\-1\-password\-stealers\-chrome\/33571.{0,1000}","offensive_tool_keyword","BrowserSnatch","steals important data from all chromium and gecko browsers installed in the system and gather the data in a stealer db to be exfiltrated out. A powerful Browser Stealer","T1081 - T1074 - T1114 - T1005 - T1041 - T1027","TA0006 - TA0009 - TA0010","N/A","N/A","Data Exfiltration","https://github.com/shaddy43/BrowserSnatch","1","1","N/A","N/A","10","3","246","39","2025-03-31T21:04:30Z","2024-08-26T18:38:42Z","47634" +"*https://1.3.3.7:8081*",".{0,1000}https\:\/\/1\.3\.3\.7\:8081.{0,1000}","offensive_tool_keyword","dnskire","A tool for file infiltration over DNS","T1071.004 - T1071.001 - T1048","TA0010 - TA0005 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/0xtosh/dnskire","1","1","N/A","N/A","7","1","17","0","2023-12-07T21:42:34Z","2022-09-10T17:56:30Z","47635" +"*https://127.0.0.1/dns-query*",".{0,1000}https\:\/\/127\.0\.0\.1\/dns\-query.{0,1000}","offensive_tool_keyword","dnscrypt","A flexible DNS proxy with support for modern encrypted DNS protocols such as DNSCrypt v2 - DNS-over-HTTPS - Anonymized DNSCrypt and ODoH (Oblivious DoH).","T1071.004 - T1568.002 - T1557.004","TA0011 - TA0006","N/A","N/A","Defense Evasion","https://github.com/DNSCrypt/dnscrypt-proxy","1","1","N/A","N/A","10","10","11963","1040","2025-04-21T03:51:34Z","2018-01-08T23:21:21Z","47636" +"*https://127.0.0.1:5000/register*",".{0,1000}https\:\/\/127\.0\.0\.1\:5000\/register.{0,1000}","offensive_tool_keyword","Commander","A command and control (C2) server","T1021 - T1027 - T1059","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/voukatas/Commander","1","1","N/A","N/A","10","10","56","16","2024-07-05T11:05:30Z","2023-02-03T16:46:33Z","47637" +"*https://127.0.0.1:5000/results/*",".{0,1000}https\:\/\/127\.0\.0\.1\:5000\/results\/.{0,1000}","offensive_tool_keyword","Commander","A command and control (C2) server","T1021 - T1027 - T1059","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/voukatas/Commander","1","1","N/A","N/A","10","10","56","16","2024-07-05T11:05:30Z","2023-02-03T16:46:33Z","47638" +"*https://127.0.0.1:5000/tasks/*",".{0,1000}https\:\/\/127\.0\.0\.1\:5000\/tasks\/.{0,1000}","offensive_tool_keyword","Commander","A command and control (C2) server","T1021 - T1027 - T1059","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/voukatas/Commander","1","1","N/A","N/A","10","10","56","16","2024-07-05T11:05:30Z","2023-02-03T16:46:33Z","47639" +"*https://127.0.0.1:7443*",".{0,1000}https\:\/\/127\.0\.0\.1\:7443.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","47641" +"*https://127.0.0.1:7443*",".{0,1000}https\:\/\/127\.0\.0\.1\:7443.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","47642" +"*https://5pider.net/blog/2024/01/27/modern-shellcode-implant-design*",".{0,1000}https\:\/\/5pider\.net\/blog\/2024\/01\/27\/modern\-shellcode\-implant\-design.{0,1000}","offensive_tool_keyword","Stardust","An modern 64-bit position independent implant template","T1055 - T1105 - T1055.012 - T1027 - T1218","TA0005 - TA0003 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/Stardust","1","1","N/A","N/A","10","10","1193","193","2025-03-21T11:41:09Z","2022-02-20T01:23:35Z","47647" +"*https://adaptix-framework.gitbook.io/adaptix-framework/adaptix-c2/getting-starting/*",".{0,1000}https\:\/\/adaptix\-framework\.gitbook\.io\/adaptix\-framework\/adaptix\-c2\/getting\-starting\/.{0,1000}","offensive_tool_keyword","AdaptixC2","C2- Adaptix is an extensible post-exploitation and adversarial emulation framework made for penetration testers","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/Adaptix-Framework/AdaptixC2","1","1","N/A","N/A","10","10","547","114","2025-04-21T06:03:46Z","2024-08-21T18:07:05Z","47649" +"*https://amsi.fail/*",".{0,1000}https\:\/\/amsi\.fail\/.{0,1000}","offensive_tool_keyword","amsi.fail","AMSI.fail generates obfuscated PowerShell snippets that break or disable AMSI for the current process. The snippets are randomly selected from a small pool of techniques/variations before being obfuscated. Every snippet is obfuscated at runtime/request so that no generated output share the same signatures.","T1059.001 - T1562.001 - T1027.005","TA0002 - TA0005 - TA0008","N/A","N/A","Defense Evasion","https://amsi.fail/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","47652" +"*https://api.fbi.gov/wanted/v1/list*",".{0,1000}https\:\/\/api\.fbi\.gov\/wanted\/v1\/list.{0,1000}","offensive_tool_keyword","ShellSync","exposing a server with suspicious scripts and executable from I-Am-Jakoby","T1059.003 - T1100 - T1027","TA0005 - TA0009 - TA0011 ","N/A","N/A","Data Exfiltration","https://github.com/I-Am-Jakoby/ShellSync","1","1","N/A","N/A","5","1","20","7","2023-11-08T18:01:18Z","2023-11-06T06:05:11Z","47658" +"*https://api.github.com/orgs/gatoxtest/*",".{0,1000}https\:\/\/api\.github\.com\/orgs\/gatoxtest\/.{0,1000}","offensive_tool_keyword","Gato-X","automate advanced enumeration and exploitation techniques against GitHub repositories and organizations","T1190 - T1083 - T1588 - T1587","TA0001 - TA0007 - TA0005","N/A","N/A","Reconnaissance","https://github.com/adnanekhan/Gato-X","1","1","N/A","N/A","7","3","270","35","2025-04-21T17:57:09Z","2024-01-27T18:55:16Z","47661" +"*https://api.localxpose.io/api/v2/downloads/loclx-darwin-amd64.zip*",".{0,1000}https\:\/\/api\.localxpose\.io\/api\/v2\/downloads\/loclx\-darwin\-amd64\.zip.{0,1000}","offensive_tool_keyword","CamHacker","Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!","T1598 - T1204 - T1566.001","TA0009 - TA0010 - TA0043","N/A","N/A","Phishing","https://github.com/KasRoudra/CamHacker","1","1","#linux","N/A","10","","N/A","","","","47663" +"*https://api.onedrive.com/v1.0/drives/me/items/root:{onedrive_file_path}:/oneDrive.createUploadSession*",".{0,1000}https\:\/\/api\.onedrive\.com\/v1\.0\/drives\/me\/items\/root\:\{onedrive_file_path\}\:\/oneDrive\.createUploadSession.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","47665" +"*https://api.sublist3r.com/search.php?domain=",".{0,1000}https\:\/\/api\.sublist3r\.com\/search\.php\?domain\=","offensive_tool_keyword","Sublist3r","Sublist3r is a python tool designed to enumerate subdomains of websites using OSINT. It helps penetration testers and bug hunters collect and gather subdomains for the domain they are targeting. Sublist3r enumerates subdomains using many search engines such as Google. Yahoo. Bing. Baidu and Ask. Sublist3r also enumerates subdomains using Netcraft. Virustotal. ThreatCrowd. DNSdumpster and ReverseDNS. subbrute was integrated with Sublist3r to increase the possibility of finding more subdomains using bruteforce with an improved wordlist. The credit goes to TheRook who is the author of subbrute.","T1210.001 - T1190 - T1574.001","TA0007 - TA0002 - TA0010","N/A","ENERGETIC BEAR","Reconnaissance","https://github.com/aboul3la/Sublist3r","1","1","N/A","N/A","5","10","10300","2148","2024-08-02T00:00:30Z","2015-12-15T00:55:25Z","47667" +"*https://auth.pico.sh/*",".{0,1000}https\:\/\/auth\.pico\.sh\/.{0,1000}","offensive_tool_keyword","pico","hacker labs - open source and managed web services leveraging SSH","T1021.005 - T1078 - T1105 - T1109 - T1197 - T1213","TA0005 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/picosh/pico","1","1","N/A","N/A","10","10","1129","36","2025-04-22T17:33:17Z","2022-08-24T03:14:52Z","47680" +"*https://avred.r00ted.ch/upload*",".{0,1000}https\:\/\/avred\.r00ted\.ch\/upload.{0,1000}","offensive_tool_keyword","avred","Avred is being used to identify which parts of a file are identified by a Antivirus and tries to show as much possible information and context about each match.","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/dobin/avred","1","1","N/A","N/A","9","5","465","55","2025-02-26T08:12:03Z","2022-05-19T12:12:34Z","47681" +"*https://badkeys.info/*",".{0,1000}https\:\/\/badkeys\.info\/.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","1","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","47682" +"*https://bin.equinox.io/c/4VmDzA7iaHb/*",".{0,1000}https\:\/\/bin\.equinox\.io\/c\/4VmDzA7iaHb\/.{0,1000}","offensive_tool_keyword","BackHAck","Backdoor Generator with C2 server - Linux & Windows - FUD AV .py .exe","T1090 - T1095 - T1008","TA0011","N/A","N/A","C2","https://github.com/AngelSecurityTeam/BackHAck","1","1","#linux","N/A","10","10","108","34","2020-03-25T21:30:47Z","2020-03-14T19:00:36Z","47687" +"*https://bitbucket.org/evilgreyswork/*",".{0,1000}https\:\/\/bitbucket\.org\/evilgreyswork\/.{0,1000}","offensive_tool_keyword","WDBypass","Disable Windows Defender (+ UAC Bypass, + Upgrade to SYSTEM)","T1089 - T1562.001 - T1548.002","TA0005 - TA0040 - TA0003 - TA0004","N/A","Dispossessor","Defense Evasion","https://bitbucket.org/evilgreyswork/wd-uac/downloads/","1","1","N/A","https://blog.injectexp.dev/2024/02/28/disable-windows-defender-uac-bypass-upgrade-to-system/","10","10","N/A","N/A","N/A","N/A","47695" +"*https://blog.sevagas.com/?Advanced-MacroPack-payloads-XLM-Injection*",".{0,1000}https\:\/\/blog\.sevagas\.com\/\?Advanced\-MacroPack\-payloads\-XLM\-Injection.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","47696" +"*https://blog.sevagas.com/?Bypass-Windows-Defender-Attack-Surface-Reduction*",".{0,1000}https\:\/\/blog\.sevagas\.com\/\?Bypass\-Windows\-Defender\-Attack\-Surface\-Reduction.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","47697" +"*https://blog.sevagas.com/?EXCEL-4-0-XLM-macro-in-MacroPack-Pro*",".{0,1000}https\:\/\/blog\.sevagas\.com\/\?EXCEL\-4\-0\-XLM\-macro\-in\-MacroPack\-Pro.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","47698" +"*https://blog.sevagas.com/?Launch-shellcodes-and-bypass-Antivirus-using-MacroPack-Pro-VBA-payloads*",".{0,1000}https\:\/\/blog\.sevagas\.com\/\?Launch\-shellcodes\-and\-bypass\-Antivirus\-using\-MacroPack\-Pro\-VBA\-payloads.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","47699" +"*https://bloodhound.readthedocs.io/en/latest/index.html*",".{0,1000}https\:\/\/bloodhound\.readthedocs\.io\/en\/latest\/index\.html.{0,1000}","offensive_tool_keyword","BloodHound","Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors","1","1","N/A","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","47700" +"*https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation*",".{0,1000}https\:\/\/book\.hacktricks\.xyz\/windows\-hardening\/windows\-local\-privilege\-escalation.{0,1000}","offensive_tool_keyword","PEASS-ng","PEASS-ng - Privilege Escalation Awesome Scripts suite","T1098","TA0004 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/peass-ng/PEASS-ng","1","1","N/A","N/A","10","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","47701" +"*https://browserling.com/tor-testing*",".{0,1000}https\:\/\/browserling\.com\/tor\-testing.{0,1000}","offensive_tool_keyword","browserling","proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","browserling.com","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","47704" +"*https://bruteratel.com:65000/activate*",".{0,1000}https\:\/\/bruteratel\.com\:65000\/activate.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","47705" +"*https://cdn.discordapp.com/attachments/976805447266877471/987826721250238464/c33cd7baf5e2abdf434c2793988ccb56.png*",".{0,1000}https\:\/\/cdn\.discordapp\.com\/attachments\/976805447266877471\/987826721250238464\/c33cd7baf5e2abdf434c2793988ccb56\.png.{0,1000}","offensive_tool_keyword","Fentanyl","Stealer Malware - Steal Discord Tokens (+ Much More Info) - Steal Passwords/Cookies/History/Credit Cards/Phone Numbers and Addresses from all Browsers (Profile Support) - Steal PC Info - Steal Video Game Accounts (Adding more games + wallets and VPN's) - Low Detections - Anti VM - Sort of Fast - Startup - IP Logger","T1547.001 - T1552.001 - T1552.005 - T1110.001 - T1082 - T1562.001 - T1574.002 - T1529 - T1497.001 - T1543.003 - T1592.001","TA0005 - TA0006 - TA0040 - TA0003 - TA0009","N/A","N/A","Malware","https://github.com/dekrypted/Fentanyl","1","1","N/A","N/A","10","","N/A","","","","47710" +"*https://cmd5.la/*",".{0,1000}https\:\/\/cmd5\.la\/.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47713" +"*https://cnc.mkbot.info/alertmsg.zip*",".{0,1000}https\:\/\/cnc\.mkbot\.info\/alertmsg\.zip.{0,1000}","offensive_tool_keyword","Jasmin-Ransomware","Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks","T1486","TA0040 - TA0002 - TA0010","N/A","N/A","Ransomware","https://github.com/codesiddhant/Jasmin-Ransomware","1","1","N/A","N/A","10","3","252","80","2021-03-01T14:51:06Z","2021-02-27T07:09:08Z","47714" +"*https://cnc.mkbot.info/handshake.php*",".{0,1000}https\:\/\/cnc\.mkbot\.info\/handshake\.php.{0,1000}","offensive_tool_keyword","Jasmin-Ransomware","Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks","T1486","TA0040 - TA0002 - TA0010","N/A","N/A","Ransomware","https://github.com/codesiddhant/Jasmin-Ransomware","1","1","N/A","N/A","10","3","252","80","2021-03-01T14:51:06Z","2021-02-27T07:09:08Z","47715" +"*https://code.google.com/p/creddump/*",".{0,1000}https\:\/\/code\.google\.com\/p\/creddump\/.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","47716" +"*https://code.kryo.se/iodine/iodine-*",".{0,1000}https\:\/\/code\.kryo\.se\/iodine\/iodine\-.{0,1000}","offensive_tool_keyword","iodine","iodine. iodined - tunnel IPv4 over DNS","T1573.001 - T1573.002 - T1573.003 - T1573.004","TA0011 - TA0010 - TA0002 - TA0005","N/A","EMBER BEAR","C2","https://github.com/yarrick/iodine","1","1","N/A","N/A","10","10","6413","524","2025-04-08T17:44:12Z","2012-02-04T19:51:39Z","47717" +"*https://codeberg.org/RipperSec/MegaMedusa*",".{0,1000}https\:\/\/codeberg\.org\/RipperSec\/MegaMedusa.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","47718" +"*https://crack.sh/get-cracking/*",".{0,1000}https\:\/\/crack\.sh\/get\-cracking\/.{0,1000}","offensive_tool_keyword","Group3r","Find vulnerabilities in AD Group Policy","T1484.002 - T1069.002 - T1087.002","TA0007 - TA0040","N/A","KNOTWEED","Discovery","https://github.com/Group3r/Group3r","1","1","N/A","AD Enumeration","7","8","781","68","2025-04-08T05:03:34Z","2021-07-05T05:05:42Z","47720" +"*https://cracker.okx.ch*",".{0,1000}https\:\/\/cracker\.okx\.ch.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47721" +"*https://crackstation.net/*",".{0,1000}https\:\/\/crackstation\.net\/.{0,1000}","offensive_tool_keyword","hack-tools","The all-in-one Red Team browser extension for Web Pentester","T1059.007 - T1505 - T1068 - T1216 - T1547.009","TA0002 - TA0001 - TA0009","N/A","N/A","Credential Access","https://github.com/LasCC/Hack-Tools","1","1","N/A","N/A","9","10","6045","678","2025-01-05T23:10:49Z","2020-06-22T21:42:16Z","47722" +"*https://curlshell:*",".{0,1000}https\:\/\/curlshell\:.{0,1000}","offensive_tool_keyword","curlshell","reverse shell using curl","T1572","TA0002 - TA0011","N/A","N/A","C2","https://github.com/irsl/curlshell","1","1","#linux","N/A","10","10","454","73","2024-04-20T15:23:11Z","2023-07-13T19:38:34Z","47725" +"*https://cutt.ly/syFzILH*",".{0,1000}https\:\/\/cutt\.ly\/syFzILH.{0,1000}","offensive_tool_keyword","Payload-Download-Cradles","download cradles to bypass AV/EPP/EDR in context of download cradle detections","T1105 - T1027 - T1203 - T1071","TA0005 - TA0009 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Payload-Download-Cradles","1","1","N/A","N/A","10","3","256","51","2022-07-07T07:20:36Z","2021-05-14T08:56:54Z","47727" +"*https://cyseclabs.com/exploits/*",".{0,1000}https\:\/\/cyseclabs\.com\/exploits\/.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","47728" +"*https://default-password.info/*",".{0,1000}https\:\/\/default\-password\.info\/.{0,1000}","offensive_tool_keyword","default-password.info","default passwords database","T1110 - T1082","TA0006 - TA0001","N/A","N/A","Credential Access","https://default-password.info/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","47729" +"*https://dehash.me*",".{0,1000}https\:\/\/dehash\.me.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47730" +"*https://dev.tuns.sh*",".{0,1000}https\:\/\/dev\.tuns\.sh.{0,1000}","offensive_tool_keyword","pico","hacker labs - open source and managed web services leveraging SSH","T1021.005 - T1078 - T1105 - T1109 - T1197 - T1213","TA0005 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/picosh/pico","1","1","N/A","N/A","10","10","1129","36","2025-04-22T17:33:17Z","2022-08-24T03:14:52Z","47731" +"*https://dirkjanm.io/abusing-azure-ad-sso-with-the-primary-refresh-token/*",".{0,1000}https\:\/\/dirkjanm\.io\/abusing\-azure\-ad\-sso\-with\-the\-primary\-refresh\-token\/.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","1","N/A","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","47732" +"*https://discord.com/api/webhooks/1172456340560560180/KwaMHIPwjfbQIhVUB-mOHNRiHoNnyAzzQcvgvjJHqGAfLSXahTDKwB1SVuq__NVlPbeQ*",".{0,1000}https\:\/\/discord\.com\/api\/webhooks\/1172456340560560180\/KwaMHIPwjfbQIhVUB\-mOHNRiHoNnyAzzQcvgvjJHqGAfLSXahTDKwB1SVuq__NVlPbeQ.{0,1000}","offensive_tool_keyword","DEDSEC-RANSOMWARE","dedsec ransomware","T1486 - T1489 - T1490 - T1495 - T1488 - T1482","TA0040 - TA0043 - TA0042 - TA0009 - TA0010","N/A","N/A","Ransomware","https://github.com/xelroth/DEDSEC-RANSOMWARE","1","1","N/A","N/A","10","1","7","1","2024-05-17T11:12:23Z","2024-05-17T10:34:03Z","47733" +"*https://discord.com/invite/5Hpj4Gs5SS*",".{0,1000}https\:\/\/discord\.com\/invite\/5Hpj4Gs5SS.{0,1000}","offensive_tool_keyword","AD_Miner","AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses","T1087.002 - T1069 - T1018 - T1595","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/Mazars-Tech/AD_Miner","1","1","N/A","AD Enumeration","7","10","1290","131","2025-03-12T10:53:09Z","2023-09-26T12:36:59Z","47734" +"*https://dns.blokada.org/dns-query*",".{0,1000}https\:\/\/dns\.blokada\.org\/dns\-query.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071.004 - T1568.002 - T1105 ","TA0011 - TA0005","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","N/A","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","47735" +"*https://dns10.quad9.net:5053/dns-query*",".{0,1000}https\:\/\/dns10\.quad9\.net\:5053\/dns\-query.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071.004 - T1568.002 - T1105 ","TA0011 - TA0005","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","N/A","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","47736" +"*https://dnsdumpster.com/*",".{0,1000}https\:\/\/dnsdumpster\.com\/.{0,1000}","offensive_tool_keyword","dnsdumpster","dns recon & research - find & lookup dns records","T1018 - T1596.001 - T1590.002","TA0007 - TA0043","N/A","Dispossessor","Reconnaissance","https://dnsdumpster.com/","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","47737" +"*https://docs.ssi.sh/*",".{0,1000}https\:\/\/docs\.ssi\.sh\/.{0,1000}","offensive_tool_keyword","sish","An open source serveo/ngrok alternative. HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH","T1572 - T1090.002","TA0010 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antoniomika/sish","1","1","N/A","N/A","10","10","4203","325","2025-04-10T20:04:08Z","2019-02-15T15:36:23Z","47739" +"*https://downloads.hak5.org/cloudc2*",".{0,1000}https\:\/\/downloads\.hak5\.org\/cloudc2.{0,1000}","offensive_tool_keyword","hak5 cloudc2","Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud","T1021 - T1102 - T1213","TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://shop.hak5.org/products/c2?","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","47741" +"*https://drive.google.com/file/d/1WLJGs3ZUypf6hLh5WL4AJmsKdUOZo5yZ*",".{0,1000}https\:\/\/drive\.google\.com\/file\/d\/1WLJGs3ZUypf6hLh5WL4AJmsKdUOZo5yZ.{0,1000}","offensive_tool_keyword","TunnelVision","TunnelVision uses DHCP option 121 to manipulate routing tables and decloak VPN traffic","T1557 - T1498.003","TA0009 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/leviathansecurity/TunnelVision","1","1","N/A","N/A","9","2","132","17","2024-05-08T19:40:13Z","2024-03-11T22:24:56Z","47747" +"*https://drive.usercontent.google.com/download?id=1Up7tr9Zh2e7FVLOdx5J1We3GJLGxEAMO&export=download*",".{0,1000}https\:\/\/drive\.usercontent\.google\.com\/download\?id\=1Up7tr9Zh2e7FVLOdx5J1We3GJLGxEAMO\&export\=download.{0,1000}","offensive_tool_keyword","defender-control","disable windows defender permanently","T1562.001 - T1562.004 - T1089","TA0005 - TA0002","N/A","LockBit","Defense Evasion","https://www.sordum.org/9480/defender-control-v2-1/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","47748" +"*https://emkei.cz/*",".{0,1000}https\:\/\/emkei\.cz\/.{0,1000}","offensive_tool_keyword","emkei.cz","Free online fake mailer with attachments","T1071","TA0005","N/A","N/A","Defense Evasion","https://emkei.cz/","1","1","N/A","N/A","6","8","N/A","N/A","N/A","N/A","47754" +"*https://en.hackndo.com/remote-lsass-dump-passwords/*",".{0,1000}https\:\/\/en\.hackndo\.com\/remote\-lsass\-dump\-passwords\/.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","47755" +"*https://erwan2212.github.io/NTHASH-FPC*",".{0,1000}https\:\/\/erwan2212\.github\.io\/NTHASH\-FPC.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","47756" +"*https://ffuf.io.fi*",".{0,1000}https\:\/\/ffuf\.io\.fi.{0,1000}","offensive_tool_keyword","ffuf","Fast web fuzzer written in Go","T1110 - T1550","TA0006 - TA0008","N/A","N/A","Reconnaissance","https://github.com/ffuf/ffuf","1","1","#linux","N/A","N/A","10","13818","1373","2025-04-05T17:35:17Z","2018-11-08T09:25:49Z","47759" +"*https://ffuf.io/FUZZ*",".{0,1000}https\:\/\/ffuf\.io\/FUZZ.{0,1000}","offensive_tool_keyword","ffuf","Fast web fuzzer written in Go","T1110 - T1550","TA0006 - TA0008","N/A","N/A","Reconnaissance","https://github.com/ffuf/ffuf","1","1","#linux","N/A","N/A","10","13818","1373","2025-04-05T17:35:17Z","2018-11-08T09:25:49Z","47760" +"*https://forum.exploit.in/topic/*",".{0,1000}https\:\/\/forum\.exploit\.in\/topic\/.{0,1000}","offensive_tool_keyword","forum.exploit.in","a well-known cybercriminal forum where threat actors discuss exploits","T1583.001 - T1583.002 - T1583.006 - T1595.002 - T1596 - T1586 - T1071.001","TA0042 - TA0001 - TA0009","N/A","Black Basta","Exploitation tool","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","47766" +"*https://github.com/bitsadmin/*",".{0,1000}https\:\/\/github\.com\/bitsadmin\/.{0,1000}","offensive_tool_keyword","nopowershell","NoPowerShell is a tool implemented in C# which supports executing PowerShell-like commands while remaining invisible to any PowerShell logging mechanisms. This .NET Framework 2 compatible binary can be loaded in Cobalt Strike to execute commands in-memory. No System.Management.Automation.dll is used. only native .NET libraries. An alternative usecase for NoPowerShell is to launch it as a DLL via rundll32.exe: rundll32 NoPowerShell.dll.main.","T1059 - T1086 - T1500 - T1564 - T1127 - T1027","TA0002 - TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","47770" +"*https://github.com/curl/curl/wiki/DNS-over-HTTPS*",".{0,1000}https\:\/\/github\.com\/curl\/curl\/wiki\/DNS\-over\-HTTPS.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071.004 - T1568.002 - T1105 ","TA0011 - TA0005","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","N/A","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","47771" +"*https://github.com/dekrypted/*",".{0,1000}https\:\/\/github\.com\/dekrypted\/.{0,1000}","offensive_tool_keyword","Fentanyl","Stealer Malware - Steal Discord Tokens (+ Much More Info) - Steal Passwords/Cookies/History/Credit Cards/Phone Numbers and Addresses from all Browsers (Profile Support) - Steal PC Info - Steal Video Game Accounts (Adding more games + wallets and VPN's) - Low Detections - Anti VM - Sort of Fast - Startup - IP Logger","T1547.001 - T1552.001 - T1552.005 - T1110.001 - T1082 - T1562.001 - T1574.002 - T1529 - T1497.001 - T1543.003 - T1592.001","TA0005 - TA0006 - TA0040 - TA0003 - TA0009","N/A","N/A","Malware","https://github.com/dekrypted/Fentanyl","1","1","N/A","github user host multiple stealers projects","10","","N/A","","","","47772" +"*https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet/raw/master/tools/ghostip.sh*",".{0,1000}https\:\/\/github\.com\/hackerschoice\/thc\-tips\-tricks\-hacks\-cheat\-sheet\/raw\/master\/tools\/ghostip\.sh.{0,1000}","offensive_tool_keyword","hackshell","Make BASH stealthy and hacker friendly with lots of bash functions","T1070.003 - T1059.004 - T1564.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/hackerschoice/hackshell","1","1","N/A","N/A","9","3","251","28","2025-04-21T11:23:41Z","2024-07-16T15:56:11Z","47773" +"*https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet/raw/master/tools/whatserver.sh*",".{0,1000}https\:\/\/github\.com\/hackerschoice\/thc\-tips\-tricks\-hacks\-cheat\-sheet\/raw\/master\/tools\/whatserver\.sh.{0,1000}","offensive_tool_keyword","hackshell","Make BASH stealthy and hacker friendly with lots of bash functions","T1070.003 - T1059.004 - T1564.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/hackerschoice/hackshell","1","1","N/A","N/A","9","3","251","28","2025-04-21T11:23:41Z","2024-07-16T15:56:11Z","47774" +"*https://github.com/Lolliedieb/lolMiner-releases/releases/download/*",".{0,1000}https\:\/\/github\.com\/Lolliedieb\/lolMiner\-releases\/releases\/download\/.{0,1000}","offensive_tool_keyword","lolminer","NVIDIA+AMD GPU Miner","T1496","TA0040","N/A","N/A","Cryptomining","https://github.com/Lolliedieb/lolMiner-releases","1","1","N/A","N/A","9","10","2781","601","2025-02-01T20:03:57Z","2018-10-27T20:35:03Z","47775" +"*https://github.com/MadExploits/Privelege-escalation/raw/main/pwnkit*",".{0,1000}https\:\/\/github\.com\/MadExploits\/Privelege\-escalation\/raw\/main\/pwnkit.{0,1000}","offensive_tool_keyword","Gecko","Gecko Backdoor is a web php backdoor","T1100 - T1059 - T1105 - T1203","TA0011 - TA0003","N/A","N/A","C2","https://github.com/MadExploits/Gecko","1","1","N/A","N/A","10","10","118","56","2025-02-08T17:50:28Z","2022-07-15T05:51:04Z","47777" +"*https://github.com/threatexpress/red-team-scripts/blob/master/HostEnum.ps1*",".{0,1000}https\:\/\/github\.com\/threatexpress\/red\-team\-scripts\/blob\/master\/HostEnum\.ps1.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","47780" +"*https://github.com/trustedsec/specula/wiki/Why-am-I-seeing-this*",".{0,1000}https\:\/\/github\.com\/trustedsec\/specula\/wiki\/Why\-am\-I\-seeing\-this.{0,1000}","offensive_tool_keyword","specula","Specula is a C2 framework that allows for interactive operations of an implant that runs purely in the context of outlook","T1071.001 - T1105 - T1204 - T1548.002 - T1071 - T1562","TA0011 - TA0002 - TA0003 - TA0006 - TA0008 - TA0007 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/trustedsec/specula","1","1","N/A","N/A","10","10","191","21","2024-09-23T09:25:33Z","2023-12-07T15:59:52Z","47781" +"*https://gitlab.com/kalilinux/*",".{0,1000}https\:\/\/gitlab\.com\/kalilinux\/.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","47783" +"*https://gitlab.com/kalilinux/packages/asleap*",".{0,1000}https\:\/\/gitlab\.com\/kalilinux\/packages\/asleap.{0,1000}","offensive_tool_keyword","asleap","Exploiting a serious deficiency in proprietary Cisco LEAP networks","T1078 - T1557 - T1040","TA0006 - TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/joswr1ght/asleap","1","1","#linux","N/A","10","1","88","20","2021-06-21T00:13:17Z","2016-08-30T13:00:21Z","47784" +"*https://gsocket.io/install.sh*",".{0,1000}https\:\/\/gsocket\.io\/install\.sh.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Securely.","T1572","TA0011 - TA0003","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","N/A","N/A","10","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","47790" +"*https://hashcapture.com/*",".{0,1000}https\:\/\/hashcapture\.com\/.{0,1000}","offensive_tool_keyword","specula","Specula is a C2 framework that allows for interactive operations of an implant that runs purely in the context of outlook","T1071.001 - T1105 - T1204 - T1548.002 - T1071 - T1562","TA0011 - TA0002 - TA0003 - TA0006 - TA0008 - TA0007 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/trustedsec/specula","1","1","N/A","N/A","10","10","191","21","2024-09-23T09:25:33Z","2023-12-07T15:59:52Z","47791" +"*https://hashcracking.ru*",".{0,1000}https\:\/\/hashcracking\.ru.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47792" +"*https://hashes.com*",".{0,1000}https\:\/\/hashes\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47793" +"*https://hashtoolkit.com/generate-hash/?text=*",".{0,1000}https\:\/\/hashtoolkit\.com\/generate\-hash\/\?text\=.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","47794" +"*https://i.imgur.com/RfsCOES.png*",".{0,1000}https\:\/\/i\.imgur\.com\/RfsCOES\.png.{0,1000}","offensive_tool_keyword","Prince-Ransomware","Go ransomware utilising ChaCha20 and ECIES encryption.","T1486 - T1489 - T1027","TA0040 - TA0009 ","N/A","N/A","Ransomware","https://github.com/SecDbg/Prince-Ransomware","1","1","N/A","N/A","10","","N/A","","","","47798" +"*https://itm4n.github.io/windows-registry-rpceptmapper-eop/*",".{0,1000}https\:\/\/itm4n\.github\.io\/windows\-registry\-rpceptmapper\-eop\/.{0,1000}","offensive_tool_keyword","Perfusion","Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)","T1068 - T1055 - T1548.002","TA0003 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/itm4n/Perfusion","1","1","N/A","N/A","10","5","419","75","2021-04-22T16:20:32Z","2021-02-11T18:28:22Z","47801" +"*https://kali.download*",".{0,1000}https\:\/\/kali\.download\/.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","47805" +"*https://lea.kz*",".{0,1000}https\:\/\/lea\.kz.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47806" +"*https://mainstream.ngrok.app/?method=UploadFile&filename=*",".{0,1000}https\:\/\/mainstream\.ngrok\.app\/\?method\=UploadFile\&filename\=.{0,1000}","offensive_tool_keyword","Kematian Stealer","Fake WinRar site distributes malware (+stealer +miner +hvnc +ransomware) from GitHub","T1195 - T1566 - T1569 - T1106 - T1486 - T1113","TA0001 - TA0002 - TA0005 - TA0006 - TA0007 - TA0009 - TA0010 - TA0011 - TA0040 - TA0043","N/A","N/A","Malware","https://github[.]com/sap3r-encrypthub/encrypthub","1","1","N/A","N/A","10","7","N/A","N/A","N/A","N/A","47815" +"*https://mastodon.be/@username_fzihfzuhfuoz/109994357971853428*",".{0,1000}https\:\/\/mastodon\.be\/\@username_fzihfzuhfuoz\/109994357971853428.{0,1000}","offensive_tool_keyword","REC2 ","REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in Rust.","T1105 - T1132 - T1071.001","TA0011 - TA0009 - TA0002","N/A","N/A","C2","https://github.com/g0h4n/REC2","1","1","N/A","N/A","10","10","153","23","2024-02-22T14:02:24Z","2023-09-25T20:39:59Z","47816" +"*https://mastodon.be/username_fzihfzuhfuoz/109743339821428173*",".{0,1000}https\:\/\/mastodon\.be\/username_fzihfzuhfuoz\/109743339821428173.{0,1000}","offensive_tool_keyword","REC2 ","REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in Rust.","T1105 - T1132 - T1071.001","TA0011 - TA0009 - TA0002","N/A","N/A","C2","https://github.com/g0h4n/REC2","1","1","N/A","N/A","10","10","153","23","2024-02-22T14:02:24Z","2023-09-25T20:39:59Z","47817" +"*https://md5.navisec.it*",".{0,1000}https\:\/\/md5\.navisec\.it.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47819" +"*https://md5decrypt.net*",".{0,1000}https\:\/\/md5decrypt\.net.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47820" +"*https://media0.giphy.com/media/l0IynvAIYxm8ZGUrm/giphy.gif?cid=ecf05e47qvbyv5iod2z91r9bufnpkvsjn1xm18a63b0g8z9a&ep=v1_gifs_related&rid=giphy.gif&ct=g*",".{0,1000}https\:\/\/media0\.giphy\.com\/media\/l0IynvAIYxm8ZGUrm\/giphy\.gif\?cid\=ecf05e47qvbyv5iod2z91r9bufnpkvsjn1xm18a63b0g8z9a\&ep\=v1_gifs_related\&rid\=giphy\.gif\&ct\=g.{0,1000}","offensive_tool_keyword","DEDSEC-RANSOMWARE","dedsec ransomware","T1486 - T1489 - T1490 - T1495 - T1488 - T1482","TA0040 - TA0043 - TA0042 - TA0009 - TA0010","N/A","N/A","Ransomware","https://github.com/xelroth/DEDSEC-RANSOMWARE","1","1","N/A","N/A","10","1","7","1","2024-05-17T11:12:23Z","2024-05-17T10:34:03Z","47830" +"*https://minio.pico.sh*",".{0,1000}https\:\/\/minio\.pico\.sh.{0,1000}","offensive_tool_keyword","pico","hacker labs - open source and managed web services leveraging SSH","T1021.005 - T1078 - T1105 - T1109 - T1197 - T1213","TA0005 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/picosh/pico","1","1","N/A","N/A","10","10","1129","36","2025-04-22T17:33:17Z","2022-08-24T03:14:52Z","47841" +"*https://mp.weixin.qq.com/s/GDPAC_9-Pxfcj_z0_C_ixw*",".{0,1000}https\:\/\/mp\.weixin\.qq\.com\/s\/GDPAC_9\-Pxfcj_z0_C_ixw.{0,1000}","offensive_tool_keyword","AVKiller","forcibly close some anti-virus processes through process injection (taking 360 Security Guard and 360 Anti-Virus as examples)","T1055.011 - T1089","TA0005 ","N/A","N/A","Defense Evasion","https://github.com/1y0n/AVKiller","1","1","N/A","N/A","10","2","127","18","2023-12-26T05:47:55Z","2023-12-19T00:55:23Z","47842" +"*https://mrd0x.com/progressive-web-apps-pwa-phishing*",".{0,1000}https\:\/\/mrd0x\.com\/progressive\-web\-apps\-pwa\-phishing.{0,1000}","offensive_tool_keyword","PWA-Phishing","Phishing with Progressive Web Apps and UI manipulation","T1071.003 - T1204.002 - T1608.003 - T1071.004","TA0006","N/A","N/A","Phishing","https://github.com/mrd0x/PWA-Phishing","1","1","N/A","N/A","10","3","288","52","2024-06-16T17:47:15Z","2024-06-09T19:47:52Z","47843" +"*https://nemesis.*.com/api/*",".{0,1000}https\:\/\/nemesis\..{0,1000}\.com\/api\/.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","47845" +"*https://nsocks.net/*",".{0,1000}https\:\/\/nsocks\.net\/.{0,1000}","offensive_tool_keyword","nsocks","proxy service that allows users to route their traffic through SOCKS5 proxie","T1090.002 - T1090 - T1071.001 - T1572","TA0011 - TA0005","N/A","Scattered Spider* - Black Basta","C2","https://github.com/bbepis/Nsocks","1","1","N/A","N/A","9","10","3","0","2020-06-08T17:25:07Z","2020-03-28T09:00:22Z","47849" +"*https://nsocks.net/proxy*",".{0,1000}https\:\/\/nsocks\.net\/proxy.{0,1000}","offensive_tool_keyword","nsocks","socks5 proxy provider","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","Scattered Spider* - Black Basta","C2","https://nsocks.net","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","47850" +"*https://nsocks4pvtcewb2ora3zk47ksx7dvazbxyhzp4myhegpthgkphpi7aad.onion/*",".{0,1000}https\:\/\/nsocks4pvtcewb2ora3zk47ksx7dvazbxyhzp4myhegpthgkphpi7aad\.onion\/.{0,1000}","offensive_tool_keyword","nsocks","socks5 proxy provider","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","Scattered Spider* - Black Basta","C2","https://nsocks.net","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","47851" +"*https://ntlm.pw*",".{0,1000}https\:\/\/ntlm\.pw.{0,1000}","offensive_tool_keyword","ntlm.pw","Database of NTLM hashes","T1003 - T1555 - T1558","TA0006","N/A","Black Basta","Credential Access","https://ntlm.pw","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","47853" +"*https://ntlm.pw/*",".{0,1000}https\:\/\/ntlm\.pw\/.{0,1000}","offensive_tool_keyword","NTLMSleuth","verify NTLM hash integrity against the robust database of ntlm.pw.","T1003 - T1555","TA0006","N/A","Black Basta","Credential Access","https://github.com/jmarr73/NTLMSleuth","1","1","N/A","N/A","8","1","8","0","2024-08-28T15:21:10Z","2023-12-12T16:41:35Z","47854" +"*https://passwordrecovery.io*",".{0,1000}https\:\/\/passwordrecovery\.io.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47858" +"*https://pastebin.com/9JyjcMAH*",".{0,1000}https\:\/\/pastebin\.com\/9JyjcMAH.{0,1000}","offensive_tool_keyword","Parasite-Invoke","Hide your P/Invoke signatures through other people's signed assemblies","T1129 - T1574.002 - T1218","TA0005","N/A","N/A","Defense Evasion","https://github.com/MzHmO/Parasite-Invoke","1","1","N/A","N/A","8","3","207","32","2024-03-10T14:53:59Z","2024-03-07T20:18:42Z","47859" +"*https://pastebin.com/iBeTbXCw*",".{0,1000}https\:\/\/pastebin\.com\/iBeTbXCw.{0,1000}","offensive_tool_keyword","Parasite-Invoke","Hide your P/Invoke signatures through other people's signed assemblies","T1129 - T1574.002 - T1218","TA0005","N/A","N/A","Defense Evasion","https://github.com/MzHmO/Parasite-Invoke","1","1","N/A","N/A","8","3","207","32","2024-03-10T14:53:59Z","2024-03-07T20:18:42Z","47860" +"*https://pastebin.com/raw/34gqdu7k*",".{0,1000}https\:\/\/pastebin\.com\/raw\/34gqdu7k.{0,1000}","offensive_tool_keyword","Lime-RAT","remote administration tool for Windows (RAT)","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","APT-C-36 - Operation Comando","Malware","https://github.com/NYAN-x-CAT/Lime-RAT","1","1","N/A","N/A","10","10","1086","413","2019-06-24T17:05:48Z","2018-02-07T15:35:56Z","47861" +"*https://pastebin.com/raw/88SGrHVh*",".{0,1000}https\:\/\/pastebin\.com\/raw\/88SGrHVh.{0,1000}","offensive_tool_keyword","Payload-Download-Cradles","download cradles to bypass AV/EPP/EDR in context of download cradle detections","T1105 - T1027 - T1203 - T1071","TA0005 - TA0009 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Payload-Download-Cradles","1","1","N/A","N/A","10","3","256","51","2022-07-07T07:20:36Z","2021-05-14T08:56:54Z","47862" +"*https://pastebin.com/raw/9kha6nwh*",".{0,1000}https\:\/\/pastebin\.com\/raw\/9kha6nwh.{0,1000}","offensive_tool_keyword","Lime-RAT","remote administration tool for Windows (RAT)","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","APT-C-36 - Operation Comando","Malware","https://github.com/NYAN-x-CAT/Lime-RAT","1","1","N/A","N/A","10","10","1086","413","2019-06-24T17:05:48Z","2018-02-07T15:35:56Z","47863" +"*https://pastebin.com/raw/DDTVwwbu*",".{0,1000}https\:\/\/pastebin\.com\/raw\/DDTVwwbu.{0,1000}","offensive_tool_keyword","Lime-RAT","remote administration tool for Windows (RAT)","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","APT-C-36 - Operation Comando","Malware","https://github.com/NYAN-x-CAT/Lime-RAT","1","1","N/A","N/A","10","10","1086","413","2019-06-24T17:05:48Z","2018-02-07T15:35:56Z","47864" +"*https://pastebin.com/raw/fevFJe98*",".{0,1000}https\:\/\/pastebin\.com\/raw\/fevFJe98.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","47865" +"*https://pastebin.com/raw/rGCQC1zq*",".{0,1000}https\:\/\/pastebin\.com\/raw\/rGCQC1zq.{0,1000}","offensive_tool_keyword","Lime-RAT","remote administration tool for Windows (RAT)","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","APT-C-36 - Operation Comando","Malware","https://github.com/NYAN-x-CAT/Lime-RAT","1","1","N/A","N/A","10","10","1086","413","2019-06-24T17:05:48Z","2018-02-07T15:35:56Z","47866" +"*https://phppasswordhash.com/*",".{0,1000}https\:\/\/phppasswordhash\.com\/.{0,1000}","offensive_tool_keyword","Gecko","Gecko Backdoor is a web php backdoor","T1100 - T1059 - T1105 - T1203","TA0011 - TA0003","N/A","N/A","C2","https://github.com/MadExploits/Gecko","1","1","N/A","N/A","10","10","118","56","2025-02-08T17:50:28Z","2022-07-15T05:51:04Z","47867" +"*https://pico.sh/getting-started*",".{0,1000}https\:\/\/pico\.sh\/getting\-started.{0,1000}","offensive_tool_keyword","pico","hacker labs - open source and managed web services leveraging SSH","T1021.005 - T1078 - T1105 - T1109 - T1197 - T1213","TA0005 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/picosh/pico","1","1","N/A","N/A","10","10","1129","36","2025-04-22T17:33:17Z","2022-08-24T03:14:52Z","47868" +"*https://pico.sh/tuns*",".{0,1000}https\:\/\/pico\.sh\/tuns.{0,1000}","offensive_tool_keyword","sish","An open source serveo/ngrok alternative. HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH","T1572 - T1090.002","TA0010 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antoniomika/sish","1","1","N/A","N/A","10","10","4203","325","2025-04-10T20:04:08Z","2019-02-15T15:36:23Z","47869" +"*https://privatix-temp-mail-v1.p.rapidapi.com/request/domains/*",".{0,1000}https\:\/\/privatix\-temp\-mail\-v1\.p\.rapidapi\.com\/request\/domains\/.{0,1000}","offensive_tool_keyword","ShellSync","using the API of a disposable email address to use anytime - could be abused by malicious actors","T1071.003","TA0005 - TA0001","N/A","N/A","Defense Evasion","https://github.com/I-Am-Jakoby/ShellSync","1","1","N/A","N/A","5","1","20","7","2023-11-08T18:01:18Z","2023-11-06T06:05:11Z","47874" +"*https://privatix-temp-mail-v1.p.rapidapi.com/request/mail/id/null/*",".{0,1000}https\:\/\/privatix\-temp\-mail\-v1\.p\.rapidapi\.com\/request\/mail\/id\/null\/.{0,1000}","offensive_tool_keyword","ShellSync","using the API of a disposable email address to use anytime - could be abused by malicious actors","T1071.003","TA0005 - TA0001","N/A","N/A","Defense Evasion","https://github.com/I-Am-Jakoby/ShellSync","1","1","N/A","N/A","5","1","20","7","2023-11-08T18:01:18Z","2023-11-06T06:05:11Z","47876" +"*https://proxy.duckduckgo.com/iu/?u=https://pdxkmdcepvahysnnxe.pythonanywhere.com/image.jpg?cmd=*",".{0,1000}https\:\/\/proxy\.duckduckgo\.com\/iu\/\?u\=https\:\/\/pdxkmdcepvahysnnxe\.pythonanywhere\.com\/image\.jpg\?cmd\=.{0,1000}","offensive_tool_keyword","DuckDuckC2","A proof-of-concept C2 channel through DuckDuckGo's image proxy service","T1071.001 - T1090.003","TA0011 - TA0042","N/A","N/A","C2","https://github.com/nopcorn/DuckDuckC2","1","1","N/A","N/A","10","10","74","6","2023-11-12T10:24:59Z","2023-09-23T20:00:09Z","47879" +"*https://ptb.discord.com/api/webhooks/1226217588959215726/AZaNnD4TIN-9sV-t0rsveiQxcROYaCVziI8BUa6CNPsUxdnW9mdHu7HnuQ55kQPXZ8_5*",".{0,1000}https\:\/\/ptb\.discord\.com\/api\/webhooks\/1226217588959215726\/AZaNnD4TIN\-9sV\-t0rsveiQxcROYaCVziI8BUa6CNPsUxdnW9mdHu7HnuQ55kQPXZ8_5.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","1","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","47880" +"*https://pyobfuscate.com/pyd*",".{0,1000}https\:\/\/pyobfuscate\.com\/pyd.{0,1000}","offensive_tool_keyword","DEDSEC-RANSOMWARE","dedsec ransomware","T1486 - T1489 - T1490 - T1495 - T1488 - T1482","TA0040 - TA0043 - TA0042 - TA0009 - TA0010","N/A","N/A","Ransomware","https://github.com/xelroth/DEDSEC-RANSOMWARE","1","1","N/A","N/A","10","1","7","1","2024-05-17T11:12:23Z","2024-05-17T10:34:03Z","47887" +"*https://pyobfuscate.com/pyd*",".{0,1000}https\:\/\/pyobfuscate\.com\/pyd.{0,1000}","offensive_tool_keyword","pyobfuscate","ADVANCED PYTHON OBFUSCATOR","T1027 - T1027.009","TA0005","N/A","N/A","Defense Evasion","https://pyobfuscate.com/pyd","1","1","N/A","N/A","8","10","N/A","N/A","N/A","N/A","47888" +"*https://ratte.ngrok.app/main/mainer*",".{0,1000}https\:\/\/ratte\.ngrok\.app\/main\/mainer.{0,1000}","offensive_tool_keyword","Kematian Stealer","Fake WinRar site distributes malware (+stealer +miner +hvnc +ransomware) from GitHub","T1195 - T1566 - T1569 - T1106 - T1486 - T1113","TA0001 - TA0002 - TA0005 - TA0006 - TA0007 - TA0009 - TA0010 - TA0011 - TA0040 - TA0043","N/A","N/A","Malware","https://github[.]com/sap3r-encrypthub/encrypthub","1","1","N/A","N/A","10","7","N/A","N/A","N/A","N/A","47899" +"*https://raw.githubusercontent.com/*/msg_x64.dll*",".{0,1000}https\:\/\/raw\.githubusercontent\.com\/.{0,1000}\/msg_x64\.dll.{0,1000}","offensive_tool_keyword","CLR-Injection","Use CLR to inject all the .NET apps","T1055.009","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/3gstudent/CLR-Injection","1","1","N/A","N/A","8","2","183","45","2021-04-17T01:39:32Z","2017-07-27T03:00:04Z","47900" +"*https://raw.githubusercontent.com/*/test/master/msg.dll*",".{0,1000}https\:\/\/raw\.githubusercontent\.com\/.{0,1000}\/test\/master\/msg\.dll.{0,1000}","offensive_tool_keyword","CLR-Injection","Use CLR to inject all the .NET apps","T1055.009","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/3gstudent/CLR-Injection","1","1","N/A","N/A","8","2","183","45","2021-04-17T01:39:32Z","2017-07-27T03:00:04Z","47901" +"*https://raw.githubusercontent.com/BlackArch/blackarch/master/mirror/mirror.lst*",".{0,1000}https\:\/\/raw\.githubusercontent\.com\/BlackArch\/blackarch\/master\/mirror\/mirror\.lst.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","47902" +"*https://raw.githubusercontent.com/KasRoudra/CamHacker*",".{0,1000}https\:\/\/raw\.githubusercontent\.com\/KasRoudra\/CamHacker.{0,1000}","offensive_tool_keyword","CamHacker","Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!","T1598 - T1204 - T1566.001","TA0009 - TA0010 - TA0043","N/A","N/A","Phishing","https://github.com/KasRoudra/CamHacker","1","1","N/A","N/A","10","","N/A","","","","47903" +"*https://raw.githubusercontent.com/KDot227/*",".{0,1000}https\:\/\/raw\.githubusercontent\.com\/KDot227\/.{0,1000}","offensive_tool_keyword","SomalifuscatorV2","windows batch obfuscator","T1027 - T1497 - T1057","TA0005","N/A","N/A","Defense Evasion","https://github.com/KDot227/SomalifuscatorV2","1","1","N/A","N/A","10","4","315","42","2025-01-19T04:30:49Z","2022-09-23T00:46:51Z","47904" +"*https://raw.githubusercontent.com/stamparm/aux/master/fetch-some-list.txt*",".{0,1000}https\:\/\/raw\.githubusercontent\.com\/stamparm\/aux\/master\/fetch\-some\-list\.txt.{0,1000}","offensive_tool_keyword","fetch-some-proxies","Simple Python script for fetching ""some"" (usable) proxies","T1090 - T1071 - T1070","TA0002 - TA0005 - TA0010","N/A","N/A","Defense Evasion","https://github.com/stamparm/fetch-some-proxies","1","1","N/A","N/A","9","6","585","138","2023-03-15T09:14:25Z","2016-10-09T22:39:56Z","47905" +"*https://reedarvin.thearvins.com/*",".{0,1000}https\:\/\/reedarvin\.thearvins\.com\/.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","1","N/A","N/A","10","8","N/A","N/A","N/A","N/A","47908" +"*https://saycheese*.serveo.net*",".{0,1000}https\:\/\/saycheese.{0,1000}\.serveo\.net.{0,1000}","offensive_tool_keyword","saycheese","Grab target's webcam shots by link","T1213 - T1071 - T1102 - T1123 - T1185 - T1200","TA0001 - TA0005 - TA0009 - TA0011","N/A","N/A","Phishing","https://github.com/hangetzzu/saycheese","1","1","N/A","N/A","9","10","1175","962","2024-06-18T23:39:41Z","2019-04-29T04:07:00Z","47918" +"*https://sharpsploit.cobbr.io/api*",".{0,1000}https\:\/\/sharpsploit\.cobbr\.io\/api.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","47927" +"*https://shop.hak5.org/pages/cloud-c2-feedback*",".{0,1000}https\:\/\/shop\.hak5\.org\/pages\/cloud\-c2\-feedback.{0,1000}","offensive_tool_keyword","hak5 cloudc2","Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud","T1021 - T1102 - T1213","TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://shop.hak5.org/products/c2?","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","47928" +"*https://sliver.sh/install*",".{0,1000}https\:\/\/sliver\.sh\/install.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","47932" +"*https://sniff.su/*.gz*",".{0,1000}https\:\/\/sniff\.su\/.{0,1000}\.gz.{0,1000}","offensive_tool_keyword","Intercepter-NG","android wifi sniffer","T1433","TA0006","N/A","N/A","Sniffing & Spoofing","https://github.com/intercepter-ng","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","47933" +"*https://sniff.su/*.zip*",".{0,1000}https\:\/\/sniff\.su\/.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","Intercepter-NG","android wifi sniffer","T1433","TA0006","N/A","N/A","Sniffing & Spoofing","https://github.com/intercepter-ng","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","47934" +"*https://sourceforge.net/projects/winexe*",".{0,1000}https\:\/\/sourceforge\.net\/projects\/winexe.{0,1000}","offensive_tool_keyword","winexe","Winexe remotely executes commands on Windows systems from GNU/Linux","T1059.004 - T1021.005 - T1078.003","TA0002 - TA0008 - TA0011","N/A","APT28","Lateral Movement","https://www.kali.org/tools/winexe/","1","1","#linux #windows","N/A","8","8","N/A","N/A","N/A","N/A","47935" +"*https://sped.lol/*",".{0,1000}https\:\/\/sped\.lol\/.{0,1000}","offensive_tool_keyword","SomalifuscatorV2","windows batch obfuscator","T1027 - T1497 - T1057","TA0005","N/A","N/A","Defense Evasion","https://github.com/KDot227/SomalifuscatorV2","1","1","N/A","N/A","10","4","315","42","2025-01-19T04:30:49Z","2022-09-23T00:46:51Z","47937" +"*https://SSHamble.com/*",".{0,1000}https\:\/\/SSHamble\.com\/.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","1","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","47938" +"*https://sysdig.com/blog/hiding-linux-processes-for-fun-and-profit/*",".{0,1000}https\:\/\/sysdig\.com\/blog\/hiding\-linux\-processes\-for\-fun\-and\-profit\/.{0,1000}","offensive_tool_keyword","libprocesshider","Hide a process under Linux using the ld preloader","T1055 - T1564 - T1620","TA0005 ","N/A","Sandworm","Defense Evasion","https://github.com/gianlucaborello/libprocesshider","1","1","#linux","N/A","9","10","1061","320","2019-08-02T14:28:28Z","2014-08-16T01:09:30Z","47944" +"*https://t.me/BotFather*",".{0,1000}https\:\/\/t\.me\/BotFather.{0,1000}","offensive_tool_keyword","TelegramRAT","Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions","T1071.001 - T1105 - T1027","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/machine1337/TelegramRAT","1","1","N/A","N/A","10","10","372","62","2024-01-23T12:05:59Z","2023-06-30T10:59:55Z","47945" +"*https://t.me/eightbase*",".{0,1000}https\:\/\/t\.me\/eightbase.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","47946" +"*https://t.me/encrypthub*",".{0,1000}https\:\/\/t\.me\/encrypthub.{0,1000}","offensive_tool_keyword","Kematian Stealer","Fake WinRar site distributes malware (+stealer +miner +hvnc +ransomware) from GitHub","T1195 - T1566 - T1569 - T1106 - T1486 - T1113","TA0001 - TA0002 - TA0005 - TA0006 - TA0007 - TA0009 - TA0010 - TA0011 - TA0040 - TA0043","N/A","N/A","Malware","https://github[.]com/sap3r-encrypthub/encrypthub","1","1","N/A","N/A","10","7","N/A","N/A","N/A","N/A","47947" +"*https://t.me/machine1337*",".{0,1000}https\:\/\/t\.me\/machine1337.{0,1000}","offensive_tool_keyword","TelegramRAT","Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions","T1071.001 - T1105 - T1027","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/machine1337/TelegramRAT","1","1","N/A","N/A","10","10","372","62","2024-01-23T12:05:59Z","2023-06-30T10:59:55Z","47948" +"*https://t.me/MegaMedusaLog*",".{0,1000}https\:\/\/t\.me\/MegaMedusaLog.{0,1000}","offensive_tool_keyword","MegaMedusa","MegaMedusa is DDoS tool using NodeJS language","T1498 - T1498.001","TA0040","N/A","N/A","DDOS","https://github.com/TrashDono/MegaMedusa","1","1","N/A","N/A","7","3","221","76","2025-03-20T17:26:23Z","2024-04-09T11:57:14Z","47949" +"*https://t.me/moom825*",".{0,1000}https\:\/\/t\.me\/moom825.{0,1000}","offensive_tool_keyword","xeno-rat","Xeno-RAT is an open-source remote access tool (RAT) developed in C# providing a comprehensive set of features for remote system management. Has features such as HVNC - live microphone - reverse proxy and much much more","T1133 - T1021.001 - T1563.002 - T1113 - T1123 - T1571 - T1090","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011","N/A","N/A","C2","https://github.com/moom825/xeno-rat","1","1","N/A","N/A","10","10","1225","323","2024-03-05T06:22:36Z","2023-10-17T06:41:56Z","47950" +"*https://t.me/NovaGroup2023*",".{0,1000}https\:\/\/t\.me\/NovaGroup2023.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","47951" +"*https://t.me/peass*",".{0,1000}https\:\/\/t\.me\/peass.{0,1000}","offensive_tool_keyword","PEASS-ng","PEASS-ng - Privilege Escalation Awesome Scripts suite","T1098","TA0004 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/peass-ng/PEASS-ng","1","1","N/A","N/A","10","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","47952" +"*https://t.me/ransom_house*",".{0,1000}https\:\/\/t\.me\/ransom_house.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","47953" +"*https://thc.org/hs*",".{0,1000}https\:\/\/thc\.org\/hs.{0,1000}","offensive_tool_keyword","hackshell","Make BASH stealthy and hacker friendly with lots of bash functions","T1070.003 - T1059.004 - T1564.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/hackerschoice/hackshell","1","1","N/A","N/A","9","3","251","28","2025-04-21T11:23:41Z","2024-07-16T15:56:11Z","47961" +"*https://tor2web.*","https\:\/\/tor2web\..{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","47964" +"*https://transfer.sh/get/*/*.pdf*",".{0,1000}https\:\/\/transfer\.sh\/get\/.{0,1000}\/.{0,1000}\.pdf.{0,1000}","offensive_tool_keyword","transfer.sh","Downloading pdf from transfer.sh","T1105 - T1204 - T1071 - T1195","TA0002 - TA0005 - TA0006","N/A","Black Basta","Collection","https://medium.com/checkmarx-security/python-obfuscation-traps-1acced941375","1","1","#filehostingservice","N/A","10","8","N/A","N/A","N/A","N/A","47968" +"*https://transfer.sh/get/*/*.py*","https\:\/\/transfer\.sh\/get\/.{0,1000}\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","transfer.sh","Downloading python scripts from transfer.sh","T1105 - T1204 - T1071 - T1195","TA0002 - TA0005 - TA0006","N/A","Black Basta","Collection","https://medium.com/checkmarx-security/python-obfuscation-traps-1acced941375","1","1","#filehostingservice","N/A","10","8","N/A","N/A","N/A","N/A","47969" +"*https://trufflesecurity.com/canaries*",".{0,1000}https\:\/\/trufflesecurity\.com\/canaries.{0,1000}","offensive_tool_keyword","truffleHog","Searches through git repositories for secrets. digging deep into commit history and branches. This is effective at finding secrets accidentally committed.","T1552 - T1596 - T1083","TA0009 - TA0005 - TA0002","N/A","Scattered Spider*","Reconnaissance","https://github.com/dxa4481/truffleHog","1","1","#linux","N/A","6","10","18812","1839","2025-04-22T17:32:40Z","2016-12-31T05:08:12Z","47972" +"*https://tuns.sh*",".{0,1000}https\:\/\/tuns\.sh.{0,1000}","offensive_tool_keyword","sish","An open source serveo/ngrok alternative. HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH","T1572 - T1090.002","TA0010 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antoniomika/sish","1","1","N/A","N/A","10","10","4203","325","2025-04-10T20:04:08Z","2019-02-15T15:36:23Z","47976" +"*https://unit259.fyi/db*",".{0,1000}https\:\/\/unit259\.fyi\/db.{0,1000}","offensive_tool_keyword","DataBouncing","Data Bouncing is a technique for transmitting data between two endpoints using DNS lookups and HTTP header manipulation","T1048 - T1041","TA0010","N/A","N/A","Data Exfiltration","https://github.com/Unit-259/DataBouncing","1","1","N/A","N/A","9","1","15","0","2025-03-12T07:34:04Z","2025-03-12T06:58:51Z","47980" +"*https://viperone.gitbook.io/pentest-everything*",".{0,1000}https\:\/\/viperone\.gitbook\.io\/pentest\-everything.{0,1000}","offensive_tool_keyword","PSMapExec","A PowerShell tool heavily inspired by the popular tool CrackMapExec. Far too often I find myself on engagements without access to Linux in order to make use of CrackMapExec.","T1059.001 - T1021.006 - T1110.001 - T1021.001 - T1021.004 - T1021.005 - T1021.003 - T1621","TA0002 - TA0011 - TA0005 - TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/The-Viper-One/PsMapExec","1","1","N/A","N/A","10","10","954","108","2025-03-11T14:38:50Z","2023-06-20T16:57:27Z","47985" +"*https://weakpass.com/*",".{0,1000}https\:\/\/weakpass\.com\/.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","47988" +"*https://web.archive.org/*https://www.kernel-exploits.com/media/*",".{0,1000}https\:\/\/web\.archive\.org\/.{0,1000}https\:\/\/www\.kernel\-exploits\.com\/media\/.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","47989" +"*https://wfuzz.readthedocs.io*",".{0,1000}https\:\/\/wfuzz\.readthedocs\.io.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","47993" +"*https://whoamianony.top/posts/*",".{0,1000}https\:\/\/whoamianony\.top\/posts\/.{0,1000}","offensive_tool_keyword","SharpRODC","audit the security of read-only domain controllers","T1012 - T1482 - T1207 - T1208 - T1209 - T1212","TA0007 - TA0008 - TA0006","N/A","N/A","Discovery","https://github.com/wh0amitz/SharpRODC","1","1","N/A","N/A","8","2","115","8","2023-11-27T12:41:52Z","2023-11-24T14:35:49Z","47994" +"*https://www.1secmail.com/api/v1/?action=getDomainList*",".{0,1000}https\:\/\/www\.1secmail\.com\/api\/v1\/\?action\=getDomainList.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","47995" +"*https://www.1secmail.com/api/v1/?action=getMessages&login=*",".{0,1000}https\:\/\/www\.1secmail\.com\/api\/v1\/\?action\=getMessages\&login\=.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","47996" +"*https://www.1secmail.com/api/v1/?action=readMessage&login=*",".{0,1000}https\:\/\/www\.1secmail\.com\/api\/v1\/\?action\=readMessage\&login\=.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","47997" +"*https://www.blackarch.org/blackarch/blackarch/lastupdate*",".{0,1000}https\:\/\/www\.blackarch\.org\/blackarch\/blackarch\/lastupdate.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","48000" +"*https://www.blackhillsinfosec.com/bypass-anti-virus-run-mimikatz*",".{0,1000}https\:\/\/www\.blackhillsinfosec\.com\/bypass\-anti\-virus\-run\-mimikatz.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","1","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","48001" +"*https://www.browserling.com/browse*",".{0,1000}https\:\/\/www\.browserling\.com\/browse.{0,1000}","offensive_tool_keyword","browserling","proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","browserling.com","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","48002" +"*https://www.hashkill.com*",".{0,1000}https\:\/\/www\.hashkill\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","48010" +"*https://www.joeware.net/downloads/dl2.php*",".{0,1000}https\:\/\/www\.joeware\.net\/downloads\/dl2\.php.{0,1000}","offensive_tool_keyword","NetSess","Command line tool to enumerate NetBIOS sessions on a specified local or remote machine. ","T1016 - T1046 - T1087","TA0007 - TA0043","N/A","MUSTANG PANDA","Discovery","https://www.joeware.net/freetools/tools/netsess/","1","1","N/A","could be any joeware softwares","7","9","N/A","N/A","N/A","N/A","48011" +"*https://www.myget.org/F/fireeye/api/v2*",".{0,1000}https\:\/\/www\.myget\.org\/F\/fireeye\/api\/v2.{0,1000}","offensive_tool_keyword","commando-vm","CommandoVM - a fully customizable Windows-based security distribution for penetration testing and red teaming.","T1059 - T1053 - T1055 - T1070","TA0002 - TA0004 - TA0008","N/A","N/A","Exploitation OS","https://github.com/mandiant/commando-vm","1","1","N/A","N/A","N/A","10","7168","1313","2024-09-24T19:14:18Z","2019-03-26T22:36:32Z","48015" +"*https://www.nirsoft.net/utils/webcamimagesave.zip*","https\:\/\/www\.nirsoft\.net\/utils\/webcamimagesave\.zip","offensive_tool_keyword","nirsoft","designed to capture webcam images","T1125 - T1056.004 - T1140","TA0005 - TA0006","N/A","N/A","Collection","https://medium.com/checkmarx-security/python-obfuscation-traps-1acced941375","1","1","N/A","N/A","10","8","N/A","N/A","N/A","N/A","48021" +"*https://www.somd5.com*",".{0,1000}https\:\/\/www\.somd5\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","48029" +"*https://www.sordum.org/downloads/?st-defender-control*",".{0,1000}https\:\/\/www\.sordum\.org\/downloads\/\?st\-defender\-control.{0,1000}","offensive_tool_keyword","defender-control","disable windows defender permanently","T1562.001 - T1562.004 - T1089","TA0005 - TA0002","N/A","LockBit","Defense Evasion","https://www.sordum.org/9480/defender-control-v2-1/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","48030" +"*https://www.synacktiv.com/publications/ounedpy-exploiting-hidden-organizational-units-acl-attack-vectors-in-active-directory*",".{0,1000}https\:\/\/www\.synacktiv\.com\/publications\/ounedpy\-exploiting\-hidden\-organizational\-units\-acl\-attack\-vectors\-in\-active\-directory.{0,1000}","offensive_tool_keyword","Ouned","The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning","T1484 - T1210","TA0001 - TA0004 - TA0005 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/synacktiv/Ouned","1","1","N/A","N/A","10","2","112","14","2025-03-29T14:20:38Z","2024-04-17T10:18:04Z","48031" +"*https://www.trustedsec.com/blog/abusing-windows-telemetry-for-persistence/*",".{0,1000}https\:\/\/www\.trustedsec\.com\/blog\/abusing\-windows\-telemetry\-for\-persistence\/.{0,1000}","offensive_tool_keyword","Telemetry","Abusing Windows Telemetry for persistence through registry modifications and scheduled tasks to execute arbitrary commands with system-level privileges.","T1053 - T1547 - T1059","TA0003 - TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/Imanfeng/Telemetry","1","1","N/A","N/A","9","2","140","13","2020-07-02T09:41:27Z","2020-06-24T16:30:44Z","48033" +"*https://www.win-rar.co/panel/*",".{0,1000}https\:\/\/www\.win\-rar\.co\/panel\/.{0,1000}","offensive_tool_keyword","Kematian Stealer","Fake WinRar site distributes malware (+stealer +miner +hvnc +ransomware) from GitHub","T1195 - T1566 - T1569 - T1106 - T1486 - T1113","TA0001 - TA0002 - TA0005 - TA0006 - TA0007 - TA0009 - TA0010 - TA0011 - TA0040 - TA0043","N/A","N/A","Malware","https://github[.]com/sap3r-encrypthub/encrypthub","1","1","N/A","N/A","10","7","N/A","N/A","N/A","N/A","48034" +"*https://youareanidiot.cc*",".{0,1000}https\:\/\/youareanidiot\.cc.{0,1000}","offensive_tool_keyword","Fentanyl","Stealer Malware - Steal Discord Tokens (+ Much More Info) - Steal Passwords/Cookies/History/Credit Cards/Phone Numbers and Addresses from all Browsers (Profile Support) - Steal PC Info - Steal Video Game Accounts (Adding more games + wallets and VPN's) - Low Detections - Anti VM - Sort of Fast - Startup - IP Logger","T1547.001 - T1552.001 - T1552.005 - T1110.001 - T1082 - T1562.001 - T1574.002 - T1529 - T1497.001 - T1543.003 - T1592.001","TA0005 - TA0006 - TA0040 - TA0003 - TA0009","N/A","N/A","Malware","https://github.com/dekrypted/Fentanyl","1","1","N/A","N/A","10","","N/A","","","","48039" +"*https://YOURREDIRECTWEBSERVER.azurewebsites.net*",".{0,1000}https\:\/\/YOURREDIRECTWEBSERVER\.azurewebsites\.net.{0,1000}","offensive_tool_keyword","GraphRunner","A Post-exploitation Toolset for Interacting with the Microsoft Graph API","T1059.007 - T1087.001 - T1078.001 - T1585.001 - T1071.001","TA0002 - TA0003 - TA0008 - TA0011","N/A","N/A","Exploitation tool","https://github.com/dafthack/GraphRunner","1","1","N/A","N/A","10","10","1082","127","2024-11-07T04:40:34Z","2023-08-15T17:19:11Z","48040" +"*https_payload_localtunnel.ps1*",".{0,1000}https_payload_localtunnel\.ps1.{0,1000}","offensive_tool_keyword","hoaxshell","An unconventional Windows reverse shell. currently undetected by Microsoft Defender and various other AV solutions. solely based on http(s) traffic","T1059 - T1071 - T1071.001 - T1203","TA0002 - TA0011","N/A","N/A","C2","https://github.com/t3l3machus/hoaxshell","1","1","N/A","N/A","N/A","10","3212","499","2025-01-19T12:29:35Z","2022-07-10T15:36:24Z","48044" +"*https_payload_localtunnel_outfile.ps1*",".{0,1000}https_payload_localtunnel_outfile\.ps1.{0,1000}","offensive_tool_keyword","hoaxshell","An unconventional Windows reverse shell. currently undetected by Microsoft Defender and various other AV solutions. solely based on http(s) traffic","T1059 - T1071 - T1071.001 - T1203","TA0002 - TA0011","N/A","N/A","C2","https://github.com/t3l3machus/hoaxshell","1","1","N/A","N/A","N/A","10","3212","499","2025-01-19T12:29:35Z","2022-07-10T15:36:24Z","48045" +"*https_payload_ngrok.ps1*",".{0,1000}https_payload_ngrok\.ps1.{0,1000}","offensive_tool_keyword","hoaxshell","An unconventional Windows reverse shell. currently undetected by Microsoft Defender and various other AV solutions. solely based on http(s) traffic","T1059 - T1071 - T1071.001 - T1203","TA0002 - TA0011","N/A","N/A","C2","https://github.com/t3l3machus/hoaxshell","1","1","N/A","N/A","N/A","10","3212","499","2025-01-19T12:29:35Z","2022-07-10T15:36:24Z","48046" +"*https_payload_ngrok_outfile.ps1*",".{0,1000}https_payload_ngrok_outfile\.ps1.{0,1000}","offensive_tool_keyword","hoaxshell","An unconventional Windows reverse shell. currently undetected by Microsoft Defender and various other AV solutions. solely based on http(s) traffic","T1059 - T1071 - T1071.001 - T1203","TA0002 - TA0011","N/A","N/A","C2","https://github.com/t3l3machus/hoaxshell","1","1","N/A","N/A","N/A","10","3212","499","2025-01-19T12:29:35Z","2022-07-10T15:36:24Z","48047" +"*https_payload_trusted.ps1*",".{0,1000}https_payload_trusted\.ps1.{0,1000}","offensive_tool_keyword","hoaxshell","An unconventional Windows reverse shell. currently undetected by Microsoft Defender and various other AV solutions. solely based on http(s) traffic","T1059 - T1071 - T1071.001 - T1203","TA0002 - TA0011","N/A","N/A","C2","https://github.com/t3l3machus/hoaxshell","1","1","N/A","N/A","N/A","10","3212","499","2025-01-19T12:29:35Z","2022-07-10T15:36:24Z","48048" +"*https_revshell.exe*",".{0,1000}https_revshell\.exe.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","48049" +"*httpsmuggler.jar*",".{0,1000}httpsmuggler\.jar.{0,1000}","offensive_tool_keyword","burpsuite","Collection of burpsuite plugins","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","network exploitation tool","N/A","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","48051" +"*Huan.sln*",".{0,1000}Huan\.sln.{0,1000}","offensive_tool_keyword","Huan","Huan is an encrypted PE Loader Generator that I developed for learning PE file structure and PE loading processes. It encrypts the PE file to be run with different keys each time and embeds it in a new section of the loader binary. Currently. it works on 64 bit PE files.","T1027 - T1036 - T1564 - T1003 - T1056 - T1204 - T1588 - T1620","TA0002 - TA0008 - ","N/A","N/A","Exploitation tool","https://github.com/frkngksl/Huan","1","1","N/A","N/A","N/A","6","540","107","2021-08-13T10:48:26Z","2021-05-21T08:55:02Z","48054" +"*Huan.vcxproj*",".{0,1000}Huan\.vcxproj.{0,1000}","offensive_tool_keyword","Huan","Huan is an encrypted PE Loader Generator that I developed for learning PE file structure and PE loading processes. It encrypts the PE file to be run with different keys each time and embeds it in a new section of the loader binary. Currently. it works on 64 bit PE files.","T1027 - T1036 - T1564 - T1003 - T1056 - T1204 - T1588 - T1620","TA0002 - TA0008 - ","N/A","N/A","Exploitation tool","https://github.com/frkngksl/Huan","1","1","N/A","N/A","N/A","6","540","107","2021-08-13T10:48:26Z","2021-05-21T08:55:02Z","48055" +"*HuanLoader.vcxproj*",".{0,1000}HuanLoader\.vcxproj.{0,1000}","offensive_tool_keyword","Huan","Huan is an encrypted PE Loader Generator that I developed for learning PE file structure and PE loading processes. It encrypts the PE file to be run with different keys each time and embeds it in a new section of the loader binary. Currently. it works on 64 bit PE files.","T1027 - T1036 - T1564 - T1003 - T1056 - T1204 - T1588 - T1620","TA0002 - TA0008 - ","N/A","N/A","Exploitation tool","https://github.com/frkngksl/Huan","1","1","N/A","N/A","N/A","6","540","107","2021-08-13T10:48:26Z","2021-05-21T08:55:02Z","48056" +"*hub.docker.com/u/kalilinux/*",".{0,1000}hub\.docker\.com\/u\/kalilinux\/.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","48057" +"*HunnicCyber/SharpDomainSpray*",".{0,1000}HunnicCyber\/SharpDomainSpray.{0,1000}","offensive_tool_keyword","SharpDomainSpray","Basic password spraying tool for internal tests and red teaming","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/HunnicCyber/SharpDomainSpray","1","1","N/A","N/A","10","1","90","18","2020-03-21T09:17:48Z","2019-06-05T10:47:05Z","48060" +"*hunters33dootzzwybhxyh6xnmumopeoza6u4hkontdqu7awnhmix7ad.onion*",".{0,1000}hunters33dootzzwybhxyh6xnmumopeoza6u4hkontdqu7awnhmix7ad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","48061" +"*hunters33mmcwww7ek7q5ndahul6nmzmrsumfs6aenicbqon6mxfiqyd.onion*",".{0,1000}hunters33mmcwww7ek7q5ndahul6nmzmrsumfs6aenicbqon6mxfiqyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","48062" +"*hunters55atbdusuladzv7vzv6a423bkh6ksl2uftwrxyuarbzlfh7yd.onion*",".{0,1000}hunters55atbdusuladzv7vzv6a423bkh6ksl2uftwrxyuarbzlfh7yd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","48063" +"*hunters55rdxciehoqzwv7vgyv6nt37tbwax2reroyzxhou7my5ejyid.onion*",".{0,1000}hunters55rdxciehoqzwv7vgyv6nt37tbwax2reroyzxhou7my5ejyid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","48064" +"*hXOR-Packer.v0.1.zip*",".{0,1000}hXOR\-Packer\.v0\.1\.zip.{0,1000}","offensive_tool_keyword","hXOR-Packer","hXOR Packer is a PE (Portable Executable) packer with Huffman Compression and Xor encryption.","T1027 - T1048.003 - T1140 - T1205.001","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/akuafif/hXOR-Packer","1","1","N/A","N/A","9","1","57","14","2021-09-11T13:00:34Z","2020-11-19T14:57:03Z","48070" +"*hxt254aygrsziejn.onion*",".{0,1000}hxt254aygrsziejn\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","48072" +"*hydra-cobaltstrike*",".{0,1000}hydra\-cobaltstrike.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","48081" +"*hyperion_2.0.orig.tar.gz*",".{0,1000}hyperion_2\.0\.orig\.tar\.gz.{0,1000}","offensive_tool_keyword","hyperion","A runtime PE-Crypter - The crypter is started via the command line and encrypts an input executable with AES-128. The encrypted file decrypts itself on startup (bruteforcing the AES key which may take a few seconds)","T1027.002 - T1059.001 - T1116","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://www.kali.org/tools/hyperion/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","48085" +"*Hyper-V-Hypervisor-Downgrade/Config.xml*",".{0,1000}Hyper\-V\-Hypervisor\-Downgrade\/Config\.xml.{0,1000}","offensive_tool_keyword","WindowsDowndate","A tool that takes over Windows Updates to craft custom downgrades and expose past fixed vulnerabilities","T1072 - T1486 - T1505.002 - T1495 - T1499.004","TA0005 - TA0004 - TA0003 ","N/A","N/A","Defense Evasion","https://github.com/SafeBreach-Labs/WindowsDowndate","1","1","N/A","N/A","10","7","663","88","2024-10-26T10:18:49Z","2024-01-08T19:42:47Z","48088" +"*Hypnos-main.zip*",".{0,1000}Hypnos\-main\.zip.{0,1000}","offensive_tool_keyword","Hypnos","indirect syscalls - the Win API functions are not hooked by AV/EDR - bypass EDR detections","T1055.012 - T1136.001 - T1070.004 - T1055.001","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/CaptainNox/Hypnos","1","1","N/A","N/A","10","1","49","6","2024-02-12T17:51:24Z","2023-07-11T09:07:10Z","48089" +"*hypobrychium.exe*",".{0,1000}hypobrychium\.exe.{0,1000}","offensive_tool_keyword","hypobrychium","hypobrychium AV/EDR Bypass","T1562.001 - T1070.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/foxlox/hypobrychium","1","1","N/A","N/A","8","1","72","21","2023-07-21T21:13:20Z","2023-07-18T09:55:07Z","48091" +"*hypobrychium-main*",".{0,1000}hypobrychium\-main.{0,1000}","offensive_tool_keyword","hypobrychium","hypobrychium AV/EDR Bypass","T1562.001 - T1070.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/foxlox/hypobrychium","1","1","N/A","N/A","8","1","72","21","2023-07-21T21:13:20Z","2023-07-18T09:55:07Z","48092" +"*i2pinstall*",".{0,1000}i2pinstall.{0,1000}","offensive_tool_keyword","I2P","I2P - The Invisible Internet Project.","T1048.001 - T1568.003","TA0011 - TA0040","N/A","N/A","Data Exfiltration","https://geti2p.net/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","48103" +"*I-Am-Jakoby/ShellSync*",".{0,1000}I\-Am\-Jakoby\/ShellSync.{0,1000}","offensive_tool_keyword","ShellSync","exposing a server with suspicious scripts and executable from I-Am-Jakoby","T1059.003 - T1100 - T1027","TA0005 - TA0009 - TA0011 ","N/A","N/A","Data Exfiltration","https://github.com/I-Am-Jakoby/ShellSync","1","1","N/A","N/A","5","1","20","7","2023-11-08T18:01:18Z","2023-11-06T06:05:11Z","48108" +"*iammaguire/Gotato*",".{0,1000}iammaguire\/Gotato.{0,1000}","offensive_tool_keyword","Gotato","Generic impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported.","T1003.003 - T1056.002 - T1550.001 - T1090","TA0005 - TA0004 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/iammaguire/Gotato","1","1","N/A","N/A","9","2","112","16","2021-06-07T21:19:58Z","2021-06-05T22:32:48Z","48110" +"*ibmiscanner2john.py*",".{0,1000}ibmiscanner2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","48114" +"*IBurpExtender.java*",".{0,1000}IBurpExtender\.java.{0,1000}","offensive_tool_keyword","burpsuite","CO2 is a project for lightweight and useful enhancements to Portswigger popular Burp Suite web penetration tool through the standard Extender API","T1583 - T1595 - T1190","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/JGillam/burp-co2","1","1","N/A","network exploitation tool","N/A","2","152","34","2024-02-21T02:23:00Z","2015-04-19T03:38:34Z","48116" +"*IBurpExtenderCallbacks.java*",".{0,1000}IBurpExtenderCallbacks\.java.{0,1000}","offensive_tool_keyword","burpsuite","CO2 is a project for lightweight and useful enhancements to Portswigger popular Burp Suite web penetration tool through the standard Extender API","T1583 - T1595 - T1190","TA0010 - TA0007 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/JGillam/burp-co2","1","1","N/A","network exploitation tool","N/A","2","152","34","2024-02-21T02:23:00Z","2015-04-19T03:38:34Z","48117" +"*icebreaker-master.zip*",".{0,1000}icebreaker\-master\.zip.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","48160" +"*icebreaker-scan.xml*",".{0,1000}icebreaker\-scan\.xml.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","48161" +"*IcebreakerSecurity/DelegationBOF*",".{0,1000}IcebreakerSecurity\/DelegationBOF.{0,1000}","offensive_tool_keyword","cobaltstrike","This tool uses LDAP to check a domain for known abusable Kerberos delegation settings","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/IcebreakerSecurity/DelegationBOF","1","1","N/A","N/A","10","10","141","23","2022-05-04T14:00:36Z","2022-03-28T20:14:24Z","48162" +"*IcebreakerSecurity/DelegationBOF*",".{0,1000}IcebreakerSecurity\/DelegationBOF.{0,1000}","offensive_tool_keyword","DelegationBOF","This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently. it supports RBCD. Constrained. Constrained w/Protocol Transition. and Unconstrained Delegation checks.","T1098 - T1214 - T1552","TA0006","N/A","N/A","Credential Access","https://github.com/IcebreakerSecurity/DelegationBOF","1","1","N/A","N/A","N/A","10","141","23","2022-05-04T14:00:36Z","2022-03-28T20:14:24Z","48163" +"*IcebreakerSecurity/PersistBOF*",".{0,1000}IcebreakerSecurity\/PersistBOF.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to automate common persistence tasks for red teamers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/IcebreakerSecurity/PersistBOF","1","1","N/A","N/A","10","10","274","44","2023-03-07T11:23:42Z","2022-03-29T14:50:47Z","48164" +"*ice-wzl/wmiexec2*",".{0,1000}ice\-wzl\/wmiexec2.{0,1000}","offensive_tool_keyword","wmiexec2","wmiexec2.0 is the same wmiexec that everyone knows and loves (debatable). This 2.0 version is obfuscated to avoid well known signatures from various AV engines.","T1021.005 - T1047 - T1059.001 - T1059.003 - T1059.005","TA0008 - TA0002 - TA0011","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/ice-wzl/wmiexec2","1","1","N/A","N/A","9","1","34","1","2024-06-12T17:56:15Z","2023-02-07T22:10:08Z","48165" +"*ICMP-ReceiveFile.py*",".{0,1000}ICMP\-ReceiveFile\.py.{0,1000}","offensive_tool_keyword","ICMP-TransferTools","Transfer files to and from a Windows host via ICMP in restricted network environments.","T1041 - T1001 - T1105 - T1205","TA0005 - TA0001 - TA0008","N/A","N/A","Data Exfiltration","https://github.com/icyguider/ICMP-TransferTools","1","1","N/A","N/A","N/A","4","321","63","2022-01-27T16:53:44Z","2022-01-27T16:50:13Z","48167" +"*Icmp-Redirect.py*",".{0,1000}Icmp\-Redirect\.py.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","N/A","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","48168" +"*ICMP-SendFile.py*",".{0,1000}ICMP\-SendFile\.py.{0,1000}","offensive_tool_keyword","ICMP-TransferTools","Transfer files to and from a Windows host via ICMP in restricted network environments.","T1041 - T1001 - T1105 - T1205","TA0005 - TA0001 - TA0008","N/A","N/A","Data Exfiltration","https://github.com/icyguider/ICMP-TransferTools","1","1","N/A","N/A","N/A","4","321","63","2022-01-27T16:53:44Z","2022-01-27T16:50:13Z","48169" +"*icmpsh.exe*",".{0,1000}icmpsh\.exe.{0,1000}","offensive_tool_keyword","icmpsh","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","10","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","48170" +"*icmpsh.exe*",".{0,1000}icmpsh\.exe.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","N/A","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","48171" +"*icmpsh.git*",".{0,1000}icmpsh\.git.{0,1000}","offensive_tool_keyword","icmpsh","Simple reverse ICMP shell","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/bdamele/icmpsh","1","1","N/A","N/A","10","10","1573","415","2018-04-06T17:15:44Z","2011-04-15T10:04:12Z","48172" +"*icmpsh_m.py*",".{0,1000}icmpsh_m\.py.{0,1000}","offensive_tool_keyword","icmpsh","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","10","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","48173" +"*icmpsh_m.py*",".{0,1000}icmpsh_m\.py.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","48174" +"*icmpsh-m.*",".{0,1000}icmpsh\-m\..{0,1000}","offensive_tool_keyword","icmpsh","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","10","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","48175" +"*icmpsh-m.c*",".{0,1000}icmpsh\-m\.c.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","48176" +"*icmpsh-m.pl*",".{0,1000}icmpsh\-m\.pl.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","48177" +"*icmpsh-master*",".{0,1000}icmpsh\-master.{0,1000}","offensive_tool_keyword","icmpsh","Simple reverse ICMP shell","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/bdamele/icmpsh","1","1","N/A","N/A","10","10","1573","415","2018-04-06T17:15:44Z","2011-04-15T10:04:12Z","48178" +"*icmpsh-s.*",".{0,1000}icmpsh\-s\..{0,1000}","offensive_tool_keyword","icmpsh","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","10","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","48179" +"*icyguider/DumpNParse*",".{0,1000}icyguider\/DumpNParse.{0,1000}","offensive_tool_keyword","DumpNParse","A Combination LSASS Dumper and LSASS Parser","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/icyguider/DumpNParse","1","1","N/A","N/A","10","2","150","24","2021-11-21T14:25:24Z","2021-11-21T14:18:42Z","48181" +"*icyguider/LatLoader*",".{0,1000}icyguider\/LatLoader.{0,1000}","offensive_tool_keyword","LatLoader","PoC module to demonstrate automated lateral movement with the Havoc C2 framework","T1570 - T1071 - T1021 - T1563 - T1105","TA0008 - TA0011 - TA0002 - TA0010","N/A","N/A","Lateral Movement","https://github.com/icyguider/LatLoader","1","1","N/A","N/A","9","4","301","35","2023-12-09T00:28:32Z","2023-10-06T15:03:17Z","48182" +"*icyguider/LightsOut*",".{0,1000}icyguider\/LightsOut.{0,1000}","offensive_tool_keyword","LightsOut","Generate an obfuscated DLL that will disable AMSI & ETW","T1027.003 - T1059.001 - T1082","TA0005 - TA0002 - TA0004","N/A","N/A","Exploitation tool","https://github.com/icyguider/LightsOut","1","1","N/A","N/A","10","4","321","44","2024-07-15T21:29:16Z","2023-06-01T14:57:44Z","48183" +"*icyguider/Shhhloader*",".{0,1000}icyguider\/Shhhloader.{0,1000}","offensive_tool_keyword","Shhhloader","shellcode loader that compiles a C++ stub to bypass AV/EDR","T1027 - T1055 - T1140 - T1218","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/icyguider/Shhhloader","1","1","N/A","N/A","9","10","1186","191","2024-05-08T20:24:35Z","2021-09-28T16:52:24Z","48184" +"*icyguider/UAC-BOF-Bonanza*",".{0,1000}icyguider\/UAC\-BOF\-Bonanza.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of UAC Bypass Techniques Weaponized as BOFs","T1548.002 - T1203 - T1055 - T1134.002","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/icyguider/UAC-BOF-Bonanza","1","1","N/A","N/A","10","6","500","65","2024-02-21T22:07:54Z","2024-02-16T14:47:13Z","48185" +"*IDiagnosticProfileUAC.git*",".{0,1000}IDiagnosticProfileUAC\.git.{0,1000}","offensive_tool_keyword","IDiagnosticProfileUAC","UAC bypass using auto-elevated COM object Virtual Factory for DiagCpl","T1548.002 - T1059.003 - T1027.002","TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/Wh04m1001/IDiagnosticProfileUAC","1","1","N/A","N/A","10","2","182","32","2022-07-02T20:31:47Z","2022-07-02T19:55:42Z","48188" +"*IDiagnosticProfileUAC-main*",".{0,1000}IDiagnosticProfileUAC\-main.{0,1000}","offensive_tool_keyword","IDiagnosticProfileUAC","UAC bypass using auto-elevated COM object Virtual Factory for DiagCpl","T1548.002 - T1059.003 - T1027.002","TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/Wh04m1001/IDiagnosticProfileUAC","1","1","N/A","N/A","10","2","182","32","2022-07-02T20:31:47Z","2022-07-02T19:55:42Z","48189" +"*Idov31/Jormungandr*",".{0,1000}Idov31\/Jormungandr.{0,1000}","offensive_tool_keyword","Jormungandr","Jormungandr is a kernel implementation of a COFF loader allowing kernel developers to load and execute their COFFs in the kernel","T1215 - T1059.003 - T1547.006","TA0004 - TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Idov31/Jormungandr","1","1","N/A","N/A","N/A","3","228","27","2023-09-26T18:06:53Z","2023-06-25T06:24:16Z","48190" +"*Idov31/Nidhogg*",".{0,1000}Idov31\/Nidhogg.{0,1000}","offensive_tool_keyword","Nidhogg","Nidhogg is an all-in-one simple to use rootkit for red teams.","T1055 - T1055.012 - T1574 - T1574.002 - T1056 - T1056.001 - T1027 - T1027.002 - T1112 - T1050 - T1106 - T1554 - T1554.002 - T1134 - T1134.001 - T1037 - T1037.001 - T1053 - T1053.005 - T1055.011 - T1098 - T1098.003 - T1070.001 - T1070.002 - T1070.003 - T1070.004 - T1070.006 - T1070.007 - T1070.008 - T1070.009 - T1083 - T1113 - T1113.001 - T1125 - T1125.001 - T1482 - T1489 - T1490 - T1497 - T1497.001 - T1497.002 - T1497.003 - T1498 - T1498.001 - T1498.002 - T1499 - T1499.001 - T1499.002 - T1499.003 - T1499.004 - T1499.005 - T1562 - T1562.001 - T1562.003 - T1562.004 - T1562.006 - T1562.007 - T1562.008 - T1562.009 - T1562.010 - T1562.011 - T1562.012","TA0005 - TA0003 - TA0004 - TA0006 - TA0009 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/Idov31/Nidhogg","1","1","N/A","N/A","10","10","1946","284","2025-04-19T14:28:47Z","2022-05-29T14:37:50Z","48191" +"*Idov31/Sandman*",".{0,1000}Idov31\/Sandman.{0,1000}","offensive_tool_keyword","Sandman","Sandman is a NTP based backdoor for red team engagements in hardened networks.","T1105 - T1027 - T1071.001","TA0011 - TA0005","N/A","N/A","Persistence","https://github.com/Idov31/Sandman","1","1","N/A","N/A","10","8","785","108","2024-03-31T17:40:15Z","2022-08-21T11:04:45Z","48192" +"*idrac_default_pass.txt*",".{0,1000}idrac_default_pass\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","48193" +"*idrac_default_user.txt*",".{0,1000}idrac_default_user\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","48194" +"*IDSyscall.exe*",".{0,1000}IDSyscall\.exe.{0,1000}","offensive_tool_keyword","HadesLdr","Shellcode Loader Implementing Indirect Dynamic Syscall - API Hashing - Fileless Shellcode retrieving using Winsock2","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CognisysGroup/HadesLdr","1","1","N/A","N/A","10","3","292","47","2023-07-15T21:23:49Z","2023-07-12T11:44:07Z","48195" +"*IDSyscall.sln*",".{0,1000}IDSyscall\.sln.{0,1000}","offensive_tool_keyword","HadesLdr","Shellcode Loader Implementing Indirect Dynamic Syscall - API Hashing - Fileless Shellcode retrieving using Winsock2","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CognisysGroup/HadesLdr","1","1","N/A","N/A","10","3","292","47","2023-07-15T21:23:49Z","2023-07-12T11:44:07Z","48196" +"*IDSyscall.vcxproj*",".{0,1000}IDSyscall\.vcxproj.{0,1000}","offensive_tool_keyword","HadesLdr","Shellcode Loader Implementing Indirect Dynamic Syscall - API Hashing - Fileless Shellcode retrieving using Winsock2","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CognisysGroup/HadesLdr","1","1","N/A","N/A","10","3","292","47","2023-07-15T21:23:49Z","2023-07-12T11:44:07Z","48197" +"*IDSyscall/IDSyscall*",".{0,1000}IDSyscall\/IDSyscall.{0,1000}","offensive_tool_keyword","HadesLdr","Shellcode Loader Implementing Indirect Dynamic Syscall - API Hashing - Fileless Shellcode retrieving using Winsock2","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CognisysGroup/HadesLdr","1","1","N/A","N/A","10","3","292","47","2023-07-15T21:23:49Z","2023-07-12T11:44:07Z","48198" +"*ie_execcommand_uaf.rb*",".{0,1000}ie_execcommand_uaf\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","48201" +"*ie_win_fakenotification-clippy*",".{0,1000}ie_win_fakenotification\-clippy.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","48202" +"*ie_win_htapowershell.*",".{0,1000}ie_win_htapowershell\..{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","48203" +"*ie_win_missingflash-prettytheft*",".{0,1000}ie_win_missingflash\-prettytheft.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","48204" +"*IERMTCBpbnRvIHByb2Nlc3MgOiA=*",".{0,1000}IERMTCBpbnRvIHByb2Nlc3MgOiA\=.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","48206" +"*Ignitetechnologies/Persistence-Accessibility-Features*",".{0,1000}Ignitetechnologies\/Persistence\-Accessibility\-Features.{0,1000}","offensive_tool_keyword","Persistence-Accessibility-Features","automated sticky keys backdoor","T1174 - T1078 - T1546.013","TA0003","N/A","N/A","Persistence","https://github.com/Ignitetechnologies/Persistence-Accessibility-Features","1","1","N/A","N/A","9","1","34","12","2020-05-18T05:59:58Z","2020-05-18T05:59:23Z","48225" +"*ihamburglar/fgdump*",".{0,1000}ihamburglar\/fgdump.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","1","N/A","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","48226" +"*IIS-Backdoor.*",".{0,1000}IIS\-Backdoor\..{0,1000}","offensive_tool_keyword","IIS-Raid","A native backdoor module for Microsoft IIS","T1505.003 - T1059.001 - T1071.001","TA0002 - TA0011","N/A","N/A","C2","https://github.com/0x09AL/IIS-Raid","1","1","N/A","N/A","10","10","541","124","2020-07-03T13:31:42Z","2020-02-17T16:28:10Z","48227" +"*IIS-Raid-master*",".{0,1000}IIS\-Raid\-master.{0,1000}","offensive_tool_keyword","IIS-Raid","A native backdoor module for Microsoft IIS","T1505.003 - T1059.001 - T1071.001","TA0002 - TA0011","N/A","N/A","C2","https://github.com/0x09AL/IIS-Raid","1","1","N/A","N/A","10","10","541","124","2020-07-03T13:31:42Z","2020-02-17T16:28:10Z","48228" +"*Ikeext-Privesc.ps1*",".{0,1000}Ikeext\-Privesc\.ps1.{0,1000}","offensive_tool_keyword","Ikeext-Privesc","Windows IKEEXT DLL Hijacking Exploit Tool","T1546.011 - T1574.009 - T1036.004","TA0003 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/securycore/Ikeext-Privesc","1","1","N/A","N/A","10","1","33","52","2018-02-25T13:45:15Z","2018-02-27T11:18:56Z","48232" +"*ikeforce.py*",".{0,1000}ikeforce\.py.{0,1000}","offensive_tool_keyword","IKEForce","IKEForce is a command line IPSEC VPN brute forcing tool for Linux that allows group name/ID enumeration and XAUTH brute forcing capabilities.","T1110 - T1201 - T1018","TA0001 - TA0002 - TA0007","N/A","N/A","Exploitation tool","https://github.com/SpiderLabs/ikeforce","1","1","#linux","N/A","N/A","3","241","73","2019-09-18T09:35:41Z","2014-09-12T01:11:00Z","48233" +"*ikescan2john.py*",".{0,1000}ikescan2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","48234" +"*ILBypass.ps1*",".{0,1000}ILBypass\.ps1.{0,1000}","offensive_tool_keyword","octopus","Octopus is an open source. pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S.","T1059.001 - T1105 - T1071.001 - T1219 - T1573","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/mhaskar/Octopus","1","1","N/A","N/A","10","10","750","156","2021-07-06T23:52:37Z","2019-08-30T21:09:07Z","48235" +"*Imanfeng/Telemetry*",".{0,1000}Imanfeng\/Telemetry.{0,1000}","offensive_tool_keyword","Telemetry","Abusing Windows Telemetry for persistence through registry modifications and scheduled tasks to execute arbitrary commands with system-level privileges.","T1053 - T1547 - T1059","TA0003 - TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/Imanfeng/Telemetry","1","1","N/A","N/A","9","2","140","13","2020-07-02T09:41:27Z","2020-06-24T16:30:44Z","48236" +"*imapattack.py*",".{0,1000}imapattack\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","48238" +"*imapattack.py*",".{0,1000}imapattack\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48239" +"*imaprelayclient.py*",".{0,1000}imaprelayclient\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","48240" +"*imaprelayclient.py*",".{0,1000}imaprelayclient\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48241" +"*IMDSpoof-main*",".{0,1000}IMDSpoof\-main.{0,1000}","offensive_tool_keyword","IMDSpoof","IMDSPOOF is a cyber deception tool that spoofs the AWS IMDS service to return HoneyTokens that can be alerted on.","T1584 - T1204 - T1078 - T1558","TA0007 - TA0001 - TA0002 - TA0004","N/A","N/A","Sniffing & Spoofing","https://github.com/grahamhelton/IMDSpoof","1","1","N/A","N/A","8","2","101","3","2023-11-24T23:42:48Z","2023-11-24T23:21:21Z","48245" +"*imgproxy.dev.pico.sh*",".{0,1000}imgproxy\.dev\.pico\.sh.{0,1000}","offensive_tool_keyword","pico","hacker labs - open source and managed web services leveraging SSH","T1021.005 - T1078 - T1105 - T1109 - T1197 - T1213","TA0005 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/picosh/pico","1","1","N/A","N/A","10","10","1129","36","2025-04-22T17:33:17Z","2022-08-24T03:14:52Z","48246" +"*im-hanzou/Arbitrium-RAT*",".{0,1000}im\-hanzou\/Arbitrium\-RAT.{0,1000}","offensive_tool_keyword","Arbitrium-RAT","cross-platform fully undetectable remote access trojan to control Android Windows and Linux","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","N/A","Malware","https://github.com/im-hanzou/Arbitrium-RAT","1","1","N/A","N/A","10","4","355","309","2021-01-15T23:21:13Z","2021-01-16T03:03:11Z","48247" +"*impacket-*.tar.gz*",".{0,1000}impacket\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48254" +"*impacket.*",".{0,1000}impacket\..{0,1000}","offensive_tool_keyword","cobaltstrike","Fileless Lateral Movement tool that relies on ChangeServiceConfigA to run command","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/SCShell","1","1","N/A","N/A","10","10","1484","248","2023-07-10T01:31:54Z","2019-11-13T23:39:27Z","48255" +"*'impacket.*",".{0,1000}\'impacket\..{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48257" +"*impacket.git*",".{0,1000}impacket\.git.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48263" +"*impacket.ldap*",".{0,1000}impacket\.ldap.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48271" +"*impacket.ntlm*",".{0,1000}impacket\.ntlm.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48274" +"*impacket.smbconnection*",".{0,1000}impacket\.smbconnection.{0,1000}","offensive_tool_keyword","smbcrawler","SmbCrawler is a tool that takes credentials and a list of hosts and crawls through those shares","T1077 - T1021 - T1110 - T1083","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/SySS-Research/smbcrawler","1","1","N/A","N/A","N/A","2","161","21","2025-03-24T07:46:43Z","2021-06-09T19:27:08Z","48278" +"*impacket/*.py*",".{0,1000}impacket\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48280" +"*impacket:latest*",".{0,1000}impacket\:latest.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48281" +"*impacket:latest*","Impacket\s.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48282" +"*impacket__init__*",".{0,1000}impacket__init__.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48283" +"*impacket_findDelegation*",".{0,1000}impacket_findDelegation.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","48284" +"*impacket_rpcdump_output_*",".{0,1000}impacket_rpcdump_output_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","48285" +"*impacket-atexec*",".{0,1000}impacket\-atexec.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48286" +"*impacket-dcomexec*",".{0,1000}impacket\-dcomexec.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48287" +"*impacketfile.py*",".{0,1000}impacketfile\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","48288" +"*impacket-GetADUsers*",".{0,1000}impacket\-GetADUsers.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48289" +"*impacket-GetNPUsers*",".{0,1000}impacket\-GetNPUsers.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48290" +"*impacket-getST*",".{0,1000}impacket\-getST.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48291" +"*impacket-getTGT*",".{0,1000}impacket\-getTGT.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48292" +"*impacketldap_shell*",".{0,1000}impacketldap_shell.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48293" +"*impacketlogger*",".{0,1000}impacketlogger.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48294" +"*impacket-lookupsid*",".{0,1000}impacket\-lookupsid.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48295" +"*impacketmssqlshell*",".{0,1000}impacketmssqlshell.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48296" +"*impacket-netview*",".{0,1000}impacket\-netview.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48297" +"*impacketntlmrelayx*",".{0,1000}impacketntlmrelayx.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48298" +"*impacketos_ident*",".{0,1000}impacketos_ident.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48299" +"*impacket-psexec*",".{0,1000}impacket\-psexec.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48300" +"*impacket-reg*",".{0,1000}impacket\-reg.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48301" +"*impacket-reg*",".{0,1000}impacket\-reg.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself. Packets can be constructed from scratch. as well as parsed from raw data. and the object oriented API makes it simple to work with deep hierarchies of protocols. The library provides a set of tools as examples of what can be done within the context of this library","T1071.001 - T1071.002 - T1071.004 - T1071.005 ","TA0005 - TA0006","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/SecureAuthCorp/impacket","1","1","N/A","N/A","N/A","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48302" +"*impacketremcomsvc*",".{0,1000}impacketremcomsvc.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48303" +"*impacketrpcdatabase*",".{0,1000}impacketrpcdatabase.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48304" +"*impacket-rpcdump*",".{0,1000}impacket\-rpcdump.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48306" +"*impacket-samrdump*",".{0,1000}impacket\-samrdump.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48307" +"*impacketsecretsdump*",".{0,1000}impacketsecretsdump.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48308" +"*impacket-secretsdump*",".{0,1000}impacket\-secretsdump.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","48309" +"*impacket-secretsdump*",".{0,1000}impacket\-secretsdump.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48310" +"*impacketserviceinstall*",".{0,1000}impacketserviceinstall.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48311" +"*impacket-services*",".{0,1000}impacket\-services.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48312" +"*impacketsmbclient*",".{0,1000}impacketsmbclient.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48313" +"*impacket-smbclient*",".{0,1000}impacket\-smbclient.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48314" +"*impacket-smbserver*",".{0,1000}impacket\-smbserver.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48315" +"*impacket-ticketer*",".{0,1000}impacket\-ticketer.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48316" +"*impacketutils*",".{0,1000}impacketutils.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48317" +"*impacket-wmiexec*",".{0,1000}impacket\-wmiexec.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Command execution with WMI From Linux","T1550 - T1555 - T1212 - T1558","N/A","N/A","Black Basta","Exploitation tool","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","48318" +"*impacket-wmiexec*",".{0,1000}impacket\-wmiexec.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself. Packets can be constructed from scratch. as well as parsed from raw data. and the object oriented API makes it simple to work with deep hierarchies of protocols. The library provides a set of tools as examples of what can be done within the context of this library","T1071.001 - T1071.002 - T1071.004 - T1071.005 ","TA0005 - TA0006","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/SecureAuthCorp/impacket","1","1","N/A","N/A","N/A","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48319" +"*ImpactDecoder*",".{0,1000}ImpactDecoder.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48320" +"*ImpactPacket*",".{0,1000}ImpactPacket.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48321" +"*ImpersonateAndUnload.cpp*",".{0,1000}ImpersonateAndUnload\.cpp.{0,1000}","offensive_tool_keyword","unDefender","Killing your preferred antimalware by abusing native symbolic links and NT paths.","T1562.001 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/APTortellini/unDefender","1","1","N/A","N/A","10","4","358","81","2022-01-29T12:35:31Z","2021-08-21T14:45:39Z","48329" +"*ImpersonateLocalService*",".{0,1000}ImpersonateLocalService.{0,1000}","offensive_tool_keyword","cobaltstrike","A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/PPLDump_BOF","1","1","N/A","N/A","10","10","140","25","2021-09-24T07:10:04Z","2021-09-24T07:05:59Z","48331" +"*impersonate-main.zip*",".{0,1000}impersonate\-main\.zip.{0,1000}","offensive_tool_keyword","impersonate","A windows token impersonation tool","T1134 - T1550","TA0004 - TA0003","N/A","N/A","Lateral Movement","https://github.com/sensepost/impersonate","1","1","N/A","N/A","10","4","301","38","2023-04-19T12:53:50Z","2022-10-28T06:30:02Z","48334" +"*impersonateprocess.py*",".{0,1000}impersonateprocess\.py.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","48335" +"*impersonateuser.boo*",".{0,1000}impersonateuser\.boo.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","48336" +"*impersonateuser.py*",".{0,1000}impersonateuser\.py.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","48337" +"*imperva_gzip.py*",".{0,1000}imperva_gzip\.py.{0,1000}","offensive_tool_keyword","Imperva_gzip_WAF_Bypass","Imperva Cloud WAF was vulnerable to a bypass that allows attackers to evade WAF rules when sending malicious HTTP POST payloads. such as log4j exploits. SQL injection. command execution. directory traversal. XXE. etc.","T1190 - T1210 - T1506 - T1061 - T1071 - T1100 - T1220","TA0001 - TA0002 - TA0003 - TA0040","N/A","N/A","Defense Evasion","https://github.com/BishopFox/Imperva_gzip_WAF_Bypass","1","1","N/A","network exploitation tool","N/A","2","157","29","2022-01-07T17:39:29Z","2022-01-07T17:38:33Z","48342" +"*Implant*TeamServer.exe*",".{0,1000}Implant.{0,1000}TeamServer\.exe.{0,1000}","offensive_tool_keyword","VirusTotalC2","Abusing VirusTotal API to host our C2 traffic. usefull for bypassing blocking firewall rules if VirusTotal is in the target white list and in case you don't have C2 infrastructure. now you have a free one","T1071.004 - T1102 - T1021.002","TA0011 - TA0008 - TA0042","N/A","N/A","C2","https://github.com/RATandC2/VirusTotalC2","1","1","N/A","N/A","10","10","27","81","2022-09-28T15:10:44Z","2022-09-28T15:12:42Z","48343" +"*implant.sleep-obf*",".{0,1000}implant\.sleep\-obf.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","48345" +"*implant/elevate/*",".{0,1000}implant\/elevate\/.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","48346" +"*implant/gather/*",".{0,1000}implant\/gather\/.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","48347" +"*implant/inject/*",".{0,1000}implant\/inject\/.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","48348" +"*implant/persist/*",".{0,1000}implant\/persist\/.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","48349" +"*implant/pivot/*",".{0,1000}implant\/pivot\/.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","48350" +"*implant/sliver/*",".{0,1000}implant\/sliver\/.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","48351" +"*implant_rootkit.sh*",".{0,1000}implant_rootkit\.sh.{0,1000}","offensive_tool_keyword","D3m0n1z3dShell","Demonized Shell is an Advanced Tool for persistence in linux","T1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037","TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Persistence","https://github.com/MatheuZSecurity/D3m0n1z3dShell","1","1","#linux","N/A","10","4","373","54","2025-01-05T13:56:51Z","2023-05-30T02:30:47Z","48353" +"*implant-callback.*",".{0,1000}implant\-callback\..{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","48354" +"*Implants/powershell.ps1*",".{0,1000}Implants\/powershell\.ps1.{0,1000}","offensive_tool_keyword","PickleC2","PickleC2 is a post-exploitation and Lateral Movements framework","T1059.006 - T1021 - T1071 - T1550 - T1560 - T1570","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/xRET2pwn/PickleC2","1","1","N/A","N/A","10","10","91","20","2021-07-26T21:12:04Z","2021-07-13T09:16:19Z","48355" +"*ImplantSSP.csproj*",".{0,1000}ImplantSSP\.csproj.{0,1000}","offensive_tool_keyword","ImplantSSP","Installs a user-supplied Security Support Provider (SSP) DLL on the system which will be loaded by LSA on system start","T1547.008 - T1073.001 - T1055.001","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/matterpreter/OffensiveCSharp/tree/master/ImplantSSP","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","48356" +"*import/nessus/*",".{0,1000}import\/nessus\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","48410" +"*import/nexpose*",".{0,1000}import\/nexpose.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","48411" +"*import_msf_web*",".{0,1000}import_msf_web.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","48412" +"*Import-DllImports*",".{0,1000}Import\-DllImports.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48415" +"*Import-DllInRemoteProcess*",".{0,1000}Import\-DllInRemoteProcess.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1105","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48416" +"*Import-DllInRemoteProcess*",".{0,1000}Import\-DllInRemoteProcess.{0,1000}","offensive_tool_keyword","mimikatz","Invoke-Mimikatz.ps1 function name","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Invoke-Mimikatz.ps1","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","48417" +"*Import-DllInRemoteProcess*",".{0,1000}Import\-DllInRemoteProcess.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","48418" +"*Import-PhishWinLib*",".{0,1000}Import\-PhishWinLib.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","48426" +"*improsec/SharpEventPersist*",".{0,1000}improsec\/SharpEventPersist.{0,1000}","offensive_tool_keyword","SharpEventPersist","Persistence by writing/reading shellcode from Event Log","T1055 - T1070.001 - T1547.001","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/improsec/SharpEventPersist","1","1","N/A","N/A","10","10","371","50","2022-05-27T14:52:02Z","2022-05-20T14:52:56Z","48427" +"*in.mirrors.cicku.me/blackarch/*/os/*",".{0,1000}in\.mirrors\.cicku\.me\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","48431" +"*inbukcc4xk67uzbgkzufdqq3q3ikhwtebqxza5zlfbtzwm2g6usxidqd.onion*",".{0,1000}inbukcc4xk67uzbgkzufdqq3q3ikhwtebqxza5zlfbtzwm2g6usxidqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","48433" +"*incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion*",".{0,1000}incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","48436" +"*incblog7vmuq7rktic73r4ha4j757m3ptym37tyvifzp2roedyyzzxid.onion*",".{0,1000}incblog7vmuq7rktic73r4ha4j757m3ptym37tyvifzp2roedyyzzxid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","48437" +"*inceptor/obfuscators*",".{0,1000}inceptor\/obfuscators.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1027 - T1055 - T1070 - T1112 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","48440" +"*inceptor-main.zip*",".{0,1000}inceptor\-main\.zip.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","48441" +"*include*bofmask.h*",".{0,1000}include.{0,1000}bofmask\.h.{0,1000}","offensive_tool_keyword","BOFMask","BOFMask is a proof-of-concept for masking Cobalt Strike's Beacon payload while executing a Beacon Object File (BOF)","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/passthehashbrowns/BOFMask","1","1","N/A","N/A","10","2","120","27","2023-06-28T14:35:32Z","2023-06-27T21:19:22Z","48449" +"*incognito.exe*",".{0,1000}incognito\.exe.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Token Manipulation Tokens can be impersonated from other users with a session/running processes on the machine. Most C2 frameworks have functionality for this built-in (such as the Steal Token functionality in Cobalt Strike)","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","48451" +"*incpaykabjqc2mtdxq6c23nqh4x6m5dkps5fr6vgdkgzp5njssx6qkid.onion*",".{0,1000}incpaykabjqc2mtdxq6c23nqh4x6m5dkps5fr6vgdkgzp5njssx6qkid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","48454" +"*incpaysp74dphcbjyvg2eepxnl3tkgt5mq5vd4tnjusoissz342bdnad.onion*",".{0,1000}incpaysp74dphcbjyvg2eepxnl3tkgt5mq5vd4tnjusoissz342bdnad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","48455" +"*Indestructible7/Imminent-Monitor*",".{0,1000}Indestructible7\/Imminent\-Monitor.{0,1000}","offensive_tool_keyword","Imminent-Monitor","used for malicious activities such as keylogging - screen capture and remote control of infected systems.","T1012 - T1059 - T1105 - T1071 - T1124 - T1041","TA0005 - TA0003 - TA0011 - TA0009","Imminent RAT","PROMETHIUM","Malware","https://github.com/Indestructible7/Imminent-Monitor-v3.9","1","1","N/A","N/A","8","1","4","2","2022-11-04T18:48:14Z","2022-11-04T18:15:20Z","48456" +"*inexorableposh.exe*",".{0,1000}inexorableposh\.exe.{0,1000}","offensive_tool_keyword","Powerpick","allowing the execution of Powershell functionality without the use of Powershell.exe","T1059.001 - T1059.003 - T1086 - T1027.001","TA0005 - TA0002","N/A","Black Basta - Dispossessor","Defense Evasion","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","48457" +"*infection_monkey.py*",".{0,1000}infection_monkey\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","48458" +"*InflativeLoading-DumpPEFromMemory*",".{0,1000}InflativeLoading\-DumpPEFromMemory.{0,1000}","offensive_tool_keyword","InflativeLoading","Dynamically convert a native EXE to PIC shellcode by prepending a shellcode stub","T1027 - T1055 - T1140","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/senzee1984/InflativeLoading","1","1","N/A","N/A","10","4","309","64","2024-04-12T17:14:07Z","2024-01-05T03:59:33Z","48460" +"*information_gathering_tools.py*",".{0,1000}information_gathering_tools\.py.{0,1000}","offensive_tool_keyword","hackingtool","ALL IN ONE Hacking Tool For Hackers","T1059 - T1078 - T1105 - T1110 - T1566","TA0002 - TA0008 - TA0009 - TA0005 - TA0007","N/A","N/A","Exploitation tool","https://github.com/Z4nzu/hackingtool","1","1","N/A","N/A","N/A","10","52217","5629","2025-03-03T15:17:19Z","2020-04-11T09:21:31Z","48479" +"*InfosecMatter/Minimalistic-offensive-security-tools*",".{0,1000}InfosecMatter\/Minimalistic\-offensive\-security\-tools.{0,1000}","offensive_tool_keyword","Minimalistic-offensive","A repository of tools for pentesting of restricted and isolated environments.","T1110 - T1046 - T1021 - T1203 - T1485","TA0006 - TA0007 - TA0008","N/A","Dispossessor","Discovery","https://github.com/InfosecMatter/Minimalistic-offensive-security-tools","1","1","N/A","N/A","7","6","562","121","2021-10-26T11:04:46Z","2020-05-10T17:40:31Z","48480" +"*infosecn1nja/SharpDoor*",".{0,1000}infosecn1nja\/SharpDoor.{0,1000}","offensive_tool_keyword","SharpDoor","SharpDoor is alternative RDPWrap written in C# to allowed multiple RDP (Remote Desktop) sessions by patching termsrv.dll file.","T1059 - T1085 - T1070.004","TA0008 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/infosecn1nja/SharpDoor","1","1","N/A","N/A","7","4","311","61","2019-09-30T16:11:24Z","2019-09-29T02:24:07Z","48481" +"*infosecn1nja/SharpDoor*",".{0,1000}infosecn1nja\/SharpDoor.{0,1000}","offensive_tool_keyword","SharpDoor","SharpDoor is alternative RDPWrap written in C# to allowed multiple RDP (Remote Desktop) sessions by patching termsrv.dll file","T1112 - T1055 - T1562.001","TA0003 - TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/infosecn1nja/SharpDoor","1","1","N/A","N/A","9","4","311","61","2019-09-30T16:11:24Z","2019-09-29T02:24:07Z","48482" +"*Initial_Access.ps1*",".{0,1000}Initial_Access\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","48484" +"*InitialAccess_SpearphishingAttachment_FakeWordDoc.py*",".{0,1000}InitialAccess_SpearphishingAttachment_FakeWordDoc\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","48485" +"*InitialAccess_SpearphishingAttachment_Windows.py*",".{0,1000}InitialAccess_SpearphishingAttachment_Windows\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","48486" +"*initialize_fake_thread_state*",".{0,1000}initialize_fake_thread_state.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","48488" +"*initialize_spoofed_callstack*",".{0,1000}initialize_spoofed_callstack.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","48489" +"*initializeShellcodeFluctuation*",".{0,1000}initializeShellcodeFluctuation.{0,1000}","offensive_tool_keyword","C2 related tools","An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/mgeeky/ShellcodeFluctuation","1","1","N/A","N/A","10","10","1012","160","2022-06-17T18:07:33Z","2021-09-29T10:24:52Z","48490" +"*initstring/cloud_enum*",".{0,1000}initstring\/cloud_enum.{0,1000}","offensive_tool_keyword","cloud_enum","Multi-cloud OSINT tool. Enumerate public resources in AWS Azure and Google Cloud.","T1596","TA0043","N/A","N/A","Reconnaissance","https://github.com/initstring/cloud_enum","1","1","N/A","N/A","6","10","1794","271","2024-10-10T08:16:59Z","2019-05-31T09:14:05Z","48496" +"*inject.spawn*",".{0,1000}inject\.spawn.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","48503" +"*inject.spoofaddr*",".{0,1000}inject\.spoofaddr.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","48504" +"*inject_dll_reflective.py*",".{0,1000}inject_dll_reflective\.py.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","48505" +"*inject_dll_srdi.py*",".{0,1000}inject_dll_srdi\.py.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","48506" +"*inject_shellcode.py*",".{0,1000}inject_shellcode\.py.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","48508" +"*inject_shellcode_self*",".{0,1000}inject_shellcode_self.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","48509" +"*inject-amsiBypass.*",".{0,1000}inject\-amsiBypass\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF - Bypass AMSI in a remote process with code injection.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/injectAmsiBypass","1","1","N/A","N/A","10","10","378","69","2023-03-08T15:54:57Z","2021-07-19T00:08:21Z","48512" +"*inject-assembly.cna*",".{0,1000}inject\-assembly\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Inject .NET assemblies into an existing process","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/kyleavery/inject-assembly","1","1","N/A","N/A","10","10","494","74","2022-01-19T19:15:11Z","2022-01-03T15:38:10Z","48515" +"*injectassembly.x64.bin*",".{0,1000}injectassembly\.x64\.bin.{0,1000}","offensive_tool_keyword","cobaltstrike","Inject .NET assemblies into an existing process","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/kyleavery/inject-assembly","1","1","N/A","N/A","10","10","494","74","2022-01-19T19:15:11Z","2022-01-03T15:38:10Z","48516" +"*injectassembly.x64.o*",".{0,1000}injectassembly\.x64\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Inject .NET assemblies into an existing process","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/kyleavery/inject-assembly","1","1","N/A","N/A","10","10","494","74","2022-01-19T19:15:11Z","2022-01-03T15:38:10Z","48517" +"*Inject-BypassStuff*",".{0,1000}Inject\-BypassStuff.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-BypassUAC.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48519" +"*InjectDll.cpp*",".{0,1000}InjectDll\.cpp.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","48521" +"*InjectDll.vcxproj*",".{0,1000}InjectDll\.vcxproj.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","48522" +"*injectEtwBypass*",".{0,1000}injectEtwBypass.{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike BOF - Inject ETW Bypass into Remote Process via Syscalls (HellsGate|HalosGate)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/injectEtwBypass","1","1","N/A","N/A","10","10","279","55","2021-09-28T19:09:38Z","2021-09-21T23:06:42Z","48527" +"*Injection-Exploit-1.0-SNAPSHOT-all.jar*",".{0,1000}Injection\-Exploit\-1\.0\-SNAPSHOT\-all\.jar.{0,1000}","offensive_tool_keyword","POC","JNDI-Injection-Exploit is a tool for generating workable JNDI links and provide background services by starting RMI server. LDAP server and HTTP server. Using this tool allows you get JNDI links. you can insert these links into your POC to test vulnerability.","T1190 - T1133 - T1595 - T1132 - T1046 - T1041","TA0009 - TA0003 - TA0002 - TA0007 - TA0008 - TA0001","N/A","N/A","Exploitation tool","https://github.com/welk1n/JNDI-Injection-Exploit","1","1","N/A","N/A","N/A","10","2682","733","2023-03-22T21:23:32Z","2019-10-10T01:53:49Z","48543" +"*Injections/Traversal.txt*",".{0,1000}Injections\/Traversal\.txt.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","48544" +"*Injections/XSS.txt*",".{0,1000}Injections\/XSS\.txt.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","48545" +"*InjectLibraryDrv_x64.sys*",".{0,1000}InjectLibraryDrv_x64\.sys.{0,1000}","offensive_tool_keyword","VectorKernel","PoCs for Kernelmode rootkit techniques research.","T1543 - T1055 - T1134 - T1564 - T1070 - T1057 - T1574 - T1562 - T1082 - T1518","TA0003 - TA0005 - TA0004 - TA0008 - TA0007","N/A","N/A","Exploitation tool","https://github.com/daem0nc0re/VectorKernel/","1","1","N/A","N/A","10","4","367","60","2025-01-21T08:22:42Z","2023-11-23T12:36:31Z","48547" +"*Inject-LocalShellcode*",".{0,1000}Inject\-LocalShellcode.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48548" +"*InjectMate.py*",".{0,1000}InjectMate\.py.{0,1000}","offensive_tool_keyword","burpsuite","Multi-tabbed extension that helps generate payloads for various purposes (XSS. SQLi. Header injection. and more).","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Discovery","https://github.com/laconicwolf/burp-extensions","1","1","N/A","network exploitation tool","N/A","2","142","31","2019-04-08T00:49:45Z","2018-03-23T16:05:01Z","48549" +"*InjectMateCommunity.py*",".{0,1000}InjectMateCommunity\.py.{0,1000}","offensive_tool_keyword","burpsuite","A collection of scripts to extend Burp Suite","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Discovery","https://github.com/laconicwolf/burp-extensions","1","1","N/A","network exploitation tool","N/A","2","142","31","2019-04-08T00:49:45Z","2018-03-23T16:05:01Z","48550" +"*Inject-NetRipper*",".{0,1000}Inject\-NetRipper.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48551" +"*Injector.exe*",".{0,1000}Injector\.exe.{0,1000}","offensive_tool_keyword","POC","POC to check for CVE-2020-0796 / SMBGhost Expected outcome: cmd.exe launched with system access","T1210.001 - T1213 - T1212 - T1201","TA0007 - TA0002","N/A","N/A","Exploitation tool","https://github.com/ZecOps/CVE-2020-0796-LPE-POC","1","1","N/A","N/A","N/A","3","241","85","2020-04-02T08:01:38Z","2020-03-30T16:06:50Z","48552" +"*InjectPERemote.cs*",".{0,1000}InjectPERemote\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","48554" +"*injectremote.boo*",".{0,1000}injectremote\.boo.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","48556" +"*Inject-RemoteShellcode*",".{0,1000}Inject\-RemoteShellcode.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48558" +"*injectShellcode*",".{0,1000}injectShellcode.{0,1000}","offensive_tool_keyword","C2 related tools","Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners and analysts.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/mgeeky/ThreadStackSpoofer","1","1","N/A","N/A","10","10","1109","180","2022-06-17T18:06:35Z","2021-09-26T22:48:17Z","48560" +"*InjectShellcode*",".{0,1000}InjectShellcode.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","48561" +"*InjectShellCode.cs*",".{0,1000}InjectShellCode\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","48562" +"*InjectShellCodeRemote.cs*",".{0,1000}InjectShellCodeRemote\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","48563" +"*injectsu.dll*",".{0,1000}injectsu\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","48565" +"*inlineAssembly*/execmethod*",".{0,1000}inlineAssembly.{0,1000}\/execmethod.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","48570" +"*inlineDll*/dll*",".{0,1000}inlineDll.{0,1000}\/dll.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","48571" +"*inline-exec.py*",".{0,1000}inline\-exec\.py.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","48572" +"*inline-execute*whereami.x64*",".{0,1000}inline\-execute.{0,1000}whereami\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object File (BOF) that uses handwritten shellcode to return the process Environment strings without touching any DLL's.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/whereami","1","1","N/A","N/A","10","10","172","27","2023-03-13T15:56:38Z","2021-08-19T22:32:34Z","48577" +"*inlineExecute.nim*",".{0,1000}inlineExecute\.nim.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","48578" +"*InlineExecute-Assembly*",".{0,1000}InlineExecute\-Assembly.{0,1000}","offensive_tool_keyword","cobaltstrike","InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditional fork and run execute-assembly module","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/anthemtotheego/InlineExecute-Assembly","1","1","N/A","N/A","10","10","657","130","2023-07-22T23:25:15Z","2021-07-08T17:40:07Z","48579" +"*InlineShellcode*",".{0,1000}InlineShellcode.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","48580" +"*InlineWhispers.py*",".{0,1000}InlineWhispers\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/InlineWhispers","1","1","N/A","N/A","10","10","315","42","2021-11-09T15:39:27Z","2020-12-25T16:52:50Z","48581" +"*InlineWhispers2*",".{0,1000}InlineWhispers2.{0,1000}","offensive_tool_keyword","cobaltstrike","Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF) via Syswhispers2","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Sh0ckFR/InlineWhispers2","1","1","N/A","N/A","10","10","185","28","2022-07-21T08:40:05Z","2021-11-16T12:47:35Z","48582" +"*INotGreen/GlllPowerloader*",".{0,1000}INotGreen\/GlllPowerloader.{0,1000}","offensive_tool_keyword","GlllPowerloader","Sample to bypass AV/EDR and upload to transfer.sh","T1059.001 - T1202 - T1105 - T1027 - T1036 - T1070 - T1031 - T1071 - T1048","TA0005 - TA0004 - TA0002 - TA0011 - TA0010","N/A","N/A","Defense Evasion","https://github.com/INotGreen/GlllPowerloader","1","1","N/A","N/A","10","5","451","105","2024-04-12T07:28:24Z","2022-04-26T12:10:58Z","48584" +"*INotGreen/SharpThief*",".{0,1000}INotGreen\/SharpThief.{0,1000}","offensive_tool_keyword","SharpThief","A one-click program to steal the icon, resource information, version information, modification time, and digital signature (invalid) to make the program appear legitimate","T1036 - T1070 - T1078 - T1027 - T1202","TA0005 - TA0002 - TA0001","N/A","N/A","Defense Evasion","https://github.com/INotGreen/SharpThief","1","1","N/A","N/A","8","4","372","37","2024-12-17T05:46:39Z","2024-03-05T05:34:50Z","48585" +"*INotGreen/XiebroC2*",".{0,1000}INotGreen\/XiebroC2.{0,1000}","offensive_tool_keyword","XiebroC2","Command and control server - multi-person collaborative penetration testing graphical framework","T1105 - T1573.001 - T1055.001 - T1071 - T1041 - T1059.001 - T1059.008 - T1102","TA0011 - TA0003 - TA0005 - TA0007 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/INotGreen/XiebroC2","1","1","N/A","N/A","10","10","1200","192","2025-02-28T09:44:43Z","2024-02-15T15:46:07Z","48586" +"*ins1gn1a/Frampton*",".{0,1000}ins1gn1a\/Frampton.{0,1000}","offensive_tool_keyword","frampton","PE Binary Shellcode Injector - Automated code cave discovery. shellcode injection - ASLR bypass - x86/x64 compatible","T1055 - T1548.002 - T1129 - T1001","TA0002 - TA0003- TA0004 -TA0011","N/A","N/A","Exploitation tool","https://github.com/ins1gn1a/Frampton","1","1","N/A","N/A","N/A","1","75","19","2019-11-24T22:34:48Z","2019-10-29T00:22:14Z","48590" +"*insert_top_100_passwords_1_G*",".{0,1000}insert_top_100_passwords_1_G.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","48594" +"*InsidePro-PasswordsPro.rule*",".{0,1000}InsidePro\-PasswordsPro\.rule.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","48595" +"*InspectAssembly.csproj*",".{0,1000}InspectAssembly\.csproj.{0,1000}","offensive_tool_keyword","InspectAssembly","Inspect's a target .NET assembly's CIL for calls to deserializers and .NET remoting usage to aid in triaging potential privilege escalations.","T1055.012 - T1027 - T1112","TA0005 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/matterpreter/OffensiveCSharp/tree/master/InspectAssembly","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","48596" +"*InspectAssembly.exe*",".{0,1000}InspectAssembly\.exe.{0,1000}","offensive_tool_keyword","InspectAssembly","Inspect's a target .NET assembly's CIL for calls to deserializers and .NET remoting usage to aid in triaging potential privilege escalations.","T1055.012 - T1027 - T1112","TA0005 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/matterpreter/OffensiveCSharp/tree/master/InspectAssembly","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","48597" +"*install_winrar_wine32.exe*",".{0,1000}install_winrar_wine32\.exe.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","48703" +"*install_winrar_wine64.*",".{0,1000}install_winrar_wine64\..{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","48704" +"*installexe-persistence*",".{0,1000}installexe\-persistence.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","48707" +"*install-persistence*",".{0,1000}install\-persistence.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","48716" +"*install-persistence-cron*",".{0,1000}install\-persistence\-cron.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","48717" +"*Install-ServiceBinary*",".{0,1000}Install\-ServiceBinary.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerUp.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48720" +"*Install-SQLC2AgentLink*",".{0,1000}Install\-SQLC2AgentLink.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","48721" +"*Install-SQLC2Server*",".{0,1000}Install\-SQLC2Server.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","48722" +"*Install-SSP.ps1*",".{0,1000}Install\-SSP\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1116","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48725" +"*install-tor2web.sh*",".{0,1000}install\-tor2web\.sh.{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","48726" +"*Intercepter-NG-1.0.zip*",".{0,1000}Intercepter\-NG\-1\.0\.zip.{0,1000}","offensive_tool_keyword","Intercepter-NG","android wifi sniffer","T1433","TA0006","N/A","N/A","Sniffing & Spoofing","https://github.com/intercepter-ng","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","48736" +"*Intercepter-NG-1.3.zip*",".{0,1000}Intercepter\-NG\-1\.3\.zip.{0,1000}","offensive_tool_keyword","Intercepter-NG","android wifi sniffer","T1433","TA0006","N/A","N/A","Sniffing & Spoofing","https://github.com/intercepter-ng","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","48737" +"*Internal-Monologue.exe*",".{0,1000}Internal\-Monologue\.exe.{0,1000}","offensive_tool_keyword","Internal-Monologue","Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS","T1003 - T1051 - T1574 - T1110 - T1547","TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/eladshamir/Internal-Monologue","1","1","N/A","N/A","N/A","10","1512","240","2018-10-11T12:13:08Z","2017-12-09T05:59:01Z","48740" +"*InternalMonologueDll*",".{0,1000}InternalMonologueDll.{0,1000}","offensive_tool_keyword","Internal-Monologue","Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS","T1003 - T1051 - T1574 - T1110 - T1547","TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/eladshamir/Internal-Monologue","1","1","N/A","N/A","N/A","10","1512","240","2018-10-11T12:13:08Z","2017-12-09T05:59:01Z","48741" +"*InternalMonologueExe*",".{0,1000}InternalMonologueExe.{0,1000}","offensive_tool_keyword","Internal-Monologue","Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS","T1003 - T1051 - T1574 - T1110 - T1547","TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/eladshamir/Internal-Monologue","1","1","N/A","N/A","N/A","10","1512","240","2018-10-11T12:13:08Z","2017-12-09T05:59:01Z","48742" +"*Inveigh.exe*",".{0,1000}Inveigh\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","48749" +"*Inveigh.ps1*",".{0,1000}Inveigh\.ps1.{0,1000}","offensive_tool_keyword","Inveigh",".NET IPv4/IPv6 machine-in-the-middle tool for penetration testers","T1550.002 - T1059.001 - T1071.001","TA0002","N/A","ALLANITE - ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/Kevin-Robertson/Inveigh","1","1","N/A","N/A","10","10","2685","462","2024-08-06T01:47:27Z","2015-04-02T18:04:41Z","48750" +"*Inveigh.psd1*",".{0,1000}Inveigh\.psd1.{0,1000}","offensive_tool_keyword","Inveigh",".NET IPv4/IPv6 machine-in-the-middle tool for penetration testers","T1550.002 - T1059.001 - T1071.001","TA0002","N/A","ALLANITE - ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/Kevin-Robertson/Inveigh","1","1","N/A","N/A","10","10","2685","462","2024-08-06T01:47:27Z","2015-04-02T18:04:41Z","48751" +"*Inveigh.psm1*",".{0,1000}Inveigh\.psm1.{0,1000}","offensive_tool_keyword","Inveigh",".NET IPv4/IPv6 machine-in-the-middle tool for penetration testers","T1550.002 - T1059.001 - T1071.001","TA0002","N/A","ALLANITE - ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/Kevin-Robertson/Inveigh","1","1","N/A","N/A","10","10","2685","462","2024-08-06T01:47:27Z","2015-04-02T18:04:41Z","48752" +"*Inveigh.sln*",".{0,1000}Inveigh\.sln.{0,1000}","offensive_tool_keyword","Inveigh",".NET IPv4/IPv6 machine-in-the-middle tool for penetration testers","T1550.002 - T1059.001 - T1071.001","TA0002","N/A","ALLANITE - ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/Kevin-Robertson/Inveigh","1","1","N/A","N/A","10","10","2685","462","2024-08-06T01:47:27Z","2015-04-02T18:04:41Z","48753" +"*Inveigh-BruteForce.ps1*",".{0,1000}Inveigh\-BruteForce\.ps1.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","48755" +"*Inveigh-Cleartext.txt*",".{0,1000}Inveigh\-Cleartext\.txt.{0,1000}","offensive_tool_keyword","Inveigh",".NET IPv4/IPv6 machine-in-the-middle tool for penetration testers","T1550.002 - T1059.001 - T1071.001","TA0002","N/A","ALLANITE - ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/Kevin-Robertson/Inveigh","1","1","N/A","N/A","10","10","2685","462","2024-08-06T01:47:27Z","2015-04-02T18:04:41Z","48756" +"*Inveigh-FormInput.txt*",".{0,1000}Inveigh\-FormInput\.txt.{0,1000}","offensive_tool_keyword","Inveigh",".NET IPv4/IPv6 machine-in-the-middle tool for penetration testers","T1550.002 - T1059.001 - T1071.001","TA0002","N/A","ALLANITE - ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/Kevin-Robertson/Inveigh","1","1","N/A","N/A","10","10","2685","462","2024-08-06T01:47:27Z","2015-04-02T18:04:41Z","48757" +"*Inveigh-Log.txt*",".{0,1000}Inveigh\-Log\.txt.{0,1000}","offensive_tool_keyword","Inveigh",".NET IPv4/IPv6 machine-in-the-middle tool for penetration testers","T1550.002 - T1059.001 - T1071.001","TA0002","N/A","ALLANITE - ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/Kevin-Robertson/Inveigh","1","1","N/A","N/A","10","10","2685","462","2024-08-06T01:47:27Z","2015-04-02T18:04:41Z","48758" +"*Inveigh-master*",".{0,1000}Inveigh\-master.{0,1000}","offensive_tool_keyword","Inveigh",".NET IPv4/IPv6 machine-in-the-middle tool for penetration testers","T1550.002 - T1059.001 - T1071.001","TA0002","N/A","ALLANITE - ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/Kevin-Robertson/Inveigh","1","1","N/A","N/A","10","10","2685","462","2024-08-06T01:47:27Z","2015-04-02T18:04:41Z","48759" +"*Inveigh-net*.zip*",".{0,1000}Inveigh\-net.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","Inveigh",".NET IPv4/IPv6 machine-in-the-middle tool for penetration testers","T1550.002 - T1059.001 - T1071.001","TA0002","N/A","ALLANITE - ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/Kevin-Robertson/Inveigh","1","1","N/A","N/A","10","10","2685","462","2024-08-06T01:47:27Z","2015-04-02T18:04:41Z","48760" +"*Inveigh-NTLMv1.txt*",".{0,1000}Inveigh\-NTLMv1\.txt.{0,1000}","offensive_tool_keyword","Inveigh",".NET IPv4/IPv6 machine-in-the-middle tool for penetration testers","T1550.002 - T1059.001 - T1071.001","TA0002","N/A","ALLANITE - ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/Kevin-Robertson/Inveigh","1","1","N/A","N/A","10","10","2685","462","2024-08-06T01:47:27Z","2015-04-02T18:04:41Z","48761" +"*Inveigh-NTLMv2.txt*",".{0,1000}Inveigh\-NTLMv2\.txt.{0,1000}","offensive_tool_keyword","Inveigh",".NET IPv4/IPv6 machine-in-the-middle tool for penetration testers","T1550.002 - T1059.001 - T1071.001","TA0002","N/A","ALLANITE - ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/Kevin-Robertson/Inveigh","1","1","N/A","N/A","10","10","2685","462","2024-08-06T01:47:27Z","2015-04-02T18:04:41Z","48762" +"*Inveigh-Relay.ps1*",".{0,1000}Inveigh\-Relay\.ps1.{0,1000}","offensive_tool_keyword","Inveigh",".NET IPv4/IPv6 machine-in-the-middle tool for penetration testers","T1550.002 - T1059.001 - T1071.001","TA0002","N/A","ALLANITE - ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/Kevin-Robertson/Inveigh","1","1","N/A","N/A","10","10","2685","462","2024-08-06T01:47:27Z","2015-04-02T18:04:41Z","48764" +"*inveighzero.exe*",".{0,1000}inveighzero\.exe.{0,1000}","offensive_tool_keyword","Inveigh",".NET IPv4/IPv6 machine-in-the-middle tool for penetration testers","T1550.002 - T1059.001 - T1071.001","TA0002","N/A","ALLANITE - ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/Kevin-Robertson/Inveigh","1","1","N/A","N/A","10","10","2685","462","2024-08-06T01:47:27Z","2015-04-02T18:04:41Z","48765" +"*InvisibilityCloak.py*",".{0,1000}InvisibilityCloak\.py.{0,1000}","offensive_tool_keyword","InvisibilityCloak","Proof-of-concept obfuscation toolkit for C# post-exploitation tools","T1027 - T1059.003 - T1140 - T1107","TA0004 - TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/h4wkst3r/InvisibilityCloak","1","1","N/A","N/A","N/A","6","540","181","2022-07-22T14:13:53Z","2021-05-19T14:19:49Z","48768" +"*InvisiShellProfiler.cpp*",".{0,1000}InvisiShellProfiler\.cpp.{0,1000}","offensive_tool_keyword","Invisi-Shell","Hide your powershell script in plain sight! Invisi-Shell bypasses all of Powershell security features (ScriptBlock logging. Module logging. Transcription. AMSI) by hooking .Net assemblies. The hook is performed via CLR Profiler API.","T1027 - T1059.001 - T1562","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/OmerYa/Invisi-Shell","1","1","N/A","N/A","10","10","1167","166","2019-08-19T19:55:19Z","2018-10-14T23:32:56Z","48770" +"*InvisiShellProfiler.dll*",".{0,1000}InvisiShellProfiler\.dll.{0,1000}","offensive_tool_keyword","Invisi-Shell","Hide your powershell script in plain sight! Invisi-Shell bypasses all of Powershell security features (ScriptBlock logging. Module logging. Transcription. AMSI) by hooking .Net assemblies. The hook is performed via CLR Profiler API.","T1027 - T1059.001 - T1562","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/OmerYa/Invisi-Shell","1","1","N/A","N/A","10","10","1167","166","2019-08-19T19:55:19Z","2018-10-14T23:32:56Z","48772" +"*Invoke-*WDigestDowngrade.ps1*",".{0,1000}Invoke\-.{0,1000}WDigestDowngrade\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","48778" +"*invoke_obfuscation.py*",".{0,1000}invoke_obfuscation\.py.{0,1000}","offensive_tool_keyword","GreatSCT","The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This tool is intended for BOTH red and blue team.","T1055 - T1112 - T1189 - T1205","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/GreatSCT/GreatSCT","1","1","N/A","N/A","N/A","10","1127","202","2021-02-10T22:05:27Z","2017-05-12T03:30:41Z","48779" +"*invoke_sessiongopher.py*",".{0,1000}invoke_sessiongopher\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Exploitation tool","https://github.com/byt3bl33d3r/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","48780" +"*Invoke-AADIntReconAsGuest*",".{0,1000}Invoke\-AADIntReconAsGuest.{0,1000}","offensive_tool_keyword","Graphpython","Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit","T1078.004 - T1114.002","TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010","N/A","N/A","Discovery","https://github.com/mlcsec/Graphpython","1","1","N/A","N/A","7","2","145","13","2024-12-07T21:54:00Z","2024-07-10T00:04:48Z","48784" +"*Invoke-AADIntUserEnumerationAsGuest*",".{0,1000}Invoke\-AADIntUserEnumerationAsGuest.{0,1000}","offensive_tool_keyword","Graphpython","Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit","T1078.004 - T1114.002","TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010","N/A","N/A","Discovery","https://github.com/mlcsec/Graphpython","1","1","N/A","N/A","7","2","145","13","2024-12-07T21:54:00Z","2024-07-10T00:04:48Z","48789" +"*Invoke-AccessCheck.ps1*",".{0,1000}Invoke\-AccessCheck\.ps1.{0,1000}","offensive_tool_keyword","PowershellTools","Powershell tools used for Red Team / Pentesting","T1087.002 - T1069.001 - T1069.002 - T1598.002 - T1083 - T1558.003 - T1564.001 - T1112","TA0007 - TA0003 - TA0006 - TA0040 - TA0005 - TA0003","N/A","N/A","Exploitation tool","https://github.com/gustanini/PowershellTools","1","1","N/A","N/A","10","1","76","13","2024-01-08T10:33:20Z","2023-10-26T16:49:59Z","48794" +"*Invoke-ACLScanner*",".{0,1000}Invoke\-ACLScanner.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","48807" +"*invoke-aclscanner*",".{0,1000}invoke\-aclscanner.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","48808" +"*Invoke-ADCSTemplateRecon*",".{0,1000}Invoke\-ADCSTemplateRecon.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","48811" +"*Invoke-ADEnum.ps1*",".{0,1000}Invoke\-ADEnum\.ps1.{0,1000}","offensive_tool_keyword","Invoke-ADEnum","Automate Active Directory Enumeration","T1016 - T1482","TA0007","N/A","N/A","Discovery","https://github.com/Leo4j/Invoke-ADEnum","1","1","N/A","N/A","7","5","448","50","2025-04-09T10:13:47Z","2023-04-18T11:19:42Z","48814" +"*Invoke-adPEAS*",".{0,1000}Invoke\-adPEAS.{0,1000}","offensive_tool_keyword","adPEAS","adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others","T1016 - T1087.002 - T1482 - T1207 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/61106960/adPEAS","1","1","N/A","N/A","8","10","1095","132","2025-04-01T16:16:15Z","2020-12-23T08:10:19Z","48815" +"*Invoke-ADSBackdoor*",".{0,1000}Invoke\-ADSBackdoor.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","48817" +"*Invoke-ADSBackdoor*",".{0,1000}Invoke\-ADSBackdoor.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","48818" +"*Invoke-ADSBackdoor*",".{0,1000}Invoke\-ADSBackdoor.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","48819" +"*Invoke-ADSBackdoor*",".{0,1000}Invoke\-ADSBackdoor.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","48820" +"*Invoke-ADSBackdoor.json*",".{0,1000}Invoke\-ADSBackdoor\.json.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","48821" +"*Invoke-AirstrikeAttackCheck*",".{0,1000}Invoke\-AirstrikeAttackCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","48822" +"*Invoke-AirstrikeAttackCheck*",".{0,1000}Invoke\-AirstrikeAttackCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","48823" +"*Invoke-AllChecks*",".{0,1000}Invoke\-AllChecks.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Check for vulnerable programs and configs","T1550 - T1555 - T1212 - T1558","N/A","N/A","Black Basta","Exploitation tool","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","48825" +"*Invoke-AmsiBypass*",".{0,1000}Invoke\-AmsiBypass.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","48826" +"*Invoke-AmsiBypass*",".{0,1000}Invoke\-AmsiBypass.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","48827" +"*Invoke-AmsiBypass*",".{0,1000}Invoke\-AmsiBypass.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","48828" +"*Invoke-APIConnectionHijack.ps1*",".{0,1000}Invoke\-APIConnectionHijack\.ps1.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","48829" +"*Invoke-ApplicationsOnStartupCheck*",".{0,1000}Invoke\-ApplicationsOnStartupCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","48830" +"*Invoke-ApplicationsOnStartupCheck*",".{0,1000}Invoke\-ApplicationsOnStartupCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","48831" +"*Invoke-ArgFuscator.ps1*",".{0,1000}Invoke\-ArgFuscator\.ps1.{0,1000}","offensive_tool_keyword","Invoke-ArgFuscator","generate obfuscated command-lines for common system-native executables","T1027 - T1059 - T1202","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/wietze/Invoke-ArgFuscator","1","1","N/A","N/A","10","2","161","28","2025-04-14T21:24:29Z","2022-11-20T17:59:23Z","48833" +"*Invoke-ArgFuscator.psd1*",".{0,1000}Invoke\-ArgFuscator\.psd1.{0,1000}","offensive_tool_keyword","Invoke-ArgFuscator","generate obfuscated command-lines for common system-native executables","T1027 - T1059 - T1202","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/wietze/Invoke-ArgFuscator","1","1","N/A","N/A","10","2","161","28","2025-04-14T21:24:29Z","2022-11-20T17:59:23Z","48834" +"*Invoke-ArgFuscator.psm1*",".{0,1000}Invoke\-ArgFuscator\.psm1.{0,1000}","offensive_tool_keyword","Invoke-ArgFuscator","generate obfuscated command-lines for common system-native executables","T1027 - T1059 - T1202","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/wietze/Invoke-ArgFuscator","1","1","N/A","N/A","10","2","161","28","2025-04-14T21:24:29Z","2022-11-20T17:59:23Z","48835" +"*Invoke-ArgFuscator-main.zip*",".{0,1000}Invoke\-ArgFuscator\-main\.zip.{0,1000}","offensive_tool_keyword","Invoke-ArgFuscator","generate obfuscated command-lines for common system-native executables","T1027 - T1059 - T1202","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/wietze/Invoke-ArgFuscator","1","1","N/A","N/A","10","2","161","28","2025-04-14T21:24:29Z","2022-11-20T17:59:23Z","48836" +"*Invoke-ARPScan*",".{0,1000}Invoke\-ARPScan.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-ARPScan.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48837" +"*invoke-arpscan*",".{0,1000}invoke\-arpscan.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","48838" +"*Invoke-ARPScan.ps1*",".{0,1000}Invoke\-ARPScan\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1077","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48839" +"*Invoke-ASREPRoast*",".{0,1000}Invoke\-ASREPRoast.{0,1000}","offensive_tool_keyword","ASREPRoast","Project that retrieves crackable hashes from KRB5 AS-REP responses for users without kerberoast preauthentication enabled. ","T1558.003","TA0006","N/A","N/A","Credential Access","https://github.com/HarmJ0y/ASREPRoast","1","1","N/A","N/A","N/A","3","202","58","2018-09-25T03:26:00Z","2017-01-14T21:07:57Z","48840" +"*InvokeAssembly.x64.dll*",".{0,1000}InvokeAssembly\.x64\.dll.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","48842" +"*Invoke-AutoKerberoast*",".{0,1000}Invoke\-AutoKerberoast.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/xan7r/kerberoast","1","1","N/A","N/A","N/A","1","73","18","2017-07-22T22:28:12Z","2016-06-08T22:58:45Z","48843" +"*Invoke-AzElevatedAccessToggle*",".{0,1000}Invoke\-AzElevatedAccessToggle.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","48846" +"*Invoke-AzRESTBastionShareableLink*",".{0,1000}Invoke\-AzRESTBastionShareableLink.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","48847" +"*Invoke-AzureAdPasswordSprayAttack*",".{0,1000}Invoke\-AzureAdPasswordSprayAttack.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","1","N/A","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","48848" +"*Invoke-AzureEnum.ps1*",".{0,1000}Invoke\-AzureEnum\.ps1.{0,1000}","offensive_tool_keyword","Invoke-AzureEnum","This cmdlet is used to perform users enumeration against Azure","T1110.003 - T1553.003","TA0001 - TA0006","N/A","N/A","Discovery","https://github.com/tobor88/PowerShell-Red-Team/blob/master/Invoke-AzureEnum.ps1","1","1","N/A","N/A","N/A","6","520","92","2023-12-08T15:50:39Z","2019-11-20T22:07:50Z","48849" +"*Invoke-AzurePasswordSpray*",".{0,1000}Invoke\-AzurePasswordSpray.{0,1000}","offensive_tool_keyword","Invoke-AzurePasswordSpray","This cmdlet is used to perform a password spray attack against Azure accounts using legacy Basic Authentication","T1110.003 - T1553.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/tobor88/PowerShell-Red-Team/blob/master/Invoke-AzurePasswordSpray.ps1","1","1","N/A","N/A","N/A","6","520","92","2023-12-08T15:50:39Z","2019-11-20T22:07:50Z","48850" +"*Invoke-AzureRmVMBulkCMD.ps1*",".{0,1000}Invoke\-AzureRmVMBulkCMD\.ps1.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","48851" +"*Invoke-AzVMBulkCMD.ps1*",".{0,1000}Invoke\-AzVMBulkCMD\.ps1.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","48852" +"*Invoke-BackdoorLNK*",".{0,1000}Invoke\-BackdoorLNK.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-BackdoorLNK.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48853" +"*Invoke-BackdoorLNK.ps1*",".{0,1000}Invoke\-BackdoorLNK\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","48854" +"*Invoke-BadPotato*",".{0,1000}Invoke\-BadPotato.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","48855" +"*Invoke-BadZure*",".{0,1000}Invoke\-BadZure.{0,1000}","offensive_tool_keyword","badazure","BadZure orchestrates the setup of Azure Active Directory tenants populating them with diverse entities while also introducing common security misconfigurations to create vulnerable tenants with multiple attack paths","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Exploitation tool","https://github.com/mvelazc0/BadZure/","1","1","N/A","N/A","5","5","451","26","2025-04-10T03:20:03Z","2023-05-05T04:52:21Z","48856" +"*Invoke-BetterSafetyKatz*",".{0,1000}Invoke\-BetterSafetyKatz.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","48857" +"*Invoke-BetterXencrypt*",".{0,1000}Invoke\-BetterXencrypt.{0,1000}","offensive_tool_keyword","Invoke-Stealth","Simple & Powerful PowerShell Script Obfuscator","T1027.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/JoelGMSec/Invoke-Stealth","1","1","N/A","N/A","9","6","559","81","2023-04-21T12:49:37Z","2021-04-13T10:22:05Z","48858" +"*Invoke-BitlockerCheck*",".{0,1000}Invoke\-BitlockerCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","48860" +"*Invoke-BlockETW*",".{0,1000}Invoke\-BlockETW.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","48862" +"*Invoke-BloodHound*",".{0,1000}Invoke\-BloodHound.{0,1000}","offensive_tool_keyword","BloodHound","Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors","1","1","N/A","N/A","10","10","10146","1759","2025-04-02T15:56:30Z","2016-04-17T18:36:14Z","48866" +"*Invoke-BloodHound*",".{0,1000}Invoke\-BloodHound.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","48867" +"*invoke-bloodhound*",".{0,1000}invoke\-bloodhound.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","48868" +"*Invoke-BloodHound*",".{0,1000}Invoke\-BloodHound.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","48869" +"*Invoke-Bof.ps1*",".{0,1000}Invoke\-Bof\.ps1.{0,1000}","offensive_tool_keyword","cobaltstrike","Load any Beacon Object File using Powershell!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/airbus-cert/Invoke-Bof","1","1","N/A","N/A","10","10","250","35","2021-12-09T15:10:41Z","2021-12-09T15:09:22Z","48872" +"*Invoke-Boolang.ps1*",".{0,1000}Invoke\-Boolang\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","48873" +"*Invoke-BruteAvailableLogons*",".{0,1000}Invoke\-BruteAvailableLogons.{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","1","N/A","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","48874" +"*Invoke-BruteForce*",".{0,1000}Invoke\-BruteForce.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","48876" +"*Invoke-BruteLogonAccount*",".{0,1000}Invoke\-BruteLogonAccount.{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","1","N/A","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","48877" +"*Invoke-BruteLogonList*",".{0,1000}Invoke\-BruteLogonList.{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","1","N/A","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","48878" +"*Invoke-BSOD.ps1*",".{0,1000}Invoke\-BSOD\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","48880" +"*Invoke-BuildAnonymousSMBServer.ps1*",".{0,1000}Invoke\-BuildAnonymousSMBServer\.ps1.{0,1000}","offensive_tool_keyword","Invoke-BuildAnonymousSMBServer","Use to build an anonymous SMB file server","T1570 - T1027 - T1071.001","TA0010","N/A","N/A","Data Exfiltration","https://github.com/3gstudent/Invoke-BuildAnonymousSMBServer","1","1","N/A","N/A","6","3","229","43","2021-08-20T14:52:10Z","2021-07-10T01:23:43Z","48882" +"*Invoke-BypassUAC*",".{0,1000}Invoke\-BypassUAC.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-BypassUAC.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48884" +"*Invoke-BypassUAC.ps1*",".{0,1000}Invoke\-BypassUAC\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","48885" +"*Invoke-BypassUACTokenManipulation*",".{0,1000}Invoke\-BypassUACTokenManipulation.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48886" +"*Invoke-CallbackIEX*",".{0,1000}Invoke\-CallbackIEX.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerBreach.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48887" +"*Invoke-CallbackIEX*",".{0,1000}Invoke\-CallbackIEX.{0,1000}","offensive_tool_keyword","PowerBreach","PowerBreach is a backdoor toolkit that aims to provide the user a wide variety of methods to backdoor a system","T1055 - T1203 - T1105 - T1202 - T1027 - T1059 - T1070","TA0005 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","48888" +"*Invoke-Carbuncle*",".{0,1000}Invoke\-Carbuncle.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","48889" +"*Invoke-Cats.ps1*",".{0,1000}Invoke\-Cats\.ps1.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","48891" +"*Invoke-CcmNaaCredentialsCheck*",".{0,1000}Invoke\-CcmNaaCredentialsCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","48892" +"*Invoke-Certify*",".{0,1000}Invoke\-Certify.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","48893" +"*Invoke-Certify*",".{0,1000}Invoke\-Certify.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","48894" +"*invokechecklocaladminaccess*",".{0,1000}invokechecklocaladminaccess.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","48897" +"*Invoke-CheckLocalAdminAccess*",".{0,1000}Invoke\-CheckLocalAdminAccess.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","48898" +"*invoke-checklocaladminaccess*",".{0,1000}invoke\-checklocaladminaccess.{0,1000}","offensive_tool_keyword","pywerview","A partial Python rewriting of PowerSploit PowerView","T1069.002 - T1018 - T1087.001 - T1033 - T1069.001 - T1087.002 - T1016 - T1482","TA0007 - TA0009","N/A","N/A","Reconnaissance","https://github.com/the-useless-one/pywerview","1","1","N/A","N/A","N/A","10","974","121","2025-03-17T14:04:51Z","2016-07-06T13:25:09Z","48900" +"*Invoke-ClearScript.ps1*",".{0,1000}Invoke\-ClearScript\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","48902" +"*Invoke-CleverSpray.ps1*",".{0,1000}Invoke\-CleverSpray\.ps1.{0,1000}","offensive_tool_keyword","Invoke-CleverSpray","Password Spraying Script detecting current and previous passwords of Active Directory User","T1110.003 - T1110.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/wavestone-cdt/Invoke-CleverSpray","1","1","N/A","N/A","10","1","65","11","2021-09-09T07:35:32Z","2018-11-29T10:05:25Z","48904" +"*Invoke-ClipboardMonitor*",".{0,1000}Invoke\-ClipboardMonitor.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48905" +"*Invoke-CMLootDownload*",".{0,1000}Invoke\-CMLootDownload.{0,1000}","offensive_tool_keyword","CMLoot","Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares","T1083 - T1039","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/1njected/CMLoot","1","1","N/A","N/A","8","2","175","22","2023-02-05T00:24:31Z","2022-06-02T10:59:21Z","48906" +"*Invoke-CMLootExtract*",".{0,1000}Invoke\-CMLootExtract.{0,1000}","offensive_tool_keyword","CMLoot","Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares","T1083 - T1039","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/1njected/CMLoot","1","1","N/A","N/A","8","2","175","22","2023-02-05T00:24:31Z","2022-06-02T10:59:21Z","48907" +"*Invoke-CMLootInventory*",".{0,1000}Invoke\-CMLootInventory.{0,1000}","offensive_tool_keyword","CMLoot","Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares","T1083 - T1039","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/1njected/CMLoot","1","1","N/A","N/A","8","2","175","22","2023-02-05T00:24:31Z","2022-06-02T10:59:21Z","48909" +"*Invoke-ConPtyShell*",".{0,1000}Invoke\-ConPtyShell.{0,1000}","offensive_tool_keyword","ConPtyShell","ConPtyShell - Fully Interactive Reverse Shell for Windows","T1059.001 - T1021.004 - T1056.003","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/ConPtyShell","1","1","N/A","N/A","10","10","1102","171","2023-01-20T10:52:52Z","2019-09-13T22:11:18Z","48911" +"*Invoke-ConPtyShell*",".{0,1000}Invoke\-ConPtyShell.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","48912" +"*Invoke-ConPtyShell*",".{0,1000}Invoke\-ConPtyShell.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","48913" +"*Invoke-ConPtyShell.ps1*",".{0,1000}Invoke\-ConPtyShell\.ps1.{0,1000}","offensive_tool_keyword","ConPtyShell","ConPtyShell - Fully Interactive Reverse Shell for Windows","T1059.001 - T1021.004 - T1056.003","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/ConPtyShell","1","1","N/A","N/A","10","10","1102","171","2023-01-20T10:52:52Z","2019-09-13T22:11:18Z","48914" +"*Invoke-ConPtyShell.ps1*",".{0,1000}Invoke\-ConPtyShell\.ps1.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","48915" +"*Invoke-CopyFile*",".{0,1000}Invoke\-CopyFile.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48916" +"*Invoke-CreateRemoteThread*",".{0,1000}Invoke\-CreateRemoteThread.{0,1000}","offensive_tool_keyword","mimikatz","Invoke-Mimikatz.ps1 function name","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Invoke-Mimikatz.ps1","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","48918" +"*Invoke-CredentialFilesCheck*",".{0,1000}Invoke\-CredentialFilesCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","48919" +"*Invoke-CredentialFilesCheck*",".{0,1000}Invoke\-CredentialFilesCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","48920" +"*Invoke-CredentialGuardCheck*",".{0,1000}Invoke\-CredentialGuardCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","48921" +"*Invoke-CredentialInjection*",".{0,1000}Invoke\-CredentialInjection.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48922" +"*Invoke-CredentialInjection*",".{0,1000}Invoke\-CredentialInjection.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","48923" +"*Invoke-CredentialInjection.ps1*",".{0,1000}Invoke\-CredentialInjection\.ps1.{0,1000}","offensive_tool_keyword","PowerSploit","PowerSploit is a collection of Microsoft PowerShell modules that can be used to aid penetration testers during all phases of an assessment. PowerSploit is comprised of the following modules and scripts","T1134 - T1087.001 - T1123 - T1547.001 - T1547.005 - T1059.001 - T1543.003 - T1555.004 - T1005 - T1482 - T1574.001 - T1574.007 - T1574.008 - T1574.009 - T1056.001 - T1027.005 - T1027.010 - T1003.001 - T1057 - T1055.001 - T1012 - T1620 - T1053.005 - T1113 - T1558.003 - T1552.002 - T1552.006 - T1047","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","Dispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - Turla","Framework","https://github.com/PowerShellMafia/PowerSploit","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","48925" +"*Invoke-CredentialInjection.ps1*",".{0,1000}Invoke\-CredentialInjection\.ps1.{0,1000}","offensive_tool_keyword","PowerSploit","PowerSploit is a collection of Microsoft PowerShell modules that can be used to aid penetration testers during all phases of an assessment. PowerSploit is comprised of the following modules and scripts","T1134 - T1087.001 - T1123 - T1547.001 - T1547.005 - T1059.001 - T1543.003 - T1555.004 - T1005 - T1482 - T1574.001 - T1574.007 - T1574.008 - T1574.009 - T1056.001 - T1027.005 - T1027.010 - T1003.001 - T1057 - T1055.001 - T1012 - T1620 - T1053.005 - T1113 - T1558.003 - T1552.002 - T1552.006 - T1047","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","Dispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - Turla","Framework","https://github.com/PowerShellMafia/PowerSploit","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","48926" +"*Invoke-CredentialPhisher*",".{0,1000}Invoke\-CredentialPhisher.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","48927" +"*Invoke-CredentialPhisher*",".{0,1000}Invoke\-CredentialPhisher.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","48928" +"*Invoke-CredentialPhisher.ps1*",".{0,1000}Invoke\-CredentialPhisher\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","48929" +"*Invoke-CredentialsPhish*",".{0,1000}Invoke\-CredentialsPhish.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","48930" +"*Invoke-DAFT.*",".{0,1000}Invoke\-DAFT\..{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","48932" +"*invoke-daisychain*",".{0,1000}invoke\-daisychain.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","48933" +"*Invoke-DCOM.ps1*",".{0,1000}Invoke\-DCOM\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1091","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48935" +"*Invoke-DCOM.ps1*",".{0,1000}Invoke\-DCOM\.ps1.{0,1000}","offensive_tool_keyword","SharpCOM","DCOM Lateral Movement","T1175","TA0008","N/A","N/A","Lateral Movement","https://github.com/rvrsh3ll/SharpCOM","1","1","N/A","N/A","10","2","128","30","2019-09-16T22:52:53Z","2018-12-13T15:10:55Z","48936" +"*Invoke-DCOM.ps1*",".{0,1000}Invoke\-DCOM\.ps1.{0,1000}","offensive_tool_keyword","SharpSploit","SharpSploit is a .NET post-exploitation library written in C# that aims to highlight the attack surface of .NET and make the use of offensive .NET easier for red teamers.","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/cobbr/SharpSploit","1","1","N/A","N/A","10","10","1789","312","2021-08-12T18:23:15Z","2018-09-20T14:22:37Z","48937" +"*Invoke-DCOMObjectScan.json*",".{0,1000}Invoke\-DCOMObjectScan\.json.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","48938" +"*invoke-dcompayload*",".{0,1000}invoke\-dcompayload.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","48939" +"*Invoke-DCOMPowerPointPivot*",".{0,1000}Invoke\-DCOMPowerPointPivot.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","48940" +"*Invoke-DCSync*",".{0,1000}Invoke\-DCSync.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","48942" +"*Invoke-DCSync*",".{0,1000}Invoke\-DCSync.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1056","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48943" +"*Invoke-DCSync.ps1*",".{0,1000}Invoke\-DCSync\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","48944" +"*Invoke-DeadUserBackdoor*",".{0,1000}Invoke\-DeadUserBackdoor.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","48945" +"*Invoke-DeadUserBackdoor*",".{0,1000}Invoke\-DeadUserBackdoor.{0,1000}","offensive_tool_keyword","PowerBreach","PowerBreach is a backdoor toolkit that aims to provide the user a wide variety of methods to backdoor a system","T1055 - T1203 - T1105 - T1202 - T1027 - T1059 - T1070","TA0005 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","48946" +"*Invoke-DefenderExclusionsCheck*",".{0,1000}Invoke\-DefenderExclusionsCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","48947" +"*Invoke-DHCPCheckup*",".{0,1000}Invoke\-DHCPCheckup.{0,1000}","offensive_tool_keyword","DDSpoof","DDSpoof is a tool that enables DHCP DNS Dynamic Update attacks against Microsoft DHCP servers in AD environments.","T1557 - T1584 - T1203","TA0005 - TA0003 TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/akamai/DDSpoof","1","1","N/A","N/A","9","2","122","13","2024-04-12T22:06:02Z","2023-12-14T06:47:45Z","48951" +"*Invoke-DinvokeKatz*",".{0,1000}Invoke\-DinvokeKatz.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","48952" +"*Invoke-DisableMachineAcctChange*",".{0,1000}Invoke\-DisableMachineAcctChange.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48953" +"*Invoke-DllEncode*",".{0,1000}Invoke\-DllEncode.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48954" +"*Invoke-DllHijackingCheck*",".{0,1000}Invoke\-DllHijackingCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","48955" +"*Invoke-DllHijackingCheck*",".{0,1000}Invoke\-DllHijackingCheck.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","48956" +"*Invoke-DllHijackingCheck*",".{0,1000}Invoke\-DllHijackingCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","48957" +"*Invoke-DllInjection*",".{0,1000}Invoke\-DllInjection.{0,1000}","offensive_tool_keyword","empire","empire script function. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1047","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48958" +"*Invoke-DllInjection.ps1*",".{0,1000}Invoke\-DllInjection\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","48960" +"*Invoke-DNSExfiltrator*",".{0,1000}Invoke\-DNSExfiltrator.{0,1000}","offensive_tool_keyword","DNSExfiltrator","DNSExfiltrator allows for transfering (exfiltrate) a file over a DNS request covert channel. This is basically a data leak testing tool allowing to exfiltrate data over a covert channel.","T1041 - T1048","TA0010 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/Arno0x/DNSExfiltrator","1","1","N/A","N/A","10","9","867","188","2024-04-29T20:20:43Z","2017-12-20T13:58:09Z","48961" +"*Invoke-DNSteal*",".{0,1000}Invoke\-DNSteal.{0,1000}","offensive_tool_keyword","Invoke-DNSteal","DNS Data Exfiltrator","T1071.004 - T1041 - T1048","TA0011 - TA0010","N/A","N/A","Data Exfiltration","https://github.com/JoelGMSec/Invoke-DNSteal","1","1","N/A","N/A","10","2","109","23","2023-07-17T11:26:19Z","2021-06-24T11:03:09Z","48962" +"*Invoke-Dogz.ps1*",".{0,1000}Invoke\-Dogz\.ps1.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","1","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","48965" +"*Invoke-DomainHarvest*",".{0,1000}Invoke\-DomainHarvest.{0,1000}","offensive_tool_keyword","MailSniper","Invoke-DomainHarvest* will attempt to connect to an * portal and determine a valid domain name for logging into the portal","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Reconnaissance","https://github.com/dafthack/MailSniper","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","48966" +"*Invoke-DomainHarvestOWA*",".{0,1000}Invoke\-DomainHarvestOWA.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","48967" +"*Invoke-DomainPasswordSpray*",".{0,1000}Invoke\-DomainPasswordSpray.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","1","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","48968" +"*Invoke-DomainPasswordSpray*",".{0,1000}Invoke\-DomainPasswordSpray.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","1","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","48969" +"*Invoke-DomainPasswordSpray*",".{0,1000}Invoke\-DomainPasswordSpray.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","48970" +"*Invoke-DomainPasswordSpray*",".{0,1000}Invoke\-DomainPasswordSpray.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","48971" +"*Invoke-DOSfuscation*",".{0,1000}Invoke\-DOSfuscation.{0,1000}","offensive_tool_keyword","Invoke-DOSfuscation","Invoke-DOSfuscation is a PowerShell v2.0+ compatible cmd.exe command obfuscation framework. (White paper: https://www.fireeye.com/blog/threat-research/2018/03/dosfuscation-exploring-obfuscation-and-detection-techniques.html)","T1027 - T1140 - T1059","TA0002 - TA0003 - TA0040","N/A","N/A","Defense Evasion","https://github.com/danielbohannon/Invoke-DOSfuscation","1","1","N/A","N/A","N/A","9","880","139","2018-03-27T12:16:18Z","2018-03-19T16:47:54Z","48972" +"*Invoke-DowngradeAccount*",".{0,1000}Invoke\-DowngradeAccount.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","48973" +"*Invoke-DownloadFile.ps1*",".{0,1000}Invoke\-DownloadFile\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","48975" +"*Invoke-DpapiDump*",".{0,1000}Invoke\-DpapiDump.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","48976" +"*Invoke-DriverCoInstallersCheck*",".{0,1000}Invoke\-DriverCoInstallersCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","48979" +"*Invoke-DropboxUpload*",".{0,1000}Invoke\-DropboxUpload.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48980" +"*Invoke-DumpMDEConfig*",".{0,1000}Invoke\-DumpMDEConfig.{0,1000}","offensive_tool_keyword","Invoke-DumpMDEConfig","PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )","T1518 - T1082 - T1005","TA0009 - TA0007 - TA0005","N/A","N/A","Discovery","https://github.com/BlackSnufkin/Invoke-DumpMDEConfig","1","1","N/A","N/A","9","2","147","23","2024-06-10T14:00:47Z","2024-06-09T15:11:16Z","48983" +"*Invoke-DumpOWAMailboxViaMSGraphApi*",".{0,1000}Invoke\-DumpOWAMailboxViaMSGraphApi.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","48984" +"*invoke-edrchecker*",".{0,1000}invoke\-edrchecker.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","48985" +"*Invoke-EDRChecker*",".{0,1000}Invoke\-EDRChecker.{0,1000}","offensive_tool_keyword","SharpEDRChecker","Checks for the presence of known defensive products such as AV/EDR and logging tools","T1083 - T1518.001 - T1063","TA0007 - TA0005","N/A","N/A","Discovery","https://github.com/PwnDexter/SharpEDRChecker","1","1","N/A","N/A","8","8","706","98","2023-10-09T11:17:49Z","2020-06-16T10:25:00Z","48986" +"*Invoke-EDRChecker.ps1*",".{0,1000}Invoke\-EDRChecker\.ps1.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","48987" +"*Invoke-EgressCheck*",".{0,1000}Invoke\-EgressCheck.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-EgressCheck.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48988" +"*Invoke-EgressCheck.ps1*",".{0,1000}Invoke\-EgressCheck\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1141","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48989" +"*Invoke-Empire*",".{0,1000}Invoke\-Empire.{0,1000}","offensive_tool_keyword","empire","empire function name of agent.ps1. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1047","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48991" +"*Invoke-EndpointProtectionCheck*",".{0,1000}Invoke\-EndpointProtectionCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","48992" +"*Invoke-EnumerateAzureBlobs.ps1*",".{0,1000}Invoke\-EnumerateAzureBlobs\.ps1.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","48993" +"*Invoke-EnumerateAzureSubDomains.ps1*",".{0,1000}Invoke\-EnumerateAzureSubDomains\.ps1.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","48994" +"*invokeenumeratelocaladmin*",".{0,1000}invokeenumeratelocaladmin.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","48996" +"*Invoke-EnumerateLocalAdmin*",".{0,1000}Invoke\-EnumerateLocalAdmin.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","48997" +"*Invoke-EnumerateLocalAdmin*",".{0,1000}Invoke\-EnumerateLocalAdmin.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","powerview.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","48998" +"*Invoke-EnumerateLocalAdmin*",".{0,1000}Invoke\-EnumerateLocalAdmin.{0,1000}","offensive_tool_keyword","powerview","PowerView is a PowerShell tool to gain network situational awareness on Windows domains","T1046 - T1087.001 - T1016","TA0007 - TA0008 - TA0009","N/A","Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA","Discovery","https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","49001" +"*Invoke-EnumerateLocalAdmin*",".{0,1000}Invoke\-EnumerateLocalAdmin.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","49002" +"*Invoke-EnumerateLocalAdmin*",".{0,1000}Invoke\-EnumerateLocalAdmin.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","49003" +"*Invoke-EnumerateLocalAdmin*",".{0,1000}Invoke\-EnumerateLocalAdmin.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","49004" +"*Invoke-EnvBypass*",".{0,1000}Invoke\-EnvBypass.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-BypassUACTokenManipulation.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49006" +"*Invoke-EnvBypass.*",".{0,1000}Invoke\-EnvBypass\..{0,1000}","offensive_tool_keyword","cobaltstrike","The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/ElevateKit","1","1","N/A","N/A","10","10","912","203","2020-06-22T21:12:24Z","2016-12-08T03:51:09Z","49007" +"*Invoke-EnvBypass.ps1*",".{0,1000}Invoke\-EnvBypass\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1125","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49008" +"*Invoke-EssessAgress*",".{0,1000}Invoke\-EssessAgress.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","49009" +"*Invoke-ESTSCookieToAccessToken*",".{0,1000}Invoke\-ESTSCookieToAccessToken.{0,1000}","offensive_tool_keyword","Graphpython","Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit","T1078.004 - T1114.002","TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010","N/A","N/A","Discovery","https://github.com/mlcsec/Graphpython","1","1","N/A","N/A","7","2","145","13","2024-12-07T21:54:00Z","2024-07-10T00:04:48Z","49010" +"*Invoke-EternalBlue*",".{0,1000}Invoke\-EternalBlue.{0,1000}","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","49011" +"*Invoke-EternalBlue*",".{0,1000}Invoke\-EternalBlue.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49012" +"*Invoke-EternalBlue*",".{0,1000}Invoke\-EternalBlue.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49013" +"*invoke-eternalblue*",".{0,1000}invoke\-eternalblue.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","49014" +"*invoke-eventhunter*",".{0,1000}invoke\-eventhunter.{0,1000}","offensive_tool_keyword","pywerview","A partial Python rewriting of PowerSploit PowerView","T1069.002 - T1018 - T1087.001 - T1033 - T1069.001 - T1087.002 - T1016 - T1482","TA0007 - TA0009","N/A","N/A","Reconnaissance","https://github.com/the-useless-one/pywerview","1","1","N/A","N/A","N/A","10","974","121","2025-03-17T14:04:51Z","2016-07-06T13:25:09Z","49017" +"*Invoke-EventLogBackdoor*",".{0,1000}Invoke\-EventLogBackdoor.{0,1000}","offensive_tool_keyword","PowerBreach","PowerBreach is a backdoor toolkit that aims to provide the user a wide variety of methods to backdoor a system","T1055 - T1203 - T1105 - T1202 - T1027 - T1059 - T1070","TA0005 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","49018" +"*Invoke-EventViewer.ps1*",".{0,1000}Invoke\-EventViewer\.ps1.{0,1000}","offensive_tool_keyword","EventViewer-UACBypass","RCE through Unsafe .Net Deserialization in Windows Event Viewer which leads to UAC bypass","T1078.004 - T1216 - T1068","TA0004 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/CsEnox/EventViewer-UACBypass","1","1","N/A","N/A","10","2","184","21","2022-04-29T09:42:37Z","2022-04-27T12:56:59Z","49020" +"*Invoke-EventVwrBypass*",".{0,1000}Invoke\-EventVwrBypass.{0,1000}","offensive_tool_keyword","cobaltstrike","The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/ElevateKit","1","1","N/A","N/A","10","10","912","203","2020-06-22T21:12:24Z","2016-12-08T03:51:09Z","49021" +"*Invoke-EventVwrBypass*",".{0,1000}Invoke\-EventVwrBypass.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-EventVwrBypass.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49022" +"*Invoke-EventVwrBypass.ps1*",".{0,1000}Invoke\-EventVwrBypass\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49024" +"*Invoke-ExcelMacroPivot*",".{0,1000}Invoke\-ExcelMacroPivot.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","49025" +"*Invoke-ExcelMacroPivot.ps1*",".{0,1000}Invoke\-ExcelMacroPivot\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","49026" +"*Invoke-ExecuteMSBuild*",".{0,1000}Invoke\-ExecuteMSBuild.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-ExecuteMSBuild.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49027" +"*Invoke-ExecuteMSBuild.ps1*",".{0,1000}Invoke\-ExecuteMSBuild\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1090","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49028" +"*Invoke-ExfilDataToGitHub*",".{0,1000}Invoke\-ExfilDataToGitHub.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49030" +"*Invoke-ExploitableLeakedHandlesCheck*",".{0,1000}Invoke\-ExploitableLeakedHandlesCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49031" +"*Invoke-Eyewitness*",".{0,1000}Invoke\-Eyewitness.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49034" +"*Invoke-FakeLogonScreen*",".{0,1000}Invoke\-FakeLogonScreen.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49035" +"*Invoke-Farmer*",".{0,1000}Invoke\-Farmer.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49036" +"*invokefilefinder*",".{0,1000}invokefilefinder.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","49039" +"*Invoke-FileFinder*",".{0,1000}Invoke\-FileFinder.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","49040" +"*Invoke-FileTransferWMImplant*",".{0,1000}Invoke\-FileTransferWMImplant.{0,1000}","offensive_tool_keyword","WMImplant","WMImplant is a PowerShell based tool that leverages WMI to both perform actions against targeted machines. but also as the C2 channel for issuing commands and receiving results. WMImplant will likely require local administrator permissions on the targeted machine.","T1021 - T1059 - T1047 - T1057 - T1049","TA0002 - TA0003 - TA0008 - TA0009 - TA0011","N/A","N/A","C2","https://github.com/FortyNorthSecurity/WMImplant","1","1","N/A","N/A","N/A","10","813","146","2024-06-25T12:02:26Z","2016-05-24T14:00:14Z","49043" +"*Invoke-FindDLLHijack*",".{0,1000}Invoke\-FindDLLHijack.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49044" +"*Invoke-FindPathHijack*",".{0,1000}Invoke\-FindPathHijack.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49045" +"*Invoke-FodHelperBypass*",".{0,1000}Invoke\-FodHelperBypass.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-FodHelperBypass.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49046" +"*Invoke-FodHelperBypass*",".{0,1000}Invoke\-FodHelperBypass.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1127","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49047" +"*Invoke-FodHelperBypass.ps1*",".{0,1000}Invoke\-FodHelperBypass\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49048" +"*Invoke-ForgeUserAgent*",".{0,1000}Invoke\-ForgeUserAgent.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","49050" +"*Invoke-FruityC2*",".{0,1000}Invoke\-FruityC2.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","49051" +"*Invoke-Get-FirefoxPasswords*",".{0,1000}Invoke\-Get\-FirefoxPasswords.{0,1000}","offensive_tool_keyword","Dispossessor","credential scripts used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","49052" +"*Invoke-Get-RBCD-Threaded*",".{0,1000}Invoke\-Get\-RBCD\-Threaded.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49053" +"*Invoke-Get-RBCD-Threaded*",".{0,1000}Invoke\-Get\-RBCD\-Threaded.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49054" +"*Invoke-GlobalMailSearch*",".{0,1000}Invoke\-GlobalMailSearch.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49055" +"*Invoke-GlobalMailSearch*",".{0,1000}Invoke\-GlobalMailSearch.{0,1000}","offensive_tool_keyword","MailSniper","To search all mailboxes in a domain","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Reconnaissance","https://github.com/dafthack/MailSniper","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49056" +"*Invoke-GlobalO365MailSearch*",".{0,1000}Invoke\-GlobalO365MailSearch.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49057" +"*Invoke-GoFetch*",".{0,1000}Invoke\-GoFetch.{0,1000}","offensive_tool_keyword","GoFetch","GoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application.","T1078 - T1078.003 - T1021 - T1021.006 - T1076.001","TA0005 - TA0001 - TA0003","N/A","Dispossessor","Discovery","https://github.com/GoFetchAD/GoFetch","1","1","N/A","N/A","10","7","633","99","2017-06-20T14:15:10Z","2017-04-11T10:45:23Z","49058" +"*Invoke-Gopher*",".{0,1000}Invoke\-Gopher.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49059" +"*Invoke-GPPPasswordCheck*",".{0,1000}Invoke\-GPPPasswordCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49060" +"*Invoke-GPPPasswordCheck*",".{0,1000}Invoke\-GPPPasswordCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49061" +"*Invoke-GrabTheHash*",".{0,1000}Invoke\-GrabTheHash.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","49062" +"*Invoke-GrabTheHash*",".{0,1000}Invoke\-GrabTheHash.{0,1000}","offensive_tool_keyword","Invoke-GrabTheHash","Get the NTLM Hash for the User or Machine Account TGT held in your current session","T1558.004 - T1003.004","TA0006","N/A","N/A","Credential Access","https://github.com/Leo4j/Invoke-GrabTheHash","1","1","N/A","N/A","8","1","6","1","2023-10-26T10:52:51Z","2023-08-22T12:14:53Z","49063" +"*Invoke-Grouper2*",".{0,1000}Invoke\-Grouper2.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49068" +"*Invoke-Grouper2*",".{0,1000}Invoke\-Grouper2.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49069" +"*Invoke-Grouper3*",".{0,1000}Invoke\-Grouper3.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49070" +"*Invoke-Grouper3*",".{0,1000}Invoke\-Grouper3.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49071" +"*Invoke-HandleKatz*",".{0,1000}Invoke\-HandleKatz.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49072" +"*Invoke-HandleKatz*",".{0,1000}Invoke\-HandleKatz.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49073" +"*Invoke-Handlekatz*",".{0,1000}Invoke\-Handlekatz.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49074" +"*Invoke-HardenedUNCPathCheck*",".{0,1000}Invoke\-HardenedUNCPathCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49075" +"*Invoke-HijackableDllsCheck*",".{0,1000}Invoke\-HijackableDllsCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49076" +"*Invoke-HijackableDllsCheck*",".{0,1000}Invoke\-HijackableDllsCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49077" +"*Invoke-HiveDump*",".{0,1000}Invoke\-HiveDump.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","49078" +"*Invoke-HiveDump*",".{0,1000}Invoke\-HiveDump.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","49079" +"*Invoke-HiveNightmare.ps1*",".{0,1000}Invoke\-HiveNightmare\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","49080" +"*Invoke-HoneypotBuster*",".{0,1000}Invoke\-HoneypotBuster.{0,1000}","offensive_tool_keyword","HoneypotBuster","Microsoft PowerShell module designed for red teams that can be used to find honeypots and honeytokens in the network or at the host","T1083 - T1059.001 - T1112","TA0007 - TA0002","N/A","N/A","Lateral Movement","https://github.com/JavelinNetworks/HoneypotBuster","1","1","N/A","N/A","8","3","282","57","2017-12-05T13:03:11Z","2017-07-22T15:40:44Z","49081" +"*Invoke-HostEnum*",".{0,1000}Invoke\-HostEnum.{0,1000}","offensive_tool_keyword","red-team-scripts","script comprised of multiple system enumeration / situational awareness techniques collected over time. If system is a member of a Windows domain. it can also perform limited domain enumeration with the -Domain switch","T1016 - T1087.001 - T1049 - T1069","TA0007 - TA0003 - TA0006","N/A","N/A","Discovery","https://github.com/threatexpress/red-team-scripts","1","1","N/A","N/A","N/A","10","1122","195","2024-11-19T19:39:01Z","2017-05-01T13:53:05Z","49084" +"*Invoke-HostRecon*",".{0,1000}Invoke\-HostRecon.{0,1000}","offensive_tool_keyword","HostRecon","Invoke-HostRecon runs a number of checks on a system to help provide situational awareness to a penetration tester during the reconnaissance phase of an engagement. It gathers information about the local system. users. and domain information. It does not use any 'net. 'ipconfig. 'whoami. 'netstat. or other system commands to help avoid detection.","T1082 - T1087 - T1033","TA0001 - TA0007 - ","N/A","N/A","Discovery","https://github.com/dafthack/HostRecon","1","1","N/A","N/A","N/A","5","446","120","2017-10-03T13:25:06Z","2017-03-28T14:53:21Z","49086" +"*invoke-hostscan*",".{0,1000}invoke\-hostscan.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","49087" +"*Invoke-HotFixVulnCheck*",".{0,1000}Invoke\-HotFixVulnCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49088" +"*Invoke-IcmpDownload*",".{0,1000}Invoke\-IcmpDownload.{0,1000}","offensive_tool_keyword","ICMP-TransferTools","Transfer files to and from a Windows host via ICMP in restricted network environments.","T1041 - T1001 - T1105 - T1205","TA0005 - TA0001 - TA0008","N/A","N/A","Data Exfiltration","https://github.com/icyguider/ICMP-TransferTools","1","1","N/A","N/A","N/A","4","321","63","2022-01-27T16:53:44Z","2022-01-27T16:50:13Z","49090" +"*Invoke-IcmpDownload.ps1*",".{0,1000}Invoke\-IcmpDownload\.ps1.{0,1000}","offensive_tool_keyword","ICMP-TransferTools","Transfer files to and from a Windows host via ICMP in restricted network environments.","T1041 - T1001 - T1105 - T1205","TA0005 - TA0001 - TA0008","N/A","N/A","Data Exfiltration","https://github.com/icyguider/ICMP-TransferTools","1","1","N/A","N/A","N/A","4","321","63","2022-01-27T16:53:44Z","2022-01-27T16:50:13Z","49091" +"*Invoke-IcmpUpload.ps1*",".{0,1000}Invoke\-IcmpUpload\.ps1.{0,1000}","offensive_tool_keyword","ICMP-TransferTools","Transfer files to and from a Windows host via ICMP in restricted network environments.","T1041 - T1001 - T1105 - T1205","TA0005 - TA0001 - TA0008","N/A","N/A","Data Exfiltration","https://github.com/icyguider/ICMP-TransferTools","1","1","N/A","N/A","N/A","4","321","63","2022-01-27T16:53:44Z","2022-01-27T16:50:13Z","49092" +"*Invoke-IkeextCheck*",".{0,1000}Invoke\-IkeextCheck.{0,1000}","offensive_tool_keyword","Ikeext-Privesc","Windows IKEEXT DLL Hijacking Exploit Tool","T1546.011 - T1574.009 - T1036.004","TA0003 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/securycore/Ikeext-Privesc","1","1","N/A","N/A","10","1","33","52","2018-02-25T13:45:15Z","2018-02-27T11:18:56Z","49093" +"*Invoke-IkeextExploit*",".{0,1000}Invoke\-IkeextExploit.{0,1000}","offensive_tool_keyword","Ikeext-Privesc","Windows IKEEXT DLL Hijacking Exploit Tool","T1546.011 - T1574.009 - T1036.004","TA0003 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/securycore/Ikeext-Privesc","1","1","N/A","N/A","10","1","33","52","2018-02-25T13:45:15Z","2018-02-27T11:18:56Z","49094" +"*Invoke-ImpersonateUser*",".{0,1000}Invoke\-ImpersonateUser.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49096" +"*Invoke-InjectGEvent*",".{0,1000}Invoke\-InjectGEvent.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49098" +"*Invoke-InjectGEventAPI*",".{0,1000}Invoke\-InjectGEventAPI.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49099" +"*Invoke-InstalledServicesCheck*",".{0,1000}Invoke\-InstalledServicesCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","N/A","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49103" +"*Invoke-Interceptor*",".{0,1000}Invoke\-Interceptor.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49105" +"*Invoke-Interceptor.ps1*",".{0,1000}Invoke\-Interceptor\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49106" +"*Invoke-InternalMonologue*",".{0,1000}Invoke\-InternalMonologue.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","49107" +"*Invoke-Internalmonologue*",".{0,1000}Invoke\-Internalmonologue.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49108" +"*Invoke-Internalmonologue*",".{0,1000}Invoke\-Internalmonologue.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49109" +"*Invoke-InternalMonologue.ps1*",".{0,1000}Invoke\-InternalMonologue\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","49110" +"*Invoke-Inveigh*",".{0,1000}Invoke\-Inveigh.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1068","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49111" +"*Invoke-Inveigh*",".{0,1000}Invoke\-Inveigh.{0,1000}","offensive_tool_keyword","Inveigh",".NET IPv4/IPv6 machine-in-the-middle tool for penetration testers","T1550.002 - T1059.001 - T1071.001","TA0002","N/A","ALLANITE - ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/Kevin-Robertson/Inveigh","1","1","N/A","N/A","10","10","2685","462","2024-08-06T01:47:27Z","2015-04-02T18:04:41Z","49112" +"*Invoke-Inveigh*",".{0,1000}Invoke\-Inveigh.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49113" +"*Invoke-Inveigh.ps1*",".{0,1000}Invoke\-Inveigh\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49114" +"*Invoke-InveighRelay*",".{0,1000}Invoke\-InveighRelay.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49115" +"*Invoke-InveighRelay.ps1*",".{0,1000}Invoke\-InveighRelay\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1089","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49116" +"*Invoke-IronCyclone*",".{0,1000}Invoke\-IronCyclone.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","49118" +"*Invoke-IronPython*",".{0,1000}Invoke\-IronPython.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49119" +"*Invoke-IronPython.ps1*",".{0,1000}Invoke\-IronPython\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49120" +"*Invoke-IronPython3*",".{0,1000}Invoke\-IronPython3.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49121" +"*Invoke-IronPython3.ps1*",".{0,1000}Invoke\-IronPython3\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49122" +"*Invoke-JSRatRegsvr*",".{0,1000}Invoke\-JSRatRegsvr.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49123" +"*Invoke-JSRatRegsvr*",".{0,1000}Invoke\-JSRatRegsvr.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49124" +"*Invoke-JSRatRundll*",".{0,1000}Invoke\-JSRatRundll.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49125" +"*Invoke-JSRatRundll*",".{0,1000}Invoke\-JSRatRundll.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49126" +"*Invoke-JuicyPotato*",".{0,1000}Invoke\-JuicyPotato.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49127" +"*Invoke-KeeThief*",".{0,1000}Invoke\-KeeThief.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49128" +"*invokekerberoast*",".{0,1000}invokekerberoast.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","49130" +"*Invoke-Kerberoast*",".{0,1000}Invoke\-Kerberoast.{0,1000}","offensive_tool_keyword","ADAPE-Script","Active Directory Assessment and Privilege Escalation Script","T1178 - T1087 - T1482","TA0002 - TA0004 - TA0007","N/A","Black Basta","Privilege Escalation","https://github.com/cjoan75/ADAPE-Script","1","1","N/A","N/A","8","1","0","0","2020-07-11T00:53:24Z","2020-08-09T16:52:35Z","49131" +"*Invoke-Kerberoast*",".{0,1000}Invoke\-Kerberoast.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","49132" +"*Invoke-Kerberoast*",".{0,1000}Invoke\-Kerberoast.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","49133" +"*Invoke-Kerberoast*",".{0,1000}Invoke\-Kerberoast.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1059","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49134" +"*Invoke-Kerberoast*",".{0,1000}Invoke\-Kerberoast.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1024 - T1071 - T1029 - T1569","TA0002 - TA0003 - TA0040","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","49135" +"*Invoke-Kerberoast*",".{0,1000}Invoke\-Kerberoast.{0,1000}","offensive_tool_keyword","powerview","PowerView is a PowerShell tool to gain network situational awareness on Windows domains","T1046 - T1087.001 - T1016","TA0007 - TA0008 - TA0009","N/A","Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA","Discovery","https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","49136" +"*Invoke-Kerberoast.ps1*",".{0,1000}Invoke\-Kerberoast\.ps1.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1024 - T1071 - T1029 - T1569","TA0002 - TA0003 - TA0040","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","49138" +"*Invoke-Keylogger*",".{0,1000}Invoke\-Keylogger\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49139" +"*Invoke-Kirby*",".{0,1000}Invoke\-Kirby.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","49140" +"*Invoke-KrbRelay*",".{0,1000}Invoke\-KrbRelay.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49141" +"*Invoke-LapsCheck*",".{0,1000}Invoke\-LapsCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49142" +"*Invoke-LapsCheck*",".{0,1000}Invoke\-LapsCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49143" +"*Invoke-LazySign.ps1*",".{0,1000}Invoke\-LazySign\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","49144" +"*Invoke-LdapSignCheck*",".{0,1000}Invoke\-LdapSignCheck.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49147" +"*Invoke-LdapSignCheck*",".{0,1000}Invoke\-LdapSignCheck.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49148" +"*Invoke-LocalAdminGroupCheck*",".{0,1000}Invoke\-LocalAdminGroupCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49149" +"*Invoke-LocalAdminGroupCheck*",".{0,1000}Invoke\-LocalAdminGroupCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49150" +"*Invoke-Lockless*",".{0,1000}Invoke\-Lockless.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49151" +"*Invoke-Locksmith.ps1*",".{0,1000}Invoke\-Locksmith\.ps1.{0,1000}","offensive_tool_keyword","Locksmith","A tiny tool to identify and remediate common misconfigurations in Active Directory Certificate Services","T1552.006 - T1222 - T1046","TA0007 - TA0040 - TA0043","N/A","N/A","Discovery","https://github.com/TrimarcJake/Locksmith","1","1","N/A","N/A","8","10","1086","100","2025-04-21T12:43:50Z","2022-04-28T01:37:32Z","49152" +"*Invoke-LockWorkStation*",".{0,1000}Invoke\-LockWorkStation.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49153" +"*Invoke-LoginPrompt.ps1*",".{0,1000}Invoke\-LoginPrompt\.ps1.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","49154" +"*Invoke-LoopBackdoor*",".{0,1000}Invoke\-LoopBackdoor.{0,1000}","offensive_tool_keyword","PowerBreach","PowerBreach is a backdoor toolkit that aims to provide the user a wide variety of methods to backdoor a system","T1055 - T1203 - T1105 - T1202 - T1027 - T1059 - T1070","TA0005 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","49155" +"*Invoke-LSADump*",".{0,1000}Invoke\-LSADump.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","49157" +"*Invoke-LsaProtectionCheck*",".{0,1000}Invoke\-LsaProtectionCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49158" +"*Invoke-LsaProtectionsCheck*",".{0,1000}Invoke\-LsaProtectionsCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49159" +"*Invoke-LSWMImplant*",".{0,1000}Invoke\-LSWMImplant.{0,1000}","offensive_tool_keyword","WMImplant","WMImplant is a PowerShell based tool that leverages WMI to both perform actions against targeted machines. but also as the C2 channel for issuing commands and receiving results. WMImplant will likely require local administrator permissions on the targeted machine.","T1021 - T1059 - T1047 - T1057 - T1049","TA0002 - TA0003 - TA0008 - TA0009 - TA0011","N/A","N/A","C2","https://github.com/FortyNorthSecurity/WMImplant","1","1","N/A","N/A","N/A","10","813","146","2024-06-25T12:02:26Z","2016-05-24T14:00:14Z","49160" +"*Invoke-M.i.m.i.k.a.t.z*",".{0,1000}Invoke\-M\.i\.m\.i\.k\.a\.t\.z.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","49161" +"*Invoke-MachineRoleCheck*",".{0,1000}Invoke\-MachineRoleCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49162" +"*Invoke-MailSearch*",".{0,1000}Invoke\-MailSearch.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49163" +"*Invoke-MalSCCM*",".{0,1000}Invoke\-MalSCCM.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49165" +"*Invoke-MalSCCM*",".{0,1000}Invoke\-MalSCCM.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49166" +"*Invoke-MassCommand.ps1*",".{0,1000}Invoke\-MassCommand\.ps1.{0,1000}","offensive_tool_keyword","PewPewPew","host a script on a PowerShell webserver, invoke the IEX download cradle to download/execute the target code and post the results back to the server","T1059.001 - T1102 - T1056 - T1071 - T1086 - T1123","TA0011 - TA0010 - TA0005 - TA0002 - TA0009 - TA0006","N/A","N/A","Credential Access","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","49168" +"*Invoke-MassMimikatz*",".{0,1000}Invoke\-MassMimikatz.{0,1000}","offensive_tool_keyword","PewPewPew","host a script on a PowerShell webserver, invoke the IEX download cradle to download/execute the target code and post the results back to the server","T1059.001 - T1102 - T1056 - T1071 - T1086 - T1123","TA0011 - TA0010 - TA0005 - TA0002 - TA0009 - TA0006","N/A","N/A","Credential Access","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","49169" +"*Invoke-MassSearch.ps1*",".{0,1000}Invoke\-MassSearch\.ps1.{0,1000}","offensive_tool_keyword","PewPewPew","host a script on a PowerShell webserver, invoke the IEX download cradle to download/execute the target code and post the results back to the server","T1059.001 - T1102 - T1056 - T1071 - T1086 - T1123","TA0011 - TA0010 - TA0005 - TA0002 - TA0009 - TA0006","N/A","N/A","Credential Access","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","49170" +"*Invoke-MassTokens.ps1*",".{0,1000}Invoke\-MassTokens\.ps1.{0,1000}","offensive_tool_keyword","PewPewPew","host a script on a PowerShell webserver, invoke the IEX download cradle to download/execute the target code and post the results back to the server","T1059.001 - T1102 - T1056 - T1071 - T1086 - T1123","TA0011 - TA0010 - TA0005 - TA0002 - TA0009 - TA0006","N/A","N/A","Credential Access","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","49171" +"*Invoke-Merlin.ps1*",".{0,1000}Invoke\-Merlin\.ps1.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","49174" +"*Invoke-MetasploitPayload*",".{0,1000}Invoke\-MetasploitPayload.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49175" +"*Invoke-MetasploitPayload*",".{0,1000}Invoke\-MetasploitPayload.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","49176" +"*Invoke-MetasploitPayload.ps1*",".{0,1000}Invoke\-MetasploitPayload\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49177" +"*Invoke-MetasploitPayload.ps1*",".{0,1000}Invoke\-MetasploitPayload\.ps1.{0,1000}","offensive_tool_keyword","PSAttack","PSAttack contains over 100 commands for Privilege Escalation - Recon and Data Exfilitration","T1059 - T1212 - T1012 - T1087 - T1005 - T1041 - T1020","TA0002 - TA0004 - TA0005 - TA0007 - TA0010 - TA0008","N/A","N/A","Exploitation tool","https://github.com/GDSSecurity/PSAttack","1","1","N/A","N/A","10","1","45","15","2017-04-04T20:37:33Z","2016-02-22T23:45:22Z","49178" +"*Invoke-MetaTwin*",".{0,1000}Invoke\-MetaTwin.{0,1000}","offensive_tool_keyword","metatwin","The project is designed as a file resource cloner. Metadata including digital signature is extracted from one file and injected into another","T1553.002 - T1114.001 - T1564.003","TA0006 - TA0010","N/A","N/A","Exploitation tool","https://github.com/threatexpress/metatwin","1","1","N/A","N/A","9","4","345","71","2024-11-19T19:45:59Z","2017-10-08T13:26:00Z","49179" +"*InvokeMeter.bat*",".{0,1000}InvokeMeter\.bat.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","49180" +"*Invoke-MFASweep*",".{0,1000}Invoke\-MFASweep.{0,1000}","offensive_tool_keyword","Graphpython","Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit","T1078.004 - T1114.002","TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010","N/A","N/A","Discovery","https://github.com/mlcsec/Graphpython","1","1","N/A","N/A","7","2","145","13","2024-12-07T21:54:00Z","2024-07-10T00:04:48Z","49181" +"*Invoke-MFASweep*",".{0,1000}Invoke\-MFASweep.{0,1000}","offensive_tool_keyword","MFASweep","A tool for checking if MFA is enabled on multiple Microsoft Services","T1595 - T1595.002 - T1078.003 - T1621","TA0006 - TA0009","N/A","N/A","Exploitation tool","https://github.com/dafthack/MFASweep","1","1","N/A","N/A","9","10","1484","203","2025-03-04T20:36:41Z","2020-09-22T16:25:03Z","49182" +"*Invoke-Mimidogz.ps1*",".{0,1000}Invoke\-Mimidogz\.ps1.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","1","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","49185" +"*Invoke-Mimikatz*",".{0,1000}Invoke\-Mimikatz.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","49187" +"*Invoke-Mimikatz*",".{0,1000}Invoke\-Mimikatz.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/g4uss47/Invoke-Mimikatz","1","1","N/A","N/A","10","1","62","14","2024-04-18T14:28:21Z","2020-09-22T16:47:19Z","49188" +"*Invoke-Mimikatz*",".{0,1000}Invoke\-Mimikatz.{0,1000}","offensive_tool_keyword","mimikatz","Invoke-Mimikatz.ps1 function name","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Invoke-Mimikatz.ps1","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","49189" +"*Invoke-Mimikatz*",".{0,1000}Invoke\-Mimikatz.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49190" +"*Invoke-Mimikatz*",".{0,1000}Invoke\-Mimikatz.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","49192" +"*Invoke-Mimikatz*",".{0,1000}Invoke\-Mimikatz.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","49193" +"*Invoke-Mimikatz.json*",".{0,1000}Invoke\-Mimikatz\.json.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","49194" +"*Invoke-Mimikatz.ps1*",".{0,1000}Invoke\-Mimikatz\.ps1.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","49195" +"*Invoke-Mimikatz.ps1*",".{0,1000}Invoke\-Mimikatz\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49196" +"*Invoke-Mimikatz.ps1*",".{0,1000}Invoke\-Mimikatz\.ps1.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","49197" +"*Invoke-Mimikatz.ps1*",".{0,1000}Invoke\-Mimikatz\.ps1.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","49198" +"*Invoke-Mimikatz.ps1*",".{0,1000}Invoke\-Mimikatz\.ps1.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/g4uss47/Invoke-Mimikatz","1","1","N/A","N/A","10","1","62","14","2024-04-18T14:28:21Z","2020-09-22T16:47:19Z","49199" +"*Invoke-Mimikatz.ps1*",".{0,1000}Invoke\-Mimikatz\.ps1.{0,1000}","offensive_tool_keyword","PSAttack","PSAttack contains over 100 commands for Privilege Escalation - Recon and Data Exfilitration","T1059 - T1212 - T1012 - T1087 - T1005 - T1041 - T1020","TA0002 - TA0004 - TA0005 - TA0007 - TA0010 - TA0008","N/A","N/A","Exploitation tool","https://github.com/GDSSecurity/PSAttack","1","1","N/A","N/A","10","1","45","15","2017-04-04T20:37:33Z","2016-02-22T23:45:22Z","49200" +"*Invoke-Mimikatz.ps1*",".{0,1000}Invoke\-Mimikatz\.ps1.{0,1000}","offensive_tool_keyword","PSAttack","PSAttack contains over 100 commands for Privilege Escalation - Recon and Data Exfilitration","T1059 - T1212 - T1012 - T1087 - T1005 - T1041 - T1020","TA0002 - TA0004 - TA0005 - TA0007 - TA0010 - TA0008","N/A","N/A","Exploitation tool","https://github.com/GDSSecurity/PSAttack","1","1","N/A","N/A","10","1","45","15","2017-04-04T20:37:33Z","2016-02-22T23:45:22Z","49201" +"*Invoke-Mimikatz-old*",".{0,1000}Invoke\-Mimikatz\-old.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","49202" +"*Invoke-MimikatzWDigestDowngrade*",".{0,1000}Invoke\-MimikatzWDigestDowngrade.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49203" +"*Invoke-mimikittenz*",".{0,1000}Invoke\-mimikittenz.{0,1000}","offensive_tool_keyword","Dispossessor","credential scripts used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","49204" +"*Invoke-Mimikittenz*",".{0,1000}Invoke\-Mimikittenz.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49205" +"*Invoke-mimikittenz.ps1*",".{0,1000}Invoke\-mimikittenz\.ps1.{0,1000}","offensive_tool_keyword","PSAttack","PSAttack contains over 100 commands for Privilege Escalation - Recon and Data Exfilitration","T1059 - T1212 - T1012 - T1087 - T1005 - T1041 - T1020","TA0002 - TA0004 - TA0005 - TA0007 - TA0010 - TA0008","N/A","N/A","Exploitation tool","https://github.com/GDSSecurity/PSAttack","1","1","N/A","N/A","10","1","45","15","2017-04-04T20:37:33Z","2016-02-22T23:45:22Z","49206" +"*Invoke-MITM6*",".{0,1000}Invoke\-MITM6.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49207" +"*Invoke-ModifiableProgramsCheck*",".{0,1000}Invoke\-ModifiableProgramsCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49208" +"*Invoke-MonitorCredSniper*",".{0,1000}Invoke\-MonitorCredSniper.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49210" +"*Invoke-MS16*",".{0,1000}Invoke\-MS16.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49211" +"*Invoke-MS16032*",".{0,1000}Invoke\-MS16032.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-MS16032.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49212" +"*Invoke-MS16032.ps1*",".{0,1000}Invoke\-MS16032\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49213" +"*Invoke-MS16-032.ps1*",".{0,1000}Invoke\-MS16\-032\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49214" +"*Invoke-MS16-032.ps1*",".{0,1000}Invoke\-MS16\-032\.ps1.{0,1000}","offensive_tool_keyword","PSAttack","PSAttack contains over 100 commands for Privilege Escalation - Recon and Data Exfilitration","T1059 - T1212 - T1012 - T1087 - T1005 - T1041 - T1020","TA0002 - TA0004 - TA0005 - TA0007 - TA0010 - TA0008","N/A","N/A","Exploitation tool","https://github.com/GDSSecurity/PSAttack","1","1","N/A","N/A","10","1","45","15","2017-04-04T20:37:33Z","2016-02-22T23:45:22Z","49215" +"*Invoke-MS16135*",".{0,1000}Invoke\-MS16135.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-MS16135.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49216" +"*Invoke-MSSprinkler*",".{0,1000}Invoke\-MSSprinkler.{0,1000}","offensive_tool_keyword","MSSprinkler","password spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approach","T1110.003 - T1110.001","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/TheresAFewConors/MSSprinkler","1","1","N/A","N/A","9","1","74","7","2025-02-25T13:32:41Z","2024-09-15T09:54:53Z","49217" +"*Invoke-NamedPipePermissionsCheck*",".{0,1000}Invoke\-NamedPipePermissionsCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49219" +"*Invoke-NanoDump*",".{0,1000}Invoke\-NanoDump.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49220" +"*Invoke-NanoDump*",".{0,1000}Invoke\-NanoDump.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49221" +"*Invoke-NetRipper*",".{0,1000}Invoke\-NetRipper.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1069","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49223" +"*Invoke-NetRipper*",".{0,1000}Invoke\-NetRipper.{0,1000}","offensive_tool_keyword","NetRipper","NetRipper - Smart traffic sniffing for penetration testers","T1173 - T1557 - T1573.001 - T1056.001","TA0009 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/NytroRST/NetRipper","1","1","N/A","N/A","10","10","1368","318","2022-06-17T21:08:54Z","2015-07-14T20:31:04Z","49224" +"*Invoke-NetRipper.ps1*",".{0,1000}Invoke\-NetRipper\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49225" +"*Invoke-NetworkAdaptersCheck*",".{0,1000}Invoke\-NetworkAdaptersCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49226" +"*Invoke-NetworkRelay*",".{0,1000}Invoke\-NetworkRelay.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49227" +"*Invoke-NetworkRelay.ps1*",".{0,1000}Invoke\-NetworkRelay\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49228" +"*Invoke-Nightmare*",".{0,1000}Invoke\-Nightmare.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49232" +"*Invoke-NinjaCopy*",".{0,1000}Invoke\-NinjaCopy.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49233" +"*Invoke-NinjaCopy*",".{0,1000}Invoke\-NinjaCopy.{0,1000}","offensive_tool_keyword","PSAttack","PSAttack contains over 100 commands for Privilege Escalation - Recon and Data Exfilitration","T1059 - T1212 - T1012 - T1087 - T1005 - T1041 - T1020","TA0002 - TA0004 - TA0005 - TA0007 - TA0010 - TA0008","N/A","N/A","Exploitation tool","https://github.com/GDSSecurity/PSAttack","1","1","N/A","N/A","10","1","45","15","2017-04-04T20:37:33Z","2016-02-22T23:45:22Z","49235" +"*Invoke-NinjaCopy.ps1*",".{0,1000}Invoke\-NinjaCopy\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49237" +"*Invoke-NTLMAuth.ps1*",".{0,1000}Invoke\-NTLMAuth\.ps1.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","49240" +"*Invoke-NTLMExtract*",".{0,1000}Invoke\-NTLMExtract.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49241" +"*Invoke-NTLMExtract*",".{0,1000}Invoke\-NTLMExtract.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49242" +"*Invoke-NTLMExtract.ps1*",".{0,1000}Invoke\-NTLMExtract\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49243" +"*Invoke-Ntsd.ps1*",".{0,1000}Invoke\-Ntsd\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1148","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49244" +"*Invoke-Obfuscation*",".{0,1000}Invoke\-Obfuscation.{0,1000}","offensive_tool_keyword","Invoke-Obfuscation","Invoke-Obfuscation is a PowerShell v2.0+ compatible PowerShell command and script obfuscator.","T1027 - T1059.001 - T1564.003","TA0005 - TA0002","N/A","Oilrig - Dispossessor","Defense Evasion","https://github.com/danielbohannon/Invoke-Obfuscation","1","1","N/A","N/A","10","10","3935","782","2023-08-10T23:49:06Z","2016-09-25T03:38:02Z","49246" +"*Invoke-Obfuscation.psd1*",".{0,1000}Invoke\-Obfuscation\.psd1.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","49247" +"*Invoke-OpenInboxFinder*",".{0,1000}Invoke\-OpenInboxFinder.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49248" +"*Invoke-OpenOWAMailboxInBrowser*",".{0,1000}Invoke\-OpenOWAMailboxInBrowser.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","49249" +"*Invoke-OxidResolver*",".{0,1000}Invoke\-OxidResolver.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49250" +"*Invoke-Oxidresolver*",".{0,1000}Invoke\-Oxidresolver.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49251" +"*Invoke-OxidResolver*",".{0,1000}Invoke\-OxidResolver.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49252" +"*Invoke-P0wnedshell*",".{0,1000}Invoke\-P0wnedshell.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49253" +"*Invoke-P0wnedshellx86*",".{0,1000}Invoke\-P0wnedshellx86.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49254" +"*Invoke-PacketCapture*",".{0,1000}Invoke\-PacketCapture.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49255" +"*Invoke-PacketKnock*",".{0,1000}Invoke\-PacketKnock.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerBreach.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49256" +"*Invoke-Paranoia*",".{0,1000}Invoke\-Paranoia.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-Paranoia.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49259" +"*Invoke-Paranoia.ps1*",".{0,1000}Invoke\-Paranoia\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49260" +"*Invoke-PassSpray*",".{0,1000}Invoke\-PassSpray.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","49262" +"*Invoke-PassSpray*",".{0,1000}Invoke\-PassSpray.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","49263" +"*Invoke-PassSpray*",".{0,1000}Invoke\-PassSpray.{0,1000}","offensive_tool_keyword","PassSpray","Domain Password Spray","T1110.003 - T1078","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/PassSpray","1","1","N/A","N/A","10","1","7","3","2025-02-20T10:07:43Z","2023-11-16T13:35:49Z","49264" +"*Invoke-PasswordSpray*",".{0,1000}Invoke\-PasswordSpray.{0,1000}","offensive_tool_keyword","MailSniper","Invoke-PasswordSpray* will attempt to connect to an * portal and perform a password spraying attack using a userlist and a single password.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Exploitation tool","https://github.com/dafthack/MailSniper","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49265" +"*Invoke-PasswordSprayEAS*",".{0,1000}Invoke\-PasswordSprayEAS.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","1","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","49266" +"*Invoke-PasswordSprayEAS*",".{0,1000}Invoke\-PasswordSprayEAS.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49267" +"*Invoke-PasswordSprayEWS*",".{0,1000}Invoke\-PasswordSprayEWS.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49268" +"*Invoke-PasswordSprayGmail*",".{0,1000}Invoke\-PasswordSprayGmail.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49269" +"*Invoke-PasswordSprayOWA*",".{0,1000}Invoke\-PasswordSprayOWA.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49270" +"*Invoke-Patamenia.ps1*",".{0,1000}Invoke\-Patamenia\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","49271" +"*Invoke-PatchDll*",".{0,1000}Invoke\-PatchDll.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-BypassUAC.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49273" +"*Invoke-PatchDll*",".{0,1000}Invoke\-PatchDll.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-PSInject.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49274" +"*Invoke-Pbind.ps1*",".{0,1000}Invoke\-Pbind\.ps1.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","49276" +"*Invoke-Phant0m*",".{0,1000}Invoke\-Phant0m.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49277" +"*Invoke-Phant0m*",".{0,1000}Invoke\-Phant0m.{0,1000}","offensive_tool_keyword","cobaltstrike","Aggressor script to integrate Phant0m with Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/p292/Phant0m_cobaltstrike","1","1","N/A","N/A","10","10","27","13","2017-06-08T06:42:18Z","2017-06-08T06:39:07Z","49278" +"*Invoke-Phant0m*",".{0,1000}Invoke\-Phant0m.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","49280" +"*Invoke-Phant0m.ps1*",".{0,1000}Invoke\-Phant0m\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49281" +"*Invoke-Phant0m.ps1*",".{0,1000}Invoke\-Phant0m\.ps1.{0,1000}","offensive_tool_keyword","cobaltstrike","Aggressor script to integrate Phant0m with Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/p292/Phant0m_cobaltstrike","1","1","N/A","N/A","10","10","27","13","2017-06-08T06:42:18Z","2017-06-08T06:39:07Z","49282" +"*Invoke-Phant0m.ps1*",".{0,1000}Invoke\-Phant0m\.ps1.{0,1000}","offensive_tool_keyword","Phant0m","Windows Event Log Killer","T1070.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/hlldz/Phant0m","1","1","N/A","N/A","N/A","10","1781","301","2023-09-21T16:08:18Z","2017-05-02T17:19:30Z","49283" +"*Invoke-PhishingLNK*",".{0,1000}Invoke\-PhishingLNK.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49284" +"*Invoke-PhishingLNK*",".{0,1000}Invoke\-PhishingLNK.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49285" +"*Invoke-PhishingLNK.ps1*",".{0,1000}Invoke\-PhishingLNK\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49286" +"*Invoke-Piper*",".{0,1000}Invoke\-Piper.{0,1000}","offensive_tool_keyword","invoke-piper","Forward local or remote tcp ports through SMB pipes.","T1003.001 - T1048 - T1021.002 - T1021.001 - T1090","TA0002 -TA0006 - TA0008","N/A","N/A","Lateral Movement","https://github.com/p3nt4/Invoke-Piper","1","1","N/A","N/A","N/A","3","295","51","2021-03-07T19:07:01Z","2017-08-03T08:06:44Z","49289" +"*Invoke-PiperClient*",".{0,1000}Invoke\-PiperClient.{0,1000}","offensive_tool_keyword","invoke-piper","Forward local or remote tcp ports through SMB pipes.","T1003.001 - T1048 - T1021.002 - T1021.001 - T1090","TA0002 -TA0006 - TA0008","N/A","N/A","Lateral Movement","https://github.com/p3nt4/Invoke-Piper","1","1","N/A","N/A","N/A","3","295","51","2021-03-07T19:07:01Z","2017-08-03T08:06:44Z","49290" +"*Invoke-PiperServer*",".{0,1000}Invoke\-PiperServer.{0,1000}","offensive_tool_keyword","invoke-piper","Forward local or remote tcp ports through SMB pipes.","T1003.001 - T1048 - T1021.002 - T1021.001 - T1090","TA0002 -TA0006 - TA0008","N/A","N/A","Lateral Movement","https://github.com/p3nt4/Invoke-Piper","1","1","N/A","N/A","N/A","3","295","51","2021-03-07T19:07:01Z","2017-08-03T08:06:44Z","49291" +"*Invoke-PipeShell.ps1*",".{0,1000}Invoke\-PipeShell\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49292" +"*Invoke-PortBind*",".{0,1000}Invoke\-PortBind.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerBreach.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49293" +"*Invoke-PortBindBackdoor*",".{0,1000}Invoke\-PortBindBackdoor.{0,1000}","offensive_tool_keyword","PowerBreach","PowerBreach is a backdoor toolkit that aims to provide the user a wide variety of methods to backdoor a system","T1055 - T1203 - T1105 - T1202 - T1027 - T1059 - T1070","TA0005 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","49294" +"*Invoke-PortFwd.ps1*",".{0,1000}Invoke\-PortFwd\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49296" +"*Invoke-PortKnockBackdoor*",".{0,1000}Invoke\-PortKnockBackdoor.{0,1000}","offensive_tool_keyword","PowerBreach","PowerBreach is a backdoor toolkit that aims to provide the user a wide variety of methods to backdoor a system","T1055 - T1203 - T1105 - T1202 - T1027 - T1059 - T1070","TA0005 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","49297" +"*Invoke-Portscan*",".{0,1000}Invoke\-Portscan.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49298" +"*Invoke-Portscan*",".{0,1000}Invoke\-Portscan.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-Portscan.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49300" +"*Invoke-PortScan*",".{0,1000}Invoke\-PortScan.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49301" +"*Invoke-PortScan*",".{0,1000}Invoke\-PortScan.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","49303" +"*Invoke-Portscan.ps1*",".{0,1000}Invoke\-Portscan\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49304" +"*Invoke-Portscan.ps1*",".{0,1000}Invoke\-Portscan\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1081","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49305" +"*Invoke-PoshRatHttp*",".{0,1000}Invoke\-PoshRatHttp.{0,1000}","offensive_tool_keyword","chimera","Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.","T1027.002 - T1059.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/tokyoneon/Chimera/","1","1","N/A","N/A","10","10","1493","252","2021-11-09T12:39:59Z","2020-09-01T07:42:22Z","49306" +"*Invoke-PoshRatHttp*",".{0,1000}Invoke\-PoshRatHttp.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49307" +"*Invoke-PoshRatHttp*",".{0,1000}Invoke\-PoshRatHttp.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49308" +"*Invoke-PoshRatHttps*",".{0,1000}Invoke\-PoshRatHttps.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49309" +"*Invoke-PoshRatHttps*",".{0,1000}Invoke\-PoshRatHttps.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49310" +"*Invoke-PostDump*",".{0,1000}Invoke\-PostDump.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection","T1003","TA0006","N/A","Black Basta","Credential Access","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49311" +"*Invoke-PostExfil*",".{0,1000}Invoke\-PostExfil.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-PostExfil.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49312" +"*Invoke-PowerDump*",".{0,1000}Invoke\-PowerDump.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","49313" +"*Invoke-PowerDump*",".{0,1000}Invoke\-PowerDump.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49314" +"*Invoke-PowerDump*",".{0,1000}Invoke\-PowerDump.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49315" +"*Invoke-PowerDump.ps1*",".{0,1000}Invoke\-PowerDump\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49316" +"*Invoke-PowerExtract*",".{0,1000}Invoke\-PowerExtract.{0,1000}","offensive_tool_keyword","powerextract","This tool is able to parse memory dumps of the LSASS process without any additional tools (e.g. Debuggers) or additional sideloading of mimikatz. It is a pure PowerShell implementation for parsing and extracting secrets (LSA / MSV and Kerberos) of the LSASS process","T1003 - T1055 - T1003.001 - T1055.012","TA0007 - TA0002","N/A","N/A","Credential Access","https://github.com/powerseb/PowerExtract","1","1","N/A","N/A","N/A","2","117","14","2025-03-28T10:49:43Z","2021-12-11T15:24:44Z","49317" +"*Invoke-PowerIncrease.ps1*",".{0,1000}Invoke\-PowerIncrease\.ps1.{0,1000}","offensive_tool_keyword","Invoke-PowerIncrease","binary padding to add junk data and change the on-disk representation of a file","T1480 - T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/The-Viper-One/Invoke-PowerIncrease","1","1","N/A","N/A","8","1","3","0","2024-08-01T18:10:02Z","2024-07-18T17:40:26Z","49319" +"*Invoke-PowerShellHistoryCheck*",".{0,1000}Invoke\-PowerShellHistoryCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49321" +"*Invoke-PowerShellIcmp*",".{0,1000}Invoke\-PowerShellIcmp.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49322" +"*Invoke-PowerShellIcmp.ps1*",".{0,1000}Invoke\-PowerShellIcmp\.ps1.{0,1000}","offensive_tool_keyword","chimera","Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.","T1027.002 - T1059.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/tokyoneon/Chimera/","1","1","N/A","N/A","10","10","1493","252","2021-11-09T12:39:59Z","2020-09-01T07:42:22Z","49323" +"*Invoke-PowerShellIcmp.ps1*",".{0,1000}Invoke\-PowerShellIcmp\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49324" +"*Invoke-PowerShellTcp*",".{0,1000}Invoke\-PowerShellTcp.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49325" +"*Invoke-PowerShellTcp*",".{0,1000}Invoke\-PowerShellTcp.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49326" +"*Invoke-PowerShellTcp.ps1*",".{0,1000}Invoke\-PowerShellTcp\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49327" +"*Invoke-PowerShellTcp.ps1*",".{0,1000}Invoke\-PowerShellTcp\.ps1.{0,1000}","offensive_tool_keyword","chimera","Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.","T1027.002 - T1059.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/tokyoneon/Chimera/","1","1","N/A","N/A","10","10","1493","252","2021-11-09T12:39:59Z","2020-09-01T07:42:22Z","49328" +"*Invoke-PowerShellTcp.ps1*",".{0,1000}Invoke\-PowerShellTcp\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49329" +"*Invoke-PowerShellTcpOneLine*",".{0,1000}Invoke\-PowerShellTcpOneLine.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49330" +"*Invoke-PowerShellTcpOneLine.ps1*",".{0,1000}Invoke\-PowerShellTcpOneLine\.ps1.{0,1000}","offensive_tool_keyword","chimera","Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.","T1027.002 - T1059.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/tokyoneon/Chimera/","1","1","N/A","N/A","10","10","1493","252","2021-11-09T12:39:59Z","2020-09-01T07:42:22Z","49332" +"*Invoke-PowerShellTcpOneLine.ps1*",".{0,1000}Invoke\-PowerShellTcpOneLine\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49333" +"*Invoke-PowerShellTcpOneLine.ps1*",".{0,1000}Invoke\-PowerShellTcpOneLine\.ps1.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","49334" +"*Invoke-PowerShellTcpOneLineBind*",".{0,1000}Invoke\-PowerShellTcpOneLineBind.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49335" +"*Invoke-PowerShellTcpOneLineBind.ps1*",".{0,1000}Invoke\-PowerShellTcpOneLineBind\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49336" +"*Invoke-PowershellTranscriptionCheck*",".{0,1000}Invoke\-PowershellTranscriptionCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49337" +"*Invoke-PowerShellUdp*",".{0,1000}Invoke\-PowerShellUdp.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49338" +"*Invoke-PowerShellUdp.ps1*",".{0,1000}Invoke\-PowerShellUdp\.ps1.{0,1000}","offensive_tool_keyword","chimera","Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.","T1027.002 - T1059.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/tokyoneon/Chimera/","1","1","N/A","N/A","10","10","1493","252","2021-11-09T12:39:59Z","2020-09-01T07:42:22Z","49339" +"*Invoke-PowerShellUdp.ps1*",".{0,1000}Invoke\-PowerShellUdp\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49340" +"*Invoke-PowerShellUdpOneLine*",".{0,1000}Invoke\-PowerShellUdpOneLine.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49341" +"*Invoke-PowerShellUdpOneLine.ps1*",".{0,1000}Invoke\-PowerShellUdpOneLine\.ps1.{0,1000}","offensive_tool_keyword","chimera","Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.","T1027.002 - T1059.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/tokyoneon/Chimera/","1","1","N/A","N/A","10","10","1493","252","2021-11-09T12:39:59Z","2020-09-01T07:42:22Z","49342" +"*Invoke-PowerShellUdpOneLine.ps1*",".{0,1000}Invoke\-PowerShellUdpOneLine\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49343" +"*Invoke-PowerShellWmi*",".{0,1000}Invoke\-PowerShellWmi.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49344" +"*Invoke-PowerShellWmi.ps1*",".{0,1000}Invoke\-PowerShellWmi\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49345" +"*Invoke-PowerThIEf*",".{0,1000}Invoke\-PowerThIEf.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","49347" +"*Invoke-PowerThIEf.ps1*",".{0,1000}Invoke\-PowerThIEf\.ps1.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","49348" +"*Invoke-PPLDump*",".{0,1000}Invoke\-PPLDump.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49349" +"*Invoke-Prasadhak*",".{0,1000}Invoke\-Prasadhak.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49350" +"*Invoke-Prasadhak.ps1*",".{0,1000}Invoke\-Prasadhak\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49351" +"*Invoke-Pre2kSpray*",".{0,1000}Invoke\-Pre2kSpray.{0,1000}","offensive_tool_keyword","Invoke-Pre2kSpray","Enumerate domain machine accounts and perform pre2k password spraying.","T1087.002 - T1110.003","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/eversinc33/Invoke-Pre2kSpray","1","1","N/A","N/A","8","1","69","11","2023-07-14T06:50:22Z","2023-07-05T10:07:38Z","49352" +"*Invoke-PrintDemon*",".{0,1000}Invoke\-PrintDemon.{0,1000}","offensive_tool_keyword","Invoke-PrintDemon","This is an PowerShell Empire launcher PoC using PrintDemon and Faxhell. The module has the Faxhell DLL already embedded which leverages CVE-2020-1048 for privilege escalation. The vulnerability allows an unprivileged user to gain system-level privileges and is based on @ionescu007 PoC.","T1204 - T1208 - T1216 - T1055 - T1203","TA0001 - TA0007 - TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/BC-SECURITY/Invoke-PrintDemon","1","1","N/A","N/A","N/A","3","201","38","2020-10-17T17:04:24Z","2020-05-15T05:14:49Z","49353" +"*Invoke-PrintDemon.ps1*",".{0,1000}Invoke\-PrintDemon\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49354" +"*Invoke-Printnightmare.ps1*",".{0,1000}Invoke\-Printnightmare\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49355" +"*Invoke-PrintNightmareCheck*",".{0,1000}Invoke\-PrintNightmareCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49356" +"*Invoke-Privesc*",".{0,1000}Invoke\-Privesc.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49358" +"*Invoke-PrivescCheck*",".{0,1000}Invoke\-PrivescCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49361" +"*Invoke-PrivescCheck*",".{0,1000}Invoke\-PrivescCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49362" +"*Invoke-PrivescCheck.ps1*",".{0,1000}Invoke\-PrivescCheck\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49363" +"*invokeprocesshunter*",".{0,1000}invokeprocesshunter.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","49364" +"*Invoke-ProcessHunter*",".{0,1000}Invoke\-ProcessHunter.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","49365" +"*invoke-processhunter*",".{0,1000}invoke\-processhunter.{0,1000}","offensive_tool_keyword","pywerview","A partial Python rewriting of PowerSploit PowerView","T1069.002 - T1018 - T1087.001 - T1033 - T1069.001 - T1087.002 - T1016 - T1482","TA0007 - TA0009","N/A","N/A","Reconnaissance","https://github.com/the-useless-one/pywerview","1","1","N/A","N/A","N/A","10","974","121","2025-03-17T14:04:51Z","2016-07-06T13:25:09Z","49368" +"*Invoke-ProcessKiller*",".{0,1000}Invoke\-ProcessKiller.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49369" +"*Invoke-ProcessScan*",".{0,1000}Invoke\-ProcessScan.{0,1000}","offensive_tool_keyword","Invoke-ProcessScan","This script uses a list from the Equation Group leak from the shadow brokers to provide context to executeables that are running on a system.","T1059.001 - T1016 - T1547.001","TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/vysecurity/Invoke-ProcessScan","1","1","N/A","N/A","N/A","1","45","19","2017-06-05T12:19:25Z","2017-06-03T18:36:30Z","49371" +"*InvokePS1.bat*",".{0,1000}InvokePS1\.bat.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","49374" +"*Invoke-ps2exe*",".{0,1000}Invoke\-ps2exe.{0,1000}","offensive_tool_keyword","PS2EXE","Module to compile powershell scripts to executables","T1027.001 - T1564.003 - T1564.005","TA0002 - TA0006","N/A","N/A","Exploitation tool","https://github.com/MScholtes/PS2EXE","1","1","N/A","N/A","N/A","10","1395","217","2025-01-05T11:26:50Z","2019-11-08T09:25:02Z","49375" +"*Invoke-PSAmsiScan*",".{0,1000}Invoke\-PSAmsiScan.{0,1000}","offensive_tool_keyword","PSAmsi","PSAmsi is a tool for auditing and defeating AMSI signatures.","T1059.001 - T1562.001 - T1070.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/cobbr/PSAmsi","1","1","N/A","N/A","7","4","390","74","2018-04-22T20:56:33Z","2017-09-22T11:48:47Z","49376" +"*Invoke-PsExec*",".{0,1000}Invoke\-PsExec.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-PsExec.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49377" +"*Invoke-PSexec.ps1*",".{0,1000}Invoke\-PSexec\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49378" +"*Invoke-PsExec.ps1*",".{0,1000}Invoke\-PsExec\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1095","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49379" +"*Invoke-PsExecCmd*",".{0,1000}Invoke\-PsExecCmd.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49380" +"*invoke-psexecpayload*",".{0,1000}invoke\-psexecpayload.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","49381" +"*Invoke-PsGcat*",".{0,1000}Invoke\-PsGcat.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49382" +"*Invoke-PSGcat.ps1*",".{0,1000}Invoke\-PSGcat\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49383" +"*Invoke-PsGcat.ps1*",".{0,1000}Invoke\-PsGcat\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49384" +"*Invoke-PsGcatAgent*",".{0,1000}Invoke\-PsGcatAgent.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49385" +"*Invoke-PsGcatAgent.ps1*",".{0,1000}Invoke\-PsGcatAgent\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49386" +"*Invoke-PSImage*",".{0,1000}Invoke\-PSImage.{0,1000}","offensive_tool_keyword","Invoke-PSImage","Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to executenInvoke-PSImage takes a PowerShell script and encodes the bytes of the script into the pixels of a PNG image. It generates a oneliner for executing either from a file of from the web.","T1027.003 - T1027..009 - T1218 - T1216 - T1059","TA0005","N/A","Sandworm Team","Defense Evasion","https://github.com/peewpw/Invoke-PSImage","1","1","N/A","N/A","7","10","2176","399","2019-09-23T15:17:03Z","2017-12-17T18:41:44Z","49387" +"*Invoke-PSInject*",".{0,1000}Invoke\-PSInject.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-PSInject.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49388" +"*Invoke-PSInject*",".{0,1000}Invoke\-PSInject.{0,1000}","offensive_tool_keyword","Powerpick","allowing the execution of Powershell functionality without the use of Powershell.exe","T1059.001 - T1059.003 - T1086 - T1027.001","TA0005 - TA0002","N/A","Black Basta - Dispossessor","Defense Evasion","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","49389" +"*Invoke-PSInject.ps1*",".{0,1000}Invoke\-PSInject\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1085","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49390" +"*Invoke-PSInject.ps1*",".{0,1000}Invoke\-PSInject\.ps1.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","49391" +"*Invoke-PSObfuscation*",".{0,1000}Invoke\-PSObfuscation.{0,1000}","offensive_tool_keyword","Invoke-Stealth","Simple & Powerful PowerShell Script Obfuscator","T1027.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/JoelGMSec/Invoke-Stealth","1","1","N/A","N/A","9","6","559","81","2023-04-21T12:49:37Z","2021-04-13T10:22:05Z","49393" +"*Invoke-PSRemoting*",".{0,1000}Invoke\-PSRemoting.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49394" +"*Invoke-PsUACme*",".{0,1000}Invoke\-PsUACme.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","49396" +"*Invoke-PsUACme*",".{0,1000}Invoke\-PsUACme.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49397" +"*Invoke-PsUACme*",".{0,1000}Invoke\-PsUACme.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","49398" +"*Invoke-PsUACme.ps1*",".{0,1000}Invoke\-PsUACme\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49399" +"*Invoke-PsUACme.ps1*",".{0,1000}Invoke\-PsUACme\.ps1.{0,1000}","offensive_tool_keyword","PSAttack","PSAttack contains over 100 commands for Privilege Escalation - Recon and Data Exfilitration","T1059 - T1212 - T1012 - T1087 - T1005 - T1041 - T1020","TA0002 - TA0004 - TA0005 - TA0007 - TA0010 - TA0008","N/A","N/A","Exploitation tool","https://github.com/GDSSecurity/PSAttack","1","1","N/A","N/A","10","1","45","15","2017-04-04T20:37:33Z","2016-02-22T23:45:22Z","49400" +"*Invoke-PuttyCreds*",".{0,1000}Invoke\-PuttyCreds.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","49401" +"*Invoke-Pwds.ps1*",".{0,1000}Invoke\-Pwds\.ps1.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","49402" +"*Invoke-RBDC*",".{0,1000}Invoke\-RBDC.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49403" +"*Invoke-RBDC-over-DAVRPC*",".{0,1000}Invoke\-RBDC\-over\-DAVRPC.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49404" +"*Invoke-RDPThief.ps1*",".{0,1000}Invoke\-RDPThief\.ps1.{0,1000}","offensive_tool_keyword","Invoke-RDPThief","perform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentials","T1055 - T1056 - T1071 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/The-Viper-One/Invoke-RDPThief","1","1","N/A","N/A","10","1","62","8","2025-01-21T20:12:33Z","2024-10-01T20:12:00Z","49407" +"*Invoke-RDPwrap.ps1*",".{0,1000}Invoke\-RDPwrap\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49408" +"*Invoke-ReadC2Output*",".{0,1000}Invoke\-ReadC2Output.{0,1000}","offensive_tool_keyword","IPPrintC2","PoC for using MS Windows printers for persistence / command and control via Internet Printing","T1090 - T1133 - T1547.012 - T1572","TA0011 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/Diverto/IPPrintC2","1","1","N/A","N/A","10","10","146","20","2024-05-03T11:13:38Z","2024-05-03T09:13:10Z","49409" +"*invoke-reflectivedllinjection-ps1*",".{0,1000}invoke\-reflectivedllinjection\-ps1.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","49411" +"*Invoke-ReflectivePEInjection*",".{0,1000}Invoke\-ReflectivePEInjection.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","49413" +"*Invoke-ReflectivePEInjection*",".{0,1000}Invoke\-ReflectivePEInjection.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-ReflectivePEInjection.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49414" +"*Invoke-ReflectivePEInjection*",".{0,1000}Invoke\-ReflectivePEInjection.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","49417" +"*Invoke-ReflectivePEInjection*",".{0,1000}Invoke\-ReflectivePEInjection.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","49418" +"*Invoke-ReflectivePEInjection.*",".{0,1000}Invoke\-ReflectivePEInjection\..{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","49419" +"*Invoke-ReflectivePEInjection.ps1*",".{0,1000}Invoke\-ReflectivePEInjection\.ps1.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","49420" +"*Invoke-ReflectivePEInjection.ps1*",".{0,1000}Invoke\-ReflectivePEInjection\.ps1.{0,1000}","offensive_tool_keyword","merlin-agent-dll","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent-dll","1","1","N/A","N/A","10","10","51","15","2025-04-17T14:01:36Z","2021-04-17T16:58:24Z","49421" +"*Invoke-Reg1c1de*",".{0,1000}Invoke\-Reg1c1de.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49442" +"*Invoke-RegistryAlwaysInstallElevatedCheck*",".{0,1000}Invoke\-RegistryAlwaysInstallElevatedCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49443" +"*Invoke-RegistryAlwaysInstallElevatedCheck*",".{0,1000}Invoke\-RegistryAlwaysInstallElevatedCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49444" +"*Invoke-RegistryAlwaysInstallElevatedCheck*",".{0,1000}Invoke\-RegistryAlwaysInstallElevatedCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49445" +"*Invoke-RemoteMimikatz*",".{0,1000}Invoke\-RemoteMimikatz.{0,1000}","offensive_tool_keyword","mimikatz","PowerShell Scripts focused on Post-Exploitation Capabilities","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/xorrior/RandomPS-Scripts","1","1","N/A","N/A","10","4","318","86","2017-12-29T17:16:42Z","2015-02-25T04:52:01Z","49446" +"*Invoke-ResolverBackdoor*",".{0,1000}Invoke\-ResolverBackdoor.{0,1000}","offensive_tool_keyword","PowerBreach","PowerBreach is a backdoor toolkit that aims to provide the user a wide variety of methods to backdoor a system","T1055 - T1203 - T1105 - T1202 - T1027 - T1059 - T1070","TA0005 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","49448" +"*Invoke-ReverseDNSLookup*",".{0,1000}Invoke\-ReverseDNSLookup.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49451" +"*Invoke-ReverseDNSLookup.ps1*",".{0,1000}Invoke\-ReverseDNSLookup\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49452" +"*Invoke-ReverseProxy*",".{0,1000}Invoke\-ReverseProxy.{0,1000}","offensive_tool_keyword","PowerProxy","PowerShell SOCKS proxy with reverse proxy capabilities","T1090.003 - T1059.001 - T1105","TA0011 - TA0005 - TA0008","N/A","Dispossessor","C2","https://github.com/get-get-get-get/PowerProxy","1","1","N/A","N/A","10","10","80","10","2021-04-23T16:51:28Z","2020-01-03T18:18:58Z","49453" +"*Invoke-ReverseSocksProxy*",".{0,1000}Invoke\-ReverseSocksProxy.{0,1000}","offensive_tool_keyword","badrats","control tool (C2) using Python server - Jscript - Powershell and C# implants and communicates via HTTP(S) and SMB","T1059 - T1027 - T1573 - T1071 - T1105","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://gitlab.com/KevinJClark/badrats","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","49454" +"*Invoke-ReverseSocksProxy*",".{0,1000}Invoke\-ReverseSocksProxy.{0,1000}","offensive_tool_keyword","Invoke-SocksProxy","also known as PortStarter is a socks proxy and reverse socks server using powershell","T1090 - T1059.001 - T1102.003","TA0011 - TA0010 - TA0005 - TA0003","PortStarter","Vice Society - Conti","C2","https://github.com/p3nt4/Invoke-SocksProxy","1","1","N/A","N/A","10","10","788","169","2021-03-21T21:00:40Z","2017-11-09T06:20:40Z","49455" +"*Invoke-ReverseSocksProxy*",".{0,1000}Invoke\-ReverseSocksProxy.{0,1000}","offensive_tool_keyword","PowerProxy","PowerShell SOCKS proxy with reverse proxy capabilities","T1090.003 - T1059.001 - T1105","TA0011 - TA0005 - TA0008","N/A","Dispossessor","C2","https://github.com/get-get-get-get/PowerProxy","1","1","N/A","N/A","10","10","80","10","2021-04-23T16:51:28Z","2020-01-03T18:18:58Z","49456" +"*invokereverttoself*",".{0,1000}invokereverttoself.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","49457" +"*Invoke-RevertToSelf*",".{0,1000}Invoke\-RevertToSelf.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","49458" +"*Invoke-RevertToSelf*",".{0,1000}Invoke\-RevertToSelf.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","49459" +"*Invoke-RevShellServer.ps1*",".{0,1000}Invoke\-RevShellServer\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49461" +"*Invoke-RickASCII*",".{0,1000}Invoke\-RickASCII.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49462" +"*Invoke-RIDHijacking*",".{0,1000}Invoke\-RIDHijacking.{0,1000}","offensive_tool_keyword","RID-Hijacking","Windows RID Hijacking persistence technique","T1174","TA0003","N/A","N/A","Persistence","https://github.com/r4wd3r/RID-Hijacking","1","1","N/A","N/A","9","2","174","43","2024-11-20T01:43:01Z","2018-07-14T18:48:51Z","49463" +"*Invoke-RIDHijacking.ps1*",".{0,1000}Invoke\-RIDHijacking\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49464" +"*invoke-ridhijacking.py*",".{0,1000}invoke\-ridhijacking\.py.{0,1000}","offensive_tool_keyword","RID-Hijacking","Windows RID Hijacking persistence technique","T1174","TA0003","N/A","N/A","Persistence","https://github.com/r4wd3r/RID-Hijacking","1","1","N/A","N/A","9","2","174","43","2024-11-20T01:43:01Z","2018-07-14T18:48:51Z","49465" +"*Invoke-Rubeus*",".{0,1000}Invoke\-Rubeus.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49469" +"*Invoke-Rubeus*",".{0,1000}Invoke\-Rubeus.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49471" +"*Invoke-RunAs.ps1*",".{0,1000}Invoke\-RunAs\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49472" +"*Invoke-RunasCs*",".{0,1000}Invoke\-RunasCs.{0,1000}","offensive_tool_keyword","RunasCs","RunasCs - Csharp and open version of windows builtin runas.exe","T1059.003 - T1059.001 - T1035","TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/RunasCs","1","1","N/A","N/A","7","10","1159","141","2024-07-12T23:31:35Z","2019-08-08T20:18:18Z","49475" +"*Invoke-RunasCs.ps1*",".{0,1000}Invoke\-RunasCs\.ps1.{0,1000}","offensive_tool_keyword","RunasCs","RunasCs - Csharp and open version of windows builtin runas.exe","T1059.003 - T1059.001 - T1035","TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/RunasCs","1","1","N/A","N/A","7","10","1159","141","2024-07-12T23:31:35Z","2019-08-08T20:18:18Z","49477" +"*invoke-runaspayload*",".{0,1000}invoke\-runaspayload.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","49478" +"*Invoke-RunAsSystem.ps1*",".{0,1000}Invoke\-RunAsSystem\.ps1.{0,1000}","offensive_tool_keyword","Invoke-RunAsSystem","A simple script to elevate current session to SYSTEM (needs to be run as Administrator)","T1548.002 - T1059.001","TA0004 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/Leo4j/Invoke-RunAsSystem","1","1","N/A","N/A","8","1","14","1","2024-11-11T17:18:20Z","2023-08-24T15:12:40Z","49479" +"*Invoke-RunAsWithCert*",".{0,1000}Invoke\-RunAsWithCert.{0,1000}","offensive_tool_keyword","Invoke-RunAsWithCert","A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine","T1550.003 - T1078 - T1027","TA0006 - TA0005","N/A","N/A","Lateral Movement","https://github.com/synacktiv/Invoke-RunAsWithCert","1","1","N/A","N/A","8","2","150","14","2024-05-13T08:26:56Z","2024-05-03T12:44:21Z","49480" +"*Invoke-RunningProcessCheck*",".{0,1000}Invoke\-RunningProcessCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49481" +"*Invoke-S3ssionGoph3r*",".{0,1000}Invoke\-S3ssionGoph3r.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49482" +"*Invoke-s4u2self*",".{0,1000}Invoke\-s4u2self.{0,1000}","offensive_tool_keyword","Invoke-s4u2self","A tool that abuses s4u2self to gain access to remote hosts","T1550.002 - T1557.001","TA0008 - TA0009","N/A","N/A","Lateral Movement","https://github.com/Leo4j/Invoke-s4u2self","1","1","N/A","N/A","9","1","5","2","2025-02-13T16:27:51Z","2023-09-14T13:31:05Z","49483" +"*Invoke-S4U-persistence.ps1*",".{0,1000}Invoke\-S4U\-persistence\.ps1.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","49484" +"*Invoke-SafetyKatz*",".{0,1000}Invoke\-SafetyKatz.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49485" +"*Invoke-SamBackupFilesCheck*",".{0,1000}Invoke\-SamBackupFilesCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49486" +"*Invoke-SAMDump*",".{0,1000}Invoke\-SAMDump.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","49488" +"*Invoke-SAMDump*",".{0,1000}Invoke\-SAMDump.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","49489" +"*Invoke-SauronEye*",".{0,1000}Invoke\-SauronEye.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49490" +"*Invoke-SauronEye.ps1*",".{0,1000}Invoke\-SauronEye\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49491" +"*Invoke-SccmCacheFolderCheck*",".{0,1000}Invoke\-SccmCacheFolderCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49492" +"*Invoke-SccmCacheFolderVulnCheck*",".{0,1000}Invoke\-SccmCacheFolderVulnCheck.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49493" +"*Invoke-ScheduledTasksCheck*",".{0,1000}Invoke\-ScheduledTasksCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49494" +"*Invoke-ScheduledTasksImagePermissionsCheck*",".{0,1000}Invoke\-ScheduledTasksImagePermissionsCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49495" +"*Invoke-ScheduledTasksUnquotedPathCheck*",".{0,1000}Invoke\-ScheduledTasksUnquotedPathCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49496" +"*Invoke-Schtasks*",".{0,1000}Invoke\-Schtasks.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49497" +"*Invoke-SCMPermissionsCheck*",".{0,1000}Invoke\-SCMPermissionsCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49498" +"*Invoke-SCOMDecrypt*",".{0,1000}Invoke\-SCOMDecrypt.{0,1000}","offensive_tool_keyword","SCOMDecrypt","SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers","T1552.001 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/nccgroup/SCOMDecrypt","1","1","N/A","N/A","10","2","123","22","2023-11-10T07:04:26Z","2017-02-21T16:15:11Z","49499" +"*Invoke-SCShell*",".{0,1000}Invoke\-SCShell.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49501" +"*Invoke-SDCLTBypass*",".{0,1000}Invoke\-SDCLTBypass.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1130","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49502" +"*Invoke-SDCLTBypass.ps1*",".{0,1000}Invoke\-SDCLTBypass\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49503" +"*Invoke-SDPropagator*",".{0,1000}Invoke\-SDPropagator.{0,1000}","offensive_tool_keyword","powershell","propagation of ACL changes on the 'AdminSDHolder' container. which can be used to maintain unauthorized access or escalate privileges in the targeted environment. The 'AdminSDHolder' container plays a crucial role in managing the security of protected groups in Active Directory. and forcing ACL changes to propagate may lead to unintended security consequences.","T1222","TA0003","N/A","N/A","Persistence","https://github.com/theyoge/AD-Pentesting-Tools/blob/main/Invoke-SDPropagator.ps1","1","1","N/A","N/A","N/A","2","128","26","2020-12-29T07:57:54Z","2020-10-14T05:01:51Z","49504" +"*Invoke-SearchGAL*",".{0,1000}Invoke\-SearchGAL.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49505" +"*Invoke-Seatbelt*",".{0,1000}Invoke\-Seatbelt.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49510" +"*Invoke-Seatbelt*",".{0,1000}Invoke\-Seatbelt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49511" +"*Invoke-SecretDecrypt*",".{0,1000}Invoke\-SecretDecrypt.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","1","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","49512" +"*Invoke-SecretStealer*",".{0,1000}Invoke\-SecretStealer.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","1","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","49514" +"*Invoke-SendReverseShell*",".{0,1000}Invoke\-SendReverseShell.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","49518" +"*Invoke-SendToPasteBin*",".{0,1000}Invoke\-SendToPasteBin.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","49519" +"*Invoke-SensitiveHiveFileAccessCheck*",".{0,1000}Invoke\-SensitiveHiveFileAccessCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49520" +"*Invoke-SensitiveHiveShadowCopyCheck*",".{0,1000}Invoke\-SensitiveHiveShadowCopyCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49521" +"*Invoke-ServiceAbuse*",".{0,1000}Invoke\-ServiceAbuse.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Exploit vulnerable service permissions (does not require touching disk)","T1550 - T1555 - T1212 - T1558","N/A","N/A","Black Basta","Exploitation tool","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","49522" +"*Invoke-ServiceAbuse*",".{0,1000}Invoke\-ServiceAbuse.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerUp.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49523" +"*Invoke-ServiceCMD*",".{0,1000}Invoke\-ServiceCMD.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49527" +"*Invoke-ServiceDisable*",".{0,1000}Invoke\-ServiceDisable.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49528" +"*Invoke-Service-persistence.ps1*",".{0,1000}Invoke\-Service\-persistence\.ps1.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","49529" +"*Invoke-ServicesImagePermissionsCheck*",".{0,1000}Invoke\-ServicesImagePermissionsCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49530" +"*Invoke-ServicesImagePermissionsCheck*",".{0,1000}Invoke\-ServicesImagePermissionsCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49531" +"*Invoke-ServicesPermissionsCheck*",".{0,1000}Invoke\-ServicesPermissionsCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49532" +"*Invoke-ServicesPermissionsCheck*",".{0,1000}Invoke\-ServicesPermissionsCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49533" +"*Invoke-ServicesPermissionsRegistryCheck*",".{0,1000}Invoke\-ServicesPermissionsRegistryCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49534" +"*Invoke-ServicesPermissionsRegistryCheck*",".{0,1000}Invoke\-ServicesPermissionsRegistryCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49535" +"*Invoke-ServiceStart*",".{0,1000}Invoke\-ServiceStart.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49536" +"*Invoke-ServiceStop*",".{0,1000}Invoke\-ServiceStop.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49537" +"*Invoke-ServicesUnquotedPathCheck*",".{0,1000}Invoke\-ServicesUnquotedPathCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49538" +"*Invoke-ServicesUnquotedPathCheck*",".{0,1000}Invoke\-ServicesUnquotedPathCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49539" +"*Invoke-ServiceUserAdd*",".{0,1000}Invoke\-ServiceUserAdd.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49540" +"*Invoke-SessionExec.ps1*",".{0,1000}Invoke\-SessionExec\.ps1.{0,1000}","offensive_tool_keyword","SessionExec","Execute commands in other Sessions","T1053 - T1569","TA0008","N/A","N/A","Lateral Movement","https://github.com/Leo4j/SessionExec","1","1","N/A","N/A","10","1","86","14","2024-07-29T12:24:28Z","2024-07-21T15:32:07Z","49542" +"*Invoke-SessionGopher*",".{0,1000}Invoke\-SessionGopher.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49543" +"*Invoke-SessionGopher*",".{0,1000}Invoke\-SessionGopher.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49544" +"*Invoke-SessionGopher*",".{0,1000}Invoke\-SessionGopher.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49545" +"*Invoke-SessionGopher*",".{0,1000}Invoke\-SessionGopher.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49546" +"*Invoke-SessionGopher*",".{0,1000}Invoke\-SessionGopher.{0,1000}","offensive_tool_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","1","N/A","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","49547" +"*Invoke-SessionGopher.ps1*",".{0,1000}Invoke\-SessionGopher\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49548" +"*Invoke-SessionHunter*",".{0,1000}Invoke\-SessionHunter.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","49550" +"*Invoke-SessionHunter.ps1*",".{0,1000}Invoke\-SessionHunter\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","49551" +"*Invoke-SessionHunter.ps1*",".{0,1000}Invoke\-SessionHunter\.ps1.{0,1000}","offensive_tool_keyword","Invoke-SessionHunter","Retrieve and display information about active user sessions on remote computers. No admin privileges required","T1033 - T1078 - T1110","TA0007","N/A","N/A","Discovery","https://github.com/Leo4j/Invoke-SessionHunter","1","1","N/A","N/A","7","2","183","20","2024-08-12T13:15:10Z","2023-08-13T13:22:05Z","49552" +"*Invoke-ShadowSpray*",".{0,1000}Invoke\-ShadowSpray.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49553" +"*invokesharefinder*",".{0,1000}invokesharefinder.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","49556" +"*Invoke-ShareFinder*",".{0,1000}Invoke\-ShareFinder.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","49557" +"*Invoke-ShareFinder*",".{0,1000}Invoke\-ShareFinder.{0,1000}","offensive_tool_keyword","conti","Conti is a Ransomware-as-a-Service (RaaS) that was first observed in December 2019. Conti has been deployed via TrickBot and used against major corporations and government agencies particularly those in North America. As with other ransomware families - actors using Conti steal sensitive files and information from compromised networks and threaten to publish this data unless the ransom is paid","T1059.003 - T1486 - T1140 - T1083 - T1490 - T1106 - T1135 - T1027 - T1057 - T1055.001 - T1021.002 - T1018 - T1489 - T1016 - T1049 - T1080","TA0002 - TA0003 - TA0004 - TA0007 - TA0009 - TA0040","Conti Ransomware","Wizard Spider - Black Basta","Ransomware","https://www.securonix.com/blog/on-conti-ransomware-tradecraft-detection/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","49558" +"*Invoke-ShareFinder*",".{0,1000}Invoke\-ShareFinder.{0,1000}","offensive_tool_keyword","Jira-Lens","finds (non-standard) shares on hosts in the local domain","T1083 - T1065 - T1204 - T1087 - T1203","TA0007 - TA0005 - TA0001","N/A","N/A","Reconnaissance","https://powersploit.readthedocs.io/en/stable/Recon/README/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","49559" +"*Invoke-ShareHunter.ps1*",".{0,1000}Invoke\-ShareHunter\.ps1.{0,1000}","offensive_tool_keyword","Invoke-ShareHunter","Enumerate the Domain for Readable and Writable Shares","T1135","TA0007","N/A","N/A","Discovery","https://github.com/Leo4j/Invoke-ShareHunter","1","1","N/A","N/A","5","1","17","1","2025-02-18T14:56:51Z","2023-09-21T14:31:17Z","49564" +"*Invoke-SharpAllowedToAct*",".{0,1000}Invoke\-SharpAllowedToAct.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49565" +"*Invoke-SharpBlock*",".{0,1000}Invoke\-SharpBlock.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49566" +"*Invoke-SharpBypassUAC*",".{0,1000}Invoke\-SharpBypassUAC.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49567" +"*Invoke-SharpChiselClient*",".{0,1000}Invoke\-SharpChiselClient.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49568" +"*Invoke-SharpChiselClient.ps1*",".{0,1000}Invoke\-SharpChiselClient\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49569" +"*Invoke-SharpChromium*",".{0,1000}Invoke\-SharpChromium.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49570" +"*Invoke-SharpClipboard*",".{0,1000}Invoke\-SharpClipboard.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49571" +"*Invoke-SharpCloud*",".{0,1000}Invoke\-SharpCloud.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49572" +"*Invoke-SharpCloud*",".{0,1000}Invoke\-SharpCloud.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49573" +"*Invoke-Sharpcradle*",".{0,1000}Invoke\-Sharpcradle.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49574" +"*Invoke-SharpDPAPI*",".{0,1000}Invoke\-SharpDPAPI.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49575" +"*Invoke-SharpDump*",".{0,1000}Invoke\-SharpDump.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49576" +"*Invoke-SharPersist*",".{0,1000}Invoke\-SharPersist.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49577" +"*Invoke-SharpGPO*",".{0,1000}Invoke\-SharpGPO.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49578" +"*Invoke-SharpGPOAbuse*",".{0,1000}Invoke\-SharpGPOAbuse.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49579" +"*Invoke-SharpGPO-RemoteAccessPolicies*",".{0,1000}Invoke\-SharpGPO\-RemoteAccessPolicies.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49580" +"*Invoke-SharpHandler*",".{0,1000}Invoke\-SharpHandler.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49581" +"*Invoke-SharpHide*",".{0,1000}Invoke\-SharpHide.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49582" +"*InvokeSharpHound*",".{0,1000}InvokeSharpHound.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","49584" +"*Invoke-Sharphound*",".{0,1000}Invoke\-Sharphound.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49585" +"*Invoke-Sharphound2*",".{0,1000}Invoke\-Sharphound2.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49586" +"*Invoke-Sharphound3*",".{0,1000}Invoke\-Sharphound3.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49587" +"*Invoke-SharpHound4*",".{0,1000}Invoke\-SharpHound4.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49588" +"*Invoke-Sharphound4*",".{0,1000}Invoke\-Sharphound4.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49589" +"*Invoke-SharpImpersonation*",".{0,1000}Invoke\-SharpImpersonation.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49590" +"*Invoke-SharpImpersonation*",".{0,1000}Invoke\-SharpImpersonation.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49591" +"*Invoke-SharpImpersonationNoSpace*",".{0,1000}Invoke\-SharpImpersonationNoSpace.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49592" +"*Invoke-SharpKatz*",".{0,1000}Invoke\-SharpKatz.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49593" +"*Invoke-SharpLdapRelayScan*",".{0,1000}Invoke\-SharpLdapRelayScan.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49594" +"*Invoke-SharpLdapRelayScan*",".{0,1000}Invoke\-SharpLdapRelayScan.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49595" +"*Invoke-Sharplocker*",".{0,1000}Invoke\-Sharplocker.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49596" +"*Invoke-SharpLoginPrompt*",".{0,1000}Invoke\-SharpLoginPrompt.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49597" +"*Invoke-SharpLoginPrompt.ps1*",".{0,1000}Invoke\-SharpLoginPrompt\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49598" +"*Invoke-SharpMove*",".{0,1000}Invoke\-SharpMove.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49599" +"*Invoke-SharpPrinter*",".{0,1000}Invoke\-SharpPrinter.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49600" +"*Invoke-SharpPrinter*",".{0,1000}Invoke\-SharpPrinter.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49601" +"*Invoke-SharpPrintNightmare*",".{0,1000}Invoke\-SharpPrintNightmare.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49602" +"*Invoke-SharpRDP*",".{0,1000}Invoke\-SharpRDP.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49603" +"*Invoke-SharpRDP.ps1*",".{0,1000}Invoke\-SharpRDP\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49605" +"*Invoke-SharpSCCM*",".{0,1000}Invoke\-SharpSCCM.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49607" +"*Invoke-SharpSCCM*",".{0,1000}Invoke\-SharpSCCM.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49608" +"*Invoke-SharpSecDump*",".{0,1000}Invoke\-SharpSecDump.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49610" +"*Invoke-SharpSecDump.ps1*",".{0,1000}Invoke\-SharpSecDump\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49611" +"*Invoke-Sharpshares*",".{0,1000}Invoke\-Sharpshares.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49612" +"*Invoke-SharpSniper*",".{0,1000}Invoke\-SharpSniper.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49613" +"*Invoke-SharpSploit*",".{0,1000}Invoke\-SharpSploit.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49614" +"*Invoke-Sharpsploit_nomimi*",".{0,1000}Invoke\-Sharpsploit_nomimi.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49615" +"*Invoke-SharpSSDP*",".{0,1000}Invoke\-SharpSSDP.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49616" +"*Invoke-SharpStay*",".{0,1000}Invoke\-SharpStay.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49617" +"*Invoke-SharpUp*",".{0,1000}Invoke\-SharpUp.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49618" +"*Invoke-SharpUp*",".{0,1000}Invoke\-SharpUp.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49619" +"*Invoke-Sharpview*",".{0,1000}Invoke\-Sharpview.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49620" +"*Invoke-SharpWatson*",".{0,1000}Invoke\-SharpWatson.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49621" +"*Invoke-Sharpweb*",".{0,1000}Invoke\-Sharpweb.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49622" +"*Invoke-Sharpweb*",".{0,1000}Invoke\-Sharpweb.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49623" +"*Invoke-SharpWeb.ps1*",".{0,1000}Invoke\-SharpWeb\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49624" +"*Invoke-SharpWSUS*",".{0,1000}Invoke\-SharpWSUS.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49625" +"*Invoke-Shellcode*",".{0,1000}Invoke\-Shellcode.{0,1000}","offensive_tool_keyword","sRDI","Shellcode Reflective DLL Injection - Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode","T1620 - T1055.001 - T1059.004 - T1027 - T1105","TA0005 - TA0004 - TA0002","N/A","N/A","Resource Development","https://github.com/monoxgas/sRDI","1","1","N/A","N/A","N/A","10","2262","473","2023-11-15T10:53:00Z","2017-07-28T19:30:53Z","49632" +"*Invoke-Shellcode*",".{0,1000}Invoke\-Shellcode.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","49633" +"*Invoke-Shellcode.ps1*",".{0,1000}Invoke\-Shellcode\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1139","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49634" +"*Invoke-Shellcode.ps1*",".{0,1000}Invoke\-Shellcode\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49635" +"*Invoke-Shellcode.ps1*",".{0,1000}Invoke\-Shellcode\.ps1.{0,1000}","offensive_tool_keyword","PowerSploit","PowerSploit is a collection of Microsoft PowerShell modules that can be used to aid penetration testers during all phases of an assessment. PowerSploit is comprised of the following modules and scripts","T1134 - T1087.001 - T1123 - T1547.001 - T1547.005 - T1059.001 - T1543.003 - T1555.004 - T1005 - T1482 - T1574.001 - T1574.007 - T1574.008 - T1574.009 - T1056.001 - T1027.005 - T1027.010 - T1003.001 - T1057 - T1055.001 - T1012 - T1620 - T1053.005 - T1113 - T1558.003 - T1552.002 - T1552.006 - T1047","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","Dispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - Turla","Framework","https://github.com/PowerShellMafia/PowerSploit","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","49636" +"*Invoke-Shellcode.ps1*",".{0,1000}Invoke\-Shellcode\.ps1.{0,1000}","offensive_tool_keyword","PSAttack","PSAttack contains over 100 commands for Privilege Escalation - Recon and Data Exfilitration","T1059 - T1212 - T1012 - T1087 - T1005 - T1041 - T1020","TA0002 - TA0004 - TA0005 - TA0007 - TA0010 - TA0008","N/A","N/A","Exploitation tool","https://github.com/GDSSecurity/PSAttack","1","1","N/A","N/A","10","1","45","15","2017-04-04T20:37:33Z","2016-02-22T23:45:22Z","49637" +"*Invoke-Shellcode.ps1*",".{0,1000}Invoke\-Shellcode\.ps1.{0,1000}","offensive_tool_keyword","Python-Rootkit","full undetectable python RAT which can bypass almost all antivirus and open a backdoor inside any windows machine which will establish a reverse https Metasploit connection to your listening machine","T1100 - T1027 - T1219 - T1560.001 - T1021.005","TA0005 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/0xIslamTaha/Python-Rootkit","1","1","N/A","N/A","10","10","606","145","2024-10-29T16:56:39Z","2016-06-09T10:49:54Z","49638" +"*Invoke--Shellcode.ps1*",".{0,1000}Invoke\-\-Shellcode\.ps1.{0,1000}","offensive_tool_keyword","NetRipper","NetRipper - Smart traffic sniffing for penetration testers","T1173 - T1557 - T1573.001 - T1056.001","TA0009 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/NytroRST/NetRipper","1","1","N/A","N/A","10","10","1368","318","2022-06-17T21:08:54Z","2015-07-14T20:31:04Z","49639" +"*Invoke-ShellcodeMSIL*",".{0,1000}Invoke\-ShellcodeMSIL.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1074","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49640" +"*Invoke-ShellcodeMSIL.ps1*",".{0,1000}Invoke\-ShellcodeMSIL\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49641" +"*Invoke-ShellCommand*",".{0,1000}Invoke\-ShellCommand.{0,1000}","offensive_tool_keyword","empire","empire function name of agent.ps1.Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1053","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49642" +"*Invoke-SigmaPotato.ps1*",".{0,1000}Invoke\-SigmaPotato\.ps1.{0,1000}","offensive_tool_keyword","SigmaPotato","SeImpersonate privilege escalation tool","T1134 - T1055 - T1543","TA0004 - TA0005 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/tylerdotrar/SigmaPotato","1","1","N/A","N/A","9","4","326","38","2024-05-16T23:46:04Z","2023-09-09T01:35:42Z","49644" +"*Invoke-SlinkyCat*",".{0,1000}Invoke\-SlinkyCat.{0,1000}","offensive_tool_keyword","SlinkyCat","This script performs a series of AD enumeration tasks","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/LaresLLC/SlinkyCat","1","1","N/A","AD Enumeration","7","1","79","8","2023-07-12T15:29:31Z","2023-07-03T23:44:18Z","49645" +"*Invoke-SMBAutoBrute*",".{0,1000}Invoke\-SMBAutoBrute.{0,1000}","offensive_tool_keyword","conti","Conti is a Ransomware-as-a-Service (RaaS) that was first observed in December 2019. Conti has been deployed via TrickBot and used against major corporations and government agencies particularly those in North America. As with other ransomware families - actors using Conti steal sensitive files and information from compromised networks and threaten to publish this data unless the ransom is paid","T1059.003 - T1486 - T1140 - T1083 - T1490 - T1106 - T1135 - T1027 - T1057 - T1055.001 - T1021.002 - T1018 - T1489 - T1016 - T1049 - T1080","TA0002 - TA0003 - TA0004 - TA0007 - TA0009 - TA0040","Conti Ransomware","Wizard Spider - Black Basta","Ransomware","https://www.securonix.com/blog/on-conti-ransomware-tradecraft-detection/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","49646" +"*Invoke-SMBAutoBrute*",".{0,1000}Invoke\-SMBAutoBrute.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-SMBAutoBrute.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49647" +"*Invoke-SMBAutoBrute*",".{0,1000}Invoke\-SMBAutoBrute.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1079","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49648" +"*Invoke-SMBAutoBrute.ps1*",".{0,1000}Invoke\-SMBAutoBrute\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49649" +"*Invoke-SMBClient*",".{0,1000}Invoke\-SMBClient.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49651" +"*Invoke-SMBClient.ps1*",".{0,1000}Invoke\-SMBClient\.ps1.{0,1000}","offensive_tool_keyword","Invoke-TheHash","Invoke-TheHash contains PowerShell functions for performing pass the hash WMI and SMB tasks. WMI and SMB connections are accessed through the .NET TCPClient. Authentication is performed by passing an NTLM hash into the NTLMv2 authentication protocol. Local administrator privilege is not required client-side.","T1028 - T1047 - T1075 - T1078","TA0003 - TA0004 - TA0006","N/A","FoxKitten","Lateral Movement","https://github.com/Kevin-Robertson/Invoke-TheHash","1","1","N/A","N/A","10","10","1569","308","2018-12-09T15:38:36Z","2017-01-03T01:05:39Z","49652" +"*Invoke-SMBEnum*",".{0,1000}Invoke\-SMBEnum.{0,1000}","offensive_tool_keyword","Invoke-TheHash","Invoke-TheHash contains PowerShell functions for performing pass the hash WMI and SMB tasks. WMI and SMB connections are accessed through the .NET TCPClient. Authentication is performed by passing an NTLM hash into the NTLMv2 authentication protocol. Local administrator privilege is not required client-side.","T1028 - T1047 - T1075 - T1078","TA0003 - TA0004 - TA0006","N/A","FoxKitten","Lateral Movement","https://github.com/Kevin-Robertson/Invoke-TheHash","1","1","N/A","N/A","10","10","1569","308","2018-12-09T15:38:36Z","2017-01-03T01:05:39Z","49653" +"*Invoke-SMBEnum*",".{0,1000}Invoke\-SMBEnum.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49654" +"*Invoke-SMBExec*",".{0,1000}Invoke\-SMBExec.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","APT20","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49656" +"*Invoke-SMBExec*",".{0,1000}Invoke\-SMBExec.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49658" +"*Invoke-SMBExec.ps1*",".{0,1000}Invoke\-SMBExec\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","APT20","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49659" +"*Invoke-SMBExec.ps1*",".{0,1000}Invoke\-SMBExec\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1093","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49660" +"*Invoke-SMBNegotiate*",".{0,1000}Invoke\-SMBNegotiate.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49664" +"*Invoke-SmbObey.*",".{0,1000}Invoke\-SmbObey\..{0,1000}","offensive_tool_keyword","smb-reverse-shell","A Reverse Shell which uses an XML file on an SMB share as a communication channel.","T1021.002 - T1027 - T1105","TA0008 - TA0010 - TA0002","N/A","N/A","C2","https://github.com/r1cksec/smb-reverse-shell","1","1","N/A","N/A","10","10","17","0","2024-02-17T12:20:01Z","2022-01-16T21:02:14Z","49666" +"*Invoke-SmbOrder.*",".{0,1000}Invoke\-SmbOrder\..{0,1000}","offensive_tool_keyword","smb-reverse-shell","A Reverse Shell which uses an XML file on an SMB share as a communication channel.","T1021.002 - T1027 - T1105","TA0008 - TA0010 - TA0002","N/A","N/A","C2","https://github.com/r1cksec/smb-reverse-shell","1","1","N/A","N/A","10","10","17","0","2024-02-17T12:20:01Z","2022-01-16T21:02:14Z","49668" +"*Invoke-SMBRemoting*",".{0,1000}Invoke\-SMBRemoting.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","49669" +"*Invoke-SMBRemoting.ps1*",".{0,1000}Invoke\-SMBRemoting\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","49670" +"*Invoke-SMBRemoting.ps1*",".{0,1000}Invoke\-SMBRemoting\.ps1.{0,1000}","offensive_tool_keyword","Invoke-SMBRemoting","Interactive Shell and Command Execution over Named-Pipes (SMB)","T1059 - T1021.002 - T1572","TA0002 - TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/Leo4j/Invoke-SMBRemoting","1","1","N/A","N/A","9","2","163","25","2024-12-05T16:30:18Z","2023-09-06T16:00:47Z","49671" +"*Invoke-SMBRemoting-main*",".{0,1000}Invoke\-SMBRemoting\-main.{0,1000}","offensive_tool_keyword","Invoke-SMBRemoting","Interactive Shell and Command Execution over Named-Pipes (SMB)","T1059 - T1021.002 - T1572","TA0002 - TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/Leo4j/Invoke-SMBRemoting","1","1","N/A","N/A","9","2","163","25","2024-12-05T16:30:18Z","2023-09-06T16:00:47Z","49672" +"*Invoke-SMBScanner*",".{0,1000}Invoke\-SMBScanner.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-SmbScanner.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49673" +"*Invoke-SmbScanner*",".{0,1000}Invoke\-SmbScanner.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-SmbScanner.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49674" +"*Invoke-SmbScanner.ps1*",".{0,1000}Invoke\-SmbScanner\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49675" +"*Invoke-Snaffler*",".{0,1000}Invoke\-Snaffler.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49676" +"*Invoke-Snaffler*",".{0,1000}Invoke\-Snaffler.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49677" +"*Invoke-SocksProxy*",".{0,1000}Invoke\-SocksProxy.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49680" +"*Invoke-SocksProxy.ps1*",".{0,1000}Invoke\-SocksProxy\.ps1.{0,1000}","offensive_tool_keyword","badrats","control tool (C2) using Python server - Jscript - Powershell and C# implants and communicates via HTTP(S) and SMB","T1059 - T1027 - T1573 - T1071 - T1105","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://gitlab.com/KevinJClark/badrats","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","49681" +"*Invoke-SocksProxy.psm1*",".{0,1000}Invoke\-SocksProxy\.psm1.{0,1000}","offensive_tool_keyword","Invoke-SocksProxy","also known as PortStarter is a socks proxy and reverse socks server using powershell","T1090 - T1059.001 - T1102.003","TA0011 - TA0010 - TA0005 - TA0003","PortStarter","Vice Society - Conti","C2","https://github.com/p3nt4/Invoke-SocksProxy","1","1","N/A","N/A","10","10","788","169","2021-03-21T21:00:40Z","2017-11-09T06:20:40Z","49682" +"*Invoke-SpawnAs*",".{0,1000}Invoke\-SpawnAs.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49683" +"*Invoke-SpoolFool*",".{0,1000}Invoke\-SpoolFool.{0,1000}","offensive_tool_keyword","SpoolFool","Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)","T1068 - T1055 - T1059.003","TA0004 - TA0005 - TA0003","","Dispossessor","Privilege Escalation","https://github.com/ly4k/SpoolFool","1","1","N/A","N/A","9","8","788","160","2022-02-09T16:54:09Z","2022-02-08T17:25:44Z","49684" +"*Invoke-Spoolsample*",".{0,1000}Invoke\-Spoolsample.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49685" +"*Invoke-SpoolSample*",".{0,1000}Invoke\-SpoolSample.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49686" +"*Invoke-SpoolSample.ps1*",".{0,1000}Invoke\-SpoolSample\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49687" +"*Invoke-SprayEmptyPassword*",".{0,1000}Invoke\-SprayEmptyPassword.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49688" +"*Invoke-SpraySinglePassword*",".{0,1000}Invoke\-SpraySinglePassword.{0,1000}","offensive_tool_keyword","Invoke-Pre2kSpray","Enumerate domain machine accounts and perform pre2k password spraying.","T1087.002 - T1110.003","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/eversinc33/Invoke-Pre2kSpray","1","1","N/A","N/A","8","1","69","11","2023-07-14T06:50:22Z","2023-07-05T10:07:38Z","49689" +"*Invoke-SQLAudit*",".{0,1000}Invoke\-SQLAudit.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Scan for MSSQL misconfigurations to escalate to System Admin","T1558.001 - T1078.002 - T1550.003","TA0008 - TA0009 - TA0003","N/A","Black Basta","Exploitation tool","https://stealthbits.com/blog/compromise-powerupsql-sql-attacks/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","49690" +"*Invoke-SQLAudit*",".{0,1000}Invoke\-SQLAudit.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49691" +"*Invoke-SQLAuditDefaultLoginPw*",".{0,1000}Invoke\-SQLAuditDefaultLoginPw.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49692" +"*Invoke-SQLAuditPrivAutoExecSp*",".{0,1000}Invoke\-SQLAuditPrivAutoExecSp.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49693" +"*Invoke-SQLAuditPrivCreateProcedure*",".{0,1000}Invoke\-SQLAuditPrivCreateProcedure.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49694" +"*Invoke-SQLAuditPrivDbChaining*",".{0,1000}Invoke\-SQLAuditPrivDbChaining.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49695" +"*Invoke-SQLAuditPrivImpersonateLogin*",".{0,1000}Invoke\-SQLAuditPrivImpersonateLogin.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49696" +"*Invoke-SQLAuditPrivServerLink*",".{0,1000}Invoke\-SQLAuditPrivServerLink.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49697" +"*Invoke-SQLAuditPrivTrustworthy*",".{0,1000}Invoke\-SQLAuditPrivTrustworthy.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49698" +"*Invoke-SQLAuditPrivXpDirtree*",".{0,1000}Invoke\-SQLAuditPrivXpDirtree.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49699" +"*Invoke-SQLAuditPrivXpFileexit*",".{0,1000}Invoke\-SQLAuditPrivXpFileexit.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49700" +"*Invoke-SQLAuditSQLiSpExecuteAs*",".{0,1000}Invoke\-SQLAuditSQLiSpExecuteAs.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49701" +"*Invoke-SQLAuditSQLiSpSigned*",".{0,1000}Invoke\-SQLAuditSQLiSpSigned.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49702" +"*Invoke-SQLAuditWeakLoginPw*",".{0,1000}Invoke\-SQLAuditWeakLoginPw.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49703" +"*Invoke-SQLC2Command*",".{0,1000}Invoke\-SQLC2Command.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49704" +"*Invoke-SQLDumpInfo*",".{0,1000}Invoke\-SQLDumpInfo.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49705" +"*Invoke-SQLDumpInfo*",".{0,1000}Invoke\-SQLDumpInfo.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49706" +"*Invoke-SQLEscalatePriv*",".{0,1000}Invoke\-SQLEscalatePriv.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49707" +"*Invoke-SQLImpersonateService*",".{0,1000}Invoke\-SQLImpersonateService.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49708" +"*Invoke-SQLImpersonateServiceCmd*",".{0,1000}Invoke\-SQLImpersonateServiceCmd.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49709" +"*Invoke-SQLOSCMD*",".{0,1000}Invoke\-SQLOSCMD.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49711" +"*Invoke-SQLOSCmd*",".{0,1000}Invoke\-SQLOSCmd.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49712" +"*Invoke-SQLOSCmd.ps1*",".{0,1000}Invoke\-SQLOSCmd\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-SQLOSCmd.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49713" +"*Invoke-SQLOSCmdAgentJob*",".{0,1000}Invoke\-SQLOSCmdAgentJob.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49715" +"*Invoke-SQLOSCmdCLR*",".{0,1000}Invoke\-SQLOSCmdCLR.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49716" +"*Invoke-SQLOSCmdCOle*",".{0,1000}Invoke\-SQLOSCmdCOle.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49717" +"*Invoke-SQLOSCmdPython*",".{0,1000}Invoke\-SQLOSCmdPython.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49718" +"*Invoke-SQLOSCmdR*",".{0,1000}Invoke\-SQLOSCmdR.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49719" +"*Invoke-SqlServer-Persist-StartupSp*",".{0,1000}Invoke\-SqlServer\-Persist\-StartupSp.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49720" +"*Invoke-SqlServer-Persist-TriggerLogon*",".{0,1000}Invoke\-SqlServer\-Persist\-TriggerLogon.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49721" +"*Invoke-SQLUncPathInjection*",".{0,1000}Invoke\-SQLUncPathInjection.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49722" +"*Invoke-SQLUncPathInjection*",".{0,1000}Invoke\-SQLUncPathInjection.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49723" +"*Invoke-SQLUncPathInjection*",".{0,1000}Invoke\-SQLUncPathInjection.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49724" +"*Invoke-SSHCommand.ps1*",".{0,1000}Invoke\-SSHCommand\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1094","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49727" +"*Invoke-SSIDExfil*",".{0,1000}Invoke\-SSIDExfil.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49728" +"*Invoke-SSIDExfil*",".{0,1000}Invoke\-SSIDExfil.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","49729" +"*Invoke-StandIn.*",".{0,1000}Invoke\-StandIn\..{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49730" +"*Invoke-Stealth.ps1*",".{0,1000}Invoke\-Stealth\.ps1.{0,1000}","offensive_tool_keyword","HTTP-Shell","MultiPlatform HTTP Reverse Shell","T1573.001 - T1104 - T1205 - T1110","TA0005 - TA0011","N/A","N/A","C2","https://github.com/JoelGMSec/HTTP-Shell","1","1","N/A","N/A","10","10","231","33","2024-09-27T10:23:14Z","2023-09-05T12:01:17Z","49732" +"*invokestealthuserhunter*",".{0,1000}invokestealthuserhunter.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","49734" +"*Invoke-StealthUserHunter*",".{0,1000}Invoke\-StealthUserHunter.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","49735" +"*Invoke-StealthUserHunter*",".{0,1000}Invoke\-StealthUserHunter.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","49737" +"*Invoke-StickyNotesExtract*",".{0,1000}Invoke\-StickyNotesExtract.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49738" +"*Invoke-SweetPotato*",".{0,1000}Invoke\-SweetPotato.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49740" +"*Invoke-SweetPotato.ps1*",".{0,1000}Invoke\-SweetPotato\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49741" +"*Invoke-SystemStartupCheck*",".{0,1000}Invoke\-SystemStartupCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49742" +"*Invoke-SystemStartupHistoryCheck*",".{0,1000}Invoke\-SystemStartupHistoryCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49743" +"*Invoke-SystemStartupHistoryCheck*",".{0,1000}Invoke\-SystemStartupHistoryCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49744" +"*Invoke-Tater.*",".{0,1000}Invoke\-Tater\..{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-Tater.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49746" +"*Invoke-Tater.ps1*",".{0,1000}Invoke\-Tater\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1119","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49747" +"*Invoke-Tater.ps1*",".{0,1000}Invoke\-Tater\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49748" +"*Invoke-TcpEndpointsCheck*",".{0,1000}Invoke\-TcpEndpointsCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49749" +"*Invoke-TheHash.ps1*",".{0,1000}Invoke\-TheHash\.ps1.{0,1000}","offensive_tool_keyword","Invoke-TheHash","Invoke-TheHash contains PowerShell functions for performing pass the hash WMI and SMB tasks. WMI and SMB connections are accessed through the .NET TCPClient. Authentication is performed by passing an NTLM hash into the NTLMv2 authentication protocol. Local administrator privilege is not required client-side.","T1028 - T1047 - T1075 - T1078","TA0003 - TA0004 - TA0006","N/A","FoxKitten","Lateral Movement","https://github.com/Kevin-Robertson/Invoke-TheHash","1","1","N/A","N/A","10","10","1569","308","2018-12-09T15:38:36Z","2017-01-03T01:05:39Z","49751" +"*Invoke-TheHash.psd1*",".{0,1000}Invoke\-TheHash\.psd1.{0,1000}","offensive_tool_keyword","Invoke-TheHash","Invoke-TheHash contains PowerShell functions for performing pass the hash WMI and SMB tasks. WMI and SMB connections are accessed through the .NET TCPClient. Authentication is performed by passing an NTLM hash into the NTLMv2 authentication protocol. Local administrator privilege is not required client-side.","T1028 - T1047 - T1075 - T1078","TA0003 - TA0004 - TA0006","N/A","FoxKitten","Lateral Movement","https://github.com/Kevin-Robertson/Invoke-TheHash","1","1","N/A","N/A","10","10","1569","308","2018-12-09T15:38:36Z","2017-01-03T01:05:39Z","49752" +"*Invoke-TheHash.psm1*",".{0,1000}Invoke\-TheHash\.psm1.{0,1000}","offensive_tool_keyword","Invoke-TheHash","Invoke-TheHash contains PowerShell functions for performing pass the hash WMI and SMB tasks. WMI and SMB connections are accessed through the .NET TCPClient. Authentication is performed by passing an NTLM hash into the NTLMv2 authentication protocol. Local administrator privilege is not required client-side.","T1028 - T1047 - T1075 - T1078","TA0003 - TA0004 - TA0006","N/A","FoxKitten","Lateral Movement","https://github.com/Kevin-Robertson/Invoke-TheHash","1","1","N/A","N/A","10","10","1569","308","2018-12-09T15:38:36Z","2017-01-03T01:05:39Z","49753" +"*Invoke-TheKatz*",".{0,1000}Invoke\-TheKatz.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49754" +"*Invoke-Thunderfox*",".{0,1000}Invoke\-Thunderfox.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49757" +"*Invoke-Thunderstruck*",".{0,1000}Invoke\-Thunderstruck.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49758" +"*Invoke-TokenDuplication.ps1*",".{0,1000}Invoke\-TokenDuplication\.ps1.{0,1000}","offensive_tool_keyword","SharpSploit","SharpSploit is a .NET post-exploitation library written in C# that aims to highlight the attack surface of .NET and make the use of offensive .NET easier for red teamers.","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/cobbr/SharpSploit","1","1","N/A","N/A","10","10","1789","312","2021-08-12T18:23:15Z","2018-09-20T14:22:37Z","49760" +"*Invoke-TokenManipulation*",".{0,1000}Invoke\-TokenManipulation.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Invoke-TokenManipulation script Tokens can be impersonated from other users with a session/running processes on the machine. Most C2 frameworks have functionality for this built-in (such as the Steal Token functionality in Cobalt Strike)","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","49762" +"*Invoke-TokenManipulation*",".{0,1000}Invoke\-TokenManipulation.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","49765" +"*Invoke-TokenManipulation.ps1*",".{0,1000}Invoke\-TokenManipulation\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1058","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49766" +"*Invoke-TokenManipulation.ps1*",".{0,1000}Invoke\-TokenManipulation\.ps1.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","49767" +"*Invoke-Tokenvator*",".{0,1000}Invoke\-Tokenvator.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49768" +"*Invoke-UacCheck*",".{0,1000}Invoke\-UacCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49769" +"*Invoke-UacCheck*",".{0,1000}Invoke\-UacCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49770" +"*Invoke-UdpEndpointsCheck*",".{0,1000}Invoke\-UdpEndpointsCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49771" +"*Invoke-UnattendFilesCheck*",".{0,1000}Invoke\-UnattendFilesCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49772" +"*Invoke-UnattendFilesCheck*",".{0,1000}Invoke\-UnattendFilesCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49773" +"*Invoke-UpdateMimikatzScript.ps1*",".{0,1000}Invoke\-UpdateMimikatzScript\.ps1.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/g4uss47/Invoke-Mimikatz","1","1","N/A","N/A","10","1","62","14","2024-04-18T14:28:21Z","2020-09-22T16:47:19Z","49774" +"*Invoke-UrbanBishop*",".{0,1000}Invoke\-UrbanBishop.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49775" +"*Invoke-UserCheck*",".{0,1000}Invoke\-UserCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49778" +"*Invoke-UserEnumerationAsOutsider*",".{0,1000}Invoke\-UserEnumerationAsOutsider.{0,1000}","offensive_tool_keyword","Graphpython","Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit","T1078.004 - T1114.002","TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010","N/A","N/A","Discovery","https://github.com/mlcsec/Graphpython","1","1","N/A","N/A","7","2","145","13","2024-12-07T21:54:00Z","2024-07-10T00:04:48Z","49779" +"*invokeuserhunter*",".{0,1000}invokeuserhunter.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","49783" +"*Invoke-UserHunter*",".{0,1000}Invoke\-UserHunter.{0,1000}","offensive_tool_keyword","cobaltstrike","PowerView menu for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/aggressor-powerview","1","1","N/A","N/A","10","10","67","18","2018-03-22T00:21:57Z","2018-03-22T00:21:13Z","49784" +"*Invoke-UserHunter*",".{0,1000}Invoke\-UserHunter.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","powerview.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49785" +"*invoke-userhunter*",".{0,1000}invoke\-userhunter.{0,1000}","offensive_tool_keyword","pywerview","A partial Python rewriting of PowerSploit PowerView","T1069.002 - T1018 - T1087.001 - T1033 - T1069.001 - T1087.002 - T1016 - T1482","TA0007 - TA0009","N/A","N/A","Reconnaissance","https://github.com/the-useless-one/pywerview","1","1","N/A","N/A","N/A","10","974","121","2025-03-17T14:04:51Z","2016-07-06T13:25:09Z","49788" +"*Invoke-UserImpersonation*",".{0,1000}Invoke\-UserImpersonation.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49792" +"*Invoke-UsernameHarvestEAS*",".{0,1000}Invoke\-UsernameHarvestEAS.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","1","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","49794" +"*Invoke-UsernameHarvestEAS*",".{0,1000}Invoke\-UsernameHarvestEAS.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49795" +"*Invoke-UsernameHarvestGmail*",".{0,1000}Invoke\-UsernameHarvestGmail.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49796" +"*Invoke-UsernameHarvestOWA*",".{0,1000}Invoke\-UsernameHarvestOWA.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49797" +"*Invoke-UserPrivilegesCheck*",".{0,1000}Invoke\-UserPrivilegesCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49798" +"*Invoke-UserPrivilegesCheck*",".{0,1000}Invoke\-UserPrivilegesCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49799" +"*Invoke-UserSessionListCheck*",".{0,1000}Invoke\-UserSessionListCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49801" +"*Invoke-UsersHomeFolderCheck*",".{0,1000}Invoke\-UsersHomeFolderCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49802" +"*Invoke-VaultCredCheck*",".{0,1000}Invoke\-VaultCredCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49803" +"*Invoke-VaultCredCheck*",".{0,1000}Invoke\-VaultCredCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49804" +"*Invoke-VaultListCheck*",".{0,1000}Invoke\-VaultListCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49805" +"*Invoke-VeeamGetCreds*",".{0,1000}Invoke\-VeeamGetCreds.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49806" +"*Invoke-VeeamGetCreds*",".{0,1000}Invoke\-VeeamGetCreds.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","1","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","49807" +"*Invoke-Vnc*",".{0,1000}Invoke\-Vnc.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-Vnc.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49808" +"*Invoke-Vnc.ps1*",".{0,1000}Invoke\-Vnc\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1087","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49809" +"*Invoke-VNCServer.ps1*",".{0,1000}Invoke\-VNCServer\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49810" +"*Invoke-VNCViewer.ps1*",".{0,1000}Invoke\-VNCViewer\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49811" +"*Invoke-VoiceTroll.ps1*",".{0,1000}Invoke\-VoiceTroll\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1073","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49812" +"*Invoke-Vulmap*",".{0,1000}Invoke\-Vulmap.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49813" +"*Invoke-VulnerableADCSTemplates*",".{0,1000}Invoke\-VulnerableADCSTemplates.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49814" +"*Invoke-Watson*",".{0,1000}Invoke\-Watson.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49815" +"*Invoke-watson*",".{0,1000}Invoke\-watson.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49816" +"*Invoke-Watson.ps1*",".{0,1000}Invoke\-Watson\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49817" +"*Invoke-WCMDump*",".{0,1000}Invoke\-WCMDump.{0,1000}","offensive_tool_keyword","Invoke-WCMDump","PowerShell script to dump Windows credentials from the Credential Manager Invoke-WCMDump enumerates Windows credentials in the Credential Manager and then extracts available information about each one. Passwords are retrieved for Generic type credentials. but can not be retrived by the same method for Domain type credentials. Credentials are only returned for the current user","T1003 - T1003.003 - T1003.001 - T1552","TA0006 - TA0006 - TA0006 - TA0006","N/A","N/A","Credential Access","https://github.com/peewpw/Invoke-WCMDump","1","1","N/A","N/A","10","8","722","134","2017-12-12T00:46:33Z","2017-12-09T21:36:59Z","49818" +"*Invoke-WCMDump*",".{0,1000}Invoke\-WCMDump.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49819" +"*Invoke-WCMDump.ps1*",".{0,1000}Invoke\-WCMDump\.ps1.{0,1000}","offensive_tool_keyword","seatbelt","Seatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many others","T1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518","TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011","N/A","Dispossessor","Persistence","https://github.com/GhostPack/Seatbelt","1","1","N/A","N/A","10","10","4047","722","2025-01-10T20:12:49Z","2018-07-24T17:38:51Z","49820" +"*Invoke-WDigest.ps1*",".{0,1000}Invoke\-WDigest\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","49821" +"*Invoke-WdigestDowngrade*",".{0,1000}Invoke\-WdigestDowngrade.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49822" +"*Invoke-WebCamAvi.ps1*",".{0,1000}Invoke\-WebCamAvi\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","49823" +"*Invoke-WebRev.ps1*",".{0,1000}Invoke\-WebRev\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49827" +"*Invoke-Whisker*",".{0,1000}Invoke\-Whisker.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49828" +"*Invoke-WindowsEnum*",".{0,1000}Invoke\-WindowsEnum.{0,1000}","offensive_tool_keyword","RandomPS-Scripts","PowerShell Scripts focused on Post-Exploitation Capabilities","T1082 - T1087 - T1057 - T1518 - T1016","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/xorrior/RandomPS-Scripts","1","1","N/A","N/A","8","4","318","86","2017-12-29T17:16:42Z","2015-02-25T04:52:01Z","49829" +"*Invoke-WindowsEnum.ps1*",".{0,1000}Invoke\-WindowsEnum\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49830" +"*Invoke-WindowsUpdateCheck*",".{0,1000}Invoke\-WindowsUpdateCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49831" +"*Invoke-WinEnum*",".{0,1000}Invoke\-WinEnum.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-WinEnum.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49832" +"*Invoke-WinEnum.ps1*",".{0,1000}Invoke\-WinEnum\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1145","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49833" +"*Invoke-WinlogonCheck*",".{0,1000}Invoke\-WinlogonCheck.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49834" +"*Invoke-WinlogonCheck*",".{0,1000}Invoke\-WinlogonCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49835" +"*Invoke-winPEAS*",".{0,1000}Invoke\-winPEAS.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49836" +"*Invoke-winPEAS*",".{0,1000}Invoke\-winPEAS.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49837" +"*Invoke-winPEAS.ps1*",".{0,1000}Invoke\-winPEAS\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49838" +"*invoke-winrmsession*",".{0,1000}invoke\-winrmsession.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","49839" +"*Invoke-WireTap*",".{0,1000}Invoke\-WireTap.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49840" +"*Invoke-WireTap.ps1*",".{0,1000}Invoke\-WireTap\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49841" +"*Invoke-WlanProfilesCheck*",".{0,1000}Invoke\-WlanProfilesCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49842" +"*Invoke-WLMDR*",".{0,1000}Invoke\-WLMDR.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49843" +"*Invoke-WmicDriveBy.*",".{0,1000}Invoke\-WmicDriveBy\..{0,1000}","offensive_tool_keyword","RandomPS-Scripts","PowerShell Scripts focused on Post-Exploitation Capabilities","T1059.001 - T1021.002 - T1566.002","TA0002 - TA0009 - TA0043","N/A","N/A","Discovery","https://github.com/xorrior/RandomPS-Scripts","1","1","N/A","N/A","8","4","318","86","2017-12-29T17:16:42Z","2015-02-25T04:52:01Z","49844" +"*Invoke-WMICommand.ps1*",".{0,1000}Invoke\-WMICommand\.ps1.{0,1000}","offensive_tool_keyword","PSAttack","PSAttack contains over 100 commands for Privilege Escalation - Recon and Data Exfilitration","T1059 - T1212 - T1012 - T1087 - T1005 - T1041 - T1020","TA0002 - TA0004 - TA0005 - TA0007 - TA0010 - TA0008","N/A","N/A","Exploitation tool","https://github.com/GDSSecurity/PSAttack","1","1","N/A","N/A","10","1","45","15","2017-04-04T20:37:33Z","2016-02-22T23:45:22Z","49847" +"*Invoke-WMIDebugger*",".{0,1000}Invoke\-WMIDebugger.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49848" +"*Invoke-WMIExec*",".{0,1000}Invoke\-WMIExec.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","49851" +"*Invoke-WMIExec*",".{0,1000}Invoke\-WMIExec.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1024 - T1071 - T1029 - T1569","TA0002 - TA0003 - TA0040","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","49852" +"*Invoke-WMIExec.ps1*",".{0,1000}Invoke\-WMIExec\.ps1.{0,1000}","offensive_tool_keyword","Invoke-TheHash","Invoke-TheHash contains PowerShell functions for performing pass the hash WMI and SMB tasks. WMI and SMB connections are accessed through the .NET TCPClient. Authentication is performed by passing an NTLM hash into the NTLMv2 authentication protocol. Local administrator privilege is not required client-side.","T1028 - T1047 - T1075 - T1078","TA0003 - TA0004 - TA0006","N/A","FoxKitten","Lateral Movement","https://github.com/Kevin-Robertson/Invoke-TheHash","1","1","N/A","N/A","10","10","1569","308","2018-12-09T15:38:36Z","2017-01-03T01:05:39Z","49853" +"*invoke-wmijspayload*",".{0,1000}invoke\-wmijspayload.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","49854" +"*Invoke-WMILM.json*",".{0,1000}Invoke\-WMILM\.json.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","49856" +"*Invoke-WMImplant*",".{0,1000}Invoke\-WMImplant.{0,1000}","offensive_tool_keyword","WMImplant","WMImplant is a PowerShell based tool that leverages WMI to both perform actions against targeted machines. but also as the C2 channel for issuing commands and receiving results. WMImplant will likely require local administrator permissions on the targeted machine.","T1021 - T1059 - T1047 - T1057 - T1049","TA0002 - TA0003 - TA0008 - TA0009 - TA0011","N/A","N/A","C2","https://github.com/FortyNorthSecurity/WMImplant","1","1","N/A","N/A","N/A","10","813","146","2024-06-25T12:02:26Z","2016-05-24T14:00:14Z","49857" +"*Invoke-WMIObfuscatedPSCommand*",".{0,1000}Invoke\-WMIObfuscatedPSCommand.{0,1000}","offensive_tool_keyword","WMImplant","WMImplant is a PowerShell based tool that leverages WMI to both perform actions against targeted machines. but also as the C2 channel for issuing commands and receiving results. WMImplant will likely require local administrator permissions on the targeted machine.","T1021 - T1059 - T1047 - T1057 - T1049","TA0002 - TA0003 - TA0008 - TA0009 - TA0011","N/A","N/A","C2","https://github.com/FortyNorthSecurity/WMImplant","1","1","N/A","N/A","N/A","10","813","146","2024-06-25T12:02:26Z","2016-05-24T14:00:14Z","49858" +"*invoke-wmipayload*",".{0,1000}invoke\-wmipayload.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","49859" +"*Invoke-WMIpersist.ps1*",".{0,1000}Invoke\-WMIpersist\.ps1.{0,1000}","offensive_tool_keyword","Invoke-WMIpersist","A powershell script to create WMI Event subscription persistence","T1546.003 - T1059.001","TA0003","N/A","N/A","Persistence","https://github.com/bspence7337/Invoke-WMIpersist","1","1","N/A","N/A","10","1","7","0","2018-05-18T16:42:52Z","2017-11-02T03:47:25Z","49861" +"*Invoke-WmiShadowCopy*",".{0,1000}Invoke\-WmiShadowCopy.{0,1000}","offensive_tool_keyword","Wmisploit","WmiSploit is a small set of PowerShell scripts that leverage the WMI service for post-exploitation use.","T1087 - T1059.001 - T1047","TA0003 - TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/secabstraction/WmiSploit","1","1","N/A","N/A","N/A","2","164","34","2015-08-28T23:56:00Z","2015-03-15T03:30:02Z","49864" +"*Invoke-WScriptBypassUAC*",".{0,1000}Invoke\-WScriptBypassUAC.{0,1000}","offensive_tool_keyword","cobaltstrike","The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/ElevateKit","1","1","N/A","N/A","10","10","912","203","2020-06-22T21:12:24Z","2016-12-08T03:51:09Z","49865" +"*Invoke-WScriptBypassUAC*",".{0,1000}Invoke\-WScriptBypassUAC.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-WScriptBypassUAC.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49866" +"*Invoke-WScriptBypassUAC.ps1*",".{0,1000}Invoke\-WScriptBypassUAC\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49867" +"*Invoke-WscriptElevate*",".{0,1000}Invoke\-WscriptElevate.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-WScriptBypassUAC.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","49868" +"*Invoke-WsusConfigCheck*",".{0,1000}Invoke\-WsusConfigCheck.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49869" +"*Invoke-ZeroLogon*",".{0,1000}Invoke\-ZeroLogon.{0,1000}","offensive_tool_keyword","Invoke-ZeroLogon","Zerologon CVE exploitation","T1210 - T1212 - T1216 - T1003.001 - T1003.002 - T1003.003 - T1003.004","TA0001 - TA0004 - TA0005 - TA0006","N/A","Dispossessor","Exploitation tool","https://github.com/BC-SECURITY/Invoke-ZeroLogon","1","1","N/A","N/A","N/A","3","216","41","2020-10-14T04:42:58Z","2020-09-17T05:01:46Z","49870" +"*Invoke-Zerologon*",".{0,1000}Invoke\-Zerologon.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49871" +"*Invoke-ZeroLogon.ps1*",".{0,1000}Invoke\-ZeroLogon\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","49872" +"*io_dirtycow.c*",".{0,1000}io_dirtycow\.c.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirtycow vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/nowsecure/dirtycow","1","1","N/A","N/A","N/A","1","93","25","2019-05-13T13:17:31Z","2016-10-22T14:00:37Z","49875" +"*io_dirtycow.so*",".{0,1000}io_dirtycow\.so.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirtycow vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/nowsecure/dirtycow","1","1","N/A","N/A","N/A","1","93","25","2019-05-13T13:17:31Z","2016-10-22T14:00:37Z","49876" +"*iodine-latest-android.zip*",".{0,1000}iodine\-latest\-android\.zip.{0,1000}","offensive_tool_keyword","iodine","iodine. iodined - tunnel IPv4 over DNS","T1573.001 - T1573.002 - T1573.003 - T1573.004","TA0011 - TA0010 - TA0002 - TA0005","N/A","EMBER BEAR","C2","https://github.com/yarrick/iodine","1","1","N/A","N/A","10","10","6413","524","2025-04-08T17:44:12Z","2012-02-04T19:51:39Z","49888" +"*iodine-latest-win32*",".{0,1000}iodine\-latest\-win32.{0,1000}","offensive_tool_keyword","iodine","iodine. iodined - tunnel IPv4 over DNS","T1573.001 - T1573.002 - T1573.003 - T1573.004","TA0011 - TA0010 - TA0002 - TA0005","N/A","EMBER BEAR","C2","https://github.com/yarrick/iodine","1","1","N/A","N/A","10","10","6413","524","2025-04-08T17:44:12Z","2012-02-04T19:51:39Z","49889" +"*iodine-latest-windows*",".{0,1000}iodine\-latest\-windows.{0,1000}","offensive_tool_keyword","iodine","iodine. iodined - tunnel IPv4 over DNS","T1573.001 - T1573.002 - T1573.003 - T1573.004","TA0011 - TA0010 - TA0002 - TA0005","N/A","EMBER BEAR","C2","https://github.com/yarrick/iodine","1","1","N/A","N/A","10","10","6413","524","2025-04-08T17:44:12Z","2012-02-04T19:51:39Z","49890" +"*iomoath/PowerShx*",".{0,1000}iomoath\/PowerShx.{0,1000}","offensive_tool_keyword","PowerShx","Run Powershell without software restrictions.","T1059.001 - T1055.001 - T1055.012","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/iomoath/PowerShx","1","1","N/A","N/A","7","3","286","47","2021-09-08T03:44:10Z","2021-09-06T18:32:45Z","49894" +"*iomoath/SharpSpray*",".{0,1000}iomoath\/SharpSpray.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","1","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","49895" +"*ionuttbara/windows-defender-remover*",".{0,1000}ionuttbara\/windows\-defender\-remover.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","49898" +"*ios7tojohn.pl*",".{0,1000}ios7tojohn\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","49899" +"*IOXIDResolver.py*",".{0,1000}IOXIDResolver\.py.{0,1000}","offensive_tool_keyword","SharpOxidResolver","search the current domain for computers and get bindings for all of them","T1018 - T1046 - T1016","TA0007","N/A","KNOTWEED","Discovery","https://github.com/S3cur3Th1sSh1t/SharpOxidResolver","1","1","N/A","N/A","9","1","50","9","2020-11-25T08:42:06Z","2020-11-25T08:23:23Z","49901" +"*IPeerToPeerService.*",".{0,1000}IPeerToPeerService\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","49911" +"*IPfuscation.sln*",".{0,1000}IPfuscation\.sln.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","49912" +"*IPfuscation.vcxproj*",".{0,1000}IPfuscation\.vcxproj.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","49913" +"*IPPrintC2.ps1*",".{0,1000}IPPrintC2\.ps1.{0,1000}","offensive_tool_keyword","IPPrintC2","PoC for using MS Windows printers for persistence / command and control via Internet Printing","T1090 - T1133 - T1547.012 - T1572","TA0011 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/Diverto/IPPrintC2","1","1","N/A","N/A","10","10","146","20","2024-05-03T11:13:38Z","2024-05-03T09:13:10Z","49914" +"*ipSlav/DirtyCLR*",".{0,1000}ipSlav\/DirtyCLR.{0,1000}","offensive_tool_keyword","DirtyCLR","An App Domain Manager Injection DLL PoC","T1055.001 - T1546.016 - T1055.013","TA0005 - TA0004","N/A","Black Basta","Privilege Escalation","https://github.com/ipSlav/DirtyCLR","1","1","N/A","N/A","7","2","170","19","2023-12-14T21:22:12Z","2023-12-11T11:29:36Z","49922" +"*irc.pico.sh*",".{0,1000}irc\.pico\.sh.{0,1000}","offensive_tool_keyword","pico","hacker labs - open source and managed web services leveraging SSH","T1021.005 - T1078 - T1105 - T1109 - T1197 - T1213","TA0005 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/picosh/pico","1","1","N/A","N/A","10","10","1129","36","2025-04-22T17:33:17Z","2022-08-24T03:14:52Z","49931" +"*IReversePortForwardService.*",".{0,1000}IReversePortForwardService\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","49932" +"*irkjanm/krbrelayx*",".{0,1000}irkjanm\/krbrelayx.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","49933" +"*irsl/curlshell*",".{0,1000}irsl\/curlshell.{0,1000}","offensive_tool_keyword","curlshell","reverse shell using curl","T1105 - T1059.004 - T1140","TA0011 - TA0002 - TA0007","N/A","N/A","C2","https://github.com/irsl/curlshell","1","1","#linux","N/A","10","10","454","73","2024-04-20T15:23:11Z","2023-07-13T19:38:34Z","49939" +"*is_kirbi_file*",".{0,1000}is_kirbi_file.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","49942" +"*is_proxy_stub_dll_loaded*",".{0,1000}is_proxy_stub_dll_loaded.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","49943" +"*iscsicpl_BypassUAC_x86.exe*",".{0,1000}iscsicpl_BypassUAC_x86\.exe.{0,1000}","offensive_tool_keyword","bypassUAC","UAC bypass for x64 Windows 7 - 11","T1088 - T1202 - T1112 - T1059 - T1548.002","TA0005 - TA0004","N/A","Dispossessor","Defense Evasion","https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC","1","1","N/A","N/A","9","9","802","156","2022-07-27T15:48:45Z","2022-07-14T02:37:50Z","49945" +"*ISecurityEditorUAC_off.exe*",".{0,1000}ISecurityEditorUAC_off\.exe.{0,1000}","offensive_tool_keyword","bypassUAC","UAC bypass for x64 Windows 7 - 11","T1088 - T1202 - T1112 - T1059 - T1548.002","TA0005 - TA0004","N/A","Dispossessor","Defense Evasion","https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC","1","1","N/A","N/A","9","9","802","156","2022-07-27T15:48:45Z","2022-07-14T02:37:50Z","49946" +"*isShellcodeThread*",".{0,1000}isShellcodeThread.{0,1000}","offensive_tool_keyword","C2 related tools","An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/mgeeky/ShellcodeFluctuation","1","1","N/A","N/A","10","10","1012","160","2022-06-17T18:07:33Z","2021-09-29T10:24:52Z","49947" +"*issue_shell_whoami*",".{0,1000}issue_shell_whoami.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","49948" +"*itaymigdal/LOLSpoof*",".{0,1000}itaymigdal\/LOLSpoof.{0,1000}","offensive_tool_keyword","LOLSpoof","An interactive shell to spoof some LOLBins command line","T1036.005","TA0005","N/A","N/A","Defense Evasion","https://github.com/itaymigdal/LOLSpoof","1","1","N/A","N/A","8","2","184","24","2024-01-27T05:43:59Z","2024-01-16T20:15:38Z","49953" +"*itaymigdal/Poshito*",".{0,1000}itaymigdal\/Poshito.{0,1000}","offensive_tool_keyword","Poshito","Poshito is a Windows C2 over Telegram","T1102 - T1071.001 - T1571 - T1027","TA0011 - TA0005","N/A","N/A","C2","https://github.com/itaymigdal/Poshito","1","1","N/A","N/A","7","10","10","1","2024-10-30T10:40:41Z","2024-09-10T20:14:17Z","49954" +"*it-gorillaz/lnk2pwn*",".{0,1000}it\-gorillaz\/lnk2pwn.{0,1000}","offensive_tool_keyword","lnk2pwn","Malicious Shortcut(.lnk) Generator","T1204 - T1059.007","TA0001 - TA0002","N/A","N/A","Phishing","https://github.com/it-gorillaz/lnk2pwn","1","1","N/A","N/A","8","2","193","34","2018-11-23T17:18:49Z","2018-11-23T00:12:48Z","49955" +"*itm4n/PPLmedic*",".{0,1000}itm4n\/PPLmedic.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","1","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","49959" +"*itm4n/PrintSpoofer*",".{0,1000}itm4n\/PrintSpoofer.{0,1000}","offensive_tool_keyword","PrintSpoofer","Abusing Impersonation Privileges on Windows 10 and Server 2019","T1548.002 - T1055.001 - T1055.002","TA0005 - TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrintSpoofer","1","1","N/A","N/A","10","10","1971","342","2020-09-10T17:49:41Z","2020-04-28T08:26:29Z","49960" +"*itm4n/PrintSpoofer*",".{0,1000}itm4n\/PrintSpoofer.{0,1000}","offensive_tool_keyword","printspoofer","Abusing impersonation privileges through the Printer Bug","T1134 - T1003 - T1055","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrintSpoofer","1","1","N/A","N/A","10","10","1971","342","2020-09-10T17:49:41Z","2020-04-28T08:26:29Z","49961" +"*itm4n/PrivescCheck*",".{0,1000}itm4n\/PrivescCheck.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","49962" +"*itm4nprivesc*",".{0,1000}itm4nprivesc.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","49963" +"*its-a-feature/Apfell*",".{0,1000}its\-a\-feature\/Apfell.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","49964" +"*its-a-feature/Mythic*",".{0,1000}its\-a\-feature\/Mythic.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","49965" +"*its-a-feature/Mythic*",".{0,1000}its\-a\-feature\/Mythic.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","49966" +"*ItsNee/Follina-CVE-2022-30190-POC*",".{0,1000}ItsNee\/Follina\-CVE\-2022\-30190\-POC.{0,1000}","offensive_tool_keyword","POC","Just another PoC for the new MSDT-Exploit","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/ItsNee/Follina-CVE-2022-30190-POC","1","1","N/A","N/A","N/A","1","5","0","2022-07-04T13:27:13Z","2022-06-05T13:54:04Z","49967" +"*itunes_backup2john.pl*",".{0,1000}itunes_backup2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","49968" +"*ItWasAllADream-master*",".{0,1000}ItWasAllADream\-master.{0,1000}","offensive_tool_keyword","ItWasAllADream","A PrintNightmare (CVE-2021-34527) Python Scanner. Scan entire subnets for hosts vulnerable to the PrintNightmare RCE","T1046 - T1210.002 - T1047","TA0007 - TA0002","N/A","N/A","Discovery","https://github.com/byt3bl33d3r/ItWasAllADream","1","1","N/A","N/A","7","8","796","123","2024-05-19T16:25:52Z","2021-07-05T20:13:49Z","49971" +"*IvanGlinkin/AutoSUID*",".{0,1000}IvanGlinkin\/AutoSUID.{0,1000}","offensive_tool_keyword","AutoSUID","automate harvesting the SUID executable files and to find a way for further escalating the privileges","T1548.003 - T1069.001 - T1068","TA0004 - TA0003 - TA0005","N/A","N/A","Discovery","https://github.com/IvanGlinkin/AutoSUID","1","1","N/A","N/A","7","4","375","77","2024-04-29T12:30:35Z","2021-11-28T19:44:18Z","49973" +"*ivan-sincek/php-reverse-shell*",".{0,1000}ivan\-sincek\/php\-reverse\-shell.{0,1000}","offensive_tool_keyword","php-reverse-shell","PHP shells that work on Linux OS - macOS and Windows OS","T1505.003 - T1059.003 - T1100","TA0003 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/ivan-sincek/php-reverse-shell","1","1","N/A","N/A","10","10","482","152","2023-10-03T09:48:21Z","2020-07-14T07:22:54Z","49974" +"*Ivy-main.zip*",".{0,1000}Ivy\-main\.zip.{0,1000}","offensive_tool_keyword","ivy","Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory","T1059 - T1204 - T1547","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/optiv/Ivy","1","1","N/A","N/A","10","8","744","129","2023-08-18T17:30:14Z","2021-11-18T18:29:20Z","49979" +"*iw6v2p3cruy7tqfup3yl4dgt4pfibfa3ai4zgnu5df2q3hus3lm7c7ad.onion*",".{0,1000}iw6v2p3cruy7tqfup3yl4dgt4pfibfa3ai4zgnu5df2q3hus3lm7c7ad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","49980" +"*iwantmore.pizza/posts/PEzor.html*",".{0,1000}iwantmore\.pizza\/posts\/PEzor\.html.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1027 - T1045 - T1055 - T1140 - T1204 - T1218","TA0005 - TA0043","N/A","N/A","Defense Evasion","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","49981" +"*iwork2john.py*",".{0,1000}iwork2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","49982" +"*j3qxmk6g5sk3zw62i2yhjnwmhm55rfz47fdyfkhaithlpelfjdokdxad.onion*",".{0,1000}j3qxmk6g5sk3zw62i2yhjnwmhm55rfz47fdyfkhaithlpelfjdokdxad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","49988" +"*JAB4ACAAPQAgAEcAZQB0AC0AUAByAG8AYwBlAHMAcwAgAC0AUABJAEQAIAAkAHAAaQBkACAAfAAgAFMAZQBsAGUAYwB0AC0ATwBiAGoAZQBjAHQAIAAtAEUAeABwAGEAbgBkAFAAcgBvAHAAZQByAHQAeQAgAG4AYQBtAGUAOwAgACIAJABwAGkAZAAgACQAeAAuAGUAeABlACIA*",".{0,1000}JAB4ACAAPQAgAEcAZQB0AC0AUAByAG8AYwBlAHMAcwAgAC0AUABJAEQAIAAkAHAAaQBkACAAfAAgAFMAZQBsAGUAYwB0AC0ATwBiAGoAZQBjAHQAIAAtAEUAeABwAGEAbgBkAFAAcgBvAHAAZQByAHQAeQAgAG4AYQBtAGUAOwAgACIAJABwAGkAZAAgACQAeAAuAGUAeABlACIA.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","49990" +"*jackdaw.py*",".{0,1000}jackdaw\.py.{0,1000}","offensive_tool_keyword","jackdaw","Jackdaw is here to collect all information in your domain. store it in a SQL database and show you nice graphs on how your domain objects interact with each-other an how a potential attacker may exploit these interactions. It also comes with a handy feature to help you in a password-cracking project by storing/looking up/reporting hashes/passowrds/users.","T1087 - T1482 - T1201 - T1213 - T1003","TA0007 - TA0008 - TA0009 - TA0006","N/A","N/A","Reconnaissance","https://github.com/skelsec/jackdaw","1","1","N/A","N/A","N/A","6","576","89","2025-03-15T13:37:50Z","2019-03-27T18:36:41Z","49995" +"*jackson5sec/ShimDB*",".{0,1000}jackson5sec\/ShimDB.{0,1000}","offensive_tool_keyword","ShimDB","Shim database persistence (Fin7 TTP)","T1546.011","TA0003","N/A","N/A","Persistence","https://github.com/jackson5sec/ShimDB","1","1","N/A","N/A","9","1","37","10","2020-02-25T09:41:53Z","2018-06-21T00:38:10Z","49997" +"*jakobfriedl/precompiled-binaries*",".{0,1000}jakobfriedl\/precompiled\-binaries.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","N/A","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","50000" +"*jakoby.lol/fbi*",".{0,1000}jakoby\.lol\/fbi.{0,1000}","offensive_tool_keyword","ShellSync","exposing a server with suspicious scripts and executable from I-Am-Jakoby","T1059.003 - T1100 - T1027","TA0005 - TA0009 - TA0011 ","N/A","N/A","Data Exfiltration","https://github.com/I-Am-Jakoby/ShellSync","1","1","N/A","N/A","5","1","20","7","2023-11-08T18:01:18Z","2023-11-06T06:05:11Z","50001" +"*janoglezcampos/rust_syscalls*",".{0,1000}janoglezcampos\/rust_syscalls.{0,1000}","offensive_tool_keyword","NovaLdr","NovaLdr is a Threadless Module Stomping written in Rust designed as a learning project while exploring the world of malware development. It uses advanced techniques like indirect syscalls and string encryption to achieve its functionalities","T1027.001 - T1055.012 - T1112 - T1574.002 - T1055 - T1056.002 - T1027.002 - T1070.004 - T1129","TA0004 - TA0005 - TA0040 - TA0011","N/A","N/A","Defense Evasion","https://github.com/BlackSnufkin/NovaLdr","1","1","N/A","N/A","10","3","242","40","2024-06-29T10:34:48Z","2023-10-19T07:54:39Z","50002" +"*jaredhaight/PSAttackBuildTool*",".{0,1000}jaredhaight\/PSAttackBuildTool.{0,1000}","offensive_tool_keyword","PSAttack","PSAttack contains over 100 commands for Privilege Escalation - Recon and Data Exfilitration","T1059 - T1212 - T1012 - T1087 - T1005 - T1041 - T1020","TA0002 - TA0004 - TA0005 - TA0007 - TA0010 - TA0008","N/A","N/A","Exploitation tool","https://github.com/GDSSecurity/PSAttack","1","1","N/A","N/A","10","1","45","15","2017-04-04T20:37:33Z","2016-02-22T23:45:22Z","50003" +"*jas502n/bypassAV*",".{0,1000}jas502n\/bypassAV.{0,1000}","offensive_tool_keyword","cobaltstrike","bypassAV cobaltstrike shellcode","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/jas502n/bypassAV-1","1","1","N/A","N/A","10","10","17","9","2021-03-04T01:51:14Z","2021-03-03T11:33:38Z","50004" +"*Jasmin Decryptor.csproj*",".{0,1000}Jasmin\sDecryptor\.csproj.{0,1000}","offensive_tool_keyword","Jasmin-Ransomware","Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks","T1486","TA0040 - TA0002 - TA0010","N/A","N/A","Ransomware","https://github.com/codesiddhant/Jasmin-Ransomware","1","1","N/A","N/A","10","3","252","80","2021-03-01T14:51:06Z","2021-02-27T07:09:08Z","50006" +"*Jasmin Decryptor.exe*",".{0,1000}Jasmin\sDecryptor\.exe.{0,1000}","offensive_tool_keyword","Jasmin-Ransomware","Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks","T1486","TA0040 - TA0002 - TA0010","N/A","N/A","Ransomware","https://github.com/codesiddhant/Jasmin-Ransomware","1","1","N/A","N/A","10","3","252","80","2021-03-01T14:51:06Z","2021-02-27T07:09:08Z","50007" +"*Jasmin Decryptor.pdb*",".{0,1000}Jasmin\sDecryptor\.pdb.{0,1000}","offensive_tool_keyword","Jasmin-Ransomware","Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks","T1486","TA0040 - TA0002 - TA0010","N/A","N/A","Ransomware","https://github.com/codesiddhant/Jasmin-Ransomware","1","1","N/A","N/A","10","3","252","80","2021-03-01T14:51:06Z","2021-02-27T07:09:08Z","50008" +"*Jasmin Decryptor.sln*",".{0,1000}Jasmin\sDecryptor\.sln.{0,1000}","offensive_tool_keyword","Jasmin-Ransomware","Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks","T1486","TA0040 - TA0002 - TA0010","N/A","N/A","Ransomware","https://github.com/codesiddhant/Jasmin-Ransomware","1","1","N/A","N/A","10","3","252","80","2021-03-01T14:51:06Z","2021-02-27T07:09:08Z","50009" +"*Jasmin Encryptor.csproj*",".{0,1000}Jasmin\sEncryptor\.csproj.{0,1000}","offensive_tool_keyword","Jasmin-Ransomware","Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks","T1486","TA0040 - TA0002 - TA0010","N/A","N/A","Ransomware","https://github.com/codesiddhant/Jasmin-Ransomware","1","1","N/A","N/A","10","3","252","80","2021-03-01T14:51:06Z","2021-02-27T07:09:08Z","50010" +"*Jasmin Encryptor.exe*",".{0,1000}Jasmin\sEncryptor\.exe.{0,1000}","offensive_tool_keyword","Jasmin-Ransomware","Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks","T1486","TA0040 - TA0002 - TA0010","N/A","N/A","Ransomware","https://github.com/codesiddhant/Jasmin-Ransomware","1","1","N/A","N/A","10","3","252","80","2021-03-01T14:51:06Z","2021-02-27T07:09:08Z","50011" +"*Jasmin Encryptor.sln*",".{0,1000}Jasmin\sEncryptor\.sln.{0,1000}","offensive_tool_keyword","Jasmin-Ransomware","Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks","T1486","TA0040 - TA0002 - TA0010","N/A","N/A","Ransomware","https://github.com/codesiddhant/Jasmin-Ransomware","1","1","N/A","N/A","10","3","252","80","2021-03-01T14:51:06Z","2021-02-27T07:09:08Z","50012" +"*Jasmin%20Decryptor.exe*",".{0,1000}Jasmin\%20Decryptor\.exe.{0,1000}","offensive_tool_keyword","Jasmin-Ransomware","Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks","T1486","TA0040 - TA0002 - TA0010","N/A","N/A","Ransomware","https://github.com/codesiddhant/Jasmin-Ransomware","1","1","N/A","N/A","10","3","252","80","2021-03-01T14:51:06Z","2021-02-27T07:09:08Z","50015" +"*Jasmin%20Decryptor.pdb*",".{0,1000}Jasmin\%20Decryptor\.pdb.{0,1000}","offensive_tool_keyword","Jasmin-Ransomware","Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks","T1486","TA0040 - TA0002 - TA0010","N/A","N/A","Ransomware","https://github.com/codesiddhant/Jasmin-Ransomware","1","1","N/A","N/A","10","3","252","80","2021-03-01T14:51:06Z","2021-02-27T07:09:08Z","50016" +"*Jasmin%20Encryptor.exe*",".{0,1000}Jasmin\%20Encryptor\.exe.{0,1000}","offensive_tool_keyword","Jasmin-Ransomware","Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks","T1486","TA0040 - TA0002 - TA0010","N/A","N/A","Ransomware","https://github.com/codesiddhant/Jasmin-Ransomware","1","1","N/A","N/A","10","3","252","80","2021-03-01T14:51:06Z","2021-02-27T07:09:08Z","50017" +"*jasonxtn/Argus*",".{0,1000}jasonxtn\/Argus.{0,1000}","offensive_tool_keyword","Argus","Information Gathering Toolkit","T1590.001 - T1590.002 - T1595.003 - T1016 - T1046 - T1590.005","TA0043 - TA0007","N/A","N/A","Reconnaissance","https://github.com/jasonxtn/Argus","1","1","N/A","N/A","4","10","1951","210","2024-10-08T19:04:27Z","2024-10-01T22:13:51Z","50022" +"*jatayu.php*",".{0,1000}jatayu\.php.{0,1000}","offensive_tool_keyword","Jatayu","Stealthy Stand Alone PHP Web Shell","T1071","TA0005","N/A","N/A","C2","https://github.com/SpiderMate/Jatayu","1","1","N/A","N/A","N/A","10","33","9","2019-09-12T17:03:13Z","2019-09-12T09:04:10Z","50023" +"*jatayu-image.png*",".{0,1000}jatayu\-image\.png.{0,1000}","offensive_tool_keyword","Jatayu","Stealthy Stand Alone PHP Web Shell","T1071","TA0005","N/A","N/A","C2","https://github.com/SpiderMate/Jatayu","1","1","N/A","N/A","N/A","10","33","9","2019-09-12T17:03:13Z","2019-09-12T09:04:10Z","50024" +"*java/jndi/LDAPRefServer.java*",".{0,1000}java\/jndi\/LDAPRefServer\.java.{0,1000}","offensive_tool_keyword","POC","JNDI-Injection-Exploit is a tool for generating workable JNDI links and provide background services by starting RMI server. LDAP server and HTTP server. Using this tool allows you get JNDI links. you can insert these links into your POC to test vulnerability.","T1190 - T1133 - T1595 - T1132 - T1046 - T1041","TA0009 - TA0003 - TA0002 - TA0007 - TA0008 - TA0001","N/A","N/A","Exploitation tool","https://github.com/welk1n/JNDI-Injection-Exploit","1","1","N/A","N/A","N/A","10","2682","733","2023-03-22T21:23:32Z","2019-10-10T01:53:49Z","50030" +"*java/jsp_shell_reverse_tcp*",".{0,1000}java\/jsp_shell_reverse_tcp.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","50031" +"*java/shell_reverse_tcp*",".{0,1000}java\/shell_reverse_tcp.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","50032" +"*java-socks-proxy-server.jar*",".{0,1000}java\-socks\-proxy\-server\.jar.{0,1000}","offensive_tool_keyword","chunk-Proxy","A backdoor installed on a web server that allows for the execution of commands and facilitates persistent access.","T1505.003 - T1059 - T1105 - T1071","TA0011 - TA0002 - TA0003","Ghost Ransomware","N/A","C2","https://github.com/BeichenDream/Chunk-Proxy","1","1","N/A","N/A","10","10","283","40","2022-05-07T04:24:50Z","2021-10-28T18:45:21Z","50035" +"*jbdg4buq6jd7ed3rd6cynqtq5abttuekjnxqrqyvk4xam5i7ld33jvqd.onion*",".{0,1000}jbdg4buq6jd7ed3rd6cynqtq5abttuekjnxqrqyvk4xam5i7ld33jvqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","50036" +"*jbeg2dct2zhku6c2vwnpxtm2psnjo2xnqvvpoiiwr5hxnc6wrp3uhnad.onion*",".{0,1000}jbeg2dct2zhku6c2vwnpxtm2psnjo2xnqvvpoiiwr5hxnc6wrp3uhnad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","50037" +"*jboss_jmx_upload_exploit*",".{0,1000}jboss_jmx_upload_exploit.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","50040" +"*jdk*-activator-rce-test.txt*",".{0,1000}jdk.{0,1000}\-activator\-rce\-test\.txt.{0,1000}","offensive_tool_keyword","remote-method-guesser","remote-method-guesser?(rmg) is a?Java RMI?vulnerability scanner and can be used to identify and verify common security vulnerabilities on?Java RMI?endpoints.","T1210.002 - T1046 - T1078.003","TA0001 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/qtc-de/remote-method-guesser","1","1","N/A","N/A","6","9","860","108","2024-07-03T19:40:54Z","2019-11-04T11:37:38Z","50042" +"*jdk*-call-rce-test.txt*",".{0,1000}jdk.{0,1000}\-call\-rce\-test\.txt.{0,1000}","offensive_tool_keyword","remote-method-guesser","remote-method-guesser?(rmg) is a?Java RMI?vulnerability scanner and can be used to identify and verify common security vulnerabilities on?Java RMI?endpoints.","T1210.002 - T1046 - T1078.003","TA0001 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/qtc-de/remote-method-guesser","1","1","N/A","N/A","6","9","860","108","2024-07-03T19:40:54Z","2019-11-04T11:37:38Z","50043" +"*jdk*-dgc-rce-test.txt*",".{0,1000}jdk.{0,1000}\-dgc\-rce\-test\.txt.{0,1000}","offensive_tool_keyword","remote-method-guesser","remote-method-guesser?(rmg) is a?Java RMI?vulnerability scanner and can be used to identify and verify common security vulnerabilities on?Java RMI?endpoints.","T1210.002 - T1046 - T1078.003","TA0001 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/qtc-de/remote-method-guesser","1","1","N/A","N/A","6","9","860","108","2024-07-03T19:40:54Z","2019-11-04T11:37:38Z","50044" +"*jdk*-method-rce-test.txt*",".{0,1000}jdk.{0,1000}\-method\-rce\-test\.txt.{0,1000}","offensive_tool_keyword","remote-method-guesser","remote-method-guesser?(rmg) is a?Java RMI?vulnerability scanner and can be used to identify and verify common security vulnerabilities on?Java RMI?endpoints.","T1210.002 - T1046 - T1078.003","TA0001 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/qtc-de/remote-method-guesser","1","1","N/A","N/A","6","9","860","108","2024-07-03T19:40:54Z","2019-11-04T11:37:38Z","50045" +"*jdk*-reg-bypass.txt*",".{0,1000}jdk.{0,1000}\-reg\-bypass\.txt.{0,1000}","offensive_tool_keyword","remote-method-guesser","remote-method-guesser?(rmg) is a?Java RMI?vulnerability scanner and can be used to identify and verify common security vulnerabilities on?Java RMI?endpoints.","T1210.002 - T1046 - T1078.003","TA0001 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/qtc-de/remote-method-guesser","1","1","N/A","N/A","6","9","860","108","2024-07-03T19:40:54Z","2019-11-04T11:37:38Z","50046" +"*jeffhacks/smbscan*",".{0,1000}jeffhacks\/smbscan.{0,1000}","offensive_tool_keyword","smbscan","SMBScan is a tool to enumerate file shares on an internal network.","T1135 - T1046 - T1021","TA0007 - TA0043 - TA0008","N/A","APT22","Discovery","https://github.com/jeffhacks/smbscan","1","1","N/A","N/A","8","1","44","6","2025-03-24T01:55:30Z","2021-10-26T02:28:34Z","50050" +"*jfjallid/go-lsass*",".{0,1000}jfjallid\/go\-lsass.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","1","N/A","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","50052" +"*jfjallid/go-secdump*",".{0,1000}jfjallid\/go\-secdump.{0,1000}","offensive_tool_keyword","go-secdump","Tool to remotely dump secrets from the Windows registry","T1003.002 - T1012 - T1059.003","TA0006 - TA0003 - TA0002","N/A","N/A","Credential Access","https://github.com/jfjallid/go-secdump","1","1","N/A","N/A","10","5","457","51","2025-02-21T19:16:11Z","2023-02-23T17:02:50Z","50053" +"*JGillam/burp-co2*",".{0,1000}JGillam\/burp\-co2.{0,1000}","offensive_tool_keyword","burpsuite","CO2 is a project for lightweight and useful enhancements to Portswigger popular Burp Suite web penetration tool through the standard Extender API","T1583 - T1595 - T1190","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/JGillam/burp-co2","1","1","N/A","network exploitation tool","N/A","2","152","34","2024-02-21T02:23:00Z","2015-04-19T03:38:34Z","50057" +"*jianingy/proxychains*",".{0,1000}jianingy\/proxychains.{0,1000}","offensive_tool_keyword","proxychains","proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4 SOCKS5 or HTTP(S) proxy","T1090.004 - T1090.003 - T1027 - T1573 - T1095","TA0005 - TA0011 - TA0010","N/A","Vice Society - Qilin - Black Basta - Dispossessor - EMBER BEAR","Defense Evasion","https://github.com/haad/proxychains","1","1","N/A","N/A","8","10","7142","647","2024-06-08T02:20:54Z","2011-02-25T12:27:05Z","50060" +"*Jira-Lens.py*",".{0,1000}Jira\-Lens\.py.{0,1000}","offensive_tool_keyword","Jira-Lens","Fast and customizable vulnerability scanner For JIRA written in Python","T1083 - T1065 - T1204 - T1087 - T1203","TA0007 - TA0005 - TA0001","N/A","N/A","Reconnaissance","https://github.com/MayankPandey01/Jira-Lens","1","1","N/A","N/A","N/A","4","318","52","2024-12-31T20:06:51Z","2021-11-14T18:37:47Z","50061" +"*jmarr73/NTLMSleuth*",".{0,1000}jmarr73\/NTLMSleuth.{0,1000}","offensive_tool_keyword","NTLMSleuth","verify NTLM hash integrity against the robust database of ntlm.pw.","T1003 - T1555","TA0006","N/A","Black Basta","Credential Access","https://github.com/jmarr73/NTLMSleuth","1","1","N/A","N/A","8","1","8","0","2024-08-28T15:21:10Z","2023-12-12T16:41:35Z","50064" +"*jmmcatee/cracklord*",".{0,1000}jmmcatee\/cracklord.{0,1000}","offensive_tool_keyword","cracklord","Queue and resource system for cracking passwords","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/jmmcatee/cracklord","1","1","N/A","N/A","10","4","388","70","2022-09-22T09:30:14Z","2013-12-09T23:10:54Z","50065" +"*JMousqueton/PoC-CVE-2022-30190*",".{0,1000}JMousqueton\/PoC\-CVE\-2022\-30190.{0,1000}","offensive_tool_keyword","POC","POC CVE-2022-30190 CVE 0-day MS Offic RCE aka msdt follina","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/JMousqueton/PoC-CVE-2022-30190","1","1","N/A","N/A","N/A","2","157","55","2022-06-05T21:06:13Z","2022-05-30T18:17:38Z","50066" +"*jndi_injection.rb*",".{0,1000}jndi_injection\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","50068" +"*JNDI-Injection-Exploit*",".{0,1000}JNDI\-Injection\-Exploit.{0,1000}","offensive_tool_keyword","POC","JNDI-Injection-Exploit is a tool for generating workable JNDI links and provide background services by starting RMI server. LDAP server and HTTP server. Using this tool allows you get JNDI links. you can insert these links into your POC to test vulnerability.","T1190 - T1133 - T1595 - T1132 - T1046 - T1041","TA0009 - TA0003 - TA0002 - TA0007 - TA0008 - TA0001","N/A","N/A","Exploitation tool","https://github.com/welk1n/JNDI-Injection-Exploit","1","1","N/A","N/A","N/A","10","2682","733","2023-03-22T21:23:32Z","2019-10-10T01:53:49Z","50069" +"*joaoviictorti/RustRedOps*",".{0,1000}joaoviictorti\/RustRedOps.{0,1000}","offensive_tool_keyword","RustRedOps","RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team","T1027.002 - T1053.005 - T1204.002 - T1588.002","TA0005 - TA0002 - TA0003 - TA0042","N/A","N/A","Exploitation tool","https://github.com/joaoviictorti/RustRedOps","1","1","N/A","N/A","10","10","1548","176","2025-04-20T18:50:04Z","2023-11-29T16:07:06Z","50070" +"*Joe1sn/S-inject*",".{0,1000}Joe1sn\/S\-inject.{0,1000}","offensive_tool_keyword","S-inject","Windows injection of x86/x64 DLL and Shellcode","T1055 - T1027","TA0002 - TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/Joe1sn/S-inject","1","1","N/A","N/A","10","4","313","45","2025-04-06T08:06:39Z","2024-02-05T04:39:10Z","50073" +"*JoelGMSec/EvilnoVNC*",".{0,1000}JoelGMSec\/EvilnoVNC.{0,1000}","offensive_tool_keyword","EvilnoVNC","EvilnoVNC is a Ready to go Phishing Platform","T1566 - T1566.001 - T1071 - T1071.001","TA0043 - TA0001","N/A","N/A","Phishing","https://github.com/JoelGMSec/EvilnoVNC","1","1","N/A","N/A","9","10","960","169","2025-03-04T15:59:27Z","2022-09-04T10:48:49Z","50075" +"*JoelGMSec/HTTP-Shell*",".{0,1000}JoelGMSec\/HTTP\-Shell.{0,1000}","offensive_tool_keyword","HTTP-Shell","MultiPlatform HTTP Reverse Shell","T1573.001 - T1104 - T1205 - T1110","TA0005 - TA0011","N/A","N/A","C2","https://github.com/JoelGMSec/HTTP-Shell","1","1","N/A","N/A","10","10","231","33","2024-09-27T10:23:14Z","2023-09-05T12:01:17Z","50076" +"*JoelGMSec/Invoke-Stealth*",".{0,1000}JoelGMSec\/Invoke\-Stealth.{0,1000}","offensive_tool_keyword","Invoke-Stealth","Simple & Powerful PowerShell Script Obfuscator","T1027.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/JoelGMSec/Invoke-Stealth","1","1","N/A","N/A","9","6","559","81","2023-04-21T12:49:37Z","2021-04-13T10:22:05Z","50077" +"*JoelGMSec/PSAsyncShell*",".{0,1000}JoelGMSec\/PSAsyncShell.{0,1000}","offensive_tool_keyword","PSAsyncShell","PowerShell Asynchronous TCP Reverse Shell","T1059.001 - T1071.001","TA0002 - TA0011","N/A","N/A","C2","https://github.com/JoelGMSec/PSAsyncShell","1","1","N/A","N/A","10","10","155","22","2023-11-08T12:30:00Z","2022-07-19T15:38:34Z","50078" +"*JoelGMSec/PSRansom*",".{0,1000}JoelGMSec\/PSRansom.{0,1000}","offensive_tool_keyword","PSRansom","PSRansom is a PowerShell Ransomware Simulator with C2 Server capabilities. This tool helps you simulate encryption process of a generic ransomware in any system on any system with PowerShell installed on it. Thanks to the integrated C2 server. you can exfiltrate files and receive client information via HTTP.","T1486 - T1107 - T1566.001","TA0011 - TA0010","N/A","N/A","Ransomware","https://github.com/JoelGMSec/PSRansom","1","1","N/A","N/A","9","5","478","116","2024-01-19T09:50:26Z","2022-02-27T11:52:03Z","50079" +"*john.bash_completion*",".{0,1000}john\.bash_completion.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","#linux","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50104" +"*john.session.log*",".{0,1000}john\.session\.log.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","#logfile","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50105" +"*john.zsh_completion*",".{0,1000}john\.zsh_completion.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50106" +"*john/password.lst*",".{0,1000}john\/password\.lst.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","50107" +"*john/run/fuzz.dic*",".{0,1000}john\/run\/fuzz\.dic.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50108" +"*john/src/ztex/*",".{0,1000}john\/src\/ztex\/.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50109" +"*john@moozle.wtf*",".{0,1000}john\@moozle\.wtf.{0,1000}","offensive_tool_keyword","FudgeC2","FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.","T1021.002 - T1105 - T1059.001 - T1059.003","TA0008 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/Ziconius/FudgeC2","1","1","#email","N/A","10","10","253","54","2023-05-01T21:13:56Z","2018-09-09T21:05:21Z","50110" +"*john_crack_asrep*",".{0,1000}john_crack_asrep.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","50111" +"*john_crack_kerberoast*",".{0,1000}john_crack_kerberoast.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","50112" +"*john_log_format*",".{0,1000}john_log_format.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50113" +"*john_mpi.c*",".{0,1000}john_mpi\.c.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50114" +"*john_register_all*",".{0,1000}john_register_all.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50115" +"*JohnHammond/recaptcha-phish*",".{0,1000}JohnHammond\/recaptcha\-phish.{0,1000}","offensive_tool_keyword","recaptcha-phish","Phishing with a fake reCAPTCHA","T1566.001 - T1204.002 - T1071.003","TA0001 - TA0002","Lumma Stealer","N/A","Phishing","https://github.com/JohnHammond/recaptcha-phish","1","1","N/A","N/A","10","6","534","104","2024-09-13T11:18:29Z","2024-09-13T07:00:40Z","50116" +"*JohnTheRipper/*",".{0,1000}JohnTheRipper\/.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50118" +"*JohnWoodman/stealthInjector*",".{0,1000}JohnWoodman\/stealthInjector.{0,1000}","offensive_tool_keyword","OffensiveCpp","C/C++ snippets that can be handy in specific offensive scenarios","T1055 - T1047 - T1105 - T1117 - T1129 - T1135 - T1203","TA0002 - TA0003 - TA0006 - TA0007 - TA0009","N/A","N/A","Exploitation tool","https://github.com/lsecqt/OffensiveCpp","1","1","N/A","N/A","10","8","700","83","2025-01-26T08:05:48Z","2023-04-05T09:39:33Z","50119" +"*jojonas/SharpSAMDump*",".{0,1000}jojonas\/SharpSAMDump.{0,1000}","offensive_tool_keyword","SharpSAMDump","SAM dumping via the registry in C#/.NET","T1003.002 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/jojonas/SharpSAMDump","1","1","N/A","N/A","10","1","48","8","2025-01-16T07:08:58Z","2024-05-27T10:53:27Z","50128" +"*Jomungand-main*",".{0,1000}Jomungand\-main.{0,1000}","offensive_tool_keyword","Jomungand","Shellcode Loader with memory evasion","T1055.012 - T1027.002 - T1564.006","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/RtlDallas/Jomungand","1","1","N/A","N/A","10","","N/A","","","","50130" +"*Jormungand.exe*",".{0,1000}Jormungand\.exe.{0,1000}","offensive_tool_keyword","Jomungand","Shellcode Loader with memory evasion","T1055.012 - T1027.002 - T1564.006","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/RtlDallas/Jomungand","1","1","N/A","N/A","10","","N/A","","","","50133" +"*Jormungand.vcxproj*",".{0,1000}Jormungand\.vcxproj.{0,1000}","offensive_tool_keyword","Jomungand","Shellcode Loader with memory evasion","T1055.012 - T1027.002 - T1564.006","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/RtlDallas/Jomungand","1","1","N/A","N/A","10","","N/A","","","","50134" +"*Jormungandr.cpp*",".{0,1000}Jormungandr\.cpp.{0,1000}","offensive_tool_keyword","Jormungandr","Jormungandr is a kernel implementation of a COFF loader allowing kernel developers to load and execute their COFFs in the kernel","T1215 - T1059.003 - T1547.006","TA0004 - TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Idov31/Jormungandr","1","1","N/A","N/A","N/A","3","228","27","2023-09-26T18:06:53Z","2023-06-25T06:24:16Z","50135" +"*Jormungandr.exe*",".{0,1000}Jormungandr\.exe.{0,1000}","offensive_tool_keyword","Jormungandr","Jormungandr is a kernel implementation of a COFF loader allowing kernel developers to load and execute their COFFs in the kernel","T1215 - T1059.003 - T1547.006","TA0004 - TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Idov31/Jormungandr","1","1","N/A","N/A","N/A","3","228","27","2023-09-26T18:06:53Z","2023-06-25T06:24:16Z","50136" +"*Jormungandr-master*",".{0,1000}Jormungandr\-master.{0,1000}","offensive_tool_keyword","Jormungandr","Jormungandr is a kernel implementation of a COFF loader allowing kernel developers to load and execute their COFFs in the kernel","T1215 - T1059.003 - T1547.006","TA0004 - TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Idov31/Jormungandr","1","1","N/A","N/A","N/A","3","228","27","2023-09-26T18:06:53Z","2023-06-25T06:24:16Z","50137" +"*jp.mirrors.cicku.me/blackarch/*/os/*",".{0,1000}jp\.mirrors\.cicku\.me\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","50139" +"*JPG0mez/ADCSync*",".{0,1000}JPG0mez\/ADCSync.{0,1000}","offensive_tool_keyword","adcsync","Use ESC1 to perform a makeshift DCSync and dump hashes","T1003.006 - T1021","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/JPG0mez/ADCSync","1","1","N/A","N/A","9","3","205","22","2023-11-02T21:41:08Z","2023-10-04T01:56:50Z","50140" +"*jpillora/chisel*",".{0,1000}jpillora\/chisel.{0,1000}","offensive_tool_keyword","chisel","A fast TCP/UDP tunnel over HTTP","T1090 - T1090.003 - T1572 - T1572.001","TA0042 - TA0011","N/A","BlackSuit - Royal - AvosLocker - Cactus - Yanluowang - Sandworm - KNOTWEED","C2","https://github.com/jpillora/chisel","1","1","#linux #windows","N/A","10","10","14432","1466","2024-09-28T23:35:13Z","2015-02-25T11:42:50Z","50142" +"*jqlcrn2fsfvxlngdq53rqyrwtwfrulup74xyle54bsvo3l2kgpeeijid.onion*",".{0,1000}jqlcrn2fsfvxlngdq53rqyrwtwfrulup74xyle54bsvo3l2kgpeeijid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","50148" +"*jquery-c2.*.profile*",".{0,1000}jquery\-c2\..{0,1000}\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/malleable-c2","1","1","N/A","N/A","10","10","1676","299","2023-12-13T17:14:22Z","2018-08-14T14:19:43Z","50149" +"*js-cracker-client/cracker.js*",".{0,1000}js\-cracker\-client\/cracker\.js.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","50150" +"*JScriptStager*",".{0,1000}JScriptStager.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","50151" +"*jtee43gt-6543-2iur-9422-83r5w27hgzaq*",".{0,1000}jtee43gt\-6543\-2iur\-9422\-83r5w27hgzaq.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","50152" +"*juicycreds_dump*",".{0,1000}juicycreds_dump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","50153" +"*JuicyPotato.exe*",".{0,1000}JuicyPotato\.exe.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","50156" +"*JuicyPotato.exe*",".{0,1000}JuicyPotato\.exe.{0,1000}","offensive_tool_keyword","JuicyPotato","Windows Local Privilege Escalation from Service Account to System","T1055.012 - T1068 - T1548.002 - T1505.003","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","N/A","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","50157" +"*JuicyPotato.exe*",".{0,1000}JuicyPotato\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","JuicyPotato","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","50158" +"*JuicyPotato.exe*",".{0,1000}JuicyPotato\.exe.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","50159" +"*JuicyPotato.sln*",".{0,1000}JuicyPotato\.sln.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","50160" +"*JuicyPotato.vcxproj*",".{0,1000}JuicyPotato\.vcxproj.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","50161" +"*juicypotato.x64.dll*",".{0,1000}juicypotato\.x64\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","50162" +"*juicypotato.x86.dll*",".{0,1000}juicypotato\.x86\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","50163" +"*juicypotato_reflective.dll*",".{0,1000}juicypotato_reflective\.dll.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","50164" +"*JuicyPotatoNG.cpp*",".{0,1000}JuicyPotatoNG\.cpp.{0,1000}","offensive_tool_keyword","JuicyPotatoNG","Another Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","FoxKitten - APT33 - Volatile Cedar - Sandworm","Privilege Escalation","https://github.com/antonioCoco/JuicyPotatoNG","1","1","N/A","N/A","10","9","844","101","2022-11-12T01:48:39Z","2022-09-21T17:08:35Z","50165" +"*JuicyPotatoNG.exe*",".{0,1000}JuicyPotatoNG\.exe.{0,1000}","offensive_tool_keyword","JuicyPotatoNG","Another Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","FoxKitten - APT33 - Volatile Cedar - Sandworm","Privilege Escalation","https://github.com/antonioCoco/JuicyPotatoNG","1","1","N/A","N/A","10","9","844","101","2022-11-12T01:48:39Z","2022-09-21T17:08:35Z","50166" +"*JuicyPotatoNG.sln*",".{0,1000}JuicyPotatoNG\.sln.{0,1000}","offensive_tool_keyword","JuicyPotatoNG","Another Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","FoxKitten - APT33 - Volatile Cedar - Sandworm","Privilege Escalation","https://github.com/antonioCoco/JuicyPotatoNG","1","1","N/A","N/A","10","9","844","101","2022-11-12T01:48:39Z","2022-09-21T17:08:35Z","50167" +"*JuicyPotatoNG.txt*",".{0,1000}JuicyPotatoNG\.txt.{0,1000}","offensive_tool_keyword","JuicyPotatoNG","Another Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","FoxKitten - APT33 - Volatile Cedar - Sandworm","Privilege Escalation","https://github.com/antonioCoco/JuicyPotatoNG","1","1","N/A","N/A","10","9","844","101","2022-11-12T01:48:39Z","2022-09-21T17:08:35Z","50168" +"*JuicyPotatoNG.zip*",".{0,1000}JuicyPotatoNG\.zip.{0,1000}","offensive_tool_keyword","JuicyPotatoNG","Another Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","FoxKitten - APT33 - Volatile Cedar - Sandworm","Privilege Escalation","https://github.com/antonioCoco/JuicyPotatoNG","1","1","N/A","N/A","10","9","844","101","2022-11-12T01:48:39Z","2022-09-21T17:08:35Z","50169" +"*JuicyPotatoNG-main*",".{0,1000}JuicyPotatoNG\-main.{0,1000}","offensive_tool_keyword","JuicyPotatoNG","Another Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","FoxKitten - APT33 - Volatile Cedar - Sandworm","Privilege Escalation","https://github.com/antonioCoco/JuicyPotatoNG","1","1","N/A","N/A","10","9","844","101","2022-11-12T01:48:39Z","2022-09-21T17:08:35Z","50170" +"*JumpSession_BOF-main*",".{0,1000}JumpSession_BOF\-main.{0,1000}","offensive_tool_keyword","JumpSession_BOF","Beacon Object File allowing creation of Beacons in different sessions","T1055 - T1055.012 - T1548.002","TA0002 - TA0003 - TA0004","N/A","N/A","Persistence","https://github.com/Octoberfest7/JumpSession_BOF","1","1","N/A","N/A","9","1","80","13","2022-05-23T22:23:33Z","2022-05-21T17:38:18Z","50177" +"*JunctionFolder.exe*",".{0,1000}JunctionFolder\.exe.{0,1000}","offensive_tool_keyword","JunctionFolder","Creates a junction folder in the Windows Accessories Start Up folder as described in the Vault 7 leaks. On start or when a user browses the directory - the referenced DLL will be executed by verclsid.exe in medium integrity.","T1547.001 - T1574.001 - T1204.002","TA0005 - TA0004","N/A","N/A","Persistence","https://github.com/matterpreter/OffensiveCSharp/tree/master/JunctionFolder","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","50178" +"*jweny/zabbix-saml-bypass-exp*",".{0,1000}jweny\/zabbix\-saml\-bypass\-exp.{0,1000}","offensive_tool_keyword","POC","POC exploitaiton of zabbix saml bypass exp vulnerability cve-2022-23131 (Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML)","T1548 - T1190","TA0001 - TA0002","N/A","N/A","Exploitation tool","https://github.com/jweny/zabbix-saml-bypass-exp","1","1","N/A","N/A","N/A","1","93","42","2022-02-21T04:27:48Z","2022-02-18T08:38:53Z","50182" +"*jwqpucwiolhmivnqt7qwroezymksxfjsbj6pmg2lnnglqpoe26cwnryd.onion*",".{0,1000}jwqpucwiolhmivnqt7qwroezymksxfjsbj6pmg2lnnglqpoe26cwnryd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","50183" +"*k4yt3x/orbitaldump*",".{0,1000}k4yt3x\/orbitaldump.{0,1000}","offensive_tool_keyword","orbitaldump","A simple multi-threaded distributed SSH brute-forcing tool written in Python.","T1110","TA0006","N/A","N/A","Exploitation tool","https://github.com/k4yt3x/orbitaldump","1","1","N/A","N/A","N/A","5","460","83","2022-10-30T23:40:57Z","2021-06-06T17:48:19Z","50191" +"*k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion*",".{0,1000}k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","50192" +"*K8_CS_*.rar*",".{0,1000}K8_CS_.{0,1000}\.rar.{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike4.4 one-click deployment script Randomly generate passwords. keys. port numbers. certificates. etc.. to solve the problem that cs4.x cannot run on Linux and report errors","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/AlphabugX/csOnvps","1","1","N/A","N/A","10","10","286","63","2022-03-19T00:10:03Z","2021-12-02T02:10:42Z","50193" +"*k8gege.org/*",".{0,1000}k8gege\.org\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","50194" +"*k8gege/Ladon*",".{0,1000}k8gege\/Ladon.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","50195" +"*K8Ladon.sln*",".{0,1000}K8Ladon\.sln.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","50196" +"*KABHAGUAdAAtAEwAbwBjAGEAbABHAHIAbwB1AHAATQBlAG0AYgBlAHIAIAAtAE4AYQBtAGUAIABBAGQAbQBpAG4AaQBzAHQAcgBhAHQAbwByAHMAIAB8ACAAUwBlAGwAZQBjAHQALQBPAGIAagBlAGMAdAAgAC0ARQB4AHAAYQBuAGQAUAByAG8AcABlAHIAdAB5ACAAbgBhAG0AZQApACAALQBjAG8AbgB0AGEAaQBuAHMAIABbAFMAeQBzAHQAZQBtAC4AUwBlAGMAdQByAGkAdAB5AC4AUAByAGkAbgBjAGkAcABhAGwALgBXAGkAbgBkAG8AdwBzAEkAZABlAG4AdABpAHQAeQBdADoAOgBHAGUAdABDAHUAcgByAGUAbgB0ACgAKQAuAG4AYQBtAGUA*",".{0,1000}KABHAGUAdAAtAEwAbwBjAGEAbABHAHIAbwB1AHAATQBlAG0AYgBlAHIAIAAtAE4AYQBtAGUAIABBAGQAbQBpAG4AaQBzAHQAcgBhAHQAbwByAHMAIAB8ACAAUwBlAGwAZQBjAHQALQBPAGIAagBlAGMAdAAgAC0ARQB4AHAAYQBuAGQAUAByAG8AcABlAHIAdAB5ACAAbgBhAG0AZQApACAALQBjAG8AbgB0AGEAaQBuAHMAIABbAFMAeQBzAHQAZQBtAC4AUwBlAGMAdQByAGkAdAB5AC4AUAByAGkAbgBjAGkAcABhAGwALgBXAGkAbgBkAG8AdwBzAEkAZABlAG4AdABpAHQAeQBdADoAOgBHAGUAdABDAHUAcgByAGUAbgB0ACgAKQAuAG4AYQBtAGUA.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","50197" +"*kali-*.deb*",".{0,1000}kali\-.{0,1000}\.deb.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","50200" +"*kali-anonsurf*",".{0,1000}kali\-anonsurf.{0,1000}","offensive_tool_keyword","kali-anonsurf","Anonsurf will anonymize the entire system under TOR using IPTables. It will also allow you to start and stop i2p as well.","T1568 - T1102 - T1055 - T1070","TA0002 - TA0008 - TA0011","N/A","N/A","Data Exfiltration","https://github.com/Und3rf10w/kali-anonsurf","1","1","#linux","N/A","N/A","10","1681","478","2025-02-17T03:54:56Z","2015-08-19T04:57:16Z","50201" +"*KaliLadon.*",".{0,1000}KaliLadon\..{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","50202" +"*kali-linux*.7z*",".{0,1000}kali\-linux.{0,1000}\.7z.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","50203" +"*kali-linux*.img*",".{0,1000}kali\-linux.{0,1000}\.img.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","50204" +"*kali-linux*.iso*",".{0,1000}kali\-linux.{0,1000}\.iso.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","50205" +"*kali-linux-*.torrent*",".{0,1000}kali\-linux\-.{0,1000}\.torrent.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","50206" +"*kali-linux-*.vmdk*",".{0,1000}kali\-linux\-.{0,1000}\.vmdk.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","50207" +"*kali-linux-*.vmwarevm*",".{0,1000}kali\-linux\-.{0,1000}\.vmwarevm.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","50208" +"*kali-linux-*.vmx*",".{0,1000}kali\-linux\-.{0,1000}\.vmx.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","50209" +"*kali-linux-*-installer-amd64.iso*",".{0,1000}kali\-linux\-.{0,1000}\-installer\-amd64\.iso.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","50210" +"*kali-linux-*-installer-everything-amd64.iso.torrent*",".{0,1000}kali\-linux\-.{0,1000}\-installer\-everything\-amd64\.iso\.torrent.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","50211" +"*kali-linux-*-live-everything-amd64.iso.torrent*",".{0,1000}kali\-linux\-.{0,1000}\-live\-everything\-amd64\.iso\.torrent.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","50212" +"*kali-linux-*-raspberry-pi-armhf.img.xz*",".{0,1000}kali\-linux\-.{0,1000}\-raspberry\-pi\-armhf\.img\.xz.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","50213" +"*kali-linux-*-virtualbox-amd64.ova*",".{0,1000}kali\-linux\-.{0,1000}\-virtualbox\-amd64\.ova.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","50214" +"*kali-linux-*-vmware-amd64.7z*",".{0,1000}kali\-linux\-.{0,1000}\-vmware\-amd64\.7z.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","50215" +"*kalilinux/kali-rolling*",".{0,1000}kalilinux\/kali\-rolling.{0,1000}","offensive_tool_keyword","gsocket","The Global Socket Tookit allows two users behind NAT/Firewall to establish a TCP connection with each other. Mostly abused by attackers ","T1021 - T1090 - T1573 - T1219 - T1562.001","TA0001 - TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hackerschoice/gsocket","1","1","#linux","N/A","9","10","1671","142","2025-04-22T14:47:29Z","2020-09-18T16:14:22Z","50216" +"*kalilinux/kali-rolling*",".{0,1000}kalilinux\/kali\-rolling.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","50217" +"*kaluche/bloodhound-quickwin*",".{0,1000}kaluche\/bloodhound\-quickwin.{0,1000}","offensive_tool_keyword","bloodhound-quickwin","Simple script to extract useful informations from the combo BloodHound + Neo4j","T1482 - T1087 - T1069 - T1018","TA0007 - TA0008 - TA0004","N/A","APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor","Discovery","https://github.com/kaluche/bloodhound-quickwin","1","1","N/A","AD Enumeration","6","3","239","26","2025-04-04T05:11:46Z","2021-02-16T16:04:16Z","50220" +"*karendm/ADHunt*",".{0,1000}karendm\/ADHunt.{0,1000}","offensive_tool_keyword","adhunt","Tool for exploiting Active Directory Enviroments - enumeration","T1018 - T1087 - T1087.002 - T1069 - T1069.002","TA0007 - TA0003 - TA0001","N/A","N/A","Discovery","https://github.com/karendm/ADHunt","1","1","N/A","AD Enumeration","7","1","46","10","2023-08-10T18:55:39Z","2023-06-20T13:24:10Z","50222" +"*Karkas66/CelestialSpark*",".{0,1000}Karkas66\/CelestialSpark.{0,1000}","offensive_tool_keyword","CelestialSpark","A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders Stardust","T1572 - T1048 - T1041 - T1105","TA0005 - TA0011 - TA0010","N/A","N/A","C2","https://github.com/Karkas66/CelestialSpark","1","1","N/A","N/A","10","10","103","10","2025-03-27T12:47:34Z","2024-04-11T12:17:22Z","50224" +"*Karmaleon.py*",".{0,1000}Karmaleon\.py.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","50225" +"*karmaSMB.py*",".{0,1000}karmaSMB\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","50226" +"*KasRoudra/CamHacker*",".{0,1000}KasRoudra\/CamHacker.{0,1000}","offensive_tool_keyword","CamHacker","Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured!","T1598 - T1204 - T1566.001","TA0009 - TA0010 - TA0043","N/A","N/A","Phishing","https://github.com/KasRoudra/CamHacker","1","1","N/A","N/A","10","","N/A","","","","50228" +"*katoolin*toollist.py*",".{0,1000}katoolin.{0,1000}toollist\.py.{0,1000}","offensive_tool_keyword","katoolin3","Katoolin3 brings all programs available in Kali Linux to Debian and Ubuntu.","T1203 - T1090 - T1020","TA0006 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/s-h-3-l-l/katoolin3","1","1","#linux","N/A","N/A","4","370","120","2020-08-05T17:21:00Z","2019-09-05T13:14:46Z","50230" +"*katoolin3.py*",".{0,1000}katoolin3\.py.{0,1000}","offensive_tool_keyword","katoolin3","Katoolin3 brings all programs available in Kali Linux to Debian and Ubuntu.","T1203 - T1090 - T1020","TA0006 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/s-h-3-l-l/katoolin3","1","1","#linux","N/A","N/A","4","370","120","2020-08-05T17:21:00Z","2019-09-05T13:14:46Z","50231" +"*KaynInject.x64.exe*",".{0,1000}KaynInject\.x64\.exe.{0,1000}","offensive_tool_keyword","KaynLdr","KaynLdr is a Reflective Loader written in C/ASM","T1055 - T1027 - T1055.012","TA0002 - TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/KaynLdr","1","1","N/A","N/A","9","6","532","108","2023-12-03T18:26:04Z","2021-12-26T14:32:11Z","50234" +"*KaynInject.x86.exe*",".{0,1000}KaynInject\.x86\.exe.{0,1000}","offensive_tool_keyword","KaynLdr","KaynLdr is a Reflective Loader written in C/ASM","T1055 - T1027 - T1055.012","TA0002 - TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/KaynLdr","1","1","N/A","N/A","9","6","532","108","2023-12-03T18:26:04Z","2021-12-26T14:32:11Z","50235" +"*KaynLdr.x64.dll*",".{0,1000}KaynLdr\.x64\.dll.{0,1000}","offensive_tool_keyword","KaynLdr","KaynLdr is a Reflective Loader written in C/ASM","T1055 - T1027 - T1055.012","TA0002 - TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/KaynLdr","1","1","N/A","N/A","9","6","532","108","2023-12-03T18:26:04Z","2021-12-26T14:32:11Z","50237" +"*KaynStrike.x64.bin*",".{0,1000}KaynStrike\.x64\.bin.{0,1000}","offensive_tool_keyword","KaynStrike","A User Defined Reflective Loader for Cobalt Strike Beacon that spoofs the thread start address and frees itself after entry point was executed.","T1055 - T1036 - T1070 - T1055.012 - T1055.001","TA0002 - TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/KaynStrike","1","1","N/A","N/A","9","5","422","66","2023-12-03T18:05:11Z","2022-05-30T04:22:59Z","50239" +"*KaynStrike.x64.exe*",".{0,1000}KaynStrike\.x64\.exe.{0,1000}","offensive_tool_keyword","KaynStrike","A User Defined Reflective Loader for Cobalt Strike Beacon that spoofs the thread start address and frees itself after entry point was executed.","T1055 - T1036 - T1070 - T1055.012 - T1055.001","TA0002 - TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/KaynStrike","1","1","N/A","N/A","9","5","422","66","2023-12-03T18:05:11Z","2022-05-30T04:22:59Z","50240" +"*KBDPAYLOAD.dll*",".{0,1000}KBDPAYLOAD\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Achieve execution using a custom keyboard layout","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/NtQuerySystemInformation/CustomKeyboardLayoutPersistence","1","1","N/A","N/A","10","","N/A","","","","50241" +"*KCMTicketFormatter.py*",".{0,1000}KCMTicketFormatter\.py.{0,1000}","offensive_tool_keyword","KCMTicketFormatter","Format SSSD Raw Kerberos Payloads into CCACHE files for use on Windows systems","T1558.003 - T1550.002","TA0006 - TA0005","N/A","N/A","Exploitation tool","https://github.com/blacklanternsecurity/KCMTicketFormatter","1","1","N/A","N/A","7","1","37","4","2021-05-26T20:23:56Z","2021-05-26T20:17:33Z","50244" +"*KcpPassword.cs*",".{0,1000}KcpPassword\.cs.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","50246" +"*kdcdump2john.py*",".{0,1000}kdcdump2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50247" +"*KDot227/SomalifuscatorV2*",".{0,1000}KDot227\/SomalifuscatorV2.{0,1000}","offensive_tool_keyword","SomalifuscatorV2","windows batch obfuscator","T1027 - T1497 - T1057","TA0005","N/A","N/A","Defense Evasion","https://github.com/KDot227/SomalifuscatorV2","1","1","N/A","N/A","10","4","315","42","2025-01-19T04:30:49Z","2022-09-23T00:46:51Z","50248" +"*kdstab.cna*",".{0,1000}kdstab\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","BOF combination of KillDefender and Backstab","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Octoberfest7/KDStab","1","1","N/A","N/A","10","10","167","37","2023-03-23T02:22:50Z","2022-03-10T06:09:52Z","50259" +"*KeeFarceReborn.*",".{0,1000}KeeFarceReborn\..{0,1000}","offensive_tool_keyword","Dinjector","Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL","T1055 - T1055.012 - T1055.001 - T1027.002","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Metro-Holografix/DInjector","1","1","N/A","private github repo","8","","N/A","","","","50260" +"*keepass_common_plug.*",".{0,1000}keepass_common_plug\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50263" +"*keepass_discover.py*",".{0,1000}keepass_discover\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","50264" +"*KeePassConfig.ps1*",".{0,1000}KeePassConfig\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1071","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","50267" +"*KeePassConfig.ps1*",".{0,1000}KeePassConfig\.ps1.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","50268" +"*-KeePassConfigTrigger*",".{0,1000}\-KeePassConfigTrigger.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","50269" +"*KeePassHax.dll*",".{0,1000}KeePassHax\.dll.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","50270" +"*keepass-password-dumper*",".{0,1000}keepass\-password\-dumper.{0,1000}","offensive_tool_keyword","keepass-password-dumper","KeePass Master Password Dumper is a simple proof-of-concept tool used to dump the master password from KeePass's memory. Apart from the first password character it is mostly able to recover the password in plaintext. No code execution on the target system is required. just a memory dump","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/vdohney/keepass-password-dumper","1","1","N/A","N/A","N/A","7","639","59","2023-08-17T19:26:55Z","2023-05-01T17:08:55Z","50272" +"*keepass-password-dumper*",".{0,1000}keepass\-password\-dumper.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50273" +"*keepassxcfox.dll*",".{0,1000}keepassxcfox\.dll.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","1","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","50274" +"*KeePwn-main.zip*",".{0,1000}KeePwn\-main\.zip.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50290" +"*KeeTheft/Dinvoke*",".{0,1000}KeeTheft\/Dinvoke.{0,1000}","offensive_tool_keyword","KeeThiefSyscalls","Patch GhostPack/KeeThief for it to use DInvoke and syscalls","T1003.001 - T1558.002","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/Metro-Holografix/KeeThiefSyscalls","1","1","N/A","private github repo","10","","N/A","","","","50291" +"*KeeThief*",".{0,1000}KeeThief.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","50292" +"*KeeThief.*",".{0,1000}KeeThief\..{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","50293" +"*KeeThief.ps1*",".{0,1000}KeeThief\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1072","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","50294" +"*KeeThiefSyscalls*",".{0,1000}KeeThiefSyscalls.{0,1000}","offensive_tool_keyword","KeeThiefSyscalls","Patch GhostPack/KeeThief for it to use DInvoke and syscalls","T1003.001 - T1558.002","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/Metro-Holografix/KeeThiefSyscalls","1","1","N/A","private github repo","10","","N/A","","","","50295" +"*keowu/BadRentdrv2*",".{0,1000}keowu\/BadRentdrv2.{0,1000}","offensive_tool_keyword","BadRentdrv2","A vulnerable driver (BYOVD) capable of terminating several EDRs and antivirus software","T1562 - T1068 - T1210 - T1489 - T1496","TA0005 - TA0004 - TA0040","N/A","Agrius","Defense Evasion","https://github.com/keowu/BadRentdrv2","1","1","N/A","N/A","10","1","95","20","2024-12-26T13:43:18Z","2023-10-01T18:24:38Z","50298" +"*Kerberoast.*",".{0,1000}Kerberoast\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","50306" +"*kerberoast.py*",".{0,1000}kerberoast\.py.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","1","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","50307" +"*Kerberoast.py*",".{0,1000}Kerberoast\.py.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","50308" +"*kerberoast.py*",".{0,1000}kerberoast\.py.{0,1000}","offensive_tool_keyword","powerview","PowerView.py is an alternative for the awesome original PowerView.ps1","T1046 - T1087.001 - T1016","TA0007 - TA0008 - TA0009","N/A","N/A","Discovery","https://github.com/aniqfakhrul/powerview.py","1","1","N/A","N/A","10","7","622","66","2025-04-22T09:01:39Z","2022-06-19T16:13:04Z","50309" +"*kerberoast_attack*",".{0,1000}kerberoast_attack.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","50310" +"*kerberoast_blind_output_*",".{0,1000}kerberoast_blind_output_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","50311" +"*kerberoast_john_results_*",".{0,1000}kerberoast_john_results_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","50312" +"*kerberoastables.txt*",".{0,1000}kerberoastables\.txt.{0,1000}","offensive_tool_keyword","targetedKerberoast","Kerberoast with ACL abuse capabilities","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/ShutdownRepo/targetedKerberoast","1","1","N/A","N/A","N/A","5","442","63","2024-12-16T07:32:14Z","2021-08-02T20:19:35Z","50313" +"*kerberoasting*",".{0,1000}kerberoasting.{0,1000}","offensive_tool_keyword","OSCP-Cheatsheets","kerberoasting keyword. attack that allows any domain user to request kerberos tickets from TGS that are encrypted with NTLM hash of the plaintext password of a domain user account that is used as a service account (i.e account used for running an IIS service) and crack them offline avoiding AD account lockouts.","T1558 - T1208 - T1003 - T1110","TA0001 - TA0002 - TA0003 - TA0006","N/A","N/A","Exploitation tool","https://github.com/blackc03r/OSCP-Cheatsheets/blob/master/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting.md","1","1","N/A","N/A","N/A","1","96","36","2019-09-09T22:07:47Z","2019-09-12T22:07:31Z","50314" +"*kerberoasting.boo*",".{0,1000}kerberoasting\.boo.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","50315" +"*KerberOPSEC.csproj*",".{0,1000}KerberOPSEC\.csproj.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","1","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","50317" +"*KerberOPSEC.exe*",".{0,1000}KerberOPSEC\.exe.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","1","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","50318" +"*KerberOPSEC-x64.exe*",".{0,1000}KerberOPSEC\-x64\.exe.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","1","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","50319" +"*KerberOPSEC-x86.exe*",".{0,1000}KerberOPSEC\-x86\.exe.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","1","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","50320" +"*kerberos*.kirbi*",".{0,1000}kerberos.{0,1000}\.kirbi.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/RDPHijack-BOF","1","1","N/A","N/A","10","3","298","46","2022-07-08T10:14:32Z","2022-07-08T10:14:07Z","50322" +"*kerberos/decryptor.py*",".{0,1000}kerberos\/decryptor\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","50323" +"*kerberos_enumusers.*",".{0,1000}kerberos_enumusers\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","50340" +"*kerberos_steal*",".{0,1000}kerberos_steal.{0,1000}","offensive_tool_keyword","LinikatzV2","linikatz is a tool to attack AD on UNIX","T1003.002 - T1558.003 - T1078 - T1550.001","TA0006 - TA0001 - TA0004 - TA0003","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/LinikatzV2","1","1","#linux","N/A","10","2","146","15","2023-10-19T12:26:58Z","2023-10-19T11:07:53Z","50342" +"*kerberos-ldap-password-hunter.sh*",".{0,1000}kerberos\-ldap\-password\-hunter\.sh.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","50343" +"*kerberos-ldap-password-hunter.sh*",".{0,1000}kerberos\-ldap\-password\-hunter\.sh.{0,1000}","offensive_tool_keyword","LDAP-Password-Hunter","LDAP Password Hunter is a tool which wraps features of getTGT.py (Impacket) and ldapsearch in order to look up for password stored in LDAP database","T1558.003 - T1003.003 - T1078.003 - T1212","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/oldboy21/LDAP-Password-Hunter","1","1","N/A","N/A","10","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","50344" +"*kerberos-ldap-password-hunter.sh*",".{0,1000}kerberos\-ldap\-password\-hunter\.sh.{0,1000}","offensive_tool_keyword","LDAP-Password-Hunter","Password Hunter in Active Directory","T1087.002","TA0001 - TA0007","N/A","N/A","Discovery","https://github.com/oldboy21/LDAP-Password-Hunter","1","1","N/A","N/A","7","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","50345" +"*kerberosv5.py*",".{0,1000}kerberosv5\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","50346" +"*Kerbeus-BOF-main*",".{0,1000}Kerbeus\-BOF\-main.{0,1000}","offensive_tool_keyword","cobaltstrike","BOF for Kerberos abuse (an implementation of some important features of the Rubeus)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RalfHacker/Kerbeus-BOF","1","1","N/A","N/A","10","10","458","51","2025-03-29T18:15:17Z","2023-11-20T10:01:36Z","50350" +"*kerbrute*bruteforce*",".{0,1000}kerbrute.{0,1000}bruteforce.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50356" +"*kerbrute.go*",".{0,1000}kerbrute\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50357" +"*kerbrute/cmd*",".{0,1000}kerbrute\/cmd.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50358" +"*kerbrute/util*",".{0,1000}kerbrute\/util.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50359" +"*kerbrute_*.exe*",".{0,1000}kerbrute_.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50360" +"*kerbrute_darwin_386*",".{0,1000}kerbrute_darwin_386.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","#linux","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50361" +"*kerbrute_darwin_amd64*",".{0,1000}kerbrute_darwin_amd64.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","#linux","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50362" +"*kerbrute_enum*",".{0,1000}kerbrute_enum.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","50363" +"*kerbrute_linux*",".{0,1000}kerbrute_linux.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","#linux","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50364" +"*kerbrute_pass_output_*",".{0,1000}kerbrute_pass_output_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","50365" +"*kerbrute_user_output_*",".{0,1000}kerbrute_user_output_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","50366" +"*kerbrute_userpass_wordlist_*",".{0,1000}kerbrute_userpass_wordlist_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","50367" +"*kerbrute_windows*",".{0,1000}kerbrute_windows.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50368" +"*kerbrute_windows_386.exe*",".{0,1000}kerbrute_windows_386\.exe.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50369" +"*kerbrute_windows_amd64.exe*",".{0,1000}kerbrute_windows_amd64\.exe.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50370" +"*kerbrute-master*",".{0,1000}kerbrute\-master.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50371" +"*KerbruteSession*",".{0,1000}KerbruteSession.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50372" +"*kernel_shellcode.asm*",".{0,1000}kernel_shellcode\.asm.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","50373" +"*kernelcallbacktable.x64*",".{0,1000}kernelcallbacktable\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","50374" +"*kernelcallbacktable.x64*",".{0,1000}kernelcallbacktable\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","50375" +"*kernelcallbacktable.x86*",".{0,1000}kernelcallbacktable\.x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","50376" +"*kernelcallbacktable.x86*",".{0,1000}kernelcallbacktable\.x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","50377" +"*KernelMii.cna*",".{0,1000}KernelMii\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tijme/kernel-mii","1","1","N/A","N/A","10","10","81","24","2023-05-07T18:38:29Z","2022-06-25T11:13:45Z","50378" +"*KernelMii.x64.exe*",".{0,1000}KernelMii\.x64\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tijme/kernel-mii","1","1","N/A","N/A","10","10","81","24","2023-05-07T18:38:29Z","2022-06-25T11:13:45Z","50379" +"*KernelMii.x64.o*",".{0,1000}KernelMii\.x64\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tijme/kernel-mii","1","1","N/A","N/A","10","10","81","24","2023-05-07T18:38:29Z","2022-06-25T11:13:45Z","50380" +"*KernelMii.x86.exe*",".{0,1000}KernelMii\.x86\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tijme/kernel-mii","1","1","N/A","N/A","10","10","81","24","2023-05-07T18:38:29Z","2022-06-25T11:13:45Z","50381" +"*KernelMii.x86.o*",".{0,1000}KernelMii\.x86\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tijme/kernel-mii","1","1","N/A","N/A","10","10","81","24","2023-05-07T18:38:29Z","2022-06-25T11:13:45Z","50382" +"*Kernel-Suite-Downgrade/Config.xml*",".{0,1000}Kernel\-Suite\-Downgrade\/Config\.xml.{0,1000}","offensive_tool_keyword","WindowsDowndate","A tool that takes over Windows Updates to craft custom downgrades and expose past fixed vulnerabilities","T1072 - T1486 - T1505.002 - T1495 - T1499.004","TA0005 - TA0004 - TA0003 ","N/A","N/A","Defense Evasion","https://github.com/SafeBreach-Labs/WindowsDowndate","1","1","N/A","N/A","10","7","663","88","2024-10-26T10:18:49Z","2024-01-08T19:42:47Z","50383" +"*KevinJClark/badrats*",".{0,1000}KevinJClark\/badrats.{0,1000}","offensive_tool_keyword","badrats","control tool (C2) using Python server - Jscript - Powershell and C# implants and communicates via HTTP(S) and SMB","T1059 - T1027 - T1573 - T1071 - T1105","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://gitlab.com/KevinJClark/badrats","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","50385" +"*Kevin-Robertson/Inveigh*",".{0,1000}Kevin\-Robertson\/Inveigh.{0,1000}","offensive_tool_keyword","Inveigh",".NET IPv4/IPv6 machine-in-the-middle tool for penetration testers","T1550.002 - T1059.001 - T1071.001","TA0002","N/A","ALLANITE - ENERGETIC BEAR","Sniffing & Spoofing","https://github.com/Kevin-Robertson/Inveigh","1","1","N/A","N/A","10","10","2685","462","2024-08-06T01:47:27Z","2015-04-02T18:04:41Z","50386" +"*keychain2john.py*",".{0,1000}keychain2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50390" +"*keylistattack.py*",".{0,1000}keylistattack\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","50391" +"*keylog_inject.py*",".{0,1000}keylog_inject\.py.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","50395" +"*keylog_recorder.*",".{0,1000}keylog_recorder\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","50398" +"*keylog_recorder.rb*",".{0,1000}keylog_recorder\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","50399" +"*Keylogger.cs*",".{0,1000}Keylogger\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","50411" +"*keylogger.dll*",".{0,1000}keylogger\.dll.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","50413" +"*KeyLogger.dll*",".{0,1000}KeyLogger\.dll.{0,1000}","offensive_tool_keyword","xeno-rat","Xeno-RAT is an open-source remote access tool (RAT) developed in C# providing a comprehensive set of features for remote system management. Has features such as HVNC - live microphone - reverse proxy and much much more","T1133 - T1021.001 - T1563.002 - T1113 - T1123 - T1571 - T1090","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011","N/A","N/A","C2","https://github.com/moom825/xeno-rat","1","1","N/A","N/A","10","10","1225","323","2024-03-05T06:22:36Z","2023-10-17T06:41:56Z","50414" +"*Keylogger.exe*",".{0,1000}Keylogger\.exe.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","50415" +"*Keylogger.exe*",".{0,1000}Keylogger\.exe.{0,1000}","offensive_tool_keyword","SharpLogger","Keylogger written in C#","T1056.001 - T1056.003","TA0005 - TA0006 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/djhohnstein/SharpLogger","1","1","N/A","N/A","10","2","126","41","2019-12-13T04:40:56Z","2018-12-18T01:45:17Z","50416" +"*Keylogger.java*",".{0,1000}Keylogger\.java.{0,1000}","offensive_tool_keyword","saint","(s)AINT is a Spyware Generator for Windows systems written in Java","T1056.001 - T1125 - T1123 - T1113 - T1105 - T1573.001","TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","C2","https://github.com/tiagorlampert/sAINT","1","1","N/A","N/A","10","10","712","311","2020-04-03T14:34:34Z","2017-11-18T18:43:25Z","50417" +"*Keylogger.pdb*",".{0,1000}Keylogger\.pdb.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","50419" +"*Keylogger.ps1*",".{0,1000}Keylogger\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","50420" +"*Keylogger.ps1*",".{0,1000}Keylogger\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","50421" +"*keylogger.py*",".{0,1000}keylogger\.py.{0,1000}","offensive_tool_keyword","disctopia-c2","Windows Remote Administration Tool that uses Discord Telegram and GitHub as C2s","T1105 - T1102","TA0003 - TA0008 - TA0002","N/A","N/A","C2","https://github.com/3ct0s/disctopia-c2","1","1","N/A","N/A","10","10","609","139","2024-07-18T10:16:19Z","2022-01-02T22:03:10Z","50423" +"*keylogger.x64.dll*",".{0,1000}keylogger\.x64\.dll.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","50425" +"*KeyLoggerOffline.dll*",".{0,1000}KeyLoggerOffline\.dll.{0,1000}","offensive_tool_keyword","xeno-rat","Xeno-RAT is an open-source remote access tool (RAT) developed in C# providing a comprehensive set of features for remote system management. Has features such as HVNC - live microphone - reverse proxy and much much more","T1133 - T1021.001 - T1563.002 - T1113 - T1123 - T1571 - T1090","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011","N/A","N/A","C2","https://github.com/moom825/xeno-rat","1","1","N/A","N/A","10","10","1225","323","2024-03-05T06:22:36Z","2023-10-17T06:41:56Z","50427" +"*keylogrecorder.rb*",".{0,1000}keylogrecorder\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","50428" +"*keylooger.ps1*",".{0,1000}keylooger\.ps1.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","50429" +"*keyring2john.py*",".{0,1000}keyring2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50430" +"*keystore2john.py*",".{0,1000}keystore2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50435" +"*keywa7/keywa7*",".{0,1000}keywa7\/keywa7.{0,1000}","offensive_tool_keyword","keywa7","The tool that bypasses the firewall's Application Based Rules and lets you connect to anywhere","T1090.001 - T1071.004 - T1071.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/keywa7/keywa7","1","1","N/A","N/A","6","1","61","9","2024-08-19T08:09:33Z","2024-08-05T15:27:26Z","50437" +"*keyword_obfuscation*",".{0,1000}keyword_obfuscation.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","50438" +"*kgretzky/evilginx2*",".{0,1000}kgretzky\/evilginx2.{0,1000}","offensive_tool_keyword","evilginx2","Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication","T1557.002 - T1114 - T1539","TA0001","N/A","BlackCat - COLDRIVER - Black Basta","Phishing","https://github.com/kgretzky/evilginx2","1","1","N/A","N/A","10","10","12879","2234","2025-01-21T15:16:19Z","2018-07-10T09:59:52Z","50439" +"*kgretzky/evilqr*",".{0,1000}kgretzky\/evilqr.{0,1000}","offensive_tool_keyword","evilqr","Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice","T1566.002 - T1204.001 - T1192","TA0001 - TA0005","N/A","N/A","Phishing","https://github.com/kgretzky/evilqr","1","1","N/A","N/A","N/A","3","292","45","2024-06-18T11:27:23Z","2023-06-20T12:58:09Z","50440" +"*kgretzky/pwndrop*",".{0,1000}kgretzky\/pwndrop.{0,1000}","offensive_tool_keyword","pwndrop","Self-deployable file hosting service for red teamers allowing to easily upload and share payloads over HTTP and WebDAV.","T1105 - T1071 - T1071.001 - T1090 - T1027 - T1027.005","TA0011 - TA0005 - TA0042","N/A","N/A","C2","https://github.com/kgretzky/pwndrop","1","1","N/A","N/A","10","10","2124","267","2023-02-25T05:08:15Z","2019-11-28T19:06:30Z","50441" +"*kh4sh3i/Spring-CVE*",".{0,1000}kh4sh3i\/Spring\-CVE.{0,1000}","offensive_tool_keyword","POC","POC exploit for CVE-2022-22963","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/kh4sh3i/Spring-CVE","1","1","N/A","N/A","N/A","1","14","7","2022-03-31T20:58:54Z","2022-03-31T20:19:51Z","50442" +"*khast3x/h8mail*",".{0,1000}khast3x\/h8mail.{0,1000}","offensive_tool_keyword","h8mail","Powerful and user-friendly password hunting tool.","T1581.002 - T1591 - T1590 - T1596 - T1592 - T1217.001","TA0010","N/A","N/A","Reconnaissance","https://github.com/opencubicles/h8mail","1","1","N/A","N/A","N/A","1","11","4","2019-08-19T09:46:33Z","2019-08-19T09:45:32Z","50443" +"*KidLogger-*.dmg*",".{0,1000}KidLogger\-.{0,1000}\.dmg.{0,1000}","offensive_tool_keyword","kiglogger","malware parental control software - keylogger","T1056.001 - T1113 - T1056.004","TA0006 - TA0009","N/A","N/A","Collection","https://kidlogger.net/download.html","1","1","#macos","N/A","10","10","N/A","N/A","N/A","N/A","50446" +"*Kidlogger.exe*",".{0,1000}Kidlogger\.exe.{0,1000}","offensive_tool_keyword","kiglogger","malware parental control software - keylogger","T1056.001 - T1113 - T1056.004","TA0006 - TA0009","N/A","N/A","Collection","https://kidlogger.net/download.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","50448" +"*KidLogger.net*",".{0,1000}KidLogger\.net.{0,1000}","offensive_tool_keyword","kiglogger","malware parental control software - keylogger","T1056.001 - T1113 - T1056.004","TA0006 - TA0009","N/A","N/A","Collection","https://kidlogger.net/download.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","50450" +"*kidlogger_install*",".{0,1000}kidlogger_install.{0,1000}","offensive_tool_keyword","kiglogger","malware parental control software - keylogger","T1056.001 - T1113 - T1056.004","TA0006 - TA0009","N/A","N/A","Collection","https://kidlogger.net/download.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","50453" +"*kidlogger_user.exe*",".{0,1000}kidlogger_user\.exe.{0,1000}","offensive_tool_keyword","kiglogger","malware parental control software - keylogger","T1056.001 - T1113 - T1056.004","TA0006 - TA0009","N/A","N/A","Collection","https://kidlogger.net/download.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","50454" +"*killAllNimplants*",".{0,1000}killAllNimplants.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","50459" +"*KillDefender.h*",".{0,1000}KillDefender\.h.{0,1000}","offensive_tool_keyword","KillDefenderBOF","KillDefenderBOF is a Beacon Object File PoC implementation of pwn1sher/KillDefender - kill defender","T1055.002 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/Cerbersec/KillDefenderBOF","1","1","N/A","N/A","10","3","224","30","2022-04-12T17:45:50Z","2022-02-06T21:59:03Z","50462" +"*KillDefender.x64*",".{0,1000}KillDefender\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","BOF combination of KillDefender and Backstab","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Octoberfest7/KDStab","1","1","N/A","N/A","10","10","167","37","2023-03-23T02:22:50Z","2022-03-10T06:09:52Z","50463" +"*KillDefender.x64.*",".{0,1000}KillDefender\.x64\..{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File implementation of pwn1sher's KillDefender","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Octoberfest7/KillDefender_BOF","1","1","N/A","N/A","10","10","66","15","2022-06-28T15:54:15Z","2022-02-11T07:03:59Z","50464" +"*killdefender_bof*",".{0,1000}killdefender_bof.{0,1000}","offensive_tool_keyword","cobaltstrike","BOF combination of KillDefender and Backstab","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Octoberfest7/KDStab","1","1","N/A","N/A","10","10","167","37","2023-03-23T02:22:50Z","2022-03-10T06:09:52Z","50465" +"*KillDefender_BOF*",".{0,1000}KillDefender_BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File implementation of pwn1sher's KillDefender","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Octoberfest7/KillDefender_BOF","1","1","N/A","N/A","10","10","66","15","2022-06-28T15:54:15Z","2022-02-11T07:03:59Z","50466" +"*KillDefenderBOF-main*",".{0,1000}KillDefenderBOF\-main.{0,1000}","offensive_tool_keyword","KillDefenderBOF","KillDefenderBOF is a Beacon Object File PoC implementation of pwn1sher/KillDefender - kill defender","T1055.002 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/Cerbersec/KillDefenderBOF","1","1","N/A","N/A","10","3","224","30","2022-04-12T17:45:50Z","2022-02-06T21:59:03Z","50467" +"*killprocess.py*",".{0,1000}killprocess\.py.{0,1000}","offensive_tool_keyword","mythic","Cross-platform post-exploitation HTTP Command & Control agent written in golang","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/merlin","1","1","N/A","N/A","10","10","94","16","2025-04-16T13:05:47Z","2021-01-25T12:36:46Z","50475" +"*kimi_MDPC/kimi.py*",".{0,1000}kimi_MDPC\/kimi\.py.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","50477" +"*KINGSABRI/ServerlessRedirector*",".{0,1000}KINGSABRI\/ServerlessRedirector.{0,1000}","offensive_tool_keyword","ServerlessRedirector","Serverless Redirector in various cloud vendor for red team","T1090.003 - T1095 - T1001.003","TA0010 - TA0011 - TA0008","N/A","N/A","Defense Evasion","https://github.com/KINGSABRI/ServerlessRedirector","1","1","N/A","N/A","10","1","72","10","2022-12-08T08:56:02Z","2022-12-08T07:52:49Z","50480" +"*kintercept.py*",".{0,1000}kintercept\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","50481" +"*kintercept.py*",".{0,1000}kintercept\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/SecureAuthCorp/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","50482" +"*kirbi_to_hashcat.py*",".{0,1000}kirbi_to_hashcat\.py.{0,1000}","offensive_tool_keyword","Timeroast","Timeroasting takes advantage of Windows NTP authentication mechanism allowing unauthenticated attackers to effectively request a password hash of any computer or trust account by sending an NTP request with that account's RID","T1558.003 - T1059.003 - T1078.004","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/SecuraBV/Timeroast","1","1","N/A","N/A","10","3","282","28","2023-07-04T07:12:57Z","2023-01-18T09:04:05Z","50487" +"*kirbi2john.*",".{0,1000}kirbi2john\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50488" +"*kirbi2john.py*",".{0,1000}kirbi2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50489" +"*kirbi2john.py*",".{0,1000}kirbi2john\.py.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","1","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","50490" +"*kirbikator.exe*",".{0,1000}kirbikator\.exe.{0,1000}","offensive_tool_keyword","kekeo","access the LSA (Local Security Authority) and manipulate Kerberos tickets. potentially allowing adversaries to gain unauthorized access to Active Directory resources and CIFS file shares","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/gentilkiwi/kekeo","1","1","N/A","N/A","N/A","10","1463","214","2021-12-14T10:56:48Z","2015-01-13T21:24:09Z","50491" +"*kite03/echoac-poc*",".{0,1000}kite03\/echoac\-poc.{0,1000}","offensive_tool_keyword","echoac-poc","poc stealing the Kernel's KPROCESS/EPROCESS block and writing it to a newly spawned shell to elevate its privileges to the highest possible - nt authority\system","T1068 - T1203 - T1059.003","TA0002 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/kite03/echoac-poc","1","1","N/A","N/A","8","2","138","25","2024-01-09T16:44:00Z","2023-06-28T00:52:22Z","50493" +"*kitrap0d.x86.dll*",".{0,1000}kitrap0d\.x86\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","50495" +"*kitrap0d_payload*",".{0,1000}kitrap0d_payload.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","50496" +"*kitten/basicKitten*",".{0,1000}kitten\/basicKitten.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","50498" +"*kitten_test.go*",".{0,1000}kitten_test\.go.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","50499" +"*kittens/bananaKitten*",".{0,1000}kittens\/bananaKitten.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","50501" +"*KittyStager.git*",".{0,1000}KittyStager\.git.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","50506" +"*KittyStager/cmd*",".{0,1000}KittyStager\/cmd.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","50507" +"*KittyStager/internal*",".{0,1000}KittyStager\/internal.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","50508" +"*KittyStager/kitten*",".{0,1000}KittyStager\/kitten.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","50509" +"*klezVirus/CheeseTools*",".{0,1000}klezVirus\/CheeseTools.{0,1000}","offensive_tool_keyword","CheeseTools","tools for Lateral Movement/Code Execution","T1021.006 - T1059.003 - T1105","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/klezVirus/CheeseTools","1","1","N/A","N/A","10","8","706","143","2021-08-17T20:22:56Z","2020-08-24T01:28:12Z","50518" +"*klezVirus/inceptor*",".{0,1000}klezVirus\/inceptor.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","50519" +"*klezVirus/SilentMoonwalk*",".{0,1000}klezVirus\/SilentMoonwalk.{0,1000}","offensive_tool_keyword","SilentMoonwalk","PoC Implementation of a fully dynamic call stack spoofer","T1055 - T1055.012 - T1562 - T1562.001 - T1070 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/klezVirus/SilentMoonwalk","1","1","N/A","N/A","9","8","760","100","2024-07-20T10:41:31Z","2022-12-04T13:30:33Z","50520" +"*klsecservices/rpivot*",".{0,1000}klsecservices\/rpivot.{0,1000}","offensive_tool_keyword","rpivot","socks4 reverse proxy for penetration testing","T1090.004 - T1572 - T1021.001","TA0011 - TA0002 - TA0040","N/A","N/A","C2","https://github.com/klsecservices/rpivot","1","1","N/A","N/A","10","10","589","128","2018-07-12T09:53:13Z","2016-09-07T17:25:57Z","50522" +"*kmahyyg/mremoteng-decrypt*",".{0,1000}kmahyyg\/mremoteng\-decrypt.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","1","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","50523" +"*knavesec/CredMaster*",".{0,1000}knavesec\/CredMaster.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","50525" +"*knight3xppu263m7g4ag3xlit2qxpryjwueobh7vjdc3zrscqlfu3pqd.onion*",".{0,1000}knight3xppu263m7g4ag3xlit2qxpryjwueobh7vjdc3zrscqlfu3pqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","50527" +"*known_hosts2john.py*",".{0,1000}known_hosts2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50529" +"*Koadic.persist*",".{0,1000}Koadic\.persist.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","50531" +"*koadic_load.*",".{0,1000}koadic_load\..{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","50532" +"*koadic_net.*",".{0,1000}koadic_net\..{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","50533" +"*koadic_process.*",".{0,1000}koadic_process\..{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","50534" +"*koadic_types.*",".{0,1000}koadic_types\..{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","50535" +"*koadic_util.*",".{0,1000}koadic_util\..{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","50536" +"*kost/revsocks*",".{0,1000}kost\/revsocks.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","N/A","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","50551" +"*KPortScan.exe*",".{0,1000}KPortScan\.exe.{0,1000}","offensive_tool_keyword","KPortScan","port scanner used by attackers","T1046 - T1595","TA0043 - TA0001","N/A","Dispossessor","Reconnaissance","https://github.com/stardust50578/rdp_brute","1","1","N/A","N/A","8","1","2","6","2019-05-19T14:25:06Z","2019-05-19T14:29:49Z","50555" +"*KPortScan.rar*",".{0,1000}KPortScan\.rar.{0,1000}","offensive_tool_keyword","KPortScan","port scanner used by attackers","T1046 - T1595","TA0043 - TA0001","N/A","Dispossessor","Reconnaissance","https://github.com/stardust50578/rdp_brute","1","1","N/A","N/A","8","1","2","6","2019-05-19T14:25:06Z","2019-05-19T14:29:49Z","50556" +"*KPortScan.zip*",".{0,1000}KPortScan\.zip.{0,1000}","offensive_tool_keyword","KPortScan","port scanner used by attackers","T1046 - T1595","TA0043 - TA0001","N/A","Dispossessor","Reconnaissance","https://github.com/stardust50578/rdp_brute","1","1","N/A","N/A","8","1","2","6","2019-05-19T14:25:06Z","2019-05-19T14:29:49Z","50557" +"*KPortScan3.exe*",".{0,1000}KPortScan3\.exe.{0,1000}","offensive_tool_keyword","KPortScan","port scanner used by attackers","T1046 - T1595","TA0043 - TA0001","N/A","Dispossessor","Reconnaissance","https://github.com/stardust50578/rdp_brute","1","1","N/A","N/A","8","1","2","6","2019-05-19T14:25:06Z","2019-05-19T14:29:49Z","50558" +"*kr.mirrors.cicku.me/blackarch/*/os/*",".{0,1000}kr\.mirrors\.cicku\.me\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","50559" +"*Kraken-1.2.0.zip*",".{0,1000}Kraken\-1\.2\.0\.zip.{0,1000}","offensive_tool_keyword","Kraken","Kraken is a modular multi-language webshell focused on web post-exploitation and defense evasion.","T1505 - T1547 - T1218 - T1564.001","TA0003 - TA0005 - TA0011 ","N/A","N/A","C2","https://github.com/kraken-ng/Kraken","1","1","N/A","N/A","10","10","538","47","2024-02-10T20:10:18Z","2023-02-21T10:23:55Z","50563" +"*KrakenMask-main*",".{0,1000}KrakenMask\-main.{0,1000}","offensive_tool_keyword","KrakenMask","A sleep obfuscation tool is used to encrypt the content of the .text section with RC4 (using SystemFunction032). To achieve this encryption a ROP chain is employed with QueueUserAPC and NtContinue.","T1027 - T1027.002 - T1055 - T1055.011 - T1059 - T1059.003","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/RtlDallas/KrakenMask","1","1","N/A","N/A","9","","N/A","","","","50564" +"*kraken-ng/Kraken*",".{0,1000}kraken\-ng\/Kraken.{0,1000}","offensive_tool_keyword","Kraken","Kraken is a modular multi-language webshell focused on web post-exploitation and defense evasion.","T1505 - T1547 - T1218 - T1564.001","TA0003 - TA0005 - TA0011 ","N/A","N/A","C2","https://github.com/kraken-ng/Kraken","1","1","N/A","N/A","10","10","538","47","2024-02-10T20:10:18Z","2023-02-21T10:23:55Z","50565" +"*krb2john.py*",".{0,1000}krb2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50584" +"*krb5/kerberosv5.py*",".{0,1000}krb5\/kerberosv5\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","50585" +"*krb5decoder*",".{0,1000}krb5decoder.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","50587" +"*krbcredccache.py*",".{0,1000}krbcredccache\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","50591" +"*krbjacker.py*",".{0,1000}krbjacker\.py.{0,1000}","offensive_tool_keyword","krbjack","A Kerberos AP-REQ hijacking tool with DNS unsecure updates abuse.","T1558.002 - T1552.004 - T1048.005","TA0006 - TA0007 ","N/A","N/A","Sniffing & Spoofing","https://github.com/almandin/krbjack","1","1","N/A","N/A","10","2","113","21","2025-01-22T18:12:00Z","2023-04-16T10:44:55Z","50594" +"*krbjack-main*",".{0,1000}krbjack\-main.{0,1000}","offensive_tool_keyword","krbjack","A Kerberos AP-REQ hijacking tool with DNS unsecure updates abuse.","T1558.002 - T1552.004 - T1048.005","TA0006 - TA0007 ","N/A","N/A","Sniffing & Spoofing","https://github.com/almandin/krbjack","1","1","N/A","N/A","10","2","113","21","2025-01-22T18:12:00Z","2023-04-16T10:44:55Z","50595" +"*KrbRelay*misc*",".{0,1000}KrbRelay.{0,1000}misc.{0,1000}","offensive_tool_keyword","KrbRelay","Relaying 3-headed dogs. More details at https://googleprojectzero.blogspot.com/2021/10/windows-exploitation-tricks-relaying.html and https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html","T1212 - T1558 - T1550","TA0001 - TA0004 -TA0006","N/A","Dispossessor","Exploitation tool","https://github.com/cube0x0/KrbRelay","1","1","N/A","N/A","N/A","10","907","125","2022-05-29T09:45:03Z","2022-02-14T08:21:57Z","50599" +"*KrbRelay*smb*",".{0,1000}KrbRelay.{0,1000}smb.{0,1000}","offensive_tool_keyword","KrbRelay","Relaying 3-headed dogs. More details at https://googleprojectzero.blogspot.com/2021/10/windows-exploitation-tricks-relaying.html and https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html","T1212 - T1558 - T1550","TA0001 - TA0004 -TA0006","N/A","Dispossessor","Exploitation tool","https://github.com/cube0x0/KrbRelay","1","1","N/A","N/A","N/A","10","907","125","2022-05-29T09:45:03Z","2022-02-14T08:21:57Z","50600" +"*KrbRelay*spoofing*",".{0,1000}KrbRelay.{0,1000}spoofing.{0,1000}","offensive_tool_keyword","KrbRelay","Relaying 3-headed dogs. More details at https://googleprojectzero.blogspot.com/2021/10/windows-exploitation-tricks-relaying.html and https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html","T1212 - T1558 - T1550","TA0001 - TA0004 -TA0006","N/A","Dispossessor","Exploitation tool","https://github.com/cube0x0/KrbRelay","1","1","N/A","N/A","N/A","10","907","125","2022-05-29T09:45:03Z","2022-02-14T08:21:57Z","50601" +"*KrbRelay.csproj*",".{0,1000}KrbRelay\.csproj.{0,1000}","offensive_tool_keyword","KrbRelay","Relaying 3-headed dogs. More details at https://googleprojectzero.blogspot.com/2021/10/windows-exploitation-tricks-relaying.html and https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html","T1212 - T1558 - T1550","TA0001 - TA0004 -TA0006","N/A","Dispossessor","Exploitation tool","https://github.com/cube0x0/KrbRelay","1","1","N/A","N/A","N/A","10","907","125","2022-05-29T09:45:03Z","2022-02-14T08:21:57Z","50603" +"*KrbRelay.exe*",".{0,1000}KrbRelay\.exe.{0,1000}","offensive_tool_keyword","KrbRelay","Relaying 3-headed dogs. More details at https://googleprojectzero.blogspot.com/2021/10/windows-exploitation-tricks-relaying.html and https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html","T1212 - T1558 - T1550","TA0001 - TA0004 -TA0006","N/A","Dispossessor","Exploitation tool","https://github.com/cube0x0/KrbRelay","1","1","N/A","N/A","N/A","10","907","125","2022-05-29T09:45:03Z","2022-02-14T08:21:57Z","50606" +"*KrbRelay.exe*",".{0,1000}KrbRelay\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","50607" +"*KrbRelay.sln*",".{0,1000}KrbRelay\.sln.{0,1000}","offensive_tool_keyword","KrbRelay","Relaying 3-headed dogs. More details at https://googleprojectzero.blogspot.com/2021/10/windows-exploitation-tricks-relaying.html and https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html","T1212 - T1558 - T1550","TA0001 - TA0004 -TA0006","N/A","Dispossessor","Exploitation tool","https://github.com/cube0x0/KrbRelay","1","1","N/A","N/A","N/A","10","907","125","2022-05-29T09:45:03Z","2022-02-14T08:21:57Z","50608" +"*KrbRelayUp.csproj*",".{0,1000}KrbRelayUp\.csproj.{0,1000}","offensive_tool_keyword","KrbRelayUp","a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).","T1558 - T1210","TA0004 - TA0003","N/A","Dispossessor - Back Basta","Privilege Escalation","https://github.com/Dec0ne/KrbRelayUp","1","1","N/A","N/A","10","10","1580","209","2022-08-06T12:23:58Z","2022-04-24T21:33:00Z","50610" +"*KrbRelayUp.exe*",".{0,1000}KrbRelayUp\.exe.{0,1000}","offensive_tool_keyword","KrbRelayUp","a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).","T1558 - T1210","TA0004 - TA0003","N/A","Dispossessor - Back Basta","Privilege Escalation","https://github.com/Dec0ne/KrbRelayUp","1","1","N/A","N/A","10","10","1580","209","2022-08-06T12:23:58Z","2022-04-24T21:33:00Z","50614" +"*KrbRelayUp.exe*",".{0,1000}KrbRelayUp\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","50615" +"*KrbRelayUp/1.0*",".{0,1000}KrbRelayUp\/1\.0.{0,1000}","offensive_tool_keyword","KrbRelayUp","a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).","T1558 - T1210","TA0004 - TA0003","N/A","Dispossessor - Back Basta","Privilege Escalation","https://github.com/Dec0ne/KrbRelayUp","1","1","#useragent","user-agent","10","10","1580","209","2022-08-06T12:23:58Z","2022-04-24T21:33:00Z","50617" +"*krbrelayx.git*",".{0,1000}krbrelayx\.git.{0,1000}","offensive_tool_keyword","krbrelayx","Kerberos unconstrained delegation abuse toolkit","T1558.003 - T1098","TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/dirkjanm/krbrelayx","1","1","N/A","N/A","N/A","10","1281","181","2025-01-27T09:22:54Z","2019-01-08T18:42:07Z","50619" +"*krbrelayx.py*",".{0,1000}krbrelayx\.py.{0,1000}","offensive_tool_keyword","krbrelayx","Kerberos unconstrained delegation abuse toolkit","T1558.003 - T1098","TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/dirkjanm/krbrelayx","1","1","N/A","N/A","N/A","10","1281","181","2025-01-27T09:22:54Z","2019-01-08T18:42:07Z","50621" +"*krbrelayx-master*",".{0,1000}krbrelayx\-master.{0,1000}","offensive_tool_keyword","krbrelayx","Kerberos unconstrained delegation abuse toolkit","T1558.003 - T1098","TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/dirkjanm/krbrelayx","1","1","N/A","N/A","N/A","10","1281","181","2025-01-27T09:22:54Z","2019-01-08T18:42:07Z","50622" +"*krbroast-pcap2hashcat.py*",".{0,1000}krbroast\-pcap2hashcat\.py.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","1","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","50623" +"*KRBUACBypass.csproj*",".{0,1000}KRBUACBypass\.csproj.{0,1000}","offensive_tool_keyword","KRBUACBypass","UAC Bypass By Abusing Kerberos Tickets","T1548.002 - T1558 - T1558.003","TA0004 - TA0006","N/A","N/A","Defense Evasion","https://github.com/wh0amitz/KRBUACBypass","1","1","N/A","N/A","8","5","496","62","2023-08-10T02:51:59Z","2023-07-27T12:08:12Z","50627" +"*KRBUACBypass.exe*",".{0,1000}KRBUACBypass\.exe.{0,1000}","offensive_tool_keyword","KRBUACBypass","UAC Bypass By Abusing Kerberos Tickets","T1548.002 - T1558 - T1558.003","TA0004 - TA0006","N/A","N/A","Defense Evasion","https://github.com/wh0amitz/KRBUACBypass","1","1","N/A","N/A","8","5","496","62","2023-08-10T02:51:59Z","2023-07-27T12:08:12Z","50628" +"*KRBUACBypass.sln*",".{0,1000}KRBUACBypass\.sln.{0,1000}","offensive_tool_keyword","KRBUACBypass","UAC Bypass By Abusing Kerberos Tickets","T1548.002 - T1558 - T1558.003","TA0004 - TA0006","N/A","N/A","Defense Evasion","https://github.com/wh0amitz/KRBUACBypass","1","1","N/A","N/A","8","5","496","62","2023-08-10T02:51:59Z","2023-07-27T12:08:12Z","50629" +"*kstowell@codejockeys.com*",".{0,1000}kstowell\@codejockeys\.com.{0,1000}","offensive_tool_keyword","gh0st","Malware RAT with keylogger - dll injection - C2 - Remote control","T1204.002 - T1071.001 - T1027 - T1036.005 - T1055.001 - T1005 - T1056.001 - T1074.001 - T1105 - T1562.001 - T1543.003 - T1547.001 - T1571 - T1573.001 - T1106 - T1219","TA0002 - TA0003 - TA0004 - TA0008 - TA0009 - TA0010 - TA0011","GhostRAT","N/A","Malware","https://github.com/sin5678/gh0st","1","1","#email","N/A","10","6","508","274","2013-05-08T21:17:26Z","2012-10-05T06:25:36Z","50633" +"*ktsuss-lpe.sh*",".{0,1000}ktsuss\-lpe\.sh.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","50634" +"*kubeletAttack.json*",".{0,1000}kubeletAttack\.json.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","50635" +"*kubesploitAgent-Darwin*",".{0,1000}kubesploitAgent\-Darwin.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","#linux","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","50637" +"*kubesploitAgent-Linux*",".{0,1000}kubesploitAgent\-Linux.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","#linux","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","50638" +"*kubesploit-main*",".{0,1000}kubesploit\-main.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","50639" +"*kubesploitServer-Darwin*",".{0,1000}kubesploitServer\-Darwin.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","#linux","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","50640" +"*kubesploitServer-Linux*",".{0,1000}kubesploitServer\-Linux.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","#linux","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","50641" +"*kubestroyer_linux_x64*",".{0,1000}kubestroyer_linux_x64.{0,1000}","offensive_tool_keyword","Kubestroyer","Kubestroyer aims to exploit Kubernetes clusters misconfigurations and be the swiss army knife of your Kubernetes pentests","T1588.002 - T1596 - T1552.004","TA0005 - TA0007","N/A","N/A","Exploitation tool","https://github.com/Rolix44/Kubestroyer","1","1","#linux","N/A","10","4","359","22","2024-07-26T06:33:00Z","2022-09-15T13:31:21Z","50644" +"*kubestroyer_macos_arm64*",".{0,1000}kubestroyer_macos_arm64.{0,1000}","offensive_tool_keyword","Kubestroyer","Kubestroyer aims to exploit Kubernetes clusters misconfigurations and be the swiss army knife of your Kubernetes pentests","T1588.002 - T1596 - T1552.004","TA0005 - TA0007","N/A","N/A","Exploitation tool","https://github.com/Rolix44/Kubestroyer","1","1","N/A","N/A","10","4","359","22","2024-07-26T06:33:00Z","2022-09-15T13:31:21Z","50645" +"*kubestroyer_macos_x64*",".{0,1000}kubestroyer_macos_x64.{0,1000}","offensive_tool_keyword","Kubestroyer","Kubestroyer aims to exploit Kubernetes clusters misconfigurations and be the swiss army knife of your Kubernetes pentests","T1588.002 - T1596 - T1552.004","TA0005 - TA0007","N/A","N/A","Exploitation tool","https://github.com/Rolix44/Kubestroyer","1","1","N/A","N/A","10","4","359","22","2024-07-26T06:33:00Z","2022-09-15T13:31:21Z","50646" +"*kubestroyer_windows_x64*",".{0,1000}kubestroyer_windows_x64.{0,1000}","offensive_tool_keyword","Kubestroyer","Kubestroyer aims to exploit Kubernetes clusters misconfigurations and be the swiss army knife of your Kubernetes pentests","T1588.002 - T1596 - T1552.004","TA0005 - TA0007","N/A","N/A","Exploitation tool","https://github.com/Rolix44/Kubestroyer","1","1","N/A","N/A","10","4","359","22","2024-07-26T06:33:00Z","2022-09-15T13:31:21Z","50647" +"*Kudaes/Dumpy*",".{0,1000}Kudaes\/Dumpy.{0,1000}","offensive_tool_keyword","Dumpy","Reuse open handles to dynamically dump LSASS","T1003.001 - T1055.001 - T1083","TA0006","N/A","N/A","Credential Access","https://github.com/Kudaes/Dumpy","1","1","N/A","N/A","10","3","243","24","2024-04-04T07:42:26Z","2021-10-13T21:54:59Z","50649" +"*Kudaes/Elevator*",".{0,1000}Kudaes\/Elevator.{0,1000}","offensive_tool_keyword","Elevator","UAC bypass by abusing RPC and debug objects.","T1548.002","TA0004","N/A","N/A","Privilege Escalation","https://github.com/Kudaes/Elevator","1","1","N/A","N/A","10","7","614","69","2023-10-19T08:51:09Z","2022-08-25T21:39:28Z","50650" +"*kuhl_m_dpapi_chrome.c*",".{0,1000}kuhl_m_dpapi_chrome\.c.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","50651" +"*kuhl_m_lsadump.c*",".{0,1000}kuhl_m_lsadump\.c.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","50652" +"*kuhl_m_sekurlsa_nt6.c*",".{0,1000}kuhl_m_sekurlsa_nt6\.c.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","50656" +"*kuhl_m_sekurlsa_nt6.h*",".{0,1000}kuhl_m_sekurlsa_nt6\.h.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","50657" +"*kuhl_m_sekurlsa_packages.c*",".{0,1000}kuhl_m_sekurlsa_packages\.c.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","50658" +"*kuhl_m_sekurlsa_packages.h*",".{0,1000}kuhl_m_sekurlsa_packages\.h.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","50659" +"*kuhl_m_sekurlsa_utils.c*",".{0,1000}kuhl_m_sekurlsa_utils\.c.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","50660" +"*kuhl_m_sekurlsa_utils.c*",".{0,1000}kuhl_m_sekurlsa_utils\.c.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","50661" +"*kuhl_m_sekurlsa_utils.h*",".{0,1000}kuhl_m_sekurlsa_utils\.h.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","50662" +"*kwallet2john.py*",".{0,1000}kwallet2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50664" +"*kyleavery/AceLdr*",".{0,1000}kyleavery\/AceLdr.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike UDRL for memory scanner evasion.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/kyleavery/AceLdr","1","1","N/A","N/A","10","10","925","164","2024-06-04T16:45:42Z","2022-08-11T00:06:09Z","50665" +"*kyleavery/inject-assembly*",".{0,1000}kyleavery\/inject\-assembly.{0,1000}","offensive_tool_keyword","cobaltstrike","Inject .NET assemblies into an existing process","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/kyleavery/inject-assembly","1","1","N/A","N/A","10","10","494","74","2022-01-19T19:15:11Z","2022-01-03T15:38:10Z","50666" +"*kyleavery/pendulum*",".{0,1000}kyleavery\/pendulum.{0,1000}","offensive_tool_keyword","pendulum","Linux Sleep Obfuscation","T1027 - T1036","TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/kyleavery/pendulum","1","1","#linux","N/A","9","1","95","11","2024-01-07T20:33:01Z","2024-01-07T20:32:38Z","50667" +"*l0n3m4n/CVE-2024-22274-RCE*",".{0,1000}l0n3m4n\/CVE\-2024\-22274\-RCE.{0,1000}","offensive_tool_keyword","POC","PoC - Authenticated Remote Code Execution in VMware vCenter Server (CVE-2024-22274 Exploit)","T1213 - T1059 - T1056 - T1078 - T1578","TA0001 - TA0002 - TA0008 - TA0009","N/A","N/A","Lateral Movement","https://github.com/l0n3m4n/CVE-2024-22274-RCE","1","1","N/A","N/A","10","1","42","8","2024-07-16T23:22:14Z","2024-07-15T07:26:59Z","50675" +"*L0phtCrack*",".{0,1000}L0phtCrack.{0,1000}","offensive_tool_keyword","L0phtCrack","L0phtCrack attempts to crack Windows passwords from hashes which it can obtain (given proper access) from stand-alone Windows workstations. networked servers. primary domain controllers. or Active Directory. In some cases it can sniff the hashes off the wire. It also has numerous methods of generating password guesses (dictionary. brute force. etc). LC5 was discontinued by Symantec in 2006. then re-acquired by the original L0pht guys and reborn as LC6 in 2009. For free alternatives. consider ophcrack. Cain and Abel. or John the Ripper. For downloads and more information. visit the L0phtCrack homepage.","T1003 - T1110 - T1212 - T1552 - T1609","TA0001 - TA0002 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Credential Access","http://www.l0phtcrack.com/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","50676" +"*l3m0n/WinPirate*",".{0,1000}l3m0n\/WinPirate.{0,1000}","offensive_tool_keyword","WinPirate","automated sticky keys backdoor + credentials harvesting","T1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003","TA0003 - TA0005 - TA0006","N/A","N/A","Persistence","https://github.com/l3m0n/WinPirate","1","1","N/A","N/A","9","1","13","32","2016-07-17T20:02:07Z","2016-07-18T03:40:13Z","50678" +"*l55ysq5qjpin2vq23ul3gc3h62vp4wvenl7ov6fcn65vir7kc7gb5fyd.onion*",".{0,1000}l55ysq5qjpin2vq23ul3gc3h62vp4wvenl7ov6fcn65vir7kc7gb5fyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","50682" +"*Ladon911*.ps1",".{0,1000}Ladon911.{0,1000}\.ps1","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","50770" +"*Ladon911.exe*",".{0,1000}Ladon911\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","50771" +"*Ladon911_*.rar*",".{0,1000}Ladon911_.{0,1000}\.rar.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","50772" +"*LadonExp.exe*",".{0,1000}LadonExp\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","50773" +"*LadonGUI.exe*",".{0,1000}LadonGUI\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","50774" +"*LadonLib.rar*",".{0,1000}LadonLib\.rar.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","50775" +"*Ladon-N20.exe*",".{0,1000}Ladon\-N20\.exe.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","50776" +"*Ladon-N40.exe*",".{0,1000}Ladon\-N40\.exe.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","50777" +"*LadonStudy.exe*",".{0,1000}LadonStudy\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","50778" +"*lallousz-x86@yahoo.com*",".{0,1000}lallousz\-x86\@yahoo\.com.{0,1000}","offensive_tool_keyword","prefetch-tool","Windows KASLR bypass using prefetch side-channel CVE-2024-21345 exploitation","T1564.007","TA0004","N/A","N/A","Privilege Escalation","https://github.com/exploits-forsale/prefetch-tool","1","1","#email","N/A","8","1","90","10","2024-04-26T05:40:32Z","2024-04-26T05:00:27Z","50780" +"*lambda__backdoor_new_sec_groups*",".{0,1000}lambda__backdoor_new_sec_groups.{0,1000}","offensive_tool_keyword","pacu","The AWS exploitation framework designed for testing the security of Amazon Web Services environments.","T1136.003 - T1190 - T1078.004","TA0006 - TA0001","N/A","Scattered Spider*","Framework","https://github.com/RhinoSecurityLabs/pacu","1","1","N/A","N/A","9","10","4651","731","2025-03-20T21:08:57Z","2018-06-13T21:58:59Z","50781" +"*lan_sw_port_scan.json*",".{0,1000}lan_sw_port_scan\.json.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","50784" +"*landhb/HideProcess*",".{0,1000}HideProcess.{0,1000}","offensive_tool_keyword","HideProcess","process injection rootkit","T1055 - T1055.012 - T1055.013 - T1055.015 - T1055.017","TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/landhb/HideProcess","1","1","N/A","N/A","N/A","7","669","117","2019-03-26T03:35:57Z","2017-03-07T01:30:15Z","50785" +"*landxxeaf2hoyl2jvcwuazypt6imcsbmhb7kx3x33yhparvtmkatpaad.onion*",".{0,1000}landxxeaf2hoyl2jvcwuazypt6imcsbmhb7kx3x33yhparvtmkatpaad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","50786" +"*LANs.py*",".{0,1000}LANs\.py.{0,1000}","offensive_tool_keyword","LANs.py","Automatically find the most active WLAN users then spy on one of them and/or inject arbitrary HTML/JS into pages they visit","T1538.001 - T1539.003 - T1040 - T1057 - T1134 - T1218 - T1053 - T1055 - T1059.001 - T1059.003","TA0007 - TA0006 - TA0003 - TA0002 - TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/DanMcInerney/LANs.py","1","1","N/A","N/A","N/A","10","2599","489","2021-07-31T21:33:37Z","2013-01-03T19:33:52Z","50788" +"*laps_dump*",".{0,1000}laps_dump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","50793" +"*LapsAllowedAdminGroups.txt*",".{0,1000}LapsAllowedAdminGroups\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","50794" +"*LAPSDecrypt.*",".{0,1000}LAPSDecrypt\..{0,1000}","offensive_tool_keyword","LAPSDecrypt","Quick POC looking at how encryption works for LAPS (v2)","T1552.004","TA0003","N/A","N/A","Credential Access","https://gist.github.com/xpn/23dc5b6c260a7571763ca8ca745c32f4","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","50795" +"*Lapsdump.cna*",".{0,1000}Lapsdump\.cna.{0,1000}","offensive_tool_keyword","C2-Tool-Collection","A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques","T1055 - T1218 - T1059 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","C2","https://github.com/outflanknl/C2-Tool-Collection","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","50796" +"*Lapsdump.exe*",".{0,1000}Lapsdump\.exe.{0,1000}","offensive_tool_keyword","C2-Tool-Collection","A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques","T1055 - T1218 - T1059 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","C2","https://github.com/outflanknl/C2-Tool-Collection","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","50797" +"*LAPSDumper-main*",".{0,1000}LAPSDumper\-main.{0,1000}","offensive_tool_keyword","LAPSDumper","Dumping LAPS from Python","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/n00py/LAPSDumper","1","1","N/A","N/A","10","3","267","35","2022-12-07T18:35:28Z","2020-12-19T05:15:10Z","50798" +"*LapsPasswords.txt*",".{0,1000}LapsPasswords\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","50799" +"*LAPSToolkit*",".{0,1000}LAPSToolkit.{0,1000}","offensive_tool_keyword","LAPSToolkit","Functions written in PowerShell that leverage PowerView to audit and attack Active Directory environments that have deployed Microsofts Local Administrator Password Solution (LAPS). It includes finding groups specifically delegated by sysadmins. finding users with All Extended Rights that can view passwords. and viewing all computers with LAPS enabled","T1087.001 - T1069 - T1069.003 - T1069.007 - T1069.002 - T1069.001","TA0007 - TA0008 - TA0009","N/A","Scattered Spider*","Discovery","https://github.com/leoloobeek/LAPSToolkit","1","1","N/A","N/A","10","9","859","119","2018-01-31T14:45:35Z","2016-04-27T00:06:20Z","50800" +"*LAPSToolkit.ps1*",".{0,1000}LAPSToolkit\.ps1.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","50801" +"*LAPSToolkit.ps1*",".{0,1000}LAPSToolkit\.ps1.{0,1000}","offensive_tool_keyword","LAPSToolkit","Functions written in PowerShell that leverage PowerView to audit and attack Active Directory environments that have deployed Microsofts Local Administrator Password Solution (LAPS). It includes finding groups specifically delegated by sysadmins. finding users with All Extended Rights that can view passwords. and viewing all computers with LAPS enabled","T1087.001 - T1069 - T1069.003 - T1069.007 - T1069.002 - T1069.001","TA0007 - TA0008 - TA0009","N/A","Scattered Spider*","Discovery","https://github.com/leoloobeek/LAPSToolkit","1","1","N/A","N/A","10","9","859","119","2018-01-31T14:45:35Z","2016-04-27T00:06:20Z","50802" +"*LaresLLC/SlinkyCat*",".{0,1000}LaresLLC\/SlinkyCat.{0,1000}","offensive_tool_keyword","SlinkyCat","This script performs a series of AD enumeration tasks","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/LaresLLC/SlinkyCat","1","1","N/A","AD Enumeration","7","1","79","8","2023-07-12T15:29:31Z","2023-07-03T23:44:18Z","50803" +"*LasCC/Hack-Tools*",".{0,1000}LasCC\/Hack\-Tools.{0,1000}","offensive_tool_keyword","hack-tools","The all-in-one Red Team browser extension for Web Pentester","T1059.007 - T1505 - T1068 - T1216 - T1547.009","TA0002 - TA0001 - TA0009","N/A","N/A","Vulnerability Scanner","https://github.com/LasCC/Hack-Tools","1","1","N/A","N/A","9","10","6045","678","2025-01-05T23:10:49Z","2020-06-22T21:42:16Z","50804" +"*lastpass.x86*",".{0,1000}lastpass\.x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","50808" +"*lastpass/process_lp_files.py*",".{0,1000}lastpass\/process_lp_files\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","50809" +"*lastpass_sniffed_fmt_plug*",".{0,1000}lastpass_sniffed_fmt_plug.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50810" +"*lastpass2john.py*",".{0,1000}lastpass2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50811" +"*Lateral/DCom.cs*",".{0,1000}Lateral\/DCom\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","50812" +"*Lateral/PSExec.cs*",".{0,1000}Lateral\/PSExec\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","50813" +"*Lateral/SMBClient.cs*",".{0,1000}Lateral\/SMBClient\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","50814" +"*Lateral/SMBClientDelete.cs*",".{0,1000}Lateral\/SMBClientDelete\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","50815" +"*Lateral/SMBClientGet.cs*",".{0,1000}Lateral\/SMBClientGet\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","50816" +"*Lateral/SMBClientPut.cs*",".{0,1000}Lateral\/SMBClientPut\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","50817" +"*Lateral/WMIExec.cs*",".{0,1000}Lateral\/WMIExec\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","50818" +"*lateral_wmi.py*",".{0,1000}lateral_wmi\.py.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","50819" +"*LateralMovement_*_Exploit*.py",".{0,1000}LateralMovement_.{0,1000}_Exploit.{0,1000}\.py","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","50820" +"*LateralMovement_ExploitationOfRemoteServices_AuxiliaryMs17010.py*",".{0,1000}LateralMovement_ExploitationOfRemoteServices_AuxiliaryMs17010\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","50821" +"*LateralMovement_ExploitationOfRemoteServices_MS17010.py*",".{0,1000}LateralMovement_ExploitationOfRemoteServices_MS17010\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","50822" +"*LateralMovement_Other_Ladon.py*",".{0,1000}LateralMovement_Other_Ladon\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","50823" +"*LateralMovement_PassTheHash_ByInvokeWMIExec.py*",".{0,1000}LateralMovement_PassTheHash_ByInvokeWMIExec\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","50824" +"*LateralMovement_PassTheHash_ByWmi.py*",".{0,1000}LateralMovement_PassTheHash_ByWmi\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","50825" +"*LateralMovement_PassTheTicket_ByPsexec.py*",".{0,1000}LateralMovement_PassTheTicket_ByPsexec\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","50826" +"*LateralMovement_PassTheTicket_BySharpwmi.py*",".{0,1000}LateralMovement_PassTheTicket_BySharpwmi\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","50827" +"*LateralMovement_PassTheTicket_ByWmi.py*",".{0,1000}LateralMovement_PassTheTicket_ByWmi\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","50828" +"*LaunchExploitMode.ps1*",".{0,1000}LaunchExploitMode\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","50838" +"*LaunchPreCompromise.ps1*",".{0,1000}LaunchPreCompromise\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","50840" +"*lawrenceamer/dns-black-cat*",".{0,1000}lawrenceamer\/dns\-black\-cat.{0,1000}","offensive_tool_keyword","dns-black-cat","Multi platform toolkit for an interactive DNS shell commands exfiltration - by using DNS-Cat you will be able to execute system commands in shell mode over DNS protocol","T1140 - T1048.003 - T1071.004","TA0011 - TA0040 - TA0001","N/A","N/A","C2","https://github.com/lawrenceamer/dns-black-cat","1","1","N/A","N/A","10","10","114","20","2022-09-15T18:07:05Z","2021-02-13T11:31:22Z","50841" +"*lawrenceamer/Tchopper*",".{0,1000}lawrenceamer\/Tchopper.{0,1000}","offensive_tool_keyword","Tchopper","conduct Lateral Movement attack by leveraging unfiltered services display name to smuggle binaries as chunks into the target machine","T1021 - T1564","TA0008 - TA0005","N/A","N/A","Lateral Movement","https://github.com/lawrenceamer/Tchopper","1","1","N/A","N/A","9","1","54","7","2021-06-14T08:27:31Z","2021-06-08T15:51:14Z","50842" +"*layer8secure/SilentHound*",".{0,1000}layer8secure\/SilentHound.{0,1000}","offensive_tool_keyword","SilentHound","Quietly enumerate an Active Directory Domain via LDAP parsing users + admins + groups...","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/layer8secure/SilentHound","1","1","N/A","AD Enumeration","7","5","489","47","2023-01-23T20:41:55Z","2022-07-01T13:49:24Z","50843" +"*Lazagne*Passwords.txt*",".{0,1000}Lazagne.{0,1000}Passwords\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","50844" +"*Lazagne.exe*",".{0,1000}Lazagne\.exe.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","50846" +"*laZagne.exe*",".{0,1000}laZagne\.exe.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","50847" +"*Lazagne.py*",".{0,1000}Lazagne\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","50848" +"*LaZagneForensic*",".{0,1000}LaZagneForensic.{0,1000}","offensive_tool_keyword","LaZagneForensic","Windows passwords decryption from dump files","T1003 - T1081 - T1082","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/AlessandroZ/LaZagneForensic","1","1","N/A","N/A","N/A","5","498","111","2023-02-02T16:36:21Z","2018-02-01T15:44:31Z","50852" +"*LaZagne-master.zip*",".{0,1000}LaZagne\-master\.zip.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","50853" +"*lazynmap.sh*",".{0,1000}lazynmap\.sh.{0,1000}","offensive_tool_keyword","LALIN","this script automatically install any package for pentest with uptodate tools . and lazy command for run the tools like lazynmap . install another and update to new","T1588","N/A","N/A","N/A","Exploitation tool","https://github.com/screetsec/LALIN","1","1","N/A","N/A","N/A","4","366","150","2017-04-13T13:47:21Z","2016-06-10T07:53:49Z","50854" +"*lazypariah.svg*",".{0,1000}lazypariah\.svg.{0,1000}","offensive_tool_keyword","LAZYPARIAH","LAZYPARIAH - A Tool For Generating Reverse Shell Payloads On The Fly","T1059 - T1566 - T1212 - T1574","TA0002 - TA0003 - TA0008","N/A","N/A","Resource Development","https://github.com/octetsplicer/LAZYPARIAH","1","1","N/A","N/A","N/A","2","140","28","2022-06-18T08:59:45Z","2020-11-20T05:08:36Z","50856" +"*lc65fb3wrvox6xlyn4hklwjcojau55diqxxylqs4qsfng23ftzijnxad.onion*",".{0,1000}lc65fb3wrvox6xlyn4hklwjcojau55diqxxylqs4qsfng23ftzijnxad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","50857" +"*L-codes/pwcrack-framework*",".{0,1000}L\-codes\/pwcrack\-framework.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","50861" +"*ldap_enums.go*",".{0,1000}ldap_enums\.go.{0,1000}","offensive_tool_keyword","adalanche","Active Directory ACL Visualizer and Explorer - who's really Domain Admin?","T1484 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/lkarlslund/Adalanche","1","1","N/A","AD Enumeration","10","10","1908","184","2025-03-25T13:01:45Z","2020-10-07T10:07:22Z","50866" +"*ldap_shell.py*",".{0,1000}ldap_shell\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","50867" +"*ldap3.git@powerview.py*",".{0,1000}ldap3\.git\@powerview\.py.{0,1000}","offensive_tool_keyword","powerview","PowerView.py is an alternative for the awesome original PowerView.ps1","T1046 - T1087.001 - T1016","TA0007 - TA0008 - TA0009","N/A","N/A","Discovery","https://github.com/aniqfakhrul/powerview.py","1","1","N/A","N/A","10","7","622","66","2025-04-22T09:01:39Z","2022-06-19T16:13:04Z","50868" +"*ldapasn1.py*",".{0,1000}ldapasn1\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","50869" +"*ldapattack.py*",".{0,1000}ldapattack\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","50870" +"*ldapattack.py*",".{0,1000}ldapattack\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","50871" +"*ldapdomaindump*",".{0,1000}ldapdomaindump.{0,1000}","offensive_tool_keyword","ldapdomaindump","Active Directory information dumper via LDAP","T1087 - T1005 - T1016","TA0007","N/A","EMBER BEAR","Discovery","https://github.com/dirkjanm/ldapdomaindump","1","1","N/A","N/A","10","10","1242","201","2025-04-06T13:31:57Z","2016-05-24T18:46:56Z","50873" +"*LDAPDomainDump*",".{0,1000}LDAPDomainDump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","50874" +"*ldapdomaindump.zip*",".{0,1000}ldapdomaindump\.zip.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","50875" +"*LdapMiner*",".{0,1000}LdapMiner.{0,1000}","offensive_tool_keyword","ldapminer","This is a tool I wrote to collect information from different LDAP Server implementation. This was written in C with the Netscape C","T1016 - T1018 - T1021 - T1046 - T1056 - T1069 - T1078 - T1087 - T1114 - T1482 - T1526 - T1597","TA0007","N/A","N/A","Discovery","https://sourceforge.net/projects/ldapminer/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","50877" +"*ldapnomnom*-obfuscated*",".{0,1000}ldapnomnom.{0,1000}\-obfuscated.{0,1000}","offensive_tool_keyword","ldapnomnom","Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)","T1110.003 - T1205","TA0007","N/A","N/A","Discovery","https://github.com/lkarlslund/ldapnomnom","1","1","N/A","N/A","6","10","1030","80","2024-11-09T10:15:13Z","2022-09-18T10:35:09Z","50880" +"*ldapnomnom-darwin-*",".{0,1000}ldapnomnom\-darwin\-.{0,1000}","offensive_tool_keyword","ldapnomnom","Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)","T1110.003 - T1205","TA0007","N/A","N/A","Discovery","https://github.com/lkarlslund/ldapnomnom","1","1","#linux","N/A","6","10","1030","80","2024-11-09T10:15:13Z","2022-09-18T10:35:09Z","50881" +"*ldapnomnom-linux-*",".{0,1000}ldapnomnom\-linux\-.{0,1000}","offensive_tool_keyword","ldapnomnom","Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)","T1110.003 - T1205","TA0007","N/A","N/A","Discovery","https://github.com/lkarlslund/ldapnomnom","1","1","#linux","N/A","6","10","1030","80","2024-11-09T10:15:13Z","2022-09-18T10:35:09Z","50882" +"*ldapnomnom-main*",".{0,1000}ldapnomnom\-main.{0,1000}","offensive_tool_keyword","ldapnomnom","Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)","T1110.003 - T1205","TA0007","N/A","N/A","Discovery","https://github.com/lkarlslund/ldapnomnom","1","1","N/A","N/A","6","10","1030","80","2024-11-09T10:15:13Z","2022-09-18T10:35:09Z","50883" +"*ldapnomnom-windows-386.exe*",".{0,1000}ldapnomnom\-windows\-386\.exe.{0,1000}","offensive_tool_keyword","ldapnomnom","Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)","T1110.003 - T1205","TA0007","N/A","N/A","Discovery","https://github.com/lkarlslund/ldapnomnom","1","1","N/A","N/A","6","10","1030","80","2024-11-09T10:15:13Z","2022-09-18T10:35:09Z","50884" +"*ldapnomnom-windows-amd64.exe*",".{0,1000}ldapnomnom\-windows\-amd64\.exe.{0,1000}","offensive_tool_keyword","ldapnomnom","Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)","T1110.003 - T1205","TA0007","N/A","N/A","Discovery","https://github.com/lkarlslund/ldapnomnom","1","1","N/A","N/A","6","10","1030","80","2024-11-09T10:15:13Z","2022-09-18T10:35:09Z","50885" +"*ldapnomnom-windows-arm64.exe*",".{0,1000}ldapnomnom\-windows\-arm64\.exe.{0,1000}","offensive_tool_keyword","ldapnomnom","Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)","T1110.003 - T1205","TA0007","N/A","N/A","Discovery","https://github.com/lkarlslund/ldapnomnom","1","1","N/A","N/A","6","10","1030","80","2024-11-09T10:15:13Z","2022-09-18T10:35:09Z","50886" +"*LDAP-Password-Hunter*",".{0,1000}LDAP\-Password\-Hunter.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/oldboy21/LDAP-Password-Hunter","1","1","N/A","N/A","10","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","50887" +"*ldaprelayclient.py*",".{0,1000}ldaprelayclient\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","50888" +"*ldaprelayclient.py*",".{0,1000}ldaprelayclient\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","50889" +"*LdapRelayScan.py*",".{0,1000}LdapRelayScan\.py.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","50890" +"*LdapRelayScan.py*",".{0,1000}LdapRelayScan\.py.{0,1000}","offensive_tool_keyword","LdapRelayScan","Check for LDAP protections regarding the relay of NTLM authentication","T1557","TA0001 - TA0006","N/A","N/A","Reconnaissance","https://github.com/zyn3rgy/LdapRelayScan","1","1","N/A","N/A","8","5","492","70","2024-11-19T21:11:53Z","2022-01-16T06:50:44Z","50891" +"*LdapRelayScan-main*",".{0,1000}LdapRelayScan\-main.{0,1000}","offensive_tool_keyword","LdapRelayScan","Check for LDAP protections regarding the relay of NTLM authentication","T1557","TA0001 - TA0006","N/A","N/A","Reconnaissance","https://github.com/zyn3rgy/LdapRelayScan","1","1","N/A","N/A","8","5","492","70","2024-11-19T21:11:53Z","2022-01-16T06:50:44Z","50892" +"*ldapsearchad.py*",".{0,1000}ldapsearchad\.py.{0,1000}","offensive_tool_keyword","ldapsearch-ad","Python3 script to quickly get various information from a domain controller through his LDAP service.","T1018 - T1087 - T1069","TA0007 - TA0002 - TA0008","N/A","N/A","Reconnaissance","https://github.com/yaap7/ldapsearch-ad","1","1","#linux #windows","N/A","5","3","215","36","2024-12-10T17:00:02Z","2019-12-08T00:25:57Z","50895" +"*ldapsearch-ad.py*",".{0,1000}ldapsearch\-ad\.py.{0,1000}","offensive_tool_keyword","ldapsearch-ad","Python3 script to quickly get various information from a domain controller through his LDAP service.","T1018 - T1087 - T1069","TA0007 - TA0002 - TA0008","N/A","N/A","Reconnaissance","https://github.com/yaap7/ldapsearch-ad","1","1","#linux #windows","N/A","5","3","215","36","2024-12-10T17:00:02Z","2019-12-08T00:25:57Z","50896" +"*LdapSignCheck.exe*",".{0,1000}LdapSignCheck\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File & C# project to check LDAP signing","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/cube0x0/LdapSignCheck","1","1","N/A","N/A","10","10","189","25","2024-08-07T09:32:20Z","2022-02-24T20:25:31Z","50900" +"*LdapSignCheck.Natives*",".{0,1000}LdapSignCheck\.Natives.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File & C# project to check LDAP signing","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/cube0x0/LdapSignCheck","1","1","N/A","N/A","10","10","189","25","2024-08-07T09:32:20Z","2022-02-24T20:25:31Z","50901" +"*LdapSignCheck.sln*",".{0,1000}LdapSignCheck\.sln.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File & C# project to check LDAP signing","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/cube0x0/LdapSignCheck","1","1","N/A","N/A","10","10","189","25","2024-08-07T09:32:20Z","2022-02-24T20:25:31Z","50902" +"*ldapsigncheck.x64.*",".{0,1000}ldapsigncheck\.x64\..{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File & C# project to check LDAP signing","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/cube0x0/LdapSignCheck","1","1","N/A","N/A","10","10","189","25","2024-08-07T09:32:20Z","2022-02-24T20:25:31Z","50903" +"*ldapsigncheck.x86.*",".{0,1000}ldapsigncheck\.x86\..{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File & C# project to check LDAP signing","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/cube0x0/LdapSignCheck","1","1","N/A","N/A","10","10","189","25","2024-08-07T09:32:20Z","2022-02-24T20:25:31Z","50904" +"*LDAPWordlistHarvester.ps1*",".{0,1000}LDAPWordlistHarvester\.ps1.{0,1000}","offensive_tool_keyword","LDAPWordlistHarvester","A tool to generate a wordlist from the information present in LDAP in order to crack passwords of domain accounts.","T1210.001 - T1087.003 - T1110","TA0001 - TA0006 - TA0007","N/A","Black Basta","Credential Access","https://github.com/p0dalirius/LDAPWordlistHarvester","1","1","N/A","N/A","5","","N/A","","","","50905" +"*LDAPWordlistHarvester.py*",".{0,1000}LDAPWordlistHarvester\.py.{0,1000}","offensive_tool_keyword","LDAPWordlistHarvester","A tool to generate a wordlist from the information present in LDAP in order to crack passwords of domain accounts.","T1210.001 - T1087.003 - T1110","TA0001 - TA0006 - TA0007","N/A","Black Basta","Credential Access","https://github.com/p0dalirius/LDAPWordlistHarvester","1","1","N/A","N/A","5","","N/A","","","","50906" +"*LDAPWordlistHarvester-main*",".{0,1000}LDAPWordlistHarvester\-main.{0,1000}","offensive_tool_keyword","LDAPWordlistHarvester","A tool to generate a wordlist from the information present in LDAP in order to crack passwords of domain accounts.","T1210.001 - T1087.003 - T1110","TA0001 - TA0006 - TA0007","N/A","Black Basta","Credential Access","https://github.com/p0dalirius/LDAPWordlistHarvester","1","1","N/A","N/A","5","","N/A","","","","50907" +"*ldd2bloodhound*",".{0,1000}ldd2bloodhound.{0,1000}","offensive_tool_keyword","ldapdomaindump","Active Directory information dumper via LDAP","T1087 - T1005 - T1016","TA0007","N/A","EMBER BEAR","Discovery","https://github.com/dirkjanm/ldapdomaindump","1","1","N/A","N/A","10","10","1242","201","2025-04-06T13:31:57Z","2016-05-24T18:46:56Z","50908" +"*ldeep*activedirectory.py*",".{0,1000}ldeep.{0,1000}activedirectory\.py.{0,1000}","offensive_tool_keyword","ldeep","In-depth ldap enumeration utility","T1087.002 - T1018 - T1482 - T1083","TA0007 - TA0008 - TA0009","N/A","N/A","Reconnaissance","https://github.com/franc-pentest/ldeep","1","1","N/A","N/A","5","5","465","54","2025-03-02T18:43:27Z","2018-10-22T18:21:44Z","50911" +"*ldeep*ldap_activedirectory.py*",".{0,1000}ldeep.{0,1000}ldap_activedirectory\.py.{0,1000}","offensive_tool_keyword","ldeep","In-depth ldap enumeration utility","T1087.002 - T1018 - T1482 - T1083","TA0007 - TA0008 - TA0009","N/A","N/A","Reconnaissance","https://github.com/franc-pentest/ldeep","1","1","N/A","N/A","5","5","465","54","2025-03-02T18:43:27Z","2018-10-22T18:21:44Z","50912" +"*ldeep_dump_users_enabled.json",".{0,1000}ldeep_dump_users_enabled\.json","offensive_tool_keyword","ldeep","In-depth ldap enumeration utility","T1087.002 - T1018 - T1482 - T1083","TA0007 - TA0008 - TA0009","N/A","N/A","Reconnaissance","https://github.com/franc-pentest/ldeep","1","1","N/A","N/A","5","5","465","54","2025-03-02T18:43:27Z","2018-10-22T18:21:44Z","50913" +"*ldeep_dump_users_enabled.lst",".{0,1000}ldeep_dump_users_enabled\.lst","offensive_tool_keyword","ldeep","In-depth ldap enumeration utility","T1087.002 - T1018 - T1482 - T1083","TA0007 - TA0008 - TA0009","N/A","N/A","Reconnaissance","https://github.com/franc-pentest/ldeep","1","1","N/A","N/A","5","5","465","54","2025-03-02T18:43:27Z","2018-10-22T18:21:44Z","50914" +"*ldeep_enum*",".{0,1000}ldeep_enum.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","50915" +"*ldif2john.pl*",".{0,1000}ldif2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50916" +"*leaky/leakbuf.go*",".{0,1000}leaky\/leakbuf\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","50920" +"*leechristensen/UnmanagedPowerShell*",".{0,1000}leechristensen\/UnmanagedPowerShell.{0,1000}","offensive_tool_keyword","UnmanagedPowerShell","Executes PowerShell from an unmanaged process","T1059 - T1086","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/leechristensen/UnmanagedPowerShell","1","1","N/A","N/A","6","5","487","113","2016-03-17T05:20:55Z","2014-12-15T00:59:03Z","50923" +"*Leeon123/Aoyama*",".{0,1000}Leeon123\/Aoyama.{0,1000}","offensive_tool_keyword","Aoyama ","Python Botnet ","T1059 - T1219 - T1090 - T1102 - T1213 - T1095 - T1071 - T1486 - T1083 - T1041 - T1012 - T1027","TA0011 - TA0010 - TA0002","N/A","N/A","C2","https://github.com/Leeon123/Aoyama","1","1","N/A","N/A","10","10","260","63","2022-03-23T09:49:43Z","2019-07-16T13:04:07Z","50924" +"*Leeon123/Python3-botnet*",".{0,1000}Leeon123\/Python3\-botnet.{0,1000}","offensive_tool_keyword","Aoyama ","Python Botnet ","T1059 - T1219 - T1090 - T1102 - T1213 - T1095 - T1071 - T1486 - T1083 - T1041 - T1012 - T1027","TA0011 - TA0010 - TA0002","N/A","N/A","C2","https://github.com/Leeon123/Aoyama","1","1","N/A","N/A","10","10","260","63","2022-03-23T09:49:43Z","2019-07-16T13:04:07Z","50925" +"*leftp/BackupCreds*",".{0,1000}leftp\/BackupCreds.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","1","N/A","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","50926" +"*legalhackers.com/exploits/CVE*",".{0,1000}legalhackers\.com\/exploits\/CVE.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","50927" +"*legba-main.zip*",".{0,1000}legba\-main\.zip.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","1","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50954" +"*leitosama/SharpZeroLogon*",".{0,1000}leitosama\/SharpZeroLogon.{0,1000}","offensive_tool_keyword","SharpZeroLogon","exploit for CVE-2020-1472","T1210 - T1558.003 - T1078.002 - T1098 - T1003.006","TA0001 - TA0004 - TA0005 - TA0006 - TA0003","Ghost Ransomware","N/A","Exploitation tool","https://github.com/leitosama/SharpZeroLogon","1","1","N/A","N/A","10","1","27","17","2021-02-13T10:13:32Z","2021-02-13T09:44:43Z","50955" +"*lem0nSec/ShellGhost*",".{0,1000}lem0nSec\/ShellGhost.{0,1000}","offensive_tool_keyword","ShellGhost","A memory-based evasion technique which makes shellcode invisible from process start to end","T1055.012 - T1027.002 - T1055.001","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/lem0nSec/ShellGhost","1","1","N/A","N/A","N/A","10","1175","140","2023-10-16T06:40:24Z","2023-07-01T16:56:58Z","50957" +"*LemonSaaS/ghostsocks*",".{0,1000}LemonSaaS\/ghostsocks.{0,1000}","offensive_tool_keyword","ghostsocks","SOCKS5 proxy based on lightsocks","T1090.002 - T1090","TA0005 - TA0008","Lumma Stealer","N/A","Defense Evasion","https://github.com/LemonSaaS/ghostsocks","1","1","N/A","N/A","7","1","2","1","2017-11-14T16:56:05Z","2017-11-13T03:38:57Z","50958" +"*lengjibo/FourEye*",".{0,1000}lengjibo\/FourEye.{0,1000}","offensive_tool_keyword","FourEye","AV Evasion Tool","T1059 - T1059.001 - T1059.005 - T1027 - T1027.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/lengjibo/FourEye","1","1","N/A","N/A","10","8","758","152","2021-12-08T11:55:15Z","2020-12-11T01:29:58Z","50959" +"*leo4j.gitbook.io/amnesiac*",".{0,1000}leo4j\.gitbook\.io\/amnesiac.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","50960" +"*Leo4j/Amnesiac*",".{0,1000}Leo4j\/Amnesiac.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","50961" +"*Leo4j/Ask4Creds*",".{0,1000}Leo4j\/Ask4Creds.{0,1000}","offensive_tool_keyword","Ask4Creds","Prompt User for credentials","T1056 - T1071","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Leo4j/Ask4Creds","1","1","N/A","N/A","8","1","1","0","2024-03-20T17:09:21Z","2023-11-12T15:21:40Z","50962" +"*Leo4j/CheckSMBSigning*",".{0,1000}Leo4j\/CheckSMBSigning.{0,1000}","offensive_tool_keyword","CheckSMBSigning","Checks for SMB signing disabled on all hosts in the network","T1018 - T1550","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/Leo4j/CheckSMBSigning","1","1","N/A","N/A","6","1","8","1","2023-10-13T11:55:33Z","2023-05-17T11:47:52Z","50963" +"*Leo4j/Invoke-ADEnum*",".{0,1000}Leo4j\/Invoke\-ADEnum.{0,1000}","offensive_tool_keyword","Invoke-ADEnum","Automate Active Directory Enumeration","T1016 - T1482","TA0007","N/A","N/A","Discovery","https://github.com/Leo4j/Invoke-ADEnum","1","1","N/A","N/A","7","5","448","50","2025-04-09T10:13:47Z","2023-04-18T11:19:42Z","50964" +"*Leo4j/Invoke-RunAsSystem*",".{0,1000}Leo4j\/Invoke\-RunAsSystem.{0,1000}","offensive_tool_keyword","Invoke-RunAsSystem","A simple script to elevate current session to SYSTEM (needs to be run as Administrator)","T1548.002 - T1059.001","TA0004 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/Leo4j/Invoke-RunAsSystem","1","1","N/A","N/A","8","1","14","1","2024-11-11T17:18:20Z","2023-08-24T15:12:40Z","50965" +"*Leo4j/Invoke-SessionHunter*",".{0,1000}Leo4j\/Invoke\-SessionHunter.{0,1000}","offensive_tool_keyword","Invoke-SessionHunter","Retrieve and display information about active user sessions on remote computers. No admin privileges required","T1033 - T1078 - T1110","TA0007","N/A","N/A","Discovery","https://github.com/Leo4j/Invoke-SessionHunter","1","1","N/A","N/A","7","2","183","20","2024-08-12T13:15:10Z","2023-08-13T13:22:05Z","50966" +"*Leo4j/Invoke-SMBRemoting*",".{0,1000}Leo4j\/Invoke\-SMBRemoting.{0,1000}","offensive_tool_keyword","Invoke-SMBRemoting","Interactive Shell and Command Execution over Named-Pipes (SMB)","T1059 - T1021.002 - T1572","TA0002 - TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/Leo4j/Invoke-SMBRemoting","1","1","N/A","N/A","9","2","163","25","2024-12-05T16:30:18Z","2023-09-06T16:00:47Z","50967" +"*Leo4j/KeyCredentialLink*",".{0,1000}Leo4j\/KeyCredentialLink.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","1","N/A","N/A","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","50968" +"*Leo4j/PassSpray*",".{0,1000}Leo4j\/PassSpray.{0,1000}","offensive_tool_keyword","PassSpray","Domain Password Spray","T1110.003 - T1078","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/PassSpray","1","1","N/A","N/A","10","1","7","3","2025-02-20T10:07:43Z","2023-11-16T13:35:49Z","50969" +"*Leo4j/PS2EXE*",".{0,1000}Leo4j\/PS2EXE.{0,1000}","offensive_tool_keyword","PS2EXE","Convert Powershell scripts to EXEs","T1059.001 - T1588","TA0042","N/A","N/A","Resource Development","https://github.com/Leo4j/PS2EXE","1","1","N/A","N/A","7","1","5","1","2024-08-31T12:34:50Z","2024-08-22T12:22:26Z","50970" +"*Leo4j/ShellGen*",".{0,1000}Leo4j\/ShellGen.{0,1000}","offensive_tool_keyword","ShellGen","PowerShell script to generate ShellCode in various formats","T1059.001 - T1588","TA0042","N/A","N/A","Resource Development","https://github.com/Leo4j/ShellGen","1","1","N/A","N/A","7","1","41","10","2024-09-25T09:29:13Z","2024-08-22T13:32:06Z","50971" +"*Leo4j/TGT_Monitor*",".{0,1000}Leo4j\/TGT_Monitor.{0,1000}","offensive_tool_keyword","TGT_Monitor","This script continuously monitors cache for new TGTs and displays them on the screen (admin privs required)","T1557.001 - T1040","TA0006 - TA0008","N/A","N/A","Lateral Movement","https://github.com/Leo4j/TGT_Monitor","1","1","N/A","N/A","9","1","3","0","2023-11-08T18:48:55Z","2023-11-07T22:53:45Z","50972" +"*Leo4j/Token-Impersonation*",".{0,1000}Leo4j\/Token\-Impersonation.{0,1000}","offensive_tool_keyword","Token-Impersonation","Make a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required)","T1134.001 - T1134.002","TA0004 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/Leo4j/Token-Impersonation","1","1","N/A","N/A","8","1","7","3","2024-03-20T17:07:13Z","2023-11-02T10:46:24Z","50973" +"*leoloobeek/LAPSToolkit*",".{0,1000}leoloobeek\/LAPSToolkit.{0,1000}","offensive_tool_keyword","LAPSToolkit","Functions written in PowerShell that leverage PowerView to audit and attack Active Directory environments that have deployed Microsofts Local Administrator Password Solution (LAPS). It includes finding groups specifically delegated by sysadmins. finding users with All Extended Rights that can view passwords. and viewing all computers with LAPS enabled","T1087.001 - T1069 - T1069.003 - T1069.007 - T1069.002 - T1069.001","TA0007 - TA0008 - TA0009","N/A","Scattered Spider*","Discovery","https://github.com/leoloobeek/LAPSToolkit","1","1","N/A","N/A","10","9","859","119","2018-01-31T14:45:35Z","2016-04-27T00:06:20Z","50974" +"*LetMeOutSharp.*",".{0,1000}LetMeOutSharp\..{0,1000}","offensive_tool_keyword","cobaltstrike","Project to enumerate proxy configurations and generate shellcode from CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EncodeGroup/AggressiveProxy","1","1","N/A","N/A","10","10","141","25","2020-11-04T16:08:11Z","2020-11-04T12:53:00Z","50977" +"*LetMeowIn.exe*",".{0,1000}LetMeowIn\.exe.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","1","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","50978" +"*LetMeowIn-main.zip*",".{0,1000}LetMeowIn\-main\.zip.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","1","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","50979" +"*leviathansecurity/TunnelVision*",".{0,1000}leviathansecurity\/TunnelVision.{0,1000}","offensive_tool_keyword","TunnelVision","TunnelVision uses DHCP option 121 to manipulate routing tables and decloak VPN traffic","T1557 - T1498.003","TA0009 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/leviathansecurity/TunnelVision","1","1","N/A","N/A","9","2","132","17","2024-05-08T19:40:13Z","2024-03-11T22:24:56Z","50981" +"*lexfo/sshimpanzee*",".{0,1000}lexfo\/sshimpanzee.{0,1000}","offensive_tool_keyword","sshimpanzee","SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS - ICMP - HTTP Encapsulation - HTTP/Socks Proxies - UDP","T1572 - T1095 - T1090 - T1043","TA0010 - TA0011 - TA0005","N/A","Scattered Spider*","C2","https://github.com/lexfo/sshimpanzee","1","1","N/A","N/A","10","10","263","27","2025-03-05T08:32:56Z","2023-04-03T10:11:27Z","50982" +"*Lexus89/SharpPack*",".{0,1000}Lexus89\/SharpPack.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","50983" +"*lgandx/Pcredz*",".{0,1000}lgandx\/Pcredz.{0,1000}","offensive_tool_keyword","Pcredz","This tool extracts Credit card numbers. NTLM(DCE-RPC. HTTP. SQL. LDAP. etc). Kerberos (AS-REQ Pre-Auth etype 23). HTTP Basic. SNMP. POP. SMTP. FTP. IMAP. etc from a pcap file or from a live interface.","T1116 - T1003 - T1002 - T1001 - T1005 - T1552","TA0003 - TA0002 - TA0011","N/A","N/A","Credential Access","https://github.com/lgandx/Pcredz","1","1","N/A","N/A","N/A","10","2100","413","2025-01-27T10:34:00Z","2014-04-07T02:03:33Z","50985" +"*lgandx/Responder-Windows*",".{0,1000}lgandx\/Responder\-Windows.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/lgandx/Responder-Windows/","1","1","N/A","N/A","N/A","6","523","137","2024-07-30T11:10:05Z","2015-02-07T22:59:04Z","50986" +"*liamg/traitor*",".{0,1000}liamg\/traitor.{0,1000}","offensive_tool_keyword","traitor","Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy","T1068 - T1548.004 - T1611 - T1203 - T1059.004","TA0004 - TA0001 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/liamg/traitor","1","1","#linux","N/A","10","10","6853","651","2024-03-12T21:01:14Z","2021-01-24T10:50:15Z","50991" +"*lib/Bruteforcer.cs*",".{0,1000}lib\/Bruteforcer\.cs.{0,1000}","offensive_tool_keyword","KRBUACBypass","UAC Bypass By Abusing Kerberos Tickets","T1548.002 - T1558 - T1558.003","TA0004 - TA0006","N/A","N/A","Defense Evasion","https://github.com/wh0amitz/KRBUACBypass","1","1","N/A","N/A","8","5","496","62","2023-08-10T02:51:59Z","2023-07-27T12:08:12Z","50993" +"*lib/ForgeTicket.*",".{0,1000}lib\/ForgeTicket\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","50994" +"*lib/S4U.*",".{0,1000}lib\/S4U\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","50995" +"*libFuzzer-HOWTO.*",".{0,1000}libFuzzer\-HOWTO\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50998" +"*libnspr_nspr_log_file_priv_esc.*",".{0,1000}libnspr_nspr_log_file_priv_esc\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51001" +"*libreoffice2john.py*",".{0,1000}libreoffice2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51002" +"*libs/bofalloc*",".{0,1000}libs\/bofalloc.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files (BOFs) written in rust with rust core and alloc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/wumb0/rust_bof","1","1","N/A","N/A","10","10","262","27","2024-02-08T20:45:00Z","2022-02-28T23:46:00Z","51003" +"*libs/bofentry*",".{0,1000}libs\/bofentry.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files (BOFs) written in rust with rust core and alloc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/wumb0/rust_bof","1","1","N/A","N/A","10","10","262","27","2024-02-08T20:45:00Z","2022-02-28T23:46:00Z","51004" +"*LibSnaffle.ActiveDirectory*",".{0,1000}LibSnaffle\.ActiveDirectory.{0,1000}","offensive_tool_keyword","Group3r","Find vulnerabilities in AD Group Policy","T1484.002 - T1069.002 - T1087.002","TA0007 - TA0040","N/A","KNOTWEED","Discovery","https://github.com/Group3r/Group3r","1","1","N/A","AD Enumeration","7","8","781","68","2025-04-08T05:03:34Z","2021-07-05T05:05:42Z","51007" +"*libxpc_mitm_ssudo.*",".{0,1000}libxpc_mitm_ssudo\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","#linux","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51015" +"*lightsout.py*",".{0,1000}lightsout\.py.{0,1000}","offensive_tool_keyword","LightsOut","Generate an obfuscated DLL that will disable AMSI & ETW","T1027.003 - T1059.001 - T1082","TA0005 - TA0002 - TA0004","N/A","N/A","Exploitation tool","https://github.com/icyguider/LightsOut","1","1","N/A","N/A","10","4","321","44","2024-07-15T21:29:16Z","2023-06-01T14:57:44Z","51019" +"*LightsOut-master.zip*",".{0,1000}LightsOut\-master\.zip.{0,1000}","offensive_tool_keyword","LightsOut","Generate an obfuscated DLL that will disable AMSI & ETW","T1027.003 - T1059.001 - T1082","TA0005 - TA0002 - TA0004","N/A","N/A","Exploitation tool","https://github.com/icyguider/LightsOut","1","1","N/A","N/A","10","4","321","44","2024-07-15T21:29:16Z","2023-06-01T14:57:44Z","51020" +"*ligolo_darwin*",".{0,1000}ligolo_darwin.{0,1000}","offensive_tool_keyword","ligolo","ligolo is a simple and lightweight tool for establishing SOCKS5 or TCP tunnels from a reverse connection in complete safety (TLS certificate with elliptical curve)","T1071 - T1021 - T1573","TA0011 - TA0002","N/A","AvosLocker - LockBit","C2","https://github.com/sysdream/ligolo","1","1","#linux","N/A","10","10","1764","224","2023-01-06T19:49:22Z","2020-05-22T07:58:13Z","51022" +"*ligolo_linux*",".{0,1000}ligolo_linux.{0,1000}","offensive_tool_keyword","ligolo","ligolo is a simple and lightweight tool for establishing SOCKS5 or TCP tunnels from a reverse connection in complete safety (TLS certificate with elliptical curve)","T1071 - T1021 - T1573","TA0011 - TA0002","N/A","AvosLocker - LockBit","C2","https://github.com/sysdream/ligolo","1","1","#linux","N/A","10","10","1764","224","2023-01-06T19:49:22Z","2020-05-22T07:58:13Z","51023" +"*ligolo_windows*.exe*",".{0,1000}ligolo_windows.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","ligolo","ligolo is a simple and lightweight tool for establishing SOCKS5 or TCP tunnels from a reverse connection in complete safety (TLS certificate with elliptical curve)","T1071 - T1021 - T1573","TA0011 - TA0002","N/A","AvosLocker - LockBit","C2","https://github.com/sysdream/ligolo","1","1","N/A","N/A","10","10","1764","224","2023-01-06T19:49:22Z","2020-05-22T07:58:13Z","51024" +"*ligolo-master*",".{0,1000}ligolo\-master.{0,1000}","offensive_tool_keyword","ligolo","ligolo is a simple and lightweight tool for establishing SOCKS5 or TCP tunnels from a reverse connection in complete safety (TLS certificate with elliptical curve)","T1071 - T1021 - T1573","TA0011 - TA0002","N/A","AvosLocker - LockBit","C2","https://github.com/sysdream/ligolo","1","1","N/A","N/A","10","10","1764","224","2023-01-06T19:49:22Z","2020-05-22T07:58:13Z","51025" +"*ligolo-ng_agent*",".{0,1000}ligolo\-ng_agent.{0,1000}","offensive_tool_keyword","ligolo-ng","An advanced tunneling tool that uses TUN interfaces","T1572 - T1090","TA0011","N/A","Dispossessor - AvosLocker - LockBit","C2","https://github.com/nicocha30/ligolo-ng","1","1","N/A","N/A","10","10","3380","338","2025-04-17T07:48:36Z","2021-07-28T12:55:36Z","51027" +"*ligolo-ng_proxy*",".{0,1000}ligolo\-ng_proxy.{0,1000}","offensive_tool_keyword","ligolo-ng","An advanced tunneling tool that uses TUN interfaces","T1572 - T1090","TA0011","N/A","Dispossessor - AvosLocker - LockBit","C2","https://github.com/nicocha30/ligolo-ng","1","1","N/A","N/A","10","10","3380","338","2025-04-17T07:48:36Z","2021-07-28T12:55:36Z","51028" +"*ligolo-ng-master*",".{0,1000}ligolo\-ng\-master.{0,1000}","offensive_tool_keyword","ligolo-ng","An advanced tunneling tool that uses TUN interfaces","T1572 - T1090","TA0011","N/A","Dispossessor - AvosLocker - LockBit","C2","https://github.com/nicocha30/ligolo-ng","1","1","N/A","N/A","10","10","3380","338","2025-04-17T07:48:36Z","2021-07-28T12:55:36Z","51029" +"*Lime-Crypter.exe*",".{0,1000}Lime\-Crypter\.exe.{0,1000}","offensive_tool_keyword","Lime-Crypter","An obfuscation tool for .Net + Native files","T1027 - T1045","TA0005 ","N/A","N/A","Defense Evasion","https://github.com/NYAN-x-CAT/Lime-Crypter","1","1","N/A","N/A","9","6","515","199","2024-04-22T21:31:18Z","2018-07-14T13:44:58Z","51030" +"*Lime-RAT-87e189781c0aef0e84cabe2f8c2e7d8f5143e594.zip*",".{0,1000}Lime\-RAT\-87e189781c0aef0e84cabe2f8c2e7d8f5143e594\.zip.{0,1000}","offensive_tool_keyword","Lime-RAT","remote administration tool for Windows (RAT)","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","APT-C-36 - Operation Comando","Malware","https://github.com/NYAN-x-CAT/Lime-RAT","1","1","N/A","N/A","10","10","1086","413","2019-06-24T17:05:48Z","2018-02-07T15:35:56Z","51032" +"*LimerBoy/Adamantium-Thief*",".{0,1000}LimerBoy\/Adamantium\-Thief.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","1","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","51033" +"*LinEnum.sh*",".{0,1000}LinEnum\.sh.{0,1000}","offensive_tool_keyword","LinEnum","Scripted Local Linux Enumeration & Privilege Escalation Checks","T1046 - T1087.001 - T1057 - T1082 - T1016 - T1135 - T1049 - T1059.004 - T1007 - T1069.001 - T1083 - T1018","TA0007 - TA0009 - TA0002 - TA0003 - TA0001","N/A","N/A","Privilege Escalation","https://github.com/rebootuser/LinEnum","1","1","#linux","N/A","10","10","7309","2011","2023-09-06T18:02:29Z","2013-08-20T06:26:58Z","51035" +"*LinEnum-master.ip*",".{0,1000}LinEnum\-master\.ip.{0,1000}","offensive_tool_keyword","LinEnum","Scripted Local Linux Enumeration & Privilege Escalation Checks","T1046 - T1087.001 - T1057 - T1082 - T1016 - T1135 - T1049 - T1059.004 - T1007 - T1069.001 - T1083 - T1018","TA0007 - TA0009 - TA0002 - TA0003 - TA0001","N/A","N/A","Privilege Escalation","https://github.com/rebootuser/LinEnum","1","1","#linux","N/A","10","10","7309","2011","2023-09-06T18:02:29Z","2013-08-20T06:26:58Z","51036" +"*linikatz.sh*",".{0,1000}linikatz\.sh.{0,1000}","offensive_tool_keyword","linikatz","linikatz is a tool to attack AD on UNIX","T1003.002 - T1558.003 - T1078 - T1550.001","TA0006 - TA0001 - TA0004 - TA0003","N/A","N/A","Exploitation tool","https://github.com/CiscoCXSecurity/linikatz","1","1","#linux","N/A","10","6","552","79","2023-10-19T17:01:47Z","2018-11-15T22:19:47Z","51037" +"*linikatz.zip*",".{0,1000}linikatz\.zip.{0,1000}","offensive_tool_keyword","linikatz","linikatz is a tool to attack AD on UNIX","T1003.002 - T1558.003 - T1078 - T1550.001","TA0006 - TA0001 - TA0004 - TA0003","N/A","N/A","Exploitation tool","https://github.com/CiscoCXSecurity/linikatz","1","1","#linux","N/A","10","6","552","79","2023-10-19T17:01:47Z","2018-11-15T22:19:47Z","51038" +"*linikatzV2.sh*",".{0,1000}linikatzV2\.sh.{0,1000}","offensive_tool_keyword","LinikatzV2","linikatz is a tool to attack AD on UNIX","T1003.002 - T1558.003 - T1078 - T1550.001","TA0006 - TA0001 - TA0004 - TA0003","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/LinikatzV2","1","1","#linux","N/A","10","2","146","15","2023-10-19T12:26:58Z","2023-10-19T11:07:53Z","51039" +"*linpeas_builder.py*",".{0,1000}linpeas_builder\.py.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","51043" +"*linpeas_darwin_amd64*",".{0,1000}linpeas_darwin_amd64.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","#linux","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","51045" +"*linpeas_darwin_arm64*",".{0,1000}linpeas_darwin_arm64.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","#linux","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","51047" +"*linpeas_fat.sh*",".{0,1000}linpeas_fat\.sh.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","51048" +"*linpeas_linux_386*",".{0,1000}linpeas_linux_386.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","#linux","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","51050" +"*linpeas_linux_amd64*",".{0,1000}linpeas_linux_amd64.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","#linux","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","51052" +"*linpeas_linux_arm64*",".{0,1000}linpeas_linux_arm64.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","#linux","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","51054" +"*linux/x64/meterpreter/reverse_tcp*",".{0,1000}linux\/x64\/meterpreter\/reverse_tcp.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","#linux","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","51065" +"*linux/x64/shell_reverse_tcp*",".{0,1000}linux\/x64\/shell_reverse_tcp.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","#linux","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","51066" +"*linux_hostrecon*",".{0,1000}linux_hostrecon.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","#linux","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","51069" +"*linux_hostrecon.*",".{0,1000}linux_hostrecon\..{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","#linux","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","51070" +"*Linux_LPE_eBPF_CVE*",".{0,1000}Linux_LPE_eBPF_CVE.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","#linux","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51071" +"*linux_sudo_cve-2017-1000367.c*",".{0,1000}linux_sudo_cve\-2017\-1000367\.c.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","51072" +"*linux_trap_command.py*",".{0,1000}linux_trap_command\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","#linux","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","51073" +"*LinuxARMLELF32.py*",".{0,1000}LinuxARMLELF32\.py.{0,1000}","offensive_tool_keyword","the-backdoor-factory","Patch PE ELF Mach-O binaries with shellcode new version in development*","T1055.002 - T1055.004 - T1059.001","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/secretsquirrel/the-backdoor-factory","1","1","#linux","N/A","10","10","3369","788","2023-10-30T14:13:32Z","2013-05-30T01:04:24Z","51077" +"*linux-exploit-suggester*",".{0,1000}linux\-exploit\-suggester.{0,1000}","offensive_tool_keyword","BeRoot","Privilege Escalation Project - Windows / Linux / Mac ","T1068 - T1055 - T1078 - T1548 - T1003","TA0004","N/A","N/A","Privilege Escalation","https://github.com/AlessandroZ/BeRoot","1","1","#linux","N/A","10","10","2523","459","2024-10-04T11:54:01Z","2017-04-14T12:47:31Z","51078" +"*linux-exploit-suggester*",".{0,1000}linux\-exploit\-suggester.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","51079" +"*linux-exploit-suggester.sh*",".{0,1000}linux\-exploit\-suggester\.sh.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","#linux","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","51080" +"*linux-exploit-suggester.sh*",".{0,1000}linux\-exploit\-suggester\.sh.{0,1000}","offensive_tool_keyword","Orc","Orc is a post-exploitation framework for Linux written in Bash","T1059.004 - T1036.005 - T1070.002 - T1012 - T1082 - T1003 - T1555.003 - T1049 - T1134.001 - T1202","TA0005 - TA0003 - TA0002 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/zMarch/Orc","1","1","#linux","N/A","9","4","395","53","2019-11-12T18:21:27Z","2018-08-16T11:31:39Z","51081" +"*linux-pam-backdoor-master*",".{0,1000}linux\-pam\-backdoor\-master.{0,1000}","offensive_tool_keyword","linux-pam-backdoor","Linux PAM Backdoor","T1547.001 - T1556.003","TA0003 - TA0004","N/A","N/A","Persistence","https://github.com/zephrax/linux-pam-backdoor","1","1","#linux","N/A","10","4","328","85","2023-11-13T11:29:44Z","2017-06-08T21:14:34Z","51083" +"*linuxprivchecker*",".{0,1000}linuxprivchecker.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","#linux","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","51084" +"*linux-smart-enumeration.sh*",".{0,1000}linux\-smart\-enumeration\.sh.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","#linux","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","51087" +"*linux-smart-enumeration-master*",".{0,1000}linux\-smart\-enumeration\-master.{0,1000}","offensive_tool_keyword","linux-smart-enumeration","Linux enumeration tool for privilege escalation and discovery","T1087.004 - T1016 - T1548.001 - T1046","TA0007 - TA0004 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/diego-treitos/linux-smart-enumeration","1","1","#linux","N/A","9","10","3575","584","2023-12-25T14:46:47Z","2019-02-13T11:02:21Z","51088" +"*linWinPwn-*",".{0,1000}linWinPwn\-.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","51089" +"*linWinPwn.*",".{0,1000}linWinPwn\..{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","51090" +"*lion2john.pl*",".{0,1000}lion2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51091" +"*lion2john-alt.pl*",".{0,1000}lion2john\-alt\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51092" +"*LiquidSnake.exe*",".{0,1000}LiquidSnake\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","LiquidSnake is a tool that allows operators to perform fileless Lateral Movement using WMI Event Subscriptions and GadgetToJScript","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RiccardoAncarani/LiquidSnake","1","1","N/A","N/A","10","10","332","46","2021-09-01T11:53:30Z","2021-08-31T12:23:01Z","51093" +"*lirncvjfmdhv6samxvvlohfqx7jklfxoxj7xn3fh7qeabs3taemdsdqd.onion*",".{0,1000}lirncvjfmdhv6samxvvlohfqx7jklfxoxj7xn3fh7qeabs3taemdsdqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51094" +"*list_tcppivot*",".{0,1000}list_tcppivot.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51099" +"*List-AllMailboxAndPST.ps1*",".{0,1000}List\-AllMailboxAndPST\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","51102" +"*ListAllUsers.ps1*",".{0,1000}ListAllUsers\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","51103" +"*listdlls64.exe*",".{0,1000}listdlls64\.exe.{0,1000}","offensive_tool_keyword","UnlinkDLL","DLL Unlinking from InLoadOrderModuleList - InMemoryOrderModuleList - InInitializationOrderModuleList and LdrpHashTable","T1055 - T1027 - T1070","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/frkngksl/UnlinkDLL","1","1","N/A","N/A","7","1","57","13","2023-12-15T12:04:00Z","2023-12-13T14:37:33Z","51105" +"*ListMetasploitPayloads*",".{0,1000}ListMetasploitPayloads.{0,1000}","offensive_tool_keyword","empire","Empire scripts argument. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","51115" +"*lists.tor2web.org*",".{0,1000}lists\.tor2web\.org.{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","51119" +"*livevnc.ngrok.app*",".{0,1000}livevnc\.ngrok\.app.{0,1000}","offensive_tool_keyword","Kematian Stealer","Fake WinRar site distributes malware (+stealer +miner +hvnc +ransomware) from GitHub","T1195 - T1566 - T1569 - T1106 - T1486 - T1113","TA0001 - TA0002 - TA0005 - TA0006 - TA0007 - TA0009 - TA0010 - TA0011 - TA0040 - TA0043","N/A","N/A","Malware","https://github[.]com/sap3r-encrypthub/encrypthub","1","1","#macos","N/A","10","7","N/A","N/A","N/A","N/A","51130" +"*lkarlslund/Adalanche*",".{0,1000}lkarlslund\/Adalanche.{0,1000}","offensive_tool_keyword","adalanche","Active Directory ACL Visualizer and Explorer - who's really Domain Admin?","T1484 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/lkarlslund/Adalanche","1","1","N/A","AD Enumeration","10","10","1908","184","2025-03-25T13:01:45Z","2020-10-07T10:07:22Z","51131" +"*lkarlslund/ldapnomnom*",".{0,1000}lkarlslund\/ldapnomnom.{0,1000}","offensive_tool_keyword","ldapnomnom","Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)","T1110.003 - T1205","TA0007","N/A","N/A","Discovery","https://github.com/lkarlslund/ldapnomnom","1","1","N/A","N/A","6","10","1030","80","2024-11-09T10:15:13Z","2022-09-18T10:35:09Z","51132" +"*llkat/rsockstun*",".{0,1000}llkat\/rsockstun.{0,1000}","offensive_tool_keyword","rsockstun","reverse socks tunneler with ntlm and proxy support","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","COZY BEAR","C2","https://github.com/llkat/rsockstun","1","1","N/A","N/A","10","10","53","22","2022-08-09T09:25:50Z","2018-10-17T09:51:11Z","51139" +"*LLMNR.py*",".{0,1000}LLMNR\.py.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","N/A","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","51141" +"*llmnr_sniffer.py*",".{0,1000}llmnr_sniffer\.py.{0,1000}","offensive_tool_keyword","DDSpoof","DDSpoof is a tool that enables DHCP DNS Dynamic Update attacks against Microsoft DHCP servers in AD environments.","T1557 - T1584 - T1203","TA0005 - TA0003 TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/akamai/DDSpoof","1","1","N/A","N/A","9","2","122","13","2024-04-12T22:06:02Z","2023-12-14T06:47:45Z","51142" +"*LLMNRSpoofer*",".{0,1000}LLMNRSpoofer.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","51143" +"*LLMNRSpoofer*",".{0,1000}LLMNRSpoofer.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","51144" +"*llsrpc_##*",".{0,1000}llsrpc_\#\#.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","51145" +"*LMGsec/o365creeper*",".{0,1000}LMGsec\/o365creeper.{0,1000}","offensive_tool_keyword","o365creeper","Python script that performs email address validation against Office 365 without submitting login attempts","T1592.002 - T1596","TA0007","N/A","N/A","Discovery","https://github.com/LMGsec/o365creeper","1","1","N/A","N/A","N/A","4","342","60","2020-08-07T17:40:41Z","2019-07-12T21:32:05Z","51146" +"*lnkbomb-1.0.zip*",".{0,1000}lnkbomb\-1\.0\.zip.{0,1000}","offensive_tool_keyword","lnkbomb","Malicious shortcut generator for collecting NTLM hashes from insecure file shares.","T1023.003 - T1557.002 - T1046","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/dievus/lnkbomb","1","1","N/A","N/A","10","4","327","58","2024-10-22T17:51:10Z","2022-01-03T04:17:11Z","51158" +"*lnx_keylogger.py*",".{0,1000}lnx_keylogger\.py.{0,1000}","offensive_tool_keyword","C2_Server","C2 server to connect to a victim machine via reverse shell","T1090 - T1090.001 - T1071 - T1071.001","TA0011 ","N/A","N/A","C2","https://github.com/reveng007/C2_Server","1","1","N/A","N/A","10","10","54","18","2022-02-27T02:00:02Z","2021-03-05T12:35:45Z","51161" +"*Load-BeaconParameters*",".{0,1000}Load\-BeaconParameters.{0,1000}","offensive_tool_keyword","cobaltstrike","Load any Beacon Object File using Powershell!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/airbus-cert/Invoke-Bof","1","1","N/A","N/A","10","10","250","35","2021-12-09T15:10:41Z","2021-12-09T15:09:22Z","51172" +"*loaddll64.exe*",".{0,1000}loaddll64\.exe.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51175" +"*loader.x64.exe.exe*",".{0,1000}loader\.x64\.exe\.exe.{0,1000}","offensive_tool_keyword","Stardust","An modern 64-bit position independent implant template","T1055 - T1105 - T1055.012 - T1027 - T1218","TA0005 - TA0003 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Cracked5pider/Stardust","1","1","N/A","N/A","10","10","1193","193","2025-03-21T11:41:09Z","2022-02-20T01:23:35Z","51176" +"*loader/inject.c*",".{0,1000}loader\/inject\.c.{0,1000}","offensive_tool_keyword","donut","Donut is a position-independent code that enables in-memory execution of VBScript. JScript. EXE. DLL files and dotNET assemblies. A module created by Donut can either be staged from a HTTP server or embedded directly in the loader itself","T1071.001 - T1059 - T1059.001 - T1059.005 - T1059.006 - T1059.007 - T1562.001 - T1070 - T1105 - T1106 - T1027 - T1027.002 - T1057 - T1055 - T1620","TA0011 - TA0002 - TA0005 - TA0008 - TA0004 - TA0007 - TA0003 - TA0006 - TA0010","N/A","Indrik Spider","Exploitation tool","https://github.com/TheWover/donut","1","1","N/A","N/A","N/A","10","3882","667","2024-10-23T12:19:13Z","2019-03-27T23:24:44Z","51177" +"*loader/inject_local.c*",".{0,1000}loader\/inject_local\.c.{0,1000}","offensive_tool_keyword","donut","Donut is a position-independent code that enables in-memory execution of VBScript. JScript. EXE. DLL files and dotNET assemblies. A module created by Donut can either be staged from a HTTP server or embedded directly in the loader itself","T1071.001 - T1059 - T1059.001 - T1059.005 - T1059.006 - T1059.007 - T1562.001 - T1070 - T1105 - T1106 - T1027 - T1027.002 - T1057 - T1055 - T1620","TA0011 - TA0002 - TA0005 - TA0008 - TA0004 - TA0007 - TA0003 - TA0006 - TA0010","N/A","Indrik Spider","Exploitation tool","https://github.com/TheWover/donut","1","1","N/A","N/A","N/A","10","3882","667","2024-10-23T12:19:13Z","2019-03-27T23:24:44Z","51178" +"*loader/loader/loader.c*",".{0,1000}loader\/loader\/loader\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","A protective and Low Level Shellcode Loader that defeats modern EDR systems.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/cribdragg3r/Alaris","1","1","N/A","N/A","10","10","903","142","2024-03-20T15:50:57Z","2020-02-22T15:42:37Z","51179" +"*loader_exe_x64.*",".{0,1000}loader_exe_x64\..{0,1000}","offensive_tool_keyword","donut","Donut is a position-independent code that enables in-memory execution of VBScript. JScript. EXE. DLL files and dotNET assemblies. A module created by Donut can either be staged from a HTTP server or embedded directly in the loader itself","T1071.001 - T1059 - T1059.001 - T1059.005 - T1059.006 - T1059.007 - T1562.001 - T1070 - T1105 - T1106 - T1027 - T1027.002 - T1057 - T1055 - T1620","TA0011 - TA0002 - TA0005 - TA0008 - TA0004 - TA0007 - TA0003 - TA0006 - TA0010","N/A","Indrik Spider","Exploitation tool","https://github.com/TheWover/donut","1","1","N/A","N/A","N/A","10","3882","667","2024-10-23T12:19:13Z","2019-03-27T23:24:44Z","51180" +"*loader_exe_x86.*",".{0,1000}loader_exe_x86\..{0,1000}","offensive_tool_keyword","donut","Donut is a position-independent code that enables in-memory execution of VBScript. JScript. EXE. DLL files and dotNET assemblies. A module created by Donut can either be staged from a HTTP server or embedded directly in the loader itself","T1071.001 - T1059 - T1059.001 - T1059.005 - T1059.006 - T1059.007 - T1562.001 - T1070 - T1105 - T1106 - T1027 - T1027.002 - T1057 - T1055 - T1620","TA0011 - TA0002 - TA0005 - TA0008 - TA0004 - TA0007 - TA0003 - TA0006 - TA0010","N/A","Indrik Spider","Exploitation tool","https://github.com/TheWover/donut","1","1","N/A","N/A","N/A","10","3882","667","2024-10-23T12:19:13Z","2019-03-27T23:24:44Z","51181" +"*LoadEWSDLL*",".{0,1000}LoadEWSDLL.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","51183" +"*loadKirbiFile*",".{0,1000}loadKirbiFile.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","51184" +"*loadliba_reverse_tcp.asm*",".{0,1000}loadliba_reverse_tcp\.asm.{0,1000}","offensive_tool_keyword","the-backdoor-factory","Patch PE ELF Mach-O binaries with shellcode new version in development*","T1055.002 - T1055.004 - T1059.001","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/secretsquirrel/the-backdoor-factory","1","1","N/A","N/A","10","10","3369","788","2023-10-30T14:13:32Z","2013-05-30T01:04:24Z","51185" +"*loadliba_shell.asm*",".{0,1000}loadliba_shell\.asm.{0,1000}","offensive_tool_keyword","the-backdoor-factory","Patch PE ELF Mach-O binaries with shellcode new version in development*","T1055.002 - T1055.004 - T1059.001","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/secretsquirrel/the-backdoor-factory","1","1","N/A","N/A","10","10","3369","788","2023-10-30T14:13:32Z","2013-05-30T01:04:24Z","51186" +"*loadliba_single_shell_reverse_tcp.asm*",".{0,1000}loadliba_single_shell_reverse_tcp\.asm.{0,1000}","offensive_tool_keyword","the-backdoor-factory","Patch PE ELF Mach-O binaries with shellcode new version in development*","T1055.002 - T1055.004 - T1059.001","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/secretsquirrel/the-backdoor-factory","1","1","N/A","N/A","10","10","3369","788","2023-10-30T14:13:32Z","2013-05-30T01:04:24Z","51187" +"*LocalAdminSharp.csproj*",".{0,1000}LocalAdminSharp\.csproj.{0,1000}","offensive_tool_keyword","LocalAdminSharp",".NET executable to use when dealing with privilege escalation on Windows to gain local administrator access","T1055.011 - T1068 - T1548.002 - T1548.003 - T1548.004","TA0004","N/A","N/A","Privilege Escalation","https://github.com/notdodo/LocalAdminSharp","1","1","N/A","N/A","10","2","157","17","2022-11-01T17:45:43Z","2022-01-01T10:35:09Z","51207" +"*LocalAdminSharp.exe*",".{0,1000}LocalAdminSharp\.exe.{0,1000}","offensive_tool_keyword","LocalAdminSharp",".NET executable to use when dealing with privilege escalation on Windows to gain local administrator access","T1055.011 - T1068 - T1548.002 - T1548.003 - T1548.004","TA0004","N/A","N/A","Privilege Escalation","https://github.com/notdodo/LocalAdminSharp","1","1","N/A","N/A","10","2","157","17","2022-11-01T17:45:43Z","2022-01-01T10:35:09Z","51208" +"*localexploit_demo_template.erb*",".{0,1000}localexploit_demo_template\.erb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51210" +"*localhost:1337*",".{0,1000}localhost\:1337.{0,1000}","offensive_tool_keyword","gophish","Combination of evilginx2 and GoPhish","T1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113","TA0002 - TA0003","N/A","Black Basta","Phishing","https://github.com/fin3ss3g0d/evilgophish","1","1","N/A","N/A","10","10","1762","340","2024-06-15T17:48:11Z","2022-09-07T02:47:43Z","51213" +"*localhost:1337*",".{0,1000}localhost\:1337.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","51214" +"*localhost:3000*striker*",".{0,1000}localhost\:3000.{0,1000}striker.{0,1000}","offensive_tool_keyword","Striker","Striker is a simple Command and Control (C2) program.","T1071 - T1071.001 - T1071.004 - T1071.005 - T1071.006 - T1071.007 - T1071.008 - T1071.009 - T1071.010 - T1071.012 - T1071.013 - T1071.014 - T1071.015 - T1071.016 - T1071.018 - T1105 - T1105.002 - T1573 - T1573.002 - T1573.003 - T1573.004 - T1573.005","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/4g3nt47/Striker","1","1","N/A","N/A","10","10","301","42","2023-05-04T18:00:05Z","2022-09-07T10:09:41Z","51215" +"*localhost:31337*",".{0,1000}localhost\:31337.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","51216" +"*localhost:4567*",".{0,1000}localhost\:4567.{0,1000}","offensive_tool_keyword","primusC2","another C2 framework","T1090 - T1071","TA0011 - TA0002","N/A","N/A","C2","https://github.com/Primusinterp/PrimusC2","1","1","N/A","N/A","10","10","55","4","2024-11-01T00:20:02Z","2023-04-19T10:59:30Z","51217" +"*localhost:53531*",".{0,1000}localhost\:53531.{0,1000}","offensive_tool_keyword","dnscat","This tool is designed to create an encrypted command-and-control (C&C) channel over the DNS protocol","T1071.004 - T1102 - T1071.001","TA0002 - TA0003 - TA0008","N/A","EMBER BEAR","C2","https://github.com/iagox86/dnscat2","1","1","#linux","N/A","10","10","3566","618","2024-03-14T11:17:49Z","2013-01-04T23:15:55Z","51219" +"*localhost:8000/*/hardware*",".{0,1000}localhost\:8000\/.{0,1000}\/hardware.{0,1000}","offensive_tool_keyword","ToRat","ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication","T1219 - T1021 - T1105","TA0008 - TA0011 - TA0005","N/A","N/A","C2","https://github.com/lu4p/ToRat","1","1","N/A","N/A","10","10","995","199","2023-03-13T08:56:55Z","2019-01-19T11:44:01Z","51220" +"*localhost:8000/*/netscan*",".{0,1000}localhost\:8000\/.{0,1000}\/netscan.{0,1000}","offensive_tool_keyword","ToRat","ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication","T1219 - T1021 - T1105","TA0008 - TA0011 - TA0005","N/A","N/A","C2","https://github.com/lu4p/ToRat","1","1","N/A","N/A","10","10","995","199","2023-03-13T08:56:55Z","2019-01-19T11:44:01Z","51221" +"*localhost:8000/*/osinfo*",".{0,1000}localhost\:8000\/.{0,1000}\/osinfo.{0,1000}","offensive_tool_keyword","ToRat","ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication","T1219 - T1021 - T1105","TA0008 - TA0011 - TA0005","N/A","N/A","C2","https://github.com/lu4p/ToRat","1","1","N/A","N/A","10","10","995","199","2023-03-13T08:56:55Z","2019-01-19T11:44:01Z","51222" +"*localhost:8000/*/speedtest*",".{0,1000}localhost\:8000\/.{0,1000}\/speedtest.{0,1000}","offensive_tool_keyword","ToRat","ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication","T1219 - T1021 - T1105","TA0008 - TA0011 - TA0005","N/A","N/A","C2","https://github.com/lu4p/ToRat","1","1","N/A","N/A","10","10","995","199","2023-03-13T08:56:55Z","2019-01-19T11:44:01Z","51223" +"*localhost:8022*",".{0,1000}localhost\:8022.{0,1000}","offensive_tool_keyword","MaccaroniC2","A proof-of-concept Command & Control framework that utilizes the powerful AsyncSSH Python library which provides an asynchronous client and server implementation of the SSHv2 protocol and use PyNgrok wrapper for ngrok integration.","T1090 - T1059.003","TA0011 - TA0002","N/A","N/A","C2","https://github.com/CalfCrusher/MaccaroniC2","1","1","N/A","N/A","10","10","76","16","2023-06-27T17:43:59Z","2023-05-21T13:33:48Z","51224" +"*localhost:8848*",".{0,1000}localhost\:8848.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","51225" +"*LocalPotato.cpp*",".{0,1000}LocalPotato\.cpp.{0,1000}","offensive_tool_keyword","localpotato","The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.","T1550.002 - T1078.003 - T1005 - T1070.004","TA0004 - TA0006 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/decoder-it/LocalPotato","1","1","N/A","N/A","10","7","691","92","2023-11-07T01:09:08Z","2023-01-04T18:22:29Z","51228" +"*LocalPotato.exe*",".{0,1000}LocalPotato\.exe.{0,1000}","offensive_tool_keyword","localpotato","The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.","T1550.002 - T1078.003 - T1005 - T1070.004","TA0004 - TA0006 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/decoder-it/LocalPotato","1","1","N/A","N/A","10","7","691","92","2023-11-07T01:09:08Z","2023-01-04T18:22:29Z","51229" +"*LocalPotato.sln*",".{0,1000}LocalPotato\.sln.{0,1000}","offensive_tool_keyword","localpotato","The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.","T1550.002 - T1078.003 - T1005 - T1070.004","TA0004 - TA0006 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/decoder-it/LocalPotato","1","1","N/A","N/A","10","7","691","92","2023-11-07T01:09:08Z","2023-01-04T18:22:29Z","51231" +"*LocalPotato.vcxproj*",".{0,1000}LocalPotato\.vcxproj.{0,1000}","offensive_tool_keyword","localpotato","The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.","T1550.002 - T1078.003 - T1005 - T1070.004","TA0004 - TA0006 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/decoder-it/LocalPotato","1","1","N/A","N/A","10","7","691","92","2023-11-07T01:09:08Z","2023-01-04T18:22:29Z","51232" +"*LocalPotato.zip*",".{0,1000}LocalPotato\.zip.{0,1000}","offensive_tool_keyword","localpotato","The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.","T1550.002 - T1078.003 - T1005 - T1070.004","TA0004 - TA0006 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/decoder-it/LocalPotato","1","1","N/A","N/A","10","7","691","92","2023-11-07T01:09:08Z","2023-01-04T18:22:29Z","51233" +"*LocalPotato-master*",".{0,1000}LocalPotato\-master.{0,1000}","offensive_tool_keyword","localpotato","The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.","T1550.002 - T1078.003 - T1005 - T1070.004","TA0004 - TA0006 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/decoder-it/LocalPotato","1","1","N/A","N/A","10","7","691","92","2023-11-07T01:09:08Z","2023-01-04T18:22:29Z","51234" +"*localrelay_linux_amd64*",".{0,1000}localrelay_linux_amd64.{0,1000}","offensive_tool_keyword","ligolo","ligolo is a simple and lightweight tool for establishing SOCKS5 or TCP tunnels from a reverse connection in complete safety (TLS certificate with elliptical curve)","T1071 - T1021 - T1573","TA0011 - TA0002","N/A","AvosLocker - LockBit","C2","https://github.com/sysdream/ligolo","1","1","#linux","N/A","10","10","1764","224","2023-01-06T19:49:22Z","2020-05-22T07:58:13Z","51236" +"*localtonet.com/download/*",".{0,1000}localtonet\.com\/download\/.{0,1000}","offensive_tool_keyword","localtonet","LocaltoNet is a reverse proxy that enables you to expose your localhost services to the internet","T1090 - T1102 - T1071 - T1105","TA0010 - TA0011 - TA0009 - TA0003 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/engineseller/localtonet","1","1","N/A","N/A","10","1","6","4","2022-01-31T03:19:25Z","2022-01-31T03:17:18Z","51240" +"*LocateBrc4Config*",".{0,1000}LocateBrc4Config.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51252" +"*lockbit3753ekiocyo5epmpy6klmejchjtzddoekjlnt6mu3qh4de2id.onion*",".{0,1000}lockbit3753ekiocyo5epmpy6klmejchjtzddoekjlnt6mu3qh4de2id\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51256" +"*lockbit3g3ohd3katajf6zaehxz4h4cnhmz5t735zpltywhwpc6oy3id.onion*",".{0,1000}lockbit3g3ohd3katajf6zaehxz4h4cnhmz5t735zpltywhwpc6oy3id\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51257" +"*lockbit3olp7oetlc4tl5zydnoluphh7fvdt5oa6arcp2757r7xkutid.onion*",".{0,1000}lockbit3olp7oetlc4tl5zydnoluphh7fvdt5oa6arcp2757r7xkutid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51258" +"*lockbit435xk3ki62yun7z5nhwz6jyjdp2c64j5vge536if2eny3gtid.onion*",".{0,1000}lockbit435xk3ki62yun7z5nhwz6jyjdp2c64j5vge536if2eny3gtid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51259" +"*lockbit4lahhluquhoka3t4spqym2m3dhe66d6lr337glmnlgg2nndad.onion*",".{0,1000}lockbit4lahhluquhoka3t4spqym2m3dhe66d6lr337glmnlgg2nndad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51260" +"*lockbit5eevg7vec4vwwtzgkl4kulap6oxbic2ye4mnmlq6njnpc47qd.onion*",".{0,1000}lockbit5eevg7vec4vwwtzgkl4kulap6oxbic2ye4mnmlq6njnpc47qd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51261" +"*lockbit6knrauo3qafoksvl742vieqbujxw7rd6ofzdtapjb4rrawqad.onion*",".{0,1000}lockbit6knrauo3qafoksvl742vieqbujxw7rd6ofzdtapjb4rrawqad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51262" +"*lockbit74beza5z3e3so7qmjnvlgoemscp7wtp33xo7xv7f7xtlqbkqd.onion*",".{0,1000}lockbit74beza5z3e3so7qmjnvlgoemscp7wtp33xo7xv7f7xtlqbkqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51263" +"*lockbit75naln4yj44rg6ez6vjmdcrt7up4kxmmmuvilcg4ak3zihxid.onion*",".{0,1000}lockbit75naln4yj44rg6ez6vjmdcrt7up4kxmmmuvilcg4ak3zihxid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51264" +"*lockbit7a2g6ve7etbcy6iyizjnuleffz4szgmxaawcbfauluavi5jqd.onion*",".{0,1000}lockbit7a2g6ve7etbcy6iyizjnuleffz4szgmxaawcbfauluavi5jqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51265" +"*lockbit7ouvrsdgtojeoj5hvu6bljqtghitekwpdy3b6y62ixtsu5jqd.onion*",".{0,1000}lockbit7ouvrsdgtojeoj5hvu6bljqtghitekwpdy3b6y62ixtsu5jqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51266" +"*lockbitaa46gwjck2xzmi2xops6x4x3aqn6ez7yntitero2k7ae6yoyd.onion*",".{0,1000}lockbitaa46gwjck2xzmi2xops6x4x3aqn6ez7yntitero2k7ae6yoyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51267" +"*lockbitapt2d73krlbewgv27tquljgxr33xbwwsp6rkyieto7u4ncead.onion*",".{0,1000}lockbitapt2d73krlbewgv27tquljgxr33xbwwsp6rkyieto7u4ncead\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51268" +"*lockbitapt2d73krlbewgv27tquljgxr33xbwwsp6rkyieto7u4ncead.onion.ly*",".{0,1000}lockbitapt2d73krlbewgv27tquljgxr33xbwwsp6rkyieto7u4ncead\.onion\.ly.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51269" +"*lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion*",".{0,1000}lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51270" +"*lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion.ly*",".{0,1000}lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd\.onion\.ly.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51271" +"*lockbitapt34kvrip6xojylohhxrwsvpzdffgs5z4pbbsywnzsbdguqd.onion*",".{0,1000}lockbitapt34kvrip6xojylohhxrwsvpzdffgs5z4pbbsywnzsbdguqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51272" +"*lockbitapt34kvrip6xojylohhxrwsvpzdffgs5z4pbbsywnzsbdguqd.onion.ly*",".{0,1000}lockbitapt34kvrip6xojylohhxrwsvpzdffgs5z4pbbsywnzsbdguqd\.onion\.ly.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51273" +"*lockbitapt5x4zkjbcqmz6frdhecqqgadevyiwqxukksspnlidyvd7qd.onion*",".{0,1000}lockbitapt5x4zkjbcqmz6frdhecqqgadevyiwqxukksspnlidyvd7qd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51274" +"*lockbitapt5x4zkjbcqmz6frdhecqqgadevyiwqxukksspnlidyvd7qd.onion.ly*",".{0,1000}lockbitapt5x4zkjbcqmz6frdhecqqgadevyiwqxukksspnlidyvd7qd\.onion\.ly.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51275" +"*lockbitapt6vx57t3eeqjofwgcglmutr3a35nygvokja5uuccip4ykyd.onion*",".{0,1000}lockbitapt6vx57t3eeqjofwgcglmutr3a35nygvokja5uuccip4ykyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51276" +"*lockbitapt6vx57t3eeqjofwgcglmutr3a35nygvokja5uuccip4ykyd.onion.ly*",".{0,1000}lockbitapt6vx57t3eeqjofwgcglmutr3a35nygvokja5uuccip4ykyd\.onion\.ly.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51277" +"*lockbitapt72iw55njgnqpymggskg5yp75ry7rirtdg4m7i42artsbqd.onion*",".{0,1000}lockbitapt72iw55njgnqpymggskg5yp75ry7rirtdg4m7i42artsbqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51278" +"*lockbitapt72iw55njgnqpymggskg5yp75ry7rirtdg4m7i42artsbqd.onion.ly*",".{0,1000}lockbitapt72iw55njgnqpymggskg5yp75ry7rirtdg4m7i42artsbqd\.onion\.ly.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51279" +"*lockbitaptawjl6udhpd323uehekiyatj6ftcxmkwe5sezs4fqgpjpid.onion*",".{0,1000}lockbitaptawjl6udhpd323uehekiyatj6ftcxmkwe5sezs4fqgpjpid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51280" +"*lockbitaptawjl6udhpd323uehekiyatj6ftcxmkwe5sezs4fqgpjpid.onion.ly*",".{0,1000}lockbitaptawjl6udhpd323uehekiyatj6ftcxmkwe5sezs4fqgpjpid\.onion\.ly.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51281" +"*lockbitaptbdiajqtplcrigzgdjprwugkkut63nbvy2d5r4w2agyekqd.onion*",".{0,1000}lockbitaptbdiajqtplcrigzgdjprwugkkut63nbvy2d5r4w2agyekqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51282" +"*lockbitaptbdiajqtplcrigzgdjprwugkkut63nbvy2d5r4w2agyekqd.onion.ly*",".{0,1000}lockbitaptbdiajqtplcrigzgdjprwugkkut63nbvy2d5r4w2agyekqd\.onion\.ly.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51283" +"*lockbitaptc2iq4atewz2ise62q63wfktyrl4qtwuk5qax262kgtzjqd.onion*",".{0,1000}lockbitaptc2iq4atewz2ise62q63wfktyrl4qtwuk5qax262kgtzjqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51284" +"*lockbitaptc2iq4atewz2ise62q63wfktyrl4qtwuk5qax262kgtzjqd.onion.ly*",".{0,1000}lockbitaptc2iq4atewz2ise62q63wfktyrl4qtwuk5qax262kgtzjqd\.onion\.ly.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51285" +"*lockbitb42tkml3ipianjbs6e33vhcshb7oxm2stubfvdzn3y2yqgbad.onion*",".{0,1000}lockbitb42tkml3ipianjbs6e33vhcshb7oxm2stubfvdzn3y2yqgbad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51286" +"*lockbitcuo23q7qrymbk6dsp2sadltspjvjxgcyp4elbnbr6tcnwq7qd.onion*",".{0,1000}lockbitcuo23q7qrymbk6dsp2sadltspjvjxgcyp4elbnbr6tcnwq7qd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51287" +"*lockbitsap2oaqhcun3syvbqt6n5nzt7fqosc6jdlmsfleu3ka4k2did.onion*",".{0,1000}lockbitsap2oaqhcun3syvbqt6n5nzt7fqosc6jdlmsfleu3ka4k2did\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51288" +"*lockbitsup4yezcd5enk5unncx3zcy7kw6wllyqmiyhvanjj352jayid.onion*",".{0,1000}lockbitsup4yezcd5enk5unncx3zcy7kw6wllyqmiyhvanjj352jayid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51289" +"*lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onion*",".{0,1000}lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51290" +"*lockbitsupdwon76nzykzblcplixwts4n4zoecugz2bxabtapqvmzqqd.onion*",".{0,1000}lockbitsupdwon76nzykzblcplixwts4n4zoecugz2bxabtapqvmzqqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51291" +"*lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onion*",".{0,1000}lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51292" +"*lockbitsupo7vv5vcl3jxpsdviopwvasljqcstym6efhh6oze7c6xjad.onion*",".{0,1000}lockbitsupo7vv5vcl3jxpsdviopwvasljqcstym6efhh6oze7c6xjad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51293" +"*lockbitsupq3g62dni2f36snrdb4n5qzqvovbtkt5xffw3draxk6gwqd.onion*",".{0,1000}lockbitsupq3g62dni2f36snrdb4n5qzqvovbtkt5xffw3draxk6gwqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51294" +"*lockbitsupqfyacidr6upt6nhhyipujvaablubuevxj6xy3frthvr3yd.onion*",".{0,1000}lockbitsupqfyacidr6upt6nhhyipujvaablubuevxj6xy3frthvr3yd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51295" +"*lockbitsupt7nr3fa6e7xyb73lk6bw6rcneqhoyblniiabj4uwvzapqd.onion*",".{0,1000}lockbitsupt7nr3fa6e7xyb73lk6bw6rcneqhoyblniiabj4uwvzapqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51296" +"*lockbitsupuhswh4izvoucoxsbnotkmgq6durg7kficg6u33zfvq3oyd.onion*",".{0,1000}lockbitsupuhswh4izvoucoxsbnotkmgq6durg7kficg6u33zfvq3oyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51297" +"*lockbitsupxcjntihbmat4rrh7ktowips2qzywh6zer5r3xafhviyhqd.onion*",".{0,1000}lockbitsupxcjntihbmat4rrh7ktowips2qzywh6zer5r3xafhviyhqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51298" +"*LockLess.exe*",".{0,1000}LockLess\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","51302" +"*Locksmith-main.zip*",".{0,1000}Locksmith\-main\.zip.{0,1000}","offensive_tool_keyword","Locksmith","A tiny tool to identify and remediate common misconfigurations in Active Directory Certificate Services","T1552.006 - T1222 - T1046","TA0007 - TA0040 - TA0043","N/A","N/A","Discovery","https://github.com/TrimarcJake/Locksmith","1","1","N/A","N/A","8","10","1086","100","2025-04-21T12:43:50Z","2022-04-28T01:37:32Z","51303" +"*log4_shell.rb*",".{0,1000}log4_shell\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51315" +"*log4shell*.nessus.org*",".{0,1000}log4shell.{0,1000}\.nessus\.org.{0,1000}","offensive_tool_keyword","nessus","Vulnerability scanner","T1046 - T1068 - T1190 - T1201 - T1222 - T1592","TA0001 - TA0002 - TA0007 - TA0011","N/A","N/A","Vulnerability Scanner","https://fr.tenable.com/products/nessus","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","51316" +"*log4shell.py*",".{0,1000}log4shell\.py.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","51317" +"*log4shell-scanner.jar*",".{0,1000}log4shell\-scanner\.jar.{0,1000}","offensive_tool_keyword","burp-log4shell","Log4Shell scanner for Burp Suite","T1190 - T1059.008 - T1071.001","TA0001 - TA0002 - TA0011","N/A","Dispossessor","Exploitation tool","https://github.com/silentsignal/burp-log4shell","1","1","N/A","N/A","8","5","484","72","2023-09-24T08:29:56Z","2021-12-12T14:52:49Z","51318" +"*logangoins/Cable*",".{0,1000}logangoins\/Cable.{0,1000}","offensive_tool_keyword","Cable","*.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation*","T1087 - T1016 - T1059 - T1482 - T1078","TA0007 - TA0002 - TA0003 - TA0005","N/A","N/A","Discovery","https://github.com/logangoins/Cable","1","1","N/A","N/A","7","4","361","40","2025-04-09T01:12:47Z","2024-08-10T19:47:08Z","51319" +"*logangoins/Krueger*",".{0,1000}logangoins\/Krueger.{0,1000}","offensive_tool_keyword","Krueger","remotely killing EDR with WDAC","T1562.001 - T1562.004 - T1218.011 - T1548.002 - T1027","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/logangoins/Krueger","1","1","N/A","N/A","9","4","353","42","2025-01-06T06:57:14Z","2024-11-15T20:11:01Z","51320" +"*logangoins/Stifle*",".{0,1000}logangoins\/Stifle.{0,1000}","offensive_tool_keyword","Stifle",".NET Post-Exploitation Utility for Abusing Explicit Certificate Mappings in ADCS","T1550.003 - T1552.004 - T1606.002","TA0006 - TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/logangoins/Stifle","1","1","N/A","N/A","7","2","140","9","2025-02-10T04:58:46Z","2025-02-08T06:13:43Z","51321" +"*LoGiC.NET.exe*",".{0,1000}LoGiC\.NET\.exe.{0,1000}","offensive_tool_keyword","LoGiC.NET","A more advanced free and open .NET obfuscator using dnlib","T1001","TA0011","N/A","N/A","Defense Evasion","https://github.com/AnErrupTion/LoGiC.NET","1","1","N/A","N/A","5","6","513","80","2023-08-23T09:55:54Z","2019-12-27T09:48:50Z","51325" +"*login.php?LOGMEOUTPLZ=true*",".{0,1000}login\.php\?LOGMEOUTPLZ\=true.{0,1000}","offensive_tool_keyword","wraith","A free and open-source, modular Remote Administration Tool (RAT) / Payload Dropper written in Go(lang) with a flexible command and control (C2) system.","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/wraith-labs/wraith","1","1","N/A","N/A","10","10","223","49","2023-12-03T22:16:27Z","2020-01-23T17:09:23Z","51326" +"*login-securite/conpass*",".{0,1000}login\-securite\/conpass.{0,1000}","offensive_tool_keyword","conpass","Continuous password spraying tool","T1110.001 - T1110 - T1078.001 - T1201","TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://github.com/login-securite/conpass","1","1","N/A","N/A","10","2","181","17","2025-03-03T15:05:25Z","2022-12-15T18:03:42Z","51330" +"*login-securite/lsassy*",".{0,1000}login\-securite\/lsassy.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51331" +"*login-securite/lsassy*",".{0,1000}login\-securite\/lsassy.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51332" +"*loginsight.thrift*",".{0,1000}loginsight\.thrift.{0,1000}","offensive_tool_keyword","vRealizeLogInsightRCE","POC for VMSA-2023-0001 affecting VMware vRealize Log Insight which includes the following CVEs: VMware vRealize Log Insight Directory Traversal Vulnerability (CVE-2022-31706) VMware vRealize Log Insight broken access control Vulnerability (CVE-2022-31704) VMware vRealize Log Insight contains an Information Disclosure Vulnerability (CVE-2022-31711)","T1190 - T1071 - T1003 - T1069 - T1110 - T1222","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007","N/A","Black Basta","Exploitation tool","https://github.com/horizon3ai/vRealizeLogInsightRCE","1","1","N/A","Added to cover the POC exploitation used in massive ransomware campagne that exploit public facing Vmware ESXI product ","4","2","149","22","2023-01-31T11:41:08Z","2023-01-30T22:01:08Z","51333" +"*logToBeaconLog*",".{0,1000}logToBeaconLog.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","51348" +"*LOLBins/NetLoader.xml*",".{0,1000}LOLBins\/NetLoader\.xml.{0,1000}","offensive_tool_keyword","NetLoader","Loads any C# binary in memory - patching AMSI + ETW","T1055.012 - T1112 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Flangvik/NetLoader","1","1","N/A","N/A","10","9","820","147","2021-10-03T16:41:03Z","2020-05-05T15:20:16Z","51350" +"*LOLSpoof.exe*",".{0,1000}LOLSpoof\.exe.{0,1000}","offensive_tool_keyword","LOLSpoof","An interactive shell to spoof some LOLBins command line","T1036.005","TA0005","N/A","N/A","Defense Evasion","https://github.com/itaymigdal/LOLSpoof","1","1","N/A","N/A","8","2","184","24","2024-01-27T05:43:59Z","2024-01-16T20:15:38Z","51352" +"*looCiprian/GC2-sheet*",".{0,1000}looCiprian\/GC2\-sheet.{0,1000}","offensive_tool_keyword","GC2-sheet","GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet and exfiltrate data using Google Drive.","T1071.002 - T1560 - T1105","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/looCiprian/GC2-sheet","1","1","N/A","N/A","10","10","578","111","2025-03-28T19:48:36Z","2021-09-15T19:06:12Z","51355" +"*LooneyPwner-main*",".{0,1000}LooneyPwner\-main.{0,1000}","offensive_tool_keyword","POC","Exploit tool for CVE-2023-4911 targeting the 'Looney Tunables' glibc vulnerability in various Linux distributions.","T1068 - T1210 - T1555","TA0001 - TA0003 - TA0005","N/A","N/A","Exploitation tool","https://github.com/chaudharyarjun/LooneyPwner","1","1","#linux","N/A","10","1","38","12","2023-10-18T04:59:50Z","2023-10-17T07:44:16Z","51359" +"*loot_memory.py*",".{0,1000}loot_memory\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","51360" +"*lorenzedzyzyjhzxvlcv347n5piltxamo755pzqpozh5l47kj7mxueid.onion*",".{0,1000}lorenzedzyzyjhzxvlcv347n5piltxamo755pzqpozh5l47kj7mxueid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51362" +"*lorenzezzwvtk3y24wfph4jpho27grrctqvf6yvld7256rnoz7yg2eid.onion*",".{0,1000}lorenzezzwvtk3y24wfph4jpho27grrctqvf6yvld7256rnoz7yg2eid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51363" +"*lorenzmlwpzgxq736jzseuterytjueszsvznuibanxomlpkyxk6ksoyd.onion*",".{0,1000}lorenzmlwpzgxq736jzseuterytjueszsvznuibanxomlpkyxk6ksoyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51364" +"*LostMyPassword.exe*",".{0,1000}LostMyPassword\.exe.{0,1000}","offensive_tool_keyword","LostMyPassword","Nirsoft tool that allows you to recover a lost password if it's stored by a software installed on your system","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009 ","N/A","LockBit","Credential Access","https://www.nirsoft.net/alpha/lostmypassword-x64.zip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51366" +"*LostMyPassword.zip*",".{0,1000}LostMyPassword\.zip.{0,1000}","offensive_tool_keyword","LostMyPassword","Nirsoft tool that allows you to recover a lost password if it's stored by a software installed on your system","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009 ","N/A","LockBit","Credential Access","https://www.nirsoft.net/alpha/lostmypassword-x64.zip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51367" +"*LostMyPasswordx64.zip*",".{0,1000}LostMyPasswordx64\.zip.{0,1000}","offensive_tool_keyword","LostMyPassword","Nirsoft tool that allows you to recover a lost password if it's stored by a software installed on your system","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009 ","N/A","LockBit","Credential Access","https://www.nirsoft.net/alpha/lostmypassword-x64.zip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51368" +"*lotus2john.py*",".{0,1000}lotus2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51369" +"*lsa_decryptor.py*",".{0,1000}lsa_decryptor\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","51379" +"*lsa_decryptor_nt*.py*",".{0,1000}lsa_decryptor_nt.{0,1000}\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","51380" +"*lsa_secrets.md*",".{0,1000}lsa_secrets\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51381" +"*lsadump.exe*",".{0,1000}lsadump\.exe.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","51383" +"*lsadump::*",".{0,1000}lsadump\:\:.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation command","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51384" +"*lsadump::backupkeys*",".{0,1000}lsadump\:\:backupkeys.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51385" +"*lsadump::cache*",".{0,1000}lsadump\:\:cache.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51386" +"*lsadump::changentlm*",".{0,1000}lsadump\:\:changentlm.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51387" +"*lsadump::dcshadow*",".{0,1000}lsadump\:\:dcshadow.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51388" +"*lsadump::dcsyn*",".{0,1000}lsadump\:\:dcsync.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51389" +"*lsadump::lsa*",".{0,1000}lsadump\:\:lsa.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51392" +"*lsadump::mbc*",".{0,1000}lsadump\:\:mbc.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51393" +"*lsadump::netsync*",".{0,1000}lsadump\:\:netsync.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51394" +"*lsadump::packages*",".{0,1000}lsadump\:\:packages.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51395" +"*lsadump::postzerologon*",".{0,1000}lsadump\:\:postzerologon.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51396" +"*lsadump::RpData*",".{0,1000}lsadump\:\:RpData.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51397" +"*lsadump::sam*",".{0,1000}lsadump\:\:sam.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51398" +"*lsadump::secrets*",".{0,1000}lsadump\:\:secrets.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51399" +"*lsadump::setntlm*",".{0,1000}lsadump\:\:setntlm.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51400" +"*lsadump::trust*",".{0,1000}lsadump\:\:trust.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51401" +"*lsadump::zerologon*",".{0,1000}lsadump\:\:zerologon.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51402" +"*lsarelayx.exe*",".{0,1000}lsarelayx\.exe.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","1","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","51404" +"*lsarelayx_0.1_ALPHA.zip*",".{0,1000}lsarelayx_0\.1_ALPHA\.zip.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","1","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","51405" +"*lsarpc_##*",".{0,1000}lsarpc_\#\#.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","51406" +"*lsasecrets.py*",".{0,1000}lsasecrets\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","10","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","51408" +"*lsasecretslive.py*",".{0,1000}lsasecretslive\.py.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","1","N/A","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","51410" +"*lsass.dmp*",".{0,1000}lsass\.dmp.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Dump LSASS memory through a process snapshot (-r) avoiding interacting with it directly","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51420" +"*lsass.dmp*",".{0,1000}lsass\.dmp.{0,1000}","offensive_tool_keyword","lsass","Dump LSASS memory through a process snapshot (-r) avoiding interacting with it directly","T1110","N/A","N/A","N/A","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51421" +"*lsass_*.dmp*",".{0,1000}lsass_.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","51425" +"*lsass_dump_*",".{0,1000}lsass_dump_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","51426" +"*lsass_dump_lsassy_*",".{0,1000}lsass_dump_lsassy_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","51427" +"*lsassdump.dmp*",".{0,1000}lsassdump\.dmp.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","51428" +"*LsassDump_20*.ps1*",".{0,1000}LsassDump_20.{0,1000}\.ps1.{0,1000}","offensive_tool_keyword","PSSW100AVB","This is the PSSW100AVB (Powershell Scripts With 100% AV Bypass) Framework.A list of useful Powershell scripts with 100% AV bypass ratio","T1112 - T1562.001 - T1086 - T1548.002 - T1059.001","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/tihanyin/PSSW100AVB","1","1","N/A","N/A","N/A","10","1104","174","2025-01-28T10:47:44Z","2021-10-08T17:36:24Z","51429" +"*LSASSProtectionBypass*/",".{0,1000}LSASSProtectionBypass.{0,1000}\/","offensive_tool_keyword","EDRSandBlast","EDRSandBlast is a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/wavestone-cdt/EDRSandblast","1","1","N/A","N/A","10","10","1633","292","2024-08-30T20:30:31Z","2021-11-02T15:02:42Z","51433" +"*LsassSilentProcessExit.cpp*",".{0,1000}LsassSilentProcessExit\.cpp.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","1","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","51434" +"*LsassSilentProcessExit.exe*",".{0,1000}LsassSilentProcessExit\.exe.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","1","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","51435" +"*LsassSilentProcessExit-master*",".{0,1000}LsassSilentProcessExit\-master.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","1","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","51437" +"*lsassy.*",".{0,1000}lsassy\..{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51441" +"*lsassy/dumpmethod*",".{0,1000}lsassy\/dumpmethod.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51443" +"*lsassy_dump*",".{0,1000}lsassy_dump.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","51444" +"*lsassy_dump*",".{0,1000}lsassy_dump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","51445" +"*lsassy_dump.py*",".{0,1000}lsassy_dump\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Exploitation tool","https://github.com/byt3bl33d3r/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","51446" +"*lsassy_linux_amd64*",".{0,1000}lsassy_linux_amd64.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","#linux","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51447" +"*lsassy_windows_amd64*",".{0,1000}lsassy_windows_amd64.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51449" +"*lsassy-linux-x64-*",".{0,1000}lsassy\-linux\-x64\-.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","#linux","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51450" +"*lsassy-MacOS-x64-*",".{0,1000}lsassy\-MacOS\-x64\-.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51451" +"*lsassy-windows-latest.zip*",".{0,1000}lsassy\-windows\-latest\.zip.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51452" +"*lsassy-windows-x64-*.exe",".{0,1000}lsassy\-windows\-x64\-.{0,1000}\.exe","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51453" +"*lsecqt/OffensiveCpp*",".{0,1000}lsecqt\/OffensiveCpp.{0,1000}","offensive_tool_keyword","OffensiveCpp","C/C++ snippets that can be handy in specific offensive scenarios","T1055 - T1047 - T1105 - T1117 - T1129 - T1135 - T1203","TA0002 - TA0003 - TA0006 - TA0007 - TA0009","N/A","N/A","Exploitation tool","https://github.com/lsecqt/OffensiveCpp","1","1","N/A","N/A","10","8","700","83","2025-01-26T08:05:48Z","2023-04-05T09:39:33Z","51456" +"*lu4p/ToRat*",".{0,1000}lu4p\/ToRat.{0,1000}","offensive_tool_keyword","ToRat","ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication","T1219 - T1021 - T1105","TA0008 - TA0011 - TA0005","N/A","N/A","C2","https://github.com/lu4p/ToRat","1","1","N/A","N/A","10","10","995","199","2023-03-13T08:56:55Z","2019-01-19T11:44:01Z","51460" +"*luckbit53sdne5yd5vdekadhwnbzjyqlbjkc4g33hs6faphfkvivaeid.onion*",".{0,1000}luckbit53sdne5yd5vdekadhwnbzjyqlbjkc4g33hs6faphfkvivaeid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51470" +"*luckystrike.ps1*",".{0,1000}luckystrike\.ps1.{0,1000}","offensive_tool_keyword","luckystrike","A PowerShell based utility for the creation of malicious Office macro documents.","T1566 - T1059 - T1027","TA0002 - TA0003 - TA0040","N/A","N/A","Exploitation tool","https://github.com/curi0usJack/luckystrike","1","1","N/A","N/A","10","10","1108","241","2017-11-03T17:52:13Z","2016-09-22T18:57:50Z","51471" +"*Luct0r/KerberOPSEC*",".{0,1000}Luct0r\/KerberOPSEC.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","1","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","51472" +"*LUgsLS1IT1NU*",".{0,1000}LUgsLS1IT1NU.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","51473" +"*luijait/PwnKit*",".{0,1000}luijait\/PwnKit.{0,1000}","offensive_tool_keyword","POC","exploitation of CVE-2021-4034","T1210","N/A","N/A","N/A","Exploitation tool","https://github.com/luijait/PwnKit-Exploit","1","1","N/A","N/A","N/A","1","96","14","2022-02-07T15:42:00Z","2022-01-26T18:01:26Z","51474" +"*luks2john.py*",".{0,1000}luks2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51475" +"*LVAsLS1QT1JU*",".{0,1000}LVAsLS1QT1JU.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","51479" +"*LW8sLS1vcHRpb25z*",".{0,1000}LW8sLS1vcHRpb25z.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","51480" +"*LWIsLS1idWNrZXQ=*",".{0,1000}LWIsLS1idWNrZXQ\=.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","51481" +"*LWYsLS1maWxl*",".{0,1000}LWYsLS1maWxl.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","51482" +"*LXAsLS1waWQ=*",".{0,1000}LXAsLS1waWQ\=.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","51483" +"*LXAsLS1wYXlsb2Fk*",".{0,1000}LXAsLS1wYXlsb2Fk.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","51484" +"*LXUsLS11cmk=*",".{0,1000}LXUsLS11cmk\=.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","51485" +"*ly4k/Certipy*",".{0,1000}ly4k\/Certipy.{0,1000}","offensive_tool_keyword","ADCSKiller","ADCSKiller is a Python-based tool designed to automate the process of discovering and exploiting Active Directory Certificate Services (ADCS) vulnerabilities. It leverages features of Certipy and Coercer to simplify the process of attacking ADCS infrastructure","T1552.004 - T1003.003 - T1114.002 - T1649","TA0006 - TA0003 - TA0005","N/A","N/A","Exploitation tool","https://github.com/grimlockx/ADCSKiller","1","1","N/A","N/A","N/A","8","710","70","2023-05-19T17:36:37Z","2023-05-19T06:51:41Z","51486" +"*ly4k/Certipy*",".{0,1000}ly4k\/Certipy.{0,1000}","offensive_tool_keyword","Certipy","Tool for Active Directory Certificate Services enumeration and abuse","T1552.003 - T1110.003 - T1550.004 - T1649","TA0006 - TA0008 - TA0003","N/A","Dispossessor","Exploitation tool","https://github.com/ly4k/Certipy","1","1","N/A","N/A","10","10","2704","380","2024-08-19T17:33:04Z","2021-10-06T23:02:40Z","51487" +"*ly4k/PassTheChallenge*",".{0,1000}ly4k\/PassTheChallenge.{0,1000}","offensive_tool_keyword","PassTheChallenge","Recovering NTLM hashes from Credential Guard","T1003 - T1555.002","TA0006 - TA0005","N/A","N/A","Exploitation tool","https://github.com/ly4k/PassTheChallenge","1","1","N/A","N/A","9","4","334","21","2022-12-26T01:09:18Z","2022-12-26T00:56:40Z","51488" +"*ly4k/SpoolFool*",".{0,1000}ly4k\/SpoolFool.{0,1000}","offensive_tool_keyword","SpoolFool","Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)","T1068 - T1055 - T1059.003","TA0004 - TA0005 - TA0003","","Dispossessor","Privilege Escalation","https://github.com/ly4k/SpoolFool","1","1","N/A","N/A","9","8","788","160","2022-02-09T16:54:09Z","2022-02-08T17:25:44Z","51489" +"*lyncsmash*",".{0,1000}lyncsmash.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations","T1580 - T1201 - T1071 - T1110 - T1078","TA0043 - TA0006 - TA0008","N/A","N/A","Exploitation tool","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","51490" +"*lyncsmash.git*",".{0,1000}lyncsmash\.git.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","51491" +"*lyncsmash.log*",".{0,1000}lyncsmash\.log.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","#logfile","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","51492" +"*lyncsmash.py*",".{0,1000}lyncsmash\.py.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","51493" +"*lyncsmash-master*",".{0,1000}lyncsmash\-master.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","51494" +"*lynxmk/blackvision*",".{0,1000}lynxmk\/blackvision.{0,1000}","offensive_tool_keyword","blackvision","Command line Remote Access tool (RAT) for Windows.","T1090 - T1095 - T1008","TA0011","N/A","N/A","Malware","https://github.com/quantumcore/blackvision","1","1","N/A","N/A","10","1","14","10","2019-09-16T18:32:51Z","2019-07-04T17:32:35Z","51496" +"*lypd0/DeadPotato*",".{0,1000}lypd0\/DeadPotato.{0,1000}","offensive_tool_keyword","DeadPotato","DeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privileges","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","N/A","N/A","Privilege Escalation","https://github.com/lypd0/DeadPotato","1","1","N/A","N/A","10","4","382","45","2024-08-17T06:08:29Z","2024-07-31T01:08:30Z","51497" +"*M.i.m.i.k.a.t.z*",".{0,1000}M\.i\.m\.i\.k\.a\.t\.z.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","51504" +"*M.i.m.i.k.a.t.z*",".{0,1000}M\.i\.m\.i\.k\.a\.t\.z.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51505" +"*m00zh33/golang_c2*",".{0,1000}m00zh33\/golang_c2.{0,1000}","offensive_tool_keyword","golang_c2","C2 written in Go for red teams aka gorfice2k","T1071 - T1021 - T1090","TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/m00zh33/golang_c2","1","1","N/A","N/A","10","10","6","8","2019-03-18T00:46:41Z","2019-03-19T02:39:59Z","51506" +"*m0nad/Diamorphine*",".{0,1000}m0nad\/Diamorphine.{0,1000}","offensive_tool_keyword","Diamorphine","LKM rootkit for Linux Kernels","T1547.006 - T1548.002 - T1562.001 - T1027","TA0003 - TA0004 - TA0005 - TA0006 - TA0007","N/A","N/A","Persistence","https://github.com/m0nad/Diamorphine","1","1","#linux","N/A","10","10","1986","451","2023-09-20T10:56:06Z","2013-11-06T22:38:47Z","51507" +"*m0rv4i/SharpCookieMonster*",".{0,1000}m0rv4i\/SharpCookieMonster.{0,1000}","offensive_tool_keyword","SharpCookieMonster","This C# project will dump cookies for all sites. even those with httpOnly/secure/session","T1539 - T1606","TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/m0rv4i/SharpCookieMonster","1","1","N/A","N/A","N/A","3","202","44","2023-03-15T09:51:09Z","2020-01-22T18:39:49Z","51508" +"*m232fdxbfmbrcehbrj5iayknxnggf6niqfj6x4iedrgtab4qupzjlaid.onion*",".{0,1000}m232fdxbfmbrcehbrj5iayknxnggf6niqfj6x4iedrgtab4qupzjlaid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51509" +"*m3f157O/combine_harvester*",".{0,1000}m3f157O\/combine_harvester.{0,1000}","offensive_tool_keyword","combine_harvester","Rust in-memory dumper","T1055 - T1055.001 - T1055.012","TA0005 - TA0006","N/A","N/A","Defense Evasion","https://github.com/m3f157O/combine_harvester","1","1","N/A","N/A","10","2","108","17","2023-07-26T07:16:00Z","2023-07-20T07:37:51Z","51511" +"*m4ll0k/SecretFinder*",".{0,1000}m4ll0k\/SecretFinder.{0,1000}","offensive_tool_keyword","secretfinder","SecretFinder is a python script based on LinkFinder written to discover sensitive data like apikeys - accesstoken - authorizations - jwt..etc in JavaScript files","T1083 - T1081 - T1113","TA0003 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/m4ll0k/SecretFinder","1","1","N/A","N/A","N/A","10","2153","405","2024-05-26T09:36:41Z","2020-06-08T10:50:12Z","51512" +"*m6s6axasulxjkhzh.onion*",".{0,1000}m6s6axasulxjkhzh\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51513" +"*m8sec/nullinux*",".{0,1000}m8sec\/nullinux.{0,1000}","offensive_tool_keyword","nullinux","Internal penetration testing tool for Linux that can be used to enumerate OS information/domain information/ shares/ directories and users through SMB.","T1087 - T1016 - T1077 - T1018","TA0007 - TA0006","N/A","N/A","Discovery","https://github.com/m8sec/nullinux","1","1","#linux","N/A","7","6","575","101","2024-06-19T14:29:09Z","2016-04-28T16:45:02Z","51514" +"*MAAD_Attack.ps1*",".{0,1000}MAAD_Attack\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","51515" +"*MAAD_Config.ps1*",".{0,1000}MAAD_Config\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","51516" +"*MAAD_Mitre_Map.ps1*",".{0,1000}MAAD_Mitre_Map\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","51517" +"*MAADInitialization.ps1*",".{0,1000}MAADInitialization\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","51518" +"*mac_dirty_cow.*",".{0,1000}mac_dirty_cow\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51520" +"*mac2john.py*",".{0,1000}mac2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51521" +"*mac2john-alt.py*",".{0,1000}mac2john\-alt\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51522" +"*MaccaroniC2.git*",".{0,1000}MaccaroniC2\.git.{0,1000}","offensive_tool_keyword","MaccaroniC2","A proof-of-concept Command & Control framework that utilizes the powerful AsyncSSH Python library which provides an asynchronous client and server implementation of the SSHv2 protocol and use PyNgrok wrapper for ngrok integration.","T1090 - T1059.003","TA0011 - TA0002","N/A","N/A","C2","https://github.com/CalfCrusher/MaccaroniC2","1","1","N/A","N/A","10","10","76","16","2023-06-27T17:43:59Z","2023-05-21T13:33:48Z","51523" +"*MaceTrap.exe*",".{0,1000}MaceTrap\.exe.{0,1000}","offensive_tool_keyword","macetrap","MaceTrap is a proof-of-concept for time stomping using SetFileTime. MaceTrap allows you to set the CreationTime / LastAccessTime / LastWriteTime for arbitrary files and folders","T1070.004","TA0040","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Sharp-Suite/tree/master/MaceTrap","1","1","N/A","N/A","N/A","10","1131","203","2022-12-22T23:57:19Z","2018-12-10T00:08:37Z","51527" +"*machine1337/TelegramRAT*",".{0,1000}machine1337\/TelegramRAT.{0,1000}","offensive_tool_keyword","TelegramRAT","Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions","T1071.001 - T1105 - T1027","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/machine1337/TelegramRAT","1","1","N/A","N/A","10","10","372","62","2024-01-23T12:05:59Z","2023-06-30T10:59:55Z","51528" +"*MacroDetectSandbox.vbs*",".{0,1000}MacroDetectSandbox\.vbs.{0,1000}","offensive_tool_keyword","phishing-HTML-linter","Phishing and Social-Engineering related scripts","T1566.001 - T1056.001","TA0040 - TA0001","N/A","N/A","Phishing","https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing","1","1","N/A","N/A","10","10","2689","527","2023-06-27T19:16:49Z","2018-02-02T21:24:03Z","51532" +"*MacroExploit.txt*",".{0,1000}MacroExploit\.txt.{0,1000}","offensive_tool_keyword","Excel-Exploit","MacroExploit use in excel sheet","T1137.001 - T1203 - T1059.007 - T1566.001 - T1564.003","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Mr-Cyb3rgh0st/Excel-Exploit/tree/main","1","1","N/A","N/A","N/A","1","20","3","2023-06-12T11:47:52Z","2023-06-12T11:46:53Z","51533" +"*Macrome.csproj*",".{0,1000}Macrome\.csproj.{0,1000}","offensive_tool_keyword","Macrome","An Excel Macro Document Reader/Writer for Red Teamers & Analysts. Blog posts describing what this tool actually does can be found https://malware.pizza/2020/05/12/evading-av-with-excel-macros-and-biff8-xls/ and https://malware.pizza/2020/06/19/further-evasion-in-the-forgotten-corners-of-ms-xls/","T1140","TA0005","N/A","N/A","Exploitation tool","https://github.com/michaelweber/Macrome","1","1","N/A","N/A","N/A","6","520","79","2022-02-01T16:26:13Z","2020-05-07T22:44:11Z","51537" +"*Macrome.dll*",".{0,1000}Macrome\.dll.{0,1000}","offensive_tool_keyword","Macrome","An Excel Macro Document Reader/Writer for Red Teamers & Analysts. Blog posts describing what this tool actually does can be found https://malware.pizza/2020/05/12/evading-av-with-excel-macros-and-biff8-xls/ and https://malware.pizza/2020/06/19/further-evasion-in-the-forgotten-corners-of-ms-xls/","T1140","TA0005","N/A","N/A","Exploitation tool","https://github.com/michaelweber/Macrome","1","1","N/A","N/A","N/A","6","520","79","2022-02-01T16:26:13Z","2020-05-07T22:44:11Z","51538" +"*Macrome.sln*",".{0,1000}Macrome\.sln.{0,1000}","offensive_tool_keyword","Macrome","An Excel Macro Document Reader/Writer for Red Teamers & Analysts. Blog posts describing what this tool actually does can be found https://malware.pizza/2020/05/12/evading-av-with-excel-macros-and-biff8-xls/ and https://malware.pizza/2020/06/19/further-evasion-in-the-forgotten-corners-of-ms-xls/","T1140","TA0005","N/A","N/A","Exploitation tool","https://github.com/michaelweber/Macrome","1","1","N/A","N/A","N/A","6","520","79","2022-02-01T16:26:13Z","2020-05-07T22:44:11Z","51539" +"*MACshellcode.cpp*",".{0,1000}MACshellcode\.cpp.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","51540" +"*MACshellcode.exe*",".{0,1000}MACshellcode\.exe.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","51541" +"*MACshellcode.sln*",".{0,1000}MACshellcode\.sln.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","51542" +"*MACshellcode.vcxproj*",".{0,1000}MACshellcode\.vcxproj.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","51543" +"*MadExploits/Gecko*",".{0,1000}MadExploits\/Gecko.{0,1000}","offensive_tool_keyword","Gecko","Gecko Backdoor is a web php backdoor","T1100 - T1059 - T1105 - T1203","TA0011 - TA0003","N/A","N/A","C2","https://github.com/MadExploits/Gecko","1","1","N/A","N/A","10","10","118","56","2025-02-08T17:50:28Z","2022-07-15T05:51:04Z","51546" +"*mail-in-the-middle.py*",".{0,1000}mail\-in\-the\-middle\.py.{0,1000}","offensive_tool_keyword","mail-in-the-middle","This script sits in the middle between a legitimate sender of an email and the legitimate recipient of that email. This means that we (the attackers) are receiving sensitive information not originally destined to us","T1557 - T1598.002 - T1566.002 - T1192 - T1204.002 - T1539 - T1593","TA0001 - TA0006 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/sensepost/mail-in-the-middle","1","1","N/A","N/A","8","2","108","9","2024-11-07T10:41:00Z","2024-02-21T07:25:37Z","51552" +"*mailpv.exe*",".{0,1000}mailpv\.exe.{0,1000}","offensive_tool_keyword","mailpv","Mail PassView is a small password-recovery tool that reveals the passwords and other account details in email clients","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/mailpv.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51553" +"*mailpv.zip*",".{0,1000}mailpv\.zip.{0,1000}","offensive_tool_keyword","mailpv","Mail PassView is a small password-recovery tool that reveals the passwords and other account details in email clients","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/mailpv.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51554" +"*MailSniper*",".{0,1000}MailSniper.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc...). It can be used as a non-administrative user to search their own email. or by an Exchange administrator to search the mailboxes of every user in a domain","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Discovery","https://github.com/dafthack/MailSniper","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","51555" +"*MailSniper.ps1*",".{0,1000}MailSniper\.ps1.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","51556" +"*main/gcr.py*",".{0,1000}main\/gcr\.py.{0,1000}","offensive_tool_keyword","GCR-Google-Calendar-RAT","Google Calendar RAT is a PoC of Command&Control over Google Calendar Events","T1071.001 - T1021.002 - T1059","TA0002 - TA0005","N/A","N/A","C2","https://github.com/MrSaighnal/GCR-Google-Calendar-RAT","1","1","N/A","N/A","10","10","215","41","2024-04-11T18:06:02Z","2023-06-18T13:23:31Z","51557" +"*main_air_service-probes.go*",".{0,1000}main_air_service\-probes\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","51558" +"*main_pro_service-probes.go*",".{0,1000}main_pro_service\-probes\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","51559" +"*make_kernel_shellcode*",".{0,1000}make_kernel_shellcode.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-EternalBlue.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","51569" +"*make_kernel_user_payload*",".{0,1000}make_kernel_user_payload.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-EternalBlue.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","51570" +"*make_smb1_anonymous_login_packet*",".{0,1000}make_smb1_anonymous_login_packet.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-EternalBlue.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","51571" +"*make_smb1_echo_packet*",".{0,1000}make_smb1_echo_packet.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-EternalBlue.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","51572" +"*make_smb1_free_hole_session_packet*",".{0,1000}make_smb1_free_hole_session_packet.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-EternalBlue.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","51573" +"*make_smb1_nt_trans_packet*",".{0,1000}make_smb1_nt_trans_packet.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-EternalBlue.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","51574" +"*make_smb1_trans2_explo*",".{0,1000}make_smb1_trans2_explo.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-EternalBlue.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","51575" +"*make_smb2_payload_body_packet*",".{0,1000}make_smb2_payload_body_packet.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-EternalBlue.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","51576" +"*make_smb2_payload_headers_packet*",".{0,1000}make_smb2_payload_headers_packet.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-EternalBlue.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","51577" +"*makebof.bat*",".{0,1000}makebof\.bat.{0,1000}","offensive_tool_keyword","cobaltstrike","Takes the original PPLFault and the original included DumpShellcode and combinds it all into a BOF targeting cobalt strike.","T1055 - T1078.003","TA0002 - TA0006","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Credential Access","https://github.com/trustedsec/PPLFaultDumpBOF","1","1","N/A","N/A","N/A","2","140","11","2023-05-17T12:57:20Z","2023-05-16T13:02:22Z","51578" +"*MakeHTTPSmugglerJAR.launch*",".{0,1000}MakeHTTPSmugglerJAR\.launch.{0,1000}","offensive_tool_keyword","burpsuite","A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/nccgroup/BurpSuiteHTTPSmuggler","1","1","N/A","network exploitation tool","N/A","8","721","107","2019-05-04T06:15:42Z","2018-07-03T07:47:58Z","51579" +"*makemeadmin.com/*",".{0,1000}makemeadmin\.com\/.{0,1000}","offensive_tool_keyword","MakeMeAdmin","Enables users to elevate themselves to administrator-level rights","T1078 - T1059 - T1087","TA0004","N/A","N/A","Privilege Escalation","https://github.com/pseymour/MakeMeAdmin","1","1","N/A","N/A","9","5","430","94","2024-12-22T02:56:23Z","2018-05-29T19:42:58Z","51581" +"*MakeMeAdminRemoteUI.exe*",".{0,1000}MakeMeAdminRemoteUI\.exe.{0,1000}","offensive_tool_keyword","MakeMeAdmin","Enables users to elevate themselves to administrator-level rights","T1078 - T1059 - T1087","TA0004","N/A","N/A","Privilege Escalation","https://github.com/pseymour/MakeMeAdmin","1","1","N/A","N/A","9","5","430","94","2024-12-22T02:56:23Z","2018-05-29T19:42:58Z","51582" +"*MakeMeAdminService.exe*",".{0,1000}MakeMeAdminService\.exe.{0,1000}","offensive_tool_keyword","MakeMeAdmin","Enables users to elevate themselves to administrator-level rights","T1078 - T1059 - T1087","TA0004","N/A","N/A","Privilege Escalation","https://github.com/pseymour/MakeMeAdmin","1","1","N/A","N/A","9","5","430","94","2024-12-22T02:56:23Z","2018-05-29T19:42:58Z","51583" +"*MakeMeAdminService.fr*",".{0,1000}MakeMeAdminService\.fr.{0,1000}","offensive_tool_keyword","MakeMeAdmin","Enables users to elevate themselves to administrator-level rights","T1078 - T1059 - T1087","TA0004","N/A","N/A","Privilege Escalation","https://github.com/pseymour/MakeMeAdmin","1","1","N/A","N/A","9","5","430","94","2024-12-22T02:56:23Z","2018-05-29T19:42:58Z","51584" +"*MakeMeAdminUI.resources.dll*",".{0,1000}MakeMeAdminUI\.resources\.dll.{0,1000}","offensive_tool_keyword","MakeMeAdmin","Enables users to elevate themselves to administrator-level rights","T1078 - T1059 - T1087","TA0004","N/A","N/A","Privilege Escalation","https://github.com/pseymour/MakeMeAdmin","1","1","N/A","N/A","9","5","430","94","2024-12-22T02:56:23Z","2018-05-29T19:42:58Z","51585" +"*MakeMeEnterpriseAdmin.ps1*",".{0,1000}MakeMeEnterpriseAdmin\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","51586" +"*MakeMeEnterpriseAdmin.ps1*",".{0,1000}MakeMeEnterpriseAdmin\.ps1.{0,1000}","offensive_tool_keyword","KRBUACBypass","UAC Bypass By Abusing Kerberos Tickets","T1548.002 - T1558 - T1558.003","TA0004 - TA0006","N/A","N/A","Defense Evasion","https://github.com/wh0amitz/KRBUACBypass","1","1","N/A","N/A","8","5","496","62","2023-08-10T02:51:59Z","2023-07-27T12:08:12Z","51587" +"*MakeMeEnterpriseAdmin.ps1*",".{0,1000}MakeMeEnterpriseAdmin\.ps1.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","51588" +"*malcomvetter/CSExec*",".{0,1000}malcomvetter\/CSExec.{0,1000}","offensive_tool_keyword","csexec","An implementation of PSExec in C#","T1021.002 - T1059.004 - T1077","TA0008 - TA0009 - TA0011","N/A","N/A","Lateral Movement","https://github.com/malcomvetter/CSExec","1","1","N/A","N/A","10","4","325","62","2020-12-01T14:52:01Z","2018-08-08T21:09:07Z","51589" +"*malcomvetter/UnstoppableService*",".{0,1000}malcomvetter\/UnstoppableService.{0,1000}","offensive_tool_keyword","UnstoppableService","a Windows service in C# that is self installing as a single executable and sets proper attributes to prevent an administrator from stopping or pausing the service through the Windows Service Control Manager interface","T1543.003 - T1564.001 - T1490","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/malcomvetter/UnstoppableService","1","1","N/A","N/A","5","1","66","15","2019-01-19T22:38:18Z","2018-08-07T22:11:22Z","51590" +"*Maldev-Academy/HellHall*",".{0,1000}Maldev\-Academy\/HellHall.{0,1000}","offensive_tool_keyword","HellsHall","Performing Indirect Clean Syscalls","T1106","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Maldev-Academy/HellHall","1","1","N/A","N/A","8","6","535","71","2023-04-19T06:10:47Z","2023-01-03T04:43:05Z","51595" +"*maldevel/canisrufus*",".{0,1000}maldevel\/canisrufus.{0,1000}","offensive_tool_keyword","canisrufus","A stealthy Python based Windows backdoor that uses Github as a command and control server","T1105 - T1071 - T1027","TA0003 - TA0011 - TA0005 - TA0010","N/A","Black Basta","C2","https://github.com/maldevel/canisrufus","1","1","N/A","N/A","10","10","263","78","2017-08-15T15:46:20Z","2017-08-12T06:49:40Z","51596" +"*malicious.csproj*",".{0,1000}malicious\.csproj.{0,1000}","offensive_tool_keyword","PowerLessShell","PowerLessShell rely on MSBuild.exe to remotely execute PowerShell scripts and commands without spawning powershell.exe. You can also execute raw shellcode using the same approach.","T1218.010 - T1059 - T1105 - T1047 - T1055","TA0002 - TA0011 - TA0008","N/A","N/A","Defense Evasion","https://github.com/Mr-Un1k0d3r/PowerLessShell","1","1","N/A","N/A","N/A","10","1498","256","2023-03-23T13:30:14Z","2017-05-29T23:03:52Z","51600" +"*malicious.dll*",".{0,1000}malicious\.dll.{0,1000}","offensive_tool_keyword","spoolsploit","A collection of Windows print spooler exploits containerized with other utilities for practical exploitation.","T1204 - T1547 - T1562 - T1003 - T1018 - T1570 - T1005","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/BeetleChunks/SpoolSploit","1","1","N/A","N/A","N/A","6","555","90","2021-07-16T04:49:43Z","2021-07-07T00:32:28Z","51601" +"*MaliciousInjectedDll.dll*",".{0,1000}MaliciousInjectedDll\.dll.{0,1000}","offensive_tool_keyword","UnlinkDLL","DLL Unlinking from InLoadOrderModuleList - InMemoryOrderModuleList - InInitializationOrderModuleList and LdrpHashTable","T1055 - T1027 - T1070","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/frkngksl/UnlinkDLL","1","1","N/A","N/A","7","1","57","13","2023-12-15T12:04:00Z","2023-12-13T14:37:33Z","51603" +"*MaliciousMacroMSBuild-master*",".{0,1000}MaliciousMacroMSBuild\-master.{0,1000}","offensive_tool_keyword","MaliciousMacroMSBuild","Generates Malicious Macro and Execute Powershell or Shellcode via MSBuild Application Whitelisting Bypass.","T1059.001 - T1059.003 - T1127 - T1027.002","TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/infosecn1nja/MaliciousMacroMSBuild","1","1","N/A","N/A","8","6","507","123","2019-08-06T08:16:05Z","2018-04-09T23:16:30Z","51605" +"*Malleable C2 Files*",".{0,1000}Malleable\sC2\sFiles.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike toolkit","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/1135/1135-CobaltStrike-ToolKit","1","1","N/A","N/A","10","10","150","35","2023-12-01T03:18:35Z","2019-02-22T09:36:44Z","51606" +"*Malleable PE/Stage*",".{0,1000}Malleable\sPE\/Stage.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","51607" +"*malleable_redirector.py*",".{0,1000}malleable_redirector\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","51608" +"*malleable_redirector_hidden_api_endpoint*",".{0,1000}malleable_redirector_hidden_api_endpoint.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","51609" +"*Malleable-C2-Profiles*",".{0,1000}Malleable\-C2\-Profiles.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51610" +"*Malleable-C2-Randomizer*",".{0,1000}Malleable\-C2\-Randomizer.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","51611" +"*Malleable-C2-Randomizer*",".{0,1000}Malleable\-C2\-Randomizer.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51612" +"*malleable-c2-randomizer.py*",".{0,1000}malleable\-c2\-randomizer\.py.{0,1000}","offensive_tool_keyword","C2concealer","C2concealer is a command line tool that generates randomized C2 malleable profiles for use in Cobalt Strike.","T1090 - T1090.003 - T1027 - T1027.005 - T1071 - T1071.001","TA0042 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/RedSiege/C2concealer","1","1","N/A","N/A","10","10","1053","172","2024-06-25T11:10:54Z","2020-03-23T14:13:16Z","51613" +"*MalleableProfileB64*",".{0,1000}MalleableProfileB64.{0,1000}","offensive_tool_keyword","AzureC2Relay","AzureC2Relay is an Azure Function that validates and relays Cobalt Strike beacon traffic by verifying the incoming requests based on a Cobalt Strike Malleable C2 profile.","T1090 - T1090.003 - T1027 - T1027.005 - T1071 - T1071.001","TA0042 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/Flangvik/AzureC2Relay","1","1","N/A","N/A","10","10","220","49","2021-02-15T18:06:38Z","2021-02-14T00:03:52Z","51614" +"*MalleableProfiles.vue*",".{0,1000}MalleableProfiles\.vue.{0,1000}","offensive_tool_keyword","empire","Starkiller is a Frontend for Powershell Empire. It is a web application written in VueJS","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Starkiller","1","1","N/A","N/A","10","10","1461","206","2025-03-25T03:30:16Z","2020-03-09T05:48:58Z","51615" +"*malleable-redirector-config*",".{0,1000}malleable\-redirector\-config.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","51616" +"*MalSCCM.exe*",".{0,1000}MalSCCM\.exe.{0,1000}","offensive_tool_keyword","MalSCCM","This tool allows you to abuse local or remote SCCM servers to deploy malicious applications to hosts they manage","T1072 - T1059.005 - T1090","TA0008 - TA0002 - TA0011","N/A","N/A","Exploitation tool","https://github.com/nettitude/MalSCCM","1","1","N/A","N/A","10","3","246","37","2023-09-28T17:29:50Z","2022-05-04T08:27:27Z","51618" +"*MalSCCM-main*",".{0,1000}MalSCCM\-main.{0,1000}","offensive_tool_keyword","MalSCCM","This tool allows you to abuse local or remote SCCM servers to deploy malicious applications to hosts they manage","T1072 - T1059.005 - T1090","TA0008 - TA0002 - TA0011","N/A","N/A","Exploitation tool","https://github.com/nettitude/MalSCCM","1","1","N/A","N/A","10","3","246","37","2023-09-28T17:29:50Z","2022-05-04T08:27:27Z","51619" +"*man_in_the_browser.json*",".{0,1000}man_in_the_browser\.json.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","51624" +"*ManagedEasyHook.dll*",".{0,1000}ManagedEasyHook\.dll.{0,1000}","offensive_tool_keyword","Dendrobate","Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code","T1055.012 - T1059.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Dendrobate","1","1","N/A","N/A","10","2","131","27","2021-11-19T12:18:50Z","2021-02-15T11:15:51Z","51628" +"*manageengine_adselfservice_plus_cve_2022_28810.*",".{0,1000}manageengine_adselfservice_plus_cve_2022_28810\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51630" +"*manageengine_xnode/CVE*",".{0,1000}manageengine_xnode\/CVE.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51631" +"*manager/keepass.py*",".{0,1000}manager\/keepass\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","51632" +"*manager/mRemoteNG.py*",".{0,1000}manager\/mRemoteNG\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","51633" +"*manasmbellani/brc-1.2.2*",".{0,1000}manasmbellani\/brc\-1\.2\.2.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51635" +"*mandatoryprogrammer/CursedChrome*",".{0,1000}mandatoryprogrammer\/CursedChrome.{0,1000}","offensive_tool_keyword","CursedChrome","Chrome-extension implant that turns victim Chrome browsers into fully-functional HTTP proxies allowing you to browse sites as your victims","T1176 - T1219 - T1090","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/mandatoryprogrammer/CursedChrome","1","1","N/A","N/A","10","10","1533","226","2024-10-26T19:06:54Z","2020-04-26T20:55:05Z","51636" +"*mandiant/ADFSDump*",".{0,1000}mandiant\/ADFSDump.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","1","N/A","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","51637" +"*mandiant/ccmpwn*",".{0,1000}mandiant\/ccmpwn.{0,1000}","offensive_tool_keyword","ccmpwn","Lateral Movement script that leverages the CcmExec service to remotely hijack user sessions","T1021.005","TA0008","N/A","N/A","Lateral Movement","https://github.com/mandiant/ccmpwn","1","1","N/A","N/A","10","3","201","25","2024-03-26T20:51:27Z","2024-03-14T18:43:24Z","51638" +"*mandiant/DueDLLigence*",".{0,1000}mandiant\/DueDLLigence.{0,1000}","offensive_tool_keyword","DueDLLigence","Shellcode runner framework for application whitelisting bypasses and DLL side-loading","T1055.012 - T1218.011","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/mandiant/DueDLLigence","1","1","N/A","N/A","10","5","469","89","2023-06-02T14:24:43Z","2019-10-04T18:34:27Z","51639" +"*mandiant/gocrack*",".{0,1000}mandiant\/gocrack.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","1","N/A","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","51640" +"*mandiant/msi-search*",".{0,1000}mandiant\/msi\-search.{0,1000}","offensive_tool_keyword","msi-search","This tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairs","T1005 ","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/mandiant/msi-search","1","1","N/A","N/A","10","3","276","31","2023-07-20T18:12:49Z","2023-06-29T18:31:56Z","51641" +"*mandiant/SharPersist*",".{0,1000}mandiant\/SharPersist.{0,1000}","offensive_tool_keyword","SharPersist","SharPersist Windows persistence toolkit written in C#.","T1547 - T1053 - T1027 - T1028 - T1112","TA0003 - TA0008","N/A","N/A","Persistence","https://github.com/fireeye/SharPersist","1","1","N/A","N/A","10","10","1460","257","2023-08-11T00:52:09Z","2019-06-21T13:32:14Z","51642" +"*manspider.py*",".{0,1000}manspider\.py.{0,1000}","offensive_tool_keyword","MANSPIDER","Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!","T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083","TA0007 - TA0009 - TA0010","N/A","N/A","Discovery","https://github.com/blacklanternsecurity/MANSPIDER","1","1","N/A","N/A","8","10","1117","138","2024-07-18T06:14:04Z","2020-03-18T13:27:20Z","51649" +"*manspider_scan*",".{0,1000}manspider_scan.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","51651" +"*MANSPIDER-master*",".{0,1000}MANSPIDER\-master.{0,1000}","offensive_tool_keyword","MANSPIDER","Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!","T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083","TA0007 - TA0009 - TA0010","N/A","N/A","Discovery","https://github.com/blacklanternsecurity/MANSPIDER","1","1","N/A","N/A","8","10","1117","138","2024-07-18T06:14:04Z","2020-03-18T13:27:20Z","51652" +"*map_payload_dll*",".{0,1000}map_payload_dll.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","51654" +"*mapper_cve_exploit.py*",".{0,1000}mapper_cve_exploit\.py.{0,1000}","offensive_tool_keyword","Xerror","fully automated pentesting tool","T1083 - T1069 - T1204 - T1059 - T1078","TA0007 - TA0005 - TA0002 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Chudry/Xerror","1","1","N/A","N/A","N/A","6","509","110","2022-12-08T04:33:03Z","2019-08-16T21:20:52Z","51656" +"*masky_dump*",".{0,1000}masky_dump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","51658" +"*master/bootkit/src*",".{0,1000}master\/bootkit\/src.{0,1000}","offensive_tool_keyword","bootkit-rs","Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus)","T1542.004 - T1067.002 - T1012 - T1053.005 - T1057","TA0002 - TA0040 - TA0003 - TA0001","N/A","N/A","Defense Evasion","https://github.com/memN0ps/bootkit-rs","1","1","N/A","N/A","N/A","6","528","67","2023-09-12T07:23:15Z","2023-04-11T03:53:15Z","51667" +"*master/EncryptedZIP*",".{0,1000}master\/EncryptedZIP.{0,1000}","offensive_tool_keyword","EncryptedZIP","Compresses a directory or file and then encrypts the ZIP file with a supplied key using AES256 CFB. This assembly also clears the key out of memory using RtlZeroMemory","T1564.001 - T1027 - T1214.001","TA0005 - TA0010","N/A","N/A","Defense Evasion","https://github.com/matterpreter/OffensiveCSharp/tree/master/EncryptedZIP","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","51668" +"*master/HookDetector*",".{0,1000}master\/HookDetector.{0,1000}","offensive_tool_keyword","HookDetector","Detects hooked Native API functions in the current process indicating the presence of EDR","T1055.012 - T1082 - T1057","TA0007 - TA0003","N/A","N/A","Defense Evasion","https://github.com/matterpreter/OffensiveCSharp/tree/master/HookDetector","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","51669" +"*master/ImplantSSP/*",".{0,1000}master\/ImplantSSP\/.{0,1000}","offensive_tool_keyword","ImplantSSP","Installs a user-supplied Security Support Provider (SSP) DLL on the system which will be loaded by LSA on system start","T1547.008 - T1073.001 - T1055.001","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/matterpreter/OffensiveCSharp/tree/master/ImplantSSP","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","51670" +"*master/SwampThing*",".{0,1000}master\/SwampThing.{0,1000}","offensive_tool_keyword","SwampThing","SwampThing lets you to spoof process command line args (x32/64). Essentially you create a process in a suspended state - rewrite the PEB - resume and finally revert the PEB. The end result is that logging infrastructure will record the fake command line args instead of the real ones","T1036.005 - T1564.002","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/FuzzySecurity/Sharp-Suite/tree/master/SwampThing","1","1","N/A","N/A","N/A","10","1131","203","2022-12-22T23:57:19Z","2018-12-10T00:08:37Z","51671" +"*master/UnquotedPath*",".{0,1000}master\/UnquotedPath.{0,1000}","offensive_tool_keyword","UnquotedPath","Outputs a list of unquoted service paths that aren't in System32/SysWow64 to plant a PE into","T1543.003 - T1036.005 - T1057","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/matterpreter/OffensiveCSharp/tree/master/UnquotedPath","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","51672" +"*MatheuZSecurity/D3m0n1z3dShell*",".{0,1000}MatheuZSecurity\/D3m0n1z3dShell.{0,1000}","offensive_tool_keyword","D3m0n1z3dShell","Demonized Shell is an Advanced Tool for persistence in linux","T1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037","TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Persistence","https://github.com/MatheuZSecurity/D3m0n1z3dShell","1","1","#linux","N/A","10","4","373","54","2025-01-05T13:56:51Z","2023-05-30T02:30:47Z","51676" +"*matterpreter/DefenderCheck*",".{0,1000}matterpreter\/DefenderCheck.{0,1000}","offensive_tool_keyword","DefenderCheck","Identifies the bytes that Microsoft Defender flags on","T1059.001 - T1059.005 - T1027.002 - T1070.004","TA0002 - TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/ThreatCheck","1","1","N/A","N/A","N/A","10","1185","143","2024-06-01T16:46:57Z","2020-10-08T11:22:26Z","51678" +"*matterpreter/Shhmon*",".{0,1000}matterpreter\/Shhmon.{0,1000}","offensive_tool_keyword","shhmon","Neutering Sysmon via driver unload","T1518.001 ","TA0007","N/A","N/A","Defense Evasion","https://github.com/matterpreter/Shhmon","1","1","N/A","N/A","N/A","3","228","37","2022-10-13T16:56:41Z","2019-09-12T14:13:19Z","51679" +"*MayankPandey01/Jira-Lens*",".{0,1000}MayankPandey01\/Jira\-Lens.{0,1000}","offensive_tool_keyword","Jira-Lens","Fast and customizable vulnerability scanner For JIRA written in Python","T1083 - T1065 - T1204 - T1087 - T1203","TA0007 - TA0005 - TA0001","N/A","N/A","Reconnaissance","https://github.com/MayankPandey01/Jira-Lens","1","1","N/A","N/A","N/A","4","318","52","2024-12-31T20:06:51Z","2021-11-14T18:37:47Z","51681" +"*Mayyhem/Maestro*",".{0,1000}Mayyhem\/Maestro.{0,1000}","offensive_tool_keyword","Maestro","Maestro is a post-exploitation tool that simplifies interaction with Intune/EntraID from a C2 agent on a user's workstation bypassing the need for user password knowledge - token manipulation or Azure authentication processes","T1550.004 - T1078 - T1087 - T1071 - T1102","TA0006 - TA0003 - TA0005 - TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/Mayyhem/Maestro","1","1","N/A","behavior detections opportunities here https://posts.specterops.io/requesting-azure-ad-request-tokens-on-azure-ad-joined-machines-for-browser-sso-2b0409caad30","9","4","333","33","2025-02-11T23:02:00Z","2024-01-15T18:45:50Z","51682" +"*Mayyhem/SharpSCCM*",".{0,1000}Mayyhem\/SharpSCCM.{0,1000}","offensive_tool_keyword","SharpSCCM","SharpSCCM is a post-exploitation tool designed to leverage Microsoft Endpoint Configuration Manager (a.k.a. ConfigMgr. formerly SCCM) for Lateral Movement and credential gathering without requiring access to the SCCM administration console GUI","T1078 - T1077 - T1547.001 - T1021.001 - T1087 - T1555.003","TA0008 - TA0006 - TA0003 - TA0011","N/A","N/A","Lateral Movement","https://github.com/Mayyhem/SharpSCCM/","1","1","N/A","N/A","10","7","626","94","2024-09-16T14:57:49Z","2021-08-19T05:09:19Z","51683" +"*Mazars-Tech/AD_Miner*",".{0,1000}Mazars\-Tech\/AD_Miner.{0,1000}","offensive_tool_keyword","AD_Miner","AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses","T1087.002 - T1069 - T1018 - T1595","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/Mazars-Tech/AD_Miner","1","1","N/A","AD Enumeration","7","10","1290","131","2025-03-12T10:53:09Z","2023-09-26T12:36:59Z","51684" +"*mazedecrypt.top*",".{0,1000}mazedecrypt\.top.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51686" +"*mblogci3rudehaagbryjznltdp33ojwzkq6hn2pckvjq33rycmzczpid.onion*",".{0,1000}mblogci3rudehaagbryjznltdp33ojwzkq6hn2pckvjq33rycmzczpid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51687" +"*mbrg/power-pwn*",".{0,1000}mbrg\/power\-pwn.{0,1000}","offensive_tool_keyword","power-pwn","An offensive and defensive security toolset for Microsoft 365 Power Platform","T1078 - T1078.004 - T1136 - T1136.001 - T1021 - T1021.003 - T1114 - T1114.002","TA0003 - TA0004 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/mbrg/power-pwn","1","1","N/A","N/A","10","10","939","100","2025-03-20T08:54:43Z","2022-06-14T11:40:21Z","51688" +"*mbrlkbtq5jonaqkurjwmxftytyn2ethqvbxfu4rgjbkkknndqwae6byd.onion*",".{0,1000}mbrlkbtq5jonaqkurjwmxftytyn2ethqvbxfu4rgjbkkknndqwae6byd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51689" +"*mcafee_epo2john.py*",".{0,1000}mcafee_epo2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51690" +"*McpManagementPotato.*",".{0,1000}McpManagementPotato\..{0,1000}","offensive_tool_keyword","DCOMPotato","Service DCOM Object and SeImpersonatePrivilege abuse.","T1548.002 - T1134.002","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/zcgonvh/DCOMPotato","1","1","N/A","N/A","10","4","356","48","2022-12-09T01:57:53Z","2022-12-08T14:56:13Z","51691" +"*md.mirrors.hacktegic.com/blackarch/*/os/*",".{0,1000}md\.mirrors\.hacktegic\.com\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","51694" +"*Md4-128.unverified.test-vectors.txt*",".{0,1000}Md4\-128\.unverified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51695" +"*Md5-128.unverified.test-vectors.txt*",".{0,1000}Md5\-128\.unverified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51696" +"*MDExclusionParser-main*",".{0,1000}MDExclusionParser\-main.{0,1000}","offensive_tool_keyword","MDExclusionParser","PowerShell script to quickly scan Event Log ID 5007 and 1121 for published Windows Defender Exclusions and Attack Surface Reduction (ASR) rule configuration.","T1562.001","TA0005 - TA0007","N/A","N/A","Defense Evasion","https://github.com/ViziosDe/MDExclusionParser","1","1","N/A","N/A","5","1","6","1","2024-06-12T14:17:08Z","2024-06-12T11:56:07Z","51700" +"*mDNSSpoofer*",".{0,1000}mDNSSpoofer.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","51702" +"*mdornseif/DeNiSe*",".{0,1000}mdornseif\/DeNiSe.{0,1000}","offensive_tool_keyword","DeNiSe","DeNiSe is a proof of concept for tunneling TCP over DNS in Python","T1071.004 - T1048.003","TA0011 - TA0010 - TA0001","N/A","N/A","C2","https://github.com/mdornseif/DeNiSe","1","1","N/A","N/A","10","10","28","13","2021-12-17T18:03:33Z","2010-01-15T07:43:14Z","51703" +"*MDSDLL_x64.dll*",".{0,1000}MDSDLL_x64\.dll.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","51704" +"*MDSDLL_x86.dll*",".{0,1000}MDSDLL_x86\.dll.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","51705" +"*mdsecactivebreach/CACTUSTORCH*",".{0,1000}mdsecactivebreach\/CACTUSTORCH.{0,1000}","offensive_tool_keyword","CACTUSTORCH","A JavaScript and VBScript shellcode launcher. This will spawn a 32 bit version of the binary specified and inject shellcode into it.","T1055.011 - T1059.005 - T1059.007","TA0002 - TA0005","N/A","APT32","Exploitation tool","https://github.com/mdsecactivebreach/CACTUSTORCH","1","1","N/A","N/A","8","10","1006","227","2018-07-03T06:47:36Z","2017-07-04T10:20:34Z","51706" +"*mdsecactivebreach/CACTUSTORCH*",".{0,1000}mdsecactivebreach\/CACTUSTORCH.{0,1000}","offensive_tool_keyword","cobaltstrike","CACTUSTORCH: Payload Generation for Adversary Simulations","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mdsecactivebreach/CACTUSTORCH","1","1","N/A","N/A","10","10","1006","227","2018-07-03T06:47:36Z","2017-07-04T10:20:34Z","51707" +"*mdsecactivebreach/DragonCastle*",".{0,1000}mdsecactivebreach\/DragonCastle.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","1","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","51708" +"*mdsecactivebreach/Farmer*",".{0,1000}mdsecactivebreach\/Farmer.{0,1000}","offensive_tool_keyword","Farmer","Farmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.","T1557.001 - T1056.004 - T1078.003","TA0006 - TA0004 - TA0001","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/Farmer","1","1","N/A","N/A","10","4","379","61","2021-04-28T15:27:24Z","2021-02-22T14:32:29Z","51709" +"*mdsecactivebreach/WMIPersistence*",".{0,1000}mdsecactivebreach\/WMIPersistence.{0,1000}","offensive_tool_keyword","WMIPersistence","An example of how to perform WMI Event Subscription persistence using C#","T1547.008 - T1084 - T1053 - T1059.003","TA0003 - TA0004 - TA0002","N/A","N/A","Persistence","https://github.com/mdsecactivebreach/WMIPersistence","1","1","N/A","N/A","N/A","2","113","30","2019-05-29T09:48:46Z","2019-05-29T09:40:01Z","51711" +"*Meckazin/ChromeKatz*",".{0,1000}Meckazin\/ChromeKatz.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","51712" +"*med0x2e/GadgetToJScript*",".{0,1000}med0x2e\/GadgetToJScript.{0,1000}","offensive_tool_keyword","GadgetToJScript","A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.","T1059.001 - T1078 - T1059.005","TA0002 - TA0004 - TA0001","N/A","N/A","Exploitation tool","https://github.com/med0x2e/GadgetToJScript","1","1","N/A","N/A","10","10","942","168","2021-07-26T17:35:40Z","2019-10-05T12:27:19Z","51713" +"*med0x2e/SigFlip*",".{0,1000}med0x2e\/SigFlip.{0,1000}","offensive_tool_keyword","C2 related tools","SigFlip is a tool for patching authenticode signed PE files (exe. dll. sys ..etc) without invalidating or breaking the existing signature.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/med0x2e/SigFlip","1","1","N/A","N/A","10","10","1139","197","2023-08-27T18:27:50Z","2021-08-08T15:59:19Z","51714" +"*med0x2e/SigFlip*",".{0,1000}med0x2e\/SigFlip.{0,1000}","offensive_tool_keyword","cobaltstrike","SigFlip is a tool for patching authenticode signed PE files (exe. dll. sys ..etc) without invalidating or breaking the existing signature.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/med0x2e/SigFlip","1","1","N/A","N/A","10","10","1139","197","2023-08-27T18:27:50Z","2021-08-08T15:59:19Z","51715" +"*media_variable_file_cryptography.py*",".{0,1000}media_variable_file_cryptography\.py.{0,1000}","offensive_tool_keyword","pxethief","PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager","T1555.004 - T1555.002","TA0006","N/A","N/A","Credential Access","https://github.com/MWR-CyberSec/PXEThief","1","1","N/A","N/A","N/A","4","368","57","2024-05-29T15:07:15Z","2022-08-12T22:16:46Z","51716" +"*medusakxxtp3uo7vusntvubnytaph4d3amxivbggl3hnhpk2nmus34yd.onion*",".{0,1000}medusakxxtp3uo7vusntvubnytaph4d3amxivbggl3hnhpk2nmus34yd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51719" +"*medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion*",".{0,1000}medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51720" +"*megadose/holehe*",".{0,1000}megadose\/holehe.{0,1000}","offensive_tool_keyword","holehe","holehe allows you to check if the mail is used on different sites like twitter instagram and will retrieve information on sites with the forgotten password function.","T1598.004 - T1592.002 - T1598.001","TA0003 - TA0009","N/A","N/A","Reconnaissance","https://github.com/megadose/holehe","1","1","#linux","N/A","6","10","8656","981","2024-09-10T20:24:32Z","2020-06-25T23:03:02Z","51725" +"*megadose@protonmail.com*",".{0,1000}megadose\@protonmail\.com.{0,1000}","offensive_tool_keyword","holehe","holehe allows you to check if the mail is used on different sites like twitter instagram and will retrieve information on sites with the forgotten password function.","T1598.004 - T1592.002 - T1598.001","TA0003 - TA0009","N/A","N/A","Reconnaissance","https://github.com/megadose/holehe","1","1","#email","N/A","6","10","8656","981","2024-09-10T20:24:32Z","2020-06-25T23:03:02Z","51726" +"*MegaManSec/SSH-Snake*",".{0,1000}MegaManSec\/SSH\-Snake.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","1","N/A","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","51727" +"*meliht/Mr.SIP*",".{0,1000}meliht\/Mr\.SIP.{0,1000}","offensive_tool_keyword","Mr.SIP","Mr.SIP is a simple console based SIP-based Audit and Attack Tool. Originally it was developed to be used in academic work to help developing novel SIP-based DDoS attacks and then as an idea to convert it to a fully functional SIP-based penetration testing tool. So far Mr SIP resulted several academic research papers. and journal articles. Mr.SIP can also be used as SIP client simulator and SIP traffic generator.","T1522 - T1521 - T1523 - T1505 - T1506","TA0010 - TA0002 - TA0043","N/A","N/A","Exploitation tool","https://github.com/meliht/Mr.SIP","1","1","N/A","N/A","N/A","4","399","94","2023-05-21T08:11:20Z","2017-09-07T18:23:00Z","51747" +"*Meltedd/HVNC*",".{0,1000}Meltedd\/HVNC.{0,1000}","offensive_tool_keyword","HVNC","Standalone HVNC Client & Server Coded in C++ (Modified Tinynuke)","T1021.005 - T1071 - T1563.002 - T1219","TA0001 - TA0002 - TA0008","N/A","N/A","RMM","https://github.com/Meltedd/HVNC","1","1","N/A","N/A","10","5","445","133","2025-03-27T21:20:10Z","2021-09-03T17:34:44Z","51749" +"*Memcrashed-DDoS-Exploit*",".{0,1000}Memcrashed\-DDoS\-Exploit.{0,1000}","offensive_tool_keyword","Memcrashed-DDoS-Exploit","This tool allows you to send forged UDP packets to Memcached servers obtained from Shodan.io","T1436 - T1498 - T1216 - T1190","TA0043 - TA0001","N/A","N/A","Exploitation tool","https://github.com/649/Memcrashed-DDoS-Exploit","1","1","N/A","N/A","10","10","1358","468","2022-12-02T07:14:59Z","2018-03-02T21:19:51Z","51751" +"*memory*mimipy.py*",".{0,1000}memory.{0,1000}mimipy\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","51754" +"*memory/onepassword.py*",".{0,1000}memory\/onepassword\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","51755" +"*memorydump.py*",".{0,1000}memorydump\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","51756" +"*memorydump.py*",".{0,1000}memorydump\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","51757" +"*MemReader_BoF.*",".{0,1000}MemReader_BoF\..{0,1000}","offensive_tool_keyword","cobaltstrike","MemReader Beacon Object File will allow you to search and extract specific strings from a target process memory and return what is found to the beacon output","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trainr3kt/MemReader_BoF","1","1","N/A","N/A","10","10","46","6","2023-12-05T23:25:22Z","2021-04-21T20:51:25Z","51759" +"*Meowmycks/etwunhook*",".{0,1000}Meowmycks\/etwunhook.{0,1000}","offensive_tool_keyword","etwunhook","Simple ETW unhook PoC. Overwrites NtTraceEvent opcode to disable ETW at Nt-function level.","T1055 - T1562.001","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/Meowmycks/etwunhook","1","1","N/A","N/A","9","1","47","11","2024-02-29T10:07:52Z","2024-01-22T22:21:09Z","51760" +"*Meowmycks/LetMeowIn*",".{0,1000}Meowmycks\/LetMeowIn.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","1","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","51761" +"*merlin-*.zip*",".{0,1000}merlin\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","mythic","Cross-platform post-exploitation HTTP Command & Control agent written in golang","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/merlin","1","1","N/A","N/A","10","10","94","16","2025-04-16T13:05:47Z","2021-01-25T12:36:46Z","51763" +"*Merlin_v0.1Beta.zip*",".{0,1000}Merlin_v0\.1Beta\.zip.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","51765" +"*Merlin_v0.1Beta.zip*",".{0,1000}Merlin_v0\.1Beta\.zip.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51766" +"*merlinAgent-*.7z*",".{0,1000}merlinAgent\-.{0,1000}\.7z.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51767" +"*merlinAgent-*.exe*",".{0,1000}merlinAgent\-.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51768" +"*merlinAgent.exe*",".{0,1000}merlinAgent\.exe.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","51769" +"*merlinAgent-Darwin-*",".{0,1000}merlinAgent\-Darwin\-.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","#linux","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51770" +"*merlinAgent-Darwin-x64-*",".{0,1000}merlinAgent\-Darwin\-x64\-.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","#linux","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","51771" +"*merlinAgent-Darwin-x64.*",".{0,1000}merlinAgent\-Darwin\-x64\..{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","#linux","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","51772" +"*merlin-agent-dll.7z*",".{0,1000}merlin\-agent\-dll\.7z.{0,1000}","offensive_tool_keyword","merlin-agent-dll","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent-dll","1","1","N/A","N/A","10","10","51","15","2025-04-17T14:01:36Z","2021-04-17T16:58:24Z","51773" +"*merlin-agent-dll/tarball/v*",".{0,1000}merlin\-agent\-dll\/tarball\/v.{0,1000}","offensive_tool_keyword","merlin-agent-dll","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent-dll","1","1","N/A","N/A","10","10","51","15","2025-04-17T14:01:36Z","2021-04-17T16:58:24Z","51774" +"*merlin-agent-dll/zipball/v*",".{0,1000}merlin\-agent\-dll\/zipball\/v.{0,1000}","offensive_tool_keyword","merlin-agent-dll","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent-dll","1","1","N/A","N/A","10","10","51","15","2025-04-17T14:01:36Z","2021-04-17T16:58:24Z","51775" +"*merlinAgent-Linux-*",".{0,1000}merlinAgent\-Linux\-.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","#linux","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51777" +"*merlinAgent-Linux-x64-*",".{0,1000}merlinAgent\-Linux\-x64\-.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","#linux","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","51778" +"*merlinAgent-Linux-x64.*",".{0,1000}merlinAgent\-Linux\-x64\..{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","#linux","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","51779" +"*merlinAgent-Windows-x64-*",".{0,1000}merlinAgent\-Windows\-x64\-.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","N/A","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","51780" +"*merlinAgent-Windows-x64.*",".{0,1000}merlinAgent\-Windows\-x64\..{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","N/A","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","51781" +"*merlinAgent-Windows-x64.exe*",".{0,1000}merlinAgent\-Windows\-x64\.exe.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","51782" +"*merlinAgent-Windows-x64.exe*",".{0,1000}merlinAgent\-Windows\-x64\.exe\s.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","N/A","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","51783" +"*merlinAgent-Windows-x86.exe*",".{0,1000}merlinAgent\-Windows\-x86\.exe\s.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","N/A","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","51784" +"*merlin-c2.readthedocs.io*",".{0,1000}merlin\-c2\.readthedocs\.io.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","N/A","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","51785" +"*merlin-c2.readthedocs.io*",".{0,1000}merlin\-c2\.readthedocs\.io.{0,1000}","offensive_tool_keyword","merlin-agent-dll","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent-dll","1","1","N/A","N/A","10","10","51","15","2025-04-17T14:01:36Z","2021-04-17T16:58:24Z","51786" +"*MerlinCheatSheet.pdf*",".{0,1000}MerlinCheatSheet\.pdf.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","51787" +"*merlinServer-*.7z*",".{0,1000}merlinServer\-.{0,1000}\.7z.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51793" +"*merlinServer-*.exe*",".{0,1000}merlinServer\-.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51794" +"*merlinserver.go*",".{0,1000}merlinserver\.go.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","51795" +"*merlinserver.go*",".{0,1000}merlinserver\.go.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51796" +"*merlinserver_windows_x64.exe*",".{0,1000}merlinserver_windows_x64\.exe.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","51797" +"*merlinserver_windows_x64.exe*",".{0,1000}merlinserver_windows_x64\.exe.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51798" +"*merlinServer-Darwin-x64.exe*",".{0,1000}merlinServer\-Darwin\-x64\.exe.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","#linux","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51799" +"*merlinServer-Darwin-x64.exe*",".{0,1000}merlinServer\-Darwin\-x64\.exe.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","#linux","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51800" +"*merlinServer-Linux*",".{0,1000}merlinServer\-Linux.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","#linux","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51801" +"*merlinServer-Linux-x64.7z*",".{0,1000}merlinServer\-Linux\-x64\.7z.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","#linux","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51802" +"*merlinServerLog.txt*",".{0,1000}merlinServerLog\.txt.{0,1000}","offensive_tool_keyword","kubesploit","Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang","T1021.001 - T1027 - T1071.001 - T1059.006","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://github.com/cyberark/kubesploit","1","1","N/A","N/A","10","10","1161","119","2025-02-03T12:03:19Z","2021-02-09T15:54:23Z","51803" +"*merlinServerLog.txt*",".{0,1000}merlinServerLog\.txt.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51804" +"*merlinServer-Windows-x64.exe*",".{0,1000}merlinServer\-Windows\-x64\.exe.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51805" +"*merlinServer-Windows-x64.exe*",".{0,1000}merlinServer\-Windows\-x64\.exe.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","51806" +"*mertdas/RedPersist*",".{0,1000}mertdas\/RedPersist.{0,1000}","offensive_tool_keyword","RedPersist","RedPersist is a Windows Persistence tool written in C#","T1053 - T1547 - T1112","TA0004 - TA0005 - TA0040","N/A","N/A","Persistence","https://github.com/mertdas/RedPersist","1","1","N/A","N/A","10","3","215","33","2024-03-10T15:40:05Z","2023-08-13T22:10:46Z","51807" +"*mertdas/SharpIncrease*",".{0,1000}mertdas\/SharpIncrease.{0,1000}","offensive_tool_keyword","SharpIncrease","binary padding to add junk data and change the on-disk representation of a file","T1480 - T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/mertdas/SharpIncrease","1","1","N/A","N/A","6","2","148","30","2024-06-28T21:36:46Z","2023-03-14T23:35:32Z","51808" +"*mertdas/SharpLDAP*",".{0,1000}mertdas\/SharpLDAP.{0,1000}","offensive_tool_keyword","SharpLDAP","tool written in C# that aims to do enumeration via LDAP queries","T1018 - T1069.003","TA0007 - TA0011","N/A","N/A","Discovery","https://github.com/mertdas/SharpLDAP","1","1","N/A","N/A","8","1","0","1","2023-01-14T21:52:36Z","2022-11-16T00:38:43Z","51809" +"*mertdas/SharpTerminator*",".{0,1000}mertdas\/SharpTerminator.{0,1000}","offensive_tool_keyword","SharpTerminator","Terminate AV/EDR Processes using kernel driver","T1055.003 - T1547.001 - T1053.005 - T1091 - T1014 - T1053.006 - T1053.004 - T1112 - T1112.001","TA0007 - TA0008 - TA0006 - TA0002","N/A","N/A","Exploitation tool","https://github.com/mertdas/SharpTerminator","1","1","N/A","N/A","10","4","341","66","2023-06-12T00:38:54Z","2023-06-11T06:35:51Z","51810" +"*messagebox_reflective.dll*",".{0,1000}messagebox_reflective\.dll.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","51885" +"*Metasploit*",".{0,1000}Metasploit.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51893" +"*metasploit.go*",".{0,1000}metasploit\.go.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","51895" +"*metasploit.rb*",".{0,1000}metasploit\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51896" +"*metasploit/framework*",".{0,1000}metasploit\/framework.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51897" +"*metasploit/peass.rb*",".{0,1000}metasploit\/peass\.rb.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","51898" +"*metasploit_framework.rb*",".{0,1000}metasploit_framework\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51899" +"*metasploit-framework*",".{0,1000}metasploit\-framework.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51900" +"*metasploit-framework*",".{0,1000}metasploit\-framework.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://www.metasploit.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51901" +"*metasploitframework*.msi*",".{0,1000}metasploitframework.{0,1000}\.msi.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51902" +"*metasploitframework-latest.msi*",".{0,1000}metasploitframework\-latest\.msi.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-omnibus","1","1","N/A","N/A","10","3","268","213","2025-04-18T13:17:56Z","2015-02-26T18:42:09Z","51903" +"*MetasploitPayload.ps1*",".{0,1000}MetasploitPayload\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1149","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","51904" +"*MetasploitSelfSignedCA*",".{0,1000}MetasploitSelfSignedCA.{0,1000}","offensive_tool_keyword","metasploit","metasploit command lines patterns","T1573.002 - T1021","TA0001 - TA0002 - TA0003","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Exploitation tool","https://github.com/rapid7/metasploit-framework","1","1","#certificate","default SSL cert","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51905" +"*metatwin.ps1*",".{0,1000}metatwin\.ps1.{0,1000}","offensive_tool_keyword","metatwin","The project is designed as a file resource cloner. Metadata including digital signature is extracted from one file and injected into another","T1553.002 - T1114.001 - T1564.003","TA0006 - TA0010","N/A","N/A","Exploitation tool","https://github.com/threatexpress/metatwin","1","1","N/A","N/A","9","4","345","71","2024-11-19T19:45:59Z","2017-10-08T13:26:00Z","51906" +"*metatwin-master*",".{0,1000}metatwin\-master.{0,1000}","offensive_tool_keyword","metatwin","The project is designed as a file resource cloner. Metadata including digital signature is extracted from one file and injected into another","T1553.002 - T1114.001 - T1564.003","TA0006 - TA0010","N/A","N/A","Exploitation tool","https://github.com/threatexpress/metatwin","1","1","N/A","N/A","9","4","345","71","2024-11-19T19:45:59Z","2017-10-08T13:26:00Z","51907" +"*meterpeter.ps1*",".{0,1000}meterpeter\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","51908" +"*meterpreter*.rb*",".{0,1000}meterpreter.{0,1000}\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51910" +"*meterpreter.*",".{0,1000}meterpreter\..{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","51911" +"*Meterpreter.java*",".{0,1000}Meterpreter\.java.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","51912" +"*Meterpreter.ps1*",".{0,1000}Meterpreter\.ps1.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","51913" +"*meterpreter.sl*",".{0,1000}meterpreter\.sl.{0,1000}","offensive_tool_keyword","armitage","Armitage is a graphical cyber attack management tool for Metasploit that visualizes your targets. recommends exploits and exposes the advanced capabilities of the framework ","T1210 - T1059.003 - T1547.001 - T1057 - T1046 - T1562.001 - T1071.001 - T1060 - T1573.002","TA0002 - TA0008 - TA0005 - TA0007 - TA0011","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla - Black Basta","Exploitation tool","https://github.com/r00t0v3rr1d3/armitage","1","1","N/A","N/A","N/A","2","129","32","2022-12-06T00:17:23Z","2022-01-23T17:32:01Z","51914" +"*meterpreter_*.rb",".{0,1000}meterpreter_.{0,1000}\.rb","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51915" +"*meterpreter_loader*",".{0,1000}meterpreter_loader.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","51916" +"*METERPRETER_STAGER*",".{0,1000}METERPRETER_STAGER.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","51917" +"*meterpreter-in-go.exe*",".{0,1000}meterpreter\-in\-go\.exe.{0,1000}","offensive_tool_keyword","EXOCET-AV-Evasion","EXOCET - AV-evading undetectable payload delivery tool","T1055 - T1218.011 - T1027.009 - T1027 - T1105 - T1102.001","TA0005 - TA0001 - TA0002 - TA0009","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","Defense Evasion","https://github.com/tanc7/EXOCET-AV-Evasion","1","1","N/A","N/A","10","9","840","147","2022-08-16T02:58:39Z","2020-07-15T06:55:13Z","51918" +"*Metro-Holografix/CSExec*",".{0,1000}Metro\-Holografix\/CSExec.{0,1000}","offensive_tool_keyword","CSExec","An alternative to *exec.py from impacket with some builtin tricks","T1059.001 - T1059.005 - T1071.001","TA0002","N/A","N/A","Lateral Movement","https://github.com/Metro-Holografix/CSExec.py","1","1","N/A","private github repo","10","","N/A","","","","51924" +"*Metro-Holografix/Dinjector*",".{0,1000}Metro\-Holografix\/Dinjector.{0,1000}","offensive_tool_keyword","Dinjector","Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL","T1055 - T1055.012 - T1055.001 - T1027.002","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Metro-Holografix/DInjector","1","1","N/A","private github repo","8","","N/A","","","","51925" +"*metsrv.dll*",".{0,1000}metsrv\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","51926" +"*metsvc-server.exe*",".{0,1000}metsvc\-server\.exe.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","service file name","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","51927" +"*metterpreter*",".{0,1000}metterpreter.{0,1000}","offensive_tool_keyword","metasploit-payloads","shell payload","T1059.001 - T1027 - T1210.001","TA0002 - TA0003 - TA0007","N/A","N/A","Framework","https://github.com/rapid7/metasploit-payloads","1","1","N/A","N/A","10","10","1819","689","2025-02-13T15:01:44Z","2014-04-03T21:18:24Z","51928" +"*mez-0/DecryptRDCManager*",".{0,1000}mez\-0\/DecryptRDCManager.{0,1000}","offensive_tool_keyword","DecryptRDCManager","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/mez-0/DecryptRDCManager","1","1","N/A","N/A","8","1","73","7","2020-09-29T10:12:58Z","2020-09-29T08:53:46Z","51929" +"*MFASweep.ps1*",".{0,1000}MFASweep\.ps1.{0,1000}","offensive_tool_keyword","MFASweep","A tool for checking if MFA is enabled on multiple Microsoft Services","T1595 - T1595.002 - T1078.003 - T1621","TA0006 - TA0009","N/A","N/A","Exploitation tool","https://github.com/dafthack/MFASweep","1","1","N/A","N/A","9","10","1484","203","2025-03-04T20:36:41Z","2020-09-22T16:25:03Z","51930" +"*mgeeky.tech/protectmytooling/*",".{0,1000}mgeeky\.tech\/protectmytooling\/.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","51932" +"*mgeeky/ElusiveMice*",".{0,1000}mgeeky\/ElusiveMice.{0,1000}","offensive_tool_keyword","ElusiveMice","Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind","T1620 - T1055.012 - T1202","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/mgeeky/ElusiveMice","1","1","N/A","N/A","10","5","449","78","2023-07-12T17:54:07Z","2021-08-27T19:22:20Z","51933" +"*mgeeky/PackMyPayload*",".{0,1000}mgeeky\/PackMyPayload.{0,1000}","offensive_tool_keyword","PackMyPayload","A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats","T1027 - T1036 - T1048 - T1070 - T1096 - T1195","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/mgeeky/PackMyPayload/","1","1","N/A","N/A","10","10","912","143","2024-06-10T09:50:43Z","2022-02-08T19:26:28Z","51934" +"*mgeeky/RedWarden*",".{0,1000}mgeeky\/RedWarden.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","51935" +"*mhaskar/DNSStager*",".{0,1000}mhaskar\/DNSStager.{0,1000}","offensive_tool_keyword","DNSStager","DNSStager is an open-source project based on Python used to hide and transfer your payload using DNS.","T1071.004 - T1568.002 - T1102","TA0002 - TA0005 - TA0009 - TA0010","N/A","Black Basta","Defense Evasion","https://github.com/mhaskar/DNSStager","1","1","N/A","N/A","10","7","613","133","2023-05-03T12:25:07Z","2021-04-18T21:58:21Z","51938" +"*mhaskar/Octopus*",".{0,1000}mhaskar\/Octopus.{0,1000}","offensive_tool_keyword","octopus","Octopus is an open source. pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S.","T1059.001 - T1105 - T1071.001 - T1219 - T1573","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/mhaskar/Octopus","1","1","N/A","N/A","10","10","750","156","2021-07-06T23:52:37Z","2019-08-30T21:09:07Z","51939" +"*mhdehvkomeabau7gsetnsrhkfign4jgnx3wajth5yb5h6kvzbd72wlqd.onion*",".{0,1000}mhdehvkomeabau7gsetnsrhkfign4jgnx3wajth5yb5h6kvzbd72wlqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","51940" +"*mhuzaifi0604/spellbound*",".{0,1000}mhuzaifi0604\/spellbound.{0,1000}","offensive_tool_keyword","spellbound","Spellbound is a C2 (Command and Control) framework meant for creating a botnet. ","T1105 - T1132 - T1059.003 - T1094 - T1005","TA0011 - TA0009 - TA0010 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/mhuzaifi0604/spellbound","1","1","N/A","N/A","10","10","45","5","2023-09-22T10:52:53Z","2023-09-19T14:45:15Z","51942" +"*mhydeath.exe*",".{0,1000}mhydeath\.exe.{0,1000}","offensive_tool_keyword","mhydeath","Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.","T1562.001","TA0040 - TA0005","N/A","Black Basta","Defense Evasion","https://github.com/zer0condition/mhydeath","1","1","N/A","N/A","10","4","397","71","2023-08-22T08:01:04Z","2023-08-22T07:15:36Z","51943" +"*mhydeath-master*",".{0,1000}mhydeath\-master.{0,1000}","offensive_tool_keyword","mhydeath","Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.","T1562.001","TA0040 - TA0005","N/A","Black Basta","Defense Evasion","https://github.com/zer0condition/mhydeath","1","1","N/A","N/A","10","4","397","71","2023-08-22T08:01:04Z","2023-08-22T07:15:36Z","51944" +"*micahvandeusen/gMSADumper*",".{0,1000}micahvandeusen\/gMSADumper.{0,1000}","offensive_tool_keyword","gMSADumper","Lists who can read any gMSA password blobs and parses them if the current user has access.","T1552.001 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/micahvandeusen/gMSADumper","1","1","N/A","N/A","N/A","3","274","51","2024-02-12T02:15:32Z","2021-04-10T00:15:24Z","51945" +"*mIcHyAmRaNe/wso-webshell*",".{0,1000}mIcHyAmRaNe\/wso\-webshell.{0,1000}","offensive_tool_keyword","wso-webshell","wso php webshell","T1100 - T1027 - T1059","TA0003 - TA0007","N/A","EMBER BEAR - Sandworm","Persistence","https://github.com/mIcHyAmRaNe/wso-webshell","1","1","N/A","N/A","10","4","376","211","2024-07-08T04:54:36Z","2017-05-04T23:34:02Z","51948" +"*micr0 shell.py*",".{0,1000}micr0\sshell\.py.{0,1000}","offensive_tool_keyword","micr0_shell","micr0shell is a Python script that dynamically generates Windows X64 PIC Null-Free reverse shell shellcode.","T1059.003 - T1027.001","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/senzee1984/micr0_shell","1","1","N/A","N/A","9","2","186","30","2024-07-21T08:16:57Z","2023-08-13T02:46:51Z","51949" +"*micr0_shell-main*",".{0,1000}micr0_shell\-main.{0,1000}","offensive_tool_keyword","micr0_shell","micr0shell is a Python script that dynamically generates Windows X64 PIC Null-Free reverse shell shellcode.","T1059.003 - T1027.001","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/senzee1984/micr0_shell","1","1","N/A","N/A","9","2","186","30","2024-07-21T08:16:57Z","2023-08-13T02:46:51Z","51950" +"*micr0shell.py *",".{0,1000}micr0shell\.py\s.{0,1000}","offensive_tool_keyword","micr0_shell","micr0shell is a Python script that dynamically generates Windows X64 PIC Null-Free reverse shell shellcode.","T1059.003 - T1027.001","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/senzee1984/micr0_shell","1","1","N/A","N/A","9","2","186","30","2024-07-21T08:16:57Z","2023-08-13T02:46:51Z","51951" +"*microbrownys.strangled.net*",".{0,1000}microbrownys\.strangled\.net.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","51952" +"*MicroBurst.psm1*",".{0,1000}MicroBurst\.psm1.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","51953" +"*MicroBurst-Az.psm1*",".{0,1000}MicroBurst\-Az\.psm1.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","51954" +"*MicroBurst-AzureAD*",".{0,1000}MicroBurst\-AzureAD.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","51955" +"*MicroBurst-AzureREST*",".{0,1000}MicroBurst\-AzureREST.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","51956" +"*MicroBurst-AzureRM*",".{0,1000}MicroBurst\-AzureRM.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","51957" +"*MicroBurst-master*",".{0,1000}MicroBurst\-master.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","51958" +"*MicroBurst-Misc.psm1*",".{0,1000}MicroBurst\-Misc\.psm1.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","51959" +"*MicroBurst-MSOL*",".{0,1000}MicroBurst\-MSOL.{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","51960" +"*microchsse.strangled.net*",".{0,1000}microchsse\.strangled\.net.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","51961" +"*microlilics.crabdance.com*",".{0,1000}microlilics\.crabdance\.com.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","51962" +"*micronaoko.jumpingcrab.com*",".{0,1000}micronaoko\.jumpingcrab\.com.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","51963" +"*microplants.strangled.net*",".{0,1000}microplants\.strangled\.net.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","N/A","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","51964" +"*microsploit.git*",".{0,1000}microsploit\.git.{0,1000}","offensive_tool_keyword","BruteSploit","Fast and easy create backdoor office exploitation using module metasploit packet . Microsoft Office . Open Office . Macro attack . Buffer Overflow","T1587 - T1588 - T1608","N/A","N/A","N/A","Exploitation tool","https://github.com/screetsec/Microsploit","1","1","N/A","N/A","N/A","5","439","121","2017-07-11T16:28:27Z","2017-03-16T05:26:55Z","51980" +"*Midl2Bytes.exe*",".{0,1000}Midl2Bytes\.exe.{0,1000}","offensive_tool_keyword","SharpSystemTriggers","Collection of remote authentication triggers in C#","T1078 - T1059.001 - T1550","TA0008 ","N/A","N/A","Lateral Movement","https://github.com/cube0x0/SharpSystemTriggers","1","1","N/A","N/A","10","5","483","57","2024-05-15T21:24:56Z","2021-09-12T18:18:15Z","51982" +"*mifunftyundf6deg.azurewebsites.net*",".{0,1000}mifunftyundf6deg\.azurewebsites\.net.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","51984" +"*mimidogz-master.zip*",".{0,1000}mimidogz\-master\.zip.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","1","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","52005" +"*mimidrv.pdb*",".{0,1000}mimidrv\.pdb.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52008" +"*mimidrv.sys*",".{0,1000}mimidrv\.sys.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation ","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52009" +"*mimidrv.sys*",".{0,1000}mimidrv\.sys.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52010" +"*mimidrv.sys*",".{0,1000}mimidrv\.sys.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52011" +"*mimidrv.zip*",".{0,1000}mimidrv\.zip.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52012" +"*Mimikatz*",".{0,1000}Mimikatz.{0,1000}","offensive_tool_keyword","mimikatz","Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets.","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52016" +"*Mimikatz.cs*",".{0,1000}Mimikatz\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","52017" +"*mimikatz.exe*",".{0,1000}mimikatz\.exe.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","52019" +"*mimikatz.exe*",".{0,1000}mimikatz\.exe.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","52020" +"*mimikatz.exe*",".{0,1000}mimikatz\.exe.{0,1000}","offensive_tool_keyword","FilelessPELoader","Loading Remote AES Encrypted PE in memory - Decrypted it and run it","T1027.001 - T1059.001 - T1071","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/FilelessPELoader","1","1","N/A","N/A","10","10","933","196","2023-08-29T21:46:11Z","2023-02-08T16:59:33Z","52021" +"*mimikatz.exe*",".{0,1000}mimikatz\.exe.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52022" +"*mimikatz.exe*",".{0,1000}mimikatz\.exe.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","52023" +"*mimikatz.py*",".{0,1000}mimikatz\.py.{0,1000}","offensive_tool_keyword","Arbitrium-RAT","cross-platform fully undetectable remote access trojan to control Android Windows and Linux","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","N/A","Malware","https://github.com/im-hanzou/Arbitrium-RAT","1","1","N/A","N/A","10","4","355","309","2021-01-15T23:21:13Z","2021-01-16T03:03:11Z","52026" +"*mimikatz.py*",".{0,1000}mimikatz\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/SecureAuthCorp/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","52027" +"*mimikatz.raw*",".{0,1000}mimikatz\.raw.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","52028" +"*mimikatz_cred_collector.py*",".{0,1000}mimikatz_cred_collector\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","52030" +"*mimikatz_dotnet2js*",".{0,1000}mimikatz_dotnet2js.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","52031" +"*mimikatz_dynwrapx*",".{0,1000}mimikatz_dynwrapx.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","52032" +"*mimikatz_tashlib*",".{0,1000}mimikatz_tashlib.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","52033" +"*mimikatz_trunk.7z*",".{0,1000}mimikatz_trunk\.7z.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archive names","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52035" +"*mimikatz_trunk.zip*",".{0,1000}mimikatz_trunk\.zip.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archive names","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52036" +"*mimikatz_x64.dll*",".{0,1000}mimikatz_x64\.dll.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","52037" +"*mimikatz_x64.exe*",".{0,1000}mimikatz_x64\.exe.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","52038" +"*mimikatz_x86.dll*",".{0,1000}mimikatz_x86\.dll.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","52039" +"*mimikatz_x86.exe*",".{0,1000}mimikatz_x86\.exe.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","52040" +"*MimikatzByPowerShellForDomain.py*",".{0,1000}MimikatzByPowerShellForDomain\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","52041" +"*mimikatz-obf.exe*",".{0,1000}mimikatz\-obf\.exe.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","52042" +"*MimikatzOnLocal.py*",".{0,1000}MimikatzOnLocal\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","52043" +"*mimikittenz*",".{0,1000}mimikittenz.{0,1000}","offensive_tool_keyword","mimikittenz","mimikittenz is a post-exploitation powershell tool that utilizes the Windows function ReadProcessMemory() in order to extract plain-text passwords from various target processes mimikittenz can also easily extract other kinds of juicy info from target processes using regex patterns including but not limited Encryption Keys & All the other goodstuff","T1003 - T1216 - T1552 - T1002 - T1083","TA0003 - TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/orlyjamie/mimikittenz","1","1","N/A","N/A","10","10","1840","334","2024-06-28T11:10:03Z","2016-07-04T13:57:18Z","52046" +"*mimilib.dll*",".{0,1000}mimilib\.dll.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52052" +"*mimilib.dll*",".{0,1000}mimilib\.dll.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52053" +"*mimilib.py*",".{0,1000}mimilib\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","52054" +"*mimilove.vcxproj*",".{0,1000}mimilove\.vcxproj.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52057" +"*mimipenguin.*",".{0,1000}mimipenguin\..{0,1000}","offensive_tool_keyword","crossc2","generate CobaltStrike's cross-platform payload","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","52060" +"*mimipenguin.*",".{0,1000}mimipenguin.{0,1000}","offensive_tool_keyword","mimipenguin","A tool to dump the login password from the current linux user","T1003.007","TA0006 - TA0002 ","N/A","TeamTNT","Credential Access","https://github.com/huntergregal/mimipenguin","1","1","#linux","N/A","10","10","3940","644","2023-05-17T13:20:46Z","2017-03-28T21:24:28Z","52061" +"*mimipenguin.cna*",".{0,1000}mimipenguin\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","52062" +"*mimipenguin.git*",".{0,1000}mimipenguin\.git.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52063" +"*MimiPenguin.json*",".{0,1000}MimiPenguin\.json.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","52064" +"*mimipenguin.py*",".{0,1000}mimipenguin\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Exploitation tool","https://github.com/byt3bl33d3r/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","52065" +"*mimipenguin.py*",".{0,1000}mimipenguin\.py.{0,1000}","offensive_tool_keyword","D3m0n1z3dShell","Demonized Shell is an Advanced Tool for persistence in linux","T1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037","TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Persistence","https://github.com/MatheuZSecurity/D3m0n1z3dShell","1","1","#linux","N/A","10","4","373","54","2025-01-05T13:56:51Z","2023-05-30T02:30:47Z","52066" +"*mimipenguin.sh*",".{0,1000}mimipenguin\.sh.{0,1000}","offensive_tool_keyword","D3m0n1z3dShell","Demonized Shell is an Advanced Tool for persistence in linux","T1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037","TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Persistence","https://github.com/MatheuZSecurity/D3m0n1z3dShell","1","1","#linux","N/A","10","4","373","54","2025-01-05T13:56:51Z","2023-05-30T02:30:47Z","52067" +"*mimipenguin.so*",".{0,1000}mimipenguin\.so.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","52068" +"*mimipenguin_*.tar.gz*",".{0,1000}mimipenguin_.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","mimipenguin","A tool to dump the login password from the current linux user","T1003.007","TA0006 - TA0002 ","N/A","TeamTNT","Credential Access","https://github.com/huntergregal/mimipenguin","1","1","#linux","N/A","10","10","3940","644","2023-05-17T13:20:46Z","2017-03-28T21:24:28Z","52069" +"*mimipenguin_x32.so*",".{0,1000}mimipenguin_x32\.so.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","52070" +"*mimipy.py*",".{0,1000}mimipy\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","52071" +"*mimiRatz*",".{0,1000}mimiRatz.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","52073" +"*mimishim.*",".{0,1000}mimishim\..{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","52074" +"*mimispool.dll*",".{0,1000}mimispool\.dll.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation ","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52077" +"*Minidump.exe*",".{0,1000}Minidump\.exe.{0,1000}","offensive_tool_keyword","bof-collection","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003 - T1021.001 - T1053 - T1055 - T1057 - T1059.003 - T1070 - T1071 - T1078.002 - T1078.003 - T1078.005 - T1106 - T1136 - T1204 - T1218 - T1547 - T1555.003 - T1555.004 - T1573 - T1574 - T1596 - T1543","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","1","N/A","N/A","N/A","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","52081" +"*minidump.exe*",".{0,1000}minidump\.exe.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","52082" +"*Minidump.sln*",".{0,1000}Minidump\.sln.{0,1000}","offensive_tool_keyword","bof-collection","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003 - T1021.001 - T1053 - T1055 - T1057 - T1059.003 - T1070 - T1071 - T1078.002 - T1078.003 - T1078.005 - T1106 - T1136 - T1204 - T1218 - T1547 - T1555.003 - T1555.004 - T1573 - T1574 - T1596 - T1543","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","1","N/A","N/A","N/A","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","52084" +"*minidump_add_memory_block*",".{0,1000}minidump_add_memory_block.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of beacon object files for use with Cobalt Strike to facilitate","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rookuu/BOFs","1","1","N/A","N/A","10","10","175","26","2021-02-11T10:48:12Z","2021-02-11T10:28:48Z","52085" +"*minidump_add_memory64_block*",".{0,1000}minidump_add_memory64_block.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of beacon object files for use with Cobalt Strike to facilitate","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rookuu/BOFs","1","1","N/A","N/A","10","10","175","26","2021-02-11T10:48:12Z","2021-02-11T10:28:48Z","52086" +"*MiniEmpireDLL.dll*",".{0,1000}MiniEmpireDLL\.dll.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","52090" +"*minikerberos.zip*",".{0,1000}minikerberos\.zip.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","52091" +"*minio.dev.pico.sh*",".{0,1000}minio\.dev\.pico\.sh.{0,1000}","offensive_tool_keyword","pico","hacker labs - open source and managed web services leveraging SSH","T1021.005 - T1078 - T1105 - T1109 - T1197 - T1213","TA0005 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/picosh/pico","1","1","N/A","N/A","10","10","1129","36","2025-04-22T17:33:17Z","2022-08-24T03:14:52Z","52094" +"*minio.pico.sh*",".{0,1000}minio\.pico\.sh.{0,1000}","offensive_tool_keyword","pico","hacker labs - open source and managed web services leveraging SSH","T1021.005 - T1078 - T1105 - T1109 - T1197 - T1213","TA0005 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/picosh/pico","1","1","N/A","N/A","10","10","1129","36","2025-04-22T17:33:17Z","2022-08-24T03:14:52Z","52095" +"*mirror.archlinux.tw/BlackArch/*/os/*",".{0,1000}mirror\.archlinux\.tw\/BlackArch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52096" +"*mirror.cedia.org.ec/blackarch/*/os/*",".{0,1000}mirror\.cedia\.org\.ec\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52097" +"*mirror.cyberbits.eu/blackarch/*/os/*",".{0,1000}mirror\.cyberbits\.eu\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52098" +"*mirror.easyname.at/blackarch/*/os/*",".{0,1000}mirror\.easyname\.at\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52099" +"*mirror.easyname.ch/blackarch/*/os/*",".{0,1000}mirror\.easyname\.ch\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52100" +"*mirror.maa.albony.in/blackarch/*/os/*",".{0,1000}mirror\.maa\.albony\.in\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52101" +"*mirror.math.princeton.edu/pub/blackarch/*/os/*",".{0,1000}mirror\.math\.princeton\.edu\/pub\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52102" +"*mirror.serverion.com/blackarch/*/os/*",".{0,1000}mirror\.serverion\.com\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52103" +"*mirror.sg.gs/blackarch/*/os/*",".{0,1000}mirror\.sg\.gs\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52104" +"*mirror.sjtu.edu.cn/blackarch/*/os/*",".{0,1000}mirror\.sjtu\.edu\.cn\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52105" +"*mirror.team-cymru.com/blackarch/*/os/*",".{0,1000}mirror\.team\-cymru\.com\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52106" +"*mirror.telepoint.bg/blackarch/*/os/*",".{0,1000}mirror\.telepoint\.bg\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52107" +"*mirror.tillo.ch/ftp/blackarch/*/os/*",".{0,1000}mirror\.tillo\.ch\/ftp\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52108" +"*mirror.yandex.ru/mirrors/blackarch/*/os/*",".{0,1000}mirror\.yandex\.ru\/mirrors\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52109" +"*mirror.zetup.net/blackarch/*/os/*",".{0,1000}mirror\.zetup\.net\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52110" +"*mirrordump.py*",".{0,1000}mirrordump\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","52111" +"*mirrors.aliyun.com/blackarch/*/os/*",".{0,1000}mirrors\.aliyun\.com\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52112" +"*mirrors.aliyun.com/parrot*",".{0,1000}mirrors\.aliyun\.com\/parrot.{0,1000}","offensive_tool_keyword","parrot os","Parrot OS is a Debian-based. security-oriented Linux distribution that is designed for ethical hacking. penetration testing and digital forensics.","T1590 - T1200 - T1027 - T1578 - T1003 - T1001 - T1046 - T1570 - T1114 - T1105","TA0043 - TA0002 - TA0003 - TA0004 - TA0006 - TA0005 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation OS","https://www.parrotsec.org/download/","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","52113" +"*mirrors.cicku.me/blackarch/*/os/*",".{0,1000}mirrors\.cicku\.me\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52114" +"*mirrors.dotsrc.org/blackarch/*/os/*",".{0,1000}mirrors\.dotsrc\.org\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52115" +"*mirrors.gethosted.online/blackarch/blackarch/*/os/*",".{0,1000}mirrors\.gethosted\.online\/blackarch\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52116" +"*mirrors.hostico.ro/blackarch/*/os/*",".{0,1000}mirrors\.hostico\.ro\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52117" +"*mirrors.hust.edu.cn/blackarch/*/os/*",".{0,1000}mirrors\.hust\.edu\.cn\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52118" +"*mirrors.nju.edu.cn/blackarch/*/os/*",".{0,1000}mirrors\.nju\.edu\.cn\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52119" +"*mirrors.ocf.berkeley.edu/blackarch/*/os/*",".{0,1000}mirrors\.ocf\.berkeley\.edu\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52120" +"*mirrors.tuna.tsinghua.edu.cn/blackarch/*/os/*",".{0,1000}mirrors\.tuna\.tsinghua\.edu\.cn\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52121" +"*mirrors.ustc.edu.cn/blackarch/*/os/*",".{0,1000}mirrors\.ustc\.edu\.cn\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","52122" +"*misc::aadcookie*",".{0,1000}misc\:\:aadcookie.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52123" +"*misc::clip*",".{0,1000}misc\:\:clip.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52124" +"*misc::cmd*",".{0,1000}misc\:\:cmd.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52125" +"*misc::compress*",".{0,1000}misc\:\:compress.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52126" +"*misc::detours*",".{0,1000}misc\:\:detours.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52127" +"*misc::efs*",".{0,1000}misc\:\:efs.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52128" +"*misc::lock*",".{0,1000}misc\:\:lock.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52129" +"*misc::memssp*",".{0,1000}misc\:\:memssp.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52130" +"*misc::mflt*",".{0,1000}misc\:\:mflt.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52131" +"*misc::ncroutemon*",".{0,1000}misc\:\:ncroutemon.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52132" +"*misc::ngcsign*",".{0,1000}misc\:\:ngcsign.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52133" +"*misc::printnightmare*",".{0,1000}misc\:\:printnightmare.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52134" +"*misc::regedit*",".{0,1000}misc\:\:regedit.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52136" +"*misc::sccm*",".{0,1000}misc\:\:sccm.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52137" +"*misc::shadowcopies*",".{0,1000}misc\:\:shadowcopies.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52138" +"*misc::skeleton*",".{0,1000}misc\:\:skeleton.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52139" +"*misc::spooler*",".{0,1000}misc\:\:spooler.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52140" +"*misc::taskmgr*",".{0,1000}misc\:\:taskmgr.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52141" +"*misc::wp*",".{0,1000}misc\:\:wp.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52142" +"*misc::xor*",".{0,1000}misc\:\:xor.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52143" +"*miscbackdoorlnkhelp*",".{0,1000}miscbackdoorlnkhelp.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike kit for Persistence","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/0xthirteen/StayKit","1","1","N/A","N/A","10","10","475","73","2020-01-27T14:53:31Z","2020-01-24T22:20:20Z","52145" +"*Misc-Powershell-Scripts/blob/master/Invoke-DCOM.ps1*",".{0,1000}Misc\-Powershell\-Scripts\/blob\/master\/Invoke\-DCOM\.ps1.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","52146" +"*Misc-PowerShell-Stuff/blob/master/Invoke-TokenDuplication.ps1*",".{0,1000}Misc\-PowerShell\-Stuff\/blob\/master\/Invoke\-TokenDuplication\.ps1.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","52147" +"*missile-command.txt*",".{0,1000}missile\-command\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52148" +"*MisterDaneel/pysoxy*",".{0,1000}MisterDaneel\/pysoxy.{0,1000}","offensive_tool_keyword","pysoxy","A small Socks5 Proxy Server in Python","T1090","TA0011","N/A","N/A","C2","https://github.com/MisterDaneel/pysoxy","1","1","N/A","N/A","10","10","149","51","2023-10-15T06:12:45Z","2016-04-21T07:56:24Z","52149" +"*MitchHS/DLL-Spoofer*",".{0,1000}MitchHS\/DLL\-Spoofer.{0,1000}","offensive_tool_keyword","DLL-Spoofer","POC for a DLL spoofer to determine DLL Hijacking","T1574.002","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/MitchHS/DLL-Spoofer","1","1","N/A","N/A","9","1","60","7","2025-03-04T14:14:15Z","2023-10-18T14:34:38Z","52150" +"*mitchmoser/SharpShares*",".{0,1000}mitchmoser\/SharpShares.{0,1000}","offensive_tool_keyword","SharpShares","Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain","T1046 - T1135","TA0007 - TA0001","N/A","BlackSuit - Royal - BianLian - Fog","Discovery","https://github.com/mitchmoser/SharpShares","1","1","N/A","N/A","10","4","351","49","2021-09-21T08:14:27Z","2020-09-25T22:35:57Z","52151" +"*mitm6.py*",".{0,1000}mitm6\.py.{0,1000}","offensive_tool_keyword","mitm6","performs MiTM for IPv6","T1547 - T1557 - T1569 - T1562 - T1573","TA0002 - TA0003 - TA0008","N/A","N/A","Sniffing & Spoofing","https://github.com/fox-it/mitm6","1","1","N/A","N/A","10","10","1778","256","2024-02-20T16:11:53Z","2018-01-10T21:27:28Z","52154" +"*mitmdump*",".{0,1000}mitmdump.{0,1000}","offensive_tool_keyword","mitmproxy","An interactive. SSL-capable man-in-the-middle proxy for HTTP with a console interface","T1557 - T1553 - T1003 - T1556 - T1563","TA0002 - TA0009 - TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/mitmproxy/mitmproxy","1","1","#linux #windows","command-line version of mitmproxy","10","10","38814","4162","2025-04-22T13:29:41Z","2010-02-16T04:10:13Z","52157" +"*MITMf.py*",".{0,1000}MITMf\.py.{0,1000}","offensive_tool_keyword","MITMf","Framework for Man-In-The-Middle attacks","T1557 - T1192 - T1173 - T1185","TA0001 - TA0011 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/byt3bl33d3r/MITMf","1","1","N/A","N/A","10","10","3612","1047","2018-08-28T15:44:25Z","2014-07-07T11:13:51Z","52158" +"*mitmproxy*",".{0,1000}mitmproxy.{0,1000}","offensive_tool_keyword","mitmproxy","An interactive. SSL-capable man-in-the-middle proxy for HTTP with a console interface","T1557 - T1553 - T1003 - T1556 - T1563","TA0002 - TA0009 - TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/mitmproxy/mitmproxy","1","1","#linux #windows","N/A","10","10","38814","4162","2025-04-22T13:29:41Z","2010-02-16T04:10:13Z","52159" +"*mitmsocks4j*",".{0,1000}mitmsocks4j.{0,1000}","offensive_tool_keyword","mitmsocks4j","Man-in-the-middle SOCKS Proxy for Java","T1557 - T1563 - T1559 - T1588","TA0007 - TA0008","N/A","N/A","Sniffing & Spoofing","https://github.com/Akdeniz/mitmsocks4j","1","1","N/A","N/A","10","1","35","11","2013-02-14T20:42:37Z","2013-02-10T21:33:52Z","52163" +"*mitmweb*",".{0,1000}mitmweb.{0,1000}","offensive_tool_keyword","mitmproxy","An interactive. SSL-capable man-in-the-middle proxy for HTTP with a console interface","T1557 - T1553 - T1003 - T1556 - T1563","TA0002 - TA0009 - TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/mitmproxy/mitmproxy","1","1","#linux #windows","web-based interface for mitmproxy","10","10","38814","4162","2025-04-22T13:29:41Z","2010-02-16T04:10:13Z","52164" +"*mlcsec/FormThief*",".{0,1000}mlcsec\/FormThief.{0,1000}","offensive_tool_keyword","FormThief","Spoofing desktop login applications with WinForms and WPF","T1204.002 - T1056.004 - T1071.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/mlcsec/FormThief","1","1","N/A","N/A","8","2","173","31","2024-02-19T22:40:09Z","2024-02-19T22:34:07Z","52173" +"*mlcsec/Graphpython*",".{0,1000}mlcsec\/Graphpython.{0,1000}","offensive_tool_keyword","Graphpython","Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit","T1078.004 - T1114.002","TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010","N/A","N/A","Discovery","https://github.com/mlcsec/Graphpython","1","1","N/A","N/A","7","2","145","13","2024-12-07T21:54:00Z","2024-07-10T00:04:48Z","52174" +"*mlcsec/SharpGraphView*",".{0,1000}mlcsec\/SharpGraphView.{0,1000}","offensive_tool_keyword","SharpGraphView","Microsoft Graph API post-exploitation toolkit","T1078.004 - T1114.002","TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010","N/A","N/A","Discovery","https://github.com/mlcsec/SharpGraphView","1","1","N/A","N/A","6","1","94","9","2024-07-13T12:27:38Z","2024-05-04T11:23:42Z","52175" +"*mobaxtermfox.dll*",".{0,1000}mobaxtermfox\.dll.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","1","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","52178" +"*Mobile-Security-Framework*",".{0,1000}Mobile\-Security\-Framework.{0,1000}","offensive_tool_keyword","Mobile-Security-Framework-MobSF","Mobile Security Framework (MobSF) is an automated. all-in-one mobile application (Android/iOS/Windows) pen-testing. malware analysis and security assessment framework capable of performing static and dynamic analysis.","T1565.001 - T1565.002 - T1565.003 - T1565.004 - T1523","TA0007 - TA0010 - TA0003","N/A","N/A","Framework","https://github.com/MobSF/Mobile-Security-Framework-MobSF","1","1","N/A","N/A","N/A","10","18450","3353","2025-03-29T17:57:28Z","2015-01-31T04:36:01Z","52180" +"*MockDirUACBypass*",".{0,1000}MockDirUACBypass.{0,1000}","offensive_tool_keyword","MockDirUACBypass","Creates a mock trusted directory C:\Windows \System32\ and moves an auto-elevating Windows executable into the mock directory. A user-supplied DLL which exports the appropriate functions is dropped and when the executable is run - the DLL is loaded and run as high integrity.","T1574.002 - T1547.008 - T1059.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/matterpreter/OffensiveCSharp/tree/master/MockDirUACBypass","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","52182" +"*MockDirUACBypassDll*",".{0,1000}MockDirUACBypassDll.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","52183" +"*Mockingjay_BOF.sln*",".{0,1000}Mockingjay_BOF\.sln.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object File (BOF) Conversion of the Mockingjay Process Injection Technique","T1055.012 - T1059.001 - T1027.002","TA0002 - TA0005","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ewby/Mockingjay_BOF","1","1","N/A","N/A","9","10","151","18","2023-11-07T19:04:03Z","2023-08-27T06:01:28Z","52184" +"*Mockingjay_BOF-main*",".{0,1000}Mockingjay_BOF\-main.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object File (BOF) Conversion of the Mockingjay Process Injection Technique","T1055.012 - T1059.001 - T1027.002","TA0002 - TA0005","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ewby/Mockingjay_BOF","1","1","N/A","N/A","9","10","151","18","2023-11-07T19:04:03Z","2023-08-27T06:01:28Z","52185" +"*mod_auth_remote.phish.htaccess*",".{0,1000}mod_auth_remote\.phish\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52186" +"*mod_buster.py*",".{0,1000}mod_buster\.py.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","52187" +"*mod_caucho.shell.htaccess*",".{0,1000}mod_caucho\.shell\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52188" +"*mod_cgi.shell.bash.htaccess*",".{0,1000}mod_cgi\.shell\.bash\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","#linux","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52189" +"*mod_cgi.shell.bind.htaccess*",".{0,1000}mod_cgi\.shell\.bind\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52190" +"*mod_cgi.shell.windows.htaccess*",".{0,1000}mod_cgi\.shell\.windows\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52191" +"*mod_mono.shell.htaccess*",".{0,1000}mod_mono\.shell\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52192" +"*mod_multi.shell.htaccess*",".{0,1000}mod_multi\.shell\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52193" +"*mod_nikto.py*",".{0,1000}mod_nikto\.py.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","52194" +"*mod_perl.embperl.shell.htaccess*",".{0,1000}mod_perl\.embperl\.shell\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52195" +"*mod_perl.IPP.shell.htaccess*",".{0,1000}mod_perl\.IPP\.shell\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52196" +"*mod_perl.Mason.shell.htaccess*",".{0,1000}mod_perl\.Mason\.shell\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52197" +"*mod_perl.shell.htaccess*",".{0,1000}mod_perl\.shell\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52198" +"*mod_php.shell.htaccess*",".{0,1000}mod_php\.shell\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52199" +"*mod_php.shell2.htaccess*",".{0,1000}mod_php\.shell2\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52200" +"*mod_php.stealth-shell.htaccess*",".{0,1000}mod_php\.stealth\-shell\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52201" +"*mod_python.shell.htaccess*",".{0,1000}mod_python\.shell\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52202" +"*mod_rivet.shell.htaccess*",".{0,1000}mod_rivet\.shell\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52203" +"*mod_ruby.shell.htaccess*",".{0,1000}mod_ruby\.shell\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52204" +"*mod_sendmail.rce.htaccess*",".{0,1000}mod_sendmail\.rce\.htaccess.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","52205" +"*mod_shellshock.py*",".{0,1000}mod_shellshock\.py.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","52206" +"*mod_wp_enum.py*",".{0,1000}mod_wp_enum\.py.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","52207" +"*ModHideDrv_x64.sys*",".{0,1000}ModHideDrv_x64\.sys.{0,1000}","offensive_tool_keyword","VectorKernel","PoCs for Kernelmode rootkit techniques research.","T1543 - T1055 - T1134 - T1564 - T1070 - T1057 - T1574 - T1562 - T1082 - T1518","TA0003 - TA0005 - TA0004 - TA0008 - TA0007","N/A","N/A","Exploitation tool","https://github.com/daem0nc0re/VectorKernel/","1","1","N/A","N/A","10","4","367","60","2025-01-21T08:22:42Z","2023-11-23T12:36:31Z","52219" +"*Modified-Amsi-ScanBuffer-Patch*",".{0,1000}Modified\-Amsi\-ScanBuffer\-Patch.{0,1000}","offensive_tool_keyword","AmsiBypass","bypassing Anti-Malware Scanning Interface (AMSI) features","T1548.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/S3cur3Th1sSh1t/Amsi-Bypass-Powershell","1","1","N/A","N/A","10","10","1890","311","2024-11-28T10:31:15Z","2019-05-14T06:09:25Z","52221" +"*Modlishka/config*",".{0,1000}Modlishka\/config.{0,1000}","offensive_tool_keyword","Modlishka ","Modlishka is a powerful and flexible HTTP reverse proxy. It implements an entirely new and interesting approach of handling browser-based HTTP traffic flow. which allows to transparently proxy multi-domain destination traffic. both TLS and non-TLS. over a single domain. without a requirement of installing any additional certificate on the client.","T1090.001 - T1071.001 - T1556.001 - T1204.001 - T1568.002","TA0011 - TA0001 - TA0002 - TA0005 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/drk1wi/Modlishka","1","1","N/A","network exploitation tool","5","10","4967","897","2024-04-19T12:23:00Z","2018-12-19T15:59:54Z","52227" +"*Modlishka-linux-amd64*",".{0,1000}Modlishka\-linux\-amd64.{0,1000}","offensive_tool_keyword","Modlishka ","Modlishka is a powerful and flexible HTTP reverse proxy. It implements an entirely new and interesting approach of handling browser-based HTTP traffic flow. which allows to transparently proxy multi-domain destination traffic. both TLS and non-TLS. over a single domain. without a requirement of installing any additional certificate on the client.","T1090.001 - T1071.001 - T1556.001 - T1204.001 - T1568.002","TA0011 - TA0001 - TA0002 - TA0005 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/drk1wi/Modlishka","1","1","#linux","network exploitation tool","5","10","4967","897","2024-04-19T12:23:00Z","2018-12-19T15:59:54Z","52229" +"*Modlishka-windows-*-amd64.exe*",".{0,1000}Modlishka\-windows\-.{0,1000}\-amd64\.exe.{0,1000}","offensive_tool_keyword","Modlishka ","Modlishka is a powerful and flexible HTTP reverse proxy. It implements an entirely new and interesting approach of handling browser-based HTTP traffic flow. which allows to transparently proxy multi-domain destination traffic. both TLS and non-TLS. over a single domain. without a requirement of installing any additional certificate on the client.","T1090.001 - T1071.001 - T1556.001 - T1204.001 - T1568.002","TA0011 - TA0001 - TA0002 - TA0005 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/drk1wi/Modlishka","1","1","N/A","network exploitation tool","5","10","4967","897","2024-04-19T12:23:00Z","2018-12-19T15:59:54Z","52230" +"*modules*daclread.py*",".{0,1000}modules.{0,1000}daclread\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","52240" +"*modules/enumrate.py*",".{0,1000}modules\/enumrate\.py.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","52245" +"*modules/exploits/*.js*",".{0,1000}modules\/exploits\/.{0,1000}\.js.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","52246" +"*modules/exploits/*.rb*",".{0,1000}modules\/exploits\/.{0,1000}\.rb.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","52247" +"*modules/nemesis.rb*",".{0,1000}modules\/nemesis\.rb.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","52248" +"*mojo_##*",".{0,1000}mojo_\#\#.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","52252" +"*monero2john.py*",".{0,1000}monero2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","52254" +"*money2john.py*",".{0,1000}money2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","52255" +"*mongodb2john.js*",".{0,1000}mongodb2john\.js.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","52256" +"*monkey*tunnel.py*",".{0,1000}monkey.{0,1000}tunnel\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","52261" +"*monkey_island.exe*",".{0,1000}monkey_island\.exe.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","52263" +"*monkey-linux-32*",".{0,1000}monkey\-linux\-32.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","#linux","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","52266" +"*monkey-linux-64*",".{0,1000}monkey\-linux\-64.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","#linux","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","52267" +"*monkey-windows-32.exe*",".{0,1000}monkey\-windows\-32\.exe.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","52268" +"*monkey-windows-64.exe*",".{0,1000}monkey\-windows\-64\.exe.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","52269" +"*monoxgas/Koppeling*",".{0,1000}monoxgas\/Koppeling.{0,1000}","offensive_tool_keyword","Koppeling","Adaptive DLL hijacking / dynamic export forwarding","T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/monoxgas/Koppeling","1","1","N/A","N/A","8","8","748","128","2020-07-06T14:47:57Z","2020-02-18T21:08:16Z","52270" +"*monoxgas/sRDI*",".{0,1000}monoxgas\/sRDI.{0,1000}","offensive_tool_keyword","sRDI","Shellcode Reflective DLL Injection - Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode","T1620 - T1055.001 - T1059.004 - T1027 - T1105","TA0005 - TA0004 - TA0002","N/A","N/A","Resource Development","https://github.com/monoxgas/sRDI","1","1","N/A","N/A","N/A","10","2262","473","2023-11-15T10:53:00Z","2017-07-28T19:30:53Z","52271" +"*monti5o7lvyrpyk26lqofnfvajtyqruwatlfaazgm3zskt3xiktudwid.onion*",".{0,1000}monti5o7lvyrpyk26lqofnfvajtyqruwatlfaazgm3zskt3xiktudwid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","52272" +"*moom825/Discord-RAT-2.0*",".{0,1000}moom825\/Discord\-RAT\-2\.0.{0,1000}","offensive_tool_keyword","Discord-RAT-2.0","Discord Remote Administration Tool fully written in c#, stub size of ~75kb with over 40 post exploitations modules","T1059.005 - T1105 - T1569.002 - T1027.001","TA0011 - TA0003 - TA0006 - TA0009 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/moom825/Discord-RAT-2.0","1","1","N/A","N/A","10","10","512","115","2023-11-03T01:15:38Z","2022-07-15T20:09:56Z","52273" +"*moom825/xeno-rat*",".{0,1000}moom825\/xeno\-rat.{0,1000}","offensive_tool_keyword","xeno-rat","Xeno-RAT is an open-source remote access tool (RAT) developed in C# providing a comprehensive set of features for remote system management. Has features such as HVNC - live microphone - reverse proxy and much much more","T1133 - T1021.001 - T1563.002 - T1113 - T1123 - T1571 - T1090","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011","N/A","N/A","C2","https://github.com/moom825/xeno-rat","1","1","N/A","N/A","10","10","1225","323","2024-03-05T06:22:36Z","2023-10-17T06:41:56Z","52274" +"*moonD4rk/HackBrowserData*",".{0,1000}moonD4rk\/HackBrowserData.{0,1000}","offensive_tool_keyword","cobaltstrike","C# binary with embeded golang hack-browser-data","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/S3cur3Th1sSh1t/Sharp-HackBrowserData","1","1","N/A","N/A","10","10","96","17","2021-12-09T18:58:27Z","2020-12-06T12:28:47Z","52275" +"*moonD4rk/HackBrowserData*",".{0,1000}moonD4rk\/HackBrowserData.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","52276" +"*morphHTA*",".{0,1000}morphHTA.{0,1000}","offensive_tool_keyword","morphHTA","morphHTA - Morphing Cobalt Strikes evil.HTA payload generator","T1059.007 - T1027.002 - T1564.001 - T1547.001","TA0002 - TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vysecurity/morphHTA","1","1","N/A","N/A","N/A","6","522","130","2023-04-14T19:15:57Z","2017-02-24T11:27:00Z","52281" +"*mortar-main.zip*",".{0,1000}mortar\-main\.zip.{0,1000}","offensive_tool_keyword","mortar","red teaming evasion technique to defeat and divert detection and prevention of security products.Mortar Loader performs encryption and decryption of selected binary inside the memory streams and execute it directly with out writing any malicious indicator into the hard-drive. Mortar is able to bypass modern anti-virus products and advanced XDR solutions","T1055 - T1027 - T1036 - T1112 - T1037 - T1105 - T1059 - T1562","TA0002 - TA0003 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/0xsp-SRD/mortar","1","1","N/A","N/A","10","10","1451","235","2023-12-21T22:00:38Z","2021-11-25T16:49:47Z","52283" +"*mosajjal/dnspot*",".{0,1000}mosajjal\/dnspot.{0,1000}","offensive_tool_keyword","dnspot","End-to-end Encrypted DNS Tunnelling and C2 framework","T1071.004 - T1090.002 - T1573.002","TA0011 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/mosajjal/dnspot","1","1","N/A","N/A","10","10","73","16","2025-02-01T08:13:29Z","2021-09-25T08:49:43Z","52284" +"*mosquitto2john.py*",".{0,1000}mosquitto2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","52285" +"*mousejack*",".{0,1000}mousejack.{0,1000}","offensive_tool_keyword","mousejack","MouseJack device discovery and research tools","T1179 - T1059 - T1065 - T1057","TA0011 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/BastilleResearch/mousejack","1","1","N/A","N/A","10","10","1329","261","2017-12-19T10:16:25Z","2016-02-23T14:19:38Z","52288" +"*Mouselogger.ps1*",".{0,1000}Mouselogger\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","52289" +"*mouseshaker.*",".{0,1000}mouseshaker\..{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","52290" +"*MoveKit-master.zip*",".{0,1000}MoveKit\-master\.zip.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike kit for Lateral Movement","T1021.002 - T1021.006 - T1021.004","TA0008 - TA0002","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Lateral Movement","https://github.com/0xthirteen/MoveKit","1","1","N/A","N/A","10","7","666","109","2020-02-21T20:23:45Z","2020-01-24T22:19:16Z","52292" +"*Mozilla/5.0 (*-bit) dnstwist*",".{0,1000}Mozilla\/5\.0\s\(.{0,1000}\-bit\)\sdnstwist.{0,1000}","offensive_tool_keyword","dnstwist","See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.","T1560 - T1565 - T1566 - T1568 - T1569","TA0002 - TA0005","N/A","N/A","Phishing","https://github.com/elceef/dnstwist","1","1","#useragent","N/A","3","10","5113","801","2025-04-15T18:41:47Z","2015-06-11T12:24:17Z","52297" +"*Mozilla/5.0 (compatible, MSIE 11, Windows NT 6.3; Trident/7.0; rv:11.0) like TsunamiWave*",".{0,1000}Mozilla\/5\.0\s\(compatible,\sMSIE\s11,\sWindows\sNT\s6\.3\;\sTrident\/7\.0\;\srv\:11\.0\)\slike\sTsunamiWave.{0,1000}","offensive_tool_keyword","Tsunami","another C2 framework","T1573 - T1027 - T1059 - T1071 ","TA0011 - TA0009 - TA0003 - TA0007 - TA0008","N/A","N/A","C2","https://github.com/trustedsec/The_Shelf","1","1","#useragent","user-agent","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","52298" +"*Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 10.0; WOW64; Trident/7.0; Specula; Microsoft Outlook*",".{0,1000}Mozilla\/5\.0\s\(compatible\;\sMSIE\s10\.0\;\sWindows\sNT\s10\.0\;\sWOW64\;\sTrident\/7\.0\;\sSpecula\;\sMicrosoft\sOutlook.{0,1000}","offensive_tool_keyword","specula","Specula is a C2 framework that allows for interactive operations of an implant that runs purely in the context of outlook","T1071.001 - T1105 - T1204 - T1548.002 - T1071 - T1562","TA0011 - TA0002 - TA0003 - TA0006 - TA0008 - TA0007 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/trustedsec/specula","1","1","#useragent","default UA template","10","10","191","21","2024-09-23T09:25:33Z","2023-12-07T15:59:52Z","52300" +"*Mozilla/6.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36*",".{0,1000}Mozilla\/6\.0\s\(Windows\sNT\s10\.0\;\sWin64\;\sx64\)\sAppleWebKit\/537\.36\s\(KHTML,\slike\sGecko\)\sChrome\/103\.0\.0\.0\sSafari\/537\.36.{0,1000}","offensive_tool_keyword","GraphStrike","Cobalt Strike HTTPS beaconing over Microsoft Graph API","T1102 - T1071.001 ","TA0002 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/RedSiege/GraphStrike","1","1","#useragent","malicious user agent used by graphstrike server (not a real one)","10","10","585","95","2024-06-25T11:18:19Z","2024-01-02T00:18:44Z","52302" +"*mozilla2john.py*",".{0,1000}mozilla2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","52303" +"*mozlz4-win32.exe*",".{0,1000}mozlz4\-win32\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","52304" +"*mozlz4-win32.exe*",".{0,1000}mozlz4\-win32\.exe.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","52305" +"*mpgn/BackupOperatorToDA*",".{0,1000}mpgn\/BackupOperatorToDA.{0,1000}","offensive_tool_keyword","BackupOperatorToDA","From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller","T1078 - T1078.003 - T1021 - T1021.006 - T1112 - T1003.003","TA0005 - TA0001 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/mpgn/BackupOperatorToDA","1","1","N/A","N/A","10","5","421","53","2025-01-04T14:16:46Z","2022-02-15T20:51:46Z","52312" +"*mqtt_check.py*",".{0,1000}mqtt_check\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/SecureAuthCorp/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","52313" +"*mr.un1k0d3r@gmail.com*",".{0,1000}mr\.un1k0d3r\@gmail\.com.{0,1000}","offensive_tool_keyword","ThunderShell","ThunderShell is a C# RAT that communicates via HTTP requests. All the network traffic is encrypted using a second layer of RC4 to avoid SSL interception and defeat network detection on the target system. RC4 is a weak cipher and is used to help obfuscate the traffic. HTTPS options should be used to provide integrity and strong encryption.","T1021.002 - T1573.002 - T1001.003","TA0008 - TA0011 - TA0040","N/A","LockBit","C2","https://github.com/Mr-Un1k0d3r/ThunderShell","1","1","#email","N/A","10","10","779","223","2023-03-29T21:57:08Z","2017-09-12T01:11:29Z","52314" +"*Mr-B0b/SpaceRunner*",".{0,1000}Mr\-B0b\/SpaceRunner.{0,1000}","offensive_tool_keyword","SpaceRunner","enables the compilation of a C# program that will execute arbitrary PowerShell code without launching PowerShell processes through the use of runspace.","T1059.001 - T1027","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Mr-B0b/SpaceRunner","1","1","N/A","N/A","7","2","195","38","2020-07-26T10:39:53Z","2020-07-26T09:31:09Z","52315" +"*Mr-Cyb3rgh0st/Excel-Exploit*",".{0,1000}Mr\-Cyb3rgh0st\/Excel\-Exploit.{0,1000}","offensive_tool_keyword","Excel-Exploit","MacroExploit use in excel sheet","T1137.001 - T1203 - T1059.007 - T1566.001 - T1564.003","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Mr-Cyb3rgh0st/Excel-Exploit/tree/main","1","1","N/A","N/A","N/A","1","20","3","2023-06-12T11:47:52Z","2023-06-12T11:46:53Z","52316" +"*mrd0x/BITB*",".{0,1000}mrd0x\/BITB.{0,1000}","offensive_tool_keyword","bitb","Browser templates for Browser In The Browser (BITB) attack","T1056.001 - T1134 - T1090","TA0005 - TA0006 - TA0003","N/A","N/A","Sniffing & Spoofing","https://github.com/mrd0x/BITB","1","1","N/A","N/A","10","10","2823","474","2024-01-26T05:20:18Z","2022-03-15T16:51:39Z","52317" +"*mrd0x/PWA-Phishing*",".{0,1000}mrd0x\/PWA\-Phishing.{0,1000}","offensive_tool_keyword","PWA-Phishing","Phishing with Progressive Web Apps and UI manipulation","T1071.003 - T1204.002 - T1608.003 - T1071.004","TA0006","N/A","N/A","Phishing","https://github.com/mrd0x/PWA-Phishing","1","1","N/A","N/A","10","3","288","52","2024-06-16T17:47:15Z","2024-06-09T19:47:52Z","52318" +"*mremoteng_decrypt.py*",".{0,1000}mremoteng_decrypt\.py.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/haseebT/mRemoteNG-Decrypt","1","1","N/A","N/A","8","2","146","42","2023-07-06T16:15:20Z","2019-05-27T05:25:57Z","52319" +"*mremoteng_decrypt.py*",".{0,1000}mremoteng_decrypt\.py.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","1","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","52320" +"*mRemoteNG-local.py*",".{0,1000}mRemoteNG\-local\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","52321" +"*MrEmpy/Reaper*",".{0,1000}MrEmpy\/Reaper.{0,1000}","offensive_tool_keyword","reaper","Reaper is a proof-of-concept designed to exploit BYOVD (Bring Your Own Vulnerable Driver) driver vulnerability. This malicious technique involves inserting a legitimate - vulnerable driver into a target system - which allows attackers to exploit the driver to perform malicious actions.","T1547.009 - T1215 - T1129 - T1548.002","TA0002 - TA0003 - TA0040 - TA0005","N/A","N/A","Defense Evasion","https://github.com/MrEmpy/Reaper","1","1","N/A","N/A","10","2","158","34","2024-12-07T01:52:58Z","2023-09-21T02:09:48Z","52322" +"*Mr-Un1k0d3r/DKMC*",".{0,1000}Mr\-Un1k0d3r\/DKMC.{0,1000}","offensive_tool_keyword","DKMC","Malicious payload evasion tool","T1027 - T1055.012","TA0005 - TA0040","N/A","Molerats","Defense Evasion","https://github.com/Mr-Un1k0d3r/DKMC","1","1","N/A","N/A","10","10","1392","290","2020-07-20T03:36:56Z","2016-12-05T03:44:07Z","52324" +"*mrv44idagzu47oktcipn6tlll6nzapi6pk3u7ehsucl4hpxon45dl4yd.onion*",".{0,1000}mrv44idagzu47oktcipn6tlll6nzapi6pk3u7ehsucl4hpxon45dl4yd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","52325" +"*ms04_007_killbill.*",".{0,1000}ms04_007_killbill\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52328" +"*ms16_075_reflection_juicy.rb*",".{0,1000}ms16_075_reflection_juicy\.rb.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","52332" +"*ms17_010_eternalblue*",".{0,1000}ms17_010_eternalblue.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52333" +"*ms17_010_eternalblue.*",".{0,1000}ms17_010_eternalblue\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52334" +"*ms17_010_psexec*",".{0,1000}ms17_010_psexec.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52335" +"*ms17_010_psexec.*",".{0,1000}ms17_010_psexec\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52336" +"*MSBuildShell*",".{0,1000}MSBuildShell.{0,1000}","offensive_tool_keyword","MSBuildShell","a Powershell Host running within MSBuild.exe This code lets you Bypass Application Whitelisting and Powershell.exe restrictions and gives you a shell that almost looks and feels like a normal Powershell session (Get-Credential. PSSessions -> Works. Tab Completion -> Unfortunately not). It will also bypass the Antimalware Scan Interface (AMSI). which provides enhanced malware protection for Powershell scripts","T1027 - T1086 - T1059 - T1064 - T1089","TA0002 - TA0003 - TA0040","N/A","N/A","Exploitation tool","https://github.com/Cn33liz/MSBuildShell","1","1","N/A","N/A","N/A","3","287","74","2019-08-02T06:46:52Z","2016-11-11T18:52:38Z","52340" +"*MScholtes/PS2EXE*",".{0,1000}MScholtes\/PS2EXE.{0,1000}","offensive_tool_keyword","PS2EXE","Module to compile powershell scripts to executables","T1027.001 - T1564.003 - T1564.005","TA0002 - TA0006","N/A","N/A","Exploitation tool","https://github.com/MScholtes/PS2EXE","1","1","N/A","N/A","N/A","10","1395","217","2025-01-05T11:26:50Z","2019-11-08T09:25:02Z","52341" +"*msf_api_doc.rb*",".{0,1000}msf_api_doc\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52346" +"*msf_cve_extracter.py*",".{0,1000}msf_cve_extracter\.py.{0,1000}","offensive_tool_keyword","Xerror","fully automated pentesting tool","T1083 - T1069 - T1204 - T1059 - T1078","TA0007 - TA0005 - TA0002 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Chudry/Xerror","1","1","N/A","N/A","N/A","6","509","110","2022-12-08T04:33:03Z","2019-08-16T21:20:52Z","52347" +"*msf_exec.py*",".{0,1000}msf_exec\.py.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52348" +"*msf_matchers*",".{0,1000}msf_matchers.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52349" +"*msf_payload.ps1*",".{0,1000}msf_payload\.ps1.{0,1000}","offensive_tool_keyword","nps_payload","This script will generate payloads for basic intrusion detection avoidance","T1027 - T1027.005 - T1055 - T1211","TA0005 - TA0004","N/A","N/A","Exploitation tool","https://github.com/trustedsec/nps_payload","1","1","N/A","N/A","9","5","442","123","2023-11-30T09:24:13Z","2017-07-23T17:01:19Z","52350" +"*msf-auxiliarys*",".{0,1000}msf\-auxiliarys.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","52352" +"*msfconsole*",".{0,1000}msfconsole.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52355" +"*msfconsole.*",".{0,1000}msfconsole\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52356" +"*msfconsole_spec*",".{0,1000}msfconsole_spec.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52357" +"*msfcrawler.*",".{0,1000}msfcrawler\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52358" +"*msfd.rb*",".{0,1000}msfd\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52359" +"*msfdb_helpers*",".{0,1000}msfdb_helpers.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52362" +"*msfencode*",".{0,1000}msfencode.{0,1000}","offensive_tool_keyword","msfvenom","Msfvenom is the combination of payload generation and encoding. It replaced msfpayload and msfencode on June 8th 2015.","T1059.001 - T1027 - T1210.001 - T1204.002","TA0002 - TA0003 - TA0004","N/A","APT32 - Black Basta","Resource Development","https://github.com/rapid7/metasploit-framework/wiki/How-to-use-msfvenom","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52363" +"*msfJavaToolkit*",".{0,1000}msfJavaToolkit.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52364" +"*msf-json-rpc.*",".{0,1000}msf\-json\-rpc\..{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","52365" +"*msf-json-rpc.ru*",".{0,1000}msf\-json\-rpc\.ru.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52366" +"*msflag.ps1*",".{0,1000}msflag\.ps1.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52367" +"*MsfModule*",".{0,1000}MsfModule.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","52368" +"*msfmodule.py*",".{0,1000}msfmodule\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","52369" +"*MsfModuleAsFunction*",".{0,1000}MsfModuleAsFunction.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","52370" +"*msfpattern.*",".{0,1000}msfpattern\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52371" +"*msfpayload*",".{0,1000}msfpayload.{0,1000}","offensive_tool_keyword","msfvenom","Msfvenom is the combination of payload generation and encoding. It replaced msfpayload and msfencode on June 8th 2015.","T1059.001 - T1027 - T1210.001 - T1204.002","TA0002 - TA0003 - TA0004","N/A","APT32 - Black Basta","Resource Development","https://github.com/rapid7/metasploit-framework/wiki/How-to-use-msfvenom","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52372" +"*msfrelay.py*",".{0,1000}msfrelay\.py.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52375" +"*msf-revhttps*",".{0,1000}msf\-revhttps.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","52376" +"*MSFRottenPotato*",".{0,1000}MSFRottenPotato.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52377" +"*MSFRottenPotato.*",".{0,1000}MSFRottenPotato\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52378" +"*MSFRottenPotato.dll*",".{0,1000}MSFRottenPotato\.dll.{0,1000}","offensive_tool_keyword","RottenPotatoNG","perform the RottenPotato attack and get a handle to a privileged token","T1134.001 - T1055.012 - T1547.001","TA0004","N/A","Sandworm","Privilege Escalation","https://github.com/breenmachine/RottenPotatoNG","1","1","N/A","N/A","8","10","935","183","2017-12-29T14:38:47Z","2017-12-29T13:19:03Z","52379" +"*MSFRottenPotato.exe*",".{0,1000}MSFRottenPotato\.exe.{0,1000}","offensive_tool_keyword","RottenPotatoNG","perform the RottenPotato attack and get a handle to a privileged token","T1134.001 - T1055.012 - T1547.001","TA0004","N/A","Sandworm","Privilege Escalation","https://github.com/breenmachine/RottenPotatoNG","1","1","N/A","N/A","8","10","935","183","2017-12-29T14:38:47Z","2017-12-29T13:19:03Z","52380" +"*MSFRottenPotatoTestHarness.exe*",".{0,1000}MSFRottenPotatoTestHarness\.exe.{0,1000}","offensive_tool_keyword","JuicyPotato","Windows Local Privilege Escalation from Service Account to System","T1055.012 - T1068 - T1548.002 - T1505.003","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/uknowsec/JuicyPotato","1","1","N/A","N/A","10","2","190","46","2021-07-01T05:28:41Z","2021-06-10T12:06:13Z","52381" +"*MSFRottenPotatoTestHarness.exe*",".{0,1000}MSFRottenPotatoTestHarness\.exe.{0,1000}","offensive_tool_keyword","RottenPotatoNG","perform the RottenPotato attack and get a handle to a privileged token","T1134.001 - T1055.012 - T1547.001","TA0004","N/A","Sandworm","Privilege Escalation","https://github.com/breenmachine/RottenPotatoNG","1","1","N/A","N/A","8","10","935","183","2017-12-29T14:38:47Z","2017-12-29T13:19:03Z","52382" +"*msf-sgn.raw*",".{0,1000}msf\-sgn\.raw.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","52383" +"*msfshellcode_payload.bin*",".{0,1000}msfshellcode_payload\.bin.{0,1000}","offensive_tool_keyword","Rust-for-Malware-Development","malware development using Rust","T1055.001 - T1027 - T1204 - T1518 - T1056 - T1021 - T1587/001","TA0005 - TA0003 - TA0007 - TA0009 - TA0004 - TA0008 - TA0042","N/A","N/A","Exploitation tool","https://github.com/Whitecat18/Rust-for-Malware-Development","1","1","N/A","N/A","8","10","2123","53","2025-04-22T18:09:57Z","2024-02-12T16:55:06Z","52384" +"*msfvemonpayload*",".{0,1000}msfvemonpayload.{0,1000}","offensive_tool_keyword","cobaltstrike","backdoor c2","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/wahyuhadi/beacon-c2-go","1","1","N/A","N/A","10","10","38","10","2020-01-14T11:15:42Z","2019-12-22T08:59:34Z","52387" +"*msfwrapper.erb*",".{0,1000}msfwrapper\.erb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-omnibus","1","1","N/A","N/A","10","3","268","213","2025-04-18T13:17:56Z","2015-02-26T18:42:09Z","52396" +"*Mshikaki.exe*",".{0,1000}Mshikaki\.exe.{0,1000}","offensive_tool_keyword","Mshikaki","A shellcode injection tool capable of bypassing AMSI. Features the QueueUserAPC() injection technique and supports XOR encryption","T1055.012 - T1116 - T1027.002 - T1562.001","TA0005 - TA0006 - TA0040 - TA0002","N/A","N/A","Exploitation tool","https://github.com/trevorsaudi/Mshikaki","1","1","N/A","N/A","9","2","135","25","2023-11-26T18:13:40Z","2023-09-03T16:35:50Z","52398" +"*Mshikaki-main*",".{0,1000}Mshikaki\-main.{0,1000}","offensive_tool_keyword","Mshikaki","A shellcode injection tool capable of bypassing AMSI. Features the QueueUserAPC() injection technique and supports XOR encryption","T1055.012 - T1116 - T1027.002 - T1562.001","TA0005 - TA0006 - TA0040 - TA0002","N/A","N/A","Exploitation tool","https://github.com/trevorsaudi/Mshikaki","1","1","N/A","N/A","9","2","135","25","2023-11-26T18:13:40Z","2023-09-03T16:35:50Z","52399" +"*mshta/shellcode_inject*",".{0,1000}mshta\/shellcode_inject.{0,1000}","offensive_tool_keyword","GreatSCT","The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This tool is intended for BOTH red and blue team.","T1055 - T1112 - T1189 - T1205","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/GreatSCT/GreatSCT","1","1","N/A","N/A","N/A","10","1127","202","2021-02-10T22:05:27Z","2017-05-12T03:30:41Z","52417" +"*MSHTAStager*",".{0,1000}MSHTAStager.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","52418" +"*msi-search-main.zip*",".{0,1000}msi\-search\-main\.zip.{0,1000}","offensive_tool_keyword","msi-search","This tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairs","T1005 ","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/mandiant/msi-search","1","1","N/A","N/A","10","3","276","31","2023-07-20T18:12:49Z","2023-06-29T18:31:56Z","52470" +"*msLDAPDump.py*",".{0,1000}msLDAPDump\.py.{0,1000}","offensive_tool_keyword","msldapdump","LDAP enumeration tool implemented in Python3","T1018 - T1210.001","TA0007 - TA0001","N/A","N/A","Reconnaissance","https://github.com/dievus/msLDAPDump","1","1","N/A","N/A","N/A","3","226","31","2024-09-23T18:11:26Z","2022-12-30T23:35:40Z","52471" +"*MSOfficeManipulator.cs*",".{0,1000}MSOfficeManipulator\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","52472" +"*msol_dump.ps1*",".{0,1000}msol_dump\.ps1.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","52474" +"*MSOLSpray.git*",".{0,1000}MSOLSpray\.git.{0,1000}","offensive_tool_keyword","MSOLSpray","This module will perform password spraying against Microsoft Online accounts (Azure/O365)","T1110.003 - T1553.003 - T1621","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/MSOLSpray","1","1","N/A","network exploitation tool","10","10","964","174","2024-03-19T11:03:06Z","2020-03-16T13:38:22Z","52476" +"*MSOLSpray.ps1*",".{0,1000}MSOLSpray\.ps1.{0,1000}","offensive_tool_keyword","MSOLSpray","This module will perform password spraying against Microsoft Online accounts (Azure/O365)","T1110.003 - T1553.003 - T1621","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/MSOLSpray","1","1","N/A","network exploitation tool","10","10","964","174","2024-03-19T11:03:06Z","2020-03-16T13:38:22Z","52477" +"*MSOLSpray-master*",".{0,1000}MSOLSpray\-master.{0,1000}","offensive_tool_keyword","MSOLSpray","This module will perform password spraying against Microsoft Online accounts (Azure/O365)","T1110.003 - T1553.003 - T1621","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/MSOLSpray","1","1","N/A","network exploitation tool","10","10","964","174","2024-03-19T11:03:06Z","2020-03-16T13:38:22Z","52478" +"*mspass.exe*",".{0,1000}mspass\.exe.{0,1000}","offensive_tool_keyword","mspass","MessenPass can only be used to recover the passwords for the current logged-on user on your local computer. and it only works if you chose the remember your password in one of the above programs. You cannot use this utility for grabbing the passwords of other users.","T1003 - T1016 - T1021 - T1056 - T1110 - T1212 - T1552 - T1557","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/mspass.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","52479" +"*mspass.zip*",".{0,1000}mspass\.zip.{0,1000}","offensive_tool_keyword","mspass","MessenPass can only be used to recover the passwords for the current logged-on user on your local computer. and it only works if you chose the remember your password in one of the above programs. You cannot use this utility for grabbing the passwords of other users.","T1003 - T1016 - T1021 - T1056 - T1110 - T1212 - T1552 - T1557","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/mspass.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","52480" +"*msquic_openssl/msquic.dll*",".{0,1000}msquic_openssl\/msquic\.dll.{0,1000}","offensive_tool_keyword","ntlmquic","POC tools for exploring SMB over QUIC protocol","T1210.002 - T1210.003 - T1210.004","TA0001","N/A","N/A","Exploitation tool","https://github.com/xpn/ntlmquic","1","1","N/A","network exploitation tool","6","2","122","15","2022-04-06T11:22:11Z","2022-04-05T13:01:02Z","52481" +"*msquic_openssl/msquic.lib*",".{0,1000}msquic_openssl\/msquic\.lib.{0,1000}","offensive_tool_keyword","ntlmquic","POC tools for exploring SMB over QUIC protocol","T1210.002 - T1210.003 - T1210.004","TA0001","N/A","N/A","Exploitation tool","https://github.com/xpn/ntlmquic","1","1","N/A","network exploitation tool","6","2","122","15","2022-04-06T11:22:11Z","2022-04-05T13:01:02Z","52482" +"*MS-RPNVulnerableDC.txt*",".{0,1000}MS\-RPNVulnerableDC\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","52483" +"*mssgbox_shellcode_arranged_x64.b64*",".{0,1000}mssgbox_shellcode_arranged_x64\.b64.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","52486" +"*mssgbox_shellcode_exitfunc_thread_x64.bin*",".{0,1000}mssgbox_shellcode_exitfunc_thread_x64\.bin.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","52487" +"*mssgbox_shellcode_x64.b64*",".{0,1000}mssgbox_shellcode_x64\.b64.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","52488" +"*mssgbox_shellcode_x64.bin*",".{0,1000}mssgbox_shellcode_x64\.bin.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","52489" +"*mssgbox_shellcode_x64.bin*",".{0,1000}mssgbox_shellcode_x64\.bin.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","52490" +"*mssgbox_shellcode_x64_with_hexsymbol.txt*",".{0,1000}mssgbox_shellcode_x64_with_hexsymbol\.txt.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","52491" +"*mssgbox_shellcode_x64_without_hexsymbol.txt*",".{0,1000}mssgbox_shellcode_x64_without_hexsymbol\.txt.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","52492" +"*mssql_brute.rc*",".{0,1000}mssql_brute\.rc.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52493" +"*mssql_local_auth_bypass.*",".{0,1000}mssql_local_auth_bypass\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52494" +"*mssql_local_hashdump.rb*",".{0,1000}mssql_local_hashdump\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52495" +"*mssqlattack.py*",".{0,1000}mssqlattack\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","52496" +"*mssqlattack.py*",".{0,1000}mssqlattack\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","52497" +"*mssqlproxy-master*",".{0,1000}mssqlproxy\-master.{0,1000}","offensive_tool_keyword","mssqlproxy","mssqlproxy is a toolkit aimed to perform Lateral Movement in restricted environments through a compromised Microsoft SQL Server via socket reuse","T1021.002 - T1071.001 - T1573.002","TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/blackarrowsec/mssqlproxy","1","1","N/A","N/A","10","8","741","114","2021-02-16T20:13:04Z","2020-02-12T08:44:28Z","52498" +"*mssqlrelayclient.*",".{0,1000}mssqlrelayclient\..{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","52499" +"*mssqlrelayclient.py*",".{0,1000}mssqlrelayclient\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","52500" +"*mssqlsvc.kirbi*",".{0,1000}mssqlsvc\.kirbi.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Crack with TGSRepCrack","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","52501" +"*msv7eaydbdue7x6hos2kzbtwgoi7xmtuddlqgniqghs3qc54wajudwad.onion*",".{0,1000}msv7eaydbdue7x6hos2kzbtwgoi7xmtuddlqgniqghs3qc54wajudwad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","52502" +"*mthbernardes*rsg*",".{0,1000}mthbernardes.{0,1000}rsg.{0,1000}","offensive_tool_keyword","rsg","A tool to generate various ways to do a reverse shell","T1071.001 - T1071.004 - T1071.005 - T1071.006 - T1071.007","TA0002 - TA0011 - TA0003","N/A","N/A","Resource Development","https://github.com/mthbernardes/rsg","1","1","N/A","N/A","N/A","10","561","126","2024-05-03T16:33:20Z","2017-12-12T02:57:07Z","52504" +"*mthbernardes/rsg*",".{0,1000}mthbernardes\/rsg.{0,1000}","offensive_tool_keyword","rsg","reverse shell powershell","T1059.001 - T1203 - T1105 - T1562.001","TA0002 - TA0011","N/A","Black Basta","C2","https://github.com/mthbernardes/rsg","1","1","N/A","N/A","10","10","561","126","2024-05-03T16:33:20Z","2017-12-12T02:57:07Z","52505" +"*mttaggart/OffensiveNotion*",".{0,1000}mttaggart\/OffensiveNotion.{0,1000}","offensive_tool_keyword","OffensiveNotion","Notion (yes the notetaking app) as a C2.","T1090 - T1090.002 - T1071 - T1071.001","TA0011 - TA0042","N/A","N/A","C2","https://github.com/mttaggart/OffensiveNotion","1","1","N/A","N/A","10","10","1161","130","2023-05-21T13:24:01Z","2022-01-18T16:39:54Z","52506" +"*mtth-bfft/adeleg*",".{0,1000}mtth\-bfft\/adeleg.{0,1000}","offensive_tool_keyword","adeleg","an Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest","T1595 - T1087.002 - T1069.002","TA0007 - TA0004","N/A","N/A","Discovery","https://github.com/mtth-bfft/adeleg","1","1","N/A","N/A","8","3","294","31","2023-06-07T15:08:53Z","2022-02-09T19:47:04Z","52507" +"*mufeedvh/moonwalk*",".{0,1000}mufeedvh\/moonwalk.{0,1000}","offensive_tool_keyword","moonwalk","Cover your tracks during Linux Exploitation by leaving zero traces on system logs and filesystem timestamps.","T1070 - T1036.005 - T1070.004","TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/mufeedvh/moonwalk","1","1","#linux","N/A","10","10","1440","129","2022-10-08T05:05:36Z","2021-12-19T11:24:00Z","52508" +"*multi_meter_inject.rb*",".{0,1000}multi_meter_inject\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52510" +"*multi_vendor_cctv_dvr_pass*",".{0,1000}multi_vendor_cctv_dvr_pass.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52511" +"*multibit2john.py*",".{0,1000}multibit2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","52512" +"*MultiPotato.cpp*",".{0,1000}MultiPotato\.cpp.{0,1000}","offensive_tool_keyword","MultiPotato","get SYSTEM via SeImpersonate privileges","T1548.002 - T1134.002","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S3cur3Th1sSh1t/MultiPotato","1","1","N/A","N/A","10","6","518","92","2021-11-20T16:20:23Z","2021-11-19T15:50:55Z","52513" +"*MultiPotato.exe*",".{0,1000}MultiPotato\.exe.{0,1000}","offensive_tool_keyword","MultiPotato","get SYSTEM via SeImpersonate privileges","T1548.002 - T1134.002","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S3cur3Th1sSh1t/MultiPotato","1","1","N/A","N/A","10","6","518","92","2021-11-20T16:20:23Z","2021-11-19T15:50:55Z","52514" +"*MultiPotato-main*",".{0,1000}MultiPotato\-main.{0,1000}","offensive_tool_keyword","MultiPotato","get SYSTEM via SeImpersonate privileges","T1548.002 - T1134.002","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S3cur3Th1sSh1t/MultiPotato","1","1","N/A","N/A","10","6","518","92","2021-11-20T16:20:23Z","2021-11-19T15:50:55Z","52515" +"*mustafashykh/router-scan*",".{0,1000}mustafashykh\/router\-scan.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","1","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","52516" +"*mvelazc0/BadZure*",".{0,1000}mvelazc0\/BadZure.{0,1000}","offensive_tool_keyword","badazure","BadZure orchestrates the setup of Azure Active Directory tenants populating them with diverse entities while also introducing common security misconfigurations to create vulnerable tenants with multiple attack paths","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Exploitation tool","https://github.com/mvelazc0/BadZure/","1","1","N/A","N/A","5","5","451","26","2025-04-10T03:20:03Z","2023-05-05T04:52:21Z","52522" +"*-my.sharepoint.com/personal/Fakeuser*",".{0,1000}\-my\.sharepoint\.com\/personal\/Fakeuser.{0,1000}","offensive_tool_keyword","onedrive_user_enum","enumerate valid onedrive users","T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/onedrive_user_enum","1","1","N/A","network exploitation tool","N/A","7","663","83","2025-04-17T00:13:11Z","2019-03-05T08:54:38Z","52523" +"*-my.sharepoint.com/personal/TESTUSER_*",".{0,1000}\-my\.sharepoint\.com\/personal\/TESTUSER_.{0,1000}","offensive_tool_keyword","onedrive_user_enum","enumerate valid onedrive users","T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/onedrive_user_enum","1","1","N/A","network exploitation tool","N/A","7","663","83","2025-04-17T00:13:11Z","2019-03-05T08:54:38Z","52524" +"*my_dump_my_pe*",".{0,1000}my_dump_my_pe.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","52525" +"*mybmtbgd7aprdnw2ekxht5qap5daam2wch25coqerrq2zdioanob34ad.onion*",".{0,1000}mybmtbgd7aprdnw2ekxht5qap5daam2wch25coqerrq2zdioanob34ad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","52527" +"*MyMeterpreter.ps1*",".{0,1000}MyMeterpreter\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","52528" +"*myosbja7hixkkjqihsjh6yvmqplz62gr3r4isctjjtu2vm5jg6hsv2ad.onion*",".{0,1000}myosbja7hixkkjqihsjh6yvmqplz62gr3r4isctjjtu2vm5jg6hsv2ad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","52529" +"*myreallycooltotallyrealtenant.onmicrosoft.com*",".{0,1000}myreallycooltotallyrealtenant\.onmicrosoft\.com.{0,1000}","offensive_tool_keyword","teamsphisher","Send phishing messages and attachments to Microsoft Teams users","T1566.001 - T1566.002 - T1204.001","TA0001 - TA0005","N/A","Black Basta","Phishing","https://github.com/Octoberfest7/TeamsPhisher","1","1","N/A","N/A","N/A","10","1073","138","2024-06-19T21:41:55Z","2023-07-03T02:19:47Z","52530" +"*myseatbelt.py*",".{0,1000}myseatbelt\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","52531" +"*mysql_authbypass_hashdump.rb*",".{0,1000}mysql_authbypass_hashdump\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52533" +"*mysql_file_enum.rb*",".{0,1000}mysql_file_enum\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52534" +"*mysql_hashdump.rb*",".{0,1000}mysql_hashdump\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52535" +"*mysql-privesc-race.c*",".{0,1000}mysql\-privesc\-race\.c.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","52536" +"*Mystikal-main*",".{0,1000}Mystikal\-main.{0,1000}","offensive_tool_keyword","Mystikal","macOS Initial Access Payload Generator","T1059.005 - T1204.002 - T1566.001","TA0002 - TA0001","N/A","N/A","Exploitation tool","https://github.com/D00MFist/Mystikal","1","1","N/A","N/A","9","4","305","39","2024-01-10T15:48:12Z","2021-05-03T14:46:16Z","52537" +"*mythic_c2_container*",".{0,1000}mythic_c2_container.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","52538" +"*mythic_nginx*",".{0,1000}mythic_nginx.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","52539" +"*mythic_payloadtype*",".{0,1000}mythic_payloadtype.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","52540" +"*mythic_payloadtype*",".{0,1000}mythic_payloadtype.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","52541" +"*mythic_payloadtype_container*",".{0,1000}mythic_payloadtype_container.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","52542" +"*mythic_rest.Payload*",".{0,1000}mythic_rest\.Payload.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","52543" +"*mythic_service.py*",".{0,1000}mythic_service\.py.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","52544" +"*mythic_translator_containter*",".{0,1000}mythic_translator_containter.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","52545" +"*MythicAgents/Apollo*",".{0,1000}MythicAgents\/Apollo.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","52546" +"*MythicAgents/Athena*",".{0,1000}MythicAgents\/Athena.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","52547" +"*MythicAgents/merlin*",".{0,1000}MythicAgents\/merlin.{0,1000}","offensive_tool_keyword","mythic","Cross-platform post-exploitation HTTP Command & Control agent written in golang","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/merlin","1","1","N/A","N/A","10","10","94","16","2025-04-16T13:05:47Z","2021-01-25T12:36:46Z","52548" +"*MythicAgents/tetanus*",".{0,1000}MythicAgents\/tetanus.{0,1000}","offensive_tool_keyword","tetanus","Mythic C2 agent targeting Linux and Windows hosts written in Rust","T1059 - T1105 - T1219 - T1573 - T1071","TA0011 - TA0010 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/MythicAgents/tetanus","1","1","N/A","N/A","N/A","10","333","49","2024-12-19T19:07:03Z","2022-03-07T20:35:33Z","52549" +"*MythicAgents/thanatos*",".{0,1000}MythicAgents\/thanatos.{0,1000}","offensive_tool_keyword","mythic","Thanatos is a Windows and Linux C2 agent written in rust.","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/thanatos","1","1","N/A","N/A","10","10","333","49","2024-12-19T19:07:03Z","2022-03-07T20:35:33Z","52550" +"*MythicClient.cs*",".{0,1000}MythicClient\.cs.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","52553" +"*mythic-docker*",".{0,1000}mythic\-docker.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","52554" +"*myzxcg/RealBlindingEDR*",".{0,1000}myzxcg\/RealBlindingEDR.{0,1000}","offensive_tool_keyword","RealBlindingEDR","AV/EDR evasion","T1562.001 - T1548.001","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/myzxcg/RealBlindingEDR","1","1","N/A","N/A","10","10","1050","190","2024-06-21T03:16:55Z","2023-10-28T07:06:53Z","52556" +"*MzHmO/DebugAmsi*",".{0,1000}MzHmO\/DebugAmsi.{0,1000}","offensive_tool_keyword","DebugAmsi","DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.","T1562.001 - T1050.005","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/MzHmO/DebugAmsi","1","1","N/A","N/A","10","1","97","22","2023-09-18T17:17:26Z","2023-08-28T07:32:54Z","52558" +"*MzHmO/NtlmThief*",".{0,1000}MzHmO\/NtlmThief.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","1","N/A","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","52559" +"*MzHmO/Parasite-Invoke*",".{0,1000}MzHmO\/Parasite\-Invoke.{0,1000}","offensive_tool_keyword","Parasite-Invoke","Hide your P/Invoke signatures through other people's signed assemblies","T1129 - T1574.002 - T1218","TA0005","N/A","N/A","Defense Evasion","https://github.com/MzHmO/Parasite-Invoke","1","1","N/A","N/A","8","3","207","32","2024-03-10T14:53:59Z","2024-03-07T20:18:42Z","52560" +"*MzHmO/PowershellKerberos*",".{0,1000}MzHmO\/PowershellKerberos.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","52561" +"*MzHmO/Privileger*",".{0,1000}MzHmO\/Privileger.{0,1000}","offensive_tool_keyword","Privileger","Privileger is a tool to work with Windows Privileges","T1548.002","TA0004 ","N/A","N/A","Privilege Escalation","https://github.com/MzHmO/Privileger","1","1","N/A","N/A","8","2","136","32","2023-02-07T07:28:40Z","2023-01-31T11:24:37Z","52562" +"*MzHmO/TGSThief*",".{0,1000}MzHmO\/TGSThief.{0,1000}","offensive_tool_keyword","TGSThief","get the TGS of a user whose logon session is just present on the computer","T1558 - T1558.003 - T1078 - T1078.005","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/MzHmO/TGSThief","1","1","N/A","N/A","9","2","181","27","2023-07-25T05:30:39Z","2023-07-23T07:47:05Z","52563" +"*n00py/LAPSDumper*",".{0,1000}n00py\/LAPSDumper.{0,1000}","offensive_tool_keyword","LAPSDumper","Dumping LAPS from Python","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/n00py/LAPSDumper","1","1","N/A","N/A","10","3","267","35","2022-12-07T18:35:28Z","2020-12-19T05:15:10Z","52565" +"*n00py/Slackor*",".{0,1000}n00py\/Slackor.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","52566" +"*n0de.exe*elevationstation*",".{0,1000}n0de\.exe.{0,1000}elevationstation.{0,1000}","offensive_tool_keyword","elevationstation","elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","52567" +"*n1k7l4i/goMatrixC2*",".{0,1000}n1k7l4i\/goMatrixC2.{0,1000}","offensive_tool_keyword","goMatrixC2","C2 leveraging Matrix/Element Messaging Platform as Backend to control Implants in goLang.","T1090 - T1027 - T1071","TA0011 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/n1k7l4i/goMatrixC2","1","1","N/A","N/A","10","","N/A","","","","52568" +"*n1k7l4i/goZulipC2*",".{0,1000}n1k7l4i\/goZulipC2.{0,1000}","offensive_tool_keyword","goZulipC2","C2 leveraging Zulip Messaging Platform as Backend.","T1090 - T1090.003 - T1071 - T1071.001","TA0011 - TA0009","N/A","N/A","C2","https://github.com/n1k7l4i/goZulipC2","1","1","N/A","N/A","10","","N/A","","","","52569" +"*n1nj4sec/mimipy*",".{0,1000}n1nj4sec\/mimipy.{0,1000}","offensive_tool_keyword","mimipy","Tool to dump passwords from various processes memory","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/n1nj4sec/mimipy","1","1","N/A","N/A","10","3","207","36","2017-04-30T00:09:15Z","2017-04-05T21:06:32Z","52570" +"*n37sn4k3/BrowserDataGrabber*",".{0,1000}n37sn4k3\/BrowserDataGrabber.{0,1000}","offensive_tool_keyword","Browser Data Grabber","credential access tool used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://github.com/n37sn4k3/BrowserDataGrabber","1","1","N/A","N/A","10","1","7","4","2018-05-28T15:49:03Z","2018-05-04T12:33:32Z","52571" +"*nac_bypass*",".{0,1000}nac_bypass.{0,1000}","offensive_tool_keyword","nac_bypass","nac bypass - The basic requirement for an NAC bypass is access to a device that has already been authenticated. This device is used to log into the network and then smuggle in network packages from a different device. This involves placing the attackers system between the network switch and the authenticated device. One way to do this is with a Raspberry Pi and two network adapters","T1550.002 - T1078 - T1133 - T1040 - T1550","TA0001 - TA0002 - TA0003 - TA0006","N/A","N/A","Defense Evasion","https://github.com/scipag/nac_bypass","1","1","N/A","N/A","N/A","3","299","69","2025-02-24T14:17:42Z","2019-01-03T06:55:00Z","52573" +"*nachovpn.local*",".{0,1000}nachovpn\.local.{0,1000}","offensive_tool_keyword","NachoVPN","NachoVPN is a Proof of Concept that demonstrates exploitation of SSL-VPN clients using a rogue VPN serve","T1071 - T1027 - T1547 - T1204","TA0003 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/AmberWolfCyber/NachoVPN","1","1","N/A","N/A","7","3","218","28","2024-11-28T12:40:55Z","2024-10-30T15:53:56Z","52575" +"*nagios-root-privesc.sh*",".{0,1000}nagios\-root\-privesc\.sh.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","52578" +"*naksyn/Pyramid*",".{0,1000}naksyn\/Pyramid.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","52579" +"*named_pipes.txt*",".{0,1000}named_pipes\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52584" +"*NamedPipeImpersonation.exe*",".{0,1000}NamedPipeImpersonation\.exe.{0,1000}","offensive_tool_keyword","PrivFu","Kernel mode WinDbg extension and PoCs for token privilege investigation.","T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001","TA0007 - TA0008 - TA0002 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","52586" +"*NamedPipeImpersonation.exe*",".{0,1000}NamedPipeImpersonation\.exe.{0,1000}","offensive_tool_keyword","PrivFu","ArtsOfGetSystem privesc tools","T1134 - T1134.001 - T1078 - T1059 - T1075","TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu/","1","1","N/A","ArtsOfGetSystem","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","52587" +"*NamedPipeMaster/releases/download/*",".{0,1000}NamedPipeMaster\/releases\/download\/.{0,1000}","offensive_tool_keyword","NamedPipeMaster","a tool used to analyze monitor and interact with named pipes - allows dll injection and impersonation","T1055.001 - T1134.001 - T1010 - T1550.002","TA0007 - TA0008 - TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/zeze-zeze/NamedPipeMaster","1","1","N/A","N/A","9","2","161","15","2024-10-27T05:24:11Z","2024-08-23T02:03:44Z","52588" +"*NamedPipeMaster-32bit.zip*",".{0,1000}NamedPipeMaster\-32bit\.zip.{0,1000}","offensive_tool_keyword","NamedPipeMaster","a tool used to analyze monitor and interact with named pipes - allows dll injection and impersonation","T1055.001 - T1134.001 - T1010 - T1550.002","TA0007 - TA0008 - TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/zeze-zeze/NamedPipeMaster","1","1","N/A","N/A","9","2","161","15","2024-10-27T05:24:11Z","2024-08-23T02:03:44Z","52589" +"*NamedPipeMaster-64bit.zip*",".{0,1000}NamedPipeMaster\-64bit\.zip.{0,1000}","offensive_tool_keyword","NamedPipeMaster","a tool used to analyze monitor and interact with named pipes - allows dll injection and impersonation","T1055.001 - T1134.001 - T1010 - T1550.002","TA0007 - TA0008 - TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/zeze-zeze/NamedPipeMaster","1","1","N/A","N/A","9","2","161","15","2024-10-27T05:24:11Z","2024-08-23T02:03:44Z","52591" +"*NamedPipeMaster-main.zip*",".{0,1000}NamedPipeMaster\-main\.zip.{0,1000}","offensive_tool_keyword","NamedPipeMaster","a tool used to analyze monitor and interact with named pipes - allows dll injection and impersonation","T1055.001 - T1134.001 - T1010 - T1550.002","TA0007 - TA0008 - TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/zeze-zeze/NamedPipeMaster","1","1","N/A","N/A","9","2","161","15","2024-10-27T05:24:11Z","2024-08-23T02:03:44Z","52594" +"*NamedPipePoker.cpp*",".{0,1000}NamedPipePoker\.cpp.{0,1000}","offensive_tool_keyword","NamedPipeMaster","a tool used to analyze monitor and interact with named pipes - allows dll injection and impersonation","T1055.001 - T1134.001 - T1010 - T1550.002","TA0007 - TA0008 - TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/zeze-zeze/NamedPipeMaster","1","1","N/A","N/A","9","2","161","15","2024-10-27T05:24:11Z","2024-08-23T02:03:44Z","52595" +"*NamelessImplant.dll*",".{0,1000}NamelessImplant\.dll.{0,1000}","offensive_tool_keyword","NamelessC2","A C2 with all its components written in Rust","T1102 - T1573.001 - T1027 - T1219 - T1205","TA0011 - TA0003 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/trickster0/NamelessC2","1","1","N/A","N/A","10","10","266","33","2024-09-26T21:21:20Z","2024-09-26T21:06:37Z","52599" +"*namelessserver.com*",".{0,1000}namelessserver\.com.{0,1000}","offensive_tool_keyword","NamelessC2","A C2 with all its components written in Rust","T1102 - T1573.001 - T1027 - T1219 - T1205","TA0011 - TA0003 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/trickster0/NamelessC2","1","1","N/A","N/A","10","10","266","33","2024-09-26T21:21:20Z","2024-09-26T21:06:37Z","52600" +"*nanodump.*",".{0,1000}nanodump\..{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","52632" +"*nanodump.*",".{0,1000}nanodump\..{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52633" +"*nanodump.git*",".{0,1000}nanodump\.git.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52634" +"*nanodump.x64*",".{0,1000}nanodump\.x64.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52635" +"*nanodump.x64.exe*",".{0,1000}nanodump\.x64\.exe.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52636" +"*nanodump.x86*",".{0,1000}nanodump\.x86.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52637" +"*nanodump_dump*",".{0,1000}nanodump_dump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","52638" +"*nanodump_ppl.x64.dll*",".{0,1000}nanodump_ppl\.x64\.dll.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","52640" +"*nanodump_ppl_dump*",".{0,1000}nanodump_ppl_dump.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52641" +"*nanodump_ppl_dump.x64*",".{0,1000}nanodump_ppl_dump\.x64.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52642" +"*nanodump_ppl_dump.x86*",".{0,1000}nanodump_ppl_dump\.x86.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52643" +"*nanodump_ppl_medic*",".{0,1000}nanodump_ppl_medic.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52644" +"*nanodump_ppl_medic.x64*",".{0,1000}nanodump_ppl_medic\.x64.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52645" +"*nanodump_ppl_medic.x86*",".{0,1000}nanodump_ppl_medic\.x86.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52646" +"*nanodump_ssp*",".{0,1000}nanodump_ssp.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","52647" +"*nanodump_ssp*",".{0,1000}nanodump_ssp.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52648" +"*nanodump_ssp.x64*",".{0,1000}nanodump_ssp\.x64.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52649" +"*nanodump_ssp.x64.dll*",".{0,1000}nanodump_ssp\.x64\.dll.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","52650" +"*nanodump_ssp.x64.dll*",".{0,1000}nanodump_ssp\.x64\.dll.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52651" +"*nanodump_ssp.x86*",".{0,1000}nanodump_ssp\.x86.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52652" +"*nanodump_ssp_embedded.*",".{0,1000}nanodump_ssp_embedded\..{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","52653" +"*NanoDumpChoose*",".{0,1000}NanoDumpChoose.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","52654" +"*NanoDumpWriteDump*",".{0,1000}NanoDumpWriteDump.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52658" +"*nanorobeus*_cs.x64.*",".{0,1000}nanorobeus.{0,1000}_cs\.x64\..{0,1000}","offensive_tool_keyword","nanorobeus","COFF file (BOF) for managing Kerberos tickets.","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","C2","https://github.com/wavvs/nanorobeus","1","1","N/A","N/A","10","10","294","31","2023-07-02T12:56:27Z","2022-07-04T00:33:30Z","52659" +"*nanorobeus*_cs.x86.*",".{0,1000}nanorobeus.{0,1000}_cs\.x86\..{0,1000}","offensive_tool_keyword","nanorobeus","COFF file (BOF) for managing Kerberos tickets.","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","C2","https://github.com/wavvs/nanorobeus","1","1","N/A","N/A","10","10","294","31","2023-07-02T12:56:27Z","2022-07-04T00:33:30Z","52660" +"*nanorobeus*dump*",".{0,1000}nanorobeus.{0,1000}dump.{0,1000}","offensive_tool_keyword","nanorobeus","COFF file (BOF) for managing Kerberos tickets.","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","C2","https://github.com/wavvs/nanorobeus","1","1","N/A","N/A","10","10","294","31","2023-07-02T12:56:27Z","2022-07-04T00:33:30Z","52661" +"*nanorobeus.cna*",".{0,1000}nanorobeus\.cna.{0,1000}","offensive_tool_keyword","nanorobeus","COFF file (BOF) for managing Kerberos tickets.","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","C2","https://github.com/wavvs/nanorobeus","1","1","N/A","N/A","10","10","294","31","2023-07-02T12:56:27Z","2022-07-04T00:33:30Z","52662" +"*nanorobeus.py*",".{0,1000}nanorobeus\.py.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","52663" +"*nanorobeus.x64*",".{0,1000}nanorobeus\.x64.{0,1000}","offensive_tool_keyword","nanorobeus","COFF file (BOF) for managing Kerberos tickets.","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","C2","https://github.com/wavvs/nanorobeus","1","1","N/A","N/A","10","10","294","31","2023-07-02T12:56:27Z","2022-07-04T00:33:30Z","52664" +"*nanorobeus.x64.*",".{0,1000}nanorobeus\.x64\..{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","52665" +"*nanorobeus.x86*",".{0,1000}nanorobeus\.x86.{0,1000}","offensive_tool_keyword","nanorobeus","COFF file (BOF) for managing Kerberos tickets.","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","C2","https://github.com/wavvs/nanorobeus","1","1","N/A","N/A","10","10","294","31","2023-07-02T12:56:27Z","2022-07-04T00:33:30Z","52666" +"*nanorobeus_brc4*",".{0,1000}nanorobeus_brc4.{0,1000}","offensive_tool_keyword","nanorobeus","COFF file (BOF) for managing Kerberos tickets.","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","C2","https://github.com/wavvs/nanorobeus","1","1","N/A","N/A","10","10","294","31","2023-07-02T12:56:27Z","2022-07-04T00:33:30Z","52667" +"*nanorobeus64*",".{0,1000}nanorobeus64.{0,1000}","offensive_tool_keyword","nanorobeus","COFF file (BOF) for managing Kerberos tickets.","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","C2","https://github.com/wavvs/nanorobeus","1","1","N/A","N/A","10","10","294","31","2023-07-02T12:56:27Z","2022-07-04T00:33:30Z","52668" +"*nanorobeus86*",".{0,1000}nanorobeus86.{0,1000}","offensive_tool_keyword","nanorobeus","COFF file (BOF) for managing Kerberos tickets.","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","C2","https://github.com/wavvs/nanorobeus","1","1","N/A","N/A","10","10","294","31","2023-07-02T12:56:27Z","2022-07-04T00:33:30Z","52669" +"*nanorobeus-main*",".{0,1000}nanorobeus\-main.{0,1000}","offensive_tool_keyword","nanorobeus","COFF file (BOF) for managing Kerberos tickets.","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","C2","https://github.com/wavvs/nanorobeus","1","1","N/A","N/A","10","10","294","31","2023-07-02T12:56:27Z","2022-07-04T00:33:30Z","52670" +"*Narasimha1997/fake-sms*",".{0,1000}Narasimha1997\/fake\-sms.{0,1000}","offensive_tool_keyword","fake-sms","A simple command line tool using which you can skip phone number based SMS verification by using a temporary phone number that acts like a proxy.","T1598.003 - T1514","TA0003 - TA0009","N/A","N/A","Defense Evasion","https://github.com/Narasimha1997/fake-sms","1","1","N/A","N/A","8","10","2745","176","2023-08-01T15:34:41Z","2021-02-18T15:18:50Z","52672" +"*NativeBypassCredGuard.exe*",".{0,1000}NativeBypassCredGuard\.exe.{0,1000}","offensive_tool_keyword","NativeBypassCredGuard","Bypass Credential Guard by patching WDigest.dll using only NTAPI functions","T1558 - T1003.006","TA0006 - TA0005","N/A","N/A","Defense Evasion","https://github.com/ricardojoserf/NativeBypassCredGuard","1","1","N/A","N/A","7","3","236","28","2025-04-08T18:58:37Z","2024-12-01T16:58:03Z","52675" +"*NativeEasyHook32.dll*",".{0,1000}NativeEasyHook32\.dll.{0,1000}","offensive_tool_keyword","Dendrobate","Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code","T1055.012 - T1059.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Dendrobate","1","1","N/A","N/A","10","2","131","27","2021-11-19T12:18:50Z","2021-02-15T11:15:51Z","52677" +"*NativeEasyHook64.dll*",".{0,1000}NativeEasyHook64\.dll.{0,1000}","offensive_tool_keyword","Dendrobate","Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code","T1055.012 - T1059.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Dendrobate","1","1","N/A","N/A","10","2","131","27","2021-11-19T12:18:50Z","2021-02-15T11:15:51Z","52678" +"*nbdytundtyud5dey.azurewebsites.net*",".{0,1000}nbdytundtyud5dey\.azurewebsites\.net.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","52681" +"*NBNSBruteForceHost*",".{0,1000}NBNSBruteForceHost.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","52682" +"*NBNSBruteForcePause*",".{0,1000}NBNSBruteForcePause.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","52683" +"*NBNSBruteForceSpoofer*",".{0,1000}NBNSBruteForceSpoofer.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","52684" +"*NBNSBruteForceSpoofer*",".{0,1000}NBNSBruteForceSpoofer.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","52685" +"*NBNSBruteForceTarget*",".{0,1000}NBNSBruteForceTarget.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","52686" +"*nbnsspoof.py*",".{0,1000}nbnsspoof\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","52687" +"*NBNSSpoofer*",".{0,1000}NBNSSpoofer.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","52688" +"*nbzzb6sa6xuura2z.onion*",".{0,1000}nbzzb6sa6xuura2z\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","52694" +"*nccgroup/ABPTTS*",".{0,1000}nccgroup\/ABPTTS.{0,1000}","offensive_tool_keyword","ABPTTS","TCP tunneling over HTTP/HTTPS for web application servers","T1071.001 - T1573","TA0003 - TA0011","N/A","N/A","Persistence","https://github.com/nccgroup/ABPTTS","1","1","N/A","N/A","9","8","735","151","2016-08-12T19:36:24Z","2016-07-29T21:45:57Z","52722" +"*nccgroup/Accomplice*",".{0,1000}nccgroup\/Accomplice.{0,1000}","offensive_tool_keyword","Accomplice","Tools for discovery and abuse of COM hijacks","T1120 - T1174","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/nccgroup/Accomplice","1","1","N/A","N/A","7","4","303","47","2019-10-15T21:54:09Z","2019-09-04T23:32:09Z","52723" +"*nccgroup/demiguise*",".{0,1000}nccgroup\/demiguise.{0,1000}","offensive_tool_keyword","demiguise","The aim of this project is to generate .html files that contain an encrypted HTA file. The idea is that when your target visits the page. the key is fetched and the HTA is decrypted dynamically within the browser and pushed directly to the user. This is an evasion technique to get round content / file-type inspection implemented by some security-appliances. This tool is not designed to create awesome HTA content. There are many other tools/techniques that can help you with that. What it might help you with is getting your HTA into an environment in the first place. and (if you use environmental keying) to avoid it being sandboxed.","T1564 - T1071.001 - T1071.004 - T1059 - T1070","TA0002 - TA0011 - TA0008","N/A","N/A","Defense Evasion","https://github.com/nccgroup/demiguise","1","1","N/A","N/A","9","10","1389","257","2022-11-09T08:12:25Z","2017-07-26T08:56:15Z","52724" +"*nccgroup/SCOMDecrypt*",".{0,1000}nccgroup\/SCOMDecrypt.{0,1000}","offensive_tool_keyword","SCOMDecrypt","SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers","T1552.001 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/nccgroup/SCOMDecrypt","1","1","N/A","N/A","10","2","123","22","2023-11-10T07:04:26Z","2017-02-21T16:15:11Z","52725" +"*ncrack-*.dmg*",".{0,1000}ncrack\-.{0,1000}\.dmg.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","1","#macos","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","52726" +"*ncrack-*-setup.exe*",".{0,1000}ncrack\-.{0,1000}\-setup\.exe.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","1","N/A","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","52727" +"*ncrack.exe*",".{0,1000}ncrack\.exe.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","1","N/A","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","52728" +"*NcrackInstaller.exe*",".{0,1000}NcrackInstaller\.exe.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","1","N/A","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","52729" +"*ncrack-master.zip*",".{0,1000}ncrack\-master\.zip.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","1","N/A","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","52730" +"*ncrack-services*",".{0,1000}ncrack\-services.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","1","N/A","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","52731" +"*ndp_spoof.*",".{0,1000}ndp_spoof\..{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","52733" +"*Ne0nd0g/merlin*",".{0,1000}Ne0nd0g\/merlin.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","52734" +"*Ne0nd0g/merlin-agent*",".{0,1000}Ne0nd0g\/merlin\-agent.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","N/A","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","52735" +"*Ne0nd0g/merlin-agent-dll*",".{0,1000}Ne0nd0g\/merlin\-agent\-dll.{0,1000}","offensive_tool_keyword","merlin-agent-dll","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent-dll","1","1","N/A","N/A","10","10","51","15","2025-04-17T14:01:36Z","2021-04-17T16:58:24Z","52736" +"*NecroStealer.exe*",".{0,1000}NecroStealer\.exe.{0,1000}","offensive_tool_keyword","Necro-Stealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/Necro-Stealer","1","1","N/A","N/A","8","1","6","1","2022-12-06T16:06:55Z","2022-12-06T15:52:17Z","52737" +"*needle_sift.x64*",".{0,1000}needle_sift\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Strstr with user-supplied needle and filename as a BOF.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/Needle_Sift_BOF","1","1","N/A","N/A","10","10","32","8","2021-09-27T22:57:33Z","2021-09-27T20:13:10Z","52738" +"*needlesift.cna*",".{0,1000}needlesift\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Strstr with user-supplied needle and filename as a BOF.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/Needle_Sift_BOF","1","1","N/A","N/A","10","10","32","8","2021-09-27T22:57:33Z","2021-09-27T20:13:10Z","52740" +"*neo2john.py*",".{0,1000}neo2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","52751" +"*neo4jconnection.py*",".{0,1000}neo4jconnection\.py.{0,1000}","offensive_tool_keyword","sprayhound","Password spraying tool and Bloodhound integration","T1110.003 - T1210.001 - T1069.002","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/Hackndo/sprayhound","1","1","N/A","N/A","N/A","3","231","19","2024-12-31T08:09:37Z","2020-02-06T17:45:37Z","52754" +"*Nessus-*.deb*",".{0,1000}Nessus\-.{0,1000}\.deb.{0,1000}","offensive_tool_keyword","nessus","Vulnerability scanner","T1046 - T1068 - T1190 - T1201 - T1222 - T1592","TA0001 - TA0002 - TA0007 - TA0011","N/A","N/A","Vulnerability Scanner","https://fr.tenable.com/products/nessus","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","52759" +"*Nessus-*.dmg*",".{0,1000}Nessus\-.{0,1000}\.dmg.{0,1000}","offensive_tool_keyword","nessus","Vulnerability scanner","T1046 - T1068 - T1190 - T1201 - T1222 - T1592","TA0001 - TA0002 - TA0007 - TA0011","N/A","N/A","Vulnerability Scanner","https://fr.tenable.com/products/nessus","1","1","#macos","N/A","9","10","N/A","N/A","N/A","N/A","52760" +"*Nessus-*.msi*",".{0,1000}Nessus\-.{0,1000}\.msi.{0,1000}","offensive_tool_keyword","nessus","Vulnerability scanner","T1046 - T1068 - T1190 - T1201 - T1222 - T1592","TA0001 - TA0002 - TA0007 - TA0011","N/A","N/A","Vulnerability Scanner","https://fr.tenable.com/products/nessus","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","52761" +"*Nessus-*.rpm*",".{0,1000}Nessus\-.{0,1000}\.rpm.{0,1000}","offensive_tool_keyword","nessus","Vulnerability scanner","T1046 - T1068 - T1190 - T1201 - T1222 - T1592","TA0001 - TA0002 - TA0007 - TA0011","N/A","N/A","Vulnerability Scanner","https://fr.tenable.com/products/nessus","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","52762" +"*Nessus-*.tar.gz*",".{0,1000}Nessus\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","nessus","Vulnerability scanner","T1046 - T1068 - T1190 - T1201 - T1222 - T1592","TA0001 - TA0002 - TA0007 - TA0011","N/A","N/A","Vulnerability Scanner","https://fr.tenable.com/products/nessus","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","52763" +"*Nessus-*.txz*",".{0,1000}Nessus\-.{0,1000}\.txz.{0,1000}","offensive_tool_keyword","nessus","Vulnerability scanner","T1046 - T1068 - T1190 - T1201 - T1222 - T1592","TA0001 - TA0002 - TA0007 - TA0011","N/A","N/A","Vulnerability Scanner","https://fr.tenable.com/products/nessus","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","52764" +"*nessus_vulns_cleaner.rc*",".{0,1000}nessus_vulns_cleaner\.rc.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","52765" +"*nessus-updates*.tar.gz*",".{0,1000}nessus\-updates.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","nessus","Vulnerability scanner","T1046 - T1068 - T1190 - T1201 - T1222 - T1592","TA0001 - TA0002 - TA0007 - TA0011","N/A","N/A","Vulnerability Scanner","https://fr.tenable.com/products/nessus","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","52768" +"*net::alias*",".{0,1000}net\:\:alias.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","53087" +"*net::deleg*",".{0,1000}net\:\:deleg.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","53088" +"*net::group*",".{0,1000}net\:\:group.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","53089" +"*net::if*",".{0,1000}net\:\:if.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","53090" +"*net::serverinfo*",".{0,1000}net\:\:serverinfo.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","53091" +"*net::session*",".{0,1000}net\:\:session.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","53092" +"*net::share*",".{0,1000}net\:\:share.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","53093" +"*net::stats*",".{0,1000}net\:\:stats.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","53094" +"*net::tod*",".{0,1000}net\:\:tod.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","53095" +"*net::trust*",".{0,1000}net\:\:trust.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","53096" +"*net::user*",".{0,1000}net\:\:user.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","53097" +"*net::wsession*",".{0,1000}net\:\:wsession.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","53098" +"*net_portscan.py*",".{0,1000}net_portscan\.py.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","53102" +"*net_recon.*",".{0,1000}net_recon\..{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","53103" +"*netbiosX/AMSI-Provider*",".{0,1000}netbiosX\/AMSI\-Provider.{0,1000}","offensive_tool_keyword","AMSI-Provider","A fake AMSI Provider which can be used for persistence","T1546.013 - T1574.012","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/netbiosX/AMSI-Provider","1","1","N/A","N/A","10","2","150","16","2021-05-16T16:56:15Z","2021-05-15T16:18:47Z","53136" +"*netero1010/EDRSilencer*",".{0,1000}netero1010\/EDRSilencer.{0,1000}","offensive_tool_keyword","EDRSilencer","A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server","T1562.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/netero1010/EDRSilencer","1","1","N/A","N/A","10","10","1645","209","2024-11-03T16:05:14Z","2023-12-26T04:15:39Z","53140" +"*netero1010/GhostTask*",".{0,1000}netero1010\/GhostTask.{0,1000}","offensive_tool_keyword","GhostTask","Creates scheduled tasks with a restrictive security descriptor - making them invisible to all users. - Establishes scheduled tasks directly via the registry - bypassing the generation of standard Windows event logs. - Provides support to modify existing scheduled tasks without generating Windows event logs. - Supports remote scheduled task creation (by using specially crafted Silver Ticket). - Supports to run in C2 with in-memory PE execution module (e.g. - BruteRatel's memexec)","T1053.005 - T1112 - T1078","TA0003 - TA0005 - TA0007","N/A","N/A","Defense Evasion","https://github.com/netero1010/GhostTask","1","1","N/A","N/A","10","6","549","63","2025-01-02T15:26:01Z","2023-10-23T13:05:00Z","53141" +"*netero1010/Quser-BOF*",".{0,1000}netero1010\/Quser\-BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF for quser.exe implementation using Windows API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/Quser-BOF","1","1","N/A","N/A","10","10","85","11","2023-03-22T17:07:02Z","2021-04-01T15:19:50Z","53142" +"*netero1010/SCCMVNC*",".{0,1000}netero1010\/SCCMVNC.{0,1000}","offensive_tool_keyword","SCCMVNC","A tool to modify SCCM remote control settings on the client machine - enabling remote control without permission prompts or notifications. This can be done without requiring access to SCCM server.","T1078 - T1562 - T1557","TA0005 - TA0003 - TA0008","N/A","N/A","Lateral Movement","https://github.com/netero1010/SCCMVNC","1","1","N/A","N/A","8","1","87","10","2024-10-20T14:29:43Z","2024-10-20T14:15:28Z","53143" +"*netero1010/ScheduleRunner*",".{0,1000}netero1010\/ScheduleRunner.{0,1000}","offensive_tool_keyword","ScheduleRunner","A C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operation","T1210 - T1570 - T1021 - T1550","TA0008","N/A","N/A","Persistence","https://github.com/netero1010/ScheduleRunner","1","1","N/A","N/A","9","4","336","46","2025-01-22T02:06:59Z","2021-10-12T15:27:32Z","53144" +"*netero1010/ServiceMove-BOF*",".{0,1000}netero1010\/ServiceMove\-BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","New Lateral Movement technique by abusing Windows Perception Simulation Service to achieve DLL hijacking code execution.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/ServiceMove-BOF","1","1","N/A","N/A","10","10","291","48","2022-02-23T07:17:38Z","2021-08-16T07:16:31Z","53145" +"*NetExec-main.zip*",".{0,1000}NetExec\-main\.zip.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","53151" +"*NetExec-main.zip*",".{0,1000}NetExec\-main\.zip.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","53152" +"*Net-GPPPassword.cs*",".{0,1000}Net\-GPPPassword\.cs.{0,1000}","offensive_tool_keyword","Net-GPPPassword",".NET implementation of Get-GPPPassword. Retrieves the plaintext password and other information for accounts pushed through Group Policy Preferences.","T1059.001 - T1552.007","TA0002 - TA0006","N/A","N/A","Credential Access","https://github.com/outflanknl/Net-GPPPassword","1","1","N/A","N/A","10","2","172","36","2019-12-18T10:14:32Z","2019-10-14T12:35:46Z","53153" +"*Net-GPPPassword.exe*",".{0,1000}Net\-GPPPassword\.exe.{0,1000}","offensive_tool_keyword","Net-GPPPassword",".NET implementation of Get-GPPPassword. Retrieves the plaintext password and other information for accounts pushed through Group Policy Preferences.","T1059.001 - T1552.007","TA0002 - TA0006","N/A","N/A","Credential Access","https://github.com/outflanknl/Net-GPPPassword","1","1","N/A","N/A","10","2","172","36","2019-12-18T10:14:32Z","2019-10-14T12:35:46Z","53154" +"*Net-GPPPassword_dotNET*",".{0,1000}Net\-GPPPassword_dotNET.{0,1000}","offensive_tool_keyword","Net-GPPPassword",".NET implementation of Get-GPPPassword. Retrieves the plaintext password and other information for accounts pushed through Group Policy Preferences.","T1059.001 - T1552.007","TA0002 - TA0006","N/A","N/A","Credential Access","https://github.com/outflanknl/Net-GPPPassword","1","1","N/A","N/A","10","2","172","36","2019-12-18T10:14:32Z","2019-10-14T12:35:46Z","53155" +"*Net-GPPPassword-master*",".{0,1000}Net\-GPPPassword\-master.{0,1000}","offensive_tool_keyword","Net-GPPPassword",".NET implementation of Get-GPPPassword. Retrieves the plaintext password and other information for accounts pushed through Group Policy Preferences.","T1059.001 - T1552.007","TA0002 - TA0006","N/A","N/A","Credential Access","https://github.com/outflanknl/Net-GPPPassword","1","1","N/A","N/A","10","2","172","36","2019-12-18T10:14:32Z","2019-10-14T12:35:46Z","53156" +"*nethunter-*.torrent*",".{0,1000}nethunter\-.{0,1000}\.torrent.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","53157" +"*nethunter-*.zip*",".{0,1000}nethunter\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","53158" +"*nethunter-*-oos-ten-kalifs-full.zip*",".{0,1000}nethunter\-.{0,1000}\-oos\-ten\-kalifs\-full\.zip.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","53159" +"*netlm_downgrade.*",".{0,1000}netlm_downgrade\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","53162" +"*NETLMv2_fmt_plug.*",".{0,1000}NETLMv2_fmt_plug\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53163" +"*NetLoader-master*",".{0,1000}NetLoader\-master.{0,1000}","offensive_tool_keyword","NetLoader","Loads any C# binary in memory - patching AMSI + ETW","T1055.012 - T1112 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Flangvik/NetLoader","1","1","N/A","N/A","10","9","820","147","2021-10-03T16:41:03Z","2020-05-05T15:20:16Z","53165" +"*netloggedonusers.*",".{0,1000}netloggedonusers\..{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","53166" +"*netlogon_##*",".{0,1000}netlogon_\#\#.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","53167" +"*NetNTLMtoSilverTicket.git*",".{0,1000}NetNTLMtoSilverTicket\.git.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","1","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","53169" +"*NetNTLMtoSilverTicket-master*",".{0,1000}NetNTLMtoSilverTicket\-master.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","1","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","53170" +"*netpass.exe*",".{0,1000}netpass\.exe.{0,1000}","offensive_tool_keyword","netpass","When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password.","T1081 - T1003 - T1555","TA0006 - TA0009","N/A","Kimsuky - XDSpy - TRAVELING SPIDER","Credential Access","https://www.nirsoft.net/utils/network_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53171" +"*netpass.zip*",".{0,1000}netpass\.zip.{0,1000}","offensive_tool_keyword","netpass","When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password.","T1081 - T1003 - T1555","TA0006 - TA0009","N/A","Kimsuky - XDSpy - TRAVELING SPIDER","Credential Access","https://www.nirsoft.net/utils/network_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53172" +"*netpass_x64.exe*",".{0,1000}netpass_x64\.exe.{0,1000}","offensive_tool_keyword","netpass","When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password.","T1081 - T1003 - T1555","TA0006 - TA0009","N/A","Kimsuky - XDSpy - TRAVELING SPIDER","Credential Access","https://www.nirsoft.net/utils/network_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53173" +"*netpass-x64.zip*",".{0,1000}netpass\-x64\.zip.{0,1000}","offensive_tool_keyword","netpass","When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password.","T1081 - T1003 - T1555","TA0006 - TA0009","N/A","Kimsuky - XDSpy - TRAVELING SPIDER","Credential Access","https://www.nirsoft.net/utils/network_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53174" +"*NetshHelperBeacon.exe*",".{0,1000}NetshHelperBeacon\.exe.{0,1000}","offensive_tool_keyword","NetshHelperBeacon","DLL to load from Windows NetShell. Will pop calc and execute shellcode.","T1055 - T1218","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/outflanknl/NetshHelperBeacon","1","1","N/A","N/A","10","2","179","36","2016-09-26T19:57:08Z","2016-09-26T12:52:02Z","53216" +"*netsniff-ng*",".{0,1000}netsniff\-ng.{0,1000}","offensive_tool_keyword","netsniff-ng","netsniff-ng is a high performance Linux network sniffer for packet inspection. It can be used for protocol analysis. reverse engineering or network debugging. The gain of performance is reached by 'zero-copy' mechanisms. so that the kernel does not need to copy packets from kernelspace to userspace.","T1040 - T1052 - T1065 - T1096 - T1102 - T1113 - T1114 - T1123 - T1127 - T1136 - T1143 - T1190 - T1200 - T1201 - T1219 - T1222 - T1496 - T1497 - T1557 - T1560 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0007 - TA0011","N/A","N/A","Sniffing & Spoofing","https://packages.debian.org/fr/sid/netsniff-ng","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","53218" +"*NetSPI/Powershell-Modules*",".{0,1000}NetSPI\/Powershell\-Modules.{0,1000}","offensive_tool_keyword","PowerUpSQL","NetSPI powershell modules to gather credentials","T1552.001 - T1555.004 - T1003","TA0006 - TA0009 - TA0010","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/NetSPI/Powershell-Modules","1","1","N/A","N/A","10","2","168","101","2019-06-06T15:54:47Z","2014-02-28T21:24:21Z","53219" +"*nettitude/ETWHash*",".{0,1000}nettitude\/ETWHash.{0,1000}","offensive_tool_keyword","ETWHash","C# POC to extract NetNTLMv1/v2 hashes from ETW provider","T1556.001","TA0009 ","N/A","N/A","Credential Access","https://github.com/nettitude/ETWHash","1","1","N/A","N/A","N/A","3","256","29","2023-05-10T06:45:06Z","2023-04-26T15:53:01Z","53236" +"*nettitude/MalSCCM*",".{0,1000}nettitude\/MalSCCM.{0,1000}","offensive_tool_keyword","MalSCCM","This tool allows you to abuse local or remote SCCM servers to deploy malicious applications to hosts they manage","T1072 - T1059.005 - T1090","TA0008 - TA0002 - TA0011","N/A","N/A","Exploitation tool","https://github.com/nettitude/MalSCCM","1","1","N/A","N/A","10","3","246","37","2023-09-28T17:29:50Z","2022-05-04T08:27:27Z","53237" +"*netuser_enum*",".{0,1000}netuser_enum.{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","53238" +"*netview.py*",".{0,1000}netview\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Sniffing & Spoofing","https://github.com/SecureAuthCorp/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","53239" +"*netview_enum*",".{0,1000}netview_enum.{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","53240" +"*network2john.lua*",".{0,1000}network2john\.lua.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53243" +"*NetworkMiner*",".{0,1000}NetworkMiner.{0,1000}","offensive_tool_keyword","NetworkMiner","A Network Forensic Analysis Tool (NFAT)","T1040 - T1052 - T1065 - T1096 - T1102 - T1113 - T1114 - T1123 - T1127 - T1136 - T1143 - T1190 - T1200 - T1201 - T1219 - T1222 - T1496 - T1497 - T1557 - T1560 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0007 - TA0011","N/A","N/A","Sniffing & Spoofing","http://www.netresec.com/?page=NetworkMiner","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53245" +"*NetworkServiceExploit.exe*",".{0,1000}NetworkServiceExploit\.exe.{0,1000}","offensive_tool_keyword","NetworkServiceExploit","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","NetworkServiceExploit","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","53246" +"*NetworkServiceExploit.exe*",".{0,1000}NetworkServiceExploit\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","NetworkServiceExploit","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","53247" +"*nevcorps5cvivjf6i2gm4uia7cxng5ploqny2rgrinctazjlnqr2yiyd.onion*",".{0,1000}nevcorps5cvivjf6i2gm4uia7cxng5ploqny2rgrinctazjlnqr2yiyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","53250" +"*NewAdminAccountCreation.ps1*",".{0,1000}NewAdminAccountCreation\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","53280" +"*New-ElevatedPersistenceOption*",".{0,1000}New\-ElevatedPersistenceOption.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Persistence.psm1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","53282" +"*New-GPOImmediateTask*",".{0,1000}New\-GPOImmediateTask.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","53284" +"*New-HoneyHash*",".{0,1000}New\-HoneyHash.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","New-HoneyHash.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","53285" +"*New-HoneyHash.ps1*",".{0,1000}New\-HoneyHash\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1086","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","53286" +"*New-InMemoryModule*",".{0,1000}New\-InMemoryModule.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-BypassUACTokenManipulation.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","53288" +"*New-UserPersistenceOption*",".{0,1000}New\-UserPersistenceOption.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Persistence.psm1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","53312" +"*New-WmiSession.ps1*",".{0,1000}New\-WmiSession\.ps1.{0,1000}","offensive_tool_keyword","Wmisploit","WmiSploit is a small set of PowerShell scripts that leverage the WMI service for post-exploitation use.","T1087 - T1059.001 - T1047","TA0003 - TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/secabstraction/WmiSploit","1","1","N/A","N/A","N/A","2","164","34","2015-08-28T23:56:00Z","2015-03-15T03:30:02Z","53316" +"*nextnet.exe*",".{0,1000}nextnet\.exe.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","53317" +"*ngrok-stable-linux-arm.zip*",".{0,1000}ngrok\-stable\-linux\-arm\.zip.{0,1000}","offensive_tool_keyword","BackHAck","Backdoor Generator with C2 server - Linux & Windows - FUD AV .py .exe","T1090 - T1095 - T1008","TA0011","N/A","N/A","C2","https://github.com/AngelSecurityTeam/BackHAck","1","1","#linux","N/A","10","10","108","34","2020-03-25T21:30:47Z","2020-03-14T19:00:36Z","53324" +"*NiceRAT-main.zip*",".{0,1000}NiceRAT\-main\.zip.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","1","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","53332" +"*nickvourd/COM-Hunter*",".{0,1000}nickvourd\/COM\-Hunter.{0,1000}","offensive_tool_keyword","COM-Hunter","COM-hunter is a COM Hijacking persistnce tool written in C#","T1122 - T1055.012","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/nickvourd/COM-Hunter","1","1","N/A","N/A","10","3","289","48","2025-03-11T04:49:55Z","2022-05-26T19:34:59Z","53334" +"*nickvourd/Supernova*",".{0,1000}nickvourd\/Supernova.{0,1000}","offensive_tool_keyword","Supernova","securely encrypt raw shellcodes","T1027 - T1055.004 - T1140","TA0002 - TA0005 - TA0042","N/A","N/A","Exploitation tool","https://github.com/nickvourd/Supernova","1","1","N/A","N/A","10","9","829","151","2025-04-18T19:15:22Z","2023-08-08T11:30:34Z","53335" +"*nickzer0/RagingRotator*",".{0,1000}nickzer0\/RagingRotator.{0,1000}","offensive_tool_keyword","RagingRotator","A tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways.","T1110 - T1027 - T1071 - T1090 - T1621","TA0006 - TA0005 - TA0001","N/A","N/A","Credential Access","https://github.com/nickzer0/RagingRotator","1","1","N/A","N/A","10","1","79","7","2024-06-06T19:31:34Z","2023-09-01T15:19:38Z","53336" +"*nicocha30/ligolo-ng*",".{0,1000}nicocha30\/ligolo\-ng.{0,1000}","offensive_tool_keyword","ligolo-ng","An advanced tunneling tool that uses TUN interfaces","T1572 - T1090","TA0011","N/A","Dispossessor - AvosLocker - LockBit","C2","https://github.com/nicocha30/ligolo-ng","1","1","N/A","N/A","10","10","3380","338","2025-04-17T07:48:36Z","2021-07-28T12:55:36Z","53337" +"*Nidhogg-0.1.zip*",".{0,1000}Nidhogg\-0\.1\.zip.{0,1000}","offensive_tool_keyword","Nidhogg","Nidhogg is an all-in-one simple to use rootkit for red teams.","T1055 - T1055.012 - T1574 - T1574.002 - T1056 - T1056.001 - T1027 - T1027.002 - T1112 - T1050 - T1106 - T1554 - T1554.002 - T1134 - T1134.001 - T1037 - T1037.001 - T1053 - T1053.005 - T1055.011 - T1098 - T1098.003 - T1070.001 - T1070.002 - T1070.003 - T1070.004 - T1070.006 - T1070.007 - T1070.008 - T1070.009 - T1083 - T1113 - T1113.001 - T1125 - T1125.001 - T1482 - T1489 - T1490 - T1497 - T1497.001 - T1497.002 - T1497.003 - T1498 - T1498.001 - T1498.002 - T1499 - T1499.001 - T1499.002 - T1499.003 - T1499.004 - T1499.005 - T1562 - T1562.001 - T1562.003 - T1562.004 - T1562.006 - T1562.007 - T1562.008 - T1562.009 - T1562.010 - T1562.011 - T1562.012","TA0005 - TA0003 - TA0004 - TA0006 - TA0009 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/Idov31/Nidhogg","1","1","N/A","N/A","10","10","1946","284","2025-04-19T14:28:47Z","2022-05-29T14:37:50Z","53380" +"*Nidhogg-0.2.zip*",".{0,1000}Nidhogg\-0\.2\.zip.{0,1000}","offensive_tool_keyword","Nidhogg","Nidhogg is an all-in-one simple to use rootkit for red teams.","T1055 - T1055.012 - T1574 - T1574.002 - T1056 - T1056.001 - T1027 - T1027.002 - T1112 - T1050 - T1106 - T1554 - T1554.002 - T1134 - T1134.001 - T1037 - T1037.001 - T1053 - T1053.005 - T1055.011 - T1098 - T1098.003 - T1070.001 - T1070.002 - T1070.003 - T1070.004 - T1070.006 - T1070.007 - T1070.008 - T1070.009 - T1083 - T1113 - T1113.001 - T1125 - T1125.001 - T1482 - T1489 - T1490 - T1497 - T1497.001 - T1497.002 - T1497.003 - T1498 - T1498.001 - T1498.002 - T1499 - T1499.001 - T1499.002 - T1499.003 - T1499.004 - T1499.005 - T1562 - T1562.001 - T1562.003 - T1562.004 - T1562.006 - T1562.007 - T1562.008 - T1562.009 - T1562.010 - T1562.011 - T1562.012","TA0005 - TA0003 - TA0004 - TA0006 - TA0009 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/Idov31/Nidhogg","1","1","N/A","N/A","10","10","1946","284","2025-04-19T14:28:47Z","2022-05-29T14:37:50Z","53381" +"*Nidhogg-0.3.zip*",".{0,1000}Nidhogg\-0\.3\.zip.{0,1000}","offensive_tool_keyword","Nidhogg","Nidhogg is an all-in-one simple to use rootkit for red teams.","T1055 - T1055.012 - T1574 - T1574.002 - T1056 - T1056.001 - T1027 - T1027.002 - T1112 - T1050 - T1106 - T1554 - T1554.002 - T1134 - T1134.001 - T1037 - T1037.001 - T1053 - T1053.005 - T1055.011 - T1098 - T1098.003 - T1070.001 - T1070.002 - T1070.003 - T1070.004 - T1070.006 - T1070.007 - T1070.008 - T1070.009 - T1083 - T1113 - T1113.001 - T1125 - T1125.001 - T1482 - T1489 - T1490 - T1497 - T1497.001 - T1497.002 - T1497.003 - T1498 - T1498.001 - T1498.002 - T1499 - T1499.001 - T1499.002 - T1499.003 - T1499.004 - T1499.005 - T1562 - T1562.001 - T1562.003 - T1562.004 - T1562.006 - T1562.007 - T1562.008 - T1562.009 - T1562.010 - T1562.011 - T1562.012","TA0005 - TA0003 - TA0004 - TA0006 - TA0009 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/Idov31/Nidhogg","1","1","N/A","N/A","10","10","1946","284","2025-04-19T14:28:47Z","2022-05-29T14:37:50Z","53382" +"*Nidhogg-0.4.zip*",".{0,1000}Nidhogg\-0\.4\.zip.{0,1000}","offensive_tool_keyword","Nidhogg","Nidhogg is an all-in-one simple to use rootkit for red teams.","T1055 - T1055.012 - T1574 - T1574.002 - T1056 - T1056.001 - T1027 - T1027.002 - T1112 - T1050 - T1106 - T1554 - T1554.002 - T1134 - T1134.001 - T1037 - T1037.001 - T1053 - T1053.005 - T1055.011 - T1098 - T1098.003 - T1070.001 - T1070.002 - T1070.003 - T1070.004 - T1070.006 - T1070.007 - T1070.008 - T1070.009 - T1083 - T1113 - T1113.001 - T1125 - T1125.001 - T1482 - T1489 - T1490 - T1497 - T1497.001 - T1497.002 - T1497.003 - T1498 - T1498.001 - T1498.002 - T1499 - T1499.001 - T1499.002 - T1499.003 - T1499.004 - T1499.005 - T1562 - T1562.001 - T1562.003 - T1562.004 - T1562.006 - T1562.007 - T1562.008 - T1562.009 - T1562.010 - T1562.011 - T1562.012","TA0005 - TA0003 - TA0004 - TA0006 - TA0009 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/Idov31/Nidhogg","1","1","N/A","N/A","10","10","1946","284","2025-04-19T14:28:47Z","2022-05-29T14:37:50Z","53383" +"*Nidhogg-0.5.zip*",".{0,1000}Nidhogg\-0\.5\.zip.{0,1000}","offensive_tool_keyword","Nidhogg","Nidhogg is an all-in-one simple to use rootkit for red teams.","T1055 - T1055.012 - T1574 - T1574.002 - T1056 - T1056.001 - T1027 - T1027.002 - T1112 - T1050 - T1106 - T1554 - T1554.002 - T1134 - T1134.001 - T1037 - T1037.001 - T1053 - T1053.005 - T1055.011 - T1098 - T1098.003 - T1070.001 - T1070.002 - T1070.003 - T1070.004 - T1070.006 - T1070.007 - T1070.008 - T1070.009 - T1083 - T1113 - T1113.001 - T1125 - T1125.001 - T1482 - T1489 - T1490 - T1497 - T1497.001 - T1497.002 - T1497.003 - T1498 - T1498.001 - T1498.002 - T1499 - T1499.001 - T1499.002 - T1499.003 - T1499.004 - T1499.005 - T1562 - T1562.001 - T1562.003 - T1562.004 - T1562.006 - T1562.007 - T1562.008 - T1562.009 - T1562.010 - T1562.011 - T1562.012","TA0005 - TA0003 - TA0004 - TA0006 - TA0009 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/Idov31/Nidhogg","1","1","N/A","N/A","10","10","1946","284","2025-04-19T14:28:47Z","2022-05-29T14:37:50Z","53384" +"*Nidhogg-master*",".{0,1000}Nidhogg\-master.{0,1000}","offensive_tool_keyword","Nidhogg","Nidhogg is an all-in-one simple to use rootkit for red teams.","T1055 - T1055.012 - T1574 - T1574.002 - T1056 - T1056.001 - T1027 - T1027.002 - T1112 - T1050 - T1106 - T1554 - T1554.002 - T1134 - T1134.001 - T1037 - T1037.001 - T1053 - T1053.005 - T1055.011 - T1098 - T1098.003 - T1070.001 - T1070.002 - T1070.003 - T1070.004 - T1070.006 - T1070.007 - T1070.008 - T1070.009 - T1083 - T1113 - T1113.001 - T1125 - T1125.001 - T1482 - T1489 - T1490 - T1497 - T1497.001 - T1497.002 - T1497.003 - T1498 - T1498.001 - T1498.002 - T1499 - T1499.001 - T1499.002 - T1499.003 - T1499.004 - T1499.005 - T1562 - T1562.001 - T1562.003 - T1562.004 - T1562.006 - T1562.007 - T1562.008 - T1562.009 - T1562.010 - T1562.011 - T1562.012","TA0005 - TA0003 - TA0004 - TA0006 - TA0009 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/Idov31/Nidhogg","1","1","N/A","N/A","10","10","1946","284","2025-04-19T14:28:47Z","2022-05-29T14:37:50Z","53387" +"*Nightmangle-master*",".{0,1000}Nightmangle\-master.{0,1000}","offensive_tool_keyword","Nightmangle","ightmangle is post-exploitation Telegram Command and Control (C2/C&C) Agent","T1105 - T1132 - T1071.001","TA0011 - TA0009 - TA0002","N/A","N/A","C2","https://github.com/1N73LL1G3NC3x/Nightmangle","1","1","N/A","N/A","10","10","156","19","2023-09-26T19:21:31Z","2023-09-26T18:25:23Z","53390" +"*nikto/program*",".{0,1000}nikto\/program.{0,1000}","offensive_tool_keyword","nikto","Nikto web server scanner","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/sullo/nikto","1","1","#linux","N/A","N/A","10","9184","1306","2025-02-22T14:30:28Z","2012-11-24T04:24:29Z","53392" +"*nil0x42/phpsploit*",".{0,1000}nil0x42\/phpsploit.{0,1000}","offensive_tool_keyword","PhpSploit","Full-featured C2 framework which silently persists on webserver via evil PHP oneliner","T1505.003 - T1505 - T1059 - T1219 - T1547","TA0003 - TA0011 - TA0005","N/A","N/A","C2","https://github.com/nil0x42/phpsploit","1","1","N/A","N/A","10","10","2331","453","2024-05-06T13:49:14Z","2014-05-21T19:43:03Z","53393" +"*nimbo_main*",".{0,1000}nimbo_main.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","53397" +"*nimbo_prompt_color*",".{0,1000}nimbo_prompt_color.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","53398" +"*nimbo_root*",".{0,1000}nimbo_root.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","53399" +"*Nimbo-C2*",".{0,1000}Nimbo\-C2.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","53401" +"*Nimbo-C2.*",".{0,1000}Nimbo\-C2\..{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","53402" +"*nimbo-dependencies*",".{0,1000}nimbo\-dependencies.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","53403" +"*nimbuspwn.py*",".{0,1000}nimbuspwn\.py.{0,1000}","offensive_tool_keyword","POC","This is a PoC for Nimbuspwn a Linux privilege escalation issue identified by Microsoft as originally described in https://www.microsoft.com/security/blog/2022/04/26/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn/ (CVE-2022-29799 and CVE-2022-29800)","T1543","TA0003","N/A","N/A","Exploitation tool","https://github.com/Immersive-Labs-Sec/nimbuspwn","1","1","#linux","N/A","N/A","1","22","7","2022-05-05T10:02:27Z","2022-04-27T13:04:33Z","53404" +"*nimcrypt.nim*",".{0,1000}nimcrypt\.nim.{0,1000}","offensive_tool_keyword","Nimcrypt2",".NET PE & Raw Shellcode Packer/Loader Written in Nim","T1027 - T1202 - T1059.005 - T1105 - T1045","TA0005 - TA0011 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/icyguider/Nimcrypt2","1","1","N/A","N/A","N/A","8","771","124","2023-01-20T22:07:15Z","2022-02-23T15:43:16Z","53407" +"*NimExec.exe*",".{0,1000}NimExec\.exe.{0,1000}","offensive_tool_keyword","NimExec","Fileless Command Execution for Lateral Movement in Nim","T1021.006 - T1059.005 - T1564.001","TA0008 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/frkngksl/NimExec","1","1","N/A","N/A","N/A","4","372","38","2023-12-12T06:59:59Z","2023-04-21T19:46:53Z","53409" +"*NimExec-master*",".{0,1000}NimExec\-master.{0,1000}","offensive_tool_keyword","NimExec","Fileless Command Execution for Lateral Movement in Nim","T1021.006 - T1059.005 - T1564.001","TA0008 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/frkngksl/NimExec","1","1","N/A","N/A","N/A","4","372","38","2023-12-12T06:59:59Z","2023-04-21T19:46:53Z","53410" +"*nimplant-*",".{0,1000}nimplant\-.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","53413" +"*NimPlant*.tar.gz*",".{0,1000}NimPlant.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","53414" +"*NimPlant*.zip*",".{0,1000}NimPlant.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","53415" +"*nimplant.db*",".{0,1000}nimplant\.db.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","53416" +"*NimPlant.dll*",".{0,1000}NimPlant\.dll.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","53417" +"*NimPlant.nim*",".{0,1000}NimPlant\.nim.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","53418" +"*NimPlant.nimble*",".{0,1000}NimPlant\.nimble.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","53419" +"*NimPlant.py*",".{0,1000}NimPlant\.py.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","53420" +"*nimplantPrint*",".{0,1000}nimplantPrint.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","53421" +"*nimplants-*.js*",".{0,1000}nimplants\-.{0,1000}\.js.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","53422" +"*nimplants.html*",".{0,1000}nimplants\.html.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","53423" +"*NimShellCodeLoader*",".{0,1000}NimShellCodeLoader.{0,1000}","offensive_tool_keyword","C2 related tools","A shellcode loader written using nim","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/aeverj/NimShellCodeLoader","1","1","N/A","N/A","10","10","656","121","2025-02-18T14:31:45Z","2021-01-19T15:57:01Z","53426" +"*ninjac2*",".{0,1000}ninjac2.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","53429" +"*nirsoft.net/utils/browsing_history_view.html*",".{0,1000}nirsoft\.net\/utils\/browsing_history_view\.html.{0,1000}","offensive_tool_keyword","BrowsingHistoryView","BrowsingHistoryView is a utility that reads the history data of different Web browsers","T1217 - T1070 - T1113","TA0009 - TA0005 - TA0007","N/A","GOBLIN PANDA","Discovery","https://www.nirsoft.net/utils/browsing_history_view.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53436" +"*nishang.exe*",".{0,1000}nishang\.exe.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","53437" +"*nishang.ps1*",".{0,1000}nishang\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","53438" +"*nishang.psm1*",".{0,1000}nishang\.psm1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","53439" +"*nishang.psm1*",".{0,1000}nishang\.psm1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","53441" +"*nishang-0-3-4.html*",".{0,1000}nishang\-0\-3\-4\.html.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","53442" +"*Nishang-all-in-one*",".{0,1000}Nishang\-all\-in\-one.{0,1000}","offensive_tool_keyword","AmsiBypass","bypassing Anti-Malware Scanning Interface (AMSI) features","T1548.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/S3cur3Th1sSh1t/Amsi-Bypass-Powershell","1","1","N/A","N/A","10","10","1890","311","2024-11-28T10:31:15Z","2019-05-14T06:09:25Z","53443" +"*NixImports.csproj*",".{0,1000}NixImports\.csproj.{0,1000}","offensive_tool_keyword","NixImports","A .NET malware loader using API-Hashing to evade static analysis","T1055.012 - T1562.001 - T1140","TA0005 - TA0003 - TA0040","N/A","N/A","Defense Evasion","https://github.com/dr4k0nia/NixImports","1","1","N/A","N/A","N/A","3","207","23","2023-05-30T14:14:21Z","2023-05-22T18:32:01Z","53446" +"*NixImports.exe*",".{0,1000}NixImports\.exe.{0,1000}","offensive_tool_keyword","NixImports","A .NET malware loader using API-Hashing to evade static analysis","T1055.012 - T1562.001 - T1140","TA0005 - TA0003 - TA0040","N/A","N/A","Defense Evasion","https://github.com/dr4k0nia/NixImports","1","1","N/A","N/A","N/A","3","207","23","2023-05-30T14:14:21Z","2023-05-22T18:32:01Z","53447" +"*NixImports.git*",".{0,1000}NixImports\.git.{0,1000}","offensive_tool_keyword","NixImports","A .NET malware loader using API-Hashing to evade static analysis","T1055.012 - T1562.001 - T1140","TA0005 - TA0003 - TA0040","N/A","N/A","Defense Evasion","https://github.com/dr4k0nia/NixImports","1","1","N/A","N/A","N/A","3","207","23","2023-05-30T14:14:21Z","2023-05-22T18:32:01Z","53448" +"*NixImports.sln*",".{0,1000}NixImports\.sln.{0,1000}","offensive_tool_keyword","NixImports","A .NET malware loader using API-Hashing to evade static analysis","T1055.012 - T1562.001 - T1140","TA0005 - TA0003 - TA0040","N/A","N/A","Defense Evasion","https://github.com/dr4k0nia/NixImports","1","1","N/A","N/A","N/A","3","207","23","2023-05-30T14:14:21Z","2023-05-22T18:32:01Z","53449" +"*nixpal/shellsilo*",".{0,1000}nixpal\/shellsilo.{0,1000}","offensive_tool_keyword","shellsilo","cutting-edge tool that translates C syntax into syscall assembly and its corresponding shellcode","T1500 - T1588.002 - T1587.001 - T1546.015","TA0005 - TA0042","N/A","N/A","Resource Development","https://github.com/nixpal/shellsilo","1","1","N/A","N/A","6","2","132","13","2024-11-08T03:16:57Z","2024-03-08T02:04:04Z","53450" +"*nmap/ncrack*",".{0,1000}nmap\/ncrack.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","1","N/A","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","53477" +"*nmap_smb_scan_custom_*.txt*",".{0,1000}nmap_smb_scan_custom_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","53480" +"*nmapAnswerMachine.py*",".{0,1000}nmapAnswerMachine\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","53481" +"*no_session_payload.rb*",".{0,1000}no_session_payload\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","53491" +"*NoApiUser.exe*",".{0,1000}NoApiUser\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Use windows api to add users which can be used when net is unavailable","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/lengjibo/NetUser","1","1","N/A","N/A","10","10","420","90","2021-09-29T14:22:09Z","2020-01-09T08:33:27Z","53493" +"*No-Consolation.cna*",".{0,1000}No\-Consolation\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a Beacon Object File (BOF) that executes unmanaged PEs inline and retrieves their output without allocating a console (i.e spawning conhost.exe)","T1055 - T1129","TA0005 - TA0003","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Defense Evasion","https://github.com/fortra/No-Consolation","1","1","N/A","N/A","9","6","593","68","2024-10-23T16:25:21Z","2023-11-06T22:01:42Z","53498" +"*NoConsolation.x64.o*",".{0,1000}NoConsolation\.x64\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a Beacon Object File (BOF) that executes unmanaged PEs inline and retrieves their output without allocating a console (i.e spawning conhost.exe)","T1055 - T1129","TA0005 - TA0003","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Defense Evasion","https://github.com/fortra/No-Consolation","1","1","N/A","N/A","9","6","593","68","2024-10-23T16:25:21Z","2023-11-06T22:01:42Z","53499" +"*NoConsolation.x86.o*",".{0,1000}NoConsolation\.x86\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a Beacon Object File (BOF) that executes unmanaged PEs inline and retrieves their output without allocating a console (i.e spawning conhost.exe)","T1055 - T1129","TA0005 - TA0003","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Defense Evasion","https://github.com/fortra/No-Consolation","1","1","N/A","N/A","9","6","593","68","2024-10-23T16:25:21Z","2023-11-06T22:01:42Z","53500" +"*No-Consolation-main*",".{0,1000}No\-Consolation\-main.{0,1000}","offensive_tool_keyword","cobaltstrike","This is a Beacon Object File (BOF) that executes unmanaged PEs inline and retrieves their output without allocating a console (i.e spawning conhost.exe)","T1055 - T1129","TA0005 - TA0003","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Defense Evasion","https://github.com/fortra/No-Consolation","1","1","N/A","N/A","9","6","593","68","2024-10-23T16:25:21Z","2023-11-06T22:01:42Z","53501" +"*no-defender/dllmain.cpp*",".{0,1000}no\-defender\/dllmain\.cpp.{0,1000}","offensive_tool_keyword","no_defender","disable windows defender. (through the WSC api)","T1089","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/es3n1n/no-defender","1","1","N/A","N/A","10","10","1907","13","2024-06-08T01:29:18Z","2024-05-23T05:18:38Z","53505" +"*noescapemsqxvizdxyl7f7rmg5cdjwp33pg2wpmiaaibilb4btwzttad.onion*",".{0,1000}noescapemsqxvizdxyl7f7rmg5cdjwp33pg2wpmiaaibilb4btwzttad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","53509" +"*noescaperjh3gg6oy7rck57fiefyuzmj7kmvojxgvlmwd5pdzizrb7ad.onion*",".{0,1000}noescaperjh3gg6oy7rck57fiefyuzmj7kmvojxgvlmwd5pdzizrb7ad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","53510" +"*NoFilter-main.zip*",".{0,1000}NoFilter\-main\.zip.{0,1000}","offensive_tool_keyword","NoFilter","Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.","T1548 - T1548.002 - T1055 - T1055.004","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/deepinstinct/NoFilter","1","1","N/A","N/A","9","3","298","48","2024-10-29T07:30:35Z","2023-07-30T09:25:38Z","53513" +"*noname2j6zkgnt7ftxsjju5tfd3s45s4i3egq5bqtl72kgum4ldc6qyd.onion*",".{0,1000}noname2j6zkgnt7ftxsjju5tfd3s45s4i3egq5bqtl72kgum4ldc6qyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","53516" +"*nonamef5njcxkghbjequlibwe5d3t3li5tmyqdyarnrsryopvku76wqd.onion*",".{0,1000}nonamef5njcxkghbjequlibwe5d3t3li5tmyqdyarnrsryopvku76wqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","53517" +"*nop_shellcode.bin*",".{0,1000}nop_shellcode\.bin.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","53521" +"*nopcorn/DuckDuckC2*",".{0,1000}nopcorn\/DuckDuckC2.{0,1000}","offensive_tool_keyword","DuckDuckC2","A proof-of-concept C2 channel through DuckDuckGo's image proxy service","T1071.001 - T1090.003","TA0011 - TA0042","N/A","N/A","C2","https://github.com/nopcorn/DuckDuckC2","1","1","N/A","N/A","10","10","74","6","2023-11-12T10:24:59Z","2023-09-23T20:00:09Z","53544" +"*NoPowerShell.cna*",".{0,1000}NoPowerShell\.cna.{0,1000}","offensive_tool_keyword","C2 related tools","PowerShell rebuilt in C# for Red Teaming purposes","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","53545" +"*NoPowerShell.cna*",".{0,1000}NoPowerShell\.cna.{0,1000}","offensive_tool_keyword","nopowershell","NoPowerShell is a tool implemented in C# which supports executing PowerShell-like commands while remaining invisible to any PowerShell logging mechanisms. This .NET Framework 2 compatible binary can be loaded in Cobalt Strike to execute commands in-memory. No System.Management.Automation.dll is used. only native .NET libraries. An alternative usecase for NoPowerShell is to launch it as a DLL via rundll32.exe: rundll32 NoPowerShell.dll.main.","T1059 - T1086 - T1500 - T1564 - T1127 - T1027","TA0002 - TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","53546" +"*NoPowerShell.dll*",".{0,1000}NoPowerShell\.dll.{0,1000}","offensive_tool_keyword","C2 related tools","PowerShell rebuilt in C# for Red Teaming purposes","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","53550" +"*NoPowerShell.dll*",".{0,1000}NoPowerShell\.dll.{0,1000}","offensive_tool_keyword","nopowershell","NoPowerShell is a tool implemented in C# which supports executing PowerShell-like commands while remaining invisible to any PowerShell logging mechanisms. This .NET Framework 2 compatible binary can be loaded in Cobalt Strike to execute commands in-memory. No System.Management.Automation.dll is used. only native .NET libraries. An alternative usecase for NoPowerShell is to launch it as a DLL via rundll32.exe: rundll32 NoPowerShell.dll.main.","T1059 - T1086 - T1500 - T1564 - T1127 - T1027","TA0002 - TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","53551" +"*nopowershell.exe*",".{0,1000}nopowershell\.exe.{0,1000}","offensive_tool_keyword","C2 related tools","PowerShell rebuilt in C# for Red Teaming purposes","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","53552" +"*NoPowerShell.exe*",".{0,1000}NoPowerShell\.exe.{0,1000}","offensive_tool_keyword","nopowershell","NoPowerShell is a tool implemented in C# which supports executing PowerShell-like commands while remaining invisible to any PowerShell logging mechanisms. This .NET Framework 2 compatible binary can be loaded in Cobalt Strike to execute commands in-memory. No System.Management.Automation.dll is used. only native .NET libraries. An alternative usecase for NoPowerShell is to launch it as a DLL via rundll32.exe: rundll32 NoPowerShell.dll.main.","T1059 - T1086 - T1500 - T1564 - T1127 - T1027","TA0002 - TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","53553" +"*NoPowerShell.sln*",".{0,1000}NoPowerShell\.sln.{0,1000}","offensive_tool_keyword","nopowershell","NoPowerShell is a tool implemented in C# which supports executing PowerShell-like commands while remaining invisible to any PowerShell logging mechanisms. This .NET Framework 2 compatible binary can be loaded in Cobalt Strike to execute commands in-memory. No System.Management.Automation.dll is used. only native .NET libraries. An alternative usecase for NoPowerShell is to launch it as a DLL via rundll32.exe: rundll32 NoPowerShell.dll.main.","T1059 - T1086 - T1500 - T1564 - T1127 - T1027","TA0002 - TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","53554" +"*NoPowerShell/*.cs*",".{0,1000}NoPowerShell\/.{0,1000}\.cs.{0,1000}","offensive_tool_keyword","C2 related tools","PowerShell rebuilt in C# for Red Teaming purposes","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","53555" +"*NoPowerShell_trunk.zip*",".{0,1000}NoPowerShell_trunk\.zip.{0,1000}","offensive_tool_keyword","nopowershell","NoPowerShell is a tool implemented in C# which supports executing PowerShell-like commands while remaining invisible to any PowerShell logging mechanisms. This .NET Framework 2 compatible binary can be loaded in Cobalt Strike to execute commands in-memory. No System.Management.Automation.dll is used. only native .NET libraries. An alternative usecase for NoPowerShell is to launch it as a DLL via rundll32.exe: rundll32 NoPowerShell.dll.main.","T1059 - T1086 - T1500 - T1564 - T1127 - T1027","TA0002 - TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","53556" +"*NoPowerShell32.dll*",".{0,1000}NoPowerShell32\.dll.{0,1000}","offensive_tool_keyword","nopowershell","NoPowerShell is a tool implemented in C# which supports executing PowerShell-like commands while remaining invisible to any PowerShell logging mechanisms. This .NET Framework 2 compatible binary can be loaded in Cobalt Strike to execute commands in-memory. No System.Management.Automation.dll is used. only native .NET libraries. An alternative usecase for NoPowerShell is to launch it as a DLL via rundll32.exe: rundll32 NoPowerShell.dll.main.","T1059 - T1086 - T1500 - T1564 - T1127 - T1027","TA0002 - TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","53557" +"*NoPowerShell64.dll*",".{0,1000}NoPowerShell64\.dll.{0,1000}","offensive_tool_keyword","nopowershell","NoPowerShell is a tool implemented in C# which supports executing PowerShell-like commands while remaining invisible to any PowerShell logging mechanisms. This .NET Framework 2 compatible binary can be loaded in Cobalt Strike to execute commands in-memory. No System.Management.Automation.dll is used. only native .NET libraries. An alternative usecase for NoPowerShell is to launch it as a DLL via rundll32.exe: rundll32 NoPowerShell.dll.main.","T1059 - T1086 - T1500 - T1564 - T1127 - T1027","TA0002 - TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/bitsadmin/nopowershell","1","1","N/A","N/A","10","10","977","138","2025-04-11T09:25:41Z","2018-11-28T21:07:51Z","53558" +"*normal/randomized.profile*",".{0,1000}normal\/randomized\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","53561" +"*noseyparker-cli*",".{0,1000}noseyparker\-cli.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","1","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","53566" +"*noseyparker-main*",".{0,1000}noseyparker\-main.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","1","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","53567" +"*noseyparker-v*-universal-macos*",".{0,1000}noseyparker\-v.{0,1000}\-universal\-macos.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","1","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","53568" +"*noseyparker-v*-x86_64-unknown-linux-gnu*",".{0,1000}noseyparker\-v.{0,1000}\-x86_64\-unknown\-linux\-gnu.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","1","#linux","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","53569" +"*Nosql-Exploitation-Framework*",".{0,1000}Nosql\-Exploitation\-Framework.{0,1000}","offensive_tool_keyword","Nosql-Exploitation-Framework","A FrameWork For NoSQL Scanning and Exploitation Framework","T1210 - T1211 - T1021 - T1059","TA0002 - TA0011 - TA0003","N/A","N/A","Framework","https://github.com/torque59/Nosql-Exploitation-Framework","1","1","N/A","N/A","N/A","7","601","146","2024-12-06T14:24:45Z","2013-12-26T17:46:11Z","53570" +"*notdodo/LocalAdminSharp*",".{0,1000}notdodo\/LocalAdminSharp.{0,1000}","offensive_tool_keyword","LocalAdminSharp",".NET executable to use when dealing with privilege escalation on Windows to gain local administrator access","T1055.011 - T1068 - T1548.002 - T1548.003 - T1548.004","TA0004","N/A","N/A","Privilege Escalation","https://github.com/notdodo/LocalAdminSharp","1","1","N/A","N/A","10","2","157","17","2022-11-01T17:45:43Z","2022-01-01T10:35:09Z","53573" +"*Notselwyn/CVE-2024-1086*",".{0,1000}Notselwyn\/CVE\-2024\-1086.{0,1000}","offensive_tool_keyword","POC","local privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6","T1068 - T1548.002","TA0004","N/A","N/A","Privilege Escalation","https://github.com/Notselwyn/CVE-2024-1086","1","1","#linux","CVE-2024-1086 POC","10","10","2357","314","2024-04-17T16:09:54Z","2024-03-20T21:16:41Z","53580" +"*Notselwyn/netkit*",".{0,1000}Notselwyn\/netkit.{0,1000}","offensive_tool_keyword","netkit","Netkit is a purposefully small rootkit which can be used by clients over network to maintain a sneaky foothold into a device.","T1547 - T1021 - T1071 - T1562.001 - T1055 - T1041 - T1105","TA0003 - TA0005 - TA0002 - TA0007 - TA0009 - TA0040","N/A","N/A","Defense Evasion","https://github.com/Notselwyn/netkit","1","1","N/A","N/A","10","1","30","7","2024-03-27T19:07:03Z","2023-07-19T00:00:45Z","53581" +"*notsoshant/DCSyncer*",".{0,1000}notsoshant\/DCSyncer.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","1","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","53582" +"*NovaLdr-main*",".{0,1000}NovaLdr\-main.{0,1000}","offensive_tool_keyword","NovaLdr","NovaLdr is a Threadless Module Stomping written in Rust designed as a learning project while exploring the world of malware development. It uses advanced techniques like indirect syscalls and string encryption to achieve its functionalities","T1027.001 - T1055.012 - T1112 - T1574.002 - T1055 - T1056.002 - T1027.002 - T1070.004 - T1129","TA0004 - TA0005 - TA0040 - TA0011","N/A","N/A","Defense Evasion","https://github.com/BlackSnufkin/NovaLdr","1","1","N/A","N/A","10","3","242","40","2024-06-29T10:34:48Z","2023-10-19T07:54:39Z","53584" +"*novelbfh.zip*",".{0,1000}novelbfh\.zip.{0,1000}","offensive_tool_keyword","novelbfh","Brute force Novell hacking tool -- Circa 1993","T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/classic_hacking_tools","1","1","N/A","N/A","N/A","1","4","1","2024-06-27T09:35:42Z","2023-04-16T01:49:12Z","53586" +"*npkoxkuygikbkpuf5yxte66um727wmdo2jtpg2djhb2e224i4r25v7ad.onion*",".{0,1000}npkoxkuygikbkpuf5yxte66um727wmdo2jtpg2djhb2e224i4r25v7ad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","53594" +"*nps_payload*",".{0,1000}nps_payload.{0,1000}","offensive_tool_keyword","nps_payload","This script will generate payloads for basic intrusion detection avoidance. It utilizes publicly demonstrated techniques from several different sources.","T1059.007 - T1218.001 - T1027.002","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/trustedsec/nps_payload","1","1","N/A","N/A","N/A","5","442","123","2023-11-30T09:24:13Z","2017-07-23T17:01:19Z","53604" +"*nps_payload.py*",".{0,1000}nps_payload\.py.{0,1000}","offensive_tool_keyword","nps_payload","This script will generate payloads for basic intrusion detection avoidance","T1027 - T1027.005 - T1055 - T1211","TA0005 - TA0004","N/A","N/A","Exploitation tool","https://github.com/trustedsec/nps_payload","1","1","N/A","N/A","9","5","442","123","2023-11-30T09:24:13Z","2017-07-23T17:01:19Z","53605" +"*nps_payload-master*",".{0,1000}nps_payload\-master.{0,1000}","offensive_tool_keyword","nps_payload","This script will generate payloads for basic intrusion detection avoidance","T1027 - T1027.005 - T1055 - T1211","TA0005 - TA0004","N/A","N/A","Exploitation tool","https://github.com/trustedsec/nps_payload","1","1","N/A","N/A","9","5","442","123","2023-11-30T09:24:13Z","2017-07-23T17:01:19Z","53606" +"*NSAKEY/nsa-rules*",".{0,1000}NSAKEY\/nsa\-rules.{0,1000}","offensive_tool_keyword","nsa-rules","Password cracking rules and masks for hashcat that I generated from cracked passwords.","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/NSAKEY/nsa-rules","1","1","N/A","N/A","10","6","547","125","2017-01-03T11:53:25Z","2016-02-15T20:49:32Z","53610" +"*nsa-rules-master*",".{0,1000}nsa\-rules\-master.{0,1000}","offensive_tool_keyword","nsa-rules","Password cracking rules and masks for hashcat that I generated from cracked passwords.","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/NSAKEY/nsa-rules","1","1","N/A","N/A","10","6","547","125","2017-01-03T11:53:25Z","2016-02-15T20:49:32Z","53611" +"*nselib/data/passwords.lst*",".{0,1000}nselib\/data\/passwords\.lst.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","53616" +"*NS-Sp4ce/CVE-2021-21972*",".{0,1000}NS\-Sp4ce\/CVE\-2021\-21972.{0,1000}","offensive_tool_keyword","POC","CVE-2021-21972 POC exploitation","T1190 - T1059.001 - T1040","TA0001 - TA0003 - TA0009","N/A","Dispossessor","Exploitation tool","https://github.com/NS-Sp4ce/CVE-2021-21972","1","1","N/A","N/A","7","5","491","146","2023-06-08T04:01:33Z","2021-02-24T11:14:58Z","53619" +"*ntcreatethread.x64*",".{0,1000}ntcreatethread\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","53622" +"*ntcreatethread.x86*",".{0,1000}ntcreatethread\.x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","53623" +"*ntdissector-main*",".{0,1000}ntdissector\-main.{0,1000}","offensive_tool_keyword","ntdissector","Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.","T1003.003","TA0006 ","N/A","N/A","Credential Access","https://github.com/synacktiv/ntdissector","1","1","N/A","N/A","9","2","139","17","2024-08-16T14:18:35Z","2023-09-05T12:13:47Z","53626" +"*Ntdll_SusProcess.*",".{0,1000}Ntdll_SusProcess\..{0,1000}","offensive_tool_keyword","ntdlll-unhooking-collection","unhooking ntdll from disk - from KnownDlls - from suspended process - from remote server (fileless)","T1055 - T1055.001 - T1070 - T1070.004 - T1101 - T1574 - T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/ntdlll-unhooking-collection","1","1","N/A","N/A","9","2","188","38","2023-08-02T02:26:33Z","2023-02-07T16:54:15Z","53627" +"*NTDLLReflection-main*",".{0,1000}NTDLLReflection\-main.{0,1000}","offensive_tool_keyword","NTDLLReflection","Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll and trigger exported APIs from the export table","T1055.012 - T1574.002 - T1027.001 - T1218.011","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/NTDLLReflection","1","1","N/A","N/A","9","3","293","45","2023-08-02T02:21:43Z","2023-02-03T17:12:33Z","53628" +"*NtdllUnpatcher.cpp*",".{0,1000}NtdllUnpatcher\.cpp.{0,1000}","offensive_tool_keyword","NtdllUnpatcher","code for EDR bypassing","T1070.004 - T1055.001 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Signal-Labs/NtdllUnpatcher","1","1","N/A","N/A","10","2","150","33","2019-03-07T11:10:40Z","2019-03-07T10:20:19Z","53629" +"*NtdllUnpatcher.dll*",".{0,1000}NtdllUnpatcher\.dll.{0,1000}","offensive_tool_keyword","NtdllUnpatcher","code for EDR bypassing","T1070.004 - T1055.001 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Signal-Labs/NtdllUnpatcher","1","1","N/A","N/A","10","2","150","33","2019-03-07T11:10:40Z","2019-03-07T10:20:19Z","53630" +"*NtdllUnpatcher.lib*",".{0,1000}NtdllUnpatcher\.lib.{0,1000}","offensive_tool_keyword","NtdllUnpatcher","code for EDR bypassing","T1070.004 - T1055.001 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Signal-Labs/NtdllUnpatcher","1","1","N/A","N/A","10","2","150","33","2019-03-07T11:10:40Z","2019-03-07T10:20:19Z","53631" +"*NtdllUnpatcher.log*",".{0,1000}NtdllUnpatcher\.log.{0,1000}","offensive_tool_keyword","NtdllUnpatcher","code for EDR bypassing","T1070.004 - T1055.001 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Signal-Labs/NtdllUnpatcher","1","1","#logfile","N/A","10","2","150","33","2019-03-07T11:10:40Z","2019-03-07T10:20:19Z","53632" +"*NtdllUnpatcher.obj*",".{0,1000}NtdllUnpatcher\.obj.{0,1000}","offensive_tool_keyword","NtdllUnpatcher","code for EDR bypassing","T1070.004 - T1055.001 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Signal-Labs/NtdllUnpatcher","1","1","N/A","N/A","10","2","150","33","2019-03-07T11:10:40Z","2019-03-07T10:20:19Z","53633" +"*NtdllUnpatcher.sln*",".{0,1000}NtdllUnpatcher\.sln.{0,1000}","offensive_tool_keyword","NtdllUnpatcher","code for EDR bypassing","T1070.004 - T1055.001 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Signal-Labs/NtdllUnpatcher","1","1","N/A","N/A","10","2","150","33","2019-03-07T11:10:40Z","2019-03-07T10:20:19Z","53634" +"*NtdllUnpatcher_Injector*",".{0,1000}NtdllUnpatcher_Injector.{0,1000}","offensive_tool_keyword","NtdllUnpatcher","code for EDR bypassing","T1070.004 - T1055.001 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Signal-Labs/NtdllUnpatcher","1","1","N/A","N/A","10","2","150","33","2019-03-07T11:10:40Z","2019-03-07T10:20:19Z","53635" +"*NtdllUnpatcher-master*",".{0,1000}NtdllUnpatcher\-master.{0,1000}","offensive_tool_keyword","NtdllUnpatcher","code for EDR bypassing","T1070.004 - T1055.001 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Signal-Labs/NtdllUnpatcher","1","1","N/A","N/A","10","2","150","33","2019-03-07T11:10:40Z","2019-03-07T10:20:19Z","53636" +"*ntds_grabber.md*",".{0,1000}ntds_grabber\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","53638" +"*ntdsdump.exe*",".{0,1000}ntdsdump\.exe.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","53639" +"*NTDSgrab.ps1*",".{0,1000}NTDSgrab\.ps1.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","53640" +"*NTHASH-win32.exe*",".{0,1000}NTHASH\-win32\.exe.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53667" +"*NTHASH-win64.exe*",".{0,1000}NTHASH\-win64\.exe.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53668" +"*ntlm_info_enumeration.*",".{0,1000}ntlm_info_enumeration\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","53673" +"*ntlmdecoder.py*",".{0,1000}ntlmdecoder\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","53675" +"*NTLMExtract.ps1*",".{0,1000}NTLMExtract\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","53676" +"*ntlm-info.py*",".{0,1000}ntlm\-info\.py.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","53677" +"*NTLMInjector.ps1*",".{0,1000}NTLMInjector\.ps1.{0,1000}","offensive_tool_keyword","NTLMInjector","restore the user password after a password reset (get the previous hash with DCSync)","T1555 - T1556.003 - T1078 - T1110.003 - T1201 - T1003","TA0001 - TA0003 - TA0004 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/vletoux/NTLMInjector","1","1","N/A","N/A","10","2","167","29","2017-06-08T19:01:21Z","2017-06-04T07:25:36Z","53678" +"*ntlmquic.*",".{0,1000}ntlmquic\..{0,1000}","offensive_tool_keyword","ntlmquic","POC tools for exploring SMB over QUIC protocol","T1210.002 - T1210.003 - T1210.004","TA0001","N/A","N/A","Exploitation tool","https://github.com/xpn/ntlmquic","1","1","N/A","network exploitation tool","6","2","122","15","2022-04-06T11:22:11Z","2022-04-05T13:01:02Z","53679" +"*ntlmquic-go*",".{0,1000}ntlmquic\-go.{0,1000}","offensive_tool_keyword","ntlmquic","POC tools for exploring SMB over QUIC protocol","T1210.002 - T1210.003 - T1210.004","TA0001","N/A","N/A","Exploitation tool","https://github.com/xpn/ntlmquic","1","1","N/A","network exploitation tool","6","2","122","15","2022-04-06T11:22:11Z","2022-04-05T13:01:02Z","53680" +"*ntlmquic-master*",".{0,1000}ntlmquic\-master.{0,1000}","offensive_tool_keyword","ntlmquic","POC tools for exploring SMB over QUIC protocol","T1210.002 - T1210.003 - T1210.004","TA0001","N/A","N/A","Exploitation tool","https://github.com/xpn/ntlmquic","1","1","N/A","network exploitation tool","6","2","122","15","2022-04-06T11:22:11Z","2022-04-05T13:01:02Z","53681" +"*ntlmrecon.csv*",".{0,1000}ntlmrecon\.csv.{0,1000}","offensive_tool_keyword","NTMLRecon","A fast and flexible NTLM reconnaissance tool without external dependencies. Useful to find out information about NTLM endpoints when working with a large set of potential IP addresses and domains","T1595","TA0009","N/A","N/A","Discovery","https://github.com/pwnfoo/NTLMRecon","1","1","N/A","N/A","N/A","5","481","70","2024-06-24T18:11:12Z","2019-12-01T06:06:30Z","53683" +"*ntlmrecon-fromfile.csv*",".{0,1000}ntlmrecon\-fromfile\.csv.{0,1000}","offensive_tool_keyword","NTMLRecon","A fast and flexible NTLM reconnaissance tool without external dependencies. Useful to find out information about NTLM endpoints when working with a large set of potential IP addresses and domains","T1595","TA0009","N/A","N/A","Discovery","https://github.com/pwnfoo/NTLMRecon","1","1","N/A","N/A","N/A","5","481","70","2024-06-24T18:11:12Z","2019-12-01T06:06:30Z","53685" +"*NTLMRecon-master*",".{0,1000}NTLMRecon\-master.{0,1000}","offensive_tool_keyword","NTMLRecon","Enumerate information from NTLM authentication enabled web endpoints","T1212 - T1212.001 - T1071 - T1071.001 - T1087 - T1087.001","TA0009 - TA0007 - TA0006","N/A","N/A","Discovery","https://github.com/puzzlepeaches/NTLMRecon","1","1","N/A","N/A","8","1","35","3","2023-08-16T14:34:10Z","2023-08-09T12:10:42Z","53686" +"*ntlmrecon-ranges.csv*",".{0,1000}ntlmrecon\-ranges\.csv.{0,1000}","offensive_tool_keyword","NTMLRecon","A fast and flexible NTLM reconnaissance tool without external dependencies. Useful to find out information about NTLM endpoints when working with a large set of potential IP addresses and domains","T1595","TA0009","N/A","N/A","Discovery","https://github.com/pwnfoo/NTLMRecon","1","1","N/A","N/A","N/A","5","481","70","2024-06-24T18:11:12Z","2019-12-01T06:06:30Z","53687" +"*NTLMRelay2Self.git*",".{0,1000}NTLMRelay2Self\.git.{0,1000}","offensive_tool_keyword","NTLMRelay2Self","An other No-Fix LPE - NTLMRelay2Self over HTTP (Webdav).","T1078 - T1078.004 - T1557 - T1557.001 - T1068","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/med0x2e/NTLMRelay2Self","1","1","N/A","N/A","10","5","400","42","2024-01-27T08:52:03Z","2022-04-30T10:05:02Z","53688" +"*ntlmRelayToEWS.py*",".{0,1000}ntlmRelayToEWS\.py.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","1","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","53690" +"*NtlmRelayToEWS-master*",".{0,1000}NtlmRelayToEWS\-master.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","1","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","53691" +"*ntlmrelayx.*",".{0,1000}ntlmrelayx\..{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","53694" +"*ntlmrelayx.exe*",".{0,1000}ntlmrelayx\.exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/LuemmelSec/ntlmrelayx.py_to_exe","1","1","N/A","N/A","10","1","86","17","2023-05-26T05:35:52Z","2023-05-15T17:58:26Z","53695" +"*ntlmrelayx.py*",".{0,1000}ntlmrelayx\.py.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","53696" +"*ntlmrelayx.py*",".{0,1000}ntlmrelayx\.py.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","1","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","53697" +"*ntlmrelayx.py*",".{0,1000}ntlmrelayx\.py.{0,1000}","offensive_tool_keyword","pretender","MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS - LLMNR and NetBIOS-NS spoofing","T1557 - T1046 - T1590 - T1557.002","TA0008 - TA0011 - TA0007 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/RedTeamPentesting/pretender","1","1","N/A","N/A","7","10","1089","79","2025-02-19T08:14:57Z","2022-07-11T13:23:23Z","53698" +"*ntlmrelayx.py*",".{0,1000}ntlmrelayx\.py.{0,1000}","offensive_tool_keyword","RemotePotato0","Windows Privilege Escalation from User to Domain Admin.","T1078.002 - T1078.003 - T1078.004","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RemotePotato0","1","1","N/A","N/A","10","10","1382","215","2022-12-18T01:52:53Z","2021-02-08T22:02:19Z","53699" +"*ntlmrelayx.py_to_exe*",".{0,1000}ntlmrelayx\.py_to_exe.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/LuemmelSec/ntlmrelayx.py_to_exe","1","1","N/A","N/A","10","1","86","17","2023-05-26T05:35:52Z","2023-05-15T17:58:26Z","53701" +"*ntlmrelayx_original.py*",".{0,1000}ntlmrelayx_original\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/LuemmelSec/ntlmrelayx.py_to_exe","1","1","N/A","N/A","10","1","86","17","2023-05-26T05:35:52Z","2023-05-15T17:58:26Z","53702" +"*ntlmscan.py*",".{0,1000}ntlmscan\.py.{0,1000}","offensive_tool_keyword","ntlmscan","scan for NTLM directories","T1087 - T1083","TA0006","N/A","N/A","Reconnaissance","https://github.com/nyxgeek/ntlmscan","1","1","N/A","N/A","N/A","4","359","57","2024-06-27T11:10:32Z","2019-10-23T06:02:56Z","53703" +"*ntlmscan-master.zip*",".{0,1000}ntlmscan\-master\.zip.{0,1000}","offensive_tool_keyword","ntlmscan","scan for NTLM directories","T1087 - T1083","TA0006","N/A","N/A","Reconnaissance","https://github.com/nyxgeek/ntlmscan","1","1","N/A","N/A","N/A","4","359","57","2024-06-27T11:10:32Z","2019-10-23T06:02:56Z","53704" +"*NTLMSleuth.ps1*",".{0,1000}NTLMSleuth\.ps1.{0,1000}","offensive_tool_keyword","NTLMSleuth","verify NTLM hash integrity against the robust database of ntlm.pw.","T1003 - T1555","TA0006","N/A","Black Basta","Credential Access","https://github.com/jmarr73/NTLMSleuth","1","1","N/A","N/A","8","1","8","0","2024-08-28T15:21:10Z","2023-12-12T16:41:35Z","53705" +"*NTLMSleuth.sh*",".{0,1000}NTLMSleuth\.sh.{0,1000}","offensive_tool_keyword","NTLMSleuth","verify NTLM hash integrity against the robust database of ntlm.pw.","T1003 - T1555","TA0006","N/A","Black Basta","Credential Access","https://github.com/jmarr73/NTLMSleuth","1","1","N/A","N/A","8","1","8","0","2024-08-28T15:21:10Z","2023-12-12T16:41:35Z","53706" +"*NtlmThief.exe*",".{0,1000}NtlmThief\.exe.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","1","N/A","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","53707" +"*NtlmThief.sln*",".{0,1000}NtlmThief\.sln.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","1","N/A","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","53708" +"*NtlmThief.vcxproj*",".{0,1000}NtlmThief\.vcxproj.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","1","N/A","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","53709" +"*NtlmThief-main*",".{0,1000}NtlmThief\-main.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","1","N/A","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","53710" +"*ntpescape-master.*",".{0,1000}ntpescape\-master\..{0,1000}","offensive_tool_keyword","ntpescape","ntpescape is a tool that can stealthily (but slowly) exfiltrate data from a computer using the Network Time Protocol (NTP).","T1048 - T1071.004","TA0010 - TA0009","N/A","Black Basta","Data Exfiltration","https://github.com/evallen/ntpescape","1","1","N/A","N/A","10","2","138","15","2023-11-14T18:54:14Z","2022-09-22T16:25:15Z","53719" +"*NtRemoteLoad-main*",".{0,1000}NtRemoteLoad\-main.{0,1000}","offensive_tool_keyword","NtRemoteLoad","Remote Shellcode Injector","T1055 - T1027 - T1218.010","TA0002 - TA0005 - TA0010","N/A","N/A","Exploitation tool","https://github.com/florylsk/NtRemoteLoad","1","1","N/A","N/A","10","3","213","37","2023-08-27T17:14:44Z","2023-08-27T16:52:31Z","53720" +"*ntrights.exe*",".{0,1000}ntrights\.exe.{0,1000}","offensive_tool_keyword","NtRights","tool for adding privileges from the commandline","T1548.002 - T1059.003 - T1027.002","TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/gtworek/PSBits/tree/master/NtRights","1","1","N/A","N/A","7","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","53721" +"*NTT-Security-Japan/pac2*",".{0,1000}NTT\-Security\-Japan\/pac2.{0,1000}","offensive_tool_keyword","pac2","PAC2 is a framework that generates arbitrary flows and sends and executes them on the Power Automate Platform - using Power automate as a C2","T1550.001 - T1204.002 - T1102 - T1071.001","TA0005 - TA0008 - TA0010- TA0011","N/A","N/A","C2","https://github.com/NTT-Security-Japan/pac2","1","1","N/A","N/A","6","10","6","1","2024-04-16T11:58:54Z","2024-03-01T08:06:32Z","53722" +"*NtUserMNDragOverExploit*",".{0,1000}NtUserMNDragOverExploit.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","53723" +"*Nuages*/Implants*",".{0,1000}Nuages.{0,1000}\/Implants.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","53725" +"*nuages.getAutoruns*",".{0,1000}nuages\.getAutoruns.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","53727" +"*nuages.getImplants*",".{0,1000}nuages\.getImplants.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","53728" +"*nuages.getListeners*",".{0,1000}nuages\.getListeners.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","53729" +"*nuages.printImplants*",".{0,1000}nuages\.printImplants.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","53730" +"*nuages.printListeners*",".{0,1000}nuages\.printListeners.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","53731" +"*nuages_cli.js*",".{0,1000}nuages_cli\.js.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","53732" +"*NuagesC2Connector*",".{0,1000}NuagesC2Connector.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","53733" +"*NuagesC2Implant*",".{0,1000}NuagesC2Implant.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","53734" +"*NuagesPythonImplant*",".{0,1000}NuagesPythonImplant.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","53735" +"*NuagesSharpImplant*",".{0,1000}NuagesSharpImplant.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","53736" +"*nuclei-burp-plugin*",".{0,1000}nuclei\-burp\-plugin.{0,1000}","offensive_tool_keyword","Xerror","A BurpSuite plugin intended to help with nuclei template generation.","T1083 - T1069 - T1204 - T1059 - T1078","TA0007 - TA0005 - TA0002 - TA0011","N/A","N/A","Exploitation tool","https://github.com/projectdiscovery/nuclei-burp-plugin","1","1","N/A","network exploitation tool","N/A","10","1234","120","2024-09-11T09:29:20Z","2022-01-17T10:31:33Z","53740" +"*NUL0x4C/APCLdr*",".{0,1000}NUL0x4C\/APCLdr.{0,1000}","offensive_tool_keyword","APCLdr","APCLdr: Payload Loader With Evasion Features","T1027 - T1055 - T1055.002 - T1055.003 - T1070 - T1070.004 - T1071 - T1106 - T1574.001","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/NUL0x4C/APCLdr","1","1","N/A","N/A","N/A","4","316","54","2023-01-22T04:24:33Z","2023-01-21T18:09:36Z","53745" +"*NUL0x4C/AtomLdr*",".{0,1000}NUL0x4C\/AtomLdr.{0,1000}","offensive_tool_keyword","AtomLdr","A DLL loader with advanced evasive features","T1071.004 - T1574.001 - T1574.002 - T1071.001 - T1055.003 - T1059.003 - T1546.003 - T1574.003 - T1574.004 - T1059.001 - T1569.002","TA0011 - TA0006 - TA0002 - TA0008 - TA0007","N/A","N/A","Exploitation tool","https://github.com/NUL0x4C/AtomLdr","1","1","N/A","N/A","N/A","8","712","91","2023-02-26T19:57:09Z","2023-02-26T17:59:26Z","53746" +"*null-byte.com/bypass-amsi*",".{0,1000}null\-byte\.com\/bypass\-amsi.{0,1000}","offensive_tool_keyword","chimera","Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.","T1027.002 - T1059.001 - T1562.001","TA0005 ","N/A","N/A","Defense Evasion","https://github.com/tokyoneon/Chimera/","1","1","N/A","N/A","10","10","1493","252","2021-11-09T12:39:59Z","2020-09-01T07:42:22Z","53747" +"*nxc*nxcdb.py*",".{0,1000}nxc.{0,1000}nxcdb\.py.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","53763" +"*nxx3cy6aee2s53v7v5pxrfv7crfssw7hmgejbj47cv6xuak3bgncllqd.onion*",".{0,1000}nxx3cy6aee2s53v7v5pxrfv7crfssw7hmgejbj47cv6xuak3bgncllqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","53767" +"*NYAN-x-CAT/Lime-Crypter*",".{0,1000}NYAN\-x\-CAT\/Lime\-Crypter.{0,1000}","offensive_tool_keyword","Lime-Crypter","An obfuscation tool for .Net + Native files","T1027 - T1045","TA0005 ","N/A","N/A","Defense Evasion","https://github.com/NYAN-x-CAT/Lime-Crypter","1","1","N/A","N/A","9","6","515","199","2024-04-22T21:31:18Z","2018-07-14T13:44:58Z","53769" +"*NYAN-x-CAT/Lime-RAT*",".{0,1000}NYAN\-x\-CAT\/Lime\-RAT.{0,1000}","offensive_tool_keyword","Lime-RAT","remote administration tool for Windows (RAT)","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","APT-C-36 - Operation Comando","Malware","https://github.com/NYAN-x-CAT/Lime-RAT","1","1","N/A","N/A","10","10","1086","413","2019-06-24T17:05:48Z","2018-02-07T15:35:56Z","53770" +"*NYANxCAT@pm.me*",".{0,1000}NYANxCAT\@pm\.me.{0,1000}","offensive_tool_keyword","Lime-RAT","remote administration tool for Windows (RAT)","T1059 - T1573.001 - T1027 - T1091 - T1486 - T1036 - T1560 - T1566 - T1480 - T1498 - T1113 - T1083 - T1016 - T1105 - T1056 - T1021 - T1112 - T1082 - T1072 - T1076 - T1078 - T1209 - T1003 - T1012 - T1100 - T1135 - T1108 - T1029 - T1547 - T1053 - T1060 - T1102 - T1124 - T1049 - T1123 - T1145 - T1210 - T1046 - T1010 - T1055","TA0040 - TA0010 - TA0005 - TA0011 - TA0043 - TA0006 - TA0042 - TA0008 - TA0009 - TA0007 - TA0002 - TA0003","N/A","APT-C-36 - Operation Comando","Malware","https://github.com/NYAN-x-CAT/Lime-RAT","1","1","#email","N/A","10","10","1086","413","2019-06-24T17:05:48Z","2018-02-07T15:35:56Z","53771" +"*nysm-master.zip*",".{0,1000}nysm\-master\.zip.{0,1000}","offensive_tool_keyword","nysm","nysm is a stealth post-exploitation container","T1610 - T1057 - T1570","TA0005 - TA0002 - TA0008","N/A","N/A","Defense Evasion","https://github.com/eeriedusk/nysm","1","1","N/A","N/A","10","3","246","39","2023-12-20T13:59:17Z","2023-09-25T10:03:52Z","53773" +"*NytroRST/NetRipper*",".{0,1000}NytroRST\/NetRipper.{0,1000}","offensive_tool_keyword","NetRipper","NetRipper - Smart traffic sniffing for penetration testers","T1173 - T1557 - T1573.001 - T1056.001","TA0009 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/NytroRST/NetRipper","1","1","N/A","N/A","10","10","1368","318","2022-06-17T21:08:54Z","2015-07-14T20:31:04Z","53774" +"*nyxgeek/dirdevil*",".{0,1000}nyxgeek\/dirdevil.{0,1000}","offensive_tool_keyword","dirdevil","PowerShell to hide data in directory structures","T1027 - T1083 - T1158 - T1059.001 - T1036","TA0005","N/A","N/A","Defense Evasion","https://github.com/nyxgeek/dirdevil","1","1","N/A","N/A","6","1","44","6","2024-07-11T16:09:02Z","2024-06-25T07:26:30Z","53775" +"*nyxgeek/lyncsmash*",".{0,1000}nyxgeek\/lyncsmash.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","53776" +"*nyxgeek/ntlmscan*",".{0,1000}nyxgeek\/ntlmscan.{0,1000}","offensive_tool_keyword","ntlmscan","scan for NTLM directories","T1087 - T1083","TA0006","N/A","N/A","Reconnaissance","https://github.com/nyxgeek/ntlmscan","1","1","N/A","N/A","N/A","4","359","57","2024-06-27T11:10:32Z","2019-10-23T06:02:56Z","53777" +"*nyxgeek/o365recon*",".{0,1000}nyxgeek\/o365recon.{0,1000}","offensive_tool_keyword","o365recon","script to retrieve information via O365 and AzureAD with a valid cred ","T1110 - T1081 - T1081.001 - T1114 - T1087","TA0006 - TA0007","N/A","N/A","Reconnaissance","https://github.com/nyxgeek/o365recon","1","1","N/A","N/A","7","8","715","103","2022-08-14T04:18:28Z","2017-09-02T17:19:42Z","53778" +"*nyxgeek/teamstracker*",".{0,1000}nyxgeek\/teamstracker.{0,1000}","offensive_tool_keyword","teamstracker","using graph proxy to monitor teams user presence","T1552.007 - T1052.001 - T1602","TA0003 - TA0005 - TA0007","N/A","N/A","Reconnaissance","https://github.com/nyxgeek/teamstracker","1","1","N/A","N/A","3","1","54","4","2024-06-27T11:57:35Z","2023-08-15T03:41:46Z","53779" +"*o_getprivs*",".{0,1000}o_getprivs.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53782" +"*o365-attack-toolkit*",".{0,1000}o365\-attack\-toolkit.{0,1000}","offensive_tool_keyword","o365-attack-toolkit","A toolkit to attack Office365","T1110 - T1114 - T1119 - T1197 - T1087.002","TA0001 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/o365-attack-toolkit","1","1","N/A","N/A","10","10","1068","217","2020-11-06T12:09:26Z","2019-07-22T10:39:46Z","53792" +"*o365creeper.git*",".{0,1000}o365creeper\.git.{0,1000}","offensive_tool_keyword","o365creeper","Python script that performs email address validation against Office 365 without submitting login attempts","T1592.002 - T1596","TA0007","N/A","N/A","Discovery","https://github.com/LMGsec/o365creeper","1","1","N/A","N/A","N/A","4","342","60","2020-08-07T17:40:41Z","2019-07-12T21:32:05Z","53793" +"*o365creeper.py*",".{0,1000}o365creeper\.py.{0,1000}","offensive_tool_keyword","o365creeper","Python script that performs email address validation against Office 365 without submitting login attempts","T1592.002 - T1596","TA0007","N/A","N/A","Discovery","https://github.com/LMGsec/o365creeper","1","1","N/A","N/A","N/A","4","342","60","2020-08-07T17:40:41Z","2019-07-12T21:32:05Z","53794" +"*o365creeper-master*",".{0,1000}o365creeper\-master.{0,1000}","offensive_tool_keyword","o365creeper","Python script that performs email address validation against Office 365 without submitting login attempts","T1592.002 - T1596","TA0007","N/A","N/A","Discovery","https://github.com/LMGsec/o365creeper","1","1","N/A","N/A","N/A","4","342","60","2020-08-07T17:40:41Z","2019-07-12T21:32:05Z","53795" +"*o365enum.py*",".{0,1000}o365enum\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","53796" +"*o365enum.py*",".{0,1000}o365enum\.py.{0,1000}","offensive_tool_keyword","o365enum","Enumerate valid usernames from Office 365 using ActiveSync - Autodiscover v1 or office.com login page.","T1595 - T1595.002 - T1114 - T1114.001 - T1087 - T1087.002","TA0040 - TA0010 - TA0007","N/A","N/A","Exploitation tool","https://github.com/gremwell/o365enum","1","1","N/A","N/A","7","3","267","39","2024-05-02T07:45:31Z","2020-02-18T12:22:50Z","53797" +"*o365enum-master*",".{0,1000}o365enum\-master.{0,1000}","offensive_tool_keyword","o365enum","Enumerate valid usernames from Office 365 using ActiveSync - Autodiscover v1 or office.com login page.","T1595 - T1595.002 - T1114 - T1114.001 - T1087 - T1087.002","TA0040 - TA0010 - TA0007","N/A","N/A","Exploitation tool","https://github.com/gremwell/o365enum","1","1","N/A","N/A","7","3","267","39","2024-05-02T07:45:31Z","2020-02-18T12:22:50Z","53798" +"*o365recon.ps1*",".{0,1000}o365recon\.ps1.{0,1000}","offensive_tool_keyword","o365recon","script to retrieve information via O365 and AzureAD with a valid cred ","T1110 - T1081 - T1081.001 - T1114 - T1087","TA0006 - TA0007","N/A","N/A","Reconnaissance","https://github.com/nyxgeek/o365recon","1","1","N/A","N/A","N/A","8","715","103","2022-08-14T04:18:28Z","2017-09-02T17:19:42Z","53799" +"*o365recon-master*",".{0,1000}o365recon\-master.{0,1000}","offensive_tool_keyword","o365recon","script to retrieve information via O365 and AzureAD with a valid cred ","T1110 - T1081 - T1081.001 - T1114 - T1087","TA0006 - TA0007","N/A","N/A","Reconnaissance","https://github.com/nyxgeek/o365recon","1","1","N/A","N/A","N/A","8","715","103","2022-08-14T04:18:28Z","2017-09-02T17:19:42Z","53800" +"*o6pi3u67zyag73ligtsupin5rjkxpfrbofwoxnhimpgpfttxqu7lsuyd.onion*",".{0,1000}o6pi3u67zyag73ligtsupin5rjkxpfrbofwoxnhimpgpfttxqu7lsuyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","53805" +"*oab-parse.py*",".{0,1000}oab\-parse\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","53806" +"*Obfuscate.py*",".{0,1000}Obfuscate\.py.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","53810" +"*obfuscate/shellter*",".{0,1000}obfuscate\/shellter.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","53811" +"*obfuscate_command*",".{0,1000}obfuscate_command.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","53813" +"*obfuscated_module_source/*",".{0,1000}obfuscated_module_source\/.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1051","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","53814" +"*obfuscator*antidisassembly.*",".{0,1000}obfuscator.{0,1000}antidisassembly\..{0,1000}","offensive_tool_keyword","Alcatraz","x64 binary obfuscator","T1027 - T1140","TA0004 - TA0042","N/A","N/A","Defense Evasion","https://github.com/weak1337/Alcatraz","1","1","N/A","N/A","10","10","1808","267","2023-07-14T14:19:01Z","2022-12-21T17:27:56Z","53817" +"*obfuskittiedump*",".{0,1000}obfuskittiedump.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","53819" +"*objects_constrained_delegation_full.txt*",".{0,1000}objects_constrained_delegation_full\.txt.{0,1000}","offensive_tool_keyword","adhunt","Tool for exploiting Active Directory Enviroments - enumeration","T1018 - T1087 - T1087.002 - T1069 - T1069.002","TA0007 - TA0003 - TA0001","N/A","N/A","Discovery","https://github.com/karendm/ADHunt","1","1","N/A","AD Enumeration","7","1","46","10","2023-08-10T18:55:39Z","2023-06-20T13:24:10Z","53822" +"*objects_unconstrained_delegation_full.txt*",".{0,1000}objects_unconstrained_delegation_full\.txt.{0,1000}","offensive_tool_keyword","adhunt","Tool for exploiting Active Directory Enviroments - enumeration","T1018 - T1087 - T1087.002 - T1069 - T1069.002","TA0007 - TA0003 - TA0001","N/A","N/A","Discovery","https://github.com/karendm/ADHunt","1","1","N/A","AD Enumeration","7","1","46","10","2023-08-10T18:55:39Z","2023-06-20T13:24:10Z","53824" +"*obscuritylabs/ase:latest*",".{0,1000}obscuritylabs\/ase\:latest.{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","53827" +"*obscuritylabs/RAI/*",".{0,1000}obscuritylabs\/RAI\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","53828" +"*octetsplicer/LAZYPARIAH*",".{0,1000}octetsplicer\/LAZYPARIAH.{0,1000}","offensive_tool_keyword","LAZYPARIAH","LAZYPARIAH - A Tool For Generating Reverse Shell Payloads On The Fly","T1059 - T1566 - T1212 - T1574","TA0002 - TA0003 - TA0008","N/A","N/A","Resource Development","https://github.com/octetsplicer/LAZYPARIAH","1","1","N/A","N/A","N/A","2","140","28","2022-06-18T08:59:45Z","2020-11-20T05:08:36Z","53830" +"*Octoberfest7/JumpSession_BOF*",".{0,1000}Octoberfest7\/JumpSession_BOF.{0,1000}","offensive_tool_keyword","JumpSession_BOF","Beacon Object File allowing creation of Beacons in different sessions","T1055 - T1055.012 - T1548.002","TA0002 - TA0003 - TA0004","N/A","N/A","Persistence","https://github.com/Octoberfest7/JumpSession_BOF","1","1","N/A","N/A","9","1","80","13","2022-05-23T22:23:33Z","2022-05-21T17:38:18Z","53831" +"*Octoberfest7/KDStab*",".{0,1000}Octoberfest7\/KDStab.{0,1000}","offensive_tool_keyword","cobaltstrike","BOF combination of KillDefender and Backstab","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Octoberfest7/KDStab","1","1","N/A","N/A","10","10","167","37","2023-03-23T02:22:50Z","2022-03-10T06:09:52Z","53832" +"*Octoberfest7/TeamsPhisher*",".{0,1000}Octoberfest7\/TeamsPhisher.{0,1000}","offensive_tool_keyword","teamsphisher","Send phishing messages and attachments to Microsoft Teams users","T1566.001 - T1566.002 - T1204.001","TA0001 - TA0005","N/A","Black Basta","Phishing","https://github.com/Octoberfest7/TeamsPhisher","1","1","N/A","N/A","N/A","10","1073","138","2024-06-19T21:41:55Z","2023-07-03T02:19:47Z","53833" +"*OEP_Hiijack_Inject_Load*",".{0,1000}OEP_Hiijack_Inject_Load.{0,1000}","offensive_tool_keyword","C2 related tools","A shellcode loader written using nim","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/aeverj/NimShellCodeLoader","1","1","N/A","N/A","10","10","656","121","2025-02-18T14:31:45Z","2021-01-19T15:57:01Z","53835" +"*offensive_notion.exe*",".{0,1000}offensive_notion\.exe.{0,1000}","offensive_tool_keyword","OffensiveNotion","Notion (yes the notetaking app) as a C2.","T1090 - T1090.002 - T1071 - T1071.001","TA0011 - TA0042","N/A","N/A","C2","https://github.com/mttaggart/OffensiveNotion","1","1","N/A","N/A","10","10","1161","130","2023-05-21T13:24:01Z","2022-01-18T16:39:54Z","53836" +"*offensive_notion_darwin_*",".{0,1000}offensive_notion_darwin_.{0,1000}","offensive_tool_keyword","OffensiveNotion","Notion (yes the notetaking app) as a C2.","T1090 - T1090.002 - T1071 - T1071.001","TA0011 - TA0042","N/A","N/A","C2","https://github.com/mttaggart/OffensiveNotion","1","1","#linux","N/A","10","10","1161","130","2023-05-21T13:24:01Z","2022-01-18T16:39:54Z","53837" +"*offensive_notion_linux_*",".{0,1000}offensive_notion_linux_.{0,1000}","offensive_tool_keyword","OffensiveNotion","Notion (yes the notetaking app) as a C2.","T1090 - T1090.002 - T1071 - T1071.001","TA0011 - TA0042","N/A","N/A","C2","https://github.com/mttaggart/OffensiveNotion","1","1","#linux","N/A","10","10","1161","130","2023-05-21T13:24:01Z","2022-01-18T16:39:54Z","53838" +"*offensive_notion_win_*.exe*",".{0,1000}offensive_notion_win_.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","OffensiveNotion","Notion (yes the notetaking app) as a C2.","T1090 - T1090.002 - T1071 - T1071.001","TA0011 - TA0042","N/A","N/A","C2","https://github.com/mttaggart/OffensiveNotion","1","1","N/A","N/A","10","10","1161","130","2023-05-21T13:24:01Z","2022-01-18T16:39:54Z","53839" +"*OffensiveCSharp*DriverQuery*",".{0,1000}OffensiveCSharp.{0,1000}DriverQuery.{0,1000}","offensive_tool_keyword","DriverQuery","Collect details about drivers on the system and optionally filter to find only ones not signed by Microsoft","T1124 - T1057 - T1082","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/matterpreter/OffensiveCSharp/tree/master/DriverQuery","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","53840" +"*OffensiveCSharp*ETWEventSubscription*",".{0,1000}OffensiveCSharp.{0,1000}ETWEventSubscription.{0,1000}","offensive_tool_keyword","ETWEventSubscription","Similar to WMI event subscriptions but leverages Event Tracing for Windows. When the event on the system occurs currently either when any user logs in or a specified process is started - the DoEvil() method is executed.","T1053.005 - T1546.003 - T1055.001","TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/matterpreter/OffensiveCSharp/tree/master/ETWEventSubscription","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","53841" +"*OffensiveCSharp-master*",".{0,1000}OffensiveCSharp\-master.{0,1000}","offensive_tool_keyword","OffensiveCSharp","Collection of Offensive C# Tooling","T1059.001 - T1055.001 - T1027","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/matterpreter/OffensiveCSharp/tree/master","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","53842" +"*OffensiveLua-main*",".{0,1000}OffensiveLua\-main.{0,1000}","offensive_tool_keyword","OffensiveLua","Offensive Lua is a collection of offensive security scripts written in Lua with FFI","T1059 - T1218.011 - T1105 - T1021.002 - T1564.001 - T1112 - T1113 - T1204.002 - T1547.002","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hackerhouse-opensource/OffensiveLua","1","1","N/A","N/A","8","2","184","25","2023-11-17T00:35:10Z","2023-10-25T17:21:13Z","53843" +"*Offensive-Panda/LsassReflectDumping*",".{0,1000}Offensive\-Panda\/LsassReflectDumping.{0,1000}","offensive_tool_keyword","LsassReflectDumping","leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process","T1003.001 - T1555.003 - T1077","TA0006","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/LsassReflectDumping","1","1","N/A","N/A","10","2","198","27","2024-10-19T08:16:13Z","2024-10-17T14:57:30Z","53844" +"*Offensive-Panda/ShadowDumper/*",".{0,1000}Offensive\-Panda\/ShadowDumper\/.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","1","N/A","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","53845" +"*Offensive-Windows-IPC-1-NamedPipes.*",".{0,1000}Offensive\-Windows\-IPC\-1\-NamedPipes\..{0,1000}","offensive_tool_keyword","NamedPipeMaster","a tool used to analyze monitor and interact with named pipes - allows dll injection and impersonation","T1055.001 - T1134.001 - T1010 - T1550.002","TA0007 - TA0008 - TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/zeze-zeze/NamedPipeMaster","1","1","N/A","N/A","9","2","161","15","2024-10-27T05:24:11Z","2024-08-23T02:03:44Z","53846" +"*office2john.py*",".{0,1000}office2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53847" +"*office365userenum.*",".{0,1000}office365userenum\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","53848" +"*Office-DDE-Payloads*",".{0,1000}Office\-DDE\-Payloads.{0,1000}","offensive_tool_keyword","Office-DDE-Payloads","Collection of scripts and templates to generate Word and Excel documents embedded with the DDE. macro-less command execution technique described by @_staaldraad and @0x5A1F (blog post link in References section below). Intended for use during sanctioned red team engagements and/or phishing campaigns.","T1221 - T1222 - T1223","TA0001 - TA0002 - TA0003","N/A","N/A","Phishing","https://github.com/0xdeadbeefJERKY/Office-DDE-Payloads","1","1","N/A","N/A","N/A","7","638","155","2023-07-16T08:22:24Z","2017-10-27T22:19:17Z","53849" +"*Offline_WinPwn.ps1*",".{0,1000}Offline_WinPwn\.ps1.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","53855" +"*offlinereg-win32.exe*",".{0,1000}offlinereg\-win32\.exe.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53856" +"*offlinereg-win64.exe*",".{0,1000}offlinereg\-win64\.exe.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53857" +"*offsecginger/koadic*",".{0,1000}offsecginger\/koadic.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","53858" +"*OFTC/tor2web/*",".{0,1000}OFTC\/tor2web\/.{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","53859" +"*OG-Sadpanda/SharpCat*",".{0,1000}OG\-Sadpanda\/SharpCat.{0,1000}","offensive_tool_keyword","cobaltstrike","C# alternative to the linux cat command... Prints file contents to console. For use with Cobalt Strike's Execute-Assembly","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OG-Sadpanda/SharpCat","1","1","N/A","N/A","10","10","16","3","2021-07-15T15:01:02Z","2021-07-15T14:57:53Z","53861" +"*OG-Sadpanda/SharpSword*",".{0,1000}OG\-Sadpanda\/SharpSword.{0,1000}","offensive_tool_keyword","cobaltstrike","Read the contents of DOCX files using Cobalt Strike's Execute-Assembly","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OG-Sadpanda/SharpSword","1","1","N/A","N/A","10","10","117","11","2024-09-30T15:21:25Z","2021-07-15T14:50:05Z","53862" +"*OG-Sadpanda/SharpSword*",".{0,1000}OG\-Sadpanda\/SharpSword.{0,1000}","offensive_tool_keyword","SharpSword","Read the contents of MS Word Documents using Cobalt Strike's Execute-Assembly","T1562.004 - T1059.001 - T1021.003","TA0005 - TA0002","N/A","N/A","C2","https://github.com/OG-Sadpanda/SharpSword","1","1","N/A","N/A","8","10","117","11","2024-09-30T15:21:25Z","2021-07-15T14:50:05Z","53863" +"*OG-Sadpanda/SharpZippo*",".{0,1000}OG\-Sadpanda\/SharpZippo.{0,1000}","offensive_tool_keyword","cobaltstrike","List/Read contents of Zip files (in memory and without extraction) using CobaltStrike's Execute-Assembly","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OG-Sadpanda/SharpZippo","1","1","N/A","N/A","10","10","59","10","2022-05-24T15:57:33Z","2022-05-24T15:52:31Z","53864" +"*Oh365UserFinder.git*",".{0,1000}Oh365UserFinder\.git.{0,1000}","offensive_tool_keyword","Oh365UserFinder","Oh365UserFinder is used for identifying valid o365 accounts and domains without the risk of account lockouts. The tool parses responses to identify the IfExistsResult flag is null or not. and responds appropriately if the user is valid. The tool will attempt to identify false positives based on response. and either automatically create a waiting period to allow the throttling value to reset. or warn the user to increase timeouts between attempts.","T1595 - T1592 - T1589 - T1591 - T1598","TA0004 - TA0005 - TA0010","N/A","N/A","Reconnaissance","https://github.com/dievus/Oh365UserFinder","1","1","N/A","N/A","N/A","6","539","94","2025-01-23T19:50:46Z","2021-11-16T22:59:04Z","53865" +"*oh365userfinder.py*",".{0,1000}oh365userfinder\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","53866" +"*oh365userfinder.py*",".{0,1000}oh365userfinder\.py.{0,1000}","offensive_tool_keyword","Oh365UserFinder","Oh365UserFinder is used for identifying valid o365 accounts and domains without the risk of account lockouts. The tool parses responses to identify the IfExistsResult flag is null or not. and responds appropriately if the user is valid. The tool will attempt to identify false positives based on response. and either automatically create a waiting period to allow the throttling value to reset. or warn the user to increase timeouts between attempts.","T1595 - T1592 - T1589 - T1591 - T1598","TA0004 - TA0005 - TA0010","N/A","N/A","Reconnaissance","https://github.com/dievus/Oh365UserFinder","1","1","N/A","N/A","N/A","6","539","94","2025-01-23T19:50:46Z","2021-11-16T22:59:04Z","53867" +"*Oh365UserFinder-main*",".{0,1000}Oh365UserFinder\-main.{0,1000}","offensive_tool_keyword","Oh365UserFinder","Oh365UserFinder is used for identifying valid o365 accounts and domains without the risk of account lockouts. The tool parses responses to identify the IfExistsResult flag is null or not. and responds appropriately if the user is valid. The tool will attempt to identify false positives based on response. and either automatically create a waiting period to allow the throttling value to reset. or warn the user to increase timeouts between attempts.","T1595 - T1592 - T1589 - T1591 - T1598","TA0004 - TA0005 - TA0010","N/A","N/A","Reconnaissance","https://github.com/dievus/Oh365UserFinder","1","1","N/A","N/A","N/A","6","539","94","2025-01-23T19:50:46Z","2021-11-16T22:59:04Z","53868" +"*oh-az/NoArgs*",".{0,1000}oh\-az\/NoArgs.{0,1000}","offensive_tool_keyword","NoArgs","NoArgs is a tool designed to dynamically spoof and conceal process arguments while staying undetected. It achieves this by hooking into Windows APIs to dynamically manipulate the Windows internals on the go. This allows NoArgs to alter process arguments discreetly.","T1055 - T1574 - T1112 - T1056","TA0005 - TA0040 - TA0009","N/A","N/A","Defense Evasion","https://github.com/oh-az/NoArgs","1","1","N/A","N/A","8","2","151","25","2024-05-07T20:38:34Z","2024-03-15T16:54:49Z","53869" +"*ohmva4gbywokzqso.onion*",".{0,1000}ohmva4gbywokzqso\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","53871" +"*ohmva4gbywokzqso.onion.cab*",".{0,1000}ohmva4gbywokzqso\.onion\.cab.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","53872" +"*ohmva4gbywokzqso.tor2web.org*",".{0,1000}ohmva4gbywokzqso\.tor2web\.org.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","53873" +"*Okta-Password-Sprayer*",".{0,1000}Okta\-Password\-Sprayer.{0,1000}","offensive_tool_keyword","Okta-Password-Sprayer","This script is a multi-threaded Okta password sprayer.","T1110 - T1110.003 - T1621","TA0006","N/A","N/A","Credential Access","https://github.com/Rhynorater/Okta-Password-Sprayer","1","1","N/A","N/A","10","1","70","16","2024-01-05T16:24:38Z","2018-09-24T23:39:16Z","53877" +"*oldboy21/LDAP-Password-Hunter*",".{0,1000}oldboy21\/LDAP\-Password\-Hunter.{0,1000}","offensive_tool_keyword","LDAP-Password-Hunter","Password Hunter in Active Directory","T1087.002","TA0001 - TA0007","N/A","N/A","Discovery","https://github.com/oldboy21/LDAP-Password-Hunter","1","1","N/A","N/A","7","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","53878" +"*oldboy21/SMBSR*",".{0,1000}oldboy21\/SMBSR.{0,1000}","offensive_tool_keyword","smbsr","Lookup for interesting stuff in SMB shares","T1135","TA0001 - TA0007","N/A","N/A","Discovery","https://github.com/oldboy21/SMBSR","1","1","N/A","N/A","7","2","149","23","2023-06-16T14:35:30Z","2021-11-10T16:55:52Z","53880" +"*OLDNamedPipeServer.ps1*",".{0,1000}OLDNamedPipeServer\.ps1.{0,1000}","offensive_tool_keyword","PipeViewer ","A tool that shows detailed information about named pipes in Windows","T1022.002 - T1056.002","TA0005 - TA0009","N/A","N/A","discovery","https://github.com/cyberark/PipeViewer","1","1","N/A","N/A","5","7","620","55","2024-11-15T09:55:35Z","2022-12-22T12:35:34Z","53881" +"*Oliver-1-1/GhostMapper*",".{0,1000}Oliver\-1\-1\/GhostMapper.{0,1000}","offensive_tool_keyword","GhostMapper","GhostMapper involves modifying Windows system ""dump_"" prefix drivers to exploit crash handling mechanisms for malicious purposes.","T1014 - T1070.004 - T1055.011","TA0003 - TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/Oliver-1-1/GhostMapper","1","1","N/A","N/A","8","3","279","62","2025-04-12T19:17:46Z","2023-10-31T11:26:33Z","53883" +"*OlivierLaflamme/PyExec*",".{0,1000}OlivierLaflamme\/PyExec.{0,1000}","offensive_tool_keyword","PyExec","This is a very simple privilege escalation technique from admin to System. This is the same technique PSExec uses.","T1134 - T1055 - T1548.002","TA0004 - TA0005 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/OlivierLaflamme/PyExec","1","1","N/A","N/A","9","1","11","7","2019-09-11T13:56:04Z","2019-09-11T13:54:15Z","53884" +"*OmerYa/Invisi-Shell*",".{0,1000}OmerYa\/Invisi\-Shell.{0,1000}","offensive_tool_keyword","Invisi-Shell","Hide your powershell script in plain sight! Invisi-Shell bypasses all of Powershell security features (ScriptBlock logging. Module logging. Transcription. AMSI) by hooking .Net assemblies. The hook is performed via CLR Profiler API.","T1027 - T1059.001 - T1562","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/OmerYa/Invisi-Shell","1","1","N/A","N/A","10","10","1167","166","2019-08-19T19:55:19Z","2018-10-14T23:32:56Z","53886" +"*-OMG-Credz-Plz*",".{0,1000}\-OMG\-Credz\-Plz.{0,1000}","offensive_tool_keyword","OMG-Credz-Plz","A script used to prompt the target to enter their creds to later be exfiltrated with dropbox.","T1056.002 - T1566.001 - T1567.002","TA0004 - TA0040 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/-OMG-Credz-Plz","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","53887" +"*OMGdump.zip*",".{0,1000}OMGdump\.zip.{0,1000}","offensive_tool_keyword","SamDumpCable","Dump users sam and system hive and exfiltrate them","T1003.002 - T1564.001","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/SamDumpCable","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","53888" +"*OMGLoggerDecoder*",".{0,1000}OMGLoggerDecoder.{0,1000}","offensive_tool_keyword","OMGLogger","Key logger which sends each and every key stroke of target remotely/locally.","T1056.001 - T1562.001","TA0004 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/OMGLogger","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","53890" +"*omg-payloads*/payloads/*",".{0,1000}omg\-payloads.{0,1000}\/payloads\/.{0,1000}","offensive_tool_keyword","omg-payloads","Official payload library for the O.MG line of products from Mischief Gadgets","T1200 - T1095 - T1059.006 - T1027","TA0010 - TA0011","N/A","N/A","Hardware","https://github.com/hak5/omg-payloads","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","53891" +"*omg-payloads-master*",".{0,1000}omg\-payloads\-master.{0,1000}","offensive_tool_keyword","omg-payloads","Official payload library for the O.MG line of products from Mischief Gadgets","T1200 - T1095 - T1059.006 - T1027","TA0010 - TA0011","N/A","N/A","Hardware","https://github.com/hak5/omg-payloads","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","53892" +"*OmriBaso/BesoToken*",".{0,1000}OmriBaso\/BesoToken.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","1","N/A","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","53895" +"*omx5iqrdbsoitf3q4xexrqw5r5tfw7vp3vl3li3lfo7saabxazshnead.onion*",".{0,1000}omx5iqrdbsoitf3q4xexrqw5r5tfw7vp3vl3li3lfo7saabxazshnead\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","53896" +"*On_Demand_C2.*",".{0,1000}On_Demand_C2\..{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of beacon BOF written to learn windows and cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Yaxser/CobaltStrike-BOF","1","1","N/A","N/A","10","10","347","57","2023-02-24T13:12:14Z","2020-10-08T01:12:41Z","53897" +"*On-Demand_C2_BOF.*",".{0,1000}On\-Demand_C2_BOF\..{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of beacon BOF written to learn windows and cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Yaxser/CobaltStrike-BOF","1","1","N/A","N/A","10","10","347","57","2023-02-24T13:12:14Z","2020-10-08T01:12:41Z","53898" +"*OnDemandC2Class.cs*",".{0,1000}OnDemandC2Class\.cs.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of beacon BOF written to learn windows and cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Yaxser/CobaltStrike-BOF","1","1","N/A","N/A","10","10","347","57","2023-02-24T13:12:14Z","2020-10-08T01:12:41Z","53899" +"*onecloudemoji/CVE-2022-30190*",".{0,1000}onecloudemoji\/CVE\-2022\-30190.{0,1000}","offensive_tool_keyword","POC","CVE-2022-30190 Follina POC","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/onecloudemoji/CVE-2022-30190","1","1","N/A","N/A","N/A","2","104","27","2022-05-31T09:35:37Z","2022-05-31T06:45:25Z","53900" +"*onedrive_doubledrive.exe*",".{0,1000}onedrive_doubledrive\.exe.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","53901" +"*onedrive_doubledrive.py*",".{0,1000}onedrive_doubledrive\.py.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","53902" +"*onedrive_enum.py*",".{0,1000}onedrive_enum\.py.{0,1000}","offensive_tool_keyword","onedrive_user_enum","enumerate valid onedrive users","T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/onedrive_user_enum","1","1","N/A","network exploitation tool","N/A","7","663","83","2025-04-17T00:13:11Z","2019-03-05T08:54:38Z","53903" +"*onedrive_ransomware.py*",".{0,1000}onedrive_ransomware\.py.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","53905" +"*onedrive_user_enum.git*",".{0,1000}onedrive_user_enum\.git.{0,1000}","offensive_tool_keyword","onedrive_user_enum","enumerate valid onedrive users","T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/onedrive_user_enum","1","1","N/A","network exploitation tool","N/A","7","663","83","2025-04-17T00:13:11Z","2019-03-05T08:54:38Z","53906" +"*One-Lin3r*",".{0,1000}One\-Lin3r.{0,1000}","offensive_tool_keyword","One-Lin3r","One-Lin3r is simple modular and light-weight framework gives you all the one-liners that you will need while penetration testing (Windows. Linux. macOS or even BSD systems) or hacking generally with a lot of new features to make all of this fully automated (ex: you won't even need to copy the one-liners).","T1059 - T1003 - T1053","TA0002 - TA0003 - TA0007","N/A","N/A","Exploitation tool","https://github.com/D4Vinci/One-Lin3r","1","1","#linux","N/A","N/A","10","1706","293","2024-10-14T19:18:37Z","2018-01-14T21:26:04Z","53908" +"*onesixtyone.1*",".{0,1000}onesixtyone\.1.{0,1000}","offensive_tool_keyword","onesixtyone","Fast SNMP scanner. onesixtyone takes a different approach to SNMP scanning. It takes advantage of the fact that SNMP is a connectionless protocol and sends all SNMP requests as fast as it can. Then the scanner waits for responses to come back and logs them in a fashion similar to Nmap ping sweeps","T1046 - T1018","TA0007 - TA0005","N/A","N/A","Reconnaissance","https://github.com/trailofbits/onesixtyone","1","1","N/A","N/A","N/A","6","594","90","2023-04-11T18:21:38Z","2014-02-07T17:02:49Z","53912" +"*onesixtyone.git*",".{0,1000}onesixtyone\.git.{0,1000}","offensive_tool_keyword","onesixtyone","Fast SNMP scanner. onesixtyone takes a different approach to SNMP scanning. It takes advantage of the fact that SNMP is a connectionless protocol and sends all SNMP requests as fast as it can. Then the scanner waits for responses to come back and logs them in a fashion similar to Nmap ping sweeps","T1046 - T1018","TA0007 - TA0005","N/A","N/A","Reconnaissance","https://github.com/trailofbits/onesixtyone","1","1","N/A","N/A","N/A","6","594","90","2023-04-11T18:21:38Z","2014-02-07T17:02:49Z","53913" +"*onionpipe/tor*",".{0,1000}onionpipe\/tor.{0,1000}","offensive_tool_keyword","onionpipe","onionpipe forwards ports on the local host to remote Onion addresses as Tor hidden services and vice-versa.","T1090.003 - T1573.002","TA0005 - TA0011","N/A","Black Basta","Defense Evasion","https://github.com/cmars/onionpipe","1","1","N/A","N/A","10","6","553","33","2025-04-22T16:34:56Z","2022-01-23T06:52:13Z","53921" +"*onionpipe-darwin-amd64-static*",".{0,1000}onionpipe\-darwin\-amd64\-static.{0,1000}","offensive_tool_keyword","onionpipe","onionpipe forwards ports on the local host to remote Onion addresses as Tor hidden services and vice-versa.","T1090.003 - T1573.002","TA0005 - TA0011","N/A","Black Basta","Defense Evasion","https://github.com/cmars/onionpipe","1","1","#linux","N/A","10","6","553","33","2025-04-22T16:34:56Z","2022-01-23T06:52:13Z","53922" +"*onionpipe-linux-amd64-static*",".{0,1000}onionpipe\-linux\-amd64\-static.{0,1000}","offensive_tool_keyword","onionpipe","onionpipe forwards ports on the local host to remote Onion addresses as Tor hidden services and vice-versa.","T1090.003 - T1573.002","TA0005 - TA0011","N/A","Black Basta","Defense Evasion","https://github.com/cmars/onionpipe","1","1","#linux","N/A","10","6","553","33","2025-04-22T16:34:56Z","2022-01-23T06:52:13Z","53923" +"*online_brute.gz.torrent*",".{0,1000}online_brute\.gz\.torrent.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","53926" +"*openBeaconBrowser*",".{0,1000}openBeaconBrowser.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","53938" +"*openBeaconBrowser*",".{0,1000}openBeaconBrowser.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53939" +"*openBeaconConsole*",".{0,1000}openBeaconConsole.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","53940" +"*openBeaconConsole*",".{0,1000}openBeaconConsole.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53941" +"*openbsd_softraid2john.py*",".{0,1000}openbsd_softraid2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53942" +"*OpenBullet.csproj*",".{0,1000}OpenBullet\.csproj.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/openbullet","1","1","N/A","N/A","10","10","1569","697","2024-09-02T12:18:29Z","2019-03-26T09:06:32Z","53943" +"*OpenBullet.exe*",".{0,1000}OpenBullet\.exe.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/openbullet","1","1","N/A","N/A","10","10","1569","697","2024-09-02T12:18:29Z","2019-03-26T09:06:32Z","53944" +"*OpenBullet.pdb*",".{0,1000}OpenBullet\.pdb.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/openbullet","1","1","N/A","N/A","10","10","1569","697","2024-09-02T12:18:29Z","2019-03-26T09:06:32Z","53945" +"*OpenBullet.sln*",".{0,1000}OpenBullet\.sln.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/openbullet","1","1","N/A","N/A","10","10","1569","697","2024-09-02T12:18:29Z","2019-03-26T09:06:32Z","53946" +"*OpenBullet.zip*",".{0,1000}OpenBullet\.zip.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/openbullet","1","1","N/A","N/A","10","10","1569","697","2024-09-02T12:18:29Z","2019-03-26T09:06:32Z","53947" +"*openbullet/openbullet*",".{0,1000}openbullet\/openbullet.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/openbullet","1","1","N/A","N/A","10","10","1569","697","2024-09-02T12:18:29Z","2019-03-26T09:06:32Z","53948" +"*OpenBullet2.Console.zip*",".{0,1000}OpenBullet2\.Console\.zip.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/OpenBullet2","1","1","N/A","N/A","10","10","1953","518","2025-03-16T10:50:26Z","2020-04-23T14:04:16Z","53949" +"*OpenBullet2.Native.exe*",".{0,1000}OpenBullet2\.Native\.exe.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/OpenBullet2","1","1","N/A","N/A","10","10","1953","518","2025-03-16T10:50:26Z","2020-04-23T14:04:16Z","53950" +"*OpenBullet2.Native.zip*",".{0,1000}OpenBullet2\.Native\.zip.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/OpenBullet2","1","1","N/A","N/A","10","10","1953","518","2025-03-16T10:50:26Z","2020-04-23T14:04:16Z","53951" +"*OpenBullet2.zip*",".{0,1000}OpenBullet2\.zip.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/OpenBullet2","1","1","N/A","N/A","10","10","1953","518","2025-03-16T10:50:26Z","2020-04-23T14:04:16Z","53952" +"*OpenBullet2-master*",".{0,1000}OpenBullet2\-master.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/OpenBullet2","1","1","N/A","N/A","10","10","1953","518","2025-03-16T10:50:26Z","2020-04-23T14:04:16Z","53954" +"*OpenBulletApp.cs*",".{0,1000}OpenBulletApp\.cs.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/openbullet","1","1","N/A","N/A","10","10","1569","697","2024-09-02T12:18:29Z","2019-03-26T09:06:32Z","53955" +"*OpenBulletCLI.csproj*",".{0,1000}OpenBulletCLI\.csproj.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/openbullet","1","1","N/A","N/A","10","10","1569","697","2024-09-02T12:18:29Z","2019-03-26T09:06:32Z","53956" +"*OpenBulletCLI.exe*",".{0,1000}OpenBulletCLI\.exe.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/openbullet","1","1","N/A","N/A","10","10","1569","697","2024-09-02T12:18:29Z","2019-03-26T09:06:32Z","53957" +"*openbullet-master*",".{0,1000}openbullet\-master.{0,1000}","offensive_tool_keyword","openbullet","The OpenBullet web testing application.","T1211 - T1211.002 - T1254 - T1254.001 - T1190 - T1190.001","TA0005 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/openbullet/openbullet","1","1","N/A","N/A","10","10","1569","697","2024-09-02T12:18:29Z","2019-03-26T09:06:32Z","53958" +"*openBypassUACDialog*",".{0,1000}openBypassUACDialog.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","53959" +"*openBypassUACDialog*",".{0,1000}openBypassUACDialog.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53960" +"*openChromeDumpsHTML.exe*",".{0,1000}openChromeDumpsHTML\.exe.{0,1000}","offensive_tool_keyword","OpenChromeDumps","OpenChrome Dump used with GrabChrome for credential access","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Yanluowang - Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53961" +"*opencubicles/h8mail*",".{0,1000}opencubicles\/h8mail.{0,1000}","offensive_tool_keyword","h8mail","Powerful and user-friendly password hunting tool.","T1581.002 - T1591 - T1590 - T1596 - T1592 - T1217.001","TA0010","N/A","N/A","Reconnaissance","https://github.com/opencubicles/h8mail","1","1","N/A","N/A","N/A","1","11","4","2019-08-19T09:46:33Z","2019-08-19T09:45:32Z","53962" +"*OPENCYBER-FR/RustHound*",".{0,1000}OPENCYBER\-FR\/RustHound.{0,1000}","offensive_tool_keyword","RustHound","Active Directory data collector for BloodHound written in Rust","T1087.002 - T1018 - T1059.003","TA0007 - TA0001 - TA0002","N/A","N/A","Discovery","https://github.com/OPENCYBER-FR/RustHound","1","1","N/A","AD Enumeration","9","10","1013","98","2024-10-21T18:58:20Z","2022-10-12T05:54:35Z","53963" +"*openGoldenTicketDialog*",".{0,1000}openGoldenTicketDialog.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53964" +"*openKeystrokeBrowser*",".{0,1000}openKeystrokeBrowser.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53966" +"*openPayloadGenerator*",".{0,1000}openPayloadGenerator.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","53967" +"*openPayloadGeneratorDialog*",".{0,1000}openPayloadGeneratorDialog.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53968" +"*openPayloadHelper*",".{0,1000}openPayloadHelper.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53969" +"*openPortScanner*",".{0,1000}openPortScanner.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","53970" +"*openPortScanner*",".{0,1000}openPortScanner.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53971" +"*openSpearPhishDialog*",".{0,1000}openSpearPhishDialog.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53972" +"*openssl_heartbleed.rb*",".{0,1000}openssl_heartbleed\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","53973" +"*openssl2john.py*",".{0,1000}openssl2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53974" +"*openwall.John.appdata.xml*",".{0,1000}openwall\.John\.appdata\.xml.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53978" +"*openwall.John.desktop*",".{0,1000}openwall\.John\.desktop.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53979" +"*openwall/john*",".{0,1000}openwall\/john.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53980" +"*openWindowsExecutableStage*",".{0,1000}openWindowsExecutableStage.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53981" +"*OperaPassView.exe*",".{0,1000}OperaPassView\.exe.{0,1000}","offensive_tool_keyword","OperaPassView","OperaPassView is a small password recovery tool that decrypts the content of the Opera Web browser password file (wand.dat) and displays the list of all Web site passwords stored in this file","T1003 - T1555 - T1145","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/opera_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53985" +"*ophcrack*",".{0,1000}ophcrack.{0,1000}","offensive_tool_keyword","ophcrack","Windows password cracker based on rainbow tables.","T1110.003 - T1555.003 - T1110.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://gitlab.com/objectifsecurite/ophcrack","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","53988" +"*o-printernightmare.ps1*",".{0,1000}o\-printernightmare\.ps1.{0,1000}","offensive_tool_keyword","Invoke-Stealth","Simple & Powerful PowerShell Script Obfuscator","T1027.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/JoelGMSec/Invoke-Stealth","1","1","N/A","N/A","9","6","559","81","2023-04-21T12:49:37Z","2021-04-13T10:22:05Z","53989" +"*optiv/Ivy.git*",".{0,1000}optiv\/Ivy\.git.{0,1000}","offensive_tool_keyword","ivy","Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory","T1059 - T1204 - T1547","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/optiv/Ivy","1","1","N/A","N/A","10","8","744","129","2023-08-18T17:30:14Z","2021-11-18T18:29:20Z","53992" +"*optiv/Registry-Recon*",".{0,1000}optiv\/Registry\-Recon.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor Script that Performs System/AV/EDR Recon","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/optiv/Registry-Recon","1","1","N/A","N/A","10","10","325","36","2022-06-06T14:39:12Z","2021-07-29T18:47:23Z","53993" +"*optiv/ScareCrow*",".{0,1000}optiv\/ScareCrow.{0,1000}","offensive_tool_keyword","cobaltstrike","ScareCrow - Payload creation framework designed around EDR bypass.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/optiv/ScareCrow","1","1","N/A","N/A","10","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","53994" +"*optiv/ScareCrow*",".{0,1000}optiv\/ScareCrow.{0,1000}","offensive_tool_keyword","ScareCrow","ScareCrow - Payload creation framework designed around EDR bypass.","T1548 - T1562 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/optiv/ScareCrow","1","1","N/A","N/A","N/A","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","53995" +"*oqwygprskqv65j72.13gpqd.top*",".{0,1000}oqwygprskqv65j72\.13gpqd\.top.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","53996" +"*oqwygprskqv65j72.1hbdbx.top*",".{0,1000}oqwygprskqv65j72\.1hbdbx\.top.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","53997" +"*oqwygprskqv65j72.1jfniy.top*",".{0,1000}oqwygprskqv65j72\.1jfniy\.top.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","53998" +"*oqwygprskqv65j72.1jitcy.top*",".{0,1000}oqwygprskqv65j72\.1jitcy\.top.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","53999" +"*oqwygprskqv65j72.1ldyev.top*",".{0,1000}oqwygprskqv65j72\.1ldyev\.top.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","54000" +"*oqwygprskqv65j72.onion*",".{0,1000}oqwygprskqv65j72\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","54001" +"*oracle_default_hashes.txt*",".{0,1000}oracle_default_hashes\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54002" +"*oracle_default_passwords.csv*",".{0,1000}oracle_default_passwords\.csv.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54003" +"*Orange-Cyberdefense/arsenal*",".{0,1000}Orange\-Cyberdefense\/arsenal.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","54004" +"*Orange-Cyberdefense/KeePwn*",".{0,1000}Orange\-Cyberdefense\/KeePwn.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","54005" +"*Orange-Cyberdefense/KeePwn*",".{0,1000}Orange\-Cyberdefense\/KeePwn.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","54006" +"*Orange-Cyberdefense/LinikatzV2*",".{0,1000}Orange\-Cyberdefense\/LinikatzV2.{0,1000}","offensive_tool_keyword","LinikatzV2","linikatz is a tool to attack AD on UNIX","T1003.002 - T1558.003 - T1078 - T1550.001","TA0006 - TA0001 - TA0004 - TA0003","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/LinikatzV2","1","1","#linux","N/A","10","2","146","15","2023-10-19T12:26:58Z","2023-10-19T11:07:53Z","54007" +"*orbitaldump.py*",".{0,1000}orbitaldump\.py.{0,1000}","offensive_tool_keyword","orbitaldump","A simple multi-threaded distributed SSH brute-forcing tool written in Python.","T1110","TA0006","N/A","N/A","Exploitation tool","https://github.com/k4yt3x/orbitaldump","1","1","N/A","N/A","N/A","5","460","83","2022-10-30T23:40:57Z","2021-06-06T17:48:19Z","54008" +"*orbitaldump/orbitaldump*",".{0,1000}orbitaldump\/orbitaldump.{0,1000}","offensive_tool_keyword","orbitaldump","A simple multi-threaded distributed SSH brute-forcing tool written in Python.","T1110","TA0006","N/A","N/A","Exploitation tool","https://github.com/k4yt3x/orbitaldump","1","1","N/A","N/A","N/A","5","460","83","2022-10-30T23:40:57Z","2021-06-06T17:48:19Z","54009" +"*OS-Command-Injection-Unix-Payloads.*",".{0,1000}OS\-Command\-Injection\-Unix\-Payloads\..{0,1000}","offensive_tool_keyword","Offensive-Payloads","List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.","T1210 - T1185 - T1059 - T1400 - T1506 - T1213 ","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/InfoSecWarrior/Offensive-Payloads/","1","1","N/A","N/A","N/A","4","328","117","2024-09-20T09:59:28Z","2022-11-18T09:43:41Z","54014" +"*OS-Command-Injection-Windows-Payloads.*",".{0,1000}OS\-Command\-Injection\-Windows\-Payloads\..{0,1000}","offensive_tool_keyword","Offensive-Payloads","List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.","T1210 - T1185 - T1059 - T1400 - T1506 - T1213 ","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/InfoSecWarrior/Offensive-Payloads/","1","1","N/A","N/A","N/A","4","328","117","2024-09-20T09:59:28Z","2022-11-18T09:43:41Z","54015" +"*OSCP-Archives*",".{0,1000}OSCP\-Archives.{0,1000}","offensive_tool_keyword","OSCP-Archives","resources for red teamers 'During my journey to getting the OSCP. I always come across many articles. Git repo. videos. and other types of sources of great and valuable information that helps me during my studies. While having all of these in a bookmark folder is great. I wanted to also build a curated list of the resources that I've collected overtime. all in one area for everyone to access.'","T1593 - T1592 - T1596","TA0001 - TA0043 - ","N/A","N/A","Exploitation tool","https://github.com/CyDefUnicorn/OSCP-Archives","1","1","N/A","N/A","N/A","7","620","194","2020-09-14T13:01:57Z","2018-09-15T16:18:05Z","54016" +"*osx/dump_keychain*",".{0,1000}osx\/dump_keychain.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54026" +"*osx/x64/meterpreter/reverse_tcp*",".{0,1000}osx\/x64\/meterpreter\/reverse_tcp.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","54027" +"*osx/x64/meterpreter_reverse_tcp*",".{0,1000}osx\/x64\/meterpreter_reverse_tcp.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","54028" +"*osx/x64/shell_reverse_tcp*",".{0,1000}osx\/x64\/shell_reverse_tcp.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","54029" +"*osx_gatekeeper_bypass.*",".{0,1000}osx_gatekeeper_bypass\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54030" +"*OtterHacker/SetProcessInjection*",".{0,1000}OtterHacker\/SetProcessInjection.{0,1000}","offensive_tool_keyword","SetProcessInjection","alternate technique allowing execution at an arbitrary memory address on a remote process that can be used to replace the standard CreateRemoteThread call.","T1055 - T1055.008 - T1055.001 - T1055.002 - T1055.012","TA0005 - TA0004 - TA0002","N/A","N/A","Defense Evasion","https://github.com/OtterHacker/SetProcessInjection","1","1","N/A","N/A","9","2","151","27","2023-10-02T09:23:42Z","2023-10-02T08:21:47Z","54031" +"*Out-CompressedDll.ps1*",".{0,1000}Out\-CompressedDll\.ps1.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","54037" +"*Out-CompressedDLL.ps1*",".{0,1000}Out\-CompressedDLL\.ps1.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","54038" +"*Out-DnsTxt.ps1*",".{0,1000}Out\-DnsTxt\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","54039" +"*Out-EncodedAsciiCommand.ps1*",".{0,1000}Out\-EncodedAsciiCommand\.ps1.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","54041" +"*Out-EncodedBinaryCommand.*",".{0,1000}Out\-EncodedBinaryCommand\..{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","54042" +"*Out-EncodedBXORCommand*",".{0,1000}Out\-EncodedBXORCommand.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","54044" +"*Out-EncodedHexCommand.*",".{0,1000}Out\-EncodedHexCommand\..{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","54046" +"*Out-EncodedOctalCommand.*",".{0,1000}Out\-EncodedOctalCommand\..{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","54047" +"*Out-EncodedSpecialCharOnlyCommand*",".{0,1000}Out\-EncodedSpecialCharOnlyCommand.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","54049" +"*Out-EncodedWhitespaceCommand*",".{0,1000}Out\-EncodedWhitespaceCommand.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","54051" +"*outflank_stage1.implant*",".{0,1000}outflank_stage1\.implant.{0,1000}","offensive_tool_keyword","RemotePipeList","A small tool that can list the named pipes bound on a remote system.","T1047 - T1021.006","TA0008 - TA0002","N/A","N/A","Discovery","https://github.com/outflanknl/C2-Tool-Collection/tree/main/Other/RemotePipeList","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","54052" +"*Outflank-Dumpert*",".{0,1000}Outflank\-Dumpert.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","54053" +"*Outflank-Dumpert.*",".{0,1000}Outflank\-Dumpert\..{0,1000}","offensive_tool_keyword","cobaltstrike","LSASS memory dumper using direct system calls and API unhooking.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Dumpert/tree/master/Dumpert-Aggressor","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","54054" +"*outflanknl/Dumpert*",".{0,1000}outflanknl\/Dumpert.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","54055" +"*outflanknl/EvilClippy*",".{0,1000}outflanknl\/EvilClippy.{0,1000}","offensive_tool_keyword","EvilClippy","A cross-platform assistant for creating malicious MS Office documents","T1566.001 - T1059.001 - T1204.002","TA0004 - TA0002","N/A","N/A","Phishing","https://github.com/outflanknl/EvilClippy","1","1","N/A","N/A","10","10","2165","402","2023-12-27T12:37:47Z","2019-03-26T12:14:03Z","54056" +"*outflanknl/Net-GPPPassword*",".{0,1000}outflanknl\/Net\-GPPPassword.{0,1000}","offensive_tool_keyword","Net-GPPPassword",".NET implementation of Get-GPPPassword. Retrieves the plaintext password and other information for accounts pushed through Group Policy Preferences.","T1059.001 - T1552.007","TA0002 - TA0006","N/A","N/A","Credential Access","https://github.com/outflanknl/Net-GPPPassword","1","1","N/A","N/A","10","2","172","36","2019-12-18T10:14:32Z","2019-10-14T12:35:46Z","54057" +"*outflanknl/NetshHelperBeacon*",".{0,1000}outflanknl\/NetshHelperBeacon.{0,1000}","offensive_tool_keyword","NetshHelperBeacon","DLL to load from Windows NetShell. Will pop calc and execute shellcode.","T1055 - T1218","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/outflanknl/NetshHelperBeacon","1","1","N/A","N/A","10","2","179","36","2016-09-26T19:57:08Z","2016-09-26T12:52:02Z","54058" +"*outflanknl/PrintNightmare*",".{0,1000}outflanknl\/PrintNightmare.{0,1000}","offensive_tool_keyword","PrintNightmare","PrintNightmare exploitation","T1210 - T1059.001 - T1548.002","TA0001 - TA0002 - TA0004","N/A","Dispossessor","Privilege Escalation","https://github.com/outflanknl/PrintNightmare","1","1","N/A","N/A","10","4","337","67","2021-09-13T08:45:26Z","2021-09-13T08:44:02Z","54059" +"*outflanknl/Recon-AD*",".{0,1000}outflanknl\/Recon\-AD.{0,1000}","offensive_tool_keyword","cobaltstrike","Recon-AD an AD recon tool based on ADSI and reflective DLL s","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","10","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","54060" +"*outflanknl/Recon-AD*",".{0,1000}outflanknl\/Recon\-AD.{0,1000}","offensive_tool_keyword","Recon-AD","AD recon tool based on ADSI and reflective DLL","T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","8","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","54061" +"*outflanknl/SharpHide*",".{0,1000}outflanknl\/SharpHide.{0,1000}","offensive_tool_keyword","SharpHide","Tool to create hidden registry keys","T1112 - T1562 - T1562.001","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/outflanknl/SharpHide","1","1","N/A","N/A","9","5","480","96","2019-10-23T10:44:22Z","2019-10-20T14:25:47Z","54062" +"*outflanknl/Spray-AD*",".{0,1000}outflanknl\/Spray\-AD.{0,1000}","offensive_tool_keyword","cobaltstrike","A Cobalt Strike tool to audit Active Directory user accounts for weak - well known or easy guessable passwords.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Spray-AD","1","1","N/A","N/A","10","10","436","54","2022-04-01T07:03:39Z","2020-01-09T10:10:48Z","54063" +"*outflanknl/WdToggle*",".{0,1000}outflanknl\/WdToggle.{0,1000}","offensive_tool_keyword","cobaltstrike","A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/WdToggle","1","1","N/A","N/A","10","10","219","31","2023-05-03T19:51:43Z","2020-12-23T13:42:25Z","54064" +"*Outflank-Recon-AD*",".{0,1000}Outflank\-Recon\-AD.{0,1000}","offensive_tool_keyword","cobaltstrike","Recon-AD an AD recon tool based on ADSI and reflective DLL s","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","10","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","54065" +"*OutlookEmailAbuse.ps1*",".{0,1000}OutlookEmailAbuse\.ps1.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","54066" +"*Out-Minidump.ps1*",".{0,1000}Out\-Minidump\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1065","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","54069" +"*Out-Minidump.ps1*",".{0,1000}Out\-Minidump\.ps1.{0,1000}","offensive_tool_keyword","link","link is a command and control framework written in rust","T1071 - T1094 - T1132 - T1008 - T1024","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/postrequest/link","1","1","N/A","N/A","10","10","575","90","2021-08-18T11:53:55Z","2021-02-02T11:15:43Z","54070" +"*Out-ObfuscatedAst.ps1*",".{0,1000}Out\-ObfuscatedAst\.ps1.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","54078" +"*Out-ObfuscatedAst.ps1*",".{0,1000}Out\-ObfuscatedAst\.ps1.{0,1000}","offensive_tool_keyword","PSAmsi","PSAmsi is a tool for auditing and defeating AMSI signatures.","T1059.001 - T1562.001 - T1070.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/cobbr/PSAmsi","1","1","N/A","N/A","7","4","390","74","2018-04-22T20:56:33Z","2017-09-22T11:48:47Z","54079" +"*Out-ObfuscatedStringCommand.ps1*",".{0,1000}Out\-ObfuscatedStringCommand\.ps1.{0,1000}","offensive_tool_keyword","PSAmsi","PSAmsi is a tool for auditing and defeating AMSI signatures.","T1059.001 - T1562.001 - T1070.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/cobbr/PSAmsi","1","1","N/A","N/A","7","4","390","74","2018-04-22T20:56:33Z","2017-09-22T11:48:47Z","54195" +"*Out-ObfuscatedTokenCommand.ps1*",".{0,1000}Out\-ObfuscatedTokenCommand\.ps1.{0,1000}","offensive_tool_keyword","PSAmsi","PSAmsi is a tool for auditing and defeating AMSI signatures.","T1059.001 - T1562.001 - T1070.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/cobbr/PSAmsi","1","1","N/A","N/A","7","4","390","74","2018-04-22T20:56:33Z","2017-09-22T11:48:47Z","54207" +"*Out-PasteBin.ps1*",".{0,1000}Out\-PasteBin\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","54229" +"*output/html/data/beacons.json*",".{0,1000}output\/html\/data\/beacons\.json.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","54256" +"*output/payloads/*",".{0,1000}output\/payloads\/.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","54262" +"*output/RatChatPT_unix*",".{0,1000}output\/RatChatPT_unix.{0,1000}","offensive_tool_keyword","ratchatpt","C2 using openAI API","T1094 - T1071.001","TA0011 - TA0002","N/A","N/A","C2","https://github.com/spartan-conseil/ratchatpt","1","1","N/A","risk of False positive","10","10","16","6","2023-06-09T12:39:00Z","2023-06-09T09:19:10Z","54263" +"*Out-RundllCommand*",".{0,1000}Out\-RundllCommand.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","54274" +"*OWASP/Amass*",".{0,1000}OWASP\/Amass.{0,1000}","offensive_tool_keyword","Amass","The OWASP Amass Project performs network mapping of attack surfaces and external asset discovery using open source information gathering and active reconnaissance techniques.","T1595 - T1596 - T1018 - T1482","TA0007 - TA0043 - ","N/A","EMBER BEAR","Reconnaissance","https://github.com/caffix/amass","1","1","#linux","N/A","5","","N/A","","","","54280" +"*OwnerPersist-POST.*",".{0,1000}OwnerPersist\-POST\..{0,1000}","offensive_tool_keyword","MicroBurst","A collection of scripts for assessing Microsoft Azure security","T1583 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","Scattered Spider*","Exploitation tool","https://github.com/NetSPI/MicroBurst","1","1","N/A","N/A","6","10","2143","320","2025-03-19T17:07:24Z","2018-07-16T16:47:20Z","54281" +"*Ox-Bruter.pl*",".{0,1000}Ox\-Bruter\.pl.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://raw.githubusercontent.com/Sup3r-Us3r/scripts/master/fb-brute.pl","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","54282" +"*OxidResolver.exe*",".{0,1000}OxidResolver\.exe.{0,1000}","offensive_tool_keyword","SharpOxidResolver","search the current domain for computers and get bindings for all of them","T1018 - T1046 - T1016","TA0007","N/A","KNOTWEED","Discovery","https://github.com/S3cur3Th1sSh1t/SharpOxidResolver","1","1","N/A","N/A","9","1","50","9","2020-11-25T08:42:06Z","2020-11-25T08:23:23Z","54283" +"*p0dalirius/Coercer*",".{0,1000}p0dalirius\/Coercer.{0,1000}","offensive_tool_keyword","ADCSKiller","ADCSKiller is a Python-based tool designed to automate the process of discovering and exploiting Active Directory Certificate Services (ADCS) vulnerabilities. It leverages features of Certipy and Coercer to simplify the process of attacking ADCS infrastructure","T1552.004 - T1003.003 - T1114.002 - T1649","TA0006 - TA0003 - TA0005","N/A","N/A","Exploitation tool","https://github.com/grimlockx/ADCSKiller","1","1","N/A","N/A","N/A","8","710","70","2023-05-19T17:36:37Z","2023-05-19T06:51:41Z","54286" +"*p0dalirius/Coercer*",".{0,1000}p0dalirius\/Coercer.{0,1000}","offensive_tool_keyword","Coercer","A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through many methods.","T1110 - T1021 - T1020","TA0006 - TA0010","N/A","N/A","Exploitation tool","https://github.com/p0dalirius/Coercer","1","1","N/A","N/A","10","10","1945","195","2025-03-21T07:42:42Z","2022-06-30T16:52:33Z","54287" +"*p0dalirius/ExtractBitlockerKeys*",".{0,1000}p0dalirius\/ExtractBitlockerKeys.{0,1000}","offensive_tool_keyword","ExtractBitlockerKeys","A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.","T1003.002 - T1039 - T1087.002","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/p0dalirius/ExtractBitlockerKeys","1","1","N/A","N/A","10","4","368","54","2025-01-31T09:39:55Z","2023-09-19T07:28:11Z","54288" +"*p0dalirius/LDAPWordlistHarvester*",".{0,1000}p0dalirius\/LDAPWordlistHarvester.{0,1000}","offensive_tool_keyword","LDAPWordlistHarvester","A tool to generate a wordlist from the information present in LDAP in order to crack passwords of domain accounts.","T1210.001 - T1087.003 - T1110","TA0001 - TA0006 - TA0007","N/A","Black Basta","Credential Access","https://github.com/p0dalirius/LDAPWordlistHarvester","1","1","N/A","N/A","5","","N/A","","","","54289" +"*p0dalirius/pyLAPS*",".{0,1000}p0dalirius\/pyLAPS.{0,1000}","offensive_tool_keyword","pyLAPS","A simple way to read and write LAPS passwords from linux.","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/p0dalirius/pyLAPS","1","1","#linux","N/A","9","2","105","16","2024-10-28T08:36:38Z","2021-10-05T18:35:21Z","54290" +"*p0f/p0f.fp*",".{0,1000}p0f\/p0f\.fp.{0,1000}","offensive_tool_keyword","p0f","P0f is a tool that utilizes an array of sophisticated purely passive traffic fingerprinting mechanisms to identify the players behind any incidental TCP/IP communications","T1046 - T1040","TA0007 - TA0010","N/A","N/A","Sniffing & Spoofing","https://www.kali.org/tools/p0f/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","54292" +"*p0wnedADAttacks.cs*",".{0,1000}p0wnedADAttacks\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54294" +"*p0wnedAmsiBypass.cs*",".{0,1000}p0wnedAmsiBypass\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54295" +"*p0wnedAwareness.cs*",".{0,1000}p0wnedAwareness\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54296" +"*p0wnedBinaries.cs*",".{0,1000}p0wnedBinaries\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54297" +"*p0wnedCredentialUI.cs*",".{0,1000}p0wnedCredentialUI\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54298" +"*p0wnedEasySystem.cs*",".{0,1000}p0wnedEasySystem\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54299" +"*p0wnedExecute.cs*",".{0,1000}p0wnedExecute\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54300" +"*p0wnedExploits.cs*",".{0,1000}p0wnedExploits\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54301" +"*p0wnedExtensionMethods.cs*",".{0,1000}p0wnedExtensionMethods\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54302" +"*p0wnedHost.cs*",".{0,1000}p0wnedHost\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54303" +"*p0wnedHostUserInterface.cs*",".{0,1000}p0wnedHostUserInterface\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54304" +"*p0wnedHostUtilities.cs*",".{0,1000}p0wnedHostUtilities\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54305" +"*p0wnedInveigh.cs*",".{0,1000}p0wnedInveigh\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54306" +"*P0wnedListener.Exe*",".{0,1000}P0wnedListener\.Exe.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54307" +"*p0wnedListenerConsole.cs*",".{0,1000}p0wnedListenerConsole\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54308" +"*p0wnedMasq.cs*",".{0,1000}p0wnedMasq\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54309" +"*p0wnedMeter.cs*",".{0,1000}p0wnedMeter\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54310" +"*p0wnedMeter.Menu*",".{0,1000}p0wnedMeter\.Menu.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54311" +"*p0wnedMov.cs*",".{0,1000}p0wnedMov\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54312" +"*p0wnedPELoader.cs*",".{0,1000}p0wnedPELoader\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54313" +"*p0wnedPotato.cs*",".{0,1000}p0wnedPotato\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54314" +"*p0wnedPowerCat.cs*",".{0,1000}p0wnedPowerCat\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54315" +"*p0wnedPPID.cs*",".{0,1000}p0wnedPPID\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54316" +"*p0wnedRawUserInterface.cs*",".{0,1000}p0wnedRawUserInterface\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54317" +"*p0wnedResources.cs*",".{0,1000}p0wnedResources\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54318" +"*p0wnedRoast.cs*",".{0,1000}p0wnedRoast\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54319" +"*p0wnedShell*",".{0,1000}p0wnedShell.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54320" +"*p0wnedShell.cs*",".{0,1000}p0wnedShell\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54321" +"*p0wnedShellx64.exe*",".{0,1000}p0wnedShellx64\.exe.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54322" +"*p0wnedShellx86.exe*",".{0,1000}p0wnedShellx86\.exe.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54323" +"*p0wnedSystem.cs*",".{0,1000}p0wnedSystem\.cs.{0,1000}","offensive_tool_keyword","p0wnedShell","p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an ?all in one? Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off). and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.","T1086 - T1059 - T1106 - T1566","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Cn33liz/p0wnedShell","1","1","N/A","N/A","N/A","10","1535","335","2019-08-02T16:24:39Z","2015-12-25T11:44:37Z","54324" +"*p0wny-shell*",".{0,1000}p0wny\-shell.{0,1000}","offensive_tool_keyword","p0wny-shell","p0wny@shell:~# is a very basic. single-file. PHP shell. It can be used to quickly execute commands on a server when pentesting a PHP application. Use it with caution: this script represents a security risk for the server.","T1059 - T1027 - T1053 - T1035 - T1105","TA0002 - TA0003 - TA0008","N/A","N/A","C2","https://github.com/flozz/p0wny-shell","1","1","N/A","N/A","N/A","10","2362","659","2024-05-16T10:22:11Z","2016-11-09T20:41:01Z","54325" +"*p27dokhpz2n7nvgr.14udep.top*",".{0,1000}p27dokhpz2n7nvgr\.14udep\.top.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","54326" +"*p27dokhpz2n7nvgr.1aweql.top*",".{0,1000}p27dokhpz2n7nvgr\.1aweql\.top.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","54327" +"*p27dokhpz2n7nvgr.1axzcw.top*",".{0,1000}p27dokhpz2n7nvgr\.1axzcw\.top.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","54328" +"*p27dokhpz2n7nvgr.1hw36d.top*",".{0,1000}p27dokhpz2n7nvgr\.1hw36d\.top.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","54329" +"*p27dokhpz2n7nvgr.1jemdr.top*",".{0,1000}p27dokhpz2n7nvgr\.1jemdr\.top.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","54330" +"*p27dokhpz2n7nvgr.onion*",".{0,1000}p27dokhpz2n7nvgr\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","54331" +"*p3nt4/Invoke-SocksProxy*",".{0,1000}p3nt4\/Invoke\-SocksProxy.{0,1000}","offensive_tool_keyword","Invoke-SocksProxy","also known as PortStarter is a socks proxy and reverse socks server using powershell","T1090 - T1059.001 - T1102.003","TA0011 - TA0010 - TA0005 - TA0003","PortStarter","Vice Society - Conti","C2","https://github.com/p3nt4/Invoke-SocksProxy","1","1","N/A","N/A","10","10","788","169","2021-03-21T21:00:40Z","2017-11-09T06:20:40Z","54332" +"*p3nt4/Nuages*",".{0,1000}p3nt4\/Nuages.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","54333" +"*p5quu5ujzzswxv4nxyuhgg3fjj2vy2a3zmtcowalkip2temdfadanlyd.onion*",".{0,1000}p5quu5ujzzswxv4nxyuhgg3fjj2vy2a3zmtcowalkip2temdfadanlyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","54334" +"*pac2.localhost:9999*",".{0,1000}pac2\.localhost\:9999.{0,1000}","offensive_tool_keyword","pac2","PAC2 is a framework that generates arbitrary flows and sends and executes them on the Power Automate Platform - using Power automate as a C2","T1550.001 - T1204.002 - T1102 - T1071.001","TA0005 - TA0008 - TA0010- TA0011","N/A","N/A","C2","https://github.com/NTT-Security-Japan/pac2","1","1","N/A","N/A","6","10","6","1","2024-04-16T11:58:54Z","2024-03-01T08:06:32Z","54336" +"*pack_py_payload*",".{0,1000}pack_py_payload.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","54337" +"*package_cvs_into_lse.sh*",".{0,1000}package_cvs_into_lse\.sh.{0,1000}","offensive_tool_keyword","linux-smart-enumeration","Linux enumeration tool for privilege escalation and discovery","T1087.004 - T1016 - T1548.001 - T1046","TA0007 - TA0004 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/diego-treitos/linux-smart-enumeration","1","1","#linux","N/A","9","10","3575","584","2023-12-25T14:46:47Z","2019-02-13T11:02:21Z","54343" +"*package=impacket*",".{0,1000}package\=impacket.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","54344" +"*packers/invobf.py*",".{0,1000}packers\/invobf\.py.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","packer bundled","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","54349" +"*PackMyPayload.py*",".{0,1000}PackMyPayload\.py.{0,1000}","offensive_tool_keyword","PackMyPayload","A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats","T1027 - T1036 - T1048 - T1070 - T1096 - T1195","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/mgeeky/PackMyPayload/","1","1","N/A","N/A","10","10","912","143","2024-06-10T09:50:43Z","2022-02-08T19:26:28Z","54352" +"*PackMyPayload-master*",".{0,1000}PackMyPayload\-master.{0,1000}","offensive_tool_keyword","PackMyPayload","A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats","T1027 - T1036 - T1048 - T1070 - T1096 - T1195","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/mgeeky/PackMyPayload/","1","1","N/A","N/A","10","10","912","143","2024-06-10T09:50:43Z","2022-02-08T19:26:28Z","54353" +"*pacu-master.zip*",".{0,1000}pacu\-master\.zip.{0,1000}","offensive_tool_keyword","pacu","The AWS exploitation framework designed for testing the security of Amazon Web Services environments.","T1136.003 - T1190 - T1078.004","TA0006 - TA0001","N/A","Scattered Spider*","Framework","https://github.com/RhinoSecurityLabs/pacu","1","1","N/A","N/A","9","10","4651","731","2025-03-20T21:08:57Z","2018-06-13T21:58:59Z","54370" +"*padlock2john.py*",".{0,1000}padlock2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54372" +"*padre-master.zip*",".{0,1000}padre\-master\.zip.{0,1000}","offensive_tool_keyword","padre","padre?is an advanced exploiter for Padding Oracle attacks against CBC mode encryption","T1203 - T1059.003 - T1027.002","TA0005 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/glebarez/padre","1","1","N/A","N/A","8","3","253","24","2024-05-13T14:28:25Z","2019-12-30T13:52:03Z","54374" +"*panelqbinglxczi2gqkwderfvgq6bcv5cbjwxrksjtvr5xv7ozh5wqad.onion*",".{0,1000}panelqbinglxczi2gqkwderfvgq6bcv5cbjwxrksjtvr5xv7ozh5wqad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","54394" +"*ParamPamPam*",".{0,1000}ParamPamPam.{0,1000}","offensive_tool_keyword","ParamPamPam","This tool is used for brute discover GET and POST parameters.","T1110 - T1210 - T1211","TA0001 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/Bo0oM/ParamPamPam","1","1","N/A","N/A","N/A","3","277","61","2022-06-27T11:45:19Z","2018-11-10T08:38:30Z","54397" +"*pard0p/Cordyceps*",".{0,1000}pard0p\/Cordyceps.{0,1000}","offensive_tool_keyword","Cordyceps","C++ self-Injecting dropper based on various EDR evasion techniques","T1055 - T1055.001 - T1070.004 - T1564.001","TA0005 - TA0002 ","N/A","N/A","Defense Evasion","https://github.com/pard0p/Cordyceps","1","1","N/A","N/A","10","","N/A","","","","54400" +"*parrot*security.vdi*",".{0,1000}parrot.{0,1000}security\.vdi.{0,1000}","offensive_tool_keyword","parrot os","Parrot OS is a Debian-based. security-oriented Linux distribution that is designed for ethical hacking. penetration testing and digital forensics.","T1590 - T1200 - T1027 - T1578 - T1003 - T1001 - T1046 - T1570 - T1114 - T1105","TA0043 - TA0002 - TA0003 - TA0004 - TA0006 - TA0005 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation OS","https://www.parrotsec.org/download/","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","54403" +"*parrotsec.org/download/*",".{0,1000}parrotsec\.org\/download\/.{0,1000}","offensive_tool_keyword","parrot os","Parrot OS is a Debian-based. security-oriented Linux distribution that is designed for ethical hacking. penetration testing and digital forensics.","T1590 - T1200 - T1027 - T1578 - T1003 - T1001 - T1046 - T1570 - T1114 - T1105","TA0043 - TA0002 - TA0003 - TA0004 - TA0006 - TA0005 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation OS","https://www.parrotsec.org/download/","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","54404" +"*Parrot-security-*.iso*",".{0,1000}Parrot\-security\-.{0,1000}\.iso.{0,1000}","offensive_tool_keyword","parrot os","Parrot OS is a Debian-based. security-oriented Linux distribution that is designed for ethical hacking. penetration testing and digital forensics.","T1590 - T1200 - T1027 - T1578 - T1003 - T1001 - T1046 - T1570 - T1114 - T1105","TA0043 - TA0002 - TA0003 - TA0004 - TA0006 - TA0005 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation OS","https://www.parrotsec.org/download/","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","54405" +"*parse_aggressor_properties*",".{0,1000}parse_aggressor_properties.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","54407" +"*parse_shellcode*",".{0,1000}parse_shellcode.{0,1000}","offensive_tool_keyword","cobaltstrike","A protective and Low Level Shellcode Loader that defeats modern EDR systems.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/cribdragg3r/Alaris","1","1","N/A","N/A","10","10","903","142","2024-03-20T15:50:57Z","2020-02-22T15:42:37Z","54410" +"*PassDetective-main.*",".{0,1000}PassDetective\-main\..{0,1000}","offensive_tool_keyword","PassDetective","PassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords - API keys and secrets","T1059 - T1059.004 - T1552 - T1552.001","TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/aydinnyunus/PassDetective","1","1","N/A","N/A","7","2","129","8","2024-06-19T10:39:39Z","2023-07-22T12:31:57Z","54417" +"*passhunt.exe*",".{0,1000}passhunt\.exe.{0,1000}","offensive_tool_keyword","PassHunt","PassHunt searches drives for documents that contain passwords or any other regular expression. Its designed to be a simple. standalone tool that can be run from a USB stick.","T1081 - T1083 - T1003 - T1039 - T1213","TA0003 - TA0010","N/A","N/A","Discovery","https://github.com/Dionach/PassHunt","1","1","N/A","N/A","N/A","1","63","30","2014-07-11T09:08:02Z","2014-07-11T08:46:20Z","54418" +"*passhunt.exe*",".{0,1000}passhunt\.exe.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","54419" +"*passhunt.py*",".{0,1000}passhunt\.py.{0,1000}","offensive_tool_keyword","PassHunt","PassHunt searches drives for documents that contain passwords or any other regular expression. Its designed to be a simple. standalone tool that can be run from a USB stick.","T1081 - T1083 - T1003 - T1039 - T1213","TA0003 - TA0010","N/A","N/A","Discovery","https://github.com/Dionach/PassHunt","1","1","N/A","N/A","N/A","1","63","30","2014-07-11T09:08:02Z","2014-07-11T08:46:20Z","54420" +"*passivex.asm*",".{0,1000}passivex\.asm.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54421" +"*passivex.dll*",".{0,1000}passivex\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54422" +"*passphrase-rule1.rule*",".{0,1000}passphrase\-rule1\.rule.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54423" +"*passphrase-rule2.rule*",".{0,1000}passphrase\-rule2\.rule.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54424" +"*PassSpray.ps1*",".{0,1000}PassSpray\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","54426" +"*PassTheCert.exe*",".{0,1000}PassTheCert\.exe.{0,1000}","offensive_tool_keyword","PassTheCert","tool to authenticate to an LDAP/S server with a certificate through Schannel","T1557 - T1071 - T1021 - T1213 - T1649","TA0006 - TA0008 - TA0009","N/A","Black Basta","Lateral Movement","https://github.com/AlmondOffSec/PassTheCert","1","1","N/A","N/A","10","7","618","76","2024-07-08T22:37:30Z","2022-04-29T09:08:32Z","54430" +"*PassTheCert.exe*",".{0,1000}PassTheCert\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","54431" +"*passthecert.py*",".{0,1000}passthecert\.py.{0,1000}","offensive_tool_keyword","PassTheCert","tool to authenticate to an LDAP/S server with a certificate through Schannel","T1557 - T1071 - T1021 - T1213 - T1649","TA0006 - TA0008 - TA0009","N/A","Black Basta","Lateral Movement","https://github.com/AlmondOffSec/PassTheCert","1","1","N/A","N/A","10","7","618","76","2024-07-08T22:37:30Z","2022-04-29T09:08:32Z","54433" +"*PassTheChallenge.cpp*",".{0,1000}PassTheChallenge\.cpp.{0,1000}","offensive_tool_keyword","PassTheChallenge","Recovering NTLM hashes from Credential Guard","T1003 - T1555.002","TA0006 - TA0005","N/A","N/A","Exploitation tool","https://github.com/ly4k/PassTheChallenge","1","1","N/A","N/A","9","4","334","21","2022-12-26T01:09:18Z","2022-12-26T00:56:40Z","54435" +"*PassTheChallenge.exe*",".{0,1000}PassTheChallenge\.exe.{0,1000}","offensive_tool_keyword","PassTheChallenge","Recovering NTLM hashes from Credential Guard","T1003 - T1555.002","TA0006 - TA0005","N/A","N/A","Exploitation tool","https://github.com/ly4k/PassTheChallenge","1","1","N/A","N/A","9","4","334","21","2022-12-26T01:09:18Z","2022-12-26T00:56:40Z","54436" +"*PassTheChallenge.pdb*",".{0,1000}PassTheChallenge\.pdb.{0,1000}","offensive_tool_keyword","PassTheChallenge","Recovering NTLM hashes from Credential Guard","T1003 - T1555.002","TA0006 - TA0005","N/A","N/A","Exploitation tool","https://github.com/ly4k/PassTheChallenge","1","1","N/A","N/A","9","4","334","21","2022-12-26T01:09:18Z","2022-12-26T00:56:40Z","54437" +"*PassTheChallenge.sln*",".{0,1000}PassTheChallenge\.sln.{0,1000}","offensive_tool_keyword","PassTheChallenge","Recovering NTLM hashes from Credential Guard","T1003 - T1555.002","TA0006 - TA0005","N/A","N/A","Exploitation tool","https://github.com/ly4k/PassTheChallenge","1","1","N/A","N/A","9","4","334","21","2022-12-26T01:09:18Z","2022-12-26T00:56:40Z","54438" +"*PassTheChallenge.vcxproj*",".{0,1000}PassTheChallenge\.vcxproj.{0,1000}","offensive_tool_keyword","PassTheChallenge","Recovering NTLM hashes from Credential Guard","T1003 - T1555.002","TA0006 - TA0005","N/A","N/A","Exploitation tool","https://github.com/ly4k/PassTheChallenge","1","1","N/A","N/A","9","4","334","21","2022-12-26T01:09:18Z","2022-12-26T00:56:40Z","54439" +"*passthehashbrowns/BOFMask*",".{0,1000}passthehashbrowns\/BOFMask.{0,1000}","offensive_tool_keyword","BOFMask","BOFMask is a proof-of-concept for masking Cobalt Strike's Beacon payload while executing a Beacon Object File (BOF)","T1547.001 - T1055 - T1027 - T1105 - T1047","TA0002 - TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/passthehashbrowns/BOFMask","1","1","N/A","N/A","10","2","120","27","2023-06-28T14:35:32Z","2023-06-27T21:19:22Z","54441" +"*passware-kit-forensic.sls*",".{0,1000}passware\-kit\-forensic\.sls.{0,1000}","offensive_tool_keyword","Passware Kit Forensic","Passware Kit Forensic is the complete encrypted electronic evidence discovery solution that reports and decrypts all password-protected items on a computer","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.passware.com/kit-forensic/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","54443" +"*PasswareKitForensic_*_Setup.dmg*",".{0,1000}PasswareKitForensic_.{0,1000}_Setup\.dmg.{0,1000}","offensive_tool_keyword","Passware Kit Forensic","Passware Kit Forensic is the complete encrypted electronic evidence discovery solution that reports and decrypts all password-protected items on a computer","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.passware.com/kit-forensic/","1","1","#macos","N/A","N/A","N/A","N/A","N/A","N/A","N/A","54444" +"*PasswareKitForensic_*_Setup.msi*",".{0,1000}PasswareKitForensic_.{0,1000}_Setup\.msi.{0,1000}","offensive_tool_keyword","Passware Kit Forensic","Passware Kit Forensic is the complete encrypted electronic evidence discovery solution that reports and decrypts all password-protected items on a computer","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.passware.com/kit-forensic/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","54445" +"*passware-kit-forensic-64bit.msi*",".{0,1000}passware\-kit\-forensic\-64bit\.msi.{0,1000}","offensive_tool_keyword","Passware Kit Forensic","Passware Kit Forensic is the complete encrypted electronic evidence discovery solution that reports and decrypts all password-protected items on a computer","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.passware.com/kit-forensic/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","54446" +"*password_box.py*",".{0,1000}password_box\.py.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","54462" +"*password_cracker.rb*",".{0,1000}password_cracker\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54463" +"*password_crackers*",".{0,1000}password_crackers.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54464" +"*Password_Cracking.sh*",".{0,1000}Password_Cracking\.sh.{0,1000}","offensive_tool_keyword","AutoC2","AutoC2 is a bash script written to install all of the red team tools that you know and love","T1059.004 - T1129 - T1486","TA0005 - TA0002 - TA0040","N/A","N/A","Exploitation tool","https://github.com/assume-breach/Home-Grown-Red-Team/tree/main/AutoC2","1","1","N/A","N/A","10","8","707","112","2024-03-22T12:32:22Z","2022-03-23T15:52:41Z","54465" +"*password_prompt_spoof.md*",".{0,1000}password_prompt_spoof\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54466" +"*PasswordBoxImplant*",".{0,1000}PasswordBoxImplant.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","54470" +"*Password-Default/service.txt*",".{0,1000}Password\-Default\/service\.txt.{0,1000}","offensive_tool_keyword","BruteSploit","BruteSploit is a collection of method for automated Generate. Bruteforce and Manipulation wordlist with interactive shell. That can be used during a penetration test to enumerate and maybe can be used in CTF for manipulation.combine.transform and permutation some words or file text","T1110","N/A","N/A","N/A","Exploitation tool","https://github.com/screetsec/BruteSploit","1","1","N/A","N/A","N/A","8","741","263","2020-04-05T00:29:26Z","2017-05-31T17:00:51Z","54471" +"*passwordfox.exe*",".{0,1000}passwordfox\.exe.{0,1000}","offensive_tool_keyword","passwordfox","recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox","T1555.003 - T1003 - T1083","TA0006 ","N/A","LockBit - GoGoogle - 8BASE - XDSpy","Credential Access","https://www.nirsoft.net/utils/passwordfox.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","54472" +"*passwordfox.zip*",".{0,1000}passwordfox\.zip.{0,1000}","offensive_tool_keyword","passwordfox","recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox","T1555.003 - T1003 - T1083","TA0006 ","N/A","LockBit - GoGoogle - 8BASE - XDSpy","Credential Access","https://www.nirsoft.net/utils/passwordfox.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","54473" +"*passwordfox-x64.zip*",".{0,1000}passwordfox\-x64\.zip.{0,1000}","offensive_tool_keyword","passwordfox","recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox","T1555.003 - T1003 - T1083","TA0006 ","N/A","LockBit - GoGoogle - 8BASE - XDSpy","Credential Access","https://www.nirsoft.net/utils/passwordfox.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","54474" +"*PasswordHashesView.exe*",".{0,1000}PasswordHashesView\.exe.{0,1000}","offensive_tool_keyword","PasswordHashesView","displays the SHA1 hash and the NTLM hash of the login password for users currently logged into your system","T1003 - T1081","TA0006","N/A","N/A","Credential Access","https://www.nirsoft.net/alpha/passwordhashesview-x64.zip","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","54475" +"*passwordhashesview.zip*",".{0,1000}passwordhashesview\.zip.{0,1000}","offensive_tool_keyword","PasswordHashesView","displays the SHA1 hash and the NTLM hash of the login password for users currently logged into your system","T1003 - T1081","TA0006","N/A","N/A","Credential Access","https://www.nirsoft.net/alpha/passwordhashesview-x64.zip","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","54476" +"*passwordhashesview-x64.zip*",".{0,1000}passwordhashesview\-x64\.zip.{0,1000}","offensive_tool_keyword","PasswordHashesView","displays the SHA1 hash and the NTLM hash of the login password for users currently logged into your system","T1003 - T1081","TA0006","N/A","N/A","Credential Access","https://www.nirsoft.net/alpha/passwordhashesview-x64.zip","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","54477" +"*password-hijaker.exe*",".{0,1000}password\-hijaker\.exe.{0,1000}","offensive_tool_keyword","WebSocketReverseShellDotNet","A .NET-based Reverse Shell, it establishes a link to the command and control for subsequent guidance.","T1071 - T1105","TA0011 - TA0002","N/A","N/A","C2","https://github.com/The-Hustler-Hattab/WebSocketReverseShellDotNet","1","1","N/A","N/A","10","10","1","0","2024-04-18T01:00:48Z","2023-12-03T03:35:24Z","54478" +"*Passwords/Leaked-Databases*.txt*",".{0,1000}Passwords\/Leaked\-Databases.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","54481" +"*Passwords_in_description.txt*",".{0,1000}Passwords_in_description\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","54482" +"*passwordspray*--user-as-pass*",".{0,1000}passwordspray.{0,1000}\-\-user\-as\-pass.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","54485" +"*passwordspray.go*",".{0,1000}passwordspray\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","54486" +"*passwordSprayCmd*",".{0,1000}passwordSprayCmd.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","54487" +"*Patch-AMSI.*",".{0,1000}Patch\-AMSI\..{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","54500" +"*patchAmsiOpenSession*",".{0,1000}patchAmsiOpenSession.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF - Bypass AMSI in a remote process with code injection.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/injectAmsiBypass","1","1","N/A","N/A","10","10","378","69","2023-03-08T15:54:57Z","2021-07-19T00:08:21Z","54501" +"*patch-amsi-x64-powershell.ps1*",".{0,1000}patch\-amsi\-x64\-powershell\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","54502" +"*Patch-ETW.*",".{0,1000}Patch\-ETW\..{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","54503" +"*Pateensy/PaensyLib/*",".{0,1000}Pateensy\/PaensyLib\/.{0,1000}","offensive_tool_keyword","Pateensy","payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy","T1056.001 - T1200 - T1036 - T1071","TA0002 - TA0005 - TA0011 - TA0006","N/A","N/A","Exploitation tool","https://github.com/screetsec/Pateensy","1","1","N/A","N/A","N/A","2","143","60","2017-01-26T12:02:56Z","2016-03-21T07:29:38Z","54507" +"*pathhijack.py*",".{0,1000}pathhijack\.py.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","54512" +"*PaulNorman01/Forensia*",".{0,1000}PaulNorman01\/Forensia.{0,1000}","offensive_tool_keyword","Forensia","Anti Forensics Tool For Red Teamers - Used For Erasing Some Footprints In The Post Exploitation Phase","T1070.001 - T1070.002 - T1070.004 - T1070.006 - T1070.009 - T1564.004 - T1553.002 - T1027","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/PaulNorman01/Forensia","1","1","N/A","N/A","10","8","755","75","2023-06-23T23:23:22Z","2022-12-07T14:45:52Z","54513" +"*PaulSec/twittor*",".{0,1000}PaulSec\/twittor.{0,1000}","offensive_tool_keyword","twittor","A fully featured backdoor that uses Twitter as a C&C server ","T1105 - T1102 - T1041","TA0003 - TA0002 - TA0007","N/A","N/A","C2","https://github.com/PaulSec/twittor","1","1","N/A","N/A","10","10","771","217","2020-09-30T13:47:31Z","2015-09-09T07:23:25Z","54514" +"*payload.csproj*",".{0,1000}payload\.csproj.{0,1000}","offensive_tool_keyword","scshell","network pentestration test (shell)","T1071.001 - T1071.004 - T1046 - T1059 - T1024","TA0002 - TA0003 - TA0007","N/A","N/A","Lateral Movement","https://github.com/Mr-Un1k0d3r/SCShell","1","1","N/A","N/A","N/A","10","1484","248","2023-07-10T01:31:54Z","2019-11-13T23:39:27Z","54518" +"*payload/encryptor_remote.py*",".{0,1000}payload\/encryptor_remote\.py.{0,1000}","offensive_tool_keyword","SetProcessInjection","alternate technique allowing execution at an arbitrary memory address on a remote process that can be used to replace the standard CreateRemoteThread call.","T1055 - T1055.008 - T1055.001 - T1055.002 - T1055.012","TA0005 - TA0004 - TA0002","N/A","N/A","Defense Evasion","https://github.com/OtterHacker/SetProcessInjection","1","1","N/A","N/A","9","2","151","27","2023-10-02T09:23:42Z","2023-10-02T08:21:47Z","54520" +"*payload/pezor.py*",".{0,1000}payload\/pezor\.py.{0,1000}","offensive_tool_keyword","MetasploitCoop","Post-exploitation collaboration platform based on MSF","T1105 - T1098 - T1104 - T1136","TA0010 - TA0011 - TA0008","N/A","N/A","C2","https://github.com/0x727/MetasploitCoop-Backend","1","1","N/A","N/A","10","10","37","8","2021-08-17T10:26:17Z","2021-08-17T07:52:12Z","54521" +"*payload_bootstrap_hint*",".{0,1000}payload_bootstrap_hint.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","54523" +"*payload_creator.py*",".{0,1000}payload_creator\.py.{0,1000}","offensive_tool_keyword","hackingtool","ALL IN ONE Hacking Tool For Hackers","T1059 - T1078 - T1105 - T1110 - T1566","TA0002 - TA0008 - TA0009 - TA0005 - TA0007","N/A","N/A","Exploitation tool","https://github.com/Z4nzu/hackingtool","1","1","N/A","N/A","N/A","10","52217","5629","2025-03-03T15:17:19Z","2020-04-11T09:21:31Z","54524" +"*payload_encryption.py*",".{0,1000}payload_encryption\.py.{0,1000}","offensive_tool_keyword","FudgeC2","FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.","T1021.002 - T1105 - T1059.001 - T1059.003","TA0008 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/Ziconius/FudgeC2","1","1","N/A","N/A","10","10","253","54","2023-05-01T21:13:56Z","2018-09-09T21:05:21Z","54525" +"*payload_inject.rb*",".{0,1000}payload_inject\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54526" +"*payload_local*",".{0,1000}payload_local.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","54527" +"*payload_msf.exe*",".{0,1000}payload_msf\.exe.{0,1000}","offensive_tool_keyword","spellbound","Spellbound is a C2 (Command and Control) framework meant for creating a botnet. ","T1105 - T1132 - T1059.003 - T1094 - T1005","TA0011 - TA0009 - TA0010 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/mhuzaifi0604/spellbound","1","1","N/A","N/A","10","10","45","5","2023-09-22T10:52:53Z","2023-09-19T14:45:15Z","54529" +"*payload_scripts.cna*",".{0,1000}payload_scripts\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","54530" +"*payload_scripts/sleepmask*",".{0,1000}payload_scripts\/sleepmask.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","54531" +"*payload_section.cpp*",".{0,1000}payload_section\.cpp.{0,1000}","offensive_tool_keyword","cobaltstrike","Achieve execution using a custom keyboard layout","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/NtQuerySystemInformation/CustomKeyboardLayoutPersistence","1","1","N/A","N/A","10","","N/A","","","","54532" +"*payload_section.hpp*",".{0,1000}payload_section\.hpp.{0,1000}","offensive_tool_keyword","cobaltstrike","Achieve execution using a custom keyboard layout","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/NtQuerySystemInformation/CustomKeyboardLayoutPersistence","1","1","N/A","N/A","10","","N/A","","","","54533" +"*payload_spellshell.exe*",".{0,1000}payload_spellshell\.exe.{0,1000}","offensive_tool_keyword","spellbound","Spellbound is a C2 (Command and Control) framework meant for creating a botnet. ","T1105 - T1132 - T1059.003 - T1094 - T1005","TA0011 - TA0009 - TA0010 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/mhuzaifi0604/spellbound","1","1","N/A","N/A","10","10","45","5","2023-09-22T10:52:53Z","2023-09-19T14:45:15Z","54535" +"*payload_tidy.rb*",".{0,1000}payload_tidy\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54536" +"*Payload_Type/freyja/*",".{0,1000}Payload_Type\/freyja\/.{0,1000}","offensive_tool_keyword","mythic","mythic C2 agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/freyja/","1","1","N/A","N/A","10","10","54","13","2024-10-29T17:32:07Z","2022-09-28T17:20:04Z","54537" +"*PayloadCommsHost*",".{0,1000}PayloadCommsHost.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","54538" +"*--payload-cookie*",".{0,1000}\-\-payload\-cookie.{0,1000}","offensive_tool_keyword","SharpSocks","Tunnellable HTTP/HTTPS socks4a proxy written in C# and deployable via PowerShell","T1090 - T1021.001","TA0002","N/A","N/A","C2","https://github.com/nettitude/SharpSocks","1","1","N/A","N/A","10","10","482","84","2023-03-15T19:19:30Z","2017-11-10T13:29:08Z","54539" +"*Payload-Download-Cradles*",".{0,1000}Payload\-Download\-Cradles.{0,1000}","offensive_tool_keyword","Payload-Download-Cradles","This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context of download cradle detections.","T1105 - T1203 - T1221 - T1027 - T1036","TA0005 - TA0002 - TA0011 - TA0009","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Payload-Download-Cradles","1","1","N/A","N/A","N/A","3","256","51","2022-07-07T07:20:36Z","2021-05-14T08:56:54Z","54540" +"*PayloadFormat.ASSEMBLY*",".{0,1000}PayloadFormat\.ASSEMBLY.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","54541" +"*PayloadFormat.DLL*",".{0,1000}PayloadFormat\.DLL.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","54542" +"*PayloadFormat.EXE*",".{0,1000}PayloadFormat\.EXE.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","54543" +"*PayloadFormat.POWERSHELL*",".{0,1000}PayloadFormat\.POWERSHELL.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","54544" +"*PayloadFormat.SHELLCODE*",".{0,1000}PayloadFormat\.SHELLCODE.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","54545" +"*PayloadFormat.SVC_EXE*",".{0,1000}PayloadFormat\.SVC_EXE.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","54546" +"*payloadgenerator.py*",".{0,1000}payloadgenerator\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","54548" +"*Payload-Generator/trix-back-gen.zip*",".{0,1000}Payload\-Generator\/trix\-back\-gen\.zip.{0,1000}","offensive_tool_keyword","Powershell-Scripts-for-Hackers-and-Pentesters","","T1059.001 - T1119 - T1027 - T1016 - T1056.001","TA0002 - TA0009 - TA0005 - TA0007 - TA0010","N/A","N/A","Collection","https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters","1","1","N/A","N/A","10","5","415","49","2025-02-23T09:05:44Z","2023-02-27T14:27:32Z","54549" +"*payloads/Follina*",".{0,1000}payloads\/Follina.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","54550" +"*payloads/Powershell*",".{0,1000}payloads\/Powershell.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","54551" +"*payloads/shellcodes*",".{0,1000}payloads\/shellcodes.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","54552" +"*payloads_examples*calc.js*",".{0,1000}payloads_examples.{0,1000}calc\.js.{0,1000}","offensive_tool_keyword","EmbedInHTML","What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.","T1027 - T1566.001","TA0005 - TA0002","N/A","N/A","Phishing","https://github.com/Arno0x/EmbedInHTML","1","1","N/A","N/A","10","5","485","119","2017-09-27T13:16:06Z","2017-09-11T07:17:20Z","54555" +"*payloads_examples*calc.xll*",".{0,1000}payloads_examples.{0,1000}calc\.xll.{0,1000}","offensive_tool_keyword","EmbedInHTML","What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource.","T1027 - T1566.001","TA0005 - TA0002","N/A","N/A","Phishing","https://github.com/Arno0x/EmbedInHTML","1","1","N/A","N/A","10","5","485","119","2017-09-27T13:16:06Z","2017-09-11T07:17:20Z","54556" +"*PayloadsAllTheThings*",".{0,1000}PayloadsAllTheThings.{0,1000}","offensive_tool_keyword","PayloadsAllTheThings","A list of useful payloads and bypasses for Web Application Security. Feel free to improve with your payloads and techniques ! ","T1210 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/Bo0oM/PayloadsAllTheThings","1","1","N/A","N/A","N/A","1","3","4","2019-02-11T06:34:14Z","2019-02-11T06:29:45Z","54557" +"*PayloadService.*",".{0,1000}PayloadService\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","54558" +"*PayloadType.BIND_PIPE*",".{0,1000}PayloadType\.BIND_PIPE.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","54560" +"*PayloadType.EXTERNAL*",".{0,1000}PayloadType\.EXTERNAL.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","54561" +"*PayloadType.HTTP*",".{0,1000}PayloadType\.HTTP.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","54562" +"*PayloadType.REVERSE_TCP*",".{0,1000}PayloadType\.REVERSE_TCP.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","54563" +"*payorgz3j6hs2gj66nk6omfw65atgmqwzxqbbxnqi3bv2mlwgcirunad.onion*",".{0,1000}payorgz3j6hs2gj66nk6omfw65atgmqwzxqbbxnqi3bv2mlwgcirunad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","54566" +"*pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion*",".{0,1000}pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","54567" +"*pcap_linktypes.py*",".{0,1000}pcap_linktypes\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","54570" +"*pcap2john.py*",".{0,1000}pcap2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54571" +"*pcapfile.py*",".{0,1000}pcapfile\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","54572" +"*PcapXray*",".{0,1000}PcapXray.{0,1000}","offensive_tool_keyword","PcapXray","Given a Pcap File. plot a network diagram displaying hosts in the network. network traffic. highlight important traffic and Tor traffic as well as potential malicious traffic including data involved in the communication.","T1040 - T1071 - T1070 - T1074 - T1075 - T1078 - T1048","TA0001 - TA0002","N/A","N/A","Sniffing & Spoofing","https://github.com/Srinivas11789/PcapXray","1","1","N/A","N/A","N/A","10","1717","281","2022-03-28T15:31:26Z","2017-10-02T04:47:51Z","54573" +"*PDF_Payload*Doomfist.pdf*",".{0,1000}PDF_Payload.{0,1000}Doomfist\.pdf.{0,1000}","offensive_tool_keyword","Mystikal","macOS Initial Access Payload Generator","T1059.005 - T1204.002 - T1566.001","TA0002 - TA0001","N/A","N/A","Exploitation tool","https://github.com/D00MFist/Mystikal","1","1","N/A","N/A","9","4","305","39","2024-01-10T15:48:12Z","2021-05-03T14:46:16Z","54602" +"*pdf2john.pl*",".{0,1000}pdf2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54603" +"*pdf-exploit-main.zip*",".{0,1000}pdf\-exploit\-main\.zip.{0,1000}","offensive_tool_keyword","POC","CVE-2024-4367 poc exploitation","T1566","TA0042","N/A","N/A","Resource Development","https://github.com/rzte/pdf-exploit","1","1","N/A","N/A","6","3","216","41","2024-07-19T03:04:41Z","2024-07-11T14:33:11Z","54605" +"*pe_inject.rb*",".{0,1000}pe_inject\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54607" +"*pe_packer/dll_main.c*",".{0,1000}pe_packer\/dll_main\.c.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","54608" +"*pe_packer/exe_main.c*",".{0,1000}pe_packer\/exe_main\.c.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","54609" +"*pe_packer/main.c*",".{0,1000}pe_packer\/main\.c.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","54610" +"*pe_packer_exe.exe*",".{0,1000}pe_packer_exe\.exe.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","54614" +"*pe2sh.exe*",".{0,1000}pe2sh\.exe.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","54615" +"*pe2shc.exe*",".{0,1000}pe2shc\.exe.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","54617" +"*pe2shc_*.zip*",".{0,1000}pe2shc_.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","avet","AVET is an AntiVirus Evasion Tool. which was developed for making life easier for pentesters and for experimenting with antivirus evasion techniques. as well as other methods used by malicious software. For an overview of new features in v2.3. as well as past version increments. have a look at the CHANGELOG file.","T1055 - T1027 - T1566","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/govolution/avet","1","1","N/A","N/A","10","10","1694","338","2023-10-12T15:00:05Z","2017-01-28T14:56:47Z","54618" +"*Pe2Shellcode.py*",".{0,1000}Pe2Shellcode\.py.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1027 - T1055 - T1070 - T1112 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","54619" +"*Peaky-XD/webshell*",".{0,1000}Peaky\-XD\/webshell.{0,1000}","offensive_tool_keyword","webshell","A collection of webshell","T1505.003 - T1100 - T1190 - T1505.004","TA0003 - TA0011 ","N/A","N/A","Persistence","https://github.com/Peaky-XD/webshell","1","1","N/A","N/A","10","","N/A","","","","54620" +"*PEASS-ng-master*",".{0,1000}PEASS\-ng\-master.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","54621" +"*PEASS-ng-master.zip*",".{0,1000}PEASS\-ng\-master\.zip.{0,1000}","offensive_tool_keyword","PEASS-ng","PEASS-ng - Privilege Escalation Awesome Scripts suite","T1098","TA0004 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/peass-ng/PEASS-ng","1","1","N/A","N/A","10","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","54622" +"*peiga/DumpThatLSASS*",".{0,1000}peiga\/DumpThatLSASS.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","1","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","54625" +"*peinject.rb*",".{0,1000}peinject\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54626" +"*peinjector.rb*",".{0,1000}peinjector\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54627" +"*PELoader/PeLoader.*",".{0,1000}PELoader\/PeLoader\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","54628" +"*pem2john.py*",".{0,1000}pem2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54629" +"*Pennyw0rth/NetExec*",".{0,1000}Pennyw0rth\/NetExec.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","54630" +"*PentestBox*",".{0,1000}PentestBox.{0,1000}","offensive_tool_keyword","pentestbox","PentestBox is an Opensource PreConfigured Portable Penetration Testing Environment for the Windows Operating System","T1043 - T1059 - T1078 - T1082 - T1083 - T1092 - T1095 - T1102 - T1123 - T1132 - T1134 - T1135 - T1140 - T1204 - T1218 - T1219 - T1222 - T1247 - T1496 - T1497 - T1543 - T1552 - T1553 - T1574 - T1583 - T1588 - T1592 - T1596 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011","N/A","N/A","Exploitation tool","https://pentestbox.org/fr/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","54634" +"*PENTESTING-BIBLE*",".{0,1000}PENTESTING\-BIBLE.{0,1000}","offensive_tool_keyword","PENTESTING-BIBLE","pentest documentation - Explore more than 2000 hacking articles saved over time as PDF. BROWSE HISTORY.","T1583 - T1598 - T1596","TA0001 - TA0008 - TA0043","N/A","N/A","Exploitation tool","https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE","1","1","N/A","N/A","N/A","10","13135","2382","2023-04-03T07:40:28Z","2019-06-28T11:26:57Z","54635" +"*pentest-machine*",".{0,1000}pentest\-machine.{0,1000}","offensive_tool_keyword","pentest-machine","Automates some pentesting work via an nmap XML file. As soon as each command finishes it writes its output to the terminal and the files in output-by-service/ and output-by-host/. Runs fast-returning commands first. Please send me protocols/commands/options that you would like to see included.","T1583 - T1584 - T1580 - T1582 - T1574","TA0002 - TA0001 - TA0003 - TA0008 - TA0009","N/A","N/A","Exploitation tool","https://github.com/DanMcInerney/pentest-machine","1","1","N/A","N/A","N/A","4","323","98","2018-09-07T20:01:41Z","2015-02-26T23:57:21Z","54636" +"*pentestmonkey/php-reverse-shell*",".{0,1000}pentestmonkey\/php\-reverse\-shell.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","54637" +"*pentestmonkey/pysecdump*",".{0,1000}pentestmonkey\/pysecdump.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","1","N/A","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","54638" +"*pentest-script-master.zip*",".{0,1000}pentest\-script\-master\.zip.{0,1000}","offensive_tool_keyword","revbshell","ReVBShell - Reverse VBS Shell","T1059.005 - T1573.001 - T1105","TA0011 - TA0010","N/A","N/A","C2","https://github.com/bitsadmin/revbshell","1","1","N/A","N/A","10","10","81","27","2019-10-08T12:00:05Z","2017-02-19T18:58:52Z","54640" +"*PE-Obfuscator.exe*",".{0,1000}PE\-Obfuscator\.exe.{0,1000}","offensive_tool_keyword","PE-Obfuscator","PE obfuscator with Evasion in mind","T1027 - T1055 - T1140 - T1564.003 - T1027.002","TA0006 - TA0002","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/PE-Obfuscator","1","1","N/A","N/A","N/A","3","213","40","2023-04-25T04:58:12Z","2023-04-25T04:00:15Z","54641" +"*PE-Obfuscator.git*",".{0,1000}PE\-Obfuscator\.git.{0,1000}","offensive_tool_keyword","PE-Obfuscator","PE obfuscator with Evasion in mind","T1027 - T1055 - T1140 - T1564.003 - T1027.002","TA0006 - TA0002","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/PE-Obfuscator","1","1","N/A","N/A","N/A","3","213","40","2023-04-25T04:58:12Z","2023-04-25T04:00:15Z","54642" +"*PE-Obfuscator-main*",".{0,1000}PE\-Obfuscator\-main.{0,1000}","offensive_tool_keyword","PE-Obfuscator","PE obfuscator with Evasion in mind","T1027 - T1055 - T1140 - T1564.003 - T1027.002","TA0006 - TA0002","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/PE-Obfuscator","1","1","N/A","N/A","N/A","3","213","40","2023-04-25T04:58:12Z","2023-04-25T04:00:15Z","54643" +"*Pepitoh/VBad*",".{0,1000}Pepitoh\/VBad.{0,1000}","offensive_tool_keyword","vbad","VBad is fully customizable VBA Obfuscation Tool combined with an MS Office document generator. It aims to help Red & Blue team for attack or defense.","T1564 - T1117 - T1204 - T1070","TA0002 - TA0008 - TA0011","N/A","N/A","Defense Evasion","https://github.com/Pepitoh/Vbad","1","1","N/A","N/A","8","6","544","127","2017-10-15T12:56:18Z","2016-03-09T12:36:04Z","54644" +"*perfdata.portswigger.net*",".{0,1000}perfdata\.portswigger\.net.{0,1000}","offensive_tool_keyword","burpsuite","The class-leading vulnerability scanning. penetration testing. and web app security platform","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://portswigger.net/burp","1","1","N/A","network exploitation tool","N/A","N/A","N/A","N/A","N/A","N/A","54646" +"*Perfusion-master.zip*",".{0,1000}Perfusion\-master\.zip.{0,1000}","offensive_tool_keyword","Perfusion","Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)","T1068 - T1055 - T1548.002","TA0003 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/itm4n/Perfusion","1","1","N/A","N/A","10","5","419","75","2021-04-22T16:20:32Z","2021-02-11T18:28:22Z","54658" +"*perl_no_sh_reverse_tcp.py*",".{0,1000}perl_no_sh_reverse_tcp\.py.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","54667" +"*perl-reverse-shell.*",".{0,1000}perl\-reverse\-shell\..{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","54668" +"*PersAutorun.cs*",".{0,1000}PersAutorun\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","54670" +"*PersCLRInstall.cs*",".{0,1000}PersCLRInstall\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","54671" +"*Persist.cna*",".{0,1000}Persist\.cna.{0,1000}","offensive_tool_keyword","AggressorScripts-1","persistence script for cobaltstrike. Persistence Aggressor Scripts for Cobalt Strike 3.0+","T1074 - T1070 - T1105 - T1558","TA0007 - TA0003 - TA0002 - TA0043","N/A","N/A","Exploitation tool","https://github.com/Cn33liz/AggressorScripts-1/tree/master/Persistence","1","1","N/A","N/A","N/A","1","2","1","2018-06-24T16:27:57Z","2019-10-18T12:56:35Z","54678" +"*PersistBOF.cna*",".{0,1000}PersistBOF\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to automate common persistence tasks for red teamers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/IcebreakerSecurity/PersistBOF","1","1","N/A","N/A","10","10","274","44","2023-03-07T11:23:42Z","2022-03-29T14:50:47Z","54685" +"*Persistence.exe*",".{0,1000}Persistence\.exe.{0,1000}","offensive_tool_keyword","DNS-Persist","DNS-Persist is a post-exploitation agent which uses DNS for command and control.","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/0x09AL/DNS-Persist","1","1","N/A","N/A","10","10","211","65","2017-11-20T08:53:25Z","2017-11-10T15:23:49Z","54686" +"*Persistence.psm1*",".{0,1000}Persistence\.psm1.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Persistence.psm1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","54687" +"*Persistence/InstallWMI*",".{0,1000}Persistence\/InstallWMI.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","54689" +"*persistence/userland/backdoor_lnk*",".{0,1000}persistence\/userland\/backdoor_lnk.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","54690" +"*Persistence_AccountManipulation_Windows.py*",".{0,1000}Persistence_AccountManipulation_Windows\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","54691" +"*Persistence_Guard_Windows.py*",".{0,1000}Persistence_Guard_Windows\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","54692" +"*Persistence_LogonScripts_Windows.py*",".{0,1000}Persistence_LogonScripts_Windows\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","54693" +"*Persistence_NewService_Windows.py*",".{0,1000}Persistence_NewService_Windows\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","54694" +"*Persistence_OfficeApplicationStartup_OfficeTest.py*",".{0,1000}Persistence_OfficeApplicationStartup_OfficeTest\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","54695" +"*Persistence_Other_WindowsLibraryMs.py*",".{0,1000}Persistence_Other_WindowsLibraryMs\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","54696" +"*Persistence_RegistryRunKeys_SharpHide.py*",".{0,1000}Persistence_RegistryRunKeys_SharpHide\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","54697" +"*Persistence_RegistryRunKeys_Windows.py*",".{0,1000}Persistence_RegistryRunKeys_Windows\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","54698" +"*Persistence_ScheduledTask_Windows.py*",".{0,1000}Persistence_ScheduledTask_Windows\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","54699" +"*Persistence_WinlogonHelperDLL_Windows.py*",".{0,1000}Persistence_WinlogonHelperDLL_Windows\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","54700" +"*PersistenceBOF.c*",".{0,1000}PersistenceBOF\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to automate common persistence tasks for red teamers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/IcebreakerSecurity/PersistBOF","1","1","N/A","N/A","10","10","274","44","2023-03-07T11:23:42Z","2022-03-29T14:50:47Z","54702" +"*PersistenceBOF.exe*",".{0,1000}PersistenceBOF\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to automate common persistence tasks for red teamers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/IcebreakerSecurity/PersistBOF","1","1","N/A","N/A","10","10","274","44","2023-03-07T11:23:42Z","2022-03-29T14:50:47Z","54703" +"*persistent-security/SMShell*",".{0,1000}persistent\-security\/SMShell.{0,1000}","offensive_tool_keyword","SMShell","PoC for a SMS-based shell. Send commands and receive responses over SMS from mobile broadband capable computers","T1021.001 - T1059.006 - T1071.004 - T1069.003","TA0002 - TA0011 - TA0009 - TA0040","N/A","N/A","C2","https://github.com/persistent-security/SMShell","1","1","N/A","N/A","10","10","360","35","2023-05-22T10:40:16Z","2023-05-22T08:26:44Z","54704" +"*persist-ice-junction.o*",".{0,1000}persist\-ice\-junction\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to automate common persistence tasks for red teamers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/IcebreakerSecurity/PersistBOF","1","1","N/A","N/A","10","10","274","44","2023-03-07T11:23:42Z","2022-03-29T14:50:47Z","54705" +"*persist-ice-monitor.o*",".{0,1000}persist\-ice\-monitor\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to automate common persistence tasks for red teamers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/IcebreakerSecurity/PersistBOF","1","1","N/A","N/A","10","10","274","44","2023-03-07T11:23:42Z","2022-03-29T14:50:47Z","54706" +"*persist-ice-shortcut.o*",".{0,1000}persist\-ice\-shortcut\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to automate common persistence tasks for red teamers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/IcebreakerSecurity/PersistBOF","1","1","N/A","N/A","10","10","274","44","2023-03-07T11:23:42Z","2022-03-29T14:50:47Z","54707" +"*persist-ice-time.o*",".{0,1000}persist\-ice\-time\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to automate common persistence tasks for red teamers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/IcebreakerSecurity/PersistBOF","1","1","N/A","N/A","10","10","274","44","2023-03-07T11:23:42Z","2022-03-29T14:50:47Z","54708" +"*persist-ice-xll.o*",".{0,1000}persist\-ice\-xll\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to automate common persistence tasks for red teamers","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/IcebreakerSecurity/PersistBOF","1","1","N/A","N/A","10","10","274","44","2023-03-07T11:23:42Z","2022-03-29T14:50:47Z","54709" +"*PersStartup.cs*",".{0,1000}PersStartup\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","54710" +"*PEScrambler.exe*",".{0,1000}PEScrambler\.exe.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","54711" +"*peterdocter/quarkspwdump*",".{0,1000}peterdocter\/quarkspwdump.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","1","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","54712" +"*PetitPotam.cna*",".{0,1000}PetitPotam\.cna.{0,1000}","offensive_tool_keyword","C2-Tool-Collection","A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques","T1055 - T1218 - T1059 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","C2","https://github.com/outflanknl/C2-Tool-Collection","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","54714" +"*PetitPotam.cpp*",".{0,1000}PetitPotam\.cpp.{0,1000}","offensive_tool_keyword","petipotam","PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.","T1557.001 - T1021","TA0008","N/A","N/A","Lateral Movement","https://github.com/topotam/PetitPotam","1","1","N/A","N/A","10","10","1944","290","2024-08-15T03:52:26Z","2021-07-18T18:19:54Z","54715" +"*PetitPotam.exe*",".{0,1000}PetitPotam\.exe.{0,1000}","offensive_tool_keyword","C2-Tool-Collection","A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques","T1055 - T1218 - T1059 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","C2","https://github.com/outflanknl/C2-Tool-Collection","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","54716" +"*PetitPotam.exe*",".{0,1000}PetitPotam\.exe.{0,1000}","offensive_tool_keyword","petipotam","PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.","T1557.001 - T1021","TA0008","N/A","N/A","Lateral Movement","https://github.com/topotam/PetitPotam","1","1","N/A","N/A","10","10","1944","290","2024-08-15T03:52:26Z","2021-07-18T18:19:54Z","54717" +"*PetitPotam.ps1*",".{0,1000}PetitPotam\.ps1.{0,1000}","offensive_tool_keyword","C2-Tool-Collection","A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques","T1055 - T1218 - T1059 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","C2","https://github.com/outflanknl/C2-Tool-Collection","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","54718" +"*PetitPotam.py*",".{0,1000}PetitPotam\.py.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","54719" +"*petitpotam.py*",".{0,1000}petitpotam\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","54720" +"*petitpotam.py*",".{0,1000}petitpotam\.py.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","54721" +"*PetitPotam.py*",".{0,1000}PetitPotam\.py.{0,1000}","offensive_tool_keyword","petipotam","PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.","T1557.001 - T1021","TA0008","N/A","N/A","Lateral Movement","https://github.com/topotam/PetitPotam","1","1","N/A","N/A","10","10","1944","290","2024-08-15T03:52:26Z","2021-07-18T18:19:54Z","54722" +"*PetitPotam.sln*",".{0,1000}PetitPotam\.sln.{0,1000}","offensive_tool_keyword","C2-Tool-Collection","A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques","T1055 - T1218 - T1059 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","C2","https://github.com/outflanknl/C2-Tool-Collection","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","54724" +"*PetitPotam.sln*",".{0,1000}PetitPotam\.sln.{0,1000}","offensive_tool_keyword","petipotam","PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.","T1557.001 - T1021","TA0008","N/A","N/A","Lateral Movement","https://github.com/topotam/PetitPotam","1","1","N/A","N/A","10","10","1944","290","2024-08-15T03:52:26Z","2021-07-18T18:19:54Z","54725" +"*PetitPotam.vcxproj*",".{0,1000}PetitPotam\.vcxproj.{0,1000}","offensive_tool_keyword","C2-Tool-Collection","A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques","T1055 - T1218 - T1059 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","C2","https://github.com/outflanknl/C2-Tool-Collection","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","54726" +"*petitpotam_check*",".{0,1000}petitpotam_check.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","54728" +"*PetitPotamModified.exe*",".{0,1000}PetitPotamModified\.exe.{0,1000}","offensive_tool_keyword","MultiPotato","get SYSTEM via SeImpersonate privileges","T1548.002 - T1134.002","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S3cur3Th1sSh1t/MultiPotato","1","1","N/A","N/A","10","6","518","92","2021-11-20T16:20:23Z","2021-11-19T15:50:55Z","54729" +"*PetitPotato.exe*",".{0,1000}PetitPotato\.exe.{0,1000}","offensive_tool_keyword","PetitPotato","Local privilege escalation via PetitPotam (Abusing impersonate privileges)","T1134.005 - T1548.001","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/wh0amitz/PetitPotato","1","1","N/A","N/A","10","5","430","52","2023-03-30T10:45:00Z","2022-04-19T19:59:19Z","54732" +"*PEzor*/Inject.c*",".{0,1000}PEzor.{0,1000}\/Inject\.c.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","54736" +"*Pezor*inject.hpp*",".{0,1000}Pezor.{0,1000}inject\.hpp.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","54737" +"*PEzor/*/bof.cpp*",".{0,1000}PEzor\/.{0,1000}\/bof\.cpp.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","54742" +"*PEzor/*syscalls.hpp*",".{0,1000}PEzor\/.{0,1000}syscalls\.hpp.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","54743" +"*pfsense*reverse_root_shell_csrf/*",".{0,1000}pfsense.{0,1000}reverse_root_shell_csrf\/.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","54745" +"*pfx2john.py*",".{0,1000}pfx2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54746" +"*pg3n5bteiatjf6rt7oa4xhzo4sj736rifjmk4gtowxjljuwwdv6mccyd.onion*",".{0,1000}pg3n5bteiatjf6rt7oa4xhzo4sj736rifjmk4gtowxjljuwwdv6mccyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","54747" +"*pgkt04/defender-control*",".{0,1000}pgkt04\/defender\-control.{0,1000}","offensive_tool_keyword","defender-control","An open-source windows defender manager. Now you can disable windows defender permanently","T1562.001 - T1562.004 - T1089","TA0005 - TA0002","N/A","LockBit","Defense Evasion","https://github.com/pgkt04/defender-control","1","1","N/A","N/A","10","10","1614","128","2023-09-09T14:57:56Z","2021-05-15T10:09:17Z","54750" +"*pgpdisk2john.py*",".{0,1000}pgpdisk2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54751" +"*pgpsda2john.py*",".{0,1000}pgpsda2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54752" +"*pgpwde2john.py*",".{0,1000}pgpwde2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54753" +"*ph4nt0mbyt3/Darkside*",".{0,1000}ph4nt0mbyt3\/Darkside.{0,1000}","offensive_tool_keyword","Darkside","C# AV/EDR Killer using less-known driver (BYOVD)","T1547.006 - T1055 - T1562.001","TA0005 - TA0003 - TA0004 ","N/A","N/A","Defense Evasion","https://github.com/ph4nt0mbyt3/Darkside","1","1","N/A","N/A","10","2","175","34","2023-11-10T16:01:21Z","2023-11-10T15:34:20Z","54759" +"*ph4ntonn/Stowaway*",".{0,1000}ph4ntonn\/Stowaway.{0,1000}","offensive_tool_keyword","stowaway","Stowaway -- Multi-hop Proxy Tool for pentesters","T1021 - T1090 - T1071 - T1573","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/ph4ntonn/Stowaway","1","1","N/A","N/A","10","10","2989","422","2025-04-05T14:48:38Z","2019-11-15T03:25:50Z","54760" +"*phant0m.cna*",".{0,1000}phant0m\.cna.{0,1000}","offensive_tool_keyword","Phant0m","Windows Event Log Killer","T1070.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/hlldz/Phant0m","1","1","N/A","N/A","N/A","10","1781","301","2023-09-21T16:08:18Z","2017-05-02T17:19:30Z","54764" +"*Phant0m_cobaltstrike*",".{0,1000}Phant0m_cobaltstrike.{0,1000}","offensive_tool_keyword","cobaltstrike","Aggressor script to integrate Phant0m with Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/p292/Phant0m_cobaltstrike","1","1","N/A","N/A","10","10","27","13","2017-06-08T06:42:18Z","2017-06-08T06:39:07Z","54765" +"*phant0m-exe.*",".{0,1000}phant0m\-exe\..{0,1000}","offensive_tool_keyword","Phant0m","Windows Event Log Killer","T1070.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/hlldz/Phant0m","1","1","N/A","N/A","N/A","10","1781","301","2023-09-21T16:08:18Z","2017-05-02T17:19:30Z","54766" +"*Phant0m-master.zip*",".{0,1000}Phant0m\-master\.zip.{0,1000}","offensive_tool_keyword","Phant0m","Windows Event Log Killer","T1070.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/hlldz/Phant0m","1","1","N/A","N/A","N/A","10","1781","301","2023-09-21T16:08:18Z","2017-05-02T17:19:30Z","54767" +"*phant0m-rdll*",".{0,1000}phant0m\-rdll.{0,1000}","offensive_tool_keyword","Phant0m","Windows Event Log Killer","T1070.004","TA0005","N/A","N/A","Defense Evasion","https://github.com/hlldz/Phant0m","1","1","N/A","N/A","N/A","10","1781","301","2023-09-21T16:08:18Z","2017-05-02T17:19:30Z","54768" +"*PhantomService.csproj*",".{0,1000}PhantomService\.csproj.{0,1000}","offensive_tool_keyword","PhantomService","Searches for and removes non-ASCII services that can't be easily removed by built-in Windows tools","T1050.005 - T1055.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/matterpreter/OffensiveCSharp/tree/master/PhantomService","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","54770" +"*PhantomService.exe*",".{0,1000}PhantomService\.exe.{0,1000}","offensive_tool_keyword","PhantomService","Searches for and removes non-ASCII services that can't be easily removed by built-in Windows tools","T1050.005 - T1055.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/matterpreter/OffensiveCSharp/tree/master/PhantomService","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","54771" +"*phillips321/adaudit*",".{0,1000}phillips321\/adaudit.{0,1000}","offensive_tool_keyword","adaudit","Powershell script to do domain auditing automation","T1087 - T1069 - T1046 - T1057 - T1114 - T1018","TA0007 - TA0003 - TA0004 - TA0006","N/A","N/A","Discovery","https://github.com/phillips321/adaudit","1","1","N/A","N/A","5","4","389","106","2025-04-08T06:17:54Z","2018-04-20T11:29:06Z","54772" +"*phish_test.go*",".{0,1000}phish_test\.go.{0,1000}","offensive_tool_keyword","gophish","Open-Source Phishing Toolkit","T1566-001 - T1566-002 - T1566-003 - T1056-001 - T1113 - T1567-001","TA0002 - TA0003","N/A","Black Basta","Phishing","https://github.com/gophish/gophish","1","1","N/A","N/A","10","10","12483","2528","2024-09-23T04:24:43Z","2013-11-18T23:26:43Z","54774" +"*phish_windows_credentials.rb*",".{0,1000}phish_windows_credentials\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54775" +"*Phish-Creds.ps1*",".{0,1000}Phish\-Creds\.ps1.{0,1000}","offensive_tool_keyword","phishing-HTML-linter","Phishing and Social-Engineering related scripts","T1566.001 - T1056.001","TA0040 - TA0001","N/A","N/A","Phishing","https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing","1","1","N/A","N/A","10","10","2689","527","2023-06-27T19:16:49Z","2018-02-02T21:24:03Z","54776" +"*phishing-HTML-linter.*",".{0,1000}phishing\-HTML\-linter\..{0,1000}","offensive_tool_keyword","phishing-HTML-linter","Phishing and Social-Engineering related scripts","T1566.001 - T1056.001","TA0040 - TA0001","N/A","N/A","Phishing","https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing","1","1","N/A","N/A","10","10","2689","527","2023-06-27T19:16:49Z","2018-02-02T21:24:03Z","54778" +"*phising_attack.py*",".{0,1000}phising_attack\.py.{0,1000}","offensive_tool_keyword","hackingtool","ALL IN ONE Hacking Tool For Hackers","T1059 - T1078 - T1105 - T1110 - T1566","TA0002 - TA0008 - TA0009 - TA0005 - TA0007","N/A","N/A","Exploitation tool","https://github.com/Z4nzu/hackingtool","1","1","N/A","N/A","N/A","10","52217","5629","2025-03-03T15:17:19Z","2020-04-11T09:21:31Z","54780" +"*php/meterpreter_reverse_tcp*",".{0,1000}php\/meterpreter_reverse_tcp.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","54802" +"*php/reverse_php*",".{0,1000}php\/reverse_php.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","54803" +"*php_passthru_reverse_tcp.py*",".{0,1000}php_passthru_reverse_tcp\.py.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","54805" +"*php_popen_reverse_tcp.py*",".{0,1000}php_popen_reverse_tcp\.py.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","54806" +"*php_proc_open_reverse_tcp.py*",".{0,1000}php_proc_open_reverse_tcp\.py.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","54807" +"*php_reverse_shell_mini.php*",".{0,1000}php_reverse_shell_mini\.php.{0,1000}","offensive_tool_keyword","php-reverse-shell","PHP shells that work on Linux OS - macOS and Windows OS","T1505.003 - T1059.003 - T1100","TA0003 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/ivan-sincek/php-reverse-shell","1","1","N/A","N/A","10","10","482","152","2023-10-03T09:48:21Z","2020-07-14T07:22:54Z","54808" +"*php_reverse_shell_older.php*",".{0,1000}php_reverse_shell_older\.php.{0,1000}","offensive_tool_keyword","php-reverse-shell","PHP shells that work on Linux OS - macOS and Windows OS","T1505.003 - T1059.003 - T1100","TA0003 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/ivan-sincek/php-reverse-shell","1","1","N/A","N/A","10","10","482","152","2023-10-03T09:48:21Z","2020-07-14T07:22:54Z","54809" +"*php_reverse_shell_older_mini.php*",".{0,1000}php_reverse_shell_older_mini\.php.{0,1000}","offensive_tool_keyword","php-reverse-shell","PHP shells that work on Linux OS - macOS and Windows OS","T1505.003 - T1059.003 - T1100","TA0003 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/ivan-sincek/php-reverse-shell","1","1","N/A","N/A","10","10","482","152","2023-10-03T09:48:21Z","2020-07-14T07:22:54Z","54810" +"*PHP-Code-injection.*",".{0,1000}PHP\-Code\-injection\..{0,1000}","offensive_tool_keyword","Offensive-Payloads","List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.","T1210 - T1185 - T1059 - T1400 - T1506 - T1213 ","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/InfoSecWarrior/Offensive-Payloads/","1","1","N/A","N/A","N/A","4","328","117","2024-09-20T09:59:28Z","2022-11-18T09:43:41Z","54811" +"*PHP-Code-Injections-Payloads.*",".{0,1000}PHP\-Code\-Injections\-Payloads\..{0,1000}","offensive_tool_keyword","Offensive-Payloads","List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.","T1210 - T1185 - T1059 - T1400 - T1506 - T1213 ","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/InfoSecWarrior/Offensive-Payloads/","1","1","N/A","N/A","N/A","4","328","117","2024-09-20T09:59:28Z","2022-11-18T09:43:41Z","54812" +"*phpmyadmin_credsteal.*",".{0,1000}phpmyadmin_credsteal\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54816" +"*php-reverse-shell.php*",".{0,1000}php\-reverse\-shell\.php.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","54818" +"*PhpSploit*",".{0,1000}PhpSploit.{0,1000}","offensive_tool_keyword","PhpSploit","Full-featured C2 framework which silently persists on webserver via evil PHP oneliner","T1505.003 - T1505 - T1059 - T1219 - T1547","TA0003 - TA0011 - TA0005","N/A","N/A","C2","https://github.com/nil0x42/phpsploit","0","1","N/A","N/A","10","10","2331","453","2024-05-06T13:49:14Z","2014-05-21T19:43:03Z","54819" +"*phpsploit-launcher.sh*",".{0,1000}phpsploit\-launcher\.sh.{0,1000}","offensive_tool_keyword","PhpSploit","Full-featured C2 framework which silently persists on webserver via evil PHP oneliner","T1505.003 - T1505 - T1059 - T1219 - T1547","TA0003 - TA0011 - TA0005","N/A","N/A","C2","https://github.com/nil0x42/phpsploit","1","1","N/A","N/A","10","10","2331","453","2024-05-06T13:49:14Z","2014-05-21T19:43:03Z","54825" +"*phra/Pezor*",".{0,1000}phra\/Pezor.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1027 - T1045 - T1055 - T1140 - T1204 - T1218","TA0005 - TA0043","N/A","N/A","Defense Evasion","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","54826" +"*phra/Pezor/*",".{0,1000}phra\/Pezor\/.{0,1000}","offensive_tool_keyword","Pezor","Open-Source Shellcode & PE Packer","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","DarkHydrus - FIN6 - TA505 - Cobalt Group - APT19 - APT41 - Threat Group-3390 - FIN7 - Earth Lusca - Leviathan - Indrik Spider - Aquatic Panda - CopyKittens - Wizard Spider - APT32 - APT37 - LuminousMoth - menuPass - Mustang Panda - Chimera - APT29","Exploitation tool","https://github.com/phra/PEzor","1","1","N/A","N/A","10","10","1936","330","2024-02-03T19:11:05Z","2020-07-22T09:45:52Z","54827" +"*PhrozenIO/SharpFtpC2*",".{0,1000}PhrozenIO\/SharpFtpC2.{0,1000}","offensive_tool_keyword","SharpFtpC2","A Streamlined FTP-Driven Command and Control Conduit for Interconnecting Remote Systems","T1071.002 - T1105 - T1090.001","TA0011","N/A","N/A","C2","https://github.com/PhrozenIO/SharpFtpC2","1","1","N/A","N/A","10","10","88","15","2023-11-09T10:37:20Z","2023-06-09T12:41:28Z","54828" +"*PhrozenIO/win-brute-logon*",".{0,1000}PhrozenIO\/win\-brute\-logon.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","1","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","54829" +"*phuip-fpizdam*",".{0,1000}phuip\-fpizdam.{0,1000}","offensive_tool_keyword","phuip-fpizdam","This is an exploit for a bug in php-fpm (CVE-2019-11043). In certain nginx + php-fpm configurations. the bug is possible to trigger from the outside. This means that a web user may get code execution if you have vulnerable config (see below).","T1190 - T1191 - T1192 - T1210 - T1059","TA0001 - TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/neex/phuip-fpizdam","1","1","N/A","N/A","N/A","10","1815","247","2019-11-12T18:53:14Z","2019-09-23T21:37:27Z","54830" +"*physmem2profit.exe*",".{0,1000}physmem2profit\.exe.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","1","N/A","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","54831" +"*physmem2profit-public.zip*",".{0,1000}physmem2profit\-public\.zip.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","1","N/A","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","54833" +"*piata_ssh_userpass.txt*",".{0,1000}piata_ssh_userpass\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54834" +"*PIC-Get-Privileges*",".{0,1000}PIC\-Get\-Privileges.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","54837" +"*Pickfordmatt/SharpLocker*",".{0,1000}Pickfordmatt\/SharpLocker.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","1","N/A","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","54838" +"*PickleC2-main*",".{0,1000}PickleC2\-main.{0,1000}","offensive_tool_keyword","PickleC2","PickleC2 is a post-exploitation and Lateral Movements framework","T1059.006 - T1021 - T1071 - T1550 - T1560 - T1570","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/xRET2pwn/PickleC2","1","1","N/A","N/A","10","10","91","20","2021-07-26T21:12:04Z","2021-07-13T09:16:19Z","54839" +"*pico.sh/irc*",".{0,1000}pico\.sh\/irc.{0,1000}","offensive_tool_keyword","pico","hacker labs - open source and managed web services leveraging SSH","T1021.005 - T1078 - T1105 - T1109 - T1197 - T1213","TA0005 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/picosh/pico","1","1","N/A","N/A","10","10","1129","36","2025-04-22T17:33:17Z","2022-08-24T03:14:52Z","54840" +"*picosh/pico*",".{0,1000}picosh\/pico.{0,1000}","offensive_tool_keyword","pico","hacker labs - open source and managed web services leveraging SSH","T1021.005 - T1078 - T1105 - T1109 - T1197 - T1213","TA0005 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/picosh/pico","1","1","N/A","N/A","10","10","1129","36","2025-04-22T17:33:17Z","2022-08-24T03:14:52Z","54841" +"*pingcastle.com*mysmartlogon.com*",".{0,1000}pingcastle\.com.{0,1000}mysmartlogon\.com.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","54849" +"*PingRAT.exe*",".{0,1000}PingRAT\.exe.{0,1000}","offensive_tool_keyword","PingRAT","secretly passes Command and Control (C2) traffic through firewalls using ICMP payloads","T1071.004 - T1573.001","TA0005 - TA0011 - TA0042","N/A","N/A","C2","https://github.com/umutcamliyurt/PingRAT","1","1","N/A","N/A","10","10","416","55","2023-09-29T22:26:15Z","2023-09-29T22:07:46Z","54856" +"*PinoyWH1Z/AoratosWin*",".{0,1000}PinoyWH1Z\/AoratosWin.{0,1000}","offensive_tool_keyword","AoratosWin","A tool that removes traces of executed applications on Windows OS.","T1070 - T1564","TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/PinoyWH1Z/AoratosWin","1","1","N/A","N/A","N/A","2","120","16","2022-09-04T09:15:35Z","2022-09-04T09:04:35Z","54858" +"*'pipename_stager'*",".{0,1000}\'pipename_stager\'.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","54889" +"*PipeViewer.csproj*",".{0,1000}PipeViewer\.csproj.{0,1000}","offensive_tool_keyword","PipeViewer ","A tool that shows detailed information about named pipes in Windows","T1022.002 - T1056.002","TA0005 - TA0009","N/A","N/A","discovery","https://github.com/cyberark/PipeViewer","1","1","N/A","N/A","5","7","620","55","2024-11-15T09:55:35Z","2022-12-22T12:35:34Z","54891" +"*PipeViewer_v1.1.zip*",".{0,1000}PipeViewer_v1\.1\.zip.{0,1000}","offensive_tool_keyword","PipeViewer ","A tool that shows detailed information about named pipes in Windows","T1022.002 - T1056.002","TA0005 - TA0009","N/A","N/A","discovery","https://github.com/cyberark/PipeViewer","1","1","N/A","N/A","5","7","620","55","2024-11-15T09:55:35Z","2022-12-22T12:35:34Z","54892" +"*PipeViewer-main*",".{0,1000}PipeViewer\-main.{0,1000}","offensive_tool_keyword","PipeViewer ","A tool that shows detailed information about named pipes in Windows","T1022.002 - T1056.002","TA0005 - TA0009","N/A","N/A","discovery","https://github.com/cyberark/PipeViewer","1","1","N/A","N/A","5","7","620","55","2024-11-15T09:55:35Z","2022-12-22T12:35:34Z","54893" +"*Pirate-Devs/Kematian*",".{0,1000}Pirate\-Devs\/Kematian.{0,1000}","offensive_tool_keyword","Kematian Stealer","Fake WinRar site distributes malware (+stealer +miner +hvnc +ransomware) from GitHub","T1195 - T1566 - T1569 - T1106 - T1486 - T1113","TA0001 - TA0002 - TA0005 - TA0006 - TA0007 - TA0009 - TA0010 - TA0011 - TA0040 - TA0043","N/A","N/A","Malware","https://github.com/Pirate-Devs/Kematian","1","1","N/A","N/A","10","","N/A","","","","54898" +"*pivotnacci/0.0.1*",".{0,1000}pivotnacci\/0\.0\.1.{0,1000}","offensive_tool_keyword","pivotnacci","A tool to make socks connections through HTTP agents","T1090 - T1090.003","TA0003 - TA0011","N/A","Sandworm","C2","https://github.com/blackarrowsec/pivotnacci","1","1","#useragent","user-agent","9","10","697","114","2021-03-30T14:37:25Z","2020-04-28T11:36:45Z","54905" +"*pivotnacci-master*",".{0,1000}pivotnacci\-master.{0,1000}","offensive_tool_keyword","pivotnacci","A tool to make socks connections through HTTP agents","T1090 - T1090.003","TA0003 - TA0011","N/A","Sandworm","C2","https://github.com/blackarrowsec/pivotnacci","1","1","N/A","N/A","9","10","697","114","2021-03-30T14:37:25Z","2020-04-28T11:36:45Z","54907" +"*pivots/named-pipe_windows.go*",".{0,1000}pivots\/named\-pipe_windows\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","54908" +"*pkexec64.tar.gz*",".{0,1000}pkexec64\.tar\.gz.{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike4.4 one-click deployment script Randomly generate passwords. keys. port numbers. certificates. etc.. to solve the problem that cs4.x cannot run on Linux and report errors Gray often ginkgo design","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/AlphabugX/csOnvps","1","1","N/A","N/A","10","10","286","63","2022-03-19T00:10:03Z","2021-12-02T02:10:42Z","54911" +"*pkgs.org/download/chntpw*",".{0,1000}pkgs\.org\/download\/chntpw.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","54915" +"*PKINITtools.git*",".{0,1000}PKINITtools\.git.{0,1000}","offensive_tool_keyword","PKINITtools","Tools for Kerberos PKINIT and relaying to AD CS","T1550.003 - T1557.002 - T1552.004 - T1212 - T1550","TA0009 - TA0008","N/A","N/A","Lateral Movement","https://github.com/dirkjanm/PKINITtools","1","1","N/A","N/A","N/A","8","737","82","2025-01-03T14:25:52Z","2021-07-27T19:06:09Z","54920" +"*pkt_comm/word_gen.*",".{0,1000}pkt_comm\/word_gen\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54921" +"*pkt_comm/word_list*",".{0,1000}pkt_comm\/word_list.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54922" +"*plackyhacker/CmdLineSpoofer*",".{0,1000}plackyhacker\/CmdLineSpoofer.{0,1000}","offensive_tool_keyword","CmdLineSpoofer","How to spoof the command line when spawning a new process from C#","T1055 - T1027 - T1036","TA0002 - TA0004 - TA0010","N/A","N/A","Defense Evasion","https://github.com/plackyhacker/CmdLineSpoofer","1","1","N/A","N/A","9","2","106","17","2021-12-28T18:56:25Z","2021-12-27T09:23:45Z","54924" +"*Plazmaz/LNKUp*",".{0,1000}Plazmaz\/LNKUp.{0,1000}","offensive_tool_keyword","LNKUp","Generates malicious LNK file payloads for data exfiltration","T1023.003 - T1048 - T1041 - T1204","TA0010","N/A","N/A","Data Exfiltration","https://github.com/Plazmaz/LNKUp","1","1","N/A","N/A","10","4","384","54","2017-08-21T22:58:13Z","2017-08-09T16:18:07Z","54926" +"*plex_unpickle_dict_rce.*",".{0,1000}plex_unpickle_dict_rce\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54937" +"*plug_getpass_nps.dll*",".{0,1000}plug_getpass_nps\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Chinese clone of cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/YDHCUI/manjusaka","1","1","N/A","N/A","10","10","818","150","2023-05-09T03:31:53Z","2022-03-18T08:16:04Z","54940" +"*plug_katz_nps.exe*",".{0,1000}plug_katz_nps\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Chinese clone of cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/YDHCUI/manjusaka","1","1","N/A","N/A","10","10","818","150","2023-05-09T03:31:53Z","2022-03-18T08:16:04Z","54941" +"*plug_qvte_nps.exe*",".{0,1000}plug_qvte_nps\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Chinese clone of cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/YDHCUI/manjusaka","1","1","N/A","N/A","10","10","818","150","2023-05-09T03:31:53Z","2022-03-18T08:16:04Z","54942" +"*plugins.nessus.org.*",".{0,1000}plugins\.nessus\.org\..{0,1000}","offensive_tool_keyword","nessus","Vulnerability scanner","T1046 - T1068 - T1190 - T1201 - T1222 - T1592","TA0001 - TA0002 - TA0007 - TA0011","N/A","N/A","Vulnerability Scanner","https://fr.tenable.com/products/nessus","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","54944" +"*plugins/nemesis.rb*",".{0,1000}plugins\/nemesis\.rb.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","54945" +"*plummm/CVE-2022-27666*",".{0,1000}plummm\/CVE\-2022\-27666.{0,1000}","offensive_tool_keyword","POC","Exploit for CVE-2022-27666","T1550 - T1555 - T1212 - T1558","TA0005","N/A","N/A","Exploitation tool","https://github.com/plummm/CVE-2022-27666","1","1","N/A","N/A","N/A","3","204","39","2022-03-28T18:21:00Z","2022-03-23T22:54:28Z","54952" +"*pnanlicgxkku2aonwsg2fwid3maycsso7joqnzp66wkfemzdk7ahsdid.onion*",".{0,1000}pnanlicgxkku2aonwsg2fwid3maycsso7joqnzp66wkfemzdk7ahsdid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","54956" +"*poc.exe*poc.txt*",".{0,1000}poc\.exe.{0,1000}poc\.txt.{0,1000}","offensive_tool_keyword","RecycledInjector","Native Syscalls Shellcode Injector","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/florylsk/RecycledInjector","1","1","N/A","N/A","N/A","3","266","43","2023-07-02T11:04:28Z","2023-06-23T16:14:56Z","54962" +"*POC_CloudFilter_ArbitraryFile_EoP*",".{0,1000}POC_CloudFilter_ArbitraryFile_EoP.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54974" +"*POC_CloudFilter_ArbitraryFile_EoP.*",".{0,1000}POC_CloudFilter_ArbitraryFile_EoP\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54975" +"*pod4gkypkd6kykwoht3kioehhpoh4k75ybdfoe6q7hqbphrd77b32jqd.onion*",".{0,1000}pod4gkypkd6kykwoht3kioehhpoh4k75ybdfoe6q7hqbphrd77b32jqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","54979" +"*pogostick.net/~pnh/ntpasswd/*",".{0,1000}pogostick\.net\/\~pnh\/ntpasswd\/.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","54988" +"*PointAndPrint.ps1*",".{0,1000}PointAndPrint\.ps1.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","54989" +"*poison_ivy_c2*",".{0,1000}poison_ivy_c2.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54990" +"*Poisoners-Session.log*",".{0,1000}Poisoners\-Session\.log.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","#logfile","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","54991" +"*poisonivy_bof.*",".{0,1000}poisonivy_bof\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","54992" +"*PoisonTendy.dll*",".{0,1000}PoisonTendy\.dll.{0,1000}","offensive_tool_keyword","SingleDose","SingleDose is a framework to build shellcode load/process injection techniques","T1055 - T1185","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/Wra7h/SingleDose","1","1","N/A","N/A","10","2","155","29","2023-05-15T19:46:43Z","2021-08-28T05:04:50Z","54994" +"*pony-02.aftxt*",".{0,1000}pony\-02\.aftxt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","55000" +"*PoolPartyBof.cna*",".{0,1000}PoolPartyBof\.cna.{0,1000}","offensive_tool_keyword","PoolPartyBof","A beacon object file implementation of PoolParty Process Injection Technique","T1055.011 - T1055 - T1620","TA0005","N/A","Black Basta","Privilege Escalation","https://github.com/0xEr3bus/PoolPartyBof","1","1","N/A","N/A","10","4","380","44","2023-12-21T19:00:20Z","2023-12-11T19:28:20Z","55008" +"*PoolPartyBof.zip*",".{0,1000}PoolPartyBof\.zip.{0,1000}","offensive_tool_keyword","PoolPartyBof","A beacon object file implementation of PoolParty Process Injection Technique","T1055.011 - T1055 - T1620","TA0005","N/A","Black Basta","Privilege Escalation","https://github.com/0xEr3bus/PoolPartyBof","1","1","N/A","N/A","10","4","380","44","2023-12-21T19:00:20Z","2023-12-11T19:28:20Z","55010" +"*PoolPartyBof_V4.x64*",".{0,1000}PoolPartyBof_V4\.x64.{0,1000}","offensive_tool_keyword","PoolPartyBof","A beacon object file implementation of PoolParty Process Injection Technique","T1055.011 - T1055 - T1620","TA0005","N/A","Black Basta","Privilege Escalation","https://github.com/0xEr3bus/PoolPartyBof","1","1","N/A","N/A","10","4","380","44","2023-12-21T19:00:20Z","2023-12-11T19:28:20Z","55011" +"*PoolPartyBof_V4.x64*",".{0,1000}PoolPartyBof_V4\.x64.{0,1000}","offensive_tool_keyword","PoolPartyBof","A beacon object file implementation of PoolParty Process Injection Technique","T1055.011 - T1055 - T1620","TA0005","N/A","Black Basta","Privilege Escalation","https://github.com/0xEr3bus/PoolPartyBof","1","1","N/A","N/A","10","4","380","44","2023-12-21T19:00:20Z","2023-12-11T19:28:20Z","55012" +"*PoolPartyBof_V5.x64*",".{0,1000}PoolPartyBof_V5\.x64.{0,1000}","offensive_tool_keyword","PoolPartyBof","A beacon object file implementation of PoolParty Process Injection Technique","T1055.011 - T1055 - T1620","TA0005","N/A","Black Basta","Privilege Escalation","https://github.com/0xEr3bus/PoolPartyBof","1","1","N/A","N/A","10","4","380","44","2023-12-21T19:00:20Z","2023-12-11T19:28:20Z","55013" +"*PoolPartyBof_V6.x64*",".{0,1000}PoolPartyBof_V6\.x64.{0,1000}","offensive_tool_keyword","PoolPartyBof","A beacon object file implementation of PoolParty Process Injection Technique","T1055.011 - T1055 - T1620","TA0005","N/A","Black Basta","Privilege Escalation","https://github.com/0xEr3bus/PoolPartyBof","1","1","N/A","N/A","10","4","380","44","2023-12-21T19:00:20Z","2023-12-11T19:28:20Z","55014" +"*PoolPartyBof_V7.x64*",".{0,1000}PoolPartyBof_V7\.x64.{0,1000}","offensive_tool_keyword","PoolPartyBof","A beacon object file implementation of PoolParty Process Injection Technique","T1055.011 - T1055 - T1620","TA0005","N/A","Black Basta","Privilege Escalation","https://github.com/0xEr3bus/PoolPartyBof","1","1","N/A","N/A","10","4","380","44","2023-12-21T19:00:20Z","2023-12-11T19:28:20Z","55015" +"*PoolPartyBof_V8.x64*",".{0,1000}PoolPartyBof_V8\.x64.{0,1000}","offensive_tool_keyword","PoolPartyBof","A beacon object file implementation of PoolParty Process Injection Technique","T1055.011 - T1055 - T1620","TA0005","N/A","Black Basta","Privilege Escalation","https://github.com/0xEr3bus/PoolPartyBof","1","1","N/A","N/A","10","4","380","44","2023-12-21T19:00:20Z","2023-12-11T19:28:20Z","55016" +"*PoolParty-main.zip*",".{0,1000}PoolParty\-main\.zip.{0,1000}","offensive_tool_keyword","PoolParty","A set of fully-undetectable process injection techniques abusing Windows Thread Pools","T1055","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/SafeBreach-Labs/PoolParty","1","1","N/A","N/A","9","10","1088","143","2023-12-11T10:52:05Z","2023-05-21T16:13:32Z","55018" +"*PoolParty-PoolParty.zip*",".{0,1000}PoolParty\-PoolParty\.zip.{0,1000}","offensive_tool_keyword","PoolParty","A set of fully-undetectable process injection techniques abusing Windows Thread Pools","T1055","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/SafeBreach-Labs/PoolParty","1","1","N/A","N/A","9","10","1088","143","2023-12-11T10:52:05Z","2023-05-21T16:13:32Z","55019" +"*port_forward_pivot.py*",".{0,1000}port_forward_pivot\.py.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","55022" +"*PortBender.cna*",".{0,1000}PortBender\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","PortBender is a TCP port redirection utility that allows a red team operator to redirect inbound traffic ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/praetorian-inc/PortBender","1","1","N/A","N/A","10","10","712","111","2023-01-31T09:44:16Z","2021-05-27T02:46:29Z","55028" +"*PortBender.cpp*",".{0,1000}PortBender\.cpp.{0,1000}","offensive_tool_keyword","cobaltstrike","PortBender is a TCP port redirection utility that allows a red team operator to redirect inbound traffic ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/praetorian-inc/PortBender","1","1","N/A","N/A","10","10","712","111","2023-01-31T09:44:16Z","2021-05-27T02:46:29Z","55029" +"*portbender.dll*",".{0,1000}portbender\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","PortBender is a TCP port redirection utility that allows a red team operator to redirect inbound traffic ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/praetorian-inc/PortBender","1","1","N/A","N/A","10","10","712","111","2023-01-31T09:44:16Z","2021-05-27T02:46:29Z","55030" +"*PortBender.exe*",".{0,1000}PortBender\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","PortBender is a TCP port redirection utility that allows a red team operator to redirect inbound traffic ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/praetorian-inc/PortBender","1","1","N/A","N/A","10","10","712","111","2023-01-31T09:44:16Z","2021-05-27T02:46:29Z","55031" +"*PortBender.h*",".{0,1000}PortBender\.h.{0,1000}","offensive_tool_keyword","cobaltstrike","PortBender is a TCP port redirection utility that allows a red team operator to redirect inbound traffic ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/praetorian-inc/PortBender","1","1","N/A","N/A","10","10","712","111","2023-01-31T09:44:16Z","2021-05-27T02:46:29Z","55032" +"*PortBender.sln*",".{0,1000}PortBender\.sln.{0,1000}","offensive_tool_keyword","cobaltstrike","PortBender is a TCP port redirection utility that allows a red team operator to redirect inbound traffic ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/praetorian-inc/PortBender","1","1","N/A","N/A","10","10","712","111","2023-01-31T09:44:16Z","2021-05-27T02:46:29Z","55033" +"*PortBender.zip*",".{0,1000}PortBender\.zip.{0,1000}","offensive_tool_keyword","cobaltstrike","PortBender is a TCP port redirection utility that allows a red team operator to redirect inbound traffic ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/praetorian-inc/PortBender","1","1","N/A","N/A","10","10","712","111","2023-01-31T09:44:16Z","2021-05-27T02:46:29Z","55034" +"*portscan.rc*",".{0,1000}portscan\.rc.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","55058" +"*portscan_result.cna*",".{0,1000}portscan_result\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","55059" +"*PortScan-Alive*",".{0,1000}PortScan\-Alive.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","55062" +"*portscanner.js*",".{0,1000}portscanner\.js.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","55063" +"*portscanner.py*",".{0,1000}portscanner\.py.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","55064" +"*Portscan-Port*",".{0,1000}Portscan\-Port.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","55065" +"*portScanWithService.py*",".{0,1000}portScanWithService\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55066" +"*portScanWithService.py*",".{0,1000}portScanWithService\.py.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","55067" +"*portswigger.net*",".{0,1000}portswigger\.net.{0,1000}","offensive_tool_keyword","burpsuite","Burp Suite is a leading range of cybersecurity tools. brought to you by PortSwigger. We believe in giving our users a competitive advantage through superior research. This tool is not free and open source","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://portswigger.net/","1","1","N/A","network exploitation tool","N/A","N/A","N/A","N/A","N/A","N/A","55068" +"*PortSwigger/http-request-smuggler*",".{0,1000}PortSwigger\/http\-request\-smuggler.{0,1000}","offensive_tool_keyword","burpsuite","Collection of burpsuite plugins","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","network exploitation tool","N/A","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","55070" +"*posh_in_mem*",".{0,1000}posh_in_mem.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","55071" +"*posh_stageless.py*",".{0,1000}posh_stageless\.py.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","55072" +"*Posh_v4_dropper_*",".{0,1000}Posh_v4_dropper_.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","55073" +"*Posh_v4_x64_*.bin*",".{0,1000}Posh_v4_x64_.{0,1000}\.bin.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","55074" +"*Posh_v4_x86_*.bin*",".{0,1000}Posh_v4_x86_.{0,1000}\.bin.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","55075" +"*PoshADCS-master.zip*",".{0,1000}PoshADCS\-master\.zip.{0,1000}","offensive_tool_keyword","PoshADCS","attack vectors against Active Directory by abusing Active Directory Certificate Services (ADCS)","T1213.003 - T1213 - T1098.003 - T1098 - T1484.001","TA0002 - TA0003 - TA0040","N/A","N/A","Persistence","https://github.com/cfalta/PoshADCS","1","1","N/A","N/A","7","2","186","17","2021-07-07T16:47:07Z","2019-10-15T15:54:03Z","55076" +"*PoshC2-*.zip*",".{0,1000}PoshC2\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","55077" +"*poshc2.server*",".{0,1000}poshc2\.server.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","55078" +"*poshc2.service*",".{0,1000}poshc2\.service.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","55079" +"*poshc2-ansible-main.yml*",".{0,1000}poshc2\-ansible\-main\.yml.{0,1000}","offensive_tool_keyword","poshc2","PoshC2 is a proxy aware C2 framework used to aid penetration testers with red teaming. post-exploitation and Lateral Movement. PoshC2 is primarily written in Python3 and follows a modular format to enable users to add their own modules and tools. allowing an extendible and flexible C2 framework. Out-of-the-box PoshC2 comes PowerShell/C# and Python implants with payloads written in PowerShell v2 and v4. C++ and C# source code. a variety of executables. DLLs and raw shellcode in addition to a Python2 payload. These enable C2 functionality on a wide range of devices and operating systems. including Windows. *nix and OSX.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","55080" +"*posh-cookie-decryptor*",".{0,1000}posh\-cookie\-decryptor.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","55081" +"*poshkatz.psd1*",".{0,1000}poshkatz\.psd1.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/Stealthbits/poshkatz","1","1","N/A","N/A","10","3","212","33","2019-12-28T15:53:40Z","2018-10-29T16:07:40Z","55084" +"*post/windows/gather*",".{0,1000}post\/windows\/gather.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","55093" +"*post/windows/gather/credentials/vnc*",".{0,1000}post\/windows\/gather\/credentials\/vnc.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","55094" +"*post_breach_handler.py*",".{0,1000}post_breach_handler\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","55095" +"*post_ex_amsi_disable*",".{0,1000}post_ex_amsi_disable.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","55096" +"*post_ex_keylogger*",".{0,1000}post_ex_keylogger.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","55097" +"*post_ex_obfuscate*",".{0,1000}post_ex_obfuscate.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","55098" +"*Post_EX_Process_Name*",".{0,1000}Post_EX_Process_Name.{0,1000}","offensive_tool_keyword","cobaltstrike","SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tylous/SourcePoint","1","1","N/A","N/A","10","10","1109","156","2025-04-16T17:15:04Z","2021-08-06T20:55:26Z","55099" +"*post_ex_smartinject*",".{0,1000}post_ex_smartinject.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","55100" +"*post_ex_spawnto_x64*",".{0,1000}post_ex_spawnto_x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","55101" +"*post_ex_spawnto_x86*",".{0,1000}post_ex_spawnto_x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","55102" +"*POST_EXPLOIT_DIR*",".{0,1000}POST_EXPLOIT_DIR.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","55103" +"*post_exploitation.py*",".{0,1000}post_exploitation\.py.{0,1000}","offensive_tool_keyword","hackingtool","ALL IN ONE Hacking Tool For Hackers","T1059 - T1078 - T1105 - T1110 - T1566","TA0002 - TA0008 - TA0009 - TA0005 - TA0007","N/A","N/A","Exploitation tool","https://github.com/Z4nzu/hackingtool","1","1","N/A","N/A","N/A","10","52217","5629","2025-03-03T15:17:19Z","2020-04-11T09:21:31Z","55104" +"*POSTDump*PROCEXP.sys*",".{0,1000}POSTDump.{0,1000}PROCEXP\.sys.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection","T1003","TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","1","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","55105" +"*POSTDump.git*",".{0,1000}POSTDump\.git.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection","T1003","TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","1","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","55107" +"*PostDump.ps1",".{0,1000}PostDump\.ps1","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection","T1003","TA0006","N/A","Black Basta","Credential Access","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","55108" +"*POSTDump-main*",".{0,1000}POSTDump\-main.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection.","T1003.001 - T1055 - T1564.001","TA0005 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","1","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","55111" +"*PostExploitation.psm1*",".{0,1000}PostExploitation\.psm1.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","55112" +"*postgres_default_pass.txt*",".{0,1000}postgres_default_pass\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","55113" +"*postgres_default_user.txt*",".{0,1000}postgres_default_user\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","55114" +"*PostMulitDomainSpider.py*",".{0,1000}PostMulitDomainSpider\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55118" +"*PostMulitMsfGetDomainInfoByBloodHound.py*",".{0,1000}PostMulitMsfGetDomainInfoByBloodHound\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55119" +"*PostPowershellPowerViewAddNetUser.py*",".{0,1000}PostPowershellPowerViewAddNetUser\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55120" +"*PostPowershellPowerViewGetNetGroup.py*",".{0,1000}PostPowershellPowerViewGetNetGroup\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55121" +"*PostPowershellPowerViewGetNetGroupMember.py*",".{0,1000}PostPowershellPowerViewGetNetGroupMember\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55122" +"*PostPowershellPowerViewGetNetProcess.py*",".{0,1000}PostPowershellPowerViewGetNetProcess\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55123" +"*PostPowershellPowerViewUserHunter.py*",".{0,1000}PostPowershellPowerViewUserHunter\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55124" +"*postrequest/link.git*",".{0,1000}postrequest\/link\.git.{0,1000}","offensive_tool_keyword","link","link is a command and control framework written in rust","T1071 - T1094 - T1132 - T1008 - T1024","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/postrequest/link","1","1","N/A","N/A","10","10","575","90","2021-08-18T11:53:55Z","2021-02-02T11:15:43Z","55125" +"*PostRewMsfAuxiliaryCVE*.py*",".{0,1000}PostRewMsfAuxiliaryCVE.{0,1000}\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55126" +"*PostRewMsfExample.py*",".{0,1000}PostRewMsfExample\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55127" +"*PostRewMsfPostConfInfos.py*",".{0,1000}PostRewMsfPostConfInfos\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55128" +"*PotatoTrigger.cpp*",".{0,1000}PotatoTrigger\.cpp.{0,1000}","offensive_tool_keyword","JuicyPotatoNG","Another Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","FoxKitten - APT33 - Volatile Cedar - Sandworm","Privilege Escalation","https://github.com/antonioCoco/JuicyPotatoNG","1","1","N/A","N/A","10","9","844","101","2022-11-12T01:48:39Z","2022-09-21T17:08:35Z","55131" +"*PowerBreach.ps1*",".{0,1000}PowerBreach\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerBreach.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","55134" +"*PowerBruteLogon.*",".{0,1000}PowerBruteLogon\..{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","1","N/A","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","55135" +"*PowerBruteLogon.zip*",".{0,1000}PowerBruteLogon\.zip.{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","1","N/A","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","55136" +"*Powercat.ps1*",".{0,1000}Powercat\.ps1.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","55141" +"*powerdump.ps1*",".{0,1000}powerdump\.ps1.{0,1000}","offensive_tool_keyword","DAMP","The Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification.","T1222 - T1222.002 - T1548 - T1548.002","TA0005 ","N/A","N/A","Persistence","https://github.com/HarmJ0y/DAMP","1","1","N/A","N/A","10","4","378","79","2019-07-25T21:18:37Z","2018-04-06T22:13:58Z","55142" +"*powerdump.ps1*",".{0,1000}powerdump\.ps1.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","55143" +"*powerdump.rb*",".{0,1000}powerdump\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","55144" +"*PowerExtract-main.zip*",".{0,1000}PowerExtract\-main\.zip.{0,1000}","offensive_tool_keyword","powerextract","This tool is able to parse memory dumps of the LSASS process without any additional tools (e.g. Debuggers) or additional sideloading of mimikatz. It is a pure PowerShell implementation for parsing and extracting secrets (LSA / MSV and Kerberos) of the LSASS process","T1003 - T1055 - T1003.001 - T1055.012","TA0007 - TA0002","N/A","N/A","Credential Access","https://github.com/powerseb/PowerExtract","1","1","N/A","N/A","N/A","2","117","14","2025-03-28T10:49:43Z","2021-12-11T15:24:44Z","55145" +"*PowerForensics*",".{0,1000}PowerForensics.{0,1000}","offensive_tool_keyword","PowerForensics","The purpose of PowerForensics is to provide an all inclusive framework for hard drive forensic analysis. PowerForensics currently supports NTFS and FAT file systems. and work has begun on Extended File System and HFS+ support.","T1003 - T1039 - T1046 - T1057","TA0005 - TA0007 - TA0010","N/A","N/A","Reconnaissance","https://github.com/Invoke-IR/PowerForensics","1","1","N/A","N/A","N/A","10","1398","275","2023-11-16T10:31:37Z","2015-03-07T17:12:19Z","55146" +"*powerglot.py*",".{0,1000}powerglot\.py.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","55147" +"*powerkatz.dll*",".{0,1000}powerkatz\.dll.{0,1000}","offensive_tool_keyword","HardHatC2","A C# Command & Control framework","T1105 - T1573 - T1071 - T1027","TA0011 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/DragoQCC/HardHatC2","1","1","N/A","N/A","10","10","996","130","2024-03-28T02:30:02Z","2022-12-08T19:40:47Z","55148" +"*powerkatz.dll*",".{0,1000}powerkatz\.dll.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","https://www.virustotal.com/gui/file-analysis/YjU2NjE0YjBiOGNlMzNhZDVlYzRhYWFkMjJhNzQ4ZGQ6MTcyNDUyMDQ0Mw==","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","55149" +"*powerkatz_x64.dll*",".{0,1000}powerkatz_x64\.dll.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","55150" +"*powerkatz_x86.dll*",".{0,1000}powerkatz_x86\.dll.{0,1000}","offensive_tool_keyword","covenant","Covenant is a collaborative .NET C2 framework for red teamers","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1570-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/cobbr/Covenant","1","1","N/A","N/A","10","10","4363","783","2024-07-18T17:25:35Z","2019-02-07T15:55:18Z","55151" +"*PowerLessShell*",".{0,1000}PowerLessShell.{0,1000}","offensive_tool_keyword","PowerLessShell","PowerLessShell rely on MSBuild.exe to remotely execute PowerShell scripts and commands without spawning powershell.exe. You can also execute raw shellcode using the same approach.","T1218.010 - T1059 - T1105 - T1047 - T1055","TA0002 - TA0011 - TA0008","N/A","N/A","Defense Evasion","https://github.com/Mr-Un1k0d3r/PowerLessShell","1","1","N/A","N/A","N/A","10","1498","256","2023-03-23T13:30:14Z","2017-05-29T23:03:52Z","55152" +"*PowerLessShell.py*",".{0,1000}PowerLessShell\.py.{0,1000}","offensive_tool_keyword","PowerLessShell","PowerLessShell rely on MSBuild.exe to remotely execute PowerShell scripts and commands without spawning powershell.exe. You can also execute raw shellcode using the same approach.","T1218.010 - T1059 - T1105 - T1047 - T1055","TA0002 - TA0011 - TA0008","N/A","N/A","Defense Evasion","https://github.com/Mr-Un1k0d3r/PowerLessShell","1","1","N/A","N/A","N/A","10","1498","256","2023-03-23T13:30:14Z","2017-05-29T23:03:52Z","55153" +"*powermad.ps1*",".{0,1000}powermad\.ps1.{0,1000}","offensive_tool_keyword","Powermad","PowerShell MachineAccountQuota and DNS exploit tools","T1087 - T1098 - T1018 - T1046 - T1081","TA0007 - TA0006 - TA0005 - TA0001","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/Kevin-Robertson/Powermad","1","1","N/A","N/A","N/A","10","1303","181","2023-01-11T00:48:35Z","2017-09-05T18:34:03Z","55154" +"*Powermad.psd1*",".{0,1000}Powermad\.psd1.{0,1000}","offensive_tool_keyword","Powermad","PowerShell MachineAccountQuota and DNS exploit tools","T1087 - T1098 - T1018 - T1046 - T1081","TA0007 - TA0006 - TA0005 - TA0001","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/Kevin-Robertson/Powermad","1","1","N/A","N/A","N/A","10","1303","181","2023-01-11T00:48:35Z","2017-09-05T18:34:03Z","55155" +"*Powermad.psm1*",".{0,1000}Powermad\.psm1.{0,1000}","offensive_tool_keyword","Powermad","PowerShell MachineAccountQuota and DNS exploit tools","T1087 - T1098 - T1018 - T1046 - T1081","TA0007 - TA0006 - TA0005 - TA0001","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/Kevin-Robertson/Powermad","1","1","N/A","N/A","N/A","10","1303","181","2023-01-11T00:48:35Z","2017-09-05T18:34:03Z","55156" +"*Powermad-master*",".{0,1000}Powermad\-master.{0,1000}","offensive_tool_keyword","Powermad","PowerShell MachineAccountQuota and DNS exploit tools","T1087 - T1098 - T1018 - T1046 - T1081","TA0007 - TA0006 - TA0005 - TA0001","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/Kevin-Robertson/Powermad","1","1","N/A","N/A","N/A","10","1303","181","2023-01-11T00:48:35Z","2017-09-05T18:34:03Z","55157" +"*powerpick.py*",".{0,1000}powerpick\.py.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","55162" +"*PowerPick.x64.dll*",".{0,1000}PowerPick\.x64\.dll.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","55163" +"*Powerpreter.psm1*",".{0,1000}Powerpreter\.psm1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","55164" +"*power-pwn-main*",".{0,1000}power\-pwn\-main.{0,1000}","offensive_tool_keyword","power-pwn","An offensive and defensive security toolset for Microsoft 365 Power Platform","T1078 - T1078.004 - T1136 - T1136.001 - T1021 - T1021.003 - T1114 - T1114.002","TA0003 - TA0004 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/mbrg/power-pwn","1","1","N/A","N/A","10","10","939","100","2025-03-20T08:54:43Z","2022-06-14T11:40:21Z","55169" +"*PowerSCCM.ps1*",".{0,1000}PowerSCCM\.ps1.{0,1000}","offensive_tool_keyword","PowerSCCM","PowerSCCM - PowerShell module to interact with SCCM deployments","T1059.001 - T1018 - T1072 - T1047","TA0005 - TA0003 - TA0002","N/A","N/A","Exploitation tool","https://github.com/PowerShellMafia/PowerSCCM","1","1","N/A","N/A","8","4","354","106","2022-01-22T15:30:56Z","2016-01-28T00:20:22Z","55170" +"*PowerSCCM.psd1*",".{0,1000}PowerSCCM\.psd1.{0,1000}","offensive_tool_keyword","PowerSCCM","PowerSCCM - PowerShell module to interact with SCCM deployments","T1059.001 - T1018 - T1072 - T1047","TA0005 - TA0003 - TA0002","N/A","N/A","Exploitation tool","https://github.com/PowerShellMafia/PowerSCCM","1","1","N/A","N/A","8","4","354","106","2022-01-22T15:30:56Z","2016-01-28T00:20:22Z","55171" +"*PowerSCCM.psm1*",".{0,1000}PowerSCCM\.psm1.{0,1000}","offensive_tool_keyword","PowerSCCM","PowerSCCM - PowerShell module to interact with SCCM deployments","T1059.001 - T1018 - T1072 - T1047","TA0005 - TA0003 - TA0002","N/A","N/A","Exploitation tool","https://github.com/PowerShellMafia/PowerSCCM","1","1","N/A","N/A","8","4","354","106","2022-01-22T15:30:56Z","2016-01-28T00:20:22Z","55172" +"*PowerSCCM-master*",".{0,1000}PowerSCCM\-master.{0,1000}","offensive_tool_keyword","PowerSCCM","PowerSCCM - PowerShell module to interact with SCCM deployments","T1059.001 - T1018 - T1072 - T1047","TA0005 - TA0003 - TA0002","N/A","N/A","Exploitation tool","https://github.com/PowerShellMafia/PowerSCCM","1","1","N/A","N/A","8","4","354","106","2022-01-22T15:30:56Z","2016-01-28T00:20:22Z","55173" +"*powerseb/PowerExtract*",".{0,1000}powerseb\/PowerExtract.{0,1000}","offensive_tool_keyword","powerextract","This tool is able to parse memory dumps of the LSASS process without any additional tools (e.g. Debuggers) or additional sideloading of mimikatz. It is a pure PowerShell implementation for parsing and extracting secrets (LSA / MSV and Kerberos) of the LSASS process","T1003 - T1055 - T1003.001 - T1055.012","TA0007 - TA0002","N/A","N/A","Credential Access","https://github.com/powerseb/PowerExtract","1","1","N/A","N/A","N/A","2","117","14","2025-03-28T10:49:43Z","2021-12-11T15:24:44Z","55174" +"*powerseb/PowerExtract*",".{0,1000}powerseb\/PowerExtract.{0,1000}","offensive_tool_keyword","powerextract","This tool is able to parse memory dumps of the LSASS process without any additional tools (e.g. Debuggers) or additional sideloading of mimikatz. It is a pure PowerShell implementation for parsing and extracting secrets (LSA / MSV and Kerberos) of the LSASS process","T1003 - T1055 - T1003.001 - T1055.012","TA0007 - TA0002","N/A","N/A","Credential Access","https://github.com/powerseb/PowerExtract","1","1","N/A","N/A","N/A","2","117","14","2025-03-28T10:49:43Z","2021-12-11T15:24:44Z","55175" +"*PowerSharpBinaries*",".{0,1000}PowerSharpBinaries.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","55176" +"*PowerSharpPack.ps1*",".{0,1000}PowerSharpPack\.ps1.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","55177" +"*PowerSharpPack-master*",".{0,1000}PowerSharpPack\-master.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","55178" +"*PowerShdll*",".{0,1000}PowerShdll.{0,1000}","offensive_tool_keyword","PowerShdll","Run PowerShell with dlls only Does not require access to powershell.exe as it uses powershell automation dlls. PowerShdll can be run with: rundll32.exe. installutil.exe. regsvcs.exe. regasm.exe. regsvr32.exe or as a standalone executable.","T1059 - T1218 - T1216 - T1053 - T1118","TA0002 - TA0008 - TA0003","N/A","N/A","Defense Evasion","https://github.com/p3nt4/PowerShdll","1","1","N/A","N/A","N/A","10","1794","256","2021-03-17T02:02:23Z","2016-07-15T00:08:32Z","55179" +"*powershell_code_execution_invoke_assembly*",".{0,1000}powershell_code_execution_invoke_assembly.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","55248" +"*powershell_collection_keylogger*",".{0,1000}powershell_collection_keylogger.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","55249" +"*powershell_collection_screenshot*",".{0,1000}powershell_collection_screenshot.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","55250" +"*powershell_command_x64.ps1*",".{0,1000}powershell_command_x64\.ps1.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","55251" +"*powershell_command_x86.ps1*",".{0,1000}powershell_command_x86\.ps1.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","55252" +"*powershell_credentials_tokens*",".{0,1000}powershell_credentials_tokens.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","55253" +"*powershell_encode_oneliner*",".{0,1000}powershell_encode_oneliner.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","55254" +"*powershell_encode_oneliner*",".{0,1000}powershell_encode_oneliner.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55255" +"*powershell_encode_stager*",".{0,1000}powershell_encode_stager.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","55256" +"*powershell_encode_stager*",".{0,1000}powershell_encode_stager.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55257" +"*powershell_management_psinject*",".{0,1000}powershell_management_psinject.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","55258" +"*powershell_management_spawn*",".{0,1000}powershell_management_spawn.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","55259" +"*powershell_privesc_bypassuac_eventvwr*",".{0,1000}powershell_privesc_bypassuac_eventvwr.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","55261" +"*powershell_privesc_sherlock*",".{0,1000}powershell_privesc_sherlock.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","55262" +"*powershell_reverse_shell.ps1*",".{0,1000}powershell_reverse_shell\.ps1.{0,1000}","offensive_tool_keyword","chimera","Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.","T1027.002 - T1059.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/tokyoneon/Chimera/","1","1","N/A","N/A","10","10","1493","252","2021-11-09T12:39:59Z","2020-09-01T07:42:22Z","55264" +"*powershell_reverse_tcp.*",".{0,1000}powershell_reverse_tcp\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","55265" +"*powershell_reverse_tcp.py*",".{0,1000}powershell_reverse_tcp\.py.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","55266" +"*powershell_reverse_tcp_v2.py*",".{0,1000}powershell_reverse_tcp_v2\.py.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","55267" +"*powershell_to_vbs.ps1*",".{0,1000}powershell_to_vbs\.ps1.{0,1000}","offensive_tool_keyword","GlllPowerloader","Sample to bypass AV/EDR and upload to transfer.sh","T1059.001 - T1202 - T1105 - T1027 - T1036 - T1070 - T1031 - T1071 - T1048","TA0005 - TA0004 - TA0002 - TA0011 - TA0010","N/A","N/A","Defense Evasion","https://github.com/INotGreen/GlllPowerloader","1","1","N/A","N/A","10","5","451","105","2024-04-12T07:28:24Z","2022-04-26T12:10:58Z","55269" +"*powershell-admin-download-execute.ino*",".{0,1000}powershell\-admin\-download\-execute\.ino.{0,1000}","offensive_tool_keyword","Pateensy","payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy","T1056.001 - T1200 - T1036 - T1071","TA0002 - TA0005 - TA0011 - TA0006","N/A","N/A","Exploitation tool","https://github.com/screetsec/Pateensy","1","1","N/A","N/A","N/A","2","143","60","2017-01-26T12:02:56Z","2016-03-21T07:29:38Z","55270" +"*PowershellAgentGenerator.*",".{0,1000}PowershellAgentGenerator\..{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","55271" +"*PowershellAmsiGenerator*",".{0,1000}PowershellAmsiGenerator.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","55272" +"*PowerShellArsenal*",".{0,1000}PowerShellArsenal.{0,1000}","offensive_tool_keyword","PowerShellArsenal","PowerShellArsenal is a PowerShell module used to aid a reverse engineer. The module can be used to disassemble managed and unmanaged code. perform .NET malware analysis. analyze/scrape memory. parse file formats and memory structures. obtain internal system information. etc.","T1057 - T1053 - T1050 - T1564 - T1083 - T1003","TA0002 - TA0003 - TA0009","N/A","N/A","Exploitation tool","https://github.com/mattifestation/PowerShellArsenal","1","1","N/A","N/A","N/A","9","870","203","2021-08-20T08:41:50Z","2014-11-16T15:20:17Z","55273" +"*PowerShellArtifactGenerator.py*",".{0,1000}PowerShellArtifactGenerator\.py.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","55274" +"*PowershellCradleGenerator.*",".{0,1000}PowershellCradleGenerator\..{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","55275" +"*PowerShellEmpire*",".{0,1000}PowerShellEmpire.{0,1000}","offensive_tool_keyword","empire","PowerShell offers a multitude of offensive advantages. including full .NET access. application whitelisting. direct access to the Win32 API. the ability to assemble malicious binaries in memory. and a default installation on Windows 7+. Offensive PowerShell had a watershed year in 2014. but despite the multitude of useful projects. many pentesters still struggle to integrate PowerShell into their engagements in a secure manner.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1047","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://www.powershellempire.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55276" +"*PowerShellExecuter.cs*",".{0,1000}PowerShellExecuter\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","55277" +"*PowershellKerberos-main*",".{0,1000}PowershellKerberos\-main.{0,1000}","offensive_tool_keyword","PowershellKerberos","Some scripts to abuse kerberos using Powershell","T1558.003 - T1558.004 - T1059.001","TA0006 - TA0002","N/A","N/A","Exploitation tool","https://github.com/MzHmO/PowershellKerberos","1","1","N/A","N/A","9","4","328","44","2023-07-27T09:53:47Z","2023-04-22T19:16:52Z","55282" +"*PowerShellMafia/PowerSCCM*",".{0,1000}PowerShellMafia\/PowerSCCM.{0,1000}","offensive_tool_keyword","PowerSCCM","PowerSCCM - PowerShell module to interact with SCCM deployments","T1059.001 - T1018 - T1072 - T1047","TA0005 - TA0003 - TA0002","N/A","N/A","Exploitation tool","https://github.com/PowerShellMafia/PowerSCCM","1","1","N/A","N/A","8","4","354","106","2022-01-22T15:30:56Z","2016-01-28T00:20:22Z","55284" +"*PowerShellMafia/PowerSploit*",".{0,1000}PowerShellMafia\/PowerSploit.{0,1000}","offensive_tool_keyword","PowerSploit","PowerSploit is a collection of Microsoft PowerShell modules that can be used to aid penetration testers during all phases of an assessment. PowerSploit is comprised of the following modules and scripts","T1134 - T1087.001 - T1123 - T1547.001 - T1547.005 - T1059.001 - T1543.003 - T1555.004 - T1005 - T1482 - T1574.001 - T1574.007 - T1574.008 - T1574.009 - T1056.001 - T1027.005 - T1027.010 - T1003.001 - T1057 - T1055.001 - T1012 - T1620 - T1053.005 - T1113 - T1558.003 - T1552.002 - T1552.006 - T1047","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","Dispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - Turla","Framework","https://github.com/PowerShellMafia/PowerSploit","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","55285" +"*PowerShellObfuscator.ps1*",".{0,1000}PowerShellObfuscator\.ps1.{0,1000}","offensive_tool_keyword","PSAmsi","PSAmsi is a tool for auditing and defeating AMSI signatures.","T1059.001 - T1562.001 - T1070.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/cobbr/PSAmsi","1","1","N/A","N/A","7","4","390","74","2018-04-22T20:56:33Z","2017-09-22T11:48:47Z","55286" +"*PowerShellRunner*runner.ps1*",".{0,1000}PowerShellRunner.{0,1000}runner\.ps1.{0,1000}","offensive_tool_keyword","PowerShellRunner","PowerShell runner for executing malicious payloads in order to bypass Windows Defender","T1059.001 - T1562.001 - T1218.005","TA0002 - TA0005","N/A","Turla","Defense Evasion","https://github.com/dievus/PowerShellRunner","1","1","N/A","N/A","9","1","70","20","2021-11-22T18:43:16Z","2021-08-03T01:29:34Z","55287" +"*PowershellRunner.h*",".{0,1000}PowershellRunner\.h.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","55288" +"*PowerShellStager*",".{0,1000}PowerShellStager.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","55290" +"*PowerShell-Suite*",".{0,1000}PowerShell\-Suite.{0,1000}","offensive_tool_keyword","PowerShell-Suite","There are great tools and resources online to accomplish most any task in PowerShell. sometimes however. there is a need to script together a util for a specific purpose or to bridge an ontological gap. This is a collection of PowerShell utilities I put together either for fun or because I had a narrow application in mind.","T1059 - T1086 - T1140 - T1145 - T1216","TA0002 - TA0003 - TA0005","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/PowerShell-Suite","1","1","N/A","N/A","N/A","10","2659","769","2021-11-19T12:18:24Z","2015-12-11T13:14:41Z","55291" +"*PowershellTools-main.zip*",".{0,1000}PowershellTools\-main\.zip.{0,1000}","offensive_tool_keyword","PowershellTools","Powershell tools used for Red Team / Pentesting","T1087.002 - T1069.001 - T1069.002 - T1598.002 - T1083 - T1558.003 - T1564.001 - T1112","TA0007 - TA0003 - TA0006 - TA0040 - TA0005 - TA0003","N/A","N/A","Exploitation tool","https://github.com/gustanini/PowershellTools","1","1","N/A","N/A","10","1","76","13","2024-01-08T10:33:20Z","2023-10-26T16:49:59Z","55292" +"*PowerShx.dll*",".{0,1000}PowerShx\.dll.{0,1000}","offensive_tool_keyword","PowerShx","Run Powershell without software restrictions.","T1059.001 - T1055.001 - T1055.012","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/iomoath/PowerShx","1","1","N/A","N/A","7","3","286","47","2021-09-08T03:44:10Z","2021-09-06T18:32:45Z","55293" +"*PowerShx.exe*",".{0,1000}PowerShx\.exe.{0,1000}","offensive_tool_keyword","PowerShx","Run Powershell without software restrictions.","T1059.001 - T1055.001 - T1055.012","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/iomoath/PowerShx","1","1","N/A","N/A","7","3","286","47","2021-09-08T03:44:10Z","2021-09-06T18:32:45Z","55294" +"*PowerShx.sln*",".{0,1000}PowerShx\.sln.{0,1000}","offensive_tool_keyword","PowerShx","Run Powershell without software restrictions.","T1059.001 - T1055.001 - T1055.012","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/iomoath/PowerShx","1","1","N/A","N/A","7","3","286","47","2021-09-08T03:44:10Z","2021-09-06T18:32:45Z","55295" +"*PowerShxDll.csproj*",".{0,1000}PowerShxDll\.csproj.{0,1000}","offensive_tool_keyword","PowerShx","Run Powershell without software restrictions.","T1059.001 - T1055.001 - T1055.012","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/iomoath/PowerShx","1","1","N/A","N/A","7","3","286","47","2021-09-08T03:44:10Z","2021-09-06T18:32:45Z","55296" +"*PowerShx-master*",".{0,1000}PowerShx\-master.{0,1000}","offensive_tool_keyword","PowerShx","Run Powershell without software restrictions.","T1059.001 - T1055.001 - T1055.012","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/iomoath/PowerShx","1","1","N/A","N/A","7","3","286","47","2021-09-08T03:44:10Z","2021-09-06T18:32:45Z","55297" +"*PowerSploit*",".{0,1000}PowerSploit.{0,1000}","offensive_tool_keyword","PowerSploit","PowerSploit is a collection of Microsoft PowerShell modules that can be used to aid penetration testers during all phases of an assessment. PowerSploit is comprised of the following modules and scripts","T1134 - T1087.001 - T1123 - T1547.001 - T1547.005 - T1059.001 - T1543.003 - T1555.004 - T1005 - T1482 - T1574.001 - T1574.007 - T1574.008 - T1574.009 - T1056.001 - T1027.005 - T1027.010 - T1003.001 - T1057 - T1055.001 - T1012 - T1620 - T1053.005 - T1113 - T1558.003 - T1552.002 - T1552.006 - T1047","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","Dispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - Turla","Framework","https://github.com/PowerShellMafia/PowerSploit","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","55298" +"*PowerSploit-*.zip*",".{0,1000}PowerSploit\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","PowerSploit","PowerSploit is a collection of Microsoft PowerShell modules that can be used to aid penetration testers during all phases of an assessment. PowerSploit is comprised of the following modules and scripts","T1134 - T1087.001 - T1123 - T1547.001 - T1547.005 - T1059.001 - T1543.003 - T1555.004 - T1005 - T1482 - T1574.001 - T1574.007 - T1574.008 - T1574.009 - T1056.001 - T1027.005 - T1027.010 - T1003.001 - T1057 - T1055.001 - T1012 - T1620 - T1053.005 - T1113 - T1558.003 - T1552.002 - T1552.006 - T1047","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","Dispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - Turla","Framework","https://github.com/PowerShellMafia/PowerSploit","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","55299" +"*PowerSploit.*",".{0,1000}PowerSploit\..{0,1000}","offensive_tool_keyword","PowerSploit","PowerSploit is a collection of Microsoft PowerShell modules that can be used to aid penetration testers during all phases of an assessment. PowerSploit is comprised of the following modules and scripts","T1134 - T1087.001 - T1123 - T1547.001 - T1547.005 - T1059.001 - T1543.003 - T1555.004 - T1005 - T1482 - T1574.001 - T1574.007 - T1574.008 - T1574.009 - T1056.001 - T1027.005 - T1027.010 - T1003.001 - T1057 - T1055.001 - T1012 - T1620 - T1053.005 - T1113 - T1558.003 - T1552.002 - T1552.006 - T1047","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","Dispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - Turla","Framework","https://github.com/PowerShellMafia/PowerSploit","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","55300" +"*PowerSploit/releases*",".{0,1000}PowerSploit\/releases.{0,1000}","offensive_tool_keyword","PowerSploit","PowerSploit is a collection of Microsoft PowerShell modules that can be used to aid penetration testers during all phases of an assessment. PowerSploit is comprised of the following modules and scripts","T1134 - T1087.001 - T1123 - T1547.001 - T1547.005 - T1059.001 - T1543.003 - T1555.004 - T1005 - T1482 - T1574.001 - T1574.007 - T1574.008 - T1574.009 - T1056.001 - T1027.005 - T1027.010 - T1003.001 - T1057 - T1055.001 - T1012 - T1620 - T1053.005 - T1113 - T1558.003 - T1552.002 - T1552.006 - T1047","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","Dispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - Turla","Framework","https://github.com/PowerShellMafia/PowerSploit","1","1","N/A","N/A","10","10","12274","4660","2020-08-17T23:19:49Z","2012-05-26T16:08:48Z","55301" +"*powerstager*",".{0,1000}powerstager.{0,1000}","offensive_tool_keyword","PowerStager","PowerStager: This script creates an executable stager that downloads a selected powershell payload.","T1105 - T1059.001 - T1204","TA0002 - TA0003 - TA0004","N/A","N/A","Resource Development","https://github.com/z0noxz/powerstager","1","1","N/A","N/A","N/A","2","184","48","2019-12-15T09:30:05Z","2017-04-17T12:13:31Z","55302" +"*PowerUp.ps1*",".{0,1000}PowerUp\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerUp.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","55303" +"*PowerUp.ps1*",".{0,1000}PowerUp\.ps1.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","55304" +"*PowerUpSQL*",".{0,1000}PowerUpSQL.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","55305" +"*PowerUpSQL.ps1*",".{0,1000}PowerUpSQL\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","55306" +"*PowerView.ps1*",".{0,1000}PowerView\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","55307" +"*PowerView.ps1*",".{0,1000}PowerView\.ps1.{0,1000}","offensive_tool_keyword","DBC2","DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.","T1105 - T1071.004 - T1102","TA0003 - TA0002 - TA0008","N/A","BlackCat - Scattered Spider*","C2","https://github.com/Arno0x/DBC2","1","1","N/A","N/A","10","10","295","86","2017-10-27T07:39:02Z","2016-12-14T10:35:56Z","55308" +"*powerview.ps1*",".{0,1000}powerview\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1078","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","55310" +"*PowerView.ps1*",".{0,1000}PowerView\.ps1.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","55311" +"*PowerView.ps1*",".{0,1000}PowerView\.ps1.{0,1000}","offensive_tool_keyword","PSAttack","PSAttack contains over 100 commands for Privilege Escalation - Recon and Data Exfilitration","T1059 - T1212 - T1012 - T1087 - T1005 - T1041 - T1020","TA0002 - TA0004 - TA0005 - TA0007 - TA0010 - TA0008","N/A","N/A","Exploitation tool","https://github.com/GDSSecurity/PSAttack","1","1","N/A","N/A","10","1","45","15","2017-04-04T20:37:33Z","2016-02-22T23:45:22Z","55313" +"*PowerView_dev.ps1*",".{0,1000}PowerView_dev\.ps1.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","55316" +"*PowerView3-Aggressor*",".{0,1000}PowerView3\-Aggressor.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Aggressor script menu for Powerview/SharpView","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tevora-threat/PowerView3-Aggressor","1","1","N/A","N/A","10","10","130","40","2018-07-24T21:52:03Z","2018-07-24T21:16:10Z","55318" +"*ppenum.c*",".{0,1000}ppenum\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Simple BOF to read the protection level of a process","T1012","TA0007","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Reconnaissance","https://github.com/rasta-mouse/PPEnum","1","1","N/A","N/A","N/A","2","115","9","2023-05-10T16:41:09Z","2023-05-10T16:38:36Z","55320" +"*ppenum.exe*",".{0,1000}ppenum\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Simple BOF to read the protection level of a process","T1012","TA0007","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Reconnaissance","https://github.com/rasta-mouse/PPEnum","1","1","N/A","N/A","N/A","2","115","9","2023-05-10T16:41:09Z","2023-05-10T16:38:36Z","55321" +"*ppenum.x64.*",".{0,1000}ppenum\.x64\..{0,1000}","offensive_tool_keyword","cobaltstrike","Simple BOF to read the protection level of a process","T1012","TA0007","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Reconnaissance","https://github.com/rasta-mouse/PPEnum","1","1","N/A","N/A","N/A","2","115","9","2023-05-10T16:41:09Z","2023-05-10T16:38:36Z","55322" +"*ppenum.x86.*",".{0,1000}ppenum\.x86\..{0,1000}","offensive_tool_keyword","cobaltstrike","Simple BOF to read the protection level of a process","T1012","TA0007","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Reconnaissance","https://github.com/rasta-mouse/PPEnum","1","1","N/A","N/A","N/A","2","115","9","2023-05-10T16:41:09Z","2023-05-10T16:38:36Z","55323" +"*ppid_shellcode_spawn.bin*",".{0,1000}ppid_shellcode_spawn\.bin.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","55324" +"*ppidShellcodeSpawn4-cleaned.bin*",".{0,1000}ppidShellcodeSpawn4\-cleaned\.bin.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","55325" +"*ppidShellcodeSpawn-cleaned.bin*",".{0,1000}ppidShellcodeSpawn\-cleaned\.bin.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","55326" +"*PPIDSpoof.ps1*",".{0,1000}PPIDSpoof\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","55327" +"*ppl_dump.x64*",".{0,1000}ppl_dump\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/PPLDump_BOF","1","1","N/A","N/A","10","10","140","25","2021-09-24T07:10:04Z","2021-09-24T07:05:59Z","55329" +"*ppl_medic_dll.*",".{0,1000}ppl_medic_dll\..{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","55330" +"*PPLBlade.dmp*",".{0,1000}PPLBlade\.dmp.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","1","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","55331" +"*PPLBlade.exe*",".{0,1000}PPLBlade\.exe.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","1","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","55332" +"*PPLBlade-main.*",".{0,1000}PPLBlade\-main\..{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","1","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","55333" +"*PPLdump*",".{0,1000}PPLdump.{0,1000}","offensive_tool_keyword","ppldump","Dump the memory of a PPL with a userland exploit","T1003 - T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/itm4n/PPLdump","1","1","N/A","N/A","10","9","868","140","2022-07-24T14:03:14Z","2021-04-07T13:12:47Z","55335" +"*PPLdump.exe*",".{0,1000}PPLdump\.exe.{0,1000}","offensive_tool_keyword","ppldump","Dump the memory of a PPL with a userland exploit","T1003 - T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/itm4n/PPLdump","1","1","N/A","N/A","10","9","868","140","2022-07-24T14:03:14Z","2021-04-07T13:12:47Z","55336" +"*ppldump.py*",".{0,1000}ppldump\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","55337" +"*PPLDump_BOF.*",".{0,1000}PPLDump_BOF\..{0,1000}","offensive_tool_keyword","cobaltstrike","A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/PPLDump_BOF","1","1","N/A","N/A","10","10","140","25","2021-09-24T07:10:04Z","2021-09-24T07:05:59Z","55338" +"*ppldump_embedded*",".{0,1000}ppldump_embedded.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","55339" +"*PPLdump64.exe*",".{0,1000}PPLdump64\.exe.{0,1000}","offensive_tool_keyword","ppldump","Dump the memory of a PPL with a userland exploit","T1003 - T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/itm4n/PPLdump","1","1","N/A","N/A","10","9","868","140","2022-07-24T14:03:14Z","2021-04-07T13:12:47Z","55340" +"*PPLdumpDll*",".{0,1000}PPLdumpDll.{0,1000}","offensive_tool_keyword","ppldump","Dump the memory of a PPL with a userland exploit","T1003 - T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/itm4n/PPLdump","1","1","N/A","N/A","10","9","868","140","2022-07-24T14:03:14Z","2021-04-07T13:12:47Z","55341" +"*PPLFault.*",".{0,1000}PPLFault\..{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","55342" +"*pplfault.cna*",".{0,1000}pplfault\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Takes the original PPLFault and the original included DumpShellcode and combinds it all into a BOF targeting cobalt strike.","T1055 - T1078.003","TA0002 - TA0006","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Credential Access","https://github.com/trustedsec/PPLFaultDumpBOF","1","1","N/A","N/A","N/A","2","140","11","2023-05-17T12:57:20Z","2023-05-16T13:02:22Z","55343" +"*PPLFault.exe*",".{0,1000}PPLFault\.exe.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","55344" +"*PPLFaultDumpBOF*",".{0,1000}PPLFaultDumpBOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Takes the original PPLFault and the original included DumpShellcode and combinds it all into a BOF targeting cobalt strike.","T1055 - T1078.003","TA0002 - TA0006","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Credential Access","https://github.com/trustedsec/PPLFaultDumpBOF","1","1","N/A","N/A","N/A","2","140","11","2023-05-17T12:57:20Z","2023-05-16T13:02:22Z","55345" +"*PPLFault-Localhost-SMB.ps1*",".{0,1000}PPLFault\-Localhost\-SMB\.ps1.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","55346" +"*PPLFault-Patch-Downgrade/Config.xml*",".{0,1000}PPLFault\-Patch\-Downgrade\/Config\.xml.{0,1000}","offensive_tool_keyword","WindowsDowndate","A tool that takes over Windows Updates to craft custom downgrades and expose past fixed vulnerabilities","T1072 - T1486 - T1505.002 - T1495 - T1499.004","TA0005 - TA0004 - TA0003 ","N/A","N/A","Defense Evasion","https://github.com/SafeBreach-Labs/WindowsDowndate","1","1","N/A","N/A","10","7","663","88","2024-10-26T10:18:49Z","2024-01-08T19:42:47Z","55347" +"*PPLFaultPayload.dll*",".{0,1000}PPLFaultPayload\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Takes the original PPLFault and the original included DumpShellcode and combinds it all into a BOF targeting cobalt strike.","T1055 - T1078.003","TA0002 - TA0006","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Credential Access","https://github.com/trustedsec/PPLFaultDumpBOF","1","1","N/A","N/A","N/A","2","140","11","2023-05-17T12:57:20Z","2023-05-16T13:02:22Z","55348" +"*PPLFaultPayload.dll*",".{0,1000}PPLFaultPayload\.dll.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","55349" +"*PPLFaultTemp*",".{0,1000}PPLFaultTemp.{0,1000}","offensive_tool_keyword","cobaltstrike","Takes the original PPLFault and the original included DumpShellcode and combinds it all into a BOF targeting cobalt strike.","T1055 - T1078.003","TA0002 - TA0006","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Credential Access","https://github.com/trustedsec/PPLFaultDumpBOF","1","1","N/A","N/A","N/A","2","140","11","2023-05-17T12:57:20Z","2023-05-16T13:02:22Z","55350" +"*PPLFaultTemp*",".{0,1000}PPLFaultTemp.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","55351" +"*PPLKiller.exe*",".{0,1000}PPLKiller\.exe.{0,1000}","offensive_tool_keyword","PPLKiller","Tool to bypass LSA Protection (aka Protected Process Light)","T1547.002 - T1558.003","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/RedCursorSecurityConsulting/PPLKiller","1","1","N/A","N/A","10","10","933","139","2022-12-04T23:38:31Z","2020-07-06T10:11:49Z","55352" +"*PPLKiller.sln*",".{0,1000}PPLKiller\.sln.{0,1000}","offensive_tool_keyword","PPLKiller","Tool to bypass LSA Protection (aka Protected Process Light)","T1547.002 - T1558.003","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/RedCursorSecurityConsulting/PPLKiller","1","1","N/A","N/A","10","10","933","139","2022-12-04T23:38:31Z","2020-07-06T10:11:49Z","55353" +"*PPLKiller.vcxproj*",".{0,1000}PPLKiller\.vcxproj.{0,1000}","offensive_tool_keyword","PPLKiller","Tool to bypass LSA Protection (aka Protected Process Light)","T1547.002 - T1558.003","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/RedCursorSecurityConsulting/PPLKiller","1","1","N/A","N/A","10","10","933","139","2022-12-04T23:38:31Z","2020-07-06T10:11:49Z","55354" +"*PPLKiller-master*",".{0,1000}PPLKiller\-master.{0,1000}","offensive_tool_keyword","PPLKiller","Tool to bypass LSA Protection (aka Protected Process Light)","T1547.002 - T1558.003","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/RedCursorSecurityConsulting/PPLKiller","1","1","N/A","N/A","10","10","933","139","2022-12-04T23:38:31Z","2020-07-06T10:11:49Z","55355" +"*PPLmedicDll.dll*",".{0,1000}PPLmedicDll\.dll.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","1","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","55357" +"*PppEWCIgXbsepIwnuRIHtQLC*",".{0,1000}PppEWCIgXbsepIwnuRIHtQLC.{0,1000}","offensive_tool_keyword","ThunderShell","ThunderShell is a C# RAT that communicates via HTTP requests. All the network traffic is encrypted using a second layer of RC4 to avoid SSL interception and defeat network detection on the target system. RC4 is a weak cipher and is used to help obfuscate the traffic. HTTPS options should be used to provide integrity and strong encryption.","T1021.002 - T1573.002 - T1001.003","TA0008 - TA0011 - TA0040","N/A","LockBit","C2","https://github.com/Mr-Un1k0d3r/ThunderShell","1","1","N/A","N/A","10","10","779","223","2023-03-29T21:57:08Z","2017-09-12T01:11:29Z","55359" +"*ppypykatz.py*",".{0,1000}ppypykatz\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","55360" +"*ppzmaodrgtg7r6zcputdlaqfliubmmjpo4u56l3ayckut3nyvw6dyayd.onion*",".{0,1000}ppzmaodrgtg7r6zcputdlaqfliubmmjpo4u56l3ayckut3nyvw6dyayd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","55361" +"*praetorian.antihacker*",".{0,1000}praetorian\.antihacker.{0,1000}","offensive_tool_keyword","cobaltstrike","PortBender is a TCP port redirection utility that allows a red team operator to redirect inbound traffic ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/praetorian-inc/PortBender","1","1","N/A","N/A","10","10","712","111","2023-01-31T09:44:16Z","2021-05-27T02:46:29Z","55362" +"*praetorian.com/blog/relaying-to-adfs-attacks/*",".{0,1000}praetorian\.com\/blog\/relaying\-to\-adfs\-attacks\/.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","1","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","55363" +"*praetorian-inc/ADFSRelay*",".{0,1000}praetorian\-inc\/ADFSRelay.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","1","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","55364" +"*praetorian-inc/gato*",".{0,1000}praetorian\-inc\/gato.{0,1000}","offensive_tool_keyword","gato","GitHub Self-Hosted Runner Enumeration and Attack Tool","T1083 - T1087 - T1081","TA0006 - TA0007","N/A","N/A","Reconnaissance","https://github.com/praetorian-inc/gato","1","1","N/A","N/A","N/A","7","630","55","2025-04-10T23:25:04Z","2023-01-06T15:43:27Z","55365" +"*praetorian-inc/noseyparker*",".{0,1000}praetorian\-inc\/noseyparker.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","1","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","55366" +"*praetorian-inc/PortBender*",".{0,1000}praetorian\-inc\/PortBender.{0,1000}","offensive_tool_keyword","cobaltstrike","PortBender is a TCP port redirection utility that allows a red team operator to redirect inbound traffic ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/praetorian-inc/PortBender","1","1","N/A","N/A","10","10","712","111","2023-01-31T09:44:16Z","2021-05-27T02:46:29Z","55367" +"*prepare_ppl_command_line*",".{0,1000}prepare_ppl_command_line.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","55370" +"*prepareResponseForHiddenAPICall*",".{0,1000}prepareResponseForHiddenAPICall.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","55371" +"*Prepouce/CoercedPotato*",".{0,1000}Prepouce\/CoercedPotato.{0,1000}","offensive_tool_keyword","CoercedPotato","CoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022.","T1548.002 - T1134.002","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/Prepouce/CoercedPotato","1","1","N/A","N/A","10","4","366","66","2024-08-26T08:09:00Z","2023-09-11T19:04:29Z","55373" +"*PrimusC2-main.zip*",".{0,1000}PrimusC2\-main\.zip.{0,1000}","offensive_tool_keyword","primusC2","another C2 framework","T1090 - T1071","TA0011 - TA0002","N/A","N/A","C2","https://github.com/Primusinterp/PrimusC2","1","1","N/A","N/A","10","10","55","4","2024-11-01T00:20:02Z","2023-04-19T10:59:30Z","55375" +"*Prince-Ransomware/releases/download*",".{0,1000}Prince\-Ransomware\/releases\/download.{0,1000}","offensive_tool_keyword","Prince-Ransomware","Go ransomware utilising ChaCha20 and ECIES encryption.","T1486 - T1489 - T1027","TA0040 - TA0009 ","N/A","N/A","Ransomware","https://github.com/SecDbg/Prince-Ransomware","1","1","N/A","N/A","10","","N/A","","","","55376" +"*print_shtinkering_crash_location*",".{0,1000}print_shtinkering_crash_location.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","55377" +"*PrinterNotifyPotato.*",".{0,1000}PrinterNotifyPotato\..{0,1000}","offensive_tool_keyword","DCOMPotato","Service DCOM Object and SeImpersonatePrivilege abuse.","T1548.002 - T1134.002","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/zcgonvh/DCOMPotato","1","1","N/A","N/A","10","4","356","48","2022-12-09T01:57:53Z","2022-12-08T14:56:13Z","55380" +"*PrintNightmare.dll*",".{0,1000}PrintNightmare\.dll.{0,1000}","offensive_tool_keyword","PrintNightmare","PrintNightmare exploitation","T1210 - T1059.001 - T1548.002","TA0001 - TA0002 - TA0004","N/A","Dispossessor","Privilege Escalation","https://github.com/outflanknl/PrintNightmare","1","1","N/A","N/A","10","4","337","67","2021-09-13T08:45:26Z","2021-09-13T08:44:02Z","55383" +"*PrintNotifyPotato.exe*",".{0,1000}PrintNotifyPotato\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","55385" +"*PrintNotifyPotato-NET2.exe*",".{0,1000}PrintNotifyPotato\-NET2\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","55386" +"*PrintSpoofer-*",".{0,1000}PrintSpoofer\-.{0,1000}","offensive_tool_keyword","cobaltstrike","Reflection dll implementation of PrintSpoofer used in conjunction with Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/crisprss/PrintSpoofer","1","1","N/A","N/A","10","10","88","12","2021-10-07T17:45:00Z","2021-10-07T17:28:45Z","55390" +"*PrintSpoofer.*",".{0,1000}PrintSpoofer\..{0,1000}","offensive_tool_keyword","cobaltstrike","Reflection dll implementation of PrintSpoofer used in conjunction with Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/crisprss/PrintSpoofer","1","1","N/A","N/A","10","10","88","12","2021-10-07T17:45:00Z","2021-10-07T17:28:45Z","55391" +"*PrintSpoofer.cpp*",".{0,1000}PrintSpoofer\.cpp.{0,1000}","offensive_tool_keyword","PrintSpoofer","Abusing Impersonation Privileges on Windows 10 and Server 2019","T1548.002 - T1055.001 - T1055.002","TA0005 - TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrintSpoofer","1","1","N/A","N/A","10","10","1971","342","2020-09-10T17:49:41Z","2020-04-28T08:26:29Z","55393" +"*PrintSpoofer.exe*",".{0,1000}PrintSpoofer\.exe.{0,1000}","offensive_tool_keyword","PrintSpoofer","Abusing Impersonation Privileges on Windows 10 and Server 2019","T1548.002 - T1055.001 - T1055.002","TA0005 - TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrintSpoofer","1","1","N/A","N/A","10","10","1971","342","2020-09-10T17:49:41Z","2020-04-28T08:26:29Z","55394" +"*printspoofer.exe*",".{0,1000}printspoofer\.exe.{0,1000}","offensive_tool_keyword","PrivFu","Kernel mode WinDbg extension and PoCs for token privilege investigation.","T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001","TA0007 - TA0008 - TA0002 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","55395" +"*printspoofer.py*",".{0,1000}printspoofer\.py.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","55396" +"*PrintSpoofer.sln*",".{0,1000}PrintSpoofer\.sln.{0,1000}","offensive_tool_keyword","PrintSpoofer","Abusing Impersonation Privileges on Windows 10 and Server 2019","T1548.002 - T1055.001 - T1055.002","TA0005 - TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrintSpoofer","1","1","N/A","N/A","10","10","1971","342","2020-09-10T17:49:41Z","2020-04-28T08:26:29Z","55397" +"*PrintSpoofer_x64.exe*",".{0,1000}PrintSpoofer_x64\.exe.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","55398" +"*PrintSpoofer32.exe*",".{0,1000}PrintSpoofer32\.exe.{0,1000}","offensive_tool_keyword","PrintSpoofer","Abusing Impersonation Privileges on Windows 10 and Server 2019","T1548.002 - T1055.001 - T1055.002","TA0005 - TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrintSpoofer","1","1","N/A","N/A","10","10","1971","342","2020-09-10T17:49:41Z","2020-04-28T08:26:29Z","55399" +"*PrintSpoofer32.exe*",".{0,1000}PrintSpoofer32\.exe.{0,1000}","offensive_tool_keyword","printspoofer","Abusing impersonation privileges through the Printer Bug","T1134 - T1003 - T1055","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrintSpoofer","1","1","N/A","N/A","10","10","1971","342","2020-09-10T17:49:41Z","2020-04-28T08:26:29Z","55400" +"*PrintSpoofer64.exe*",".{0,1000}PrintSpoofer64\.exe.{0,1000}","offensive_tool_keyword","PrintSpoofer","Abusing Impersonation Privileges on Windows 10 and Server 2019","T1548.002 - T1055.001 - T1055.002","TA0005 - TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrintSpoofer","1","1","N/A","N/A","10","10","1971","342","2020-09-10T17:49:41Z","2020-04-28T08:26:29Z","55401" +"*PrintSpoofer64.exe*",".{0,1000}PrintSpoofer64\.exe.{0,1000}","offensive_tool_keyword","printspoofer","Abusing impersonation privileges through the Printer Bug","T1134 - T1003 - T1055","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrintSpoofer","1","1","N/A","N/A","10","10","1971","342","2020-09-10T17:49:41Z","2020-04-28T08:26:29Z","55402" +"*PrintSpoofer-master*",".{0,1000}PrintSpoofer\-master.{0,1000}","offensive_tool_keyword","printspoofer","Abusing Impersonation Privileges on Windows 10 and Server 2019","T1548.002 - T1055.001 - T1055.002","TA0005 - TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrintSpoofer","1","1","N/A","N/A","10","10","1971","342","2020-09-10T17:49:41Z","2020-04-28T08:26:29Z","55403" +"*PrintSpooferNet.exe*",".{0,1000}PrintSpooferNet\.exe.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","55404" +"*priv/priv_windows.go*",".{0,1000}priv\/priv_windows\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","55406" +"*privcheck32*",".{0,1000}privcheck32.{0,1000}","offensive_tool_keyword","PrivKit","PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.","T1548.002 - T1059.003 - T1027.002","TA0005","N/A","N/A","Privilege Escalation","https://github.com/mertdas/PrivKit","1","1","N/A","N/A","9","5","405","47","2024-06-15T16:54:32Z","2023-03-20T04:19:40Z","55410" +"*PrivEditor.dll*",".{0,1000}PrivEditor\.dll.{0,1000}","offensive_tool_keyword","PrivFu","Kernel mode WinDbg extension and PoCs for token privilege investigation.","T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001","TA0007 - TA0008 - TA0002 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","55412" +"*privesc_checker*",".{0,1000}privesc_checker.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55415" +"*privesc_checker.py*",".{0,1000}privesc_checker\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55416" +"*privesc_checker.py*",".{0,1000}privesc_checker\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55417" +"*privesc_juicy_potato.py*",".{0,1000}privesc_juicy_potato\.py.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","55419" +"*privesc_powerup.py*",".{0,1000}privesc_powerup\.py.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","55421" +"*privesc-check*",".{0,1000}privesc\-check.{0,1000}","offensive_tool_keyword","windows-privesc-check","privesc script checker - Windows-privesc-check is standalone executable that runs on Windows systems. It tries to find misconfigurations that could allow local unprivileged users to escalate privileges to other users or to access local apps (e.g. databases).","T1048 - T1059 - T1088 - T1208","TA0004 - TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/pentestmonkey/windows-privesc-check","1","1","N/A","N/A","N/A","10","1505","321","2023-08-01T07:35:20Z","2015-03-22T13:39:38Z","55422" +"*PrivescCheck.ps1*",".{0,1000}PrivescCheck\.ps1.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","55423" +"*PrivescCheck_*.*",".{0,1000}PrivescCheck_.{0,1000}\..{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","55424" +"*PrivescCheckAsciiReport*",".{0,1000}PrivescCheckAsciiReport.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","55425" +"*PrivEscManager.cs*",".{0,1000}PrivEscManager\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","55426" +"*privexchange.py*",".{0,1000}privexchange\.py.{0,1000}","offensive_tool_keyword","PrivExchange","Exchange your privileges for Domain Admin privs by abusing Exchange","T1091.001 - T1101 - T1201 - T1570","TA0006","N/A","N/A","Exploitation tool","https://github.com/dirkjanm/PrivExchange","1","1","N/A","N/A","N/A","10","1011","173","2020-01-23T19:48:51Z","2019-01-21T17:39:47Z","55429" +"*privexchange.py*",".{0,1000}privexchange\.py.{0,1000}","offensive_tool_keyword","privexchange","Exchange your privileges for Domain Admin privs by abusing Exchange","T1053.005 - T1078 - T1069.002","TA0002 - TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/dirkjanm/PrivExchange","1","1","N/A","N/A","N/A","10","1011","173","2020-01-23T19:48:51Z","2019-01-21T17:39:47Z","55430" +"*PrivExchange-master.zip*",".{0,1000}PrivExchange\-master\.zip.{0,1000}","offensive_tool_keyword","privexchange","Exchange your privileges for Domain Admin privs by abusing Exchange","T1053.005 - T1078 - T1069.002","TA0002 - TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/dirkjanm/PrivExchange","1","1","N/A","N/A","N/A","10","1011","173","2020-01-23T19:48:51Z","2019-01-21T17:39:47Z","55431" +"*PrivFu-main.zip*",".{0,1000}PrivFu\-main\.zip.{0,1000}","offensive_tool_keyword","PrivFu","Kernel mode WinDbg extension and PoCs for token privilege investigation.","T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001","TA0007 - TA0008 - TA0002 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","55433" +"*PrivFu-master*",".{0,1000}PrivFu\-master.{0,1000}","offensive_tool_keyword","PrivFu","Kernel mode WinDbg extension and PoCs for token privilege investigation.","T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001","TA0007 - TA0008 - TA0002 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","55434" +"*PrivFuPipeClient.exe*",".{0,1000}PrivFuPipeClient\.exe.{0,1000}","offensive_tool_keyword","PrivFu","ArtsOfGetSystem privesc tools","T1134 - T1134.001 - T1078 - T1059 - T1075","TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu/","1","1","N/A","ArtsOfGetSystem","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","55435" +"*privilege::backup*",".{0,1000}privilege\:\:backup.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","55436" +"*privilege::debug*",".{0,1000}privilege\:\:debug.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation command","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","55437" +"*privilege::debug*",".{0,1000}privilege\:\:debug.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","55438" +"*privilege::driver*",".{0,1000}privilege\:\:driver.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","55439" +"*privilege::id*",".{0,1000}privilege\:\:id.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","55440" +"*privilege::name*",".{0,1000}privilege\:\:name.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","55441" +"*privilege::restore*",".{0,1000}privilege\:\:restore.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","55442" +"*privilege::security*",".{0,1000}privilege\:\:security.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","55443" +"*privilege::sysenv*",".{0,1000}privilege\:\:sysenv.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","55444" +"*privilege::tcb*",".{0,1000}privilege\:\:tcb.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","55445" +"*PrivilegeEscalation_BypassUserAccountControl_Windows.py*",".{0,1000}PrivilegeEscalation_BypassUserAccountControl_Windows\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55450" +"*PrivilegeEscalation_EnumPatchExample_Windows.py*",".{0,1000}PrivilegeEscalation_EnumPatchExample_Windows\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55451" +"*PrivilegeEscalation_ExploitationForPrivilegeEscalation_CVE_2021_40449.py*",".{0,1000}PrivilegeEscalation_ExploitationForPrivilegeEscalation_CVE_2021_40449\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55452" +"*PrivilegeEscalation_ExploitationForPrivilegeEscalation_EfsPotato.py*",".{0,1000}PrivilegeEscalation_ExploitationForPrivilegeEscalation_EfsPotato\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55453" +"*PrivilegeEscalation_ExploitationForPrivilegeEscalation_SweetPotato.py*",".{0,1000}PrivilegeEscalation_ExploitationForPrivilegeEscalation_SweetPotato\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55454" +"*PrivilegeEscalation_ExploitationForPrivilegeEscalation_Windows.py*",".{0,1000}PrivilegeEscalation_ExploitationForPrivilegeEscalation_Windows\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55455" +"*PrivilegeEscalation_ProcessInjection_Getsystem.py*",".{0,1000}PrivilegeEscalation_ProcessInjection_Getsystem\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","55456" +"*Privileger.cpp*",".{0,1000}Privileger\.cpp.{0,1000}","offensive_tool_keyword","Privileger","Privileger is a tool to work with Windows Privileges","T1548.002","TA0004 ","N/A","N/A","Privilege Escalation","https://github.com/MzHmO/Privileger","1","1","N/A","N/A","8","2","136","32","2023-02-07T07:28:40Z","2023-01-31T11:24:37Z","55457" +"*Privileger.exe*",".{0,1000}Privileger\.exe.{0,1000}","offensive_tool_keyword","Privileger","Privileger is a tool to work with Windows Privileges","T1548.002","TA0004 ","N/A","N/A","Privilege Escalation","https://github.com/MzHmO/Privileger","1","1","N/A","N/A","8","2","136","32","2023-02-07T07:28:40Z","2023-01-31T11:24:37Z","55458" +"*Privileger-main.*",".{0,1000}Privileger\-main\..{0,1000}","offensive_tool_keyword","Privileger","Privileger is a tool to work with Windows Privileges","T1548.002","TA0004 ","N/A","N/A","Privilege Escalation","https://github.com/MzHmO/Privileger","1","1","N/A","N/A","8","2","136","32","2023-02-07T07:28:40Z","2023-01-31T11:24:37Z","55459" +"*Privilegerx64.exe*",".{0,1000}Privilegerx64\.exe.{0,1000}","offensive_tool_keyword","Privileger","Privileger is a tool to work with Windows Privileges","T1548.002","TA0004 ","N/A","N/A","Privilege Escalation","https://github.com/MzHmO/Privileger","1","1","N/A","N/A","8","2","136","32","2023-02-07T07:28:40Z","2023-01-31T11:24:37Z","55460" +"*Privilegerx86.exe*",".{0,1000}Privilegerx86\.exe.{0,1000}","offensive_tool_keyword","Privileger","Privileger is a tool to work with Windows Privileges","T1548.002","TA0004 ","N/A","N/A","Privilege Escalation","https://github.com/MzHmO/Privileger","1","1","N/A","N/A","8","2","136","32","2023-02-07T07:28:40Z","2023-01-31T11:24:37Z","55461" +"*PrivKit32*",".{0,1000}PrivKit32.{0,1000}","offensive_tool_keyword","PrivKit","PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.","T1548.002 - T1059.003 - T1027.002","TA0005","N/A","N/A","Privilege Escalation","https://github.com/mertdas/PrivKit","1","1","N/A","N/A","9","5","405","47","2024-06-15T16:54:32Z","2023-03-20T04:19:40Z","55462" +"*PrivKit-main*",".{0,1000}PrivKit\-main.{0,1000}","offensive_tool_keyword","PrivKit","PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.","T1548.002 - T1059.003 - T1027.002","TA0005","N/A","N/A","Privilege Escalation","https://github.com/mertdas/PrivKit","1","1","N/A","N/A","9","5","405","47","2024-06-15T16:54:32Z","2023-03-20T04:19:40Z","55463" +"*Probable-Wordlists*",".{0,1000}Probable\-Wordlists.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","55465" +"*Probable-Wordlists*",".{0,1000}Probable\-Wordlists.{0,1000}","offensive_tool_keyword","Probable-Wordlists","real password lists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","55466" +"*procdump.exe*lsass*",".{0,1000}procdump\.exe.{0,1000}lsass.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Dump LSASS memory through a process snapshot (-r) avoiding interacting with it directly","T1003.001","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","55472" +"*procdump/dump_windows.go*",".{0,1000}procdump\/dump_windows\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","55473" +"*procdump_dump*",".{0,1000}procdump_dump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","55474" +"*procdump_embedded*",".{0,1000}procdump_embedded.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","55475" +"*process::exports*",".{0,1000}process\:\:exports.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","55487" +"*process::suspend*",".{0,1000}process\:\:suspend.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","55488" +"*process_imports.cna*",".{0,1000}process_imports\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to parse the imports of a provided PE-file. optionally extracting symbols on a per-dll basis.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/DLL_Imports_BOF","1","1","N/A","N/A","10","10","85","11","2021-10-28T18:07:09Z","2021-10-27T21:02:44Z","55490" +"*process_imports.x64*",".{0,1000}process_imports\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF to parse the imports of a provided PE-file. optionally extracting symbols on a per-dll basis.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/DLL_Imports_BOF","1","1","N/A","N/A","10","10","85","11","2021-10-28T18:07:09Z","2021-10-27T21:02:44Z","55491" +"*process_inject_allocator*",".{0,1000}process_inject_allocator.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","55493" +"*process_inject_bof_allocator*",".{0,1000}process_inject_bof_allocator.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","55494" +"*process_inject_bof_reuse_memory*",".{0,1000}process_inject_bof_reuse_memory.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","55495" +"*process_inject_execute*",".{0,1000}process_inject_execute.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","55496" +"*process_inject_min_alloc*",".{0,1000}process_inject_min_alloc.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","55497" +"*process_inject_startrwx*",".{0,1000}process_inject_startrwx.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","55498" +"*Process_Inject_Struct*",".{0,1000}Process_Inject_Struct.{0,1000}","offensive_tool_keyword","cobaltstrike","SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tylous/SourcePoint","1","1","N/A","N/A","10","10","1109","156","2025-04-16T17:15:04Z","2021-08-06T20:55:26Z","55499" +"*process_inject_transform_x*",".{0,1000}process_inject_transform_x.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","55500" +"*process_inject_userwx*",".{0,1000}process_inject_userwx.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","55501" +"*process_killer.exe*",".{0,1000}process_killer\.exe.{0,1000}","offensive_tool_keyword","mhydeath","Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.","T1562.001","TA0040 - TA0005","N/A","Black Basta","Defense Evasion","https://github.com/zer0condition/mhydeath","1","1","N/A","N/A","10","4","397","71","2023-08-22T08:01:04Z","2023-08-22T07:15:36Z","55502" +"*process_memdump.rb*",".{0,1000}process_memdump\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","55503" +"*process_mimikatz*",".{0,1000}process_mimikatz.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","55504" +"*process_protection_enum*.dmp*",".{0,1000}process_protection_enum.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","cobaltstrike","A BOF port of the research of @thefLinkk and @codewhitesec","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com//EspressoCake/HandleKatz_BOF","1","1","N/A","N/A","10","","N/A","","","","55506" +"*process_protection_enum.*",".{0,1000}process_protection_enum\..{0,1000}","offensive_tool_keyword","cobaltstrike","A Syscall-only BOF file intended to grab process protection attributes. limited to a handful that Red Team operators and pentesters would commonly be interested in.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/Process_Protection_Level_BOF","1","1","N/A","N/A","10","10","58","10","2021-08-30T00:18:57Z","2021-08-29T23:08:22Z","55507" +"*Process_Protection_Level_BOF.*",".{0,1000}Process_Protection_Level_BOF\..{0,1000}","offensive_tool_keyword","cobaltstrike","A Syscall-only BOF file intended to grab process protection attributes. limited to a handful that Red Team operators and pentesters would commonly be interested in.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/Process_Protection_Level_BOF","1","1","N/A","N/A","10","10","58","10","2021-08-30T00:18:57Z","2021-08-29T23:08:22Z","55508" +"*Process_Protection_Level_BOF/*",".{0,1000}Process_Protection_Level_BOF\/.{0,1000}","offensive_tool_keyword","cobaltstrike","A Syscall-only BOF file intended to grab process protection attributes. limited to a handful that Red Team operators and pentesters would commonly be interested in.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/Process_Protection_Level_BOF","1","1","N/A","N/A","10","10","58","10","2021-08-30T00:18:57Z","2021-08-29T23:08:22Z","55509" +"*process_snapshot.exe*",".{0,1000}process_snapshot\.exe.{0,1000}","offensive_tool_keyword","acheron","indirect syscalls for AV/EDR evasion in Go assembly","T1055.012 - T1059.001 - T1059.003","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/f1zm0/acheron","1","1","N/A","N/A","N/A","4","326","39","2023-06-13T19:20:33Z","2023-04-07T10:40:33Z","55510" +"*ProcessCommandChannelImplantMessage*",".{0,1000}ProcessCommandChannelImplantMessage.{0,1000}","offensive_tool_keyword","SharpSocks","Tunnellable HTTP/HTTPS socks4a proxy written in C# and deployable via PowerShell","T1090 - T1021.001","TA0002","N/A","N/A","C2","https://github.com/nettitude/SharpSocks","1","1","N/A","N/A","10","10","482","84","2023-03-15T19:19:30Z","2017-11-10T13:29:08Z","55511" +"*ProcessDestroy.x64*",".{0,1000}ProcessDestroy\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","55512" +"*ProcessDestroy.x64.*",".{0,1000}ProcessDestroy\.x64\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","55513" +"*ProcessDestroy.x86*",".{0,1000}ProcessDestroy\.x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","55514" +"*ProcessDestroy.x86.*",".{0,1000}ProcessDestroy\.x86\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","55515" +"*ProcessEncryptedC2Request*",".{0,1000}ProcessEncryptedC2Request.{0,1000}","offensive_tool_keyword","SharpSocks","Tunnellable HTTP/HTTPS socks4a proxy written in C# and deployable via PowerShell","T1090 - T1021.001","TA0002","N/A","N/A","C2","https://github.com/nettitude/SharpSocks","1","1","N/A","N/A","10","10","482","84","2023-03-15T19:19:30Z","2017-11-10T13:29:08Z","55516" +"*ProcessFileZillaFile*",".{0,1000}ProcessFileZillaFile.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","55517" +"*ProcessHerpaderping_x64*",".{0,1000}ProcessHerpaderping_x64.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","55523" +"*ProcessHerpaderping_x86*",".{0,1000}ProcessHerpaderping_x86.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","55524" +"*ProcessHerpaderpingTemplate*",".{0,1000}ProcessHerpaderpingTemplate.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","55525" +"*processhider.c*",".{0,1000}processhider\.c.{0,1000}","offensive_tool_keyword","Sudomy","Ghost In The Shell - This tool will setting up your backdoor/rootkits when backdoor already setup it will be hidden your spesisifc process.unlimited your session in metasploit and transparent. Even when it killed. it will re-run again. There always be a procces which while run another process.So we can assume that this procces is unstopable like a Ghost in The Shell","T1587 - T1588 - T1608","N/A","N/A","N/A","Exploitation tool","https://github.com/screetsec/Vegile","1","1","#linux","N/A","N/A","8","726","164","2022-09-01T01:54:35Z","2018-01-02T05:29:48Z","55526" +"*processImplantMessage*",".{0,1000}processImplantMessage.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","55528" +"*processinject_min_alloc*",".{0,1000}processinject_min_alloc.{0,1000}","offensive_tool_keyword","cobaltstrike","SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tylous/SourcePoint","1","1","N/A","N/A","10","10","1109","156","2025-04-16T17:15:04Z","2021-08-06T20:55:26Z","55530" +"*ProcessPPKFile*",".{0,1000}ProcessPPKFile.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","55534" +"*ProcessPuTTYLocal*",".{0,1000}ProcessPuTTYLocal.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","55535" +"*ProcessRDPFile*",".{0,1000}ProcessRDPFile.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","55536" +"*ProcessRDPLocal*",".{0,1000}ProcessRDPLocal.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","55537" +"*ProcessSuperPuTTYFile*",".{0,1000}ProcessSuperPuTTYFile.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","55538" +"*Processus-Thief/HEKATOMB*",".{0,1000}Processus\-Thief\/HEKATOMB.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/Processus-Thief/HEKATOMB","1","1","N/A","N/A","10","","N/A","","","","55542" +"*ProcessWinSCPLocal*",".{0,1000}ProcessWinSCPLocal.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","55543" +"*ProcHideDrv_x64.sys*",".{0,1000}ProcHideDrv_x64\.sys.{0,1000}","offensive_tool_keyword","VectorKernel","PoCs for Kernelmode rootkit techniques research.","T1543 - T1055 - T1134 - T1564 - T1070 - T1057 - T1574 - T1562 - T1082 - T1518","TA0003 - TA0005 - TA0004 - TA0008 - TA0007","N/A","N/A","Exploitation tool","https://github.com/daem0nc0re/VectorKernel/","1","1","N/A","N/A","10","4","367","60","2025-01-21T08:22:42Z","2023-11-23T12:36:31Z","55545" +"*ProgIDsUACBypass.*",".{0,1000}ProgIDsUACBypass\..{0,1000}","offensive_tool_keyword","cobaltstrike","Erebus CobaltStrike post penetration testing plugin","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DeEpinGh0st/Erebus","1","1","N/A","N/A","10","10","1518","221","2021-10-28T06:20:51Z","2019-09-26T09:32:00Z","55567" +"*program/replay.pl*",".{0,1000}program\/replay\.pl.{0,1000}","offensive_tool_keyword","nikto","Nikto web server scanner","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/sullo/nikto","1","1","#linux","N/A","N/A","10","9184","1306","2025-02-22T14:30:28Z","2012-11-24T04:24:29Z","55590" +"*projectb-temp/mimidogz*",".{0,1000}projectb\-temp\/mimidogz.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","1","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","55602" +"*promethw27cbrcot.onion*",".{0,1000}promethw27cbrcot\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","55604" +"*PromptCreds_x64.dll*",".{0,1000}PromptCreds_x64\.dll.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","55606" +"*PromptCreds_x86.dll*",".{0,1000}PromptCreds_x86\.dll.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","55607" +"*prosody2john.py*",".{0,1000}prosody2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","55608" +"*ProtectMyToolingGUI.pyw*",".{0,1000}ProtectMyToolingGUI\.pyw.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","55609" +"*ProtectMyTooling-master.zip*",".{0,1000}ProtectMyTooling\-master\.zip.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","55610" +"*Protocol/EfiGuard.h*",".{0,1000}Protocol\/EfiGuard\.h.{0,1000}","offensive_tool_keyword","EfiGuard","EfiGuard is a portable x64 UEFI bootkit that patches the Windows boot manager - boot loader and kernel at boot time in order to disable PatchGuard and Driver Signature Enforcement (DSE).","T1542.002 - T1542.003 - T1542.004","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Mattiwatti/EfiGuard","1","1","N/A","N/A","10","10","1977","354","2025-02-24T11:57:36Z","2019-03-25T19:47:39Z","55611" +"*proxy_bypass.py*",".{0,1000}proxy_bypass\.py.{0,1000}","offensive_tool_keyword","autobloody","Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound","T1078 - T1078.003 - T1021 - T1021.006 - T1076.001","TA0005 - TA0001 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/CravateRouge/autobloody","1","1","#linux","N/A","10","6","545","54","2024-11-14T13:07:54Z","2022-09-07T13:34:30Z","55622" +"*proxy_cmd_for_exec_by_sibling*",".{0,1000}proxy_cmd_for_exec_by_sibling.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","55623" +"*proxy_linux_amd64*",".{0,1000}proxy_linux_amd64.{0,1000}","offensive_tool_keyword","Modlishka ","Modlishka is a powerful and flexible HTTP reverse proxy. It implements an entirely new and interesting approach of handling browser-based HTTP traffic flow. which allows to transparently proxy multi-domain destination traffic. both TLS and non-TLS. over a single domain. without a requirement of installing any additional certificate on the client.","T1090.001 - T1071.001 - T1556.001 - T1204.001 - T1568.002","TA0011 - TA0001 - TA0002 - TA0005 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/drk1wi/Modlishka","1","1","#linux","network exploitation tool","5","10","4967","897","2024-04-19T12:23:00Z","2018-12-19T15:59:54Z","55624" +"*proxychains*scshell*",".{0,1000}proxychains.{0,1000}scshell.{0,1000}","offensive_tool_keyword","cobaltstrike","Fileless Lateral Movement tool that relies on ChangeServiceConfigA to run command","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/SCShell","1","1","N/A","N/A","10","10","1484","248","2023-07-10T01:31:54Z","2019-11-13T23:39:27Z","55639" +"*proxychains.sourceforge.net*",".{0,1000}proxychains\.sourceforge\.net.{0,1000}","offensive_tool_keyword","proxychains","proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4 SOCKS5 or HTTP(S) proxy","T1090.004 - T1090.003 - T1027 - T1573 - T1095","TA0005 - TA0011 - TA0010","N/A","Vice Society - Qilin - Black Basta - Dispossessor - EMBER BEAR","Defense Evasion","https://github.com/haad/proxychains","1","1","N/A","N/A","8","10","7142","647","2024-06-08T02:20:54Z","2011-02-25T12:27:05Z","55642" +"*proxychains-master*",".{0,1000}proxychains\-master.{0,1000}","offensive_tool_keyword","proxychains","proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4 SOCKS5 or HTTP(S) proxy","T1090.004 - T1090.003 - T1027 - T1573 - T1095","TA0005 - TA0011 - TA0010","N/A","Vice Society - Qilin - Black Basta - Dispossessor - EMBER BEAR","Defense Evasion","https://github.com/haad/proxychains","1","1","N/A","N/A","8","10","7142","647","2024-06-08T02:20:54Z","2011-02-25T12:27:05Z","55646" +"*proxychains-other.conf*",".{0,1000}proxychains\-other\.conf.{0,1000}","offensive_tool_keyword","proxychains","proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4 SOCKS5 or HTTP(S) proxy","T1090.004 - T1090.003 - T1027","TA0005 - TA0011 - TA0010","N/A","Vice Society - Qilin - Black Basta - Dispossessor - EMBER BEAR","Defense Evasion","https://github.com/haad/proxychains","1","1","N/A","N/A","8","10","7142","647","2024-06-08T02:20:54Z","2011-02-25T12:27:05Z","55647" +"*Proxy-DLL-Loads*",".{0,1000}Proxy\-DLL\-Loads.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55649" +"*proxyDllLoads.c*",".{0,1000}proxyDllLoads\.c.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55650" +"*proxyDllLoads.exe*",".{0,1000}proxyDllLoads\.exe.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55651" +"*proxyLogon.py*",".{0,1000}proxyLogon\.py.{0,1000}","offensive_tool_keyword","Earth Lusca Operations Tools ","Earth Lusca Operations Tools and commands","T1203 - T1218 - T1027 - T1064 - T1029 - T1210 - T1090","TA0007 - TA0008","N/A","Earth Lusca - Black Basta","Exploitation tool","https://www.trendmicro.com/content/dam/trendmicro/global/en/research/22/a/earth-lusca-employs-sophisticated-infrastructure-varied-tools-and-techniques/technical-brief-delving-deep-an-analysis-of-earth-lusca-operations.pdf https://github.com/RickGeex/ProxyLogon","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","55652" +"*proxyshell.py*",".{0,1000}proxyshell\.py.{0,1000}","offensive_tool_keyword","Earth Lusca Operations Tools ","Earth Lusca Operations Tools and commands","T1203 - T1218 - T1027 - T1064 - T1029 - T1210 - T1090","TA0007 - TA0008","N/A","Earth Lusca - Black Basta","Exploitation tool","https://www.trendmicro.com/content/dam/trendmicro/global/en/research/22/a/earth-lusca-employs-sophisticated-infrastructure-varied-tools-and-techniques/technical-brief-delving-deep-an-analysis-of-earth-lusca-operations.pdf https://github.com/dmaasland/proxyshell-poc","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","55654" +"*proxyshell_rce.py*",".{0,1000}proxyshell_rce\.py.{0,1000}","offensive_tool_keyword","Earth Lusca Operations Tools ","Earth Lusca Operations Tools and commands","T1203 - T1218 - T1027 - T1064 - T1029 - T1210 - T1090","TA0007 - TA0008","N/A","Earth Lusca - Black Basta","Exploitation tool","https://www.trendmicro.com/content/dam/trendmicro/global/en/research/22/a/earth-lusca-employs-sophisticated-infrastructure-varied-tools-and-techniques/technical-brief-delving-deep-an-analysis-of-earth-lusca-operations.pdf https://github.com/dmaasland/proxyshell-poc","1","1","N/A","N/A","10","","N/A","","","","55655" +"*proxyshellcodeurl*",".{0,1000}proxyshellcodeurl.{0,1000}","offensive_tool_keyword","cobaltstrike","Project to enumerate proxy configurations and generate shellcode from CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EncodeGroup/AggressiveProxy","1","1","N/A","N/A","10","10","141","25","2020-11-04T16:08:11Z","2020-11-04T12:53:00Z","55656" +"*proxyshell-enumerate.py*",".{0,1000}proxyshell\-enumerate\.py.{0,1000}","offensive_tool_keyword","Earth Lusca Operations Tools ","Earth Lusca Operations Tools and commands","T1203 - T1218 - T1027 - T1064 - T1029 - T1210 - T1090","TA0007 - TA0008","N/A","Earth Lusca - Black Basta","Exploitation tool","https://www.trendmicro.com/content/dam/trendmicro/global/en/research/22/a/earth-lusca-employs-sophisticated-infrastructure-varied-tools-and-techniques/technical-brief-delving-deep-an-analysis-of-earth-lusca-operations.pdf https://github.com/dmaasland/proxyshell-poc","1","1","N/A","N/A","10","","N/A","","","","55657" +"*proxyshell-poc*",".{0,1000}proxyshell\-poc.{0,1000}","offensive_tool_keyword","Earth Lusca Operations Tools ","Earth Lusca Operations Tools and commands","T1203 - T1218 - T1027 - T1064 - T1029 - T1210 - T1090","TA0007 - TA0008","N/A","Earth Lusca - Black Basta","Exploitation tool","https://www.trendmicro.com/content/dam/trendmicro/global/en/research/22/a/earth-lusca-employs-sophisticated-infrastructure-varied-tools-and-techniques/technical-brief-delving-deep-an-analysis-of-earth-lusca-operations.pdf https://github.com/dmaasland/proxyshell-poc","1","1","N/A","N/A","10","","N/A","","","","55658" +"*ps_token2john.py*",".{0,1000}ps_token2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","55660" +"*ps_wmi_exec.rb*",".{0,1000}ps_wmi_exec\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","55661" +"*ps2exe.ps1*",".{0,1000}ps2exe\.ps1.{0,1000}","offensive_tool_keyword","PS2EXE","Module to compile powershell scripts to executables","T1027.001 - T1564.003 - T1564.005","TA0002 - TA0006","N/A","N/A","Exploitation tool","https://github.com/MScholtes/PS2EXE","1","1","N/A","N/A","N/A","10","1395","217","2025-01-05T11:26:50Z","2019-11-08T09:25:02Z","55667" +"*ps2exe.psd1*",".{0,1000}ps2exe\.psd1.{0,1000}","offensive_tool_keyword","PS2EXE","Module to compile powershell scripts to executables","T1027.001 - T1564.003 - T1564.005","TA0002 - TA0006","N/A","N/A","Exploitation tool","https://github.com/MScholtes/PS2EXE","1","1","N/A","N/A","N/A","10","1395","217","2025-01-05T11:26:50Z","2019-11-08T09:25:02Z","55668" +"*ps2exe.psm1*",".{0,1000}ps2exe\.psm1.{0,1000}","offensive_tool_keyword","PS2EXE","Module to compile powershell scripts to executables","T1027.001 - T1564.003 - T1564.005","TA0002 - TA0006","N/A","N/A","Exploitation tool","https://github.com/MScholtes/PS2EXE","1","1","N/A","N/A","N/A","10","1395","217","2025-01-05T11:26:50Z","2019-11-08T09:25:02Z","55669" +"*PS2EXE-master*",".{0,1000}PS2EXE\-master.{0,1000}","offensive_tool_keyword","PS2EXE","Module to compile powershell scripts to executables","T1027.001 - T1564.003 - T1564.005","TA0002 - TA0006","N/A","N/A","Exploitation tool","https://github.com/MScholtes/PS2EXE","1","1","N/A","N/A","N/A","10","1395","217","2025-01-05T11:26:50Z","2019-11-08T09:25:02Z","55670" +"*PSAmsiClient.ps1*",".{0,1000}PSAmsiClient\.ps1.{0,1000}","offensive_tool_keyword","PSAmsi","PSAmsi is a tool for auditing and defeating AMSI signatures.","T1059.001 - T1562.001 - T1070.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/cobbr/PSAmsi","1","1","N/A","N/A","7","4","390","74","2018-04-22T20:56:33Z","2017-09-22T11:48:47Z","55671" +"*PSAmsiScanner.ps1*",".{0,1000}PSAmsiScanner\.ps1.{0,1000}","offensive_tool_keyword","PSAmsi","PSAmsi is a tool for auditing and defeating AMSI signatures.","T1059.001 - T1562.001 - T1070.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/cobbr/PSAmsi","1","1","N/A","N/A","7","4","390","74","2018-04-22T20:56:33Z","2017-09-22T11:48:47Z","55672" +"*pscmd/serverscript.ps1*",".{0,1000}pscmd\/serverscript\.ps1.{0,1000}","offensive_tool_keyword","evilrdp","Th evil twin of aardwolfgui using the aardwolf RDP client library that gives you extended control over the target and additional scripting capabilities from the command line.","T1021.001 - T1056.001 - T1113 - T1078.002 - T1105 - T1090.002 - T1059.001","TA0008 - TA0002 - TA0005 - TA0001 - TA0009 - TA0010 - TA0011","N/A","Black Basta","C2","https://github.com/skelsec/evilrdp","1","1","N/A","N/A","10","10","299","31","2025-03-15T13:37:21Z","2023-11-29T13:44:58Z","55681" +"*PSconfusion.py*",".{0,1000}PSconfusion\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","CS anti-killing including python version and C version","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Gality369/CS-Loader","1","1","N/A","N/A","10","10","829","141","2025-04-02T09:37:10Z","2020-08-17T21:33:06Z","55683" +"*pse2john.py*",".{0,1000}pse2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","55685" +"*ps-empire*",".{0,1000}ps\-empire.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","55688" +"*psexec.py*",".{0,1000}psexec\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","55691" +"*psexec_ms17_010.rb*",".{0,1000}psexec_ms17_010\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","55693" +"*-PsExecCmd*",".{0,1000}\-PsExecCmd.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-PsExec.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","55696" +"*PsExecLiveImplant*",".{0,1000}PsExecLiveImplant.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","55697" +"*pseymour/MakeMeAdmin*",".{0,1000}pseymour\/MakeMeAdmin.{0,1000}","offensive_tool_keyword","MakeMeAdmin","Enables users to elevate themselves to administrator-level rights","T1078 - T1059 - T1087","TA0004","N/A","N/A","Privilege Escalation","https://github.com/pseymour/MakeMeAdmin","1","1","N/A","N/A","9","5","430","94","2024-12-22T02:56:23Z","2018-05-29T19:42:58Z","55702" +"*PsMapExec.ps1*",".{0,1000}PsMapExec\.ps1.{0,1000}","offensive_tool_keyword","PSMapExec","A PowerShell tool heavily inspired by the popular tool CrackMapExec. Far too often I find myself on engagements without access to Linux in order to make use of CrackMapExec.","T1059.001 - T1021.006 - T1110.001 - T1021.001 - T1021.004 - T1021.005 - T1021.003 - T1621","TA0002 - TA0011 - TA0005 - TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/The-Viper-One/PsMapExec","1","1","N/A","N/A","10","10","954","108","2025-03-11T14:38:50Z","2023-06-20T16:57:27Z","55713" +"*PsMapExec-main*",".{0,1000}PsMapExec\-main.{0,1000}","offensive_tool_keyword","PSMapExec","A PowerShell tool heavily inspired by the popular tool CrackMapExec. Far too often I find myself on engagements without access to Linux in order to make use of CrackMapExec.","T1059.001 - T1021.006 - T1110.001 - T1021.001 - T1021.004 - T1021.005 - T1021.003 - T1621","TA0002 - TA0011 - TA0005 - TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/The-Viper-One/PsMapExec","1","1","N/A","N/A","10","10","954","108","2025-03-11T14:38:50Z","2023-06-20T16:57:27Z","55714" +"*Pspersist-main*",".{0,1000}Pspersist\-main.{0,1000}","offensive_tool_keyword","Pspersist","Dropping a powershell script at %HOMEPATH%\Documents\windowspowershell\ that contains the implant's path and whenever powershell process is created the implant will executed too.","T1546 - T1546.013 - T1053 - T1053.005 - T1037 - T1037.001","TA0003","N/A","N/A","Persistence","https://github.com/TheD1rkMtr/Pspersist","1","1","N/A","N/A","10","1","85","24","2023-08-02T02:27:29Z","2023-02-01T17:21:38Z","55716" +"*pspy-master*",".{0,1000}pspy\-master.{0,1000}","offensive_tool_keyword","pspy","Monitor linux processes without root permissions","T1057 - T1514 - T1082","TA0007 - TA0009 - TA0003","N/A","N/A","Discovery","https://github.com/DominicBreuker/pspy","1","1","#linux","N/A","6","10","5370","538","2023-01-17T21:09:22Z","2018-02-08T21:41:37Z","55727" +"*PSRansom.ps1*",".{0,1000}PSRansom\.ps1.{0,1000}","offensive_tool_keyword","PSRansom","PSRansom is a PowerShell Ransomware Simulator with C2 Server capabilities. This tool helps you simulate encryption process of a generic ransomware in any system on any system with PowerShell installed on it. Thanks to the integrated C2 server. you can exfiltrate files and receive client information via HTTP.","T1486 - T1107 - T1566.001","TA0011 - TA0010","N/A","N/A","Ransomware","https://github.com/JoelGMSec/PSRansom","1","1","N/A","N/A","9","5","478","116","2024-01-19T09:50:26Z","2022-02-27T11:52:03Z","55730" +"*PSRecon.ps1*",".{0,1000}PSRecon.{0,1000}","offensive_tool_keyword","PSRecon","PSRecon gathers data from a remote Windows host using PowerShell (v2 or later). organizes the data into folders. hashes all extracted data. hashes PowerShell and various system properties. and sends the data off to the security team. The data can be pushed to a share. sent over email. or retained locally.","T1059 - T1003 - T1556 - T1204","TA0002 - TA0009","N/A","N/A","Discovery","https://github.com/gfoss/PSRecon","1","1","N/A","N/A","9","5","486","105","2017-07-29T15:03:04Z","2015-08-03T05:43:38Z","55731" +"*PSRunspace-InvokeRun-certutilCoded.txt*",".{0,1000}PSRunspace\-InvokeRun\-certutilCoded\.txt.{0,1000}","offensive_tool_keyword","OSEP-Code-Snippets","notable code snippets for Offensive Security's PEN-300 (OSEP) course","T1116 - T1204.002 - T1027.009 - T1021.005 - T1560.001 - T1100 - T1003.001 - T1564.001 - T1047 - T1210 - T1134.002 - T1055 - T1055.011 - T1055.012 - T1204","TA0005 - TA0040 - TA0008 - TA0003 - TA0006 - TA0004","N/A","N/A","Exploitation tool","https://github.com/chvancooten/OSEP-Code-Snippets","1","1","N/A","N/A","8","10","1254","444","2024-01-04T15:17:17Z","2021-03-10T21:34:41Z","55733" +"*pstgdump.exe*",".{0,1000}pstgdump\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://gitlab.com/kalilinux/packages/windows-binaries/-/tree/kali/master/fgdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55734" +"*PstPassword.exe*",".{0,1000}PstPassword\.exe.{0,1000}","offensive_tool_keyword","PstPassword","recover the PST passwords of Outlook","T1212","TA0006","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/pst_password.html","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","55735" +"*pstpassword.zip*",".{0,1000}pstpassword\.zip.{0,1000}","offensive_tool_keyword","PstPassword","recover the PST passwords of Outlook","T1212","TA0006","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/pst_password.html","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","55736" +"*pstpassword_setup.exe*",".{0,1000}pstpassword_setup\.exe.{0,1000}","offensive_tool_keyword","PstPassword","recover the PST passwords of Outlook","T1212","TA0006","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/pst_password.html","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","55737" +"*pstree.ps1*",".{0,1000}pstree\.ps1.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","55738" +"*pth-rpcclient*",".{0,1000}pth\-rpcclient.{0,1000}","offensive_tool_keyword","pth-toolkit","A modified version of the passing-the-hash tool collection https://code.google.com/p/passing-the-hash/ designed to be portable and work straight out of the box even on the most 'bare bones' systems","T1550.002 - T1075 - T1078","TA0006 - TA0008","N/A","APT1","Lateral Movement","https://github.com/byt3bl33d3r/pth-toolkit","1","1","N/A","N/A","10","6","575","131","2015-02-06T15:10:41Z","2015-02-03T10:31:56Z","55755" +"*pth-smbclient*",".{0,1000}pth\-smbclient.{0,1000}","offensive_tool_keyword","pth-toolkit","A modified version of the passing-the-hash tool collection https://code.google.com/p/passing-the-hash/ designed to be portable and work straight out of the box even on the most 'bare bones' systems","T1550.002 - T1075 - T1078","TA0006 - TA0008","N/A","APT1","Lateral Movement","https://github.com/byt3bl33d3r/pth-toolkit","1","1","N/A","N/A","10","6","575","131","2015-02-06T15:10:41Z","2015-02-03T10:31:56Z","55756" +"*pth-smbget*",".{0,1000}pth\-smbget.{0,1000}","offensive_tool_keyword","pth-toolkit","A modified version of the passing-the-hash tool collection https://code.google.com/p/passing-the-hash/ designed to be portable and work straight out of the box even on the most 'bare bones' systems","T1550.002 - T1075 - T1078","TA0006 - TA0008","N/A","APT1","Lateral Movement","https://github.com/byt3bl33d3r/pth-toolkit","1","1","N/A","N/A","10","6","575","131","2015-02-06T15:10:41Z","2015-02-03T10:31:56Z","55762" +"*pth-toolkit*",".{0,1000}pth\-toolkit.{0,1000}","offensive_tool_keyword","pth-toolkit","A modified version of the passing-the-hash tool collection https://code.google.com/p/passing-the-hash/ designed to be portable and work straight out of the box even on the most 'bare bones' systems","T1550.002 - T1075 - T1078","TA0006 - TA0008","N/A","APT1","Lateral Movement","https://github.com/byt3bl33d3r/pth-toolkit","1","1","N/A","N/A","10","6","575","131","2015-02-06T15:10:41Z","2015-02-03T10:31:56Z","55763" +"*pth-toolkit-master.zip*",".{0,1000}pth\-toolkit\-master\.zip.{0,1000}","offensive_tool_keyword","pth-toolkit","A modified version of the passing-the-hash tool collection https://code.google.com/p/passing-the-hash/ designed to be portable and work straight out of the box even on the most 'bare bones' systems","T1550.002 - T1075 - T1078","TA0006 - TA0008","N/A","APT1","Lateral Movement","https://github.com/byt3bl33d3r/pth-toolkit","1","1","N/A","N/A","10","6","575","131","2015-02-06T15:10:41Z","2015-02-03T10:31:56Z","55764" +"*pth-winexe*",".{0,1000}pth\-winexe.{0,1000}","offensive_tool_keyword","pth-toolkit","A modified version of the passing-the-hash tool collection https://code.google.com/p/passing-the-hash/ designed to be portable and work straight out of the box even on the most 'bare bones' systems","T1550.002 - T1075 - T1078","TA0006 - TA0008","N/A","APT1","Lateral Movement","https://github.com/byt3bl33d3r/pth-toolkit","1","1","N/A","N/A","10","6","575","131","2015-02-06T15:10:41Z","2015-02-03T10:31:56Z","55765" +"*pth-wmic*",".{0,1000}pth\-wmic.{0,1000}","offensive_tool_keyword","pth-toolkit","A modified version of the passing-the-hash tool collection https://code.google.com/p/passing-the-hash/ designed to be portable and work straight out of the box even on the most 'bare bones' systems","T1550.002 - T1075 - T1078","TA0006 - TA0008","N/A","APT1","Lateral Movement","https://github.com/byt3bl33d3r/pth-toolkit","1","1","N/A","N/A","10","6","575","131","2015-02-06T15:10:41Z","2015-02-03T10:31:56Z","55766" +"*pth-wmis*",".{0,1000}pth\-wmis.{0,1000}","offensive_tool_keyword","pth-toolkit","A modified version of the passing-the-hash tool collection https://code.google.com/p/passing-the-hash/ designed to be portable and work straight out of the box even on the most 'bare bones' systems","T1550.002 - T1075 - T1078","TA0006 - TA0008","N/A","APT1","Lateral Movement","https://github.com/byt3bl33d3r/pth-toolkit","1","1","N/A","N/A","10","6","575","131","2015-02-06T15:10:41Z","2015-02-03T10:31:56Z","55768" +"*ptresearch/AttackDetection*",".{0,1000}ptresearch\/AttackDetection.{0,1000}","offensive_tool_keyword","POC","POC exploits - The Attack Detection Team searches for new vulnerabilities and 0-days. reproduces it and creates PoC exploits to understand how these security flaws work and how related attacks can be detected on the network layer. Additionally. we are interested in malware and hackers TTPs. so we develop Suricata rules for detecting all sorts of such activities.","T1210 - T1583 - T1586 - T1589 - T1596","TA0002 - TA0011 - TA0007","N/A","N/A","Exploitation tool","https://github.com/ptresearch/AttackDetection","1","1","N/A","N/A","N/A","10","1353","359","2022-08-31T09:26:21Z","2016-03-24T14:42:50Z","55769" +"*pts764gt354fder34fsqw45gdfsavadfgsfg.kraskula.com*",".{0,1000}pts764gt354fder34fsqw45gdfsavadfgsfg\.kraskula\.com.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","55770" +"*ptunnel-client.log*",".{0,1000}ptunnel\-client\.log.{0,1000}","offensive_tool_keyword","ptunnel-ng","Tunnel TCP connections through ICMP.","T1095.001 - T1572.001","TA0011 - TA0040 - TA0003","N/A","N/A","Data Exfiltration","https://github.com/utoni/ptunnel-ng","1","1","#logfile","N/A","8","5","456","76","2024-11-27T18:34:33Z","2017-12-19T18:10:35Z","55771" +"*ptunnel-master*",".{0,1000}ptunnel\-master.{0,1000}","offensive_tool_keyword","ptunnel-ng","Tunnel TCP connections through ICMP.","T1095.001 - T1572.001","TA0011 - TA0040 - TA0003","N/A","N/A","Data Exfiltration","https://github.com/utoni/ptunnel-ng","1","1","N/A","N/A","8","5","456","76","2024-11-27T18:34:33Z","2017-12-19T18:10:35Z","55774" +"*ptunnel-ng.conf*",".{0,1000}ptunnel\-ng\.conf.{0,1000}","offensive_tool_keyword","ptunnel-ng","Tunnel TCP connections through ICMP.","T1095.001 - T1572.001","TA0011 - TA0040 - TA0003","N/A","N/A","Data Exfiltration","https://github.com/utoni/ptunnel-ng","1","1","N/A","N/A","8","5","456","76","2024-11-27T18:34:33Z","2017-12-19T18:10:35Z","55776" +"*ptunnel-ng.git*",".{0,1000}ptunnel\-ng\.git.{0,1000}","offensive_tool_keyword","ptunnel-ng","Tunnel TCP connections through ICMP.","T1095.001 - T1572.001","TA0011 - TA0040 - TA0003","N/A","N/A","Data Exfiltration","https://github.com/utoni/ptunnel-ng","1","1","N/A","N/A","8","5","456","76","2024-11-27T18:34:33Z","2017-12-19T18:10:35Z","55777" +"*ptunnel-ng.service*",".{0,1000}ptunnel\-ng\.service.{0,1000}","offensive_tool_keyword","ptunnel-ng","Tunnel TCP connections through ICMP.","T1095.001 - T1572.001","TA0011 - TA0040 - TA0003","N/A","N/A","Data Exfiltration","https://github.com/utoni/ptunnel-ng","1","1","N/A","N/A","8","5","456","76","2024-11-27T18:34:33Z","2017-12-19T18:10:35Z","55778" +"*ptunnel-ng.te*",".{0,1000}ptunnel\-ng\.te.{0,1000}","offensive_tool_keyword","ptunnel-ng","Tunnel TCP connections through ICMP.","T1095.001 - T1572.001","TA0011 - TA0040 - TA0003","N/A","N/A","Data Exfiltration","https://github.com/utoni/ptunnel-ng","1","1","N/A","N/A","8","5","456","76","2024-11-27T18:34:33Z","2017-12-19T18:10:35Z","55779" +"*ptunnel-ng-x64.exe*",".{0,1000}ptunnel\-ng\-x64\.exe.{0,1000}","offensive_tool_keyword","ptunnel-ng","Tunnel TCP connections through ICMP.","T1095.001 - T1572.001","TA0011 - TA0040 - TA0003","N/A","N/A","Data Exfiltration","https://github.com/utoni/ptunnel-ng","1","1","N/A","N/A","8","5","456","76","2024-11-27T18:34:33Z","2017-12-19T18:10:35Z","55780" +"*ptunnel-ng-x64-dbg.exe*",".{0,1000}ptunnel\-ng\-x64\-dbg\.exe.{0,1000}","offensive_tool_keyword","ptunnel-ng","Tunnel TCP connections through ICMP.","T1095.001 - T1572.001","TA0011 - TA0040 - TA0003","N/A","N/A","Data Exfiltration","https://github.com/utoni/ptunnel-ng","1","1","N/A","N/A","8","5","456","76","2024-11-27T18:34:33Z","2017-12-19T18:10:35Z","55781" +"*ptunnel-ng-x86.exe*",".{0,1000}ptunnel\-ng\-x86\.exe.{0,1000}","offensive_tool_keyword","ptunnel-ng","Tunnel TCP connections through ICMP.","T1095.001 - T1572.001","TA0011 - TA0040 - TA0003","N/A","N/A","Data Exfiltration","https://github.com/utoni/ptunnel-ng","1","1","N/A","N/A","8","5","456","76","2024-11-27T18:34:33Z","2017-12-19T18:10:35Z","55782" +"*ptunnel-ng-x86-dbg.exe*",".{0,1000}ptunnel\-ng\-x86\-dbg\.exe.{0,1000}","offensive_tool_keyword","ptunnel-ng","Tunnel TCP connections through ICMP.","T1095.001 - T1572.001","TA0011 - TA0040 - TA0003","N/A","N/A","Data Exfiltration","https://github.com/utoni/ptunnel-ng","1","1","N/A","N/A","8","5","456","76","2024-11-27T18:34:33Z","2017-12-19T18:10:35Z","55783" +"*ptunnel-server.log*",".{0,1000}ptunnel\-server\.log.{0,1000}","offensive_tool_keyword","ptunnel-ng","Tunnel TCP connections through ICMP.","T1095.001 - T1572.001","TA0011 - TA0040 - TA0003","N/A","N/A","Data Exfiltration","https://github.com/utoni/ptunnel-ng","1","1","#logfile","N/A","8","5","456","76","2024-11-27T18:34:33Z","2017-12-19T18:10:35Z","55784" +"*pupwinutils.shellcode*",".{0,1000}pupwinutils\.shellcode.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55809" +"*pupy*/checkvm.py*",".{0,1000}pupy.{0,1000}\/checkvm\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55810" +"*pupy/external/Inveigh*",".{0,1000}pupy\/external\/Inveigh.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55811" +"*pupy/external/LaZagne*",".{0,1000}pupy\/external\/LaZagne.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55812" +"*pupy/external/linux-exploit-suggester*",".{0,1000}pupy\/external\/linux\-exploit\-suggester.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","#linux","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55813" +"*pupy/external/mimipy*",".{0,1000}pupy\/external\/mimipy.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55814" +"*pupy/external/pyopus*",".{0,1000}pupy\/external\/pyopus.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55815" +"*pupy/external/pywerview*",".{0,1000}pupy\/external\/pywerview.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55816" +"*pupy/external/winpty*",".{0,1000}pupy\/external\/winpty.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55817" +"*pupy/external/WinPwnage*",".{0,1000}pupy\/external\/WinPwnage.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55818" +"*pupy/payload_*",".{0,1000}pupy\/payload_.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55819" +"*pupy/pupy/external/BeRoot*",".{0,1000}pupy\/pupy\/external\/BeRoot.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55820" +"*PupyCmdLoop*",".{0,1000}PupyCmdLoop.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55821" +"*PupyCredentials.py*",".{0,1000}PupyCredentials\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55822" +"*PupyDnsCnc.py*",".{0,1000}PupyDnsCnc\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55823" +"*PupyDnsCommandServerHandler*",".{0,1000}PupyDnsCommandServerHandler.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55824" +"*PupyKCPSocketStream*",".{0,1000}PupyKCPSocketStream.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55826" +"*pupylib.payloads.ps1*",".{0,1000}pupylib\.payloads\.ps1.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55827" +"*PupyLoaderTemplate.*",".{0,1000}PupyLoaderTemplate\..{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55828" +"*PupyOffloadDNS*",".{0,1000}PupyOffloadDNS.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55829" +"*PupyOffloadSocket*",".{0,1000}PupyOffloadSocket.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55830" +"*PupySocketStream.py*",".{0,1000}PupySocketStream\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55831" +"*PupyVirtualStream.py*",".{0,1000}PupyVirtualStream\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","55832" +"*pureqh/bypassAV*",".{0,1000}pureqh\/bypassAV.{0,1000}","offensive_tool_keyword","cobaltstrike","bypassAV cobaltstrike shellcode","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/pureqh/bypassAV","1","1","N/A","N/A","10","10","455","98","2021-05-18T05:03:03Z","2021-02-25T05:26:11Z","55833" +"*purevpn_cred_collector.*",".{0,1000}purevpn_cred_collector\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","55834" +"*purplepanda.py*",".{0,1000}purplepanda\.py.{0,1000}","offensive_tool_keyword","PurplePanda","This tool fetches resources from different cloud/saas applications focusing on permissions in order to identify privilege escalation paths and dangerous permissions in the cloud/saas configurations. Note that PurplePanda searches both privileges escalation paths within a platform and across platforms.","T1595 - T1078 - T1583 - T1087 - T1526","TA0003 - TA0004 - TA0007 - TA0040","N/A","N/A","Exploitation tool","https://github.com/carlospolop/PurplePanda","1","1","N/A","N/A","N/A","7","687","83","2025-04-14T16:23:50Z","2022-01-01T12:10:40Z","55835" +"*purplepanda_config.py*",".{0,1000}purplepanda_config\.py.{0,1000}","offensive_tool_keyword","PurplePanda","This tool fetches resources from different cloud/saas applications focusing on permissions in order to identify privilege escalation paths and dangerous permissions in the cloud/saas configurations. Note that PurplePanda searches both privileges escalation paths within a platform and across platforms.","T1595 - T1078 - T1583 - T1087 - T1526","TA0003 - TA0004 - TA0007 - TA0040","N/A","N/A","Exploitation tool","https://github.com/carlospolop/PurplePanda","1","1","N/A","N/A","N/A","7","687","83","2025-04-14T16:23:50Z","2022-01-01T12:10:40Z","55836" +"*purplepanda_github.py*",".{0,1000}purplepanda_github\.py.{0,1000}","offensive_tool_keyword","PurplePanda","This tool fetches resources from different cloud/saas applications focusing on permissions in order to identify privilege escalation paths and dangerous permissions in the cloud/saas configurations. Note that PurplePanda searches both privileges escalation paths within a platform and across platforms.","T1595 - T1078 - T1583 - T1087 - T1526","TA0003 - TA0004 - TA0007 - TA0040","N/A","N/A","Exploitation tool","https://github.com/carlospolop/PurplePanda","1","1","N/A","N/A","N/A","7","687","83","2025-04-14T16:23:50Z","2022-01-01T12:10:40Z","55837" +"*PURPLEPANDA_NEO4J_URL=*",".{0,1000}PURPLEPANDA_NEO4J_URL\=.{0,1000}","offensive_tool_keyword","PurplePanda","This tool fetches resources from different cloud/saas applications focusing on permissions in order to identify privilege escalation paths and dangerous permissions in the cloud/saas configurations. Note that PurplePanda searches both privileges escalation paths within a platform and across platforms.","T1595 - T1078 - T1583 - T1087 - T1526","TA0003 - TA0004 - TA0007 - TA0040","N/A","N/A","Exploitation tool","https://github.com/carlospolop/PurplePanda","1","1","N/A","N/A","N/A","7","687","83","2025-04-14T16:23:50Z","2022-01-01T12:10:40Z","55838" +"*purplepanda_prints.py*",".{0,1000}purplepanda_prints\.py.{0,1000}","offensive_tool_keyword","PurplePanda","This tool fetches resources from different cloud/saas applications focusing on permissions in order to identify privilege escalation paths and dangerous permissions in the cloud/saas configurations. Note that PurplePanda searches both privileges escalation paths within a platform and across platforms.","T1595 - T1078 - T1583 - T1087 - T1526","TA0003 - TA0004 - TA0007 - TA0040","N/A","N/A","Exploitation tool","https://github.com/carlospolop/PurplePanda","1","1","N/A","N/A","N/A","7","687","83","2025-04-14T16:23:50Z","2022-01-01T12:10:40Z","55839" +"*PURPLEPANDA_PWD=*",".{0,1000}PURPLEPANDA_PWD\=.{0,1000}","offensive_tool_keyword","PurplePanda","This tool fetches resources from different cloud/saas applications focusing on permissions in order to identify privilege escalation paths and dangerous permissions in the cloud/saas configurations. Note that PurplePanda searches both privileges escalation paths within a platform and across platforms.","T1595 - T1078 - T1583 - T1087 - T1526","TA0003 - TA0004 - TA0007 - TA0040","N/A","N/A","Exploitation tool","https://github.com/carlospolop/PurplePanda","1","1","N/A","N/A","N/A","7","687","83","2025-04-14T16:23:50Z","2022-01-01T12:10:40Z","55840" +"*PurpleSharp.exe*",".{0,1000}PurpleSharp\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","55841" +"*puzzlepeaches/NTLMRecon*",".{0,1000}puzzlepeaches\/NTLMRecon.{0,1000}","offensive_tool_keyword","NTMLRecon","Enumerate information from NTLM authentication enabled web endpoints","T1212 - T1212.001 - T1071 - T1071.001 - T1087 - T1087.001","TA0009 - TA0007 - TA0006","N/A","N/A","Discovery","https://github.com/puzzlepeaches/NTLMRecon","1","1","N/A","N/A","8","1","35","3","2023-08-16T14:34:10Z","2023-08-09T12:10:42Z","55847" +"*PWCrack*",".{0,1000}PWCrack.{0,1000}","offensive_tool_keyword","PWCrack","cracking tool for multiple hash type","T1110 - T1111 - T1210 - T1558.002 - T1555","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","N/A","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","55850" +"*pwd*/*/rules/best64.rule*",".{0,1000}pwd.{0,1000}\/.{0,1000}\/rules\/best64\.rule.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Crack the hash with Hashcat","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","55853" +"*PWDump.*",".{0,1000}PWDump\..{0,1000}","offensive_tool_keyword","pwdump","a tool used within a command-line interface on 64bit Windows computers to extract the NTLM (LanMan) hashes from LSASS.exe in memory. This tool may be used in conjunction with malware or other penetration testing tools to obtain credentials for use in Windows authentication systems","T1003 - T1110.001 - T1555.003 - T1003.002","TA0006","N/A","menuPass - APT41 - Threat Group-3390 - APT1 - Turla - APT39 - FIN5","Credential Access","https://ftp.samba.org/pub/samba/pwdump/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55869" +"*pwdump.exe*",".{0,1000}pwdump\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://gitlab.com/kalilinux/packages/windows-binaries/-/tree/kali/master/fgdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55870" +"*PwDump7.exe*",".{0,1000}PwDump7\.exe.{0,1000}","offensive_tool_keyword","PwDump7","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.openwall.com/passwords/windows-pwdump","1","1","N/A","N/A","10","8","N/A","N/A","N/A","N/A","55874" +"*-PWDumpFormat*",".{0,1000}\-PWDumpFormat.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","55877" +"*PWDumpX.zip*",".{0,1000}PWDumpX\.zip.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","1","N/A","N/A","10","8","N/A","N/A","N/A","N/A","55881" +"*pw-inspector.*",".{0,1000}pw\-inspector\..{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","55885" +"*pwn1sher/CS-BOFs*",".{0,1000}pwn1sher\/CS\-BOFs.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of CobaltStrike beacon object files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/pwn1sher/CS-BOFs","1","1","N/A","N/A","10","10","103","22","2022-02-14T09:47:30Z","2021-01-18T08:54:48Z","55887" +"*pwn1sher/WMEye*",".{0,1000}pwn1sher\/WMEye.{0,1000}","offensive_tool_keyword","WMEye","WMEye is a post exploitation tool that uses WMI Event Filter and MSBuild Execution for Lateral Movement","T1047 - T1053.005 - T1124 - T1203 - T1569.002","TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/pwn1sher/WMEye","1","1","N/A","N/A","8","4","365","59","2021-12-24T05:38:50Z","2021-09-07T08:18:30Z","55888" +"*PwnDexter/SharpEDRChecker*",".{0,1000}PwnDexter\/SharpEDRChecker.{0,1000}","offensive_tool_keyword","SharpEDRChecker","Checks for the presence of known defensive products such as AV/EDR and logging tools","T1083 - T1518.001 - T1063","TA0007 - TA0005","N/A","N/A","Discovery","https://github.com/PwnDexter/SharpEDRChecker","1","1","N/A","N/A","8","8","706","98","2023-10-09T11:17:49Z","2020-06-16T10:25:00Z","55896" +"*pwndrop-linux-amd64*",".{0,1000}pwndrop\-linux\-amd64.{0,1000}","offensive_tool_keyword","pwndrop","Self-deployable file hosting service for red teamers allowing to easily upload and share payloads over HTTP and WebDAV.","T1105 - T1071 - T1071.001 - T1090 - T1027 - T1027.005","TA0011 - TA0005 - TA0042","N/A","N/A","C2","https://github.com/kgretzky/pwndrop","1","1","#linux","N/A","10","10","2124","267","2023-02-25T05:08:15Z","2019-11-28T19:06:30Z","55901" +"*pwndrop-master*",".{0,1000}pwndrop\-master.{0,1000}","offensive_tool_keyword","pwndrop","Self-deployable file hosting service for red teamers allowing to easily upload and share payloads over HTTP and WebDAV.","T1105 - T1071 - T1071.001 - T1090 - T1027 - T1027.005","TA0011 - TA0005 - TA0042","N/A","N/A","C2","https://github.com/kgretzky/pwndrop","1","1","N/A","N/A","10","10","2124","267","2023-02-25T05:08:15Z","2019-11-28T19:06:30Z","55902" +"*pwned_x64/notepad.exe*",".{0,1000}pwned_x64\/notepad\.exe.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","55903" +"*Pwned-creds_Domainpasswordspray.txt*",".{0,1000}Pwned\-creds_Domainpasswordspray\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","55904" +"*pwned-passwords-ntlm*",".{0,1000}pwned\-passwords\-ntlm.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","55906" +"*pwnkit64decoded.c*",".{0,1000}pwnkit64decoded\.c.{0,1000}","offensive_tool_keyword","POC","exploitation of CVE-2021-4034","T1210","N/A","N/A","N/A","Exploitation tool","https://github.com/luijait/PwnKit-Exploit","1","1","N/A","N/A","N/A","1","96","14","2022-02-07T15:42:00Z","2022-01-26T18:01:26Z","55910" +"*pwnsauc3/RWXFinder*",".{0,1000}pwnsauc3\/RWXFinder.{0,1000}","offensive_tool_keyword","rwxfinder","The program uses the Windows API functions to traverse through directories and locate DLL files with RWX section","T1059.001 - T1059.003 - T1070.004","TA0002 - TA0005 - TA0040","N/A","N/A","Discovery","https://github.com/pwnsauc3/RWXFinder","1","1","N/A","N/A","5","2","101","14","2023-07-15T15:42:55Z","2023-07-14T07:47:21Z","55914" +"*pwsafe2john.py*",".{0,1000}pwsafe2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","55916" +"*pxethief.py*",".{0,1000}pxethief\.py.{0,1000}","offensive_tool_keyword","pxethief","PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager","T1555.004 - T1555.002","TA0006","N/A","N/A","Credential Access","https://github.com/MWR-CyberSec/PXEThief","1","1","N/A","N/A","N/A","4","368","57","2024-05-29T15:07:15Z","2022-08-12T22:16:46Z","55919" +"*pycobalt.*",".{0,1000}pycobalt\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","55932" +"*pycobalt/aggressor*",".{0,1000}pycobalt\/aggressor.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","55933" +"*pycobalt_debug_on*",".{0,1000}pycobalt_debug_on.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","55934" +"*pycobalt_path*",".{0,1000}pycobalt_path.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","55935" +"*pycobalt_python*",".{0,1000}pycobalt_python.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","55936" +"*pycobalt_timeout*",".{0,1000}pycobalt_timeout.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","55937" +"*PyExec-main.*",".{0,1000}PyExec\-main\..{0,1000}","offensive_tool_keyword","PyExec","This is a very simple privilege escalation technique from admin to System. This is the same technique PSExec uses.","T1134 - T1055 - T1548.002","TA0004 - TA0005 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/OlivierLaflamme/PyExec","1","1","N/A","N/A","9","1","11","7","2019-09-11T13:56:04Z","2019-09-11T13:54:15Z","55941" +"*PyExfil.MoriRT.com*",".{0,1000}PyExfil\.MoriRT\.com.{0,1000}","offensive_tool_keyword","PyExfil","A Python Package for Data Exfiltration","T1041 - T1567 - T1027","TA0011 - TA0009 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/ytisf/PyExfil","1","1","N/A","N/A","10","8","782","141","2024-05-07T07:58:02Z","2014-11-27T19:06:24Z","55958" +"*pyExfil-latest.zip*",".{0,1000}pyExfil\-latest\.zip.{0,1000}","offensive_tool_keyword","PyExfil","A Python Package for Data Exfiltration","T1041 - T1567 - T1027","TA0011 - TA0009 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/ytisf/PyExfil","1","1","N/A","N/A","10","8","782","141","2024-05-07T07:58:02Z","2014-11-27T19:06:24Z","55970" +"*PyExfil-master*",".{0,1000}PyExfil\-master.{0,1000}","offensive_tool_keyword","PyExfil","A Python Package for Data Exfiltration","T1041 - T1567 - T1027","TA0011 - TA0009 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/ytisf/PyExfil","1","1","N/A","N/A","10","8","782","141","2024-05-07T07:58:02Z","2014-11-27T19:06:24Z","55971" +"*pygpoabuse.py*",".{0,1000}pygpoabuse\.py.{0,1000}","offensive_tool_keyword","pyGPOAbuse","python implementation of SharpGPOAbuse","T1566.001 - T1059.006 - T1112","TA0001 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/Hackndo/pyGPOAbuse","1","1","N/A","N/A","8","5","416","48","2024-02-18T19:23:57Z","2020-05-10T21:21:27Z","55973" +"*pyherion.py*",".{0,1000}pyherion\.py.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","55974" +"*pyLAPS-main*",".{0,1000}pyLAPS\-main.{0,1000}","offensive_tool_keyword","pyLAPS","A simple way to read and write LAPS passwords from linux.","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/p0dalirius/pyLAPS","1","1","#linux","N/A","9","2","105","16","2024-10-28T08:36:38Z","2021-10-05T18:35:21Z","55988" +"*pyMalleableC2*",".{0,1000}pyMalleableC2.{0,1000}","offensive_tool_keyword","cobaltstrike","Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CodeXTF2/Burp2Malleable","1","1","N/A","N/A","10","10","385","34","2023-04-06T15:24:12Z","2022-08-14T18:05:39Z","55989" +"*pypykatz.exe*",".{0,1000}pypykatz\.exe.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","55999" +"*pypykatz.git*",".{0,1000}pypykatz\.git.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","56000" +"*pypykatz.py*",".{0,1000}pypykatz\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","56003" +"*pypykatz.zip*",".{0,1000}pypykatz\.zip.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","56007" +"*pypykatz_handler.py*",".{0,1000}pypykatz_handler\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","56008" +"*pypykatz_rekall.py*",".{0,1000}pypykatz_rekall\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","56009" +"*pypykatz-master.zip*",".{0,1000}pypykatz\-master\.zip.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","56012" +"*Pyramid-main.zip*",".{0,1000}Pyramid\-main\.zip.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","56013" +"*pyrdp_scapy.py*",".{0,1000}pyrdp_scapy\.py.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","N/A","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","56019" +"*pyrdp-clonecert.py*",".{0,1000}pyrdp\-clonecert\.py.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","N/A","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","56020" +"*pyrdp-convert.py*",".{0,1000}pyrdp\-convert\.py.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","N/A","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","56021" +"*pyrdp-mitm.py*",".{0,1000}pyrdp\-mitm\.py.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","N/A","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","56023" +"*pyrdp-player.py*",".{0,1000}pyrdp\-player\.py.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","N/A","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","56024" +"*PyroTek3/PowerShell-AD-Recon*",".{0,1000}PyroTek3\/PowerShell\-AD\-Recon.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","56029" +"*pysecdump.exe*",".{0,1000}pysecdump\.exe.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","1","N/A","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","56032" +"*pysecdump.py*",".{0,1000}pysecdump\.py.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","1","N/A","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","56033" +"*pysnaffler-main*",".{0,1000}pysnaffler\-main.{0,1000}","offensive_tool_keyword","pysnaffler","This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.","T1083 - T1087 - T1114 - T1518","TA0007 - TA0009 - TA0010","N/A","N/A","Collection","https://github.com/skelsec/pysnaffler","1","1","N/A","N/A","10","1","91","5","2025-03-15T13:46:34Z","2023-11-17T21:52:40Z","56044" +"*pysoserial.py*",".{0,1000}pysoserial\.py.{0,1000}","offensive_tool_keyword","pysoserial","Python-based proof-of-concept tool for generating payloads that utilize unsafe Java object deserialization.","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","N/A","Resource Development","https://github.com/aStrowxyu/Pysoserial","1","1","N/A","N/A","9","1","9","1","2021-12-06T07:41:55Z","2021-11-16T01:55:31Z","56045" +"*Pysoserial-main*",".{0,1000}Pysoserial\-main.{0,1000}","offensive_tool_keyword","pysoserial","Python-based proof-of-concept tool for generating payloads that utilize unsafe Java object deserialization.","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","N/A","Resource Development","https://github.com/aStrowxyu/Pysoserial","1","1","N/A","N/A","9","1","9","1","2021-12-06T07:41:55Z","2021-11-16T01:55:31Z","56046" +"*PySplunkWhisperer2*",".{0,1000}PySplunkWhisperer2.{0,1000}","offensive_tool_keyword","SplunkWhisperer2","Local privilege escalation or remote code execution through Splunk Universal Forwarder (UF) misconfigurations","T1068 - T1059.003 - T1071.001","TA0004 - TA0003 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/cnotin/SplunkWhisperer2","1","1","N/A","N/A","9","10","250","53","2022-09-30T16:41:17Z","2019-02-24T18:05:51Z","56048" +"*pystinger_for_darkshadow*",".{0,1000}pystinger_for_darkshadow.{0,1000}","offensive_tool_keyword","cobaltstrike","Bypass firewall for traffic forwarding using webshell. Pystinger implements SOCK4 proxy and port mapping through webshell. It can be directly used by metasploit-framework - viper- cobalt strike for session online.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/FunnyWolf/pystinger","1","1","N/A","N/A","10","10","1397","205","2021-09-29T13:13:43Z","2019-09-29T05:23:54Z","56052" +"*python_modules/keyboard.zip*",".{0,1000}python_modules\/keyboard\.zip.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1100","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","56097" +"*python2??/generator.py*",".{0,1000}python2\?\?\/generator\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","CS anti-killing including python version and C version","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Gality369/CS-Loader","1","1","N/A","N/A","10","10","829","141","2025-04-02T09:37:10Z","2020-08-17T21:33:06Z","56098" +"*python2??/PyLoader.py*",".{0,1000}python2\?\?\/PyLoader\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","CS anti-killing including python version and C version","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Gality369/CS-Loader","1","1","N/A","N/A","10","10","829","141","2025-04-02T09:37:10Z","2020-08-17T21:33:06Z","56099" +"*python3??/generator.py*",".{0,1000}python3\?\?\/generator\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","CS anti-killing including python version and C version","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Gality369/CS-Loader","1","1","N/A","N/A","10","10","829","141","2025-04-02T09:37:10Z","2020-08-17T21:33:06Z","56127" +"*python3??/PyLoader.py*",".{0,1000}python3\?\?\/PyLoader\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","CS anti-killing including python version and C version","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Gality369/CS-Loader","1","1","N/A","N/A","10","10","829","141","2025-04-02T09:37:10Z","2020-08-17T21:33:06Z","56128" +"*python3_reverse_tcp.py*",".{0,1000}python3_reverse_tcp\.py.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","56129" +"*python3_reverse_tcp_v2.py*",".{0,1000}python3_reverse_tcp_v2\.py.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","56130" +"*pywerview.py*",".{0,1000}pywerview\.py.{0,1000}","offensive_tool_keyword","pywerview","A partial Python rewriting of PowerSploit PowerView","T1069.002 - T1018 - T1087.001 - T1033 - T1069.001 - T1087.002 - T1016 - T1482","TA0007 - TA0009","N/A","N/A","Reconnaissance","https://github.com/the-useless-one/pywerview","1","1","N/A","N/A","N/A","10","974","121","2025-03-17T14:04:51Z","2016-07-06T13:25:09Z","56131" +"*pywhisker.py*",".{0,1000}pywhisker\.py.{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","1","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","56133" +"*pywhisker-main*",".{0,1000}pywhisker\-main.{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","1","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","56134" +"*pywsus.py*",".{0,1000}pywsus\.py.{0,1000}","offensive_tool_keyword","pywsus","The main goal of this tool is to be a standalone implementation of a legitimate WSUS server which sends malicious responses to clients. The MITM attack itself should be done using other dedicated tools such as Bettercap.","T1505.003 - T1001.001 - T1560.001 - T1071.001","TA0003 - TA0011 - TA0002","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pywsus","1","1","N/A","network exploitation tool","N/A","4","303","44","2022-11-11T19:59:21Z","2020-08-11T21:44:35Z","56135" +"*q7wp5u55lhtuafjtsl6lkt24z4wvon2jexfzhzqqfrt3bqnpqboyqoid.onion*",".{0,1000}q7wp5u55lhtuafjtsl6lkt24z4wvon2jexfzhzqqfrt3bqnpqboyqoid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","56139" +"*QAX-A-Team/BrowserGhost*",".{0,1000}QAX\-A\-Team\/BrowserGhost.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","1","N/A","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","56140" +"*QAX-A-Team/EventCleaner*",".{0,1000}QAX\-A\-Team\/EventCleaner.{0,1000}","offensive_tool_keyword","EventCleaner","erase specified records from Windows event logs","T1070.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/QAX-A-Team/EventCleaner","1","1","N/A","N/A","10","6","599","148","2018-09-07T11:02:01Z","2018-07-27T07:37:32Z","56141" +"*QAX-A-Team/EventLogMaster*",".{0,1000}QAX\-A\-Team\/EventLogMaster.{0,1000}","offensive_tool_keyword","EventLogMaster","Cobalt Strike Plugin - RDP Log Forensics & Clearing","T1070.001 - T1070.003 - T1070.004 - T1563.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/QAX-A-Team/EventLogMaster","1","1","N/A","N/A","6","4","361","73","2019-12-23T10:31:35Z","2019-12-17T05:07:09Z","56142" +"*qd7pcafncosqfqu3ha6fcx4h6sr7tzwagzpcdcnytiw3b6varaeqv5yd.onion*",".{0,1000}qd7pcafncosqfqu3ha6fcx4h6sr7tzwagzpcdcnytiw3b6varaeqv5yd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","56143" +"*qkbbaxiuqqcqb5nox4np4qjcniy2q6m7yeluvj7n5i5dn7pgpcwxwfid.onion*",".{0,1000}qkbbaxiuqqcqb5nox4np4qjcniy2q6m7yeluvj7n5i5dn7pgpcwxwfid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","56145" +"*qmnmrba4s4a3py6z.onion*",".{0,1000}qmnmrba4s4a3py6z\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","56146" +"*qtc-de/remote-method-guesser*",".{0,1000}qtc\-de\/remote\-method\-guesser.{0,1000}","offensive_tool_keyword","remote-method-guesser","remote-method-guesser?(rmg) is a?Java RMI?vulnerability scanner and can be used to identify and verify common security vulnerabilities on?Java RMI?endpoints.","T1210.002 - T1046 - T1078.003","TA0001 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/qtc-de/remote-method-guesser","1","1","N/A","N/A","6","9","860","108","2024-07-03T19:40:54Z","2019-11-04T11:37:38Z","56153" +"*quantum-mirror.hu/mirrors/pub/blackarch/*/os/*",".{0,1000}quantum\-mirror\.hu\/mirrors\/pub\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","56154" +"*QUAPCInjectAsSystem*",".{0,1000}QUAPCInjectAsSystem.{0,1000}","offensive_tool_keyword","cobaltstrike","EDR Evasion - Combination of SwampThing - TikiTorch","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rkervella/CarbonMonoxide","1","1","N/A","N/A","10","10","25","10","2020-05-28T10:40:20Z","2020-05-15T09:32:25Z","56155" +"*QUAPCInjectElevated*",".{0,1000}QUAPCInjectElevated.{0,1000}","offensive_tool_keyword","cobaltstrike","EDR Evasion - Combination of SwampThing - TikiTorch","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rkervella/CarbonMonoxide","1","1","N/A","N/A","10","10","25","10","2020-05-28T10:40:20Z","2020-05-15T09:32:25Z","56156" +"*QUAPCInjectFakecmd*",".{0,1000}QUAPCInjectFakecmd.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","56157" +"*QUAPCInjectFakecmd*",".{0,1000}QUAPCInjectFakecmd.{0,1000}","offensive_tool_keyword","cobaltstrike","EDR Evasion - Combination of SwampThing - TikiTorch","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rkervella/CarbonMonoxide","1","1","N/A","N/A","10","10","25","10","2020-05-28T10:40:20Z","2020-05-15T09:32:25Z","56158" +"*QUAPCInjectWithoutPid*",".{0,1000}QUAPCInjectWithoutPid.{0,1000}","offensive_tool_keyword","cobaltstrike","EDR Evasion - Combination of SwampThing - TikiTorch","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rkervella/CarbonMonoxide","1","1","N/A","N/A","10","10","25","10","2020-05-28T10:40:20Z","2020-05-15T09:32:25Z","56159" +"*QuarksADDumper*",".{0,1000}QuarksADDumper.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","1","N/A","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","56160" +"*quarkslab/quarkspwdump*",".{0,1000}quarkslab\/quarkspwdump.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","1","N/A","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","56161" +"*quarks-pwdump.exe*",".{0,1000}quarks\-pwdump\.exe.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","1","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","56162" +"*quarks-pwdump.exe*",".{0,1000}quarks\-pwdump\.exe.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","1","N/A","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","56163" +"*quentinhardy*msdat*",".{0,1000}quentinhardy.{0,1000}msdat.{0,1000}","offensive_tool_keyword","MSDAT","MSDAT (Microsoft SQL Database Attacking Tool) is an open source penetration testing tool that tests the security of Microsoft SQL Databases remotely.","T1110 - T1059 - T1210 - T1047","TA0002 - TA0008 - TA0001","N/A","N/A","Exploitation tool","https://github.com/quentinhardy/msdat","1","1","N/A","N/A","N/A","10","909","144","2023-08-01T10:54:24Z","2018-02-15T12:34:57Z","56176" +"*quser.x64.o*",".{0,1000}quser\.x64\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF for quser.exe implementation using Windows API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/Quser-BOF","1","1","N/A","N/A","10","10","85","11","2023-03-22T17:07:02Z","2021-04-01T15:19:50Z","56183" +"*quser.x86.o*",".{0,1000}quser\.x86\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF for quser.exe implementation using Windows API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/Quser-BOF","1","1","N/A","N/A","10","10","85","11","2023-03-22T17:07:02Z","2021-04-01T15:19:50Z","56184" +"*qvo5sd7p5yazwbrgioky7rdu4vslxrcaeruhjr7ztn3t2pihp56ewlqd.onion*",".{0,1000}qvo5sd7p5yazwbrgioky7rdu4vslxrcaeruhjr7ztn3t2pihp56ewlqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","56186" +"*qwqdanchun*",".{0,1000}qwqdanchun.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","56192" +"*qwqdanchun/DcRat*",".{0,1000}qwqdanchun\/DcRat.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","56193" +"*QWRkLU1lbWJlciBOb3RlUHJvcGVydHkgLU5hbWUgVmlydHVhbFByb3RlY3QgLVZhbHVlICRWaXJ0dWFsUHJvdGVjdA*",".{0,1000}QWRkLU1lbWJlciBOb3RlUHJvcGVydHkgLU5hbWUgVmlydHVhbFByb3RlY3QgLVZhbHVlICRWaXJ0dWFsUHJvdGVjdA.{0,1000}","offensive_tool_keyword","mimikatz","invoke mimiaktz string found used by the tool EDRaser ","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Defense Evasion","https://github.com/SafeBreach-Labs/EDRaser","1","1","N/A","N/A","10","4","363","49","2024-04-06T17:42:40Z","2023-08-10T04:30:45Z","56194" +"*QXh4OEF4eDhBeHg4QXh4OA==*",".{0,1000}QXh4OEF4eDhBeHg4QXh4OA\=\=.{0,1000}","offensive_tool_keyword","cobaltstrike","ShellCode_Loader - Msf&CobaltStrike Antivirus ShellCode loader. Shellcode_encryption - Antivirus Shellcode encryption generation tool. currently tested for Antivirus 360 & Huorong & Computer Manager & Windows Defender (other antivirus software not tested).","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Axx8/ShellCode_Loader","1","1","N/A","N/A","10","10","412","47","2022-09-20T07:24:25Z","2022-09-02T14:41:18Z","56195" +"*r00t0v3rr1d3/merlin*",".{0,1000}r00t0v3rr1d3\/merlin.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","N/A","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","56196" +"*r00t-3xp10it/venom/master/bin/void.zip*",".{0,1000}r00t\-3xp10it\/venom\/master\/bin\/void\.zip.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","56197" +"*r0oth3x49/ghauri*",".{0,1000}r0oth3x49\/ghauri.{0,1000}","offensive_tool_keyword","ghauri","A cross-platform python based advanced sql injections detection & exploitation tool","T1190 - T1210 - T1095","TA0001 - TA0002 - TA0009","N/A","N/A","Vulnerability Scanner","https://github.com/r0oth3x49/ghauri","1","1","N/A","N/A","8","10","3483","361","2025-02-25T19:09:50Z","2022-10-01T11:21:50Z","56198" +"*r0oth3x49/Tor.git*",".{0,1000}r0oth3x49\/Tor\.git.{0,1000}","offensive_tool_keyword","tor","Tor is a python based module for using tor proxy/network services on windows - osx - linux with just one click.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0005 - TA0010 - TA0011","N/A","Dispossessor - APT28 - APT29 - Leviathan","Defense Evasion","https://github.com/r0oth3x49/Tor","1","1","#linux","N/A","N/A","2","156","42","2018-04-21T10:55:00Z","2016-09-22T11:22:33Z","56199" +"*r1cksec/thoth*",".{0,1000}r1cksec\/thoth.{0,1000}","offensive_tool_keyword","thoth","Automate recon for red team assessments.","T1190 - T1083 - T1018","TA0007 - TA0043 - TA0001","N/A","N/A","Reconnaissance","https://github.com/r1cksec/thoth","1","1","N/A","N/A","7","1","95","10","2025-02-03T12:05:52Z","2021-11-15T13:40:56Z","56201" +"*r4wd3r/RID-Hijacking*",".{0,1000}r4wd3r\/RID\-Hijacking.{0,1000}","offensive_tool_keyword","RID-Hijacking","Windows RID Hijacking persistence technique","T1174","TA0003","N/A","N/A","Persistence","https://github.com/r4wd3r/RID-Hijacking","1","1","N/A","N/A","9","2","174","43","2024-11-20T01:43:01Z","2018-07-14T18:48:51Z","56204" +"*r4wd3r/Suborner*",".{0,1000}r4wd3r\/Suborner.{0,1000}","offensive_tool_keyword","Suborner","The Invisible Account Forger - A simple program to create a Windows account you will only know about ","T1098 - T1175 - T1033","TA0007 - TA0008 - TA0003","N/A","N/A","Persistence","https://github.com/r4wd3r/Suborner","1","1","N/A","N/A","9","5","469","58","2024-11-20T01:34:44Z","2022-04-26T00:12:58Z","56205" +"*r77Rootkit%201.5.2.zip*",".{0,1000}r77Rootkit\%201\.5\.2\.zip.{0,1000}","offensive_tool_keyword","r77-rootkit","Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections","T1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/bytecode77/r77-rootkit","1","1","N/A","N/A","10","10","1884","425","2025-03-25T17:59:20Z","2017-12-17T13:04:14Z","56206" +"*radius2john.pl*",".{0,1000}radius2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","56208" +"*radius2john.py*",".{0,1000}radius2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","56209" +"*RagingRotator-main.*",".{0,1000}RagingRotator\-main\..{0,1000}","offensive_tool_keyword","RagingRotator","A tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways.","T1110 - T1027 - T1071 - T1090 - T1621","TA0006 - TA0005 - TA0001","N/A","N/A","Credential Access","https://github.com/nickzer0/RagingRotator","1","1","N/A","N/A","10","1","79","7","2024-06-06T19:31:34Z","2023-09-01T15:19:38Z","56215" +"*ragnarjtm25k3w4cy6kvfttfhm24mpynikjt7yll5pvpfo4a7yuzweyd.onion*",".{0,1000}ragnarjtm25k3w4cy6kvfttfhm24mpynikjt7yll5pvpfo4a7yuzweyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","56217" +"*ragnarmj3hlykxstyanwtgf33eyacccleg45ctygkuw7dkgysict6xyd.onion*",".{0,1000}ragnarmj3hlykxstyanwtgf33eyacccleg45ctygkuw7dkgysict6xyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","56218" +"*RAI/ase_docker*",".{0,1000}RAI\/ase_docker.{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","56220" +"*rai-attack-servers.*",".{0,1000}rai\-attack\-servers\..{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","56221" +"*Raikia/SMBCrunch*",".{0,1000}Raikia\/SMBCrunch.{0,1000}","offensive_tool_keyword","SMBCrunch","SMBCrunch allows a red teamer to quickly identify Windows File Shares in a network - performs a recursive directory listing of the provided shares and can even grab a file from the remote share if it looks like a juicy target.","T1021.002 - T1005 - T1210","TA0001 - TA0002 - TA0003 - TA0009","N/A","N/A","Lateral Movement","https://github.com/Raikia/SMBCrunch","1","1","N/A","N/A","9","2","165","20","2018-03-07T15:50:12Z","2016-03-25T10:10:19Z","56222" +"*RainbowCrack*",".{0,1000}RainbowCrack.{0,1000}","offensive_tool_keyword","RainbowCrack","The RainbowCrack tool is a hash cracker that makes use of a large-scale time-memory trade-off. A traditional brute force cracker tries all possible plaintexts one by one. which can be time consuming for complex passwords. RainbowCrack uses a time-memory trade-off to do all the cracking-time computation in advance and store the results in so-called rainbow tables. It does take a long time to precompute the tables but RainbowCrack can be hundreds of times faster than a brute force cracker once the precomputation is finished. For downloads and more information. visit the RainbowCrack homepage","T1110 - T1027 - T1071 - T1090 - T1621","TA0001 - TA0002 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Credential Access","http://project-rainbowcrack.com/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","56223" +"*rai-redirector-dns*",".{0,1000}rai\-redirector\-dns.{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","56224" +"*rai-redirector-http*",".{0,1000}rai\-redirector\-http.{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","56225" +"*rajkumardusad/onex*",".{0,1000}rajkumardusad\/onex.{0,1000}","offensive_tool_keyword","onex","Onex is a package manager for hacker's. Onex manage more than 400+ hacking tools that can be installed on single click","T1105 - T1078 - T1059 - T1087","TA0007 - TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/rajkumardusad/onex","1","1","N/A","N/A","N/A","","N/A","","","","56228" +"*rajkumardusad/Tool-X*",".{0,1000}rajkumardusad\/Tool\-X.{0,1000}","offensive_tool_keyword","Tool-X","Tool-X is a Kali Linux hacking tools installer for Termux and linux system. Tool-X was developed for Termux and linux based systems. Using Tool-X you can install almost 370+ hacking tools in Termux (android) and other Linux based distributions. Now Tool-X is available for Ubuntu Debian etc.","T1212 - T1566 - T1550 - T1133","TA0002 - TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/rajkumardusad/Tool-X","1","1","#linux","N/A","N/A","","N/A","","","","56229" +"*RalfHacker/Kerbeus-BOF*",".{0,1000}RalfHacker\/Kerbeus\-BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","BOF for Kerberos abuse (an implementation of some important features of the Rubeus)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RalfHacker/Kerbeus-BOF","1","1","N/A","N/A","10","10","458","51","2025-03-29T18:15:17Z","2023-11-20T10:01:36Z","56231" +"*RalphDesmangles/22f580655f479f189c1de9e7720776f1*",".{0,1000}RalphDesmangles\/22f580655f479f189c1de9e7720776f1.{0,1000}","offensive_tool_keyword","GetLoggedOnUsersRegistry","PoC To enumerate logged on users on a remote system using the winreg named pipe","T1087 - T1018 - T1057","TA0007 - TA0008","N/A","N/A","Discovery","https://gist.github.com/RalphDesmangles/22f580655f479f189c1de9e7720776f1","1","1","N/A","N/A","8","8","N/A","N/A","N/A","N/A","56232" +"*random_c2_profile*",".{0,1000}random_c2_profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","56234" +"*random_c2profile.*",".{0,1000}random_c2profile\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","56235" +"*random_user_agent.params*",".{0,1000}random_user_agent\.params.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","56236" +"*random_user_agent.user_agent*",".{0,1000}random_user_agent\.user_agent.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","56237" +"*randomalice1986@*",".{0,1000}randomalice1986\@.{0,1000}","offensive_tool_keyword","dnstwist","See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.","T1560 - T1565 - T1566 - T1568 - T1569","TA0002 - TA0005","N/A","N/A","Phishing","https://github.com/elceef/dnstwist","1","1","#email","email user name","3","10","5113","801","2025-04-15T18:41:47Z","2015-06-11T12:24:17Z","56238" +"*randombob1986@*",".{0,1000}randombob1986\@.{0,1000}","offensive_tool_keyword","dnstwist","See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence.","T1560 - T1565 - T1566 - T1568 - T1569","TA0002 - TA0005","N/A","N/A","Phishing","https://github.com/elceef/dnstwist","1","1","#email","email user name","3","10","5113","801","2025-04-15T18:41:47Z","2015-06-11T12:24:17Z","56240" +"*randomize_sw2_seed.py*",".{0,1000}randomize_sw2_seed\.py.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","56241" +"*Ransomware.dll*",".{0,1000}Ransomware\.dll.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","56257" +"*Ransomware.pdb*",".{0,1000}Ransomware\.pdb.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","56258" +"*ransomware_config.py*",".{0,1000}ransomware_config\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","56259" +"*ransomware_payload.py*",".{0,1000}ransomware_payload\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","56260" +"*Ransomware-E20F7CED-42AD-485E-BE4D-DE21DCE58EC0.json*",".{0,1000}Ransomware\-E20F7CED\-42AD\-485E\-BE4D\-DE21DCE58EC0\.json.{0,1000}","offensive_tool_keyword","power-pwn","An offensive and defensive security toolset for Microsoft 365 Power Platform","T1078 - T1078.004 - T1136 - T1136.001 - T1021 - T1021.003 - T1114 - T1114.002","TA0003 - TA0004 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/mbrg/power-pwn","1","1","N/A","N/A","10","10","939","100","2025-03-20T08:54:43Z","2022-06-14T11:40:21Z","56261" +"*RansomwarePoc.cpp*",".{0,1000}RansomwarePoc\.cpp.{0,1000}","offensive_tool_keyword","ContainYourself","Abuses the Windows containers framework to bypass EDRs.","T1562 - T1562.004 - T1212 - T1212.002 - T1055 - T1055.015","TA0005","N/A","N/A","Defense Evasion","https://github.com/deepinstinct/ContainYourself","1","1","N/A","N/A","10","4","310","39","2023-08-31T07:26:22Z","2023-07-12T14:47:24Z","56262" +"*RansomwarePoc.exe*",".{0,1000}RansomwarePoc\.exe.{0,1000}","offensive_tool_keyword","ContainYourself","Abuses the Windows containers framework to bypass EDRs.","T1562 - T1562.004 - T1212 - T1212.002 - T1055 - T1055.015","TA0005","N/A","N/A","Defense Evasion","https://github.com/deepinstinct/ContainYourself","1","1","N/A","N/A","10","4","310","39","2023-08-31T07:26:22Z","2023-07-12T14:47:24Z","56263" +"*ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion*",".{0,1000}ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","56265" +"*ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion*",".{0,1000}ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","56266" +"*ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion.ly*",".{0,1000}ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd\.onion\.ly.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","56267" +"*ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion.ly*",".{0,1000}ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd\.onion\.ly.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","56268" +"*rapid7.github.io/metasploit-framework/api/*",".{0,1000}rapid7\.github\.io\/metasploit\-framework\/api\/.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","56270" +"*rapid7/metasploit-omnibus*",".{0,1000}rapid7\/metasploit\-omnibus.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-omnibus","1","1","N/A","N/A","10","3","268","213","2025-04-18T13:17:56Z","2015-02-26T18:42:09Z","56271" +"*rar2john.*",".{0,1000}rar2john\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","56275" +"*rarce-1.0.0.tar.gz*",".{0,1000}rarce\-1\.0\.0\.tar\.gz.{0,1000}","offensive_tool_keyword","RaRCE","An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831 - WinRAR RCE before versions 6.23","T1068 - T1203 - T1059.003","TA0001 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/ignis-sec/CVE-2023-38831-RaRCE","1","1","N/A","N/A","9","2","115","18","2023-08-27T22:17:56Z","2023-08-27T21:49:37Z","56278" +"*rarce-1.0.0-py3-none-any.whl*",".{0,1000}rarce\-1\.0\.0\-py3\-none\-any\.whl.{0,1000}","offensive_tool_keyword","RaRCE","An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831 - WinRAR RCE before versions 6.23","T1068 - T1203 - T1059.003","TA0001 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/ignis-sec/CVE-2023-38831-RaRCE","1","1","N/A","N/A","9","2","115","18","2023-08-27T22:17:56Z","2023-08-27T21:49:37Z","56279" +"*rasman*whoami*",".{0,1000}rasman.{0,1000}whoami.{0,1000}","offensive_tool_keyword","RasmanPotato","using RasMan service for privilege escalation","T1548.002 - T1055.002 - T1055.001 ","TA0004 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/crisprss/RasmanPotato","1","1","N/A","N/A","10","4","371","53","2023-02-06T10:27:41Z","2023-02-06T09:41:51Z","56280" +"*RasmanPotato-master*",".{0,1000}RasmanPotato\-master.{0,1000}","offensive_tool_keyword","RasmanPotato","using RasMan service for privilege escalation","T1548.002 - T1055.002 - T1055.001 ","TA0004 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/crisprss/RasmanPotato","1","1","N/A","N/A","10","4","371","53","2023-02-06T10:27:41Z","2023-02-06T09:41:51Z","56284" +"*rasta-mouse/PPEnum*",".{0,1000}rasta\-mouse\/PPEnum.{0,1000}","offensive_tool_keyword","cobaltstrike","Simple BOF to read the protection level of a process","T1012","TA0007","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Reconnaissance","https://github.com/rasta-mouse/PPEnum","1","1","N/A","N/A","N/A","2","115","9","2023-05-10T16:41:09Z","2023-05-10T16:38:36Z","56286" +"*rasta-mouse/RuralBishop*",".{0,1000}rasta\-mouse\/RuralBishop.{0,1000}","offensive_tool_keyword","RuralBishop","creates a local RW section in UrbanBishop and then maps that section as RX into a remote process","T1055 - T1055.012 - T1055.002 - T1098 - T1027 - T1027.002 - T1070.004","TA0005 - TA0003 - TA0002","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/RuralBishop","1","1","N/A","N/A","10","2","107","26","2020-07-19T18:47:44Z","2020-07-19T18:47:38Z","56287" +"*rasta-mouse/SharpC2*",".{0,1000}rasta\-mouse\/SharpC2.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","56288" +"*rasta-mouse/ThreatCheck*",".{0,1000}rasta\-mouse\/ThreatCheck.{0,1000}","offensive_tool_keyword","ThreatCheck","Identifies the bytes that Microsoft Defender / AMSI Consumer flags on","T1059.001 - T1059.005 - T1027.002 - T1070.004","TA0002 - TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/ThreatCheck","1","1","N/A","N/A","10","10","1185","143","2024-06-01T16:46:57Z","2020-10-08T11:22:26Z","56289" +"*rasta-mouse/TikiTorch*",".{0,1000}rasta\-mouse\/TikiTorch.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","56290" +"*RatChatPT.exe*",".{0,1000}RatChatPT\.exe.{0,1000}","offensive_tool_keyword","ratchatgpt","ratchatpt a tool using openai api as a C2","T1094 - T1071.001","TA0011 - TA0002","N/A","N/A","C2","https://github.com/spartan-conseil/ratchatpt","1","1","N/A","N/A","10","10","16","6","2023-06-09T12:39:00Z","2023-06-09T09:19:10Z","56293" +"*RatChatPT.exe*",".{0,1000}RatChatPT\.exe.{0,1000}","offensive_tool_keyword","ratchatpt","C2 using openAI API","T1094 - T1071.001","TA0011 - TA0002","N/A","N/A","C2","https://github.com/spartan-conseil/ratchatpt","1","1","N/A","risk of False positive","10","10","16","6","2023-06-09T12:39:00Z","2023-06-09T09:19:10Z","56294" +"*RatChatPT_windows.exe*",".{0,1000}RatChatPT_windows\.exe.{0,1000}","offensive_tool_keyword","ratchatgpt","ratchatpt a tool using openai api as a C2","T1094 - T1071.001","TA0011 - TA0002","N/A","N/A","C2","https://github.com/spartan-conseil/ratchatpt","1","1","N/A","N/A","10","10","16","6","2023-06-09T12:39:00Z","2023-06-09T09:19:10Z","56295" +"*RatChatPT_windows.exe*",".{0,1000}RatChatPT_windows\.exe.{0,1000}","offensive_tool_keyword","ratchatpt","C2 using openAI API","T1094 - T1071.001","TA0011 - TA0002","N/A","N/A","C2","https://github.com/spartan-conseil/ratchatpt","1","1","N/A","risk of False positive","10","10","16","6","2023-06-09T12:39:00Z","2023-06-09T09:19:10Z","56296" +"*ratchatpt-main*",".{0,1000}ratchatpt\-main.{0,1000}","offensive_tool_keyword","ratchatpt","C2 using openAI API","T1094 - T1071.001","TA0011 - TA0002","N/A","N/A","C2","https://github.com/spartan-conseil/ratchatpt","1","1","N/A","risk of False positive","10","10","16","6","2023-06-09T12:39:00Z","2023-06-09T09:19:10Z","56298" +"*raw*/straight-shooter.c*",".{0,1000}raw.{0,1000}\/straight\-shooter\.c.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","56303" +"*raw.githubusercontent.com/6nz/virustotal-vm-blacklist/*",".{0,1000}raw\.githubusercontent\.com\/6nz\/virustotal\-vm\-blacklist\/.{0,1000}","offensive_tool_keyword","SomalifuscatorV2","windows batch obfuscator","T1027 - T1497 - T1057","TA0005","N/A","N/A","Defense Evasion","https://github.com/KDot227/SomalifuscatorV2","1","1","N/A","N/A","10","4","315","42","2025-01-19T04:30:49Z","2022-09-23T00:46:51Z","56385" +"*raw.githubusercontent.com/Flangvik/statistically-likely-usernames/*",".{0,1000}raw\.githubusercontent\.com\/Flangvik\/statistically\-likely\-usernames\/.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","56386" +"*raw.githubusercontent.com/peass-ng/PEASS-ng/master/winPEAS/winPEASps1/winPEAS.ps1*",".{0,1000}raw\.githubusercontent\.com\/peass\-ng\/PEASS\-ng\/master\/winPEAS\/winPEASps1\/winPEAS\.ps1.{0,1000}","offensive_tool_keyword","hackshell","Make BASH stealthy and hacker friendly with lots of bash functions","T1070.003 - T1059.004 - T1564.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/hackerschoice/hackshell","1","1","N/A","N/A","9","3","251","28","2025-04-21T11:23:41Z","2024-07-16T15:56:11Z","56387" +"*raw.githubusercontent.com/swagkarna/Bypass-Tamper-Protection*",".{0,1000}raw\.githubusercontent\.com\/swagkarna\/Bypass\-Tamper\-Protection.{0,1000}","offensive_tool_keyword","Defeat-Defender","script to dismantle complete windows defender protection and even bypass tamper protection - Disable Windows-Defender Permanently.","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/swagkarna/Defeat-Defender-V1.2.0","1","1","N/A","N/A","10","10","1530","316","2023-10-20T17:55:09Z","2020-12-10T07:22:06Z","56388" +"*raw_keylogger.tar.gz*",".{0,1000}raw_keylogger\.tar\.gz.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/trustedsec/SliverKeylogger","1","1","N/A","N/A","10","10","159","44","2023-09-22T19:39:04Z","2022-06-17T19:32:53Z","56390" +"*raworldw32b2qxevn3gp63pvibgixr4v75z62etlptg3u3pmajwra4ad.onion*",".{0,1000}raworldw32b2qxevn3gp63pvibgixr4v75z62etlptg3u3pmajwra4ad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","56391" +"*rawrelayserver.py*",".{0,1000}rawrelayserver\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","56392" +"*rawSHA1_linkedIn_fmt_plug*",".{0,1000}rawSHA1_linkedIn_fmt_plug.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","56393" +"*RBCD_Petitpotam_VulnerableServers.txt*",".{0,1000}RBCD_Petitpotam_VulnerableServers\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","56396" +"*rbsec/dnscan*",".{0,1000}rbsec\/dnscan.{0,1000}","offensive_tool_keyword","dnscan","dnscan is a python wordlist-based DNS subdomain scanner.","T1595 - T1595.002 - T1018 - T1046","TA0007 - TA0043","N/A","N/A","Reconnaissance","https://github.com/rbsec/dnscan","1","1","N/A","N/A","6","10","1193","410","2024-12-17T15:29:50Z","2013-03-13T10:42:07Z","56397" +"*rbvuetuneohce3ouxjlbxtimyyxokb4btncxjbo44fbgxqy7tskinwad.onion*",".{0,1000}rbvuetuneohce3ouxjlbxtimyyxokb4btncxjbo44fbgxqy7tskinwad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","56398" +"*rcat-v3.*darwin-aarch64*",".{0,1000}rcat\-v3\..{0,1000}darwin\-aarch64.{0,1000}","offensive_tool_keyword","rustcat","Rustcat(rcat) - The modern Port listener and Reverse shell","T1090.001 - T1090.002 - T1046","TA0011 - TA0009 - TA0040","N/A","N/A","C2","https://github.com/robiot/rustcat","1","1","#linux","N/A","10","10","758","63","2024-07-20T14:20:34Z","2021-06-04T17:03:47Z","56408" +"*rcat-v3.*-darwin-x86_64*",".{0,1000}rcat\-v3\..{0,1000}\-darwin\-x86_64.{0,1000}","offensive_tool_keyword","rustcat","Rustcat(rcat) - The modern Port listener and Reverse shell","T1090.001 - T1090.002 - T1046","TA0011 - TA0009 - TA0040","N/A","N/A","C2","https://github.com/robiot/rustcat","1","1","#linux","N/A","10","10","758","63","2024-07-20T14:20:34Z","2021-06-04T17:03:47Z","56409" +"*rcat-v3.*-linux-x86_64*",".{0,1000}rcat\-v3\..{0,1000}\-linux\-x86_64.{0,1000}","offensive_tool_keyword","rustcat","Rustcat(rcat) - The modern Port listener and Reverse shell","T1090.001 - T1090.002 - T1046","TA0011 - TA0009 - TA0040","N/A","N/A","C2","https://github.com/robiot/rustcat","1","1","#linux","N/A","10","10","758","63","2024-07-20T14:20:34Z","2021-06-04T17:03:47Z","56410" +"*RCE-exploits*",".{0,1000}RCE\-exploits.{0,1000}","offensive_tool_keyword","POC","poc rce - The exploit samples database is a repository for RCE (remote code execution) exploits and Proof-of-Concepts for WINDOWS. the samples are uploaded for education purposes for red and blue teams.","T1059.001 - T1210.001 - T1212 - T1055.012","TA0002 - TA0007 - TA0008","N/A","N/A","Exploitation tool","https://github.com/smgorelik/Windows-RCE-exploits","1","1","N/A","N/A","N/A","8","746","179","2023-12-11T22:30:33Z","2018-02-13T11:23:40Z","56411" +"*RCStep/RedTeam_Tools_n_Stuff*",".{0,1000}RCStep\/RedTeam_Tools_n_Stuff.{0,1000}","offensive_tool_keyword","RedTeam_Tools_n_Stuff","Collection of self-made Red Team tools","T1070.004 - T1222 - T1070.003 - T1003.005 - T1057","TA0005 - TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/samkenxstream/SAMkenXCCorePHdLAwiN8SoLr77","1","1","N/A","N/A","7","1","1","1","2023-10-13T06:31:42Z","2023-10-04T13:43:37Z","56430" +"*RDE1-main.zip*",".{0,1000}RDE1\-main\.zip.{0,1000}","offensive_tool_keyword","RDE1","RDE1 (Rusty Data Exfiltrator) is client and server tool allowing auditor to extract files from DNS and HTTPS protocols written in Rust","T1048.003 - T1567.001 - T1020","TA0011 - TA0010 - TA0040","N/A","N/A","C2","https://github.com/g0h4n/RDE1","1","1","N/A","N/A","10","10","39","6","2025-04-04T18:54:54Z","2023-09-25T20:29:08Z","56434" +"*rdi_net_user.cpp*",".{0,1000}rdi_net_user\.cpp.{0,1000}","offensive_tool_keyword","cobaltstrike","Use windows api to add users which can be used when net is unavailable","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/lengjibo/NetUser","1","1","N/A","N/A","10","10","420","90","2021-09-29T14:22:09Z","2020-01-09T08:33:27Z","56437" +"*rdp_doublepulsar_rce.*",".{0,1000}rdp_doublepulsar_rce\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","56442" +"*RDPassSpray.*.log*",".{0,1000}RDPassSpray\..{0,1000}\.log.{0,1000}","offensive_tool_keyword","RDPassSpray","Python3 tool to perform password spraying using RDP","T1110.003 - T1059.006 - T1076.001","TA0001 - TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/xFreed0m/RDPassSpray","1","1","#logfile","N/A","10","7","648","244","2023-08-17T15:09:50Z","2019-06-05T17:10:42Z","56445" +"*RDPassSpray.csv*",".{0,1000}RDPassSpray\.csv.{0,1000}","offensive_tool_keyword","RDPassSpray","Python3 tool to perform password spraying using RDP","T1110.003 - T1059.006 - T1076.001","TA0001 - TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/xFreed0m/RDPassSpray","1","1","N/A","N/A","10","7","648","244","2023-08-17T15:09:50Z","2019-06-05T17:10:42Z","56446" +"*RDPassSpray.py*",".{0,1000}RDPassSpray\.py.{0,1000}","offensive_tool_keyword","RDPassSpray","Python3 tool to perform password spraying using RDP","T1110.003 - T1059.006 - T1076.001","TA0001 - TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/xFreed0m/RDPassSpray","1","1","N/A","N/A","10","7","648","244","2023-08-17T15:09:50Z","2019-06-05T17:10:42Z","56447" +"*RDPassSpray-master*",".{0,1000}RDPassSpray\-master.{0,1000}","offensive_tool_keyword","RDPassSpray","Python3 tool to perform password spraying using RDP","T1110.003 - T1059.006 - T1076.001","TA0001 - TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/xFreed0m/RDPassSpray","1","1","N/A","N/A","10","7","648","244","2023-08-17T15:09:50Z","2019-06-05T17:10:42Z","56449" +"*rdpbrute.py*",".{0,1000}rdpbrute\.py.{0,1000}","offensive_tool_keyword","RedTeam_toolkit","Red Team Toolkit is an Open-Source Django Offensive Web-App which is keeping the useful offensive tools used in the red-teaming together","T1083 - T1065 - T1204 - T1087 - T1203","TA0007 - TA0005 - TA0001","N/A","N/A","Reconnaissance","https://github.com/signorrayan/RedTeam_toolkit","1","1","N/A","N/A","N/A","6","561","121","2025-03-28T06:59:25Z","2021-08-18T08:58:14Z","56450" +"*RDP-Caching.ps1*",".{0,1000}RDP\-Caching\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","56451" +"*RDPCredentialStealer.zip*",".{0,1000}RDPCredentialStealer\.zip.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","56452" +"*RDPCredentialStealer-main*",".{0,1000}RDPCredentialStealer\-main.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","56453" +"*RDPCredsStealerDLL.*",".{0,1000}RDPCredsStealerDLL\..{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","56454" +"*RDPCredsStealerDLL.dll*",".{0,1000}RDPCredsStealerDLL\.dll.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","56455" +"*rdphijack.*",".{0,1000}rdphijack\..{0,1000}","offensive_tool_keyword","RDPHijack-BOF","BOF - RDPHijack - Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.","T1021 - T1021.002 - T1032 - T1055 - T1070 - T1070.006 - T1070.007 - T1574.001","TA0002 - TA0003 - TA0004","N/A","N/A","Lateral Movement","https://github.com/netero1010/RDPHijack-BOF","1","1","N/A","N/A","N/A","3","298","46","2022-07-08T10:14:32Z","2022-07-08T10:14:07Z","56456" +"*rdphijack.x64*",".{0,1000}rdphijack\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/RDPHijack-BOF","1","1","N/A","N/A","10","3","298","46","2022-07-08T10:14:32Z","2022-07-08T10:14:07Z","56457" +"*rdphijack.x64.*",".{0,1000}rdphijack\.x64\..{0,1000}","offensive_tool_keyword","RDPHijack-BOF","BOF - RDPHijack - Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.","T1021 - T1021.002 - T1032 - T1055 - T1070 - T1070.006 - T1070.007 - T1574.001","TA0002 - TA0003 - TA0004","N/A","N/A","Lateral Movement","https://github.com/netero1010/RDPHijack-BOF","1","1","N/A","N/A","N/A","3","298","46","2022-07-08T10:14:32Z","2022-07-08T10:14:07Z","56458" +"*rdphijack.x86*",".{0,1000}rdphijack\.x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/RDPHijack-BOF","1","1","N/A","N/A","10","3","298","46","2022-07-08T10:14:32Z","2022-07-08T10:14:07Z","56459" +"*rdphijack.x86.*",".{0,1000}rdphijack\.x86\..{0,1000}","offensive_tool_keyword","RDPHijack-BOF","BOF - RDPHijack - Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.","T1021 - T1021.002 - T1032 - T1055 - T1070 - T1070.006 - T1070.007 - T1574.001","TA0002 - TA0003 - TA0004","N/A","N/A","Lateral Movement","https://github.com/netero1010/RDPHijack-BOF","1","1","N/A","N/A","N/A","3","298","46","2022-07-08T10:14:32Z","2022-07-08T10:14:07Z","56460" +"*RDPHijack-BOF*",".{0,1000}RDPHijack\-BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/RDPHijack-BOF","1","1","N/A","N/A","10","3","298","46","2022-07-08T10:14:32Z","2022-07-08T10:14:07Z","56461" +"*RDPHijack-BOF*",".{0,1000}RDPHijack\-BOF.{0,1000}","offensive_tool_keyword","RDPHijack-BOF","BOF - RDPHijack - Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.","T1021 - T1021.002 - T1032 - T1055 - T1070 - T1070.006 - T1070.007 - T1574.001","TA0002 - TA0003 - TA0004","N/A","N/A","Lateral Movement","https://github.com/netero1010/RDPHijack-BOF","1","1","N/A","N/A","N/A","3","298","46","2022-07-08T10:14:32Z","2022-07-08T10:14:07Z","56462" +"*RDPInception*",".{0,1000}RDPInception.{0,1000}","offensive_tool_keyword","RDPInception","A proof of concept for the RDP Inception Attack","T1188 - T1214 - T1555.003","TA0007 - TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/mdsecactivebreach/RDPInception","1","1","N/A","N/A","N/A","4","347","325","2017-06-29T16:57:25Z","2017-06-29T10:08:23Z","56463" +"*RDPKeylog.exe*",".{0,1000}RDPKeylog\.exe.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","56464" +"*RDPReplayer.py*",".{0,1000}RDPReplayer\.py.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","N/A","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","56465" +"*rdpscraper*",".{0,1000}rdpscraper.{0,1000}","offensive_tool_keyword","rdpscraper","rdpscraper - Enumerates users based off RDP Screenshots","T1110 - T1189 - T1056.001","TA0006 - TA0008 - TA0011","N/A","N/A","Reconnaissance","https://github.com/x90skysn3k/rdpscraper","1","1","N/A","N/A","N/A","1","34","15","2023-10-25T21:17:52Z","2017-07-19T17:02:24Z","56466" +"*RDPSpray*",".{0,1000}RDPSpray.{0,1000}","offensive_tool_keyword","RDPSpray","Tool for password spraying RDP","T1110.001 - T1555.002","TA0006 - TA0040 - TA0003","N/A","N/A","Credential Access","https://github.com/dafthack/RDPSpray","1","1","N/A","N/A","N/A","1","95","28","2018-10-12T18:32:51Z","2018-10-12T18:29:52Z","56467" +"*RdpStrike.x64.bin*",".{0,1000}RdpStrike\.x64\.bin.{0,1000}","offensive_tool_keyword","RdpStrike","Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP","T1081 - T1055.011 - T1012 - T1113 - T1040 - T1185","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xEr3bus/RdpStrike","1","1","N/A","N/A","10","3","238","27","2024-06-11T19:40:05Z","2024-06-11T19:31:50Z","56469" +"*RdpThief.*",".{0,1000}RdpThief\..{0,1000}","offensive_tool_keyword","cobaltstrike","Erebus CobaltStrike post penetration testing plugin","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DeEpinGh0st/Erebus","1","1","N/A","N/A","10","10","1518","221","2021-10-28T06:20:51Z","2019-09-26T09:32:00Z","56471" +"*RdpThief.dll*",".{0,1000}RdpThief\.dll.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","1","N/A","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","56472" +"*RdpThief.exe*",".{0,1000}RdpThief\.exe.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","1","N/A","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","56473" +"*rdrleakdiag.py*",".{0,1000}rdrleakdiag\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","56479" +"*read_cs_teamserver*",".{0,1000}read_cs_teamserver.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","56483" +"*readShellcode*",".{0,1000}readShellcode.{0,1000}","offensive_tool_keyword","C2 related tools","Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners and analysts.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/mgeeky/ThreadStackSpoofer","1","1","N/A","N/A","10","10","1109","180","2022-06-17T18:06:35Z","2021-09-26T22:48:17Z","56487" +"*ReadyToPhish.xls*",".{0,1000}ReadyToPhish\.xls.{0,1000}","offensive_tool_keyword","Macrome","An Excel Macro Document Reader/Writer for Red Teamers & Analysts. Blog posts describing what this tool actually does can be found https://malware.pizza/2020/05/12/evading-av-with-excel-macros-and-biff8-xls/ and https://malware.pizza/2020/06/19/further-evasion-in-the-forgotten-corners-of-ms-xls/","T1140","TA0005","N/A","N/A","Exploitation tool","https://github.com/michaelweber/Macrome","1","1","N/A","N/A","N/A","6","520","79","2022-02-01T16:26:13Z","2020-05-07T22:44:11Z","56488" +"*RealBey/ThisIsNotRat*",".{0,1000}RealBey\/ThisIsNotRat.{0,1000}","offensive_tool_keyword","ThisIsNotRat","control windows computeur from telegram","T1098 - T1079 - T1105 - T1047 - T1059","TA0010 - TA0009 - TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/RealBey/ThisIsNotRat","1","1","N/A","N/A","9","10","64","17","2023-09-10T07:39:38Z","2023-09-07T14:07:32Z","56490" +"*RealBlindingEDR.cpp*",".{0,1000}RealBlindingEDR\.cpp.{0,1000}","offensive_tool_keyword","RealBlindingEDR","AV/EDR evasion","T1562.001 - T1548.001","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/myzxcg/RealBlindingEDR","1","1","N/A","N/A","10","10","1050","190","2024-06-21T03:16:55Z","2023-10-28T07:06:53Z","56491" +"*RealBlindingEDR.exe*",".{0,1000}RealBlindingEDR\.exe.{0,1000}","offensive_tool_keyword","RealBlindingEDR","AV/EDR evasion","T1562.001 - T1548.001","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/myzxcg/RealBlindingEDR","1","1","N/A","N/A","10","10","1050","190","2024-06-21T03:16:55Z","2023-10-28T07:06:53Z","56492" +"*RealBlindingEDR/releases*",".{0,1000}RealBlindingEDR\/releases.{0,1000}","offensive_tool_keyword","RealBlindingEDR","AV/EDR evasion","T1562.001 - T1548.001","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/myzxcg/RealBlindingEDR","1","1","N/A","N/A","10","10","1050","190","2024-06-21T03:16:55Z","2023-10-28T07:06:53Z","56494" +"*Real-Passwords*",".{0,1000}Real\-Passwords.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","56495" +"*Reaper-main.zip*",".{0,1000}Reaper\-main\.zip.{0,1000}","offensive_tool_keyword","reaper","Reaper is a proof-of-concept designed to exploit BYOVD (Bring Your Own Vulnerable Driver) driver vulnerability. This malicious technique involves inserting a legitimate - vulnerable driver into a target system - which allows attackers to exploit the driver to perform malicious actions.","T1547.009 - T1215 - T1129 - T1548.002","TA0002 - TA0003 - TA0040 - TA0005","N/A","N/A","Defense Evasion","https://github.com/MrEmpy/Reaper","1","1","N/A","N/A","10","2","158","34","2024-12-07T01:52:58Z","2023-09-21T02:09:48Z","56501" +"*rebootuser/LinEnum*",".{0,1000}rebootuser\/LinEnum.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","56502" +"*rec2_mastodon_x64.exe*",".{0,1000}rec2_mastodon_x64\.exe.{0,1000}","offensive_tool_keyword","REC2 ","REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in Rust.","T1105 - T1132 - T1071.001","TA0011 - TA0009 - TA0002","N/A","N/A","C2","https://github.com/g0h4n/REC2","1","1","N/A","N/A","10","10","153","23","2024-02-22T14:02:24Z","2023-09-25T20:39:59Z","56507" +"*rec2_virustotal_x64.exe*",".{0,1000}rec2_virustotal_x64\.exe.{0,1000}","offensive_tool_keyword","REC2 ","REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in Rust.","T1105 - T1132 - T1071.001","TA0011 - TA0009 - TA0002","N/A","N/A","C2","https://github.com/g0h4n/REC2","1","1","N/A","N/A","10","10","153","23","2024-02-22T14:02:24Z","2023-09-25T20:39:59Z","56508" +"*rec2mastodon.rs*",".{0,1000}rec2mastodon\.rs.{0,1000}","offensive_tool_keyword","REC2 ","REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in Rust.","T1105 - T1132 - T1071.001","TA0011 - TA0009 - TA0002","N/A","N/A","C2","https://github.com/g0h4n/REC2","1","1","N/A","N/A","10","10","153","23","2024-02-22T14:02:24Z","2023-09-25T20:39:59Z","56509" +"*rec2virustotal*",".{0,1000}rec2virustotal.{0,1000}","offensive_tool_keyword","REC2 ","REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in Rust.","T1105 - T1132 - T1071.001","TA0011 - TA0009 - TA0002","N/A","N/A","C2","https://github.com/g0h4n/REC2","1","1","N/A","N/A","10","10","153","23","2024-02-22T14:02:24Z","2023-09-25T20:39:59Z","56510" +"*rec2virustotal.rs*",".{0,1000}rec2virustotal\.rs.{0,1000}","offensive_tool_keyword","REC2 ","REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in Rust.","T1105 - T1132 - T1071.001","TA0011 - TA0009 - TA0002","N/A","N/A","C2","https://github.com/g0h4n/REC2","1","1","N/A","N/A","10","10","153","23","2024-02-22T14:02:24Z","2023-09-25T20:39:59Z","56511" +"*recaptcha-phish-main.zip*",".{0,1000}recaptcha\-phish\-main\.zip.{0,1000}","offensive_tool_keyword","recaptcha-phish","Phishing with a fake reCAPTCHA","T1566.001 - T1204.002 - T1071.003","TA0001 - TA0002","Lumma Stealer","N/A","Phishing","https://github.com/JohnHammond/recaptcha-phish","1","1","N/A","N/A","10","6","534","104","2024-09-13T11:18:29Z","2024-09-13T07:00:40Z","56513" +"*Receive-AgentJob*",".{0,1000}Receive\-AgentJob.{0,1000}","offensive_tool_keyword","empire","empire function name of agent.ps1.Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1054","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","56515" +"*reciclador.cpp*",".{0,1000}reciclador\.cpp.{0,1000}","offensive_tool_keyword","mssqlproxy","mssqlproxy is a toolkit aimed to perform Lateral Movement in restricted environments through a compromised Microsoft SQL Server via socket reuse","T1021.002 - T1071.001 - T1573.002","TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/blackarrowsec/mssqlproxy","1","1","N/A","N/A","10","8","741","114","2021-02-16T20:13:04Z","2020-02-12T08:44:28Z","56519" +"*reciclador.dll*",".{0,1000}reciclador\.dll.{0,1000}","offensive_tool_keyword","mssqlproxy","mssqlproxy is a toolkit aimed to perform Lateral Movement in restricted environments through a compromised Microsoft SQL Server via socket reuse","T1021.002 - T1071.001 - T1573.002","TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/blackarrowsec/mssqlproxy","1","1","N/A","N/A","10","8","741","114","2021-02-16T20:13:04Z","2020-02-12T08:44:28Z","56520" +"*reciclador.vcxproj*",".{0,1000}reciclador\.vcxproj.{0,1000}","offensive_tool_keyword","mssqlproxy","mssqlproxy is a toolkit aimed to perform Lateral Movement in restricted environments through a compromised Microsoft SQL Server via socket reuse","T1021.002 - T1071.001 - T1573.002","TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/blackarrowsec/mssqlproxy","1","1","N/A","N/A","10","8","741","114","2021-02-16T20:13:04Z","2020-02-12T08:44:28Z","56521" +"*recon_passive.rb*",".{0,1000}recon_passive\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","56522" +"*Recon-AD-*.dll*",".{0,1000}Recon\-AD\-.{0,1000}\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Recon-AD an AD recon tool based on ADSI and reflective DLL s","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","10","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","56523" +"*Recon-AD-*.sln*",".{0,1000}Recon\-AD\-.{0,1000}\.sln.{0,1000}","offensive_tool_keyword","cobaltstrike","Recon-AD an AD recon tool based on ADSI and reflective DLL s","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","10","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","56524" +"*Recon-AD-*.vcxproj*",".{0,1000}Recon\-AD\-.{0,1000}\.vcxproj.{0,1000}","offensive_tool_keyword","cobaltstrike","Recon-AD an AD recon tool based on ADSI and reflective DLL s","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","10","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","56525" +"*Recon-AD-AllLocalGroups*",".{0,1000}Recon\-AD\-AllLocalGroups.{0,1000}","offensive_tool_keyword","cobaltstrike","Recon-AD an AD recon tool based on ADSI and reflective DLL s","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","10","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","56526" +"*Recon-AD-Domain*",".{0,1000}Recon\-AD\-Domain.{0,1000}","offensive_tool_keyword","cobaltstrike","Recon-AD an AD recon tool based on ADSI and reflective DLL s","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","10","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","56528" +"*Recon-AD-LocalGroups*",".{0,1000}Recon\-AD\-LocalGroups.{0,1000}","offensive_tool_keyword","cobaltstrike","Recon-AD an AD recon tool based on ADSI and reflective DLL s","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","10","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","56530" +"*Recon-AD-SPNs*",".{0,1000}Recon\-AD\-SPNs.{0,1000}","offensive_tool_keyword","cobaltstrike","Recon-AD an AD recon tool based on ADSI and reflective DLL s","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","10","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","56531" +"*Recon-AD-Users.*",".{0,1000}Recon\-AD\-Users\..{0,1000}","offensive_tool_keyword","cobaltstrike","Recon-AD an AD recon tool based on ADSI and reflective DLL s","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Recon-AD","1","1","N/A","N/A","10","4","326","55","2019-10-20T21:49:39Z","2019-10-20T21:09:41Z","56533" +"*ReconUserGroupRoles.ps1*",".{0,1000}ReconUserGroupRoles\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","56538" +"*RecycledInjector.exe*",".{0,1000}RecycledInjector\.exe.{0,1000}","offensive_tool_keyword","RecycledInjector","Native Syscalls Shellcode Injector","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/florylsk/RecycledInjector","1","1","N/A","N/A","N/A","3","266","43","2023-07-02T11:04:28Z","2023-06-23T16:14:56Z","56539" +"*RecycledInjector-main*",".{0,1000}RecycledInjector\-main.{0,1000}","offensive_tool_keyword","RecycledInjector","Native Syscalls Shellcode Injector","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/florylsk/RecycledInjector","1","1","N/A","N/A","N/A","3","266","43","2023-07-02T11:04:28Z","2023-06-23T16:14:56Z","56540" +"*RecycledInjector-main*",".{0,1000}RecycledInjector\-main.{0,1000}","offensive_tool_keyword","RecycledInjector","Native Syscalls Shellcode Injector","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/florylsk/RecycledInjector","1","1","N/A","N/A","N/A","3","266","43","2023-07-02T11:04:28Z","2023-06-23T16:14:56Z","56541" +"*RedByte1337/GraphSpy*",".{0,1000}RedByte1337\/GraphSpy.{0,1000}","offensive_tool_keyword","GraphSpy","Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI","T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656","TA0001 - TA0006 - TA0003 - TA0005 - TA0008","N/A","N/A","Collection","https://github.com/RedByte1337/GraphSpy","1","1","N/A","N/A","10","7","680","72","2025-04-15T21:07:15Z","2024-02-07T19:47:15Z","56544" +"*redelk_backend_name_c2*",".{0,1000}redelk_backend_name_c2.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","56545" +"*redelk_backend_name_decoy*",".{0,1000}redelk_backend_name_decoy.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","56546" +"*RedGuard.log*",".{0,1000}RedGuard\.log.{0,1000}","offensive_tool_keyword","RedGuard","RedGuard is a C2 front flow control tool.Can avoid Blue Teams.AVs.EDRs check.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/wikiZ/RedGuard","1","1","#logfile","N/A","10","10","1466","204","2024-08-20T17:43:35Z","2022-05-08T04:02:33Z","56547" +"*RedGuard_x64.exe*",".{0,1000}RedGuard_x64\.exe.{0,1000}","offensive_tool_keyword","RedGuard","RedGuard is a C2 front flow control tool.Can avoid Blue Teams.AVs.EDRs check.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/wikiZ/RedGuard","1","1","N/A","N/A","10","10","1466","204","2024-08-20T17:43:35Z","2022-05-08T04:02:33Z","56549" +"*RedGuard_x86.exe*",".{0,1000}RedGuard_x86\.exe.{0,1000}","offensive_tool_keyword","RedGuard","RedGuard is a C2 front flow control tool.Can avoid Blue Teams.AVs.EDRs check.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","FIN7 - APT19 - menuPass - Threat Group-3390 - FIN6 - APT37 - Wizard Spider - TA505 - Cobalt Group - DarkHydrus - APT41 - Mustang Panda - Earth Lusca - APT29 - LuminousMoth - APT32 - Chimera - Leviathan - CopyKittens - Aquatic Panda - Indrik Spider","C2","https://github.com/wikiZ/RedGuard","1","1","N/A","N/A","10","10","1466","204","2024-08-20T17:43:35Z","2022-05-08T04:02:33Z","56550" +"*redhuntlabs/BucketLoot*",".{0,1000}redhuntlabs\/BucketLoot.{0,1000}","offensive_tool_keyword","BucketLoot","BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets- flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain-text","T1562.007 - T1119 - T1530","TA0006 - TA0010","N/A","N/A","Discovery","https://github.com/redhuntlabs/BucketLoot","1","1","N/A","N/A","7","5","409","58","2025-01-22T10:48:27Z","2023-07-17T09:06:14Z","56551" +"*RedHunt-OS*",".{0,1000}RedHunt\-OS.{0,1000}","offensive_tool_keyword","RedHunt-OS","Virtual Machine for Adversary Emulation and Threat Hunting by RedHunt Labs RedHunt OS aims to be a one stop shop for all your threat emulation and threat hunting needs by integrating attackers arsenal as well as defenders toolkit to actively identify the threats in your environment","T1583 - T1057 - T1016","TA0002 - TA0003 - TA0007","N/A","N/A","Exploitation tool","https://github.com/redhuntlabs/RedHunt-OS","1","1","N/A","N/A","N/A","10","1268","199","2025-01-22T10:50:09Z","2018-03-14T19:31:16Z","56552" +"*redlotus.efi*",".{0,1000}redlotus\.efi.{0,1000}","offensive_tool_keyword","bootkit-rs","Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus)","T1542.004 - T1067.002 - T1012 - T1053.005 - T1057","TA0002 - TA0040 - TA0003 - TA0001","N/A","N/A","Defense Evasion","https://github.com/memN0ps/bootkit-rs","1","1","N/A","N/A","N/A","6","528","67","2023-09-12T07:23:15Z","2023-04-11T03:53:15Z","56556" +"*redpeanut.pfx*",".{0,1000}redpeanut\.pfx.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56559" +"*RedPeanut.Resources.*.txt",".{0,1000}RedPeanut\.Resources\..{0,1000}\.txt","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56560" +"*RedPeanutAgent.C2*",".{0,1000}RedPeanutAgent\.C2.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56562" +"*RedPeanutAgent.Core*",".{0,1000}RedPeanutAgent\.Core.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56563" +"*RedPeanutAgent.cs*",".{0,1000}RedPeanutAgent\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56564" +"*RedPeanutAgent.Evasion*",".{0,1000}RedPeanutAgent\.Evasion.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56565" +"*RedPeanutAgent.Execution*",".{0,1000}RedPeanutAgent\.Execution.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56566" +"*RedPeanutAgent.Program*",".{0,1000}RedPeanutAgent\.Program.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56567" +"*RedPeanutC2*",".{0,1000}RedPeanutC2.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56568" +"*RedPeanutHtaPowerShellScript*",".{0,1000}RedPeanutHtaPowerShellScript.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56572" +"*RedPeanutHtaScript.hta*",".{0,1000}RedPeanutHtaScript\.hta.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56573" +"*RedPeanutInstallUtil.cs*",".{0,1000}RedPeanutInstallUtil\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56574" +"*RedPeanutManager.cs*",".{0,1000}RedPeanutManager\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56575" +"*RedPeanutMigrate.cs*",".{0,1000}RedPeanutMigrate\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56576" +"*RedPeanutMSBuildScript.xml*",".{0,1000}RedPeanutMSBuildScript\.xml.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56577" +"*RedPeanutPowershellScriptS*",".{0,1000}RedPeanutPowershellScriptS.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56578" +"*RedPeanutRP.cs*",".{0,1000}RedPeanutRP\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56579" +"*RedPeanutShooter.*",".{0,1000}RedPeanutShooter\..{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56580" +"*RedPeanutSpawn.cs*",".{0,1000}RedPeanutSpawn\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56581" +"*RedPeanutSpawnTikiTorch.cs*",".{0,1000}RedPeanutSpawnTikiTorch\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56582" +"*RedPeanutVBAMacro.vba*",".{0,1000}RedPeanutVBAMacro\.vba.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","56583" +"*RedSiege/CIMplant*",".{0,1000}RedSiege\/CIMplant.{0,1000}","offensive_tool_keyword","CIMplant","C# port of WMImplant which uses either CIM or WMI to query remote systems","T1047 - T1059.001 - T1021.006","TA0002 - TA0007 - TA0008","N/A","Scattered Spider*","Lateral Movement","https://github.com/RedSiege/CIMplant","1","1","N/A","N/A","10","2","199","29","2021-07-14T18:18:42Z","2021-01-29T21:41:58Z","56584" +"*RedSiege/GraphStrike*",".{0,1000}RedSiege\/GraphStrike.{0,1000}","offensive_tool_keyword","GraphStrike","Cobalt Strike HTTPS beaconing over Microsoft Graph API","T1102 - T1071.001 ","TA0002 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/RedSiege/GraphStrike","1","1","N/A","N/A","10","10","585","95","2024-06-25T11:18:19Z","2024-01-02T00:18:44Z","56585" +"*redskal/SharpAzbelt*",".{0,1000}redskal\/SharpAzbelt.{0,1000}","offensive_tool_keyword","SharpAzbelt","This is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resources","T1082 - T1003 - T1027 - T1110 - T1078","TA0006 - TA0007 - TA0005 - TA0004 - TA0003","N/A","N/A","Discovery","https://github.com/redskal/SharpAzbelt","1","1","N/A","N/A","8","1","26","7","2023-09-21T21:47:32Z","2023-09-21T21:44:03Z","56586" +"*Red-Team-Infrastructure-Wiki.*",".{0,1000}Red\-Team\-Infrastructure\-Wiki\..{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","56588" +"*Red-Teaming-Toolkit*",".{0,1000}Red\-Teaming\-Toolkit.{0,1000}","offensive_tool_keyword","Red-Teaming-Toolkit","A collection of open source and commercial tools that aid in red team operations. This repository will help you during red team engagement. If you want to contribute to this list send me a pull request","T1210 - T1211 - T1212 - T1547","TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/infosecn1nja/Red-Teaming-Toolkit","1","1","N/A","N/A","N/A","10","9454","2251","2025-04-14T02:23:20Z","2018-04-26T13:35:09Z","56589" +"*RedTeamPentesting/kbtls*",".{0,1000}RedTeamPentesting\/kbtls.{0,1000}","offensive_tool_keyword","resocks","resocks is a reverse/back-connect SOCKS5 proxy tunnel that can be used to route traffic through a system that can't be directly accessed","T1090.003 - T1090 - T1571","TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/RedTeamPentesting/resocks","1","1","N/A","N/A","8","10","437","33","2023-09-19T10:43:29Z","2023-05-02T08:42:15Z","56590" +"*RedTeamPentesting/pretender*",".{0,1000}RedTeamPentesting\/pretender.{0,1000}","offensive_tool_keyword","pretender","MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS - LLMNR and NetBIOS-NS spoofing","T1557 - T1046 - T1590 - T1557.002","TA0008 - TA0011 - TA0007 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/RedTeamPentesting/pretender","1","1","N/A","N/A","7","10","1089","79","2025-02-19T08:14:57Z","2022-07-11T13:23:23Z","56591" +"*RedTeamPentesting/resocks*",".{0,1000}RedTeamPentesting\/resocks.{0,1000}","offensive_tool_keyword","resocks","resocks is a reverse/back-connect SOCKS5 proxy tunnel that can be used to route traffic through a system that can't be directly accessed","T1090.003 - T1090 - T1571","TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/RedTeamPentesting/resocks","1","1","N/A","N/A","8","10","437","33","2023-09-19T10:43:29Z","2023-05-02T08:42:15Z","56592" +"*RedWarden.py*",".{0,1000}RedWarden\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","56593" +"*RedWarden.test*",".{0,1000}RedWarden\.test.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","N/A","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","56594" +"*redwarden_access.log*",".{0,1000}redwarden_access\.log.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","#logfile","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","56595" +"*redwarden_redirector.log*",".{0,1000}redwarden_redirector\.log.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike C2 Reverse proxy that fends off Blue Teams. AVs. EDRs. scanners through packet inspection and malleable profile correlation","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mgeeky/RedWarden","1","1","#logfile","N/A","10","10","964","143","2022-10-07T14:05:25Z","2021-05-15T22:05:39Z","56596" +"*reflct_dll_inject.exe*",".{0,1000}reflct_dll_inject\.exe.{0,1000}","offensive_tool_keyword","darkarmour","Store and execute an encrypted windows binary from inside memorywithout a single bit touching disk.","T1055.012 - T1027 - T1564.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/bats3c/darkarmour","1","1","N/A","N/A","10","8","773","122","2020-04-13T10:56:23Z","2020-04-06T20:48:20Z","56600" +"*reflective_assembly_minified.ps1*",".{0,1000}reflective_assembly_minified\.ps1.{0,1000}","offensive_tool_keyword","CSExec","An alternative to *exec.py from impacket with some builtin tricks","T1059.001 - T1059.005 - T1071.001","TA0002","N/A","N/A","Lateral Movement","https://github.com/Metro-Holografix/CSExec.py","1","1","N/A","private github repo","10","","N/A","","","","56601" +"*reflective_dll.dll*",".{0,1000}reflective_dll\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","56602" +"*reflective_dll.dll*",".{0,1000}reflective_dll\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","56603" +"*reflective_dll.x64.dll*",".{0,1000}reflective_dll\.x64\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","reflective module for HackBrowserData","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/idiotc4t/Reflective-HackBrowserData","1","1","N/A","N/A","10","10","175","25","2021-03-13T08:42:18Z","2021-03-13T08:35:01Z","56604" +"*reflective_dll.x64.dll*",".{0,1000}reflective_dll\.x64\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","56605" +"*reflective_dll_inject*",".{0,1000}reflective_dll_inject.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","56606" +"*reflective_pe_loader.*",".{0,1000}reflective_pe_loader\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","56607" +"*ReflectiveDll.*",".{0,1000}ReflectiveDll\..{0,1000}","offensive_tool_keyword","C2-Tool-Collection","A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques","T1055 - T1218 - T1059 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","C2","https://github.com/outflanknl/C2-Tool-Collection","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","56608" +"*ReflectiveDll.x64.dll*",".{0,1000}ReflectiveDll\.x64\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Example code for using named pipe output with beacon ReflectiveDLLs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rxwx/cs-rdll-ipc-example","1","1","N/A","N/A","10","10","116","23","2020-06-24T19:47:35Z","2020-06-24T19:43:56Z","56609" +"*ReflectiveDll.x86.dll*",".{0,1000}ReflectiveDll\.x86\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Example code for using named pipe output with beacon ReflectiveDLLs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rxwx/cs-rdll-ipc-example","1","1","N/A","N/A","10","10","116","23","2020-06-24T19:47:35Z","2020-06-24T19:43:56Z","56610" +"*ReflectiveDLLInjection*",".{0,1000}ReflectiveDLLInjection.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","56611" +"*ReflectiveDLLInjection.*",".{0,1000}ReflectiveDLLInjection\..{0,1000}","offensive_tool_keyword","C2-Tool-Collection","A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques","T1055 - T1218 - T1059 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","C2","https://github.com/outflanknl/C2-Tool-Collection","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","56612" +"*ReflectiveDLLInjection.*",".{0,1000}ReflectiveDLLInjection\..{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","56613" +"*ReflectiveDLLInjection.*",".{0,1000}ReflectiveDLLInjection\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","56614" +"*ReflectiveDllInjection.*",".{0,1000}ReflectiveDllInjection\..{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","56615" +"*Reflective-HackBrowserData*",".{0,1000}Reflective\-HackBrowserData.{0,1000}","offensive_tool_keyword","cobaltstrike","reflective module for HackBrowserData","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/idiotc4t/Reflective-HackBrowserData","1","1","N/A","N/A","10","10","175","25","2021-03-13T08:42:18Z","2021-03-13T08:35:01Z","56618" +"*Reflective-HackBrowserData*",".{0,1000}Reflective\-HackBrowserData.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555 - T1189 - T1217 - T1185","TA0002 - TA0009 - TA0001 - TA0010","N/A","N/A","Exploitation tool","https://github.com/moonD4rk/HackBrowserData","1","1","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","56619" +"*ReflectiveLoader.*",".{0,1000}ReflectiveLoader\..{0,1000}","offensive_tool_keyword","C2-Tool-Collection","A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques","T1055 - T1218 - T1059 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","C2","https://github.com/outflanknl/C2-Tool-Collection","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","56620" +"*ReflectiveLoader.c*",".{0,1000}ReflectiveLoader\.c.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","56621" +"*ReflectiveLoader.c*",".{0,1000}ReflectiveLoader\.c.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","56622" +"*ReflectiveLoader.cpp*",".{0,1000}ReflectiveLoader\.cpp.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","56624" +"*ReflectiveLoader.h*",".{0,1000}ReflectiveLoader\.h.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","56625" +"*ReflectiveNTDLL.cpp*",".{0,1000}ReflectiveNTDLL\.cpp.{0,1000}","offensive_tool_keyword","NTDLLReflection","Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll and trigger exported APIs from the export table","T1055.012 - T1574.002 - T1027.001 - T1218.011","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/NTDLLReflection","1","1","N/A","N/A","9","3","293","45","2023-08-02T02:21:43Z","2023-02-03T17:12:33Z","56626" +"*ReflectiveNTDLL.exe*",".{0,1000}ReflectiveNTDLL\.exe.{0,1000}","offensive_tool_keyword","NTDLLReflection","Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll and trigger exported APIs from the export table","T1055.012 - T1574.002 - T1027.001 - T1218.011","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/NTDLLReflection","1","1","N/A","N/A","9","3","293","45","2023-08-02T02:21:43Z","2023-02-03T17:12:33Z","56627" +"*ReflectiveNTDLL.sln*",".{0,1000}ReflectiveNTDLL\.sln.{0,1000}","offensive_tool_keyword","NTDLLReflection","Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll and trigger exported APIs from the export table","T1055.012 - T1574.002 - T1027.001 - T1218.011","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/NTDLLReflection","1","1","N/A","N/A","9","3","293","45","2023-08-02T02:21:43Z","2023-02-03T17:12:33Z","56628" +"*ReflectiveNTDLL.vcxproj*",".{0,1000}ReflectiveNTDLL\.vcxproj.{0,1000}","offensive_tool_keyword","NTDLLReflection","Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll and trigger exported APIs from the export table","T1055.012 - T1574.002 - T1027.001 - T1218.011","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/NTDLLReflection","1","1","N/A","N/A","9","3","293","45","2023-08-02T02:21:43Z","2023-02-03T17:12:33Z","56629" +"*ReflectiveNtdll-main*",".{0,1000}ReflectiveNtdll\-main.{0,1000}","offensive_tool_keyword","ReflectiveNtdll","A Dropper POC with a focus on aiding in EDR evasion - NTDLL Unhooking followed by loading ntdll in-memory which is present as shellcode","T1059 - T1059.003 - T1218.011 - T1027 - T1027.005 - T1070 - T1070.004","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/reveng007/ReflectiveNtdll","1","1","N/A","N/A","10","2","170","24","2023-02-10T05:30:28Z","2023-01-30T08:43:16Z","56630" +"*ReflectivePick_x64_orig.dll*",".{0,1000}ReflectivePick_x64_orig\.dll.{0,1000}","offensive_tool_keyword","empire","Empire dll paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1112","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","56631" +"*ReflectivePick_x86_orig.dll*",".{0,1000}ReflectivePick_x86_orig\.dll.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1113","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","56632" +"*RefleXXion*ntdll.dll*",".{0,1000}RefleXXion.{0,1000}ntdll\.dll.{0,1000}","offensive_tool_keyword","RefleXXion","RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks. it first collects the syscall numbers of the NtOpenFile. NtCreateSection. NtOpenSection and NtMapViewOfSection found in the LdrpThunkSignature array.","T1055.004 - T1562.004 - T1070.004","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/hlldz/RefleXXion","1","1","N/A","N/A","10","5","490","105","2022-01-25T17:06:21Z","2022-01-25T16:50:34Z","56633" +"*RefleXXion.sln*",".{0,1000}RefleXXion\.sln.{0,1000}","offensive_tool_keyword","RefleXXion","RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks. it first collects the syscall numbers of the NtOpenFile. NtCreateSection. NtOpenSection and NtMapViewOfSection found in the LdrpThunkSignature array.","T1055.004 - T1562.004 - T1070.004","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/hlldz/RefleXXion","1","1","N/A","N/A","10","5","490","105","2022-01-25T17:06:21Z","2022-01-25T16:50:34Z","56634" +"*RefleXXion-DLL*",".{0,1000}RefleXXion\-DLL.{0,1000}","offensive_tool_keyword","RefleXXion","RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks. it first collects the syscall numbers of the NtOpenFile. NtCreateSection. NtOpenSection and NtMapViewOfSection found in the LdrpThunkSignature array.","T1055.004 - T1562.004 - T1070.004","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/hlldz/RefleXXion","1","1","N/A","N/A","10","5","490","105","2022-01-25T17:06:21Z","2022-01-25T16:50:34Z","56635" +"*RefleXXion-EXE*",".{0,1000}RefleXXion\-EXE.{0,1000}","offensive_tool_keyword","RefleXXion","RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks. it first collects the syscall numbers of the NtOpenFile. NtCreateSection. NtOpenSection and NtMapViewOfSection found in the LdrpThunkSignature array.","T1055.004 - T1562.004 - T1070.004","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/hlldz/RefleXXion","1","1","N/A","N/A","10","5","490","105","2022-01-25T17:06:21Z","2022-01-25T16:50:34Z","56636" +"*RefleXXion-main*",".{0,1000}RefleXXion\-main.{0,1000}","offensive_tool_keyword","RefleXXion","RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks. it first collects the syscall numbers of the NtOpenFile. NtCreateSection. NtOpenSection and NtMapViewOfSection found in the LdrpThunkSignature array.","T1055.004 - T1562.004 - T1070.004","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/hlldz/RefleXXion","1","1","N/A","N/A","10","5","490","105","2022-01-25T17:06:21Z","2022-01-25T16:50:34Z","56637" +"*reGeorgSocksProxy.py*",".{0,1000}reGeorgSocksProxy\.py.{0,1000}","offensive_tool_keyword","reGeorg","The successor to reDuh - pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.","T1090 - T1095 - T1572","TA0003 - TA0011","N/A","FIN13 - IRIDIUM - UNC3524 - Worok - COZY BEAR - FANCY BEAR - EMBER BEAR - Sandworm","Data Exfiltration","https://github.com/sensepost/reGeorg","1","1","N/A","N/A","N/A","10","3075","826","2025-03-06T09:56:16Z","2014-08-08T00:58:12Z","56886" +"*RegHiveBackup.exe*",".{0,1000}RegHiveBackup\.exe.{0,1000}","offensive_tool_keyword","RegHiveBackup","backup the Registry files on your system into the specified folder","T1012 - T1596 - T1003","TA0006 - TA0009","N/A","N/A","Collection","https://www.nirsoft.net/alpha/reghivebackup.zip","1","1","#registry","N/A","10","10","N/A","N/A","N/A","N/A","56887" +"*Register-MaliciousWmiEvent*",".{0,1000}Register\-MaliciousWmiEvent.{0,1000}","offensive_tool_keyword","Powerlurk","PowerLurk is a PowerShell toolset for building malicious WMI Event Subsriptions","T1084 - T1059.001 - T1546.003 - T1053.005","TA0003 - TA0005 - TA0002 - TA0006","N/A","N/A","Persistence","https://github.com/Sw4mpf0x/PowerLurk","1","1","N/A","N/A","10","4","384","72","2016-07-25T22:19:22Z","2016-07-13T20:07:25Z","56893" +"*Register-SQLC2Agent*",".{0,1000}Register\-SQLC2Agent.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","56895" +"*registry_hijacking_eventvwr*",".{0,1000}registry_hijacking_eventvwr.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","56897" +"*registry_hijacking_fodhelper*",".{0,1000}registry_hijacking_fodhelper.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","56898" +"*RegistryTinker.exe*",".{0,1000}RegistryTinker\.exe.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","56901" +"*RegReeper.7z*",".{0,1000}RegReeper\.7z.{0,1000}","offensive_tool_keyword","regreeper","gain persistence and evade sysmon event code registry (creation update and deletion) REG_NOTIFY_CLASS Registry Callback of sysmon driver filter. RegSaveKeyExW() and RegRestoreKeyW() API which is not included in monitoring.","T1050.005 - T1012 - T1112 - T1553.002 - T1053.005","TA0005 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/tccontre/Reg-Restore-Persistence-Mole","1","1","N/A","N/A","10","1","51","16","2023-08-23T11:34:26Z","2023-08-03T14:47:45Z","56902" +"*RegReeper.cpp*",".{0,1000}RegReeper\.cpp.{0,1000}","offensive_tool_keyword","regreeper","gain persistence and evade sysmon event code registry (creation update and deletion) REG_NOTIFY_CLASS Registry Callback of sysmon driver filter. RegSaveKeyExW() and RegRestoreKeyW() API which is not included in monitoring.","T1050.005 - T1012 - T1112 - T1553.002 - T1053.005","TA0005 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/tccontre/Reg-Restore-Persistence-Mole","1","1","N/A","N/A","10","1","51","16","2023-08-23T11:34:26Z","2023-08-03T14:47:45Z","56903" +"*RegReeper.exe*",".{0,1000}RegReeper\.exe.{0,1000}","offensive_tool_keyword","regreeper","gain persistence and evade sysmon event code registry (creation update and deletion) REG_NOTIFY_CLASS Registry Callback of sysmon driver filter. RegSaveKeyExW() and RegRestoreKeyW() API which is not included in monitoring.","T1050.005 - T1012 - T1112 - T1553.002 - T1053.005","TA0005 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/tccontre/Reg-Restore-Persistence-Mole","1","1","N/A","N/A","10","1","51","16","2023-08-23T11:34:26Z","2023-08-03T14:47:45Z","56904" +"*RegReeper.sln*",".{0,1000}RegReeper\.sln.{0,1000}","offensive_tool_keyword","regreeper","gain persistence and evade sysmon event code registry (creation update and deletion) REG_NOTIFY_CLASS Registry Callback of sysmon driver filter. RegSaveKeyExW() and RegRestoreKeyW() API which is not included in monitoring.","T1050.005 - T1012 - T1112 - T1553.002 - T1053.005","TA0005 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/tccontre/Reg-Restore-Persistence-Mole","1","1","N/A","N/A","10","1","51","16","2023-08-23T11:34:26Z","2023-08-03T14:47:45Z","56905" +"*RegReeper.vcxproj*",".{0,1000}RegReeper\.vcxproj.{0,1000}","offensive_tool_keyword","regreeper","gain persistence and evade sysmon event code registry (creation update and deletion) REG_NOTIFY_CLASS Registry Callback of sysmon driver filter. RegSaveKeyExW() and RegRestoreKeyW() API which is not included in monitoring.","T1050.005 - T1012 - T1112 - T1553.002 - T1053.005","TA0005 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/tccontre/Reg-Restore-Persistence-Mole","1","1","N/A","N/A","10","1","51","16","2023-08-23T11:34:26Z","2023-08-03T14:47:45Z","56906" +"*Reg-Restore-Persistence-Mole-main*",".{0,1000}Reg\-Restore\-Persistence\-Mole\-main.{0,1000}","offensive_tool_keyword","regreeper","gain persistence and evade sysmon event code registry (creation update and deletion) REG_NOTIFY_CLASS Registry Callback of sysmon driver filter. RegSaveKeyExW() and RegRestoreKeyW() API which is not included in monitoring.","T1050.005 - T1012 - T1112 - T1553.002 - T1053.005","TA0005 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/tccontre/Reg-Restore-Persistence-Mole","1","1","N/A","N/A","10","1","51","16","2023-08-23T11:34:26Z","2023-08-03T14:47:45Z","56907" +"*regsvr32_command_delivery_server*",".{0,1000}regsvr32_command_delivery_server.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","56914" +"*reinstall_original_pw.py*",".{0,1000}reinstall_original_pw\.py.{0,1000}","offensive_tool_keyword","POC","Zerologon CVE exploitation","T1210 - T1068","TA0001","N/A","N/A","Exploitation tool","https://github.com/risksense/zerologon","1","1","N/A","N/A","N/A","7","657","146","2020-10-15T18:31:15Z","2020-09-14T19:19:07Z","56915" +"*rekallreader.py*",".{0,1000}rekallreader\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","56916" +"*relay*/utils/enum.py*",".{0,1000}relay.{0,1000}\/utils\/enum\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","56918" +"*RelayPackets.py*",".{0,1000}RelayPackets\.py.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","N/A","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","56920" +"*Release.Lime-Crypter.v0.5.1.exe.zip*",".{0,1000}Release\.Lime\-Crypter\.v0\.5\.1\.exe\.zip.{0,1000}","offensive_tool_keyword","Lime-Crypter","An obfuscation tool for .Net + Native files","T1027 - T1045","TA0005 ","N/A","N/A","Defense Evasion","https://github.com/NYAN-x-CAT/Lime-Crypter","1","1","N/A","N/A","9","6","515","199","2024-04-22T21:31:18Z","2018-07-14T13:44:58Z","56923" +"*release/chaserv*",".{0,1000}release\/chaserv.{0,1000}","offensive_tool_keyword","chashell","Chashell is a Go reverse shell that communicates over DNS. It can be used to bypass firewalls or tightly restricted networks","T1071.004 - T1572 - T1071 - T1027","TA0011 - TA0005 - TA0008","N/A","PYSA","C2","https://github.com/sysdream/chashell","1","1","N/A","N/A","10","10","1068","135","2022-04-05T17:22:14Z","2019-02-15T14:54:48Z","56924" +"*release/chashell_*",".{0,1000}release\/chashell_.{0,1000}","offensive_tool_keyword","chashell","Chashell is a Go reverse shell that communicates over DNS. It can be used to bypass firewalls or tightly restricted networks","T1071.004 - T1572 - T1071 - T1027","TA0011 - TA0005 - TA0008","N/A","PYSA","C2","https://github.com/sysdream/chashell","1","1","N/A","N/A","10","10","1068","135","2022-04-05T17:22:14Z","2019-02-15T14:54:48Z","56925" +"*Release/S-inject.exe*",".{0,1000}Release\/S\-inject\.exe.{0,1000}","offensive_tool_keyword","S-inject","Windows injection of x86/x64 DLL and Shellcode","T1055 - T1027","TA0002 - TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/Joe1sn/S-inject","1","1","N/A","N/A","10","4","313","45","2025-04-06T08:06:39Z","2024-02-05T04:39:10Z","56927" +"*ReleaseKeePass.exe*",".{0,1000}ReleaseKeePass\.exe.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","56928" +"*ReleaseKeePass.exe*",".{0,1000}ReleaseKeePass\.exe.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","56929" +"*ReleaseKeeTheft.exe*",".{0,1000}ReleaseKeeTheft\.exe.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","56930" +"*Remote/lastpass/lastpass.x86.*",".{0,1000}Remote\/lastpass\/lastpass\.x86\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","56992" +"*Remote/setuserpass/*",".{0,1000}Remote\/setuserpass\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","56993" +"*Remote/shspawnas*",".{0,1000}Remote\/shspawnas.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","56994" +"*Remote/suspendresume/*",".{0,1000}Remote\/suspendresume\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","56995" +"*remote_exploit.erb*",".{0,1000}remote_exploit\.erb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","56996" +"*remote_exploit_cmd_stager.*",".{0,1000}remote_exploit_cmd_stager\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","56997" +"*remote_exploit_demo_template.erb*",".{0,1000}remote_exploit_demo_template\.erb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","56998" +"*remote_shell.py*",".{0,1000}remote_shell\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","57000" +"*RemoteHashRetrieval.ps1*",".{0,1000}RemoteHashRetrieval\.ps1.{0,1000}","offensive_tool_keyword","DAMP","The Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification.","T1222 - T1222.002 - T1548 - T1548.002","TA0005 ","N/A","N/A","Persistence","https://github.com/HarmJ0y/DAMP","1","1","N/A","N/A","10","4","378","79","2019-07-25T21:18:37Z","2018-04-06T22:13:58Z","57019" +"*RemoteKrbRelay.exe*",".{0,1000}RemoteKrbRelay\.exe.{0,1000}","offensive_tool_keyword","RemoteKrbRelay","similar to KrbRelay and KrbRelayUp but With RemoteKrbRelay this can be done remotely","T1550.004 - T1557.001 - T1021.005 - T1105","TA0008 - TA0005","N/A","N/A","Lateral Movement","https://github.com/CICADA8-Research/RemoteKrbRelay","1","1","N/A","N/A","10","6","581","90","2024-06-30T14:08:50Z","2024-06-24T17:38:46Z","57025" +"*remote-method-guesser/rmg*",".{0,1000}remote\-method\-guesser\/rmg.{0,1000}","offensive_tool_keyword","remote-method-guesser","remote-method-guesser?(rmg) is a?Java RMI?vulnerability scanner and can be used to identify and verify common security vulnerabilities on?Java RMI?endpoints.","T1210.002 - T1046 - T1078.003","TA0001 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/qtc-de/remote-method-guesser","1","1","N/A","N/A","6","9","860","108","2024-07-03T19:40:54Z","2019-11-04T11:37:38Z","57026" +"*remote-method-guesser-master*",".{0,1000}remote\-method\-guesser\-master.{0,1000}","offensive_tool_keyword","remote-method-guesser","remote-method-guesser?(rmg) is a?Java RMI?vulnerability scanner and can be used to identify and verify common security vulnerabilities on?Java RMI?endpoints.","T1210.002 - T1046 - T1078.003","TA0001 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/qtc-de/remote-method-guesser","1","1","N/A","N/A","6","9","860","108","2024-07-03T19:40:54Z","2019-11-04T11:37:38Z","57027" +"*RemoteNTDLL.cpp*",".{0,1000}RemoteNTDLL\.cpp.{0,1000}","offensive_tool_keyword","ntdlll-unhooking-collection","unhooking ntdll from disk - from KnownDlls - from suspended process - from remote server (fileless)","T1055 - T1055.001 - T1070 - T1070.004 - T1101 - T1574 - T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/ntdlll-unhooking-collection","1","1","N/A","N/A","9","2","188","38","2023-08-02T02:26:33Z","2023-02-07T16:54:15Z","57028" +"*RemoteNTDLL.exe*",".{0,1000}RemoteNTDLL\.exe.{0,1000}","offensive_tool_keyword","ntdlll-unhooking-collection","unhooking ntdll from disk - from KnownDlls - from suspended process - from remote server (fileless)","T1055 - T1055.001 - T1070 - T1070.004 - T1101 - T1574 - T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/ntdlll-unhooking-collection","1","1","N/A","N/A","9","2","188","38","2023-08-02T02:26:33Z","2023-02-07T16:54:15Z","57029" +"*RemotePipeList.cna*",".{0,1000}RemotePipeList\.cna.{0,1000}","offensive_tool_keyword","RemotePipeList","A small tool that can list the named pipes bound on a remote system.","T1047 - T1021.006","TA0008 - TA0002","N/A","N/A","Discovery","https://github.com/outflanknl/C2-Tool-Collection/tree/main/Other/RemotePipeList","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","57061" +"*RemotePipeList.exe*",".{0,1000}RemotePipeList\.exe.{0,1000}","offensive_tool_keyword","RemotePipeList","A small tool that can list the named pipes bound on a remote system.","T1047 - T1021.006","TA0008 - TA0002","N/A","N/A","Discovery","https://github.com/outflanknl/C2-Tool-Collection/tree/main/Other/RemotePipeList","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","57062" +"*RemotePotato0.exe*",".{0,1000}RemotePotato0\.exe.{0,1000}","offensive_tool_keyword","RemotePotato0","Windows Privilege Escalation from User to Domain Admin.","T1078.002 - T1078.003 - T1078.004","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RemotePotato0","1","1","N/A","N/A","10","10","1382","215","2022-12-18T01:52:53Z","2021-02-08T22:02:19Z","57064" +"*remotereg.cna*",".{0,1000}remotereg\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of CobaltStrike beacon object files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/pwn1sher/CS-BOFs","1","1","N/A","N/A","10","10","103","22","2022-02-14T09:47:30Z","2021-01-18T08:54:48Z","57065" +"*RemoteShellCodeInjection-master.zip*",".{0,1000}RemoteShellCodeInjection\-master\.zip.{0,1000}","offensive_tool_keyword","WebSocketReverseShellDotNet","A .NET-based Reverse Shell, it establishes a link to the command and control for subsequent guidance.","T1071 - T1105","TA0011 - TA0002","N/A","N/A","C2","https://github.com/The-Hustler-Hattab/WebSocketReverseShellDotNet","1","1","N/A","N/A","10","10","1","0","2024-04-18T01:00:48Z","2023-12-03T03:35:24Z","57068" +"*remotewinenum.rb*",".{0,1000}remotewinenum\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","57069" +"*RemovalofAnti-PhishingServices.reg*",".{0,1000}RemovalofAnti\-PhishingServices\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","57070" +"*RemovalofWindowsDefenderAntivirus.reg*",".{0,1000}RemovalofWindowsDefenderAntivirus\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","57071" +"*Remove_SecurityComp.reg*",".{0,1000}Remove_SecurityComp\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","57073" +"*RemoveDefenderTasks.reg*",".{0,1000}RemoveDefenderTasks\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","57085" +"*removeexe-persistence*",".{0,1000}removeexe\-persistence.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","57086" +"*Remove-KeePassConfigTrigger*",".{0,1000}Remove\-KeePassConfigTrigger.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","57100" +"*RemoveKeePassTrigger.ps1*",".{0,1000}RemoveKeePassTrigger\.ps1.{0,1000}","offensive_tool_keyword","crackmapexec","Keepass exploitations from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","57101" +"*RemoveKeePassTrigger.ps1*",".{0,1000}RemoveKeePassTrigger\.ps1.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","57102" +"*remove-persistence*",".{0,1000}remove\-persistence.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","57105" +"*Remove-Persistence.ps1*",".{0,1000}Remove\-Persistence\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","57106" +"*Remove-Persistence.ps1*",".{0,1000}Remove\-Persistence\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","57107" +"*remove-persistence-cron*",".{0,1000}remove\-persistence\-cron.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","57108" +"*Remove-PoshRat*",".{0,1000}Remove\-PoshRat.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","57109" +"*Remove-PoshRat.ps1*",".{0,1000}Remove\-PoshRat\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","57110" +"*removeRegTrace*",".{0,1000}removeRegTrace.{0,1000}","offensive_tool_keyword","AoratosWin","A tool that removes traces of executed applications on Windows OS.","T1070 - T1564","TA0005 - TA0011","N/A","N/A","Defense Evasion","https://github.com/PinoyWH1Z/AoratosWin","1","1","N/A","N/A","N/A","2","120","16","2022-09-04T09:15:35Z","2022-09-04T09:04:35Z","57111" +"*RemoverofDefenderContextMenu.reg*",".{0,1000}RemoverofDefenderContextMenu\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","57112" +"*RemoveSecHealthApp.ps1*",".{0,1000}RemoveSecHealthApp\.ps1.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","57113" +"*RemoveSecurityandMaintenance.reg*",".{0,1000}RemoveSecurityandMaintenance\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","57114" +"*RemoveShellAssociation.reg*",".{0,1000}RemoveShellAssociation\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","57115" +"*RemoveSignatureUpdates.reg*",".{0,1000}RemoveSignatureUpdates\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","57116" +"*Remove-SQLC2Agent*",".{0,1000}Remove\-SQLC2Agent.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","57117" +"*Remove-SQLC2Command*",".{0,1000}Remove\-SQLC2Command.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","57118" +"*Remove-Update.ps1*",".{0,1000}Remove\-Update\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","57120" +"*RemoveWindowsDefenderFirewallRules.reg*",".{0,1000}RemoveWindowsDefenderFirewallRules\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","57122" +"*RemoveWindowsWebThreat.reg*",".{0,1000}RemoveWindowsWebThreat\.reg.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","57123" +"*replace_key_iv_shellcode*",".{0,1000}replace_key_iv_shellcode.{0,1000}","offensive_tool_keyword","cobaltstrike","A protective and Low Level Shellcode Loader that defeats modern EDR systems.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/cribdragg3r/Alaris","1","1","N/A","N/A","10","10","903","142","2024-03-20T15:50:57Z","2020-02-22T15:42:37Z","57135" +"*replace_video_fake_plugin*",".{0,1000}replace_video_fake_plugin.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","57136" +"*repository.su/blackarch/*/os/*",".{0,1000}repository\.su\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","57138" +"*RePRGM/Nimperiments*",".{0,1000}RePRGM\/Nimperiments.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","57139" +"*RequestAsPython-PowerShell.py*",".{0,1000}RequestAsPython\-PowerShell\.py.{0,1000}","offensive_tool_keyword","burpsuite","A collection of scripts to extend Burp Suite. the request gets transformed to its equivalent in Python requests. Python urllib2. and PowerShell Invoke-WebRequest.","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Discovery","https://github.com/laconicwolf/burp-extensions","1","1","N/A","network exploitation tool","N/A","2","142","31","2019-04-08T00:49:45Z","2018-03-23T16:05:01Z","57141" +"*reshacker_setup.exe*",".{0,1000}reshacker_setup\.exe.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","57157" +"*resocks/proxyrelay*",".{0,1000}resocks\/proxyrelay.{0,1000}","offensive_tool_keyword","resocks","resocks is a reverse/back-connect SOCKS5 proxy tunnel that can be used to route traffic through a system that can't be directly accessed","T1090.003 - T1090 - T1571","TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/RedTeamPentesting/resocks","1","1","N/A","N/A","8","10","437","33","2023-09-19T10:43:29Z","2023-05-02T08:42:15Z","57160" +"*resocks_Windows_x86_64.zip*",".{0,1000}resocks_Windows_x86_64\.zip.{0,1000}","offensive_tool_keyword","resocks","resocks is a reverse/back-connect SOCKS5 proxy tunnel that can be used to route traffic through a system that can't be directly accessed","T1090.003 - T1090 - T1571","TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/RedTeamPentesting/resocks","1","1","N/A","N/A","8","10","437","33","2023-09-19T10:43:29Z","2023-05-02T08:42:15Z","57161" +"*ResourceDevelopment_EstablishAccounts_RGPerson.py*",".{0,1000}ResourceDevelopment_EstablishAccounts_RGPerson\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","57164" +"*ResourceDevelopment_Server_DNSLog.py*",".{0,1000}ResourceDevelopment_Server_DNSLog\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","57165" +"*ResourceDevelopment_Server_LDAPServer.py*",".{0,1000}ResourceDevelopment_Server_LDAPServer\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","57166" +"*ResourceDevelopment_WebServices_TencentAPIGateway.py*",".{0,1000}ResourceDevelopment_WebServices_TencentAPIGateway\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","57167" +"*Resources/Design/NinjaStyle.ps1*",".{0,1000}Resources\/Design\/NinjaStyle\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","57168" +"*Resources/drone.dll*",".{0,1000}Resources\/drone\.dll.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","57169" +"*Responder.py*",".{0,1000}Responder\.py.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","N/A","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","57175" +"*Responder/tools/MultiRelay/bin/Runas.exe*",".{0,1000}Responder\/tools\/MultiRelay\/bin\/Runas\.exe.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","57176" +"*Responder/tools/MultiRelay/bin/Syssvc.exe*",".{0,1000}Responder\/tools\/MultiRelay\/bin\/Syssvc\.exe.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","57177" +"*Responder-Session.log*",".{0,1000}Responder\-Session\.log.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","#logfile","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","57182" +"*Responder-Windows*",".{0,1000}Responder\-Windows.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","N/A","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","57185" +"*RestartKeePass.ps1*",".{0,1000}RestartKeePass\.ps1.{0,1000}","offensive_tool_keyword","crackmapexec","Keepass exploitations from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","57187" +"*RestartKeePass.ps1*",".{0,1000}RestartKeePass\.ps1.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","57188" +"*restic2john.py*",".{0,1000}restic2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","57200" +"*RestoreServiceModificationVariant.exe*",".{0,1000}RestoreServiceModificationVariant\.exe.{0,1000}","offensive_tool_keyword","PrivFu","get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","KernelWritePoCs","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","57205" +"*RestrictedAdmin.exe*",".{0,1000}RestrictedAdmin\.exe.{0,1000}","offensive_tool_keyword","Ghostpack-CompiledBinaries","Compiled Binaries for Ghostpack","T1140 - T1559.002 - T1547.002 - T1055 - T1036.004","TA0005 - TA0002 - TA0040 - TA0036","N/A","N/A","Exploitation tool","https://github.com/r3motecontrol/Ghostpack-CompiledBinaries","1","1","N/A","N/A","N/A","10","1313","237","2024-10-24T21:58:54Z","2018-07-25T23:38:15Z","57206" +"*returnvar/wce*",".{0,1000}returnvar\/wce.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","1","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","57220" +"*rev_kali_192_168_0_110_1234*",".{0,1000}rev_kali_192_168_0_110_1234.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","57222" +"*reveng007/C2_Server*",".{0,1000}reveng007\/C2_Server.{0,1000}","offensive_tool_keyword","C2_Server","C2 server to connect to a victim machine via reverse shell","T1090 - T1090.001 - T1071 - T1071.001","TA0011 ","N/A","N/A","C2","https://github.com/reveng007/C2_Server","1","1","N/A","N/A","10","10","54","18","2022-02-27T02:00:02Z","2021-03-05T12:35:45Z","57223" +"*reveng007/DarkWidow*",".{0,1000}reveng007\/DarkWidow.{0,1000}","offensive_tool_keyword","DarkWidow","Indirect Dynamic Syscall SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a sacrificial Process as target process + (ACG+BlockDll) mitigation policy on spawned process + PPID spoofing (Emotet method) + Api resolving from TIB + API hashing","T1055 - T1055.012 - T1055.002 - T1098 - T1027 - T1027.001 - T1070.004 - T1036 - T1134 - T1140","TA0005 - TA0003 - TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/reveng007/DarkWidow","1","1","N/A","N/A","10","7","671","91","2025-03-12T21:58:25Z","2023-07-24T13:59:16Z","57224" +"*reveng007/Executable_Files*",".{0,1000}reveng007\/Executable_Files.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","57225" +"*reveng007/ReflectiveNtdll*",".{0,1000}reveng007\/ReflectiveNtdll.{0,1000}","offensive_tool_keyword","ReflectiveNtdll","A Dropper POC with a focus on aiding in EDR evasion - NTDLL Unhooking followed by loading ntdll in-memory which is present as shellcode","T1059 - T1059.003 - T1218.011 - T1027 - T1027.005 - T1070 - T1070.004","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/reveng007/ReflectiveNtdll","1","1","N/A","N/A","10","2","170","24","2023-02-10T05:30:28Z","2023-01-30T08:43:16Z","57226" +"*reveng007/SharpGmailC2*",".{0,1000}reveng007\/SharpGmailC2.{0,1000}","offensive_tool_keyword","SharpGmailC2","Gmail will act as Server and implant will exfiltrate data via smtp and will read commands from C2 (Gmail) via imap protocol","T1071 - T1071.004 - T1568 - T1568.002 - T1114 - T1114.001","TA0011 - TA0040 - TA0001","N/A","N/A","C2","https://github.com/reveng007/SharpGmailC2","1","1","N/A","N/A","10","10","260","47","2022-12-27T01:45:46Z","2022-11-10T06:48:15Z","57227" +"*Revenge-RAT v.0.1.exe*",".{0,1000}Revenge\-RAT\sv\.0\.1\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","57228" +"*Revenge-RAT v.0.2.exe*",".{0,1000}Revenge\-RAT\sv\.0\.2\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","57229" +"*Revenge-RAT v.0.3.exe*",".{0,1000}Revenge\-RAT\sv\.0\.3\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","57230" +"*Revenge-RAT v0.1.exe*",".{0,1000}Revenge\-RAT\sv0\.1\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","57231" +"*Revenge-RAT v0.2.exe*",".{0,1000}Revenge\-RAT\sv0\.2\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","57232" +"*Revenge-RAT v0.3.exe*",".{0,1000}Revenge\-RAT\sv0\.3\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","57233" +"*RevengeRAT-Stub-CSsharp*",".{0,1000}RevengeRAT\-Stub\-CSsharp.{0,1000}","offensive_tool_keyword","RevengeRAT-Stub-Cssharp","RevengeRAT - AsyncRAT Simple RAT","T1219 - T1055 - T1569.002 - T1035 - T1071 - T1105","TA0005 - TA0042 - TA0011","N/A","TA2541 - APT-C-36","C2","https://github.com/NYAN-x-CAT/RevengeRAT-Stub-Cssharp","1","1","N/A","N/A","10","10","92","39","2020-03-02T11:34:36Z","2019-09-15T09:39:07Z","57234" +"*reverse_shell_https.ps1*",".{0,1000}reverse_shell_https\.ps1.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","57237" +"*reverse_shell_minified.js*",".{0,1000}reverse_shell_minified\.js.{0,1000}","offensive_tool_keyword","CSExec","An alternative to *exec.py from impacket with some builtin tricks","T1059.001 - T1059.005 - T1071.001","TA0002","N/A","N/A","Lateral Movement","https://github.com/Metro-Holografix/CSExec.py","1","1","N/A","private github repo","10","","N/A","","","","57238" +"*reverse_tcp_x64.rb*",".{0,1000}reverse_tcp_x64\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","57239" +"*reverse_win_http.rb*",".{0,1000}reverse_win_http\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","57240" +"*reverseDisableWinDef.cpp*",".{0,1000}reverseDisableWinDef\.cpp.{0,1000}","offensive_tool_keyword","WinDefenderKiller","Windows Defender Killer | C++ Code Disabling Permanently Windows Defender using Registry Keys","T1562.001 - T1055.002 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/S12cybersecurity/WinDefenderKiller","1","1","N/A","N/A","10","5","448","67","2023-07-27T11:06:24Z","2023-07-25T10:32:25Z","57241" +"*ReverseProxy.dll*",".{0,1000}ReverseProxy\.dll.{0,1000}","offensive_tool_keyword","DcRat","DcRat C2 A simple remote tool in C#","T1071 - T1021 - T1003","TA0011","N/A","N/A","Malware","https://github.com/qwqdanchun/DcRat","1","1","N/A","N/A","10","10","968","332","2022-02-07T05:37:09Z","2021-03-12T11:00:37Z","57242" +"*ReverseShell.ps1*",".{0,1000}ReverseShell\.ps1.{0,1000}","offensive_tool_keyword","Windows-Privilege-Escalation","Windows Privilege Escalation Techniques and Scripts","T1055 - T1548 - T1078","TA0004 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/frizb/Windows-Privilege-Escalation","1","1","N/A","N/A","N/A","9","861","190","2020-03-25T22:35:02Z","2017-05-12T13:09:50Z","57243" +"*ReverseShell_20*.ps1*",".{0,1000}ReverseShell_20.{0,1000}\.ps1.{0,1000}","offensive_tool_keyword","PSSW100AVB","This is the PSSW100AVB (Powershell Scripts With 100% AV Bypass) Framework.A list of useful Powershell scripts with 100% AV bypass ratio","T1112 - T1562.001 - T1086 - T1548.002 - T1059.001","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/tihanyin/PSSW100AVB","1","1","N/A","N/A","N/A","10","1104","174","2025-01-28T10:47:44Z","2021-10-08T17:36:24Z","57244" +"*ReverseSock5Proxy/releases/download/*",".{0,1000}ReverseSock5Proxy\/releases\/download\/.{0,1000}","offensive_tool_keyword","ReverseSock5Proxy","A tiny Reverse Sock5 Proxy","T1090.002 - T1572 - T1071","TA0011 - TA0010","N/A","N/A","C2","https://github.com/Coldzer0/ReverseSock5Proxy","1","1","N/A","N/A","10","10","317","42","2022-11-28T21:18:26Z","2022-11-25T15:12:59Z","57245" +"*ReverseSocksProxyHandler.py*",".{0,1000}ReverseSocksProxyHandler\.py.{0,1000}","offensive_tool_keyword","Invoke-SocksProxy","also known as PortStarter is a socks proxy and reverse socks server using powershell","T1090 - T1059.001 - T1102.003","TA0011 - TA0010 - TA0005 - TA0003","PortStarter","Vice Society - Conti","C2","https://github.com/p3nt4/Invoke-SocksProxy","1","1","N/A","N/A","10","10","788","169","2021-03-21T21:00:40Z","2017-11-09T06:20:40Z","57246" +"*reverse-ssh.exe*",".{0,1000}reverse\-ssh\.exe.{0,1000}","offensive_tool_keyword","reverse-ssh","Statically-linked ssh server with reverse shell functionality for CTFs and such","T1105 - T1572 - T1569.002 - T1090","TA0001 - TA0002 - TA0003 - TA0010 - TA0011 - TA0005 ","N/A","N/A","C2","https://github.com/Fahrj/reverse-ssh","1","1","N/A","N/A","10","10","961","141","2023-02-15T00:16:25Z","2021-07-12T18:26:29Z","57250" +"*reverse-ssh/releases/latest*",".{0,1000}reverse\-ssh\/releases\/latest.{0,1000}","offensive_tool_keyword","reverse-ssh","Statically-linked ssh server with reverse shell functionality for CTFs and such","T1105 - T1572 - T1569.002 - T1090","TA0001 - TA0002 - TA0003 - TA0010 - TA0011 - TA0005 ","N/A","N/A","C2","https://github.com/Fahrj/reverse-ssh","1","1","N/A","N/A","10","10","961","141","2023-02-15T00:16:25Z","2021-07-12T18:26:29Z","57251" +"*reverse-sshx64.exe*",".{0,1000}reverse\-sshx64\.exe.{0,1000}","offensive_tool_keyword","reverse-ssh","Statically-linked ssh server with reverse shell functionality for CTFs and such","T1105 - T1572 - T1569.002 - T1090","TA0001 - TA0002 - TA0003 - TA0010 - TA0011 - TA0005 ","N/A","N/A","C2","https://github.com/Fahrj/reverse-ssh","1","1","N/A","N/A","10","10","961","141","2023-02-15T00:16:25Z","2021-07-12T18:26:29Z","57252" +"*reverse-sshx86.exe*",".{0,1000}reverse\-sshx86\.exe.{0,1000}","offensive_tool_keyword","reverse-ssh","Statically-linked ssh server with reverse shell functionality for CTFs and such","T1105 - T1572 - T1569.002 - T1090","TA0001 - TA0002 - TA0003 - TA0010 - TA0011 - TA0005 ","N/A","N/A","C2","https://github.com/Fahrj/reverse-ssh","1","1","N/A","N/A","10","10","961","141","2023-02-15T00:16:25Z","2021-07-12T18:26:29Z","57253" +"*ReverseTCP.ps1*",".{0,1000}ReverseTCP\.ps1.{0,1000}","offensive_tool_keyword","ReverseTCPShell","PowerShell ReverseTCP Shell - Framework","T1059.001 ","TA0011 ","N/A","N/A","C2","https://github.com/ZHacker13/ReverseTCPShell","1","1","N/A","N/A","10","10","1053","216","2022-09-18T20:59:33Z","2019-05-27T23:43:54Z","57254" +"*ReverseTCPShell-main*",".{0,1000}ReverseTCPShell\-main.{0,1000}","offensive_tool_keyword","ReverseTCPShell","PowerShell ReverseTCP Shell - Framework","T1059.001 ","TA0011 ","N/A","N/A","C2","https://github.com/ZHacker13/ReverseTCPShell","1","1","N/A","N/A","10","10","1053","216","2022-09-18T20:59:33Z","2019-05-27T23:43:54Z","57255" +"*ReversingID/Shellcode-Loader*",".{0,1000}ReversingID\/Shellcode\-Loader.{0,1000}","offensive_tool_keyword","Shellcode-Loader","dynamic shellcode loading","T1055 - T1055.012 - T1027 - T1027.005","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/ReversingID/Shellcode-Loader","1","1","N/A","N/A","10","3","244","44","2025-01-25T16:30:56Z","2021-08-08T08:53:03Z","57256" +"*Revoke-Obfuscation*",".{0,1000}Revoke\-Obfuscation.{0,1000}","offensive_tool_keyword","Invoke-DOSfuscation","Revoke-Obfuscation is a PowerShell v3.0+ compatible PowerShell obfuscation detection framework. used for de obfuscating powershell scripts","T1027 - T1083 - T1059","TA0002 - TA0007 - TA0040","N/A","N/A","Defense Evasion","https://github.com/danielbohannon/Revoke-Obfuscation","1","1","N/A","N/A","N/A","8","735","123","2023-12-01T02:04:51Z","2017-07-11T01:20:48Z","57265" +"*revsocks_darwin_amd64*",".{0,1000}revsocks_darwin_amd64.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","#linux","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57271" +"*revsocks_freebsd_386*",".{0,1000}revsocks_freebsd_386.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","N/A","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57272" +"*revsocks_freebsd_amd64*",".{0,1000}revsocks_freebsd_amd64.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","N/A","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57273" +"*revsocks_freebsd_arm*",".{0,1000}revsocks_freebsd_arm.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","N/A","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57274" +"*revsocks_linux_386*",".{0,1000}revsocks_linux_386.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","#linux","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57275" +"*revsocks_linux_amd64*",".{0,1000}revsocks_linux_amd64.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","#linux","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57276" +"*revsocks_linux_arm*",".{0,1000}revsocks_linux_arm.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","#linux","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57277" +"*revsocks_linux_mips*",".{0,1000}revsocks_linux_mips.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","#linux","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57278" +"*revsocks_linux_mipsle*",".{0,1000}revsocks_linux_mipsle.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","#linux","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57279" +"*revsocks_linux_s390x*",".{0,1000}revsocks_linux_s390x.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","#linux","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57280" +"*revsocks_netbsd_386*",".{0,1000}revsocks_netbsd_386.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","N/A","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57281" +"*revsocks_netbsd_amd64*",".{0,1000}revsocks_netbsd_amd64.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","N/A","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57282" +"*revsocks_netbsd_arm*",".{0,1000}revsocks_netbsd_arm.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","N/A","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57283" +"*revsocks_openbsd_386*",".{0,1000}revsocks_openbsd_386.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","N/A","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57284" +"*revsocks_openbsd_amd64*",".{0,1000}revsocks_openbsd_amd64.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","N/A","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57285" +"*revsocks_windows_386.exe*",".{0,1000}revsocks_windows_386\.exe.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","N/A","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57286" +"*revsocks_windows_amd64.exe*",".{0,1000}revsocks_windows_amd64\.exe.{0,1000}","offensive_tool_keyword","revsocks","Reverse SOCKS5 implementation in Go","T1572 - T1090 - T1071","TA0001 - TA0010 - TA0011","N/A","Dispossessor","C2","https://github.com/kost/revsocks","1","1","N/A","N/A","10","10","358","47","2024-03-13T22:31:05Z","2019-10-04T09:09:37Z","57287" +"*revTCPclient.ps1*",".{0,1000}revTCPclient\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","57289" +"*RevTcpShell.exe*",".{0,1000}RevTcpShell\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","57290" +"*RevWinDefKiller.exe*",".{0,1000}RevWinDefKiller\.exe.{0,1000}","offensive_tool_keyword","WinDefenderKiller","Windows Defender Killer | C++ Code Disabling Permanently Windows Defender using Registry Keys","T1562.001 - T1055.002 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/S12cybersecurity/WinDefenderKiller","1","1","N/A","N/A","10","5","448","67","2023-07-27T11:06:24Z","2023-07-25T10:32:25Z","57291" +"*rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion*",".{0,1000}rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","57293" +"*RhinoSecurityLabs*",".{0,1000}RhinoSecurityLabs.{0,1000}","offensive_tool_keyword","Github Username","github repo hosting exploitation tools for pentesters","N/A","N/A","N/A","N/A","Exploitation tool","https://github.com/RhinoSecurityLabs","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","57294" +"*RhinoSecurityLabs/pacu*",".{0,1000}RhinoSecurityLabs\/pacu.{0,1000}","offensive_tool_keyword","pacu","The AWS exploitation framework designed for testing the security of Amazon Web Services environments.","T1136.003 - T1190 - T1078.004","TA0006 - TA0001","N/A","Scattered Spider*","Framework","https://github.com/RhinoSecurityLabs/pacu","1","1","N/A","N/A","9","10","4651","731","2025-03-20T21:08:57Z","2018-06-13T21:58:59Z","57295" +"*rhosts_walker_spec.rb*",".{0,1000}rhosts_walker_spec\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","57297" +"*rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion*",".{0,1000}rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","57300" +"*ricardojoserf/adfsbrute*",".{0,1000}ricardojoserf\/adfsbrute.{0,1000}","offensive_tool_keyword","adfsbrute","test credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacks","T1110.003 - T1110.001 - T1110","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/ricardojoserf/adfsbrute","1","1","N/A","N/A","8","2","172","33","2021-04-23T16:43:59Z","2020-10-02T16:28:35Z","57301" +"*ricardojoserf/NativeBypassCredGuard*",".{0,1000}ricardojoserf\/NativeBypassCredGuard.{0,1000}","offensive_tool_keyword","NativeBypassCredGuard","Bypass Credential Guard by patching WDigest.dll using only NTAPI functions","T1558 - T1003.006","TA0006 - TA0005","N/A","N/A","Defense Evasion","https://github.com/ricardojoserf/NativeBypassCredGuard","1","1","N/A","N/A","7","3","236","28","2025-04-08T18:58:37Z","2024-12-01T16:58:03Z","57302" +"*ricardojoserf/NativeDump*",".{0,1000}ricardojoserf\/NativeDump.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","1","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","57303" +"*ricardojoserf/TrickDump*",".{0,1000}ricardojoserf\/TrickDump.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","1","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","57304" +"*RiccardoAncarani/BOFs*",".{0,1000}RiccardoAncarani\/BOFs.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files (BOFs) for shells and lols","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RiccardoAncarani/BOFs","1","1","N/A","N/A","10","10","118","13","2021-09-14T09:03:58Z","2021-08-27T10:04:12Z","57305" +"*RiccardoAncarani/LiquidSnake*",".{0,1000}RiccardoAncarani\/LiquidSnake.{0,1000}","offensive_tool_keyword","cobaltstrike","LiquidSnake is a tool that allows operators to perform fileless Lateral Movement using WMI Event Subscriptions and GadgetToJScript","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RiccardoAncarani/LiquidSnake","1","1","N/A","N/A","10","10","332","46","2021-09-01T11:53:30Z","2021-08-31T12:23:01Z","57306" +"*RiccardoAncarani/TaskShell*",".{0,1000}RiccardoAncarani\/TaskShell.{0,1000}","offensive_tool_keyword","cobaltstrike","tamper scheduled task with a binary","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RiccardoAncarani/TaskShell","1","1","N/A","N/A","10","10","56","9","2021-02-15T19:23:13Z","2021-02-15T19:22:26Z","57307" +"*rid_hijack.py*",".{0,1000}rid_hijack\.py.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","57308" +"*ridbrute_attack*",".{0,1000}ridbrute_attack.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","57309" +"*RIDHIJACK.ps1*",".{0,1000}RIDHIJACK\.ps1.{0,1000}","offensive_tool_keyword","RID-Hijacking","RID Hijacking Proof of Concept script by Kevin Joyce","T1174","TA0003","N/A","N/A","Persistence","https://github.com/STEALTHbits/RIDHijackingProofofConceptKJ","1","1","N/A","N/A","9","1","15","7","2018-10-30T15:00:03Z","2018-10-29T19:52:10Z","57310" +"*Ridter/atexec-pro*",".{0,1000}Ridter\/atexec\-pro.{0,1000}","offensive_tool_keyword","atexec-pro","Fileless atexec for lateral movement","T1021.002 - T1105","TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/Ridter/atexec-pro","1","1","N/A","N/A","10","4","366","45","2024-03-28T03:36:50Z","2024-03-27T09:15:00Z","57312" +"*Ridter/noPac*",".{0,1000}Ridter\/noPac.{0,1000}","offensive_tool_keyword","noPac","POC exploitation for CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user","T1548 - T1134 - T1078 - T1078.002","TA0004 ","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/Ridter/noPac","1","1","N/A","N/A","10","9","862","127","2023-01-29T03:31:27Z","2021-12-13T10:28:12Z","57313" +"*righteousgambit/quiet-riot*",".{0,1000}righteousgambit\/quiet\-riot.{0,1000}","offensive_tool_keyword","quiet-riot","Unauthenticated enumeration of AWS - Azure and GCP Principals","T1087 - T1083 - T1210","TA0007 - TA0001","N/A","N/A","Discovery","https://github.com/righteousgambit/quiet-riot","1","1","N/A","N/A","6","3","224","30","2024-11-13T19:41:26Z","2021-10-28T15:12:27Z","57314" +"*Ring3NamedPipeConsumer.exe*",".{0,1000}Ring3NamedPipeConsumer\.exe.{0,1000}","offensive_tool_keyword","NamedPipeMaster","a tool used to analyze monitor and interact with named pipes - allows dll injection and impersonation","T1055.001 - T1134.001 - T1010 - T1550.002","TA0007 - TA0008 - TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/zeze-zeze/NamedPipeMaster","1","1","N/A","N/A","9","2","161","15","2024-10-27T05:24:11Z","2024-08-23T02:03:44Z","57319" +"*Ring3NamedPipeMonitor*",".{0,1000}Ring3NamedPipeMonitor.{0,1000}","offensive_tool_keyword","NamedPipeMaster","a tool used to analyze monitor and interact with named pipes - allows dll injection and impersonation","T1055.001 - T1134.001 - T1010 - T1550.002","TA0007 - TA0008 - TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/zeze-zeze/NamedPipeMaster","1","1","N/A","N/A","9","2","161","15","2024-10-27T05:24:11Z","2024-08-23T02:03:44Z","57320" +"*Ring3NamedPipeMonitor.dll*",".{0,1000}Ring3NamedPipeMonitor\.dll.{0,1000}","offensive_tool_keyword","NamedPipeMaster","a tool used to analyze monitor and interact with named pipes - allows dll injection and impersonation","T1055.001 - T1134.001 - T1010 - T1550.002","TA0007 - TA0008 - TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/zeze-zeze/NamedPipeMaster","1","1","N/A","N/A","9","2","161","15","2024-10-27T05:24:11Z","2024-08-23T02:03:44Z","57321" +"*Ripemd-160.test-vectors.txt*",".{0,1000}Ripemd\-160\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","57322" +"*riskydissonance/SafetyDump*",".{0,1000}riskydissonance\/SafetyDump.{0,1000}","offensive_tool_keyword","SafetyDump","in memory process dumper - uses the Minidump Windows API to dump process memory before base64 encoding that dump and writing it to standard output","T1003.005 - T1059.001 - T1105 - T1071.001","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/riskydissonance/SafetyDump","1","1","N/A","N/A","10","2","162","16","2020-10-29T16:25:04Z","2019-12-10T14:45:17Z","57331" +"*rkervella/CarbonMonoxide*",".{0,1000}rkervella\/CarbonMonoxide.{0,1000}","offensive_tool_keyword","cobaltstrike","EDR Evasion - Combination of SwampThing - TikiTorch","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rkervella/CarbonMonoxide","1","1","N/A","N/A","10","10","25","10","2020-05-28T10:40:20Z","2020-05-15T09:32:25Z","57332" +"*rktazuzi7hbln7sy.onion*",".{0,1000}rktazuzi7hbln7sy\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","57333" +"*rmg-*-jar-with-dependencies.jar*",".{0,1000}rmg\-.{0,1000}\-jar\-with\-dependencies\.jar.{0,1000}","offensive_tool_keyword","remote-method-guesser","remote-method-guesser?(rmg) is a?Java RMI?vulnerability scanner and can be used to identify and verify common security vulnerabilities on?Java RMI?endpoints.","T1210.002 - T1046 - T1078.003","TA0001 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/qtc-de/remote-method-guesser","1","1","N/A","N/A","6","9","860","108","2024-07-03T19:40:54Z","2019-11-04T11:37:38Z","57387" +"*RMIRegistryExploit.java*",".{0,1000}RMIRegistryExploit\.java.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","57389" +"*rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion*",".{0,1000}rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","57395" +"*rnsm777cdsjrsdlbs4v5qoeppu3px6sb2igmh53jzrx7ipcrbjz5b2ad.onion*",".{0,1000}rnsm777cdsjrsdlbs4v5qoeppu3px6sb2igmh53jzrx7ipcrbjz5b2ad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","57396" +"*roadrecon.db*",".{0,1000}roadrecon\.db.{0,1000}","offensive_tool_keyword","ROADtools","A collection of Azure AD tools for offensive and defensive security purposes","T1136.003 - T1078.004 - T1021.006 - T1003.003","TA0002 - TA0004 - TA0005 - TA0006","N/A","APT29 - COZY BEAR - Black Basta","Exploitation tool","https://github.com/dirkjanm/ROADtools","1","1","N/A","network exploitation tool","10","10","2126","295","2025-04-17T18:55:20Z","2020-03-28T09:56:08Z","57402" +"*roadrecon/frontend*",".{0,1000}roadrecon\/frontend.{0,1000}","offensive_tool_keyword","ROADtools","A collection of Azure AD tools for offensive and defensive security purposes","T1136.003 - T1078.004 - T1021.006 - T1003.003","TA0002 - TA0004 - TA0005 - TA0006","N/A","APT29 - COZY BEAR - Black Basta","Exploitation tool","https://github.com/dirkjanm/ROADtools","1","1","N/A","network exploitation tool","10","10","2126","295","2025-04-17T18:55:20Z","2020-03-28T09:56:08Z","57403" +"*ROADtools.git*",".{0,1000}ROADtools\.git.{0,1000}","offensive_tool_keyword","ROADtools","A collection of Azure AD tools for offensive and defensive security purposes","T1136.003 - T1078.004 - T1021.006 - T1003.003","TA0002 - TA0004 - TA0005 - TA0006","N/A","APT29 - COZY BEAR - Black Basta","Exploitation tool","https://github.com/dirkjanm/ROADtools","1","1","N/A","network exploitation tool","10","10","2126","295","2025-04-17T18:55:20Z","2020-03-28T09:56:08Z","57405" +"*ROADtools-master*",".{0,1000}ROADtools\-master.{0,1000}","offensive_tool_keyword","ROADtools","A collection of Azure AD tools for offensive and defensive security purposes","T1136.003 - T1078.004 - T1021.006 - T1003.003","TA0002 - TA0004 - TA0005 - TA0006","N/A","APT29 - COZY BEAR - Black Basta","Exploitation tool","https://github.com/dirkjanm/ROADtools","1","1","N/A","network exploitation tool","10","10","2126","295","2025-04-17T18:55:20Z","2020-03-28T09:56:08Z","57408" +"*robertdavidgraham/masscan*",".{0,1000}robertdavidgraham\/masscan.{0,1000}","offensive_tool_keyword","masscan","TCP port scanner. spews SYN packets asynchronously. scanning entire Internet in under 5 minutes.","T1046","TA0007","N/A","Black Basta - Unit 29155 - Akira - EMBER BEAR","Reconnaissance","https://github.com/robertdavidgraham/masscan","1","1","N/A","N/A","N/A","10","24345","3118","2024-12-13T12:22:18Z","2013-07-28T05:35:33Z","57423" +"*RobustPentestMacro*",".{0,1000}RobustPentestMacro.{0,1000}","offensive_tool_keyword","phishing-HTML-linter","Phishing and Social-Engineering related scripts","T1566.001 - T1056.001","TA0040 - TA0001","N/A","N/A","Phishing","https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing","1","1","N/A","N/A","10","10","2689","527","2023-06-27T19:16:49Z","2018-02-02T21:24:03Z","57425" +"*rockyou.txt.gz*",".{0,1000}rockyou\.txt\.gz.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","57428" +"*rockyou.txt.gz*",".{0,1000}rockyou\.txt\.gz.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","57429" +"*rockyou-30000.*",".{0,1000}rockyou\-30000\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","57430" +"*rofl0r/proxychains*",".{0,1000}rofl0r\/proxychains.{0,1000}","offensive_tool_keyword","proxychains","proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4 SOCKS5 or HTTP(S) proxy","T1090.004 - T1090.003 - T1027 - T1573 - T1095","TA0005 - TA0011 - TA0010","N/A","Vice Society - Qilin - Black Basta - Dispossessor - EMBER BEAR","Defense Evasion","https://github.com/haad/proxychains","1","1","N/A","N/A","8","10","7142","647","2024-06-08T02:20:54Z","2011-02-25T12:27:05Z","57431" +"*RogueOxidResolver.cpp*",".{0,1000}RogueOxidResolver\.cpp.{0,1000}","offensive_tool_keyword","RoguePotato","Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RoguePotato","1","1","N/A","N/A","10","10","1081","131","2021-01-09T20:43:07Z","2020-05-10T17:38:28Z","57433" +"*RoguePotato.cpp*",".{0,1000}RoguePotato\.cpp.{0,1000}","offensive_tool_keyword","RoguePotato","Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RoguePotato","1","1","N/A","N/A","10","10","1081","131","2021-01-09T20:43:07Z","2020-05-10T17:38:28Z","57434" +"*RoguePotato.exe*",".{0,1000}RoguePotato\.exe.{0,1000}","offensive_tool_keyword","RoguePotato","Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RoguePotato","1","1","N/A","N/A","10","10","1081","131","2021-01-09T20:43:07Z","2020-05-10T17:38:28Z","57435" +"*RoguePotato.sln*",".{0,1000}RoguePotato\.sln.{0,1000}","offensive_tool_keyword","RoguePotato","Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RoguePotato","1","1","N/A","N/A","10","10","1081","131","2021-01-09T20:43:07Z","2020-05-10T17:38:28Z","57436" +"*RoguePotato.zip*",".{0,1000}RoguePotato\.zip.{0,1000}","offensive_tool_keyword","RoguePotato","Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RoguePotato","1","1","N/A","N/A","10","10","1081","131","2021-01-09T20:43:07Z","2020-05-10T17:38:28Z","57437" +"*RoguePotato-master*",".{0,1000}RoguePotato\-master.{0,1000}","offensive_tool_keyword","RoguePotato","Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RoguePotato","1","1","N/A","N/A","10","10","1081","131","2021-01-09T20:43:07Z","2020-05-10T17:38:28Z","57438" +"*RogueSploit*",".{0,1000}RogueSploit.{0,1000}","offensive_tool_keyword","RogueSploit","RogueSploit is an open source automated script made to create a Fake Acces Point. with dhcpd server. dns spoofing. host redirection. browser_autopwn1 or autopwn2 or beef+mitmf","T1534 - T1565 - T1566 - T1573 - T1590","TA0001 - TA0002 - TA0003","N/A","N/A","Sniffing & Spoofing","https://github.com/h0nus/RogueSploit","1","1","N/A","network exploitation tool","N/A","N/A","N/A","N/A","N/A","N/A","57439" +"*RogueWinRM.c*",".{0,1000}RogueWinRM\.c.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","57443" +"*RogueWinRM.cpp*",".{0,1000}RogueWinRM\.cpp.{0,1000}","offensive_tool_keyword","RogueWinRM","RogueWinRM is a local privilege escalation exploit that allows to escalate from a Service account (with SeImpersonatePrivilege) to Local System account if WinRM service is not running","T1548.003 - T1134.002 - T1055","TA0004","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RogueWinRM","1","1","N/A","N/A","10","8","788","107","2020-02-23T19:26:41Z","2019-12-02T22:58:03Z","57444" +"*RogueWinRM.exe*",".{0,1000}RogueWinRM\.exe.{0,1000}","offensive_tool_keyword","RogueWinRM","RogueWinRM is a local privilege escalation exploit that allows to escalate from a Service account (with SeImpersonatePrivilege) to Local System account if WinRM service is not running","T1548.003 - T1134.002 - T1055","TA0004","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RogueWinRM","1","1","N/A","N/A","10","8","788","107","2020-02-23T19:26:41Z","2019-12-02T22:58:03Z","57445" +"*RogueWinRM.zip*",".{0,1000}RogueWinRM\.zip.{0,1000}","offensive_tool_keyword","RogueWinRM","RogueWinRM is a local privilege escalation exploit that allows to escalate from a Service account (with SeImpersonatePrivilege) to Local System account if WinRM service is not running","T1548.003 - T1134.002 - T1055","TA0004","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RogueWinRM","1","1","N/A","N/A","10","8","788","107","2020-02-23T19:26:41Z","2019-12-02T22:58:03Z","57446" +"*Rolix44/Kubestroyer*",".{0,1000}Rolix44\/Kubestroyer.{0,1000}","offensive_tool_keyword","Kubestroyer","Kubestroyer aims to exploit Kubernetes clusters misconfigurations and be the swiss army knife of your Kubernetes pentests","T1588.002 - T1596 - T1552.004","TA0005 - TA0007","N/A","N/A","Exploitation tool","https://github.com/Rolix44/Kubestroyer","1","1","N/A","N/A","10","4","359","22","2024-07-26T06:33:00Z","2022-09-15T13:31:21Z","57447" +"*rookuu/BOFs/*",".{0,1000}rookuu\/BOFs\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of beacon object files for use with Cobalt Strike to facilitate","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rookuu/BOFs","1","1","N/A","N/A","10","10","175","26","2021-02-11T10:48:12Z","2021-02-11T10:28:48Z","57452" +"*root_userpass.txt*",".{0,1000}root_userpass\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","57458" +"*rootcathacking/catspin*",".{0,1000}rootcathacking\/catspin.{0,1000}","offensive_tool_keyword","catspin","Catspin rotates the IP address of HTTP requests making IP based blocks or slowdown measures ineffective. It is based on AWS API Gateway and deployed via AWS Cloudformation.","T1027 - T1071 - T1047 - T1090","TA0042 - TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/rootcathacking/catspin","1","1","N/A","N/A","9","3","261","32","2024-03-01T09:25:02Z","2022-07-26T08:08:33Z","57459" +"*rootclay/WMIHACKER*",".{0,1000}rootclay\/WMIHACKER.{0,1000}","offensive_tool_keyword","WMIHACKER","Bypass anti-virus software lateral movement command execution test tool - No need 445 Port","T1047 - T1569.002 - T1218 - T1036.005","TA0008 - TA0002 - TA0005","N/A","N/A","Lateral Movement","https://github.com/rootclay/WMIHACKER","1","1","N/A","N/A","9","10","1423","236","2025-01-20T15:37:28Z","2020-07-02T06:57:25Z","57461" +"*Rootkit.cpp*",".{0,1000}Rootkit\.cpp.{0,1000}","offensive_tool_keyword","Cronos-Rootkit","Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.","T1055 - T1078 - T1134 - T1562.001","TA0001 - TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/XaFF-XaFF/Cronos-Rootkit","1","1","N/A","N/A","N/A","9","899","186","2022-03-29T08:26:03Z","2021-08-25T08:54:45Z","57463" +"*rootkiter.com/EarthWorm*",".{0,1000}rootkiter\.com\/EarthWorm.{0,1000}","offensive_tool_keyword","EarthWorm","SOCKS v5 proxy service used for data forwarding in complex network environments","T1090.002 - T1573.001 - T1095","TA0010 - TA0008 - TA0011","N/A","APT27 - APT15 - Calypso - Earth Lusca - Worok","C2","https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4","1","1","N/A","N/A","10","10","156","177","2021-01-26T23:16:49Z","2019-01-03T05:01:20Z","57465" +"*rootkiter.com/Termite*",".{0,1000}rootkiter\.com\/Termite.{0,1000}","offensive_tool_keyword","Termite","Termite rootit abused by threat actors","T1014 - T1069 - T1055","TA0005 - TA0003 - TA0004","Operation TunnelSnake","Whitefly","Persistence","https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4","1","1","N/A","N/A","10","10","156","177","2021-01-26T23:16:49Z","2019-01-03T05:01:20Z","57466" +"*rootkiter/Termite*",".{0,1000}rootkiter\/Termite.{0,1000}","offensive_tool_keyword","Termite","Termite rootit abused by threat actors","T1014 - T1069 - T1055","TA0005 - TA0003 - TA0004","Operation TunnelSnake","Whitefly","Persistence","https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4","1","1","N/A","N/A","10","10","156","177","2021-01-26T23:16:49Z","2019-01-03T05:01:20Z","57467" +"*root-shellcode-linux*",".{0,1000}root\-shellcode\-linux.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","#linux","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","57470" +"*rop.find_gadgets*",".{0,1000}rop\.find_gadgets.{0,1000}","offensive_tool_keyword","Exrop","Exrop is automatic ROP chains generator tool which can build gadget chain automatically from given binary and constraints","T1554","TA0003","N/A","N/A","Exploitation tool","https://github.com/d4em0n/exrop","1","1","N/A","N/A","N/A","3","285","22","2020-02-21T08:01:06Z","2020-01-19T05:09:00Z","57471" +"*RopChain.py*",".{0,1000}RopChain\.py.{0,1000}","offensive_tool_keyword","Exrop","Exrop is automatic ROP chains generator tool which can build gadget chain automatically from given binary and constraints","T1554","TA0003","N/A","N/A","Exploitation tool","https://github.com/d4em0n/exrop","1","1","N/A","N/A","N/A","3","285","22","2020-02-21T08:01:06Z","2020-01-19T05:09:00Z","57472" +"*ROPEngine.cpp*",".{0,1000}ROPEngine\.cpp.{0,1000}","offensive_tool_keyword","ropfuscator","ROPfuscator is a fine-grained code obfuscation framework for C/C++ programs using ROP (return-oriented programming).","T1090 - T1027 - T1055 - T1099 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/ropfuscator/ropfuscator","1","1","N/A","N/A","N/A","5","426","32","2024-05-08T20:06:11Z","2021-11-16T18:13:57Z","57473" +"*ROPfuscator*",".{0,1000}ROPfuscator.{0,1000}","offensive_tool_keyword","ropfuscator","ROPfuscator is a fine-grained code obfuscation framework for C/C++ programs using ROP (return-oriented programming).","T1090 - T1027 - T1055 - T1099 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/ropfuscator/ropfuscator","1","1","N/A","N/A","N/A","5","426","32","2024-05-08T20:06:11Z","2021-11-16T18:13:57Z","57475" +"*ropfuscator-*",".{0,1000}ropfuscator\-.{0,1000}","offensive_tool_keyword","ropfuscator","ROPfuscator is a fine-grained code obfuscation framework for C/C++ programs using ROP (return-oriented programming).","T1090 - T1027 - T1055 - T1099 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/ropfuscator/ropfuscator","1","1","N/A","N/A","N/A","5","426","32","2024-05-08T20:06:11Z","2021-11-16T18:13:57Z","57476" +"*ropfuscator.*",".{0,1000}ropfuscator\..{0,1000}","offensive_tool_keyword","ropfuscator","ROPfuscator is a fine-grained code obfuscation framework for C/C++ programs using ROP (return-oriented programming).","T1090 - T1027 - T1055 - T1099 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/ropfuscator/ropfuscator","1","1","N/A","N/A","N/A","5","426","32","2024-05-08T20:06:11Z","2021-11-16T18:13:57Z","57477" +"*ropnop/go-windapsearch*",".{0,1000}ropnop\/go\-windapsearch.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","57478" +"*ropnop/kerbrute*",".{0,1000}ropnop\/kerbrute.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","57479" +"*rotarydrone/GlobalUnProtect*",".{0,1000}rotarydrone\/GlobalUnProtect.{0,1000}","offensive_tool_keyword","GlobalUnProtect","Decrypt GlobalProtect configuration and cookie files.","T1552 - T1003 - T1555","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rotarydrone/GlobalUnProtect","1","1","N/A","N/A","9","2","147","19","2024-09-10T20:19:24Z","2024-09-04T15:31:52Z","57481" +"*rottenpotato.x64.dll*",".{0,1000}rottenpotato\.x64\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","57484" +"*rottenpotato.x86.dll*",".{0,1000}rottenpotato\.x86\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","57485" +"*RottenPotatoVulnerable.txt*",".{0,1000}RottenPotatoVulnerable\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","57486" +"*RouterPassView.exe*",".{0,1000}RouterPassView\.exe.{0,1000}","offensive_tool_keyword","RouterPassView","help you to recover your lost password from your router file","T1002 - T1552 - T1027","TA0006 - TA0007","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/router_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57487" +"*routerpassview.zip*",".{0,1000}routerpassview\.zip.{0,1000}","offensive_tool_keyword","RouterPassView","help you to recover your lost password from your router file","T1002 - T1552 - T1027","TA0006 - TA0007","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/router_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57488" +"*routerpasswords.com/*",".{0,1000}routerpasswords\.com\/.{0,1000}","offensive_tool_keyword","routerpasswords.com","find default routers passwords","T1110.003 - T1200","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Linux.md","1","1","N/A","N/A","N/A","10","1594","198","2025-04-16T21:16:51Z","2021-08-16T17:34:25Z","57489" +"*routers_userpass.txt*",".{0,1000}routers_userpass\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","57490" +"*routersploit*",".{0,1000}routersploit.{0,1000}","offensive_tool_keyword","routersploit","The RouterSploit Framework is an open-source exploitation framework dedicated to embedded devices.exploits","T1210.001 - T1190 - T1213 - T1189","TA0007 - TA0002 - TA0001 - TA0011","N/A","N/A","Framework","https://github.com/threat9/routersploit","1","1","N/A","N/A","N/A","10","12482","2333","2025-04-17T11:19:16Z","2016-03-30T11:43:12Z","57491" +"*RowTeam/SharpDecryptPwd*",".{0,1000}RowTeam\/SharpDecryptPwd.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","1","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","57492" +"*royal2xthig3ou5hd7zsliqagy6yygk2cdelaxtni2fyad6dpmpxedid.onion*",".{0,1000}royal2xthig3ou5hd7zsliqagy6yygk2cdelaxtni2fyad6dpmpxedid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","57493" +"*rpc::enum*",".{0,1000}rpc\:\:enum.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","57497" +"*rpc::server*",".{0,1000}rpc\:\:server.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","57498" +"*rpcattack.py*",".{0,1000}rpcattack\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","57502" +"*rpcattack.py*",".{0,1000}rpcattack\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","57503" +"*rpc-backdoor.go*",".{0,1000}rpc\-backdoor\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","57505" +"*rpc-beacons.go*",".{0,1000}rpc\-beacons\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","57506" +"*rpcdump.py*",".{0,1000}rpcdump\.py.{0,1000}","offensive_tool_keyword","adcshunter","Uses rpcdump to locate the ADCS server and identify if ESC8 is vulnerable from unauthenticated perspective.","T1018 - T1087 - T1046 - T1201 - T1595","TA0007 - TA0043","N/A","N/A","Discovery","https://github.com/danti1988/adcshunter","1","1","N/A","N/A","7","1","80","7","2024-09-13T12:50:50Z","2023-12-14T14:31:05Z","57511" +"*rpc-hijack.go*",".{0,1000}rpc\-hijack\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","57516" +"*rpc-kill.go*",".{0,1000}rpc\-kill\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","57518" +"*rpc-msf.go*",".{0,1000}rpc\-msf\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","57520" +"*rpcrelayclient.*",".{0,1000}rpcrelayclient\..{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","57528" +"*rpcrelayclient.py*",".{0,1000}rpcrelayclient\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","57529" +"*rpcrt4_new.dll*",".{0,1000}rpcrt4_new\.dll.{0,1000}","offensive_tool_keyword","POC","Remote Code Execution Exploit in the RPC Library CVE-2022-26809","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/websecnl/CVE-2022-26809","1","1","N/A","N/A","N/A","1","26","3","2022-04-19T17:04:04Z","2022-04-14T08:12:24Z","57530" +"*rpcrt4_old.dll",".{0,1000}rpcrt4_old\.dll","offensive_tool_keyword","POC","Remote Code Execution Exploit in the RPC Library CVE-2022-26809","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/websecnl/CVE-2022-26809","1","1","N/A","N/A","N/A","1","26","3","2022-04-19T17:04:04Z","2022-04-14T08:12:24Z","57531" +"*rpc-shellcode.go*",".{0,1000}rpc\-shellcode\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","57533" +"*rpivot.zip*",".{0,1000}rpivot\.zip.{0,1000}","offensive_tool_keyword","rpivot","socks4 reverse proxy for penetration testing","T1090.004 - T1572 - T1021.001","TA0011 - TA0002 - TA0040","N/A","N/A","C2","https://github.com/klsecservices/rpivot","1","1","N/A","N/A","10","10","589","128","2018-07-12T09:53:13Z","2016-09-07T17:25:57Z","57535" +"*rpivot-master*",".{0,1000}rpivot\-master.{0,1000}","offensive_tool_keyword","rpivot","socks4 reverse proxy for penetration testing","T1090.004 - T1572 - T1021.001","TA0011 - TA0002 - TA0040","N/A","N/A","C2","https://github.com/klsecservices/rpivot","1","1","N/A","N/A","10","10","589","128","2018-07-12T09:53:13Z","2016-09-07T17:25:57Z","57536" +"*rpm.torproject.org/*public_gpg.key*",".{0,1000}rpm\.torproject\.org\/.{0,1000}public_gpg\.key.{0,1000}","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","57537" +"*rsmudge/ElevateKit*",".{0,1000}rsmudge\/ElevateKit.{0,1000}","offensive_tool_keyword","cobaltstrike","The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/ElevateKit","1","1","N/A","N/A","10","10","912","203","2020-06-22T21:12:24Z","2016-12-08T03:51:09Z","57546" +"*rsockstun-1.1.zip*",".{0,1000}rsockstun\-1\.1\.zip.{0,1000}","offensive_tool_keyword","rsockstun","reverse socks tunneler with ntlm and proxy support","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","COZY BEAR","C2","https://github.com/llkat/rsockstun","1","1","N/A","N/A","10","10","53","22","2022-08-09T09:25:50Z","2018-10-17T09:51:11Z","57552" +"*rsockstun-master*",".{0,1000}rsockstun\-master.{0,1000}","offensive_tool_keyword","rsockstun","reverse socks tunneler with ntlm and proxy support","T1090 - T1571 - T1071 - T1095","TA0011 - TA0001 - TA0008","N/A","COZY BEAR","C2","https://github.com/llkat/rsockstun","1","1","N/A","N/A","10","10","53","22","2022-08-09T09:25:50Z","2018-10-17T09:51:11Z","57553" +"*rsocx-main.zip*",".{0,1000}rsocx\-main\.zip.{0,1000}","offensive_tool_keyword","rsocx","A bind/reverse Socks5 proxy server.","T1090.001 - T1090.002 - T1071.001","TA0011 - TA0009 - TA0040","N/A","Dispossessor - Scattered Spider*","C2","https://github.com/b23r0/rsocx","1","1","N/A","N/A","10","10","381","139","2022-09-28T08:11:34Z","2015-05-13T04:02:55Z","57559" +"*rtcrowley/Offensive-Netsh-Helper*",".{0,1000}rtcrowley\/Offensive\-Netsh\-Helper.{0,1000}","offensive_tool_keyword","Offensive-Netsh-Helper","Maintain Windows Persistence with an evil Netshell Helper DLL","T1174 - T1055.011 - T1546.013 - T1574.002 - T1105","TA0003 ","N/A","N/A","Persistence","https://github.com/rtcrowley/Offensive-Netsh-Helper","1","1","N/A","N/A","9","1","12","5","2018-07-28T02:12:09Z","2018-07-25T22:49:20Z","57564" +"*RtlDallas/Jomungand*",".{0,1000}RtlDallas\/Jomungand.{0,1000}","offensive_tool_keyword","Jomungand","Shellcode Loader with memory evasion","T1055.012 - T1027.002 - T1564.006","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/RtlDallas/Jomungand","1","1","N/A","N/A","10","","N/A","","","","57565" +"*RtlDallas/KrakenMask*",".{0,1000}RtlDallas\/KrakenMask.{0,1000}","offensive_tool_keyword","KrakenMask","A sleep obfuscation tool is used to encrypt the content of the .text section with RC4 (using SystemFunction032). To achieve this encryption a ROP chain is employed with QueueUserAPC and NtContinue.","T1027 - T1027.002 - T1055 - T1055.011 - T1059 - T1059.003","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/RtlDallas/KrakenMask","1","1","N/A","N/A","9","","N/A","","","","57566" +"*rubber_ducky.py*",".{0,1000}rubber_ducky\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","57568" +"*Rubeus.Commands*",".{0,1000}Rubeus\.Commands.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57575" +"*Rubeus.exe*",".{0,1000}Rubeus\.exe.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57578" +"*Rubeus.exe*",".{0,1000}Rubeus\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","57579" +"*Rubeus.git*",".{0,1000}Rubeus\.git.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57580" +"*Rubeus.Kerberos*",".{0,1000}Rubeus\.Kerberos.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57581" +"*Rubeus.lib*",".{0,1000}Rubeus\.lib.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57582" +"*RubeusASREPRoastManager*",".{0,1000}RubeusASREPRoastManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57587" +"*RubeusChangePwManager*",".{0,1000}RubeusChangePwManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57588" +"*RubeusCreateNetOnlyManager*",".{0,1000}RubeusCreateNetOnlyManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57589" +"*RubeusDescribeManager*",".{0,1000}RubeusDescribeManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57590" +"*RubeusDumpManager*",".{0,1000}RubeusDumpManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57591" +"*RubeusHarvestManager*",".{0,1000}RubeusHarvestManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57593" +"*RubeusHashManager*",".{0,1000}RubeusHashManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57595" +"*RubeusKerberoastManager*",".{0,1000}RubeusKerberoastManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57596" +"*RubeusKerberoastMenu*",".{0,1000}RubeusKerberoastMenu.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57597" +"*RubeusKlistManager*",".{0,1000}RubeusKlistManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57598" +"*Rubeus-master*",".{0,1000}Rubeus\-master.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57600" +"*RubeusMonitorManager*",".{0,1000}RubeusMonitorManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57601" +"*Rubeus-obf.exe*",".{0,1000}Rubeus\-obf\.exe.{0,1000}","offensive_tool_keyword","ProtectMyTooling","Multi-Packer wrapper letting us daisy-chain various packers obfuscators and other Red Team oriented weaponry","T1027 - T1202","TA0005","N/A","N/A","Resource Development","https://github.com/mgeeky/ProtectMyTooling","1","1","N/A","N/A","7","10","947","136","2024-12-06T20:10:02Z","2021-09-28T09:47:45Z","57603" +"*RubeusPttManager*",".{0,1000}RubeusPttManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57604" +"*RubeusPurgeManager*",".{0,1000}RubeusPurgeManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57606" +"*RubeusRenewManager*",".{0,1000}RubeusRenewManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57608" +"*RubeusS4UManager*",".{0,1000}RubeusS4UManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57610" +"*RubeusTgtDelegManager*",".{0,1000}RubeusTgtDelegManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57612" +"*RubeusTriageManager*",".{0,1000}RubeusTriageManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57614" +"*ruby_nntpd_cmd_exec*",".{0,1000}ruby_nntpd_cmd_exec.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","57629" +"*ruby_no_sh_reverse_tcp.py*",".{0,1000}ruby_no_sh_reverse_tcp\.py.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","57630" +"*ruby_reverse_tcp.py*",".{0,1000}ruby_reverse_tcp\.py.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","57631" +"*Rudrastra-main.zip*",".{0,1000}Rudrastra\-main\.zip.{0,1000}","offensive_tool_keyword","Rudrastra","Make a Fake wireless access point aka Evil Twin","T1491 - T1090.004 - T1557.001","TA0040 - TA0011 - TA0002","N/A","N/A","Sniffing & Spoofing","https://github.com/SxNade/Rudrastra","1","1","N/A","N/A","8","1","67","21","2023-04-22T15:10:42Z","2020-11-05T09:38:15Z","57632" +"*ruler-linux64*",".{0,1000}ruler\-linux64.{0,1000}","offensive_tool_keyword","ruler","A tool to abuse Exchange services","T1087 - T1110 - T1133 - T1064 - T1204","TA0007 - TA0006 - TA0003 - TA0002 - TA0005","N/A","APT33","Persistence","https://github.com/sensepost/ruler","1","1","#linux","N/A","10","10","2222","362","2024-06-10T11:03:07Z","2016-08-18T15:05:13Z","57648" +"*ruler-linux86*",".{0,1000}ruler\-linux86.{0,1000}","offensive_tool_keyword","ruler","A tool to abuse Exchange services","T1087 - T1110 - T1133 - T1064 - T1204","TA0007 - TA0006 - TA0003 - TA0002 - TA0005","N/A","APT33","Persistence","https://github.com/sensepost/ruler","1","1","#linux","N/A","10","10","2222","362","2024-06-10T11:03:07Z","2016-08-18T15:05:13Z","57649" +"*ruler-osx64*",".{0,1000}ruler\-osx64.{0,1000}","offensive_tool_keyword","ruler","A tool to abuse Exchange services","T1087 - T1110 - T1133 - T1064 - T1204","TA0007 - TA0006 - TA0003 - TA0002 - TA0005","N/A","APT33","Persistence","https://github.com/sensepost/ruler","1","1","N/A","N/A","10","10","2222","362","2024-06-10T11:03:07Z","2016-08-18T15:05:13Z","57650" +"*ruler-win64.exe*",".{0,1000}ruler\-win64\.exe.{0,1000}","offensive_tool_keyword","ruler","A tool to abuse Exchange services","T1087 - T1110 - T1133 - T1064 - T1204","TA0007 - TA0006 - TA0003 - TA0002 - TA0005","N/A","APT33","Persistence","https://github.com/sensepost/ruler","1","1","N/A","N/A","10","10","2222","362","2024-06-10T11:03:07Z","2016-08-18T15:05:13Z","57651" +"*ruler-win86.exe*",".{0,1000}ruler\-win86\.exe.{0,1000}","offensive_tool_keyword","ruler","A tool to abuse Exchange services","T1087 - T1110 - T1133 - T1064 - T1204","TA0007 - TA0006 - TA0003 - TA0002 - TA0005","N/A","APT33","Persistence","https://github.com/sensepost/ruler","1","1","N/A","N/A","10","10","2222","362","2024-06-10T11:03:07Z","2016-08-18T15:05:13Z","57652" +"*rules/d3ad0ne.rule*",".{0,1000}rules\/d3ad0ne\.rule.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","57653" +"*run_ppl_dump_exploit*",".{0,1000}run_ppl_dump_exploit.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","57675" +"*run_ppl_medic_exploit*",".{0,1000}run_ppl_medic_exploit.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","57676" +"*run_server.bat",".{0,1000}run_server\.bat","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","57678" +"*RunasCs.exe*",".{0,1000}RunasCs\.exe.{0,1000}","offensive_tool_keyword","RunasCs","RunasCs - Csharp and open version of windows builtin runas.exe","T1059.003 - T1059.001 - T1035","TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/RunasCs","1","1","N/A","N/A","7","10","1159","141","2024-07-12T23:31:35Z","2019-08-08T20:18:18Z","57686" +"*RunasCs.zip*",".{0,1000}RunasCs\.zip.{0,1000}","offensive_tool_keyword","RunasCs","RunasCs - Csharp and open version of windows builtin runas.exe","T1059.003 - T1059.001 - T1035","TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/RunasCs","1","1","N/A","N/A","7","10","1159","141","2024-07-12T23:31:35Z","2019-08-08T20:18:18Z","57687" +"*RunasCs_net2.exe*",".{0,1000}RunasCs_net2\.exe.{0,1000}","offensive_tool_keyword","RunasCs","RunasCs - Csharp and open version of windows builtin runas.exe","T1059.003 - T1059.001 - T1035","TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/RunasCs","1","1","N/A","N/A","7","10","1159","141","2024-07-12T23:31:35Z","2019-08-08T20:18:18Z","57688" +"*RunAsWinTcb.exe*",".{0,1000}RunAsWinTcb\.exe.{0,1000}","offensive_tool_keyword","RunAsWinTcb","RunAsWinTcb uses an userland exploit to run a DLL with a protection level of WinTcb-Light.","T1073.002 - T1055.001 - T1055.002","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/tastypepperoni/RunAsWinTcb","1","1","N/A","N/A","10","2","132","17","2022-08-02T16:35:50Z","2022-07-29T16:36:06Z","57691" +"*RunAsWinTcb-master*",".{0,1000}RunAsWinTcb\-master.{0,1000}","offensive_tool_keyword","RunAsWinTcb","RunAsWinTcb uses an userland exploit to run a DLL with a protection level of WinTcb-Light.","T1073.002 - T1055.001 - T1055.002","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/tastypepperoni/RunAsWinTcb","1","1","N/A","N/A","10","2","132","17","2022-08-02T16:35:50Z","2022-07-29T16:36:06Z","57692" +"*RunCleanup-77740706-9DEC-EC11-BB3D-0022482CA4A7.json*",".{0,1000}RunCleanup\-77740706\-9DEC\-EC11\-BB3D\-0022482CA4A7\.json.{0,1000}","offensive_tool_keyword","power-pwn","An offensive and defensive security toolset for Microsoft 365 Power Platform","T1078 - T1078.004 - T1136 - T1136.001 - T1021 - T1021.003 - T1114 - T1114.002","TA0003 - TA0004 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/mbrg/power-pwn","1","1","N/A","N/A","10","10","939","100","2025-03-20T08:54:43Z","2022-06-14T11:40:21Z","57693" +"*RunCodeExec-75740706-9DEC-EC11-BB3D-0022482CA4A7.json*",".{0,1000}RunCodeExec\-75740706\-9DEC\-EC11\-BB3D\-0022482CA4A7\.json.{0,1000}","offensive_tool_keyword","power-pwn","An offensive and defensive security toolset for Microsoft 365 Power Platform","T1078 - T1078.004 - T1136 - T1136.001 - T1021 - T1021.003 - T1114 - T1114.002","TA0003 - TA0004 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/mbrg/power-pwn","1","1","N/A","N/A","10","10","939","100","2025-03-20T08:54:43Z","2022-06-14T11:40:21Z","57694" +"*RunDLL32JSStager*",".{0,1000}RunDLL32JSStager.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","57711" +"*Run-EXEonRemote*",".{0,1000}Run\-EXEonRemote.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","57712" +"*Run-EXEonRemote.ps1*",".{0,1000}Run\-EXEonRemote\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","57713" +"*RunExfil-78740706-9DEC-EC11-BB3D-0022482CA4A7.json*",".{0,1000}RunExfil\-78740706\-9DEC\-EC11\-BB3D\-0022482CA4A7\.json.{0,1000}","offensive_tool_keyword","power-pwn","An offensive and defensive security toolset for Microsoft 365 Power Platform","T1078 - T1078.004 - T1136 - T1136.001 - T1021 - T1021.003 - T1114 - T1114.002","TA0003 - TA0004 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/mbrg/power-pwn","1","1","N/A","N/A","10","10","939","100","2025-03-20T08:54:43Z","2022-06-14T11:40:21Z","57714" +"*runFakeTerminal*",".{0,1000}runFakeTerminal.{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","57715" +"*run-hiphp-tk.sh*",".{0,1000}run\-hiphp\-tk\.sh.{0,1000}","offensive_tool_keyword","hiphp","The BackDoor of HIPHP gives you the power to control websites based on PHP using HTTP/HTTPS protocol. By sending files - tokens and commands through port 80s POST/GET method - users can access a range of activities such as downloading and editing files. It also allows for connecting to Tor networks with password protection for extra security.","T1105 - T1071.001 - T1132 - T1505 - T1608 - T1560 ","TA0011 - TA0001 - TA0002 - TA0009","N/A","N/A","C2","https://github.com/yasserbdj96/hiphp","1","1","N/A","N/A","10","10","217","33","2025-04-19T07:05:12Z","2021-04-05T20:29:57Z","57716" +"*RunOF.Internals*",".{0,1000}RunOF\.Internals.{0,1000}","offensive_tool_keyword","cobaltstrike","A tool to run object files mainly beacon object files (BOF) in .Net.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nettitude/RunOF","1","1","N/A","N/A","10","10","145","21","2023-01-06T15:30:05Z","2022-02-21T13:53:39Z","57727" +"*RunRansomware-76740706-9DEC-EC11-BB3D-0022482CA4A7.json*",".{0,1000}RunRansomware\-76740706\-9DEC\-EC11\-BB3D\-0022482CA4A7\.json.{0,1000}","offensive_tool_keyword","power-pwn","An offensive and defensive security toolset for Microsoft 365 Power Platform","T1078 - T1078.004 - T1136 - T1136.001 - T1021 - T1021.003 - T1114 - T1114.002","TA0003 - TA0004 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/mbrg/power-pwn","1","1","N/A","N/A","10","10","939","100","2025-03-20T08:54:43Z","2022-06-14T11:40:21Z","57729" +"*runShellcode*",".{0,1000}runShellcode.{0,1000}","offensive_tool_keyword","C2 related tools","Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners and analysts.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/mgeeky/ThreadStackSpoofer","1","1","N/A","N/A","10","10","1109","180","2022-06-17T18:06:35Z","2021-09-26T22:48:17Z","57733" +"*runshellcode.asm*",".{0,1000}runshellcode\.asm.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57734" +"*runshellcode.exe*",".{0,1000}runshellcode\.exe.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57735" +"*runshellcode.o*",".{0,1000}runshellcode\.o.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57736" +"*RunStealCookie-8B5C57DA-F404-ED11-82E4-0022481BF843.json*",".{0,1000}RunStealCookie\-8B5C57DA\-F404\-ED11\-82E4\-0022481BF843\.json.{0,1000}","offensive_tool_keyword","power-pwn","An offensive and defensive security toolset for Microsoft 365 Power Platform","T1078 - T1078.004 - T1136 - T1136.001 - T1021 - T1021.003 - T1114 - T1114.002","TA0003 - TA0004 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/mbrg/power-pwn","1","1","N/A","N/A","10","10","939","100","2025-03-20T08:54:43Z","2022-06-14T11:40:21Z","57737" +"*RunStealPowerAutomateToken-8C5C57DA-F404-ED11-82E4-0022481BF843.json*",".{0,1000}RunStealPowerAutomateToken\-8C5C57DA\-F404\-ED11\-82E4\-0022481BF843\.json.{0,1000}","offensive_tool_keyword","power-pwn","An offensive and defensive security toolset for Microsoft 365 Power Platform","T1078 - T1078.004 - T1136 - T1136.001 - T1021 - T1021.003 - T1114 - T1114.002","TA0003 - TA0004 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/mbrg/power-pwn","1","1","N/A","N/A","10","10","939","100","2025-03-20T08:54:43Z","2022-06-14T11:40:21Z","57738" +"*runZeroInc/sshamble*",".{0,1000}runZeroInc\/sshamble.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","1","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","57749" +"*RuralBishop.csproj*",".{0,1000}RuralBishop\.csproj.{0,1000}","offensive_tool_keyword","RuralBishop","creates a local RW section in UrbanBishop and then maps that section as RX into a remote process","T1055 - T1055.012 - T1055.002 - T1098 - T1027 - T1027.002 - T1070.004","TA0005 - TA0003 - TA0002","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/RuralBishop","1","1","N/A","N/A","10","2","107","26","2020-07-19T18:47:44Z","2020-07-19T18:47:38Z","57750" +"*RuralBishop.exe*",".{0,1000}RuralBishop\.exe.{0,1000}","offensive_tool_keyword","RuralBishop","creates a local RW section in UrbanBishop and then maps that section as RX into a remote process","T1055 - T1055.012 - T1055.002 - T1098 - T1027 - T1027.002 - T1070.004","TA0005 - TA0003 - TA0002","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/RuralBishop","1","1","N/A","N/A","10","2","107","26","2020-07-19T18:47:44Z","2020-07-19T18:47:38Z","57751" +"*RuralBishop.sln*",".{0,1000}RuralBishop\.sln.{0,1000}","offensive_tool_keyword","RuralBishop","creates a local RW section in UrbanBishop and then maps that section as RX into a remote process","T1055 - T1055.012 - T1055.002 - T1098 - T1027 - T1027.002 - T1070.004","TA0005 - TA0003 - TA0002","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/RuralBishop","1","1","N/A","N/A","10","2","107","26","2020-07-19T18:47:44Z","2020-07-19T18:47:38Z","57752" +"*RuralBishop-master*",".{0,1000}RuralBishop\-master.{0,1000}","offensive_tool_keyword","RuralBishop","creates a local RW section in UrbanBishop and then maps that section as RX into a remote process","T1055 - T1055.012 - T1055.002 - T1098 - T1027 - T1027.002 - T1070.004","TA0005 - TA0003 - TA0002","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/RuralBishop","1","1","N/A","N/A","10","2","107","26","2020-07-19T18:47:44Z","2020-07-19T18:47:38Z","57753" +"*russel.vantuyl@gmail.com*",".{0,1000}russel\.vantuyl\@gmail\.com.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","#email","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","57754" +"*russel.vantuyl@gmail.com*",".{0,1000}russel\.vantuyl\@gmail\.com.{0,1000}","offensive_tool_keyword","merlin-agent","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin-agent","1","1","#email","N/A","10","10","193","62","2025-04-16T14:12:16Z","2020-07-17T20:47:56Z","57755" +"*rustbof.cna*",".{0,1000}rustbof\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files (BOFs) written in rust with rust core and alloc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/wumb0/rust_bof","1","1","N/A","N/A","10","10","262","27","2024-02-08T20:45:00Z","2022-02-28T23:46:00Z","57756" +"*rustcat-3.0.0.zip*",".{0,1000}rustcat\-3\.0\.0\.zip.{0,1000}","offensive_tool_keyword","rustcat","Rustcat(rcat) - The modern Port listener and Reverse shell","T1090.001 - T1090.002 - T1046","TA0011 - TA0009 - TA0040","N/A","N/A","C2","https://github.com/robiot/rustcat","1","1","N/A","N/A","10","10","758","63","2024-07-20T14:20:34Z","2021-06-04T17:03:47Z","57757" +"*rusthound.exe*",".{0,1000}rusthound\.exe.{0,1000}","offensive_tool_keyword","RustHound","Active Directory data collector for BloodHound written in Rust","T1087.002 - T1018 - T1059.003","TA0007 - TA0001 - TA0002","N/A","N/A","Discovery","https://github.com/OPENCYBER-FR/RustHound","1","1","N/A","AD Enumeration","9","10","1013","98","2024-10-21T18:58:20Z","2022-10-12T05:54:35Z","57783" +"*RustHound-main*",".{0,1000}RustHound\-main.{0,1000}","offensive_tool_keyword","RustHound","Active Directory data collector for BloodHound written in Rust","T1087.002 - T1018 - T1059.003","TA0007 - TA0001 - TA0002","N/A","N/A","Discovery","https://github.com/OPENCYBER-FR/RustHound","1","1","N/A","AD Enumeration","9","10","1013","98","2024-10-21T18:58:20Z","2022-10-12T05:54:35Z","57784" +"*RustPotato.exe*",".{0,1000}RustPotato\.exe.{0,1000}","offensive_tool_keyword","RustPotato","A Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privileges","T1134.001 - T1055.011","TA0004","N/A","N/A","Privilege Escalation","https://github.com/emdnaia/RustPotato","1","1","N/A","N/A","10","1","0","0","2025-01-06T18:10:17Z","2025-01-06T19:44:57Z","57785" +"*rvazarkar/GMSAPasswordReader*",".{0,1000}rvazarkar\/GMSAPasswordReader.{0,1000}","offensive_tool_keyword","GMSAPasswordReader","Reads the password blob from a GMSA account using LDAP and parses the values into hashes for re-use.","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/rvazarkar/GMSAPasswordReader","1","1","N/A","N/A","7","3","219","34","2023-02-17T14:37:40Z","2020-01-19T19:06:20Z","57790" +"*Rvn0xsy/Cooolis-ms*",".{0,1000}Rvn0xsy\/Cooolis\-ms.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","57792" +"*rvrsh3ll/BOF_Collection*",".{0,1000}rvrsh3ll\/BOF_Collection.{0,1000}","offensive_tool_keyword","cobaltstrike","Various Cobalt Strike BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rvrsh3ll/BOF_Collection","1","1","N/A","N/A","10","10","635","57","2022-10-16T13:57:18Z","2020-07-16T18:24:55Z","57793" +"*rvrsh3ll/Rubeus-Rundll32*",".{0,1000}rvrsh3ll\/Rubeus\-Rundll32.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","1","N/A","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","57794" +"*rvrsh3ll/SharpCOM*",".{0,1000}rvrsh3ll\/SharpCOM.{0,1000}","offensive_tool_keyword","SharpCOM","DCOM Lateral Movement","T1175","TA0008","N/A","N/A","Lateral Movement","https://github.com/rvrsh3ll/SharpCOM","1","1","N/A","N/A","10","2","128","30","2019-09-16T22:52:53Z","2018-12-13T15:10:55Z","57795" +"*rvrsh3ll/SharpEdge*",".{0,1000}rvrsh3ll\/SharpEdge.{0,1000}","offensive_tool_keyword","SharpEdge","C# Implementation of Get-VaultCredential - Displays Windows vault credential objects including cleartext web credentials - based on https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-VaultCredential.ps1","T1555.004 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/SharpEdge","1","1","N/A","N/A","10","1","14","7","2018-07-31T01:31:21Z","2018-07-31T09:54:11Z","57796" +"*rvrsh3ll/SharpSSDP*",".{0,1000}rvrsh3ll\/SharpSSDP.{0,1000}","offensive_tool_keyword","SharpSSDP"," execute SharpSSDP.exe through Cobalt Strike's Beacon ""execute-assembly"" module to discover SSDP related services","T1046 - T1016","TA0007 - TA0005","N/A","N/A","Discovery","https://github.com/rvrsh3ll/SharpSSDP","1","1","N/A","N/A","7","1","17","4","2018-12-16T17:14:28Z","2018-12-16T17:14:12Z","57797" +"*rvrsh3ll/TokenTactics*",".{0,1000}rvrsh3ll\/TokenTactics.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","57798" +"*RwBlAHQALQBDAG8AbQBwAHUAdABlAHIASQBuAGYAbwAgAHwAIABzAGUAbABlAGMAdAAgAC0ARQB4AHAAYQBuAGQAUAByAG8AcABlAHIAdAB5ACAAVwBpAG4AZABvAHcAcwBQAHIAbwBkAHUAYwB0AE4AYQBtAGUA*",".{0,1000}RwBlAHQALQBDAG8AbQBwAHUAdABlAHIASQBuAGYAbwAgAHwAIABzAGUAbABlAGMAdAAgAC0ARQB4AHAAYQBuAGQAUAByAG8AcABlAHIAdAB5ACAAVwBpAG4AZABvAHcAcwBQAHIAbwBkAHUAYwB0AE4AYQBtAGUA.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","57799" +"*RwBlAHQALQBXAG0AaQBPAGIAagBlAGMAdAAgAFcAaQBuADMAMgBfAE4AZQB0AHcAbwByAGsAQQBkAGEAcAB0AGUAcgBDAG8AbgBmAGkAZwB1AHIAYQB0AGkAbwBuACAAfAAgAFMAZQBsAGUAYwB0AC0ATwBiAGoAZQBjAHQAIAAtAEUAeABwAGEAbgBkAFAAcgBvAHAAZQByAHQAeQAgAEkAUABBAGQAZAByAGUAcwBzACAAfAAgAFcAaABlAHIAZQAtAE8AYgBqAGUAYwB0ACAAewAoACQAXwAgAC0AbABpAGsAZQAgACIAMQAwAC4AKgAuACoALgAqACIAKQAgAC0AbwByACAAKAAkAF8AIAAtAGwAaQBrAGUAIAAiADEAOQAyAC4AMQA2ADgALgAqAC4AKgAiACkAIAAtAG8AcgAgACgAJABfACAALQBsAGkAawBlACAAIgAxADcAMgAuADEANgA4AC4AKgAuACoAIgApAH0A*",".{0,1000}RwBlAHQALQBXAG0AaQBPAGIAagBlAGMAdAAgAFcAaQBuADMAMgBfAE4AZQB0AHcAbwByAGsAQQBkAGEAcAB0AGUAcgBDAG8AbgBmAGkAZwB1AHIAYQB0AGkAbwBuACAAfAAgAFMAZQBsAGUAYwB0AC0ATwBiAGoAZQBjAHQAIAAtAEUAeABwAGEAbgBkAFAAcgBvAHAAZQByAHQAeQAgAEkAUABBAGQAZAByAGUAcwBzACAAfAAgAFcAaABlAHIAZQAtAE8AYgBqAGUAYwB0ACAAewAoACQAXwAgAC0AbABpAGsAZQAgACIAMQAwAC4AKgAuACoALgAqACIAKQAgAC0AbwByACAAKAAkAF8AIAAtAGwAaQBrAGUAIAAiADEAOQAyAC4AMQA2ADgALgAqAC4AKgAiACkAIAAtAG8AcgAgACgAJABfACAALQBsAGkAawBlACAAIgAxADcAMgAuADEANgA4AC4AKgAuACoAIgApAH0A.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","57800" +"*rwxfinder.*",".{0,1000}rwxfinder\..{0,1000}","offensive_tool_keyword","rwxfinder","The program uses the Windows API functions to traverse through directories and locate DLL files with RWX section","T1059.001 - T1059.003 - T1070.004","TA0002 - TA0005 - TA0040","N/A","N/A","Discovery","https://github.com/pwnsauc3/RWXFinder","1","1","N/A","N/A","5","2","101","14","2023-07-15T15:42:55Z","2023-07-14T07:47:21Z","57801" +"*RWXfinder-main*",".{0,1000}RWXfinder\-main.{0,1000}","offensive_tool_keyword","rwxfinder","The program uses the Windows API functions to traverse through directories and locate DLL files with RWX section","T1059.001 - T1059.003 - T1070.004","TA0002 - TA0005 - TA0040","N/A","N/A","Discovery","https://github.com/pwnsauc3/RWXFinder","1","1","N/A","N/A","5","2","101","14","2023-07-15T15:42:55Z","2023-07-14T07:47:21Z","57802" +"*rxwx/cs-rdll-ipc-example*",".{0,1000}rxwx\/cs\-rdll\-ipc\-example.{0,1000}","offensive_tool_keyword","cobaltstrike","Example code for using named pipe output with beacon ReflectiveDLLs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rxwx/cs-rdll-ipc-example","1","1","N/A","N/A","10","10","116","23","2020-06-24T19:47:35Z","2020-06-24T19:43:56Z","57804" +"*ryhanson/phishery*",".{0,1000}ryhanson\/phishery.{0,1000}","offensive_tool_keyword","phishery","Phishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document.","T1566.001 - T1071 - T1204.002","TA0001 ","N/A","BERSERK BEAR","Phishing","https://github.com/ryhanson/phishery","1","1","N/A","N/A","9","10","993","209","2017-09-11T15:42:10Z","2016-09-25T02:19:24Z","57805" +"*RythmStick/AMSITrigger*",".{0,1000}RythmStick\/AMSITrigger.{0,1000}","offensive_tool_keyword","AMSITrigger","AMSITrigger will identify all of the malicious strings in a powershell file by repeatedly making calls to AMSI using AMSIScanBuffer - line by line. On receiving an AMSI_RESULT_DETECTED response code the line will then be scrutinised to identify the individual triggers","T1059.001 - T1218.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/RythmStick/AMSITrigger","1","1","N/A","https://www.rythmstick.net/posts/amsitrigger/","10","10","1195","166","2022-08-21T22:37:23Z","2020-05-27T09:17:19Z","57806" +"*rzte/pdf-exploit*",".{0,1000}rzte\/pdf\-exploit.{0,1000}","offensive_tool_keyword","POC","CVE-2024-4367 poc exploitation","T1566","TA0042","N/A","N/A","Resource Development","https://github.com/rzte/pdf-exploit","1","1","N/A","N/A","6","3","216","41","2024-07-19T03:04:41Z","2024-07-11T14:33:11Z","57807" +"*s0md3v*Striker*",".{0,1000}s0md3v.{0,1000}Striker.{0,1000}","offensive_tool_keyword","Striker","Recon & Vulnerability Scanning Suite for web services","T1210.001 - T1190 - T1595 - T1192","TA0007 - TA0002 - TA0008 - ","N/A","N/A","Vulnerability Scanner","https://github.com/s0md3v/Striker","1","1","N/A","N/A","N/A","10","2271","451","2023-06-04T20:15:11Z","2017-10-30T07:08:02Z","57815" +"*S12cybersecurity/Admin2Sys*",".{0,1000}S12cybersecurity\/Admin2Sys.{0,1000}","offensive_tool_keyword","Admin2Sys","Admin2Sys it's a C++ malware to escalate privileges from Administrator account to NT AUTORITY SYSTEM","T1055.002 - T1078.003 - T1068","TA0002 - TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/S12cybersecurity/Admin2Sys","1","1","N/A","N/A","10","1","54","19","2023-05-01T19:32:41Z","2023-05-01T18:50:51Z","57816" +"*S12cybersecurity/RDPCredentialStealer*",".{0,1000}S12cybersecurity\/RDPCredentialStealer.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","57817" +"*S1ckB0y1337/TokenPlayer*",".{0,1000}S1ckB0y1337\/TokenPlayer.{0,1000}","offensive_tool_keyword","TokenPlayer","Manipulating and Abusing Windows Access Tokens","T1134 - T1484 - T1055 - T1078","TA0004 - TA0005 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S1ckB0y1337/TokenPlayer","1","1","N/A","N/A","10","3","274","45","2021-01-15T16:07:47Z","2020-08-20T23:05:49Z","57818" +"*S1lkys/SharpKiller*",".{0,1000}S1lkys\/SharpKiller.{0,1000}","offensive_tool_keyword","SharpKiller","Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8","T1211 - T1202 - T1218","TA0005","N/A","N/A","Defense Evasion","https://github.com/S1lkys/SharpKiller","1","1","N/A","N/A","10","4","349","45","2024-08-29T12:23:34Z","2023-10-21T17:27:59Z","57819" +"*s2wk77h653qn54csf4gp52orhem4y72dgxsquxulf255pcymazeepbyd.onion*",".{0,1000}s2wk77h653qn54csf4gp52orhem4y72dgxsquxulf255pcymazeepbyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","57822" +"*S3cur3Th1sSh1t/Amsi-Bypass-Powershell*",".{0,1000}S3cur3Th1sSh1t\/Amsi\-Bypass\-Powershell.{0,1000}","offensive_tool_keyword","AmsiBypass","bypassing Anti-Malware Scanning Interface (AMSI) features","T1548.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/S3cur3Th1sSh1t/Amsi-Bypass-Powershell","1","1","N/A","N/A","10","10","1890","311","2024-11-28T10:31:15Z","2019-05-14T06:09:25Z","57824" +"*S3cur3Th1sSh1t/MultiPotato*",".{0,1000}S3cur3Th1sSh1t\/MultiPotato.{0,1000}","offensive_tool_keyword","MultiPotato","get SYSTEM via SeImpersonate privileges","T1548.002 - T1134.002","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S3cur3Th1sSh1t/MultiPotato","1","1","N/A","N/A","10","6","518","92","2021-11-20T16:20:23Z","2021-11-19T15:50:55Z","57825" +"*S3cur3Th1sSh1t/PowerSharpPack*",".{0,1000}S3cur3Th1sSh1t\/PowerSharpPack.{0,1000}","offensive_tool_keyword","PowerSharpPack","Many useful offensive CSharp Projects wraped into Powershell for easy usage","T1059.001 - T1027 - T1055.012","TA0002 - TA0005","N/A","Dispossessor","Exploitation tool","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","57826" +"*S3cur3Th1sSh1t/SharpOxidResolver*",".{0,1000}S3cur3Th1sSh1t\/SharpOxidResolver.{0,1000}","offensive_tool_keyword","SharpOxidResolver","search the current domain for computers and get bindings for all of them","T1018 - T1046 - T1016","TA0007","N/A","KNOTWEED","Discovery","https://github.com/S3cur3Th1sSh1t/SharpOxidResolver","1","1","N/A","N/A","9","1","50","9","2020-11-25T08:42:06Z","2020-11-25T08:23:23Z","57827" +"*S3cur3Th1sSh1t/SharpVeeamDecryptor*",".{0,1000}S3cur3Th1sSh1t\/SharpVeeamDecryptor.{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","1","N/A","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","57828" +"*S3N4T0R-0X0/Checkmate*",".{0,1000}S3N4T0R\-0X0\/Checkmate.{0,1000}","offensive_tool_keyword","Checkmate","payload Execution by Fake Windows SmartScreen with requires Administrator privileges & Turn off real SmartScreen Filter","T1059 - T1070 - T1546","TA0002 - TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/S3N4T0R-0X0/Checkmate","1","1","N/A","N/A","9","1","95","16","2024-01-12T19:03:45Z","2024-01-04T15:56:37Z","57829" +"*S3Scanner-master*",".{0,1000}S3Scanner\-master.{0,1000}","offensive_tool_keyword","S3Scanner","Scan for open S3 buckets and dump the contents","T1583 - T1583.002 - T1114 - T1114.002","TA0010","N/A","N/A","Reconnaissance","https://github.com/sa7mon/S3Scanner","1","1","N/A","N/A","8","10","2743","384","2025-04-21T14:44:23Z","2017-06-19T22:14:21Z","57833" +"*S4uDelegator.*",".{0,1000}S4uDelegator\..{0,1000}","offensive_tool_keyword","PrivFu","Kernel mode WinDbg extension and PoCs for token privilege investigation.","T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001","TA0007 - TA0008 - TA0002 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","57837" +"*S4uDelegator.exe*",".{0,1000}S4uDelegator\.exe.{0,1000}","offensive_tool_keyword","PrivFu","perform S4U logon with SeTcbPrivilege","T1134","TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","S4uDelegator","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","57838" +"*S4ULogonShell.exe*",".{0,1000}S4ULogonShell\.exe.{0,1000}","offensive_tool_keyword","PrivFu","SeTcbPrivilege exploitation","T1134 - T1134.001 - T1078 - T1059 - T1075","TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","57839" +"*S4UTomato.csproj*",".{0,1000}S4UTomato\.csproj.{0,1000}","offensive_tool_keyword","S4UTomato","Escalate Service Account To LocalSystem via Kerberos","T1558 - T1558.002 - T1548.002 - T1078 - T1078.004","TA0006 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/wh0amitz/S4UTomato","1","1","N/A","N/A","10","4","394","76","2023-09-14T08:53:19Z","2023-07-30T11:51:57Z","57842" +"*S4UTomato.exe*",".{0,1000}S4UTomato\.exe.{0,1000}","offensive_tool_keyword","S4UTomato","Escalate Service Account To LocalSystem via Kerberos","T1558 - T1558.002 - T1548.002 - T1078 - T1078.004","TA0006 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/wh0amitz/S4UTomato","1","1","N/A","N/A","10","4","394","76","2023-09-14T08:53:19Z","2023-07-30T11:51:57Z","57843" +"*S4UTomato.sln*",".{0,1000}S4UTomato\.sln.{0,1000}","offensive_tool_keyword","S4UTomato","Escalate Service Account To LocalSystem via Kerberos","T1558 - T1558.002 - T1548.002 - T1078 - T1078.004","TA0006 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/wh0amitz/S4UTomato","1","1","N/A","N/A","10","4","394","76","2023-09-14T08:53:19Z","2023-07-30T11:51:57Z","57845" +"*S4UTomato-master*",".{0,1000}S4UTomato\-master.{0,1000}","offensive_tool_keyword","S4UTomato","Escalate Service Account To LocalSystem via Kerberos","T1558 - T1558.002 - T1548.002 - T1078 - T1078.004","TA0006 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/wh0amitz/S4UTomato","1","1","N/A","N/A","10","4","394","76","2023-09-14T08:53:19Z","2023-07-30T11:51:57Z","57846" +"*s7scan*",".{0,1000}s7scan.{0,1000}","offensive_tool_keyword","Github Username","s7scan is a tool that scans networks. enumerates Siemens PLCs and gathers basic information about them. such as PLC firmware and hardwaare version. network configuration and security parameters. It is completely written on Python.","T1046 - T1018 - T1049 - T1040 - T1016 - T1057","TA0043 - TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/klsecservices/s7scan","1","1","N/A","N/A","N/A","2","139","46","2018-12-28T12:11:56Z","2018-10-12T08:52:04Z","57849" +"*sa7mon/S3Scanner*",".{0,1000}sa7mon\/S3Scanner.{0,1000}","offensive_tool_keyword","S3Scanner","Scan for open S3 buckets and dump the contents","T1583 - T1583.002 - T1114 - T1114.002","TA0010","N/A","N/A","Reconnaissance","https://github.com/sa7mon/S3Scanner","1","1","N/A","N/A","8","10","2743","384","2025-04-21T14:44:23Z","2017-06-19T22:14:21Z","57850" +"*SaadAhla/dropper*",".{0,1000}SaadAhla\/dropper.{0,1000}","offensive_tool_keyword","dropper","Generates Malicious Office Macro Enabled Dropper for DLL SideLoading and Embed it in Lnk file to bypass MOTW","T1059 - T1574.002 - T1218 - T1559.003","TA0002 - TA0005 - TA0009","N/A","N/A","Resource Development","https://github.com/SaadAhla/dropper","1","1","N/A","N/A","10","","N/A","","","","57851" +"*SaadAhla/UnhookingPatch*",".{0,1000}SaadAhla\/UnhookingPatch.{0,1000}","offensive_tool_keyword","UnhookingPatch","Bypass EDR Hooks by patching NT API stub and resolving SSNs and syscall instructions at runtime","T1055 - T1574","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/SaadAhla/UnhookingPatch","1","1","N/A","N/A","8","4","304","52","2023-08-02T02:25:38Z","2023-02-08T16:21:03Z","57852" +"*sadshade/veeam-creds*",".{0,1000}sadshade\/veeam\-creds.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","1","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","57854" +"*safari_in_operator_side_effect.*",".{0,1000}safari_in_operator_side_effect\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","57855" +"*safari_proxy_object_type_confusion.*",".{0,1000}safari_proxy_object_type_confusion\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","57856" +"*SafeBreach-Labs/BITSInject*",".{0,1000}SafeBreach\-Labs\/BITSInject.{0,1000}","offensive_tool_keyword","BITSInject","A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM account","T1197","TA0004","N/A","N/A","Privilege Escalation","https://github.com/SafeBreach-Labs/BITSInject","1","1","N/A","N/A","8","1","99","18","2019-08-24T22:02:12Z","2017-07-03T12:39:38Z","57857" +"*SafeBreach-Labs/DoubleDrive*",".{0,1000}SafeBreach\-Labs\/DoubleDrive.{0,1000}","offensive_tool_keyword","DoubleDrive","A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files","T1486 - T1562.001 - T1213 - T1070.004 - T1070.006 - T1105","TA0040 - TA0009 - TA0011 - TA0005","N/A","N/A","Ransomware","https://github.com/SafeBreach-Labs/DoubleDrive","1","1","N/A","N/A","10","2","124","14","2024-05-28T16:25:59Z","2023-05-23T13:17:38Z","57858" +"*SafeBreach-Labs/EDRaser*",".{0,1000}SafeBreach\-Labs\/EDRaser.{0,1000}","offensive_tool_keyword","EDRaser","EDRaser is a powerful tool for remotely deleting access logs & Windows event logs & databases and other files on remote machines.","T1070.004 - T1027 - T1564.001","TA0005 - TA0040 - TA0003","N/A","N/A","Defense Evasion","https://github.com/SafeBreach-Labs/EDRaser","1","1","N/A","N/A","10","4","363","49","2024-04-06T17:42:40Z","2023-08-10T04:30:45Z","57859" +"*SafeBreach-Labs/PoolParty*",".{0,1000}SafeBreach\-Labs\/PoolParty.{0,1000}","offensive_tool_keyword","PoolParty","A set of fully-undetectable process injection techniques abusing Windows Thread Pools","T1055","TA0005","N/A","Black Basta","Defense Evasion","https://github.com/SafeBreach-Labs/PoolParty","1","1","N/A","N/A","9","10","1088","143","2023-12-11T10:52:05Z","2023-05-21T16:13:32Z","57860" +"*SafeBreach-Labs/SirepRAT*",".{0,1000}SafeBreach\-Labs\/SirepRAT.{0,1000}","offensive_tool_keyword","SirepRAT","RAT tool - Remote Command Execution as SYSTEM on Windows IoT Core","T1059 - T1219 - T1105 - T1021","TA0002 - TA0011 - TA0003","N/A","N/A","C2","https://github.com/SafeBreach-Labs/SirepRAT","1","1","N/A","N/A","7","10","380","89","2020-12-13T09:52:55Z","2019-03-02T19:51:05Z","57861" +"*SafeBreach-Labs/WindowsDowndate*",".{0,1000}SafeBreach\-Labs\/WindowsDowndate.{0,1000}","offensive_tool_keyword","WindowsDowndate","A tool that takes over Windows Updates to craft custom downgrades and expose past fixed vulnerabilities","T1072 - T1486 - T1505.002 - T1495 - T1499.004","TA0005 - TA0004 - TA0003 ","N/A","N/A","Defense Evasion","https://github.com/SafeBreach-Labs/WindowsDowndate","1","1","N/A","N/A","10","7","663","88","2024-10-26T10:18:49Z","2024-01-08T19:42:47Z","57862" +"*safedv/RustiveDump*",".{0,1000}safedv\/RustiveDump.{0,1000}","offensive_tool_keyword","RustiveDump","LSASS memory dumper using only NTAPIs","T1003.001 - T1055 - T1106","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/safedv/RustiveDump","1","1","N/A","N/A","10","4","332","43","2025-03-08T12:10:35Z","2024-10-06T16:01:49Z","57863" +"*safetydump.ninja*",".{0,1000}safetydump\.ninja.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","57866" +"*safetydump.ninja*",".{0,1000}safetydump\.ninja.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1024 - T1071 - T1029 - T1569","TA0002 - TA0003 - TA0040","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","57867" +"*SafetyKatz.csproj*",".{0,1000}SafetyKatz\.csproj.{0,1000}","offensive_tool_keyword","SafetyKatz","SafetyKatz is a combination of slightly modified version of @gentilkiwis Mimikatz project and @subtees .NET PE Loader. First. the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to C:\Windows\Temp\debug.bin. Then @subtees PELoader is used to load a customized version of Mimikatz that runs sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file. removing the file after execution is complete","T1003 - T1055 - T1059 - T1574","TA0002 - TA0003 - TA0008","N/A","APT39","Credential Access","https://github.com/GhostPack/SafetyKatz","1","1","N/A","N/A","10","10","1257","247","2019-10-01T16:47:21Z","2018-07-24T17:44:15Z","57868" +"*SafetyKatz.exe*",".{0,1000}SafetyKatz\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Erebus CobaltStrike post penetration testing plugin","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DeEpinGh0st/Erebus","1","1","N/A","N/A","10","10","1518","221","2021-10-28T06:20:51Z","2019-09-26T09:32:00Z","57869" +"*SafetyKatz.exe*",".{0,1000}SafetyKatz\.exe.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","57870" +"*SafetyKatz.exe*",".{0,1000}SafetyKatz\.exe.{0,1000}","offensive_tool_keyword","SafetyKatz","SafetyKatz is a combination of slightly modified version of @gentilkiwis Mimikatz project and @subtees .NET PE Loader. First. the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to C:\Windows\Temp\debug.bin. Then @subtees PELoader is used to load a customized version of Mimikatz that runs sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file. removing the file after execution is complete","T1003 - T1055 - T1059 - T1574","TA0002 - TA0003 - TA0008","N/A","APT39","Credential Access","https://github.com/GhostPack/SafetyKatz","1","1","N/A","N/A","10","10","1257","247","2019-10-01T16:47:21Z","2018-07-24T17:44:15Z","57871" +"*SafetyKatz.exe*",".{0,1000}SafetyKatz\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","57872" +"*SafetyKatz.exe*",".{0,1000}SafetyKatz\.exe.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","57873" +"*SafetyKatz.json*",".{0,1000}SafetyKatz\.json.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","57874" +"*SafetyKatz.sln*",".{0,1000}SafetyKatz\.sln.{0,1000}","offensive_tool_keyword","SafetyKatz","SafetyKatz is a combination of slightly modified version of @gentilkiwis Mimikatz project and @subtees .NET PE Loader. First. the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to C:\Windows\Temp\debug.bin. Then @subtees PELoader is used to load a customized version of Mimikatz that runs sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file. removing the file after execution is complete","T1003 - T1055 - T1059 - T1574","TA0002 - TA0003 - TA0008","N/A","APT39","Credential Access","https://github.com/GhostPack/SafetyKatz","1","1","N/A","N/A","10","10","1257","247","2019-10-01T16:47:21Z","2018-07-24T17:44:15Z","57876" +"*SafetyKatzManager*",".{0,1000}SafetyKatzManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","57878" +"*SafetyKatz-master*",".{0,1000}SafetyKatz\-master.{0,1000}","offensive_tool_keyword","SafetyKatz","SafetyKatz is a combination of slightly modified version of @gentilkiwis Mimikatz project and @subtees .NET PE Loader. First. the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to C:\Windows\Temp\debug.bin. Then @subtees PELoader is used to load a customized version of Mimikatz that runs sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file. removing the file after execution is complete","T1003 - T1055 - T1059 - T1574","TA0002 - TA0003 - TA0008","N/A","APT39","Credential Access","https://github.com/GhostPack/SafetyKatz","1","1","N/A","N/A","10","10","1257","247","2019-10-01T16:47:21Z","2018-07-24T17:44:15Z","57879" +"*sahadnk72/jecretz*",".{0,1000}sahadnk72\/jecretz.{0,1000}","offensive_tool_keyword","jecretz","Jira Secret Hunter - Helps you find credentials and sensitive contents in Jira tickets","T1552 - T1114 - T1119 - T1070","TA0006 - TA0009 - TA0005","N/A","Scattered Spider*","Discovery","https://github.com/sahadnk72/jecretz","1","1","N/A","N/A","7","1","43","9","2022-12-08T10:00:11Z","2020-05-25T14:40:28Z","57880" +"*sAINT*launch4j.tar.xz*",".{0,1000}sAINT.{0,1000}launch4j\.tar\.xz.{0,1000}","offensive_tool_keyword","saint","(s)AINT is a Spyware Generator for Windows systems written in Java","T1056.001 - T1125 - T1123 - T1113 - T1105 - T1573.001","TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","C2","https://github.com/tiagorlampert/sAINT","1","1","N/A","N/A","10","10","712","311","2020-04-03T14:34:34Z","2017-11-18T18:43:25Z","57881" +"*saint-1.0-jar-with-dependencies.exe*",".{0,1000}saint\-1\.0\-jar\-with\-dependencies\.exe.{0,1000}","offensive_tool_keyword","saint","(s)AINT is a Spyware Generator for Windows systems written in Java","T1056.001 - T1125 - T1123 - T1113 - T1105 - T1573.001","TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","C2","https://github.com/tiagorlampert/sAINT","1","1","N/A","N/A","10","10","712","311","2020-04-03T14:34:34Z","2017-11-18T18:43:25Z","57883" +"*saint-1.0-jar-with-dependencies.jar*",".{0,1000}saint\-1\.0\-jar\-with\-dependencies\.jar.{0,1000}","offensive_tool_keyword","saint","(s)AINT is a Spyware Generator for Windows systems written in Java","T1056.001 - T1125 - T1123 - T1113 - T1105 - T1573.001","TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","C2","https://github.com/tiagorlampert/sAINT","1","1","N/A","N/A","10","10","712","311","2020-04-03T14:34:34Z","2017-11-18T18:43:25Z","57884" +"*SamAdduser.exe*",".{0,1000}SamAdduser\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Use windows api to add users which can be used when net is unavailable","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/lengjibo/NetUser","1","1","N/A","N/A","10","10","420","90","2021-09-29T14:22:09Z","2020-01-09T08:33:27Z","57894" +"*sambaPipe.py*",".{0,1000}sambaPipe\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","57895" +"*samdump.exe*",".{0,1000}samdump\.exe.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","57898" +"*samdump.py*",".{0,1000}samdump\.py.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","57899" +"*samdump.zip*",".{0,1000}samdump\.zip.{0,1000}","offensive_tool_keyword","samdump","Dumping sam","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/nyxgeek/classic_hacking_tools","1","1","N/A","N/A","N/A","1","4","1","2024-06-27T09:35:42Z","2023-04-16T01:49:12Z","57900" +"*samr_##*",".{0,1000}samr_\#\#.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","57920" +"*samratashok/nishang*",".{0,1000}samratashok\/nishang.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","57921" +"*samratashok/nishang*",".{0,1000}samratashok\/nishang.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","57922" +"*samrdump.py*",".{0,1000}samrdump\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","57923" +"*sandboxevasion.py*",".{0,1000}sandboxevasion\.py.{0,1000}","offensive_tool_keyword","disctopia-c2","Windows Remote Administration Tool that uses Discord Telegram and GitHub as C2s","T1105 - T1102","TA0003 - TA0008 - TA0002","N/A","N/A","C2","https://github.com/3ct0s/disctopia-c2","1","1","N/A","N/A","10","10","609","139","2024-07-18T10:16:19Z","2022-01-02T22:03:10Z","57929" +"*santat7kpllt6iyvqbr7q4amdv6dzrh6paatvyrzl7ry3zm72zigf4ad.onion*",".{0,1000}santat7kpllt6iyvqbr7q4amdv6dzrh6paatvyrzl7ry3zm72zigf4ad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","57933" +"*sap2john.pl*",".{0,1000}sap2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","57935" +"*sap3r-encrypthub/encrypthub*",".{0,1000}sap3r\-encrypthub\/encrypthub.{0,1000}","offensive_tool_keyword","Kematian Stealer","Fake WinRar site distributes malware (+stealer +miner +hvnc +ransomware) from GitHub","T1195 - T1566 - T1569 - T1106 - T1486 - T1113","TA0001 - TA0002 - TA0005 - TA0006 - TA0007 - TA0009 - TA0010 - TA0011 - TA0040 - TA0043","N/A","N/A","Malware","https://github[.]com/sap3r-encrypthub/encrypthub","1","1","N/A","N/A","10","7","N/A","N/A","N/A","N/A","57936" +"*SauronEye.exe*",".{0,1000}SauronEye\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","57938" +"*saycheese-master.zip*",".{0,1000}saycheese\-master\.zip.{0,1000}","offensive_tool_keyword","saycheese","Grab target's webcam shots by link","T1213 - T1071 - T1102 - T1123 - T1185 - T1200","TA0001 - TA0005 - TA0009 - TA0011","N/A","N/A","Phishing","https://github.com/hangetzzu/saycheese","1","1","N/A","N/A","9","10","1175","962","2024-06-18T23:39:41Z","2019-04-29T04:07:00Z","57940" +"*sc_inject_direct.exe*",".{0,1000}sc_inject_direct\.exe.{0,1000}","offensive_tool_keyword","acheron","indirect syscalls for AV/EDR evasion in Go assembly","T1055.012 - T1059.001 - T1059.003","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/f1zm0/acheron","1","1","N/A","N/A","N/A","4","326","39","2023-06-13T19:20:33Z","2023-04-07T10:40:33Z","58092" +"*sc_inject_indirect.exe*",".{0,1000}sc_inject_indirect\.exe.{0,1000}","offensive_tool_keyword","acheron","indirect syscalls for AV/EDR evasion in Go assembly","T1055.012 - T1059.001 - T1059.003","TA0005 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/f1zm0/acheron","1","1","N/A","N/A","N/A","4","326","39","2023-06-13T19:20:33Z","2023-04-07T10:40:33Z","58093" +"*scada_default_userpass.txt*",".{0,1000}scada_default_userpass\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","58095" +"*scan4all.51pwn.com*",".{0,1000}scan4all\.51pwn\.com.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoCs - 23 kinds of application password crack - 7000+Web fingerprints - 146 protocols and 90000+ rules Port scanning - Fuzz - HW - awesome BugBounty","T1046 - T1210.001 - T1059 - T1082 - T1110","TA0007 - TA0001 - TA0009 - TA0002 - TA0004 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","58102" +"*scan4all.51pwn.com/*",".{0,1000}scan4all\.51pwn\.com\/.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoC","T1595 - T1190 - T1068","TA0001 - TA0007 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","58103" +"*scan4all_*_linux_amd64.zip*",".{0,1000}scan4all_.{0,1000}_linux_amd64\.zip.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoC","T1595 - T1190 - T1068","TA0001 - TA0007 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","#linux","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","58108" +"*scan4all_*_windows_amd64.zip*",".{0,1000}scan4all_.{0,1000}_windows_amd64\.zip.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoC","T1595 - T1190 - T1068","TA0001 - TA0007 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","58109" +"*scan4all_windows_386.exe*",".{0,1000}scan4all_windows_386\.exe.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoCs - 23 kinds of application password crack - 7000+Web fingerprints - 146 protocols and 90000+ rules Port scanning - Fuzz - HW - awesome BugBounty","T1046 - T1210.001 - T1059 - T1082 - T1110","TA0007 - TA0001 - TA0009 - TA0002 - TA0004 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","58110" +"*scan4all_windows_amd64.exe*",".{0,1000}scan4all_windows_amd64\.exe.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoCs - 23 kinds of application password crack - 7000+Web fingerprints - 146 protocols and 90000+ rules Port scanning - Fuzz - HW - awesome BugBounty","T1046 - T1210.001 - T1059 - T1082 - T1110","TA0007 - TA0001 - TA0009 - TA0002 - TA0004 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","58111" +"*scan4all-main*",".{0,1000}scan4all\-main.{0,1000}","offensive_tool_keyword","scan4all","Official repository vuls Scan: 15000+PoCs - 23 kinds of application password crack - 7000+Web fingerprints - 146 protocols and 90000+ rules Port scanning - Fuzz - HW - awesome BugBounty","T1046 - T1210.001 - T1059 - T1082 - T1110","TA0007 - TA0001 - TA0009 - TA0002 - TA0004 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hktalent/scan4all","1","1","N/A","N/A","10","10","5655","679","2024-07-12T13:23:48Z","2022-06-20T03:11:08Z","58112" +"*ScanInterception_x64.ps1*",".{0,1000}ScanInterception_x64\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","58113" +"*scanner/backdoor*",".{0,1000}scanner\/backdoor.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","58115" +"*ScanProcessForBadgerConfig*",".{0,1000}ScanProcessForBadgerConfig.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","58124" +"*ScanTCPImplant*",".{0,1000}ScanTCPImplant.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","58125" +"*ScareCrow*_darwin_amd64*",".{0,1000}ScareCrow.{0,1000}_darwin_amd64.{0,1000}","offensive_tool_keyword","cobaltstrike","ScareCrow - Payload creation framework designed around EDR bypass.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/optiv/ScareCrow","1","1","#linux","N/A","10","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","58135" +"*ScareCrow*_windows_amd64.exe*",".{0,1000}ScareCrow.{0,1000}_windows_amd64\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","ScareCrow - Payload creation framework designed around EDR bypass.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/optiv/ScareCrow","1","1","N/A","N/A","10","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","58136" +"*ScareCrow*KnownDLL*",".{0,1000}ScareCrow.{0,1000}KnownDLL.{0,1000}","offensive_tool_keyword","cobaltstrike","ScareCrow - Payload creation framework designed around EDR bypass.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/optiv/ScareCrow","1","1","N/A","N/A","10","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","58137" +"*ScareCrow*ProcessInjection*",".{0,1000}ScareCrow.{0,1000}ProcessInjection.{0,1000}","offensive_tool_keyword","cobaltstrike","ScareCrow - Payload creation framework designed around EDR bypass.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/optiv/ScareCrow","1","1","N/A","N/A","10","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","58138" +"*ScareCrow*windows_amd64.exe*",".{0,1000}ScareCrow.{0,1000}windows_amd64\.exe.{0,1000}","offensive_tool_keyword","ScareCrow","ScareCrow - Payload creation framework designed around EDR bypass.","T1548 - T1562 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/optiv/ScareCrow","1","1","N/A","N/A","N/A","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","58139" +"*ScareCrow.cna*",".{0,1000}ScareCrow\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike script for ScareCrow payloads intergration (EDR/AV evasion)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/GeorgePatsias/ScareCrow-CobaltStrike","1","1","N/A","N/A","10","10","462","68","2022-07-15T09:39:18Z","2021-06-24T10:04:01Z","58140" +"*ScareCrow.go*",".{0,1000}ScareCrow\.go.{0,1000}","offensive_tool_keyword","ScareCrow","ScareCrow - Payload creation framework designed around EDR bypass.","T1548 - T1562 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/optiv/ScareCrow","1","1","N/A","N/A","N/A","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","58141" +"*ScareCrow/Cryptor*",".{0,1000}ScareCrow\/Cryptor.{0,1000}","offensive_tool_keyword","cobaltstrike","ScareCrow - Payload creation framework designed around EDR bypass.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/optiv/ScareCrow","1","1","N/A","N/A","10","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","58142" +"*ScareCrow/limelighter*",".{0,1000}ScareCrow\/limelighter.{0,1000}","offensive_tool_keyword","cobaltstrike","ScareCrow - Payload creation framework designed around EDR bypass.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/optiv/ScareCrow","1","1","N/A","N/A","10","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","58143" +"*ScareCrow/Loader*",".{0,1000}ScareCrow\/Loader.{0,1000}","offensive_tool_keyword","cobaltstrike","ScareCrow - Payload creation framework designed around EDR bypass.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/optiv/ScareCrow","1","1","N/A","N/A","10","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","58144" +"*ScareCrow/Utils*",".{0,1000}ScareCrow\/Utils.{0,1000}","offensive_tool_keyword","cobaltstrike","ScareCrow - Payload creation framework designed around EDR bypass.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/optiv/ScareCrow","1","1","N/A","N/A","10","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","58145" +"*ScareCrow_*_darwin_amd64*",".{0,1000}ScareCrow_.{0,1000}_darwin_amd64.{0,1000}","offensive_tool_keyword","ScareCrow","ScareCrow - Payload creation framework designed around EDR bypass.","T1548 - T1562 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/optiv/ScareCrow","1","1","#linux","N/A","N/A","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","58146" +"*ScareCrow_*_linux_amd64*",".{0,1000}ScareCrow_.{0,1000}_linux_amd64.{0,1000}","offensive_tool_keyword","ScareCrow","ScareCrow - Payload creation framework designed around EDR bypass.","T1548 - T1562 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/optiv/ScareCrow","1","1","#linux","N/A","N/A","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","58147" +"*ScareCrow_*amd64*",".{0,1000}ScareCrow_.{0,1000}amd64.{0,1000}","offensive_tool_keyword","ScareCrow","ScareCrow - Payload creation framework designed around EDR bypass.","T1548 - T1562 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/optiv/ScareCrow","1","1","N/A","N/A","N/A","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","58148" +"*ScareCrow_checksums.txt*",".{0,1000}ScareCrow_checksums\.txt.{0,1000}","offensive_tool_keyword","ScareCrow","ScareCrow - Payload creation framework designed around EDR bypass.","T1548 - T1562 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/optiv/ScareCrow","1","1","N/A","N/A","N/A","10","2805","513","2023-08-18T17:16:06Z","2021-01-25T02:21:23Z","58149" +"*SCCM_DLLSiteloading.txt*",".{0,1000}SCCM_DLLSiteloading\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","58150" +"*sccmdecryptpoc.*",".{0,1000}sccmdecryptpoc\..{0,1000}","offensive_tool_keyword","sccmdecryptpoc","SCCM Account Password Decryption POC","T1555.003","TA0006","N/A","N/A","Credential Access","https://gist.github.com/xpn/5f497d2725a041922c427c3aaa3b37d1","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","58151" +"*sccmhunter.db",".{0,1000}sccmhunter\.db","offensive_tool_keyword","sccmhunter","SCCMHunter is a post-ex tool built to streamline identifying profiling and attacking SCCM related assets in an Active Directory domain","T1087 - T1046 - T1484","TA0003 - TA0006 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/garrettfoster13/sccmhunter","1","1","N/A","N/A","9","8","750","97","2025-04-03T15:58:02Z","2023-02-20T14:09:42Z","58152" +"*sccmhunter.git*",".{0,1000}sccmhunter\.git.{0,1000}","offensive_tool_keyword","sccmhunter","SCCMHunter is a post-ex tool built to streamline identifying profiling and attacking SCCM related assets in an Active Directory domain","T1087 - T1046 - T1484","TA0003 - TA0006 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/garrettfoster13/sccmhunter","1","1","N/A","N/A","9","8","750","97","2025-04-03T15:58:02Z","2023-02-20T14:09:42Z","58153" +"*sccmhunter.py*",".{0,1000}sccmhunter\.py.{0,1000}","offensive_tool_keyword","sccmhunter","SCCMHunter is a post-ex tool built to streamline identifying profiling and attacking SCCM related assets in an Active Directory domain","T1087 - T1046 - T1484","TA0003 - TA0006 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/garrettfoster13/sccmhunter","1","1","N/A","N/A","9","8","750","97","2025-04-03T15:58:02Z","2023-02-20T14:09:42Z","58154" +"*SCCMSecrets.py*",".{0,1000}SCCMSecrets\.py.{0,1000}","offensive_tool_keyword","SCCMSecrets","SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting - initial access and lateral movement.","T1555 - T1078 - T1070 - T1021","TA0006 - TA0008 - TA0001","N/A","N/A","Lateral Movement","https://github.com/synacktiv/SCCMSecrets","1","1","N/A","N/A","8","3","208","22","2024-12-17T14:29:39Z","2024-08-14T09:45:44Z","58155" +"*SCCMVNC.exe*",".{0,1000}SCCMVNC\.exe.{0,1000}","offensive_tool_keyword","SCCMVNC","A tool to modify SCCM remote control settings on the client machine - enabling remote control without permission prompts or notifications. This can be done without requiring access to SCCM server.","T1078 - T1562 - T1557","TA0005 - TA0003 - TA0008","N/A","N/A","Lateral Movement","https://github.com/netero1010/SCCMVNC","1","1","N/A","N/A","8","1","87","10","2024-10-20T14:29:43Z","2024-10-20T14:15:28Z","58156" +"*sccmwtf.py*",".{0,1000}sccmwtf\.py.{0,1000}","offensive_tool_keyword","sccmhunter","SCCMHunter is a post-ex tool built to streamline identifying profiling and attacking SCCM related assets in an Active Directory domain","T1087 - T1046 - T1484","TA0003 - TA0006 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/garrettfoster13/sccmhunter","1","1","N/A","N/A","9","8","750","97","2025-04-03T15:58:02Z","2023-02-20T14:09:42Z","58157" +"*ScheduleRunner.csproj*",".{0,1000}ScheduleRunner\.csproj.{0,1000}","offensive_tool_keyword","ScheduleRunner","A C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operation","T1210 - T1570 - T1021 - T1550","TA0008","N/A","N/A","Persistence","https://github.com/netero1010/ScheduleRunner","1","1","N/A","N/A","9","4","336","46","2025-01-22T02:06:59Z","2021-10-12T15:27:32Z","58161" +"*ScheduleRunner.exe*",".{0,1000}ScheduleRunner\.exe.{0,1000}","offensive_tool_keyword","ScheduleRunner","A C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operation","T1210 - T1570 - T1021 - T1550","TA0008","N/A","N/A","Persistence","https://github.com/netero1010/ScheduleRunner","1","1","N/A","N/A","9","4","336","46","2025-01-22T02:06:59Z","2021-10-12T15:27:32Z","58162" +"*ScheduleRunner.sln*",".{0,1000}ScheduleRunner\.sln.{0,1000}","offensive_tool_keyword","ScheduleRunner","A C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operation","T1210 - T1570 - T1021 - T1550","TA0008","N/A","N/A","Persistence","https://github.com/netero1010/ScheduleRunner","1","1","N/A","N/A","9","4","336","46","2025-01-22T02:06:59Z","2021-10-12T15:27:32Z","58163" +"*schlamperei.x86.dll*",".{0,1000}schlamperei\.x86\.dll.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","58165" +"*schshell.cna*",".{0,1000}schshell\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Fileless Lateral Movement tool that relies on ChangeServiceConfigA to run command","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/SCShell","1","1","N/A","N/A","10","10","1484","248","2023-07-10T01:31:54Z","2019-11-13T23:39:27Z","58167" +"*SchTask_0x727/releases*",".{0,1000}SchTask_0x727\/releases.{0,1000}","offensive_tool_keyword","SchTask_0x727","create hidden scheduled tasks","T1053","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/0x727/SchTask_0x727","1","1","N/A","N/A","10","6","532","112","2021-09-01T01:34:51Z","2021-08-30T03:29:34Z","58169" +"*schtask_callback*",".{0,1000}schtask_callback.{0,1000}","offensive_tool_keyword","cobaltstrike","A Visual Studio template used to create Cobalt Strike BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/securifybv/Visual-Studio-BOF-template","1","1","N/A","N/A","10","10","304","55","2021-11-17T12:03:42Z","2021-11-13T13:44:01Z","58170" +"*schtasks_elevator*",".{0,1000}schtasks_elevator.{0,1000}","offensive_tool_keyword","cobaltstrike","The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/ElevateKit","1","1","N/A","N/A","10","10","912","203","2020-06-22T21:12:24Z","2016-12-08T03:51:09Z","58185" +"*schtasksabuse.rb*",".{0,1000}schtasksabuse\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","58187" +"*SchTasksImplant*",".{0,1000}SchTasksImplant.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","58188" +"*SCOMDecrypt.csproj*",".{0,1000}SCOMDecrypt\.csproj.{0,1000}","offensive_tool_keyword","SCOMDecrypt","SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers","T1552.001 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/nccgroup/SCOMDecrypt","1","1","N/A","N/A","10","2","123","22","2023-11-10T07:04:26Z","2017-02-21T16:15:11Z","58192" +"*SCOMDecrypt.exe*",".{0,1000}SCOMDecrypt\.exe.{0,1000}","offensive_tool_keyword","SCOMDecrypt","SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers","T1552.001 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/nccgroup/SCOMDecrypt","1","1","N/A","N/A","10","2","123","22","2023-11-10T07:04:26Z","2017-02-21T16:15:11Z","58193" +"*SCOMDecrypt.ps1*",".{0,1000}SCOMDecrypt\.ps1.{0,1000}","offensive_tool_keyword","SCOMDecrypt","SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers","T1552.001 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/nccgroup/SCOMDecrypt","1","1","N/A","N/A","10","2","123","22","2023-11-10T07:04:26Z","2017-02-21T16:15:11Z","58194" +"*screen_spy.rb*",".{0,1000}screen_spy\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","58205" +"*screengrab.exe*",".{0,1000}screengrab\.exe.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","58226" +"*screenspy.rb*",".{0,1000}screenspy\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","58228" +"*screetsec/Microsploit*",".{0,1000}screetsec\/Microsploit.{0,1000}","offensive_tool_keyword","BruteSploit","Fast and easy create backdoor office exploitation using module metasploit packet . Microsoft Office . Open Office . Macro attack . Buffer Overflow","T1587 - T1588 - T1608","N/A","N/A","N/A","Exploitation tool","https://github.com/screetsec/Microsploit","1","1","N/A","N/A","N/A","5","439","121","2017-07-11T16:28:27Z","2017-03-16T05:26:55Z","58229" +"*screetsec/Pateensy*",".{0,1000}screetsec\/Pateensy.{0,1000}","offensive_tool_keyword","Pateensy","payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy","T1056.001 - T1200 - T1036 - T1071","TA0002 - TA0005 - TA0011 - TA0006","N/A","N/A","Exploitation tool","https://github.com/screetsec/Pateensy","1","1","N/A","N/A","N/A","2","143","60","2017-01-26T12:02:56Z","2016-03-21T07:29:38Z","58230" +"*screetsec/Sudomy*",".{0,1000}screetsec\/Sudomy.{0,1000}","offensive_tool_keyword","Sudomy","Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting","T1595 - T1046","TA0002","N/A","N/A","Reconnaissance","https://github.com/screetsec/Sudomy","1","1","#linux","N/A","N/A","10","2139","396","2024-06-27T10:07:42Z","2019-07-26T10:26:34Z","58231" +"*screetsec/Vegile*",".{0,1000}screetsec\/Vegile.{0,1000}","offensive_tool_keyword","Sudomy","Ghost In The Shell - This tool will setting up your backdoor/rootkits when backdoor already setup it will be hidden your spesisifc process.unlimited your session in metasploit and transparent. Even when it killed. it will re-run again. There always be a procces which while run another process.So we can assume that this procces is unstopable like a Ghost in The Shell","T1587 - T1588 - T1608","N/A","N/A","N/A","Exploitation tool","https://github.com/screetsec/Vegile","1","1","#linux","N/A","N/A","8","726","164","2022-09-01T01:54:35Z","2018-01-02T05:29:48Z","58232" +"*script/xor-bin.py*",".{0,1000}script\/xor\-bin\.py.{0,1000}","offensive_tool_keyword","PE-Obfuscator","PE obfuscator with Evasion in mind","T1027 - T1055 - T1140 - T1564.003 - T1027.002","TA0006 - TA0002","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/PE-Obfuscator","1","1","N/A","N/A","N/A","3","213","40","2023-04-25T04:58:12Z","2023-04-25T04:00:15Z","58234" +"*ScriptBlockSmuggling.ps1*",".{0,1000}ScriptBlockSmuggling\.ps1.{0,1000}","offensive_tool_keyword","ScriptBlock-Smuggling","SCRIPTBLOCK SMUGGLING: SPOOFING POWERSHELL SECURITY LOGS AND BYPASSING AMSI WITHOUT REFLECTION OR PATCHING","T1059.001 - T1562.001 - T1112 - T1202 - T1070","TA0005","N/A","N/A","Defense Evasion","https://github.com/BC-SECURITY/ScriptBlock-Smuggling","1","1","N/A","https://bc-security.org/scriptblock-smuggling/","8","1","89","13","2024-06-18T08:35:50Z","2024-06-12T21:44:47Z","58236" +"*scripthost_uac_bypass*",".{0,1000}scripthost_uac_bypass.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","58237" +"*scripts*Remote-WmiExecute.*",".{0,1000}scripts.{0,1000}Remote\-WmiExecute\..{0,1000}","offensive_tool_keyword","ThunderShell","ThunderShell is a C# RAT that communicates via HTTP requests. All the network traffic is encrypted using a second layer of RC4 to avoid SSL interception and defeat network detection on the target system. RC4 is a weak cipher and is used to help obfuscate the traffic. HTTPS options should be used to provide integrity and strong encryption.","T1021.002 - T1573.002 - T1001.003","TA0008 - TA0011 - TA0040","N/A","LockBit","C2","https://github.com/Mr-Un1k0d3r/ThunderShell","1","1","N/A","N/A","10","10","779","223","2023-03-29T21:57:08Z","2017-09-12T01:11:29Z","58238" +"*scripts*Search-EventForUser.ps1*",".{0,1000}scripts.{0,1000}Search\-EventForUser\.ps1.{0,1000}","offensive_tool_keyword","ThunderShell","ThunderShell is a C# RAT that communicates via HTTP requests. All the network traffic is encrypted using a second layer of RC4 to avoid SSL interception and defeat network detection on the target system. RC4 is a weak cipher and is used to help obfuscate the traffic. HTTPS options should be used to provide integrity and strong encryption.","T1021.002 - T1573.002 - T1001.003","TA0008 - TA0011 - TA0040","N/A","LockBit","C2","https://github.com/Mr-Un1k0d3r/ThunderShell","1","1","N/A","N/A","10","10","779","223","2023-03-29T21:57:08Z","2017-09-12T01:11:29Z","58239" +"*scripts/ghauri.py*",".{0,1000}scripts\/ghauri\.py.{0,1000}","offensive_tool_keyword","ghauri","A cross-platform python based advanced sql injections detection & exploitation tool","T1190 - T1210 - T1095","TA0001 - TA0002 - TA0009","N/A","N/A","Vulnerability Scanner","https://github.com/r0oth3x49/ghauri","1","1","N/A","N/A","8","10","3483","361","2025-02-25T19:09:50Z","2022-10-01T11:21:50Z","58240" +"*ScriptSentry-main.zip*",".{0,1000}ScriptSentry\-main\.zip.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","58243" +"*ScRunBase32.exe*",".{0,1000}ScRunBase32\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","BypassAV ShellCode Loader (Cobaltstrike/Metasploit)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/scrun","1","1","N/A","N/A","10","10","179","76","2019-07-27T07:10:08Z","2019-07-21T15:34:41Z","58244" +"*ScRunBase32.py*",".{0,1000}ScRunBase32\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","BypassAV ShellCode Loader (Cobaltstrike/Metasploit)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/scrun","1","1","N/A","N/A","10","10","179","76","2019-07-27T07:10:08Z","2019-07-21T15:34:41Z","58245" +"*ScRunBase64.exe*",".{0,1000}ScRunBase64\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","BypassAV ShellCode Loader (Cobaltstrike/Metasploit)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/scrun","1","1","N/A","N/A","10","10","179","76","2019-07-27T07:10:08Z","2019-07-21T15:34:41Z","58246" +"*ScRunBase64.py*",".{0,1000}ScRunBase64\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","BypassAV ShellCode Loader (Cobaltstrike/Metasploit)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/scrun","1","1","N/A","N/A","10","10","179","76","2019-07-27T07:10:08Z","2019-07-21T15:34:41Z","58247" +"*scshell*XblAuthManager*",".{0,1000}scshell.{0,1000}XblAuthManager.{0,1000}","offensive_tool_keyword","cobaltstrike","Fileless Lateral Movement tool that relies on ChangeServiceConfigA to run command","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/SCShell","1","1","N/A","N/A","10","10","1484","248","2023-07-10T01:31:54Z","2019-11-13T23:39:27Z","58248" +"*SCShell.exe*",".{0,1000}SCShell\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Fileless Lateral Movement tool that relies on ChangeServiceConfigA to run command","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/SCShell","1","1","N/A","N/A","10","10","1484","248","2023-07-10T01:31:54Z","2019-11-13T23:39:27Z","58249" +"*scshell.py*",".{0,1000}scshell\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Fileless Lateral Movement tool that relies on ChangeServiceConfigA to run command","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/SCShell","1","1","N/A","N/A","10","10","1484","248","2023-07-10T01:31:54Z","2019-11-13T23:39:27Z","58250" +"*scshellbof.c*",".{0,1000}scshellbof\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Fileless Lateral Movement tool that relies on ChangeServiceConfigA to run command","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/SCShell","1","1","N/A","N/A","10","10","1484","248","2023-07-10T01:31:54Z","2019-11-13T23:39:27Z","58251" +"*scshellbof.o*",".{0,1000}scshellbof\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Fileless Lateral Movement tool that relies on ChangeServiceConfigA to run command","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/SCShell","1","1","N/A","N/A","10","10","1484","248","2023-07-10T01:31:54Z","2019-11-13T23:39:27Z","58252" +"*scshellbofx64*",".{0,1000}scshellbofx64.{0,1000}","offensive_tool_keyword","cobaltstrike","Fileless Lateral Movement tool that relies on ChangeServiceConfigA to run command","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/SCShell","1","1","N/A","N/A","10","10","1484","248","2023-07-10T01:31:54Z","2019-11-13T23:39:27Z","58253" +"*scumjr*dirtycow-vdso*",".{0,1000}scumjr.{0,1000}dirtycow\-vdso.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirtycow vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/timwr/CVE-2016-5195","1","1","N/A","N/A","N/A","10","972","393","2021-02-03T16:03:40Z","2016-10-21T11:19:21Z","58254" +"*sd6aq2r6jvuoeisrudq7jbqufjh6nck5buuzjmgalicgwrobgfj4lkqd.onion*",".{0,1000}sd6aq2r6jvuoeisrudq7jbqufjh6nck5buuzjmgalicgwrobgfj4lkqd\.onion.{0,1000}","offensive_tool_keyword","onionpipe","onionpipe forwards ports on the local host to remote Onion addresses as Tor hidden services and vice-versa.","T1090.003 - T1573.002","TA0005 - TA0011","N/A","Black Basta","Defense Evasion","https://github.com/cmars/onionpipe","1","1","N/A","N/A","10","6","553","33","2025-04-22T16:34:56Z","2022-01-23T06:52:13Z","58255" +"*sdjf982lkjsdvcjlksaf2kjhlksvvnktyoiasuc92lf.onion*",".{0,1000}sdjf982lkjsdvcjlksaf2kjhlksvvnktyoiasuc92lf\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","58256" +"*Search-cpassword*",".{0,1000}Search\-cpassword.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","58263" +"*SearchOutlook.exe*",".{0,1000}SearchOutlook\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58266" +"*searchsploit_rc*",".{0,1000}searchsploit_rc.{0,1000}","offensive_tool_keyword","cobaltstrike","Rapid Attack Infrastructure (RAI)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/obscuritylabs/RAI","1","1","N/A","N/A","10","10","304","53","2024-11-24T16:29:36Z","2018-02-12T16:23:23Z","58269" +"*Seatbelt.exe*",".{0,1000}Seatbelt\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Erebus CobaltStrike post penetration testing plugin","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DeEpinGh0st/Erebus","1","1","N/A","N/A","10","10","1518","221","2021-10-28T06:20:51Z","2019-09-26T09:32:00Z","58279" +"*Seatbelt.exe*",".{0,1000}Seatbelt\.exe.{0,1000}","offensive_tool_keyword","seatbelt","Seatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many others","T1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518","TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011","N/A","Dispossessor","Persistence","https://github.com/GhostPack/Seatbelt","1","1","N/A","N/A","10","10","4047","722","2025-01-10T20:12:49Z","2018-07-24T17:38:51Z","58280" +"*Seatbelt.exe*",".{0,1000}Seatbelt\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58281" +"*SeatbeltNet*.exe*",".{0,1000}SeatbeltNet.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","seatbelt","Seatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many others","T1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518","TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011","N/A","Dispossessor","Persistence","https://github.com/GhostPack/Seatbelt","1","1","N/A","N/A","10","10","4047","722","2025-01-10T20:12:49Z","2018-07-24T17:38:51Z","58283" +"*SecDbg/Prince-Ransomware*",".{0,1000}SecDbg\/Prince\-Ransomware.{0,1000}","offensive_tool_keyword","Prince-Ransomware","Go ransomware utilising ChaCha20 and ECIES encryption.","T1486 - T1489 - T1027","TA0040 - TA0009 ","N/A","N/A","Ransomware","https://github.com/SecDbg/Prince-Ransomware","1","1","N/A","N/A","10","","N/A","","","","58284" +"*secinject.cna*",".{0,1000}secinject\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Section Mapping Process Injection (secinject): Cobalt Strike BOF","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/apokryptein/secinject","1","1","N/A","N/A","10","10","94","23","2022-01-07T21:09:32Z","2021-09-05T01:17:47Z","58286" +"*secinject.git*",".{0,1000}secinject\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","Section Mapping Process Injection (secinject): Cobalt Strike BOF","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/apokryptein/secinject","1","1","N/A","N/A","10","10","94","23","2022-01-07T21:09:32Z","2021-09-05T01:17:47Z","58287" +"*secinject.x64*",".{0,1000}secinject\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Section Mapping Process Injection (secinject): Cobalt Strike BOF","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/apokryptein/secinject","1","1","N/A","N/A","10","10","94","23","2022-01-07T21:09:32Z","2021-09-05T01:17:47Z","58288" +"*secinject.x86*",".{0,1000}secinject\.x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Section Mapping Process Injection (secinject): Cobalt Strike BOF","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/apokryptein/secinject","1","1","N/A","N/A","10","10","94","23","2022-01-07T21:09:32Z","2021-09-05T01:17:47Z","58289" +"*secinject/src*",".{0,1000}secinject\/src.{0,1000}","offensive_tool_keyword","cobaltstrike","Section Mapping Process Injection (secinject): Cobalt Strike BOF","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/apokryptein/secinject","1","1","N/A","N/A","10","10","94","23","2022-01-07T21:09:32Z","2021-09-05T01:17:47Z","58290" +"*--seclogon-leak-local*",".{0,1000}\-\-seclogon\-leak\-local.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","58291" +"*--seclogon-leak-remote*",".{0,1000}\-\-seclogon\-leak\-remote.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","58292" +"*SeCreateTokenPrivilegePoC.exe*",".{0,1000}SeCreateTokenPrivilegePoC\.exe.{0,1000}","offensive_tool_keyword","PrivFu","PoCs for sensitive token privileges such SeDebugPrivilege","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","PrivilegedOperations","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","58294" +"*secredump.exe*",".{0,1000}secredump\.exe.{0,1000}","offensive_tool_keyword","BackupOperatorToDA","From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller","T1078 - T1078.003 - T1021 - T1021.006 - T1112 - T1003.003","TA0005 - TA0001 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/mpgn/BackupOperatorToDA","1","1","N/A","N/A","10","5","421","53","2025-01-04T14:16:46Z","2022-02-15T20:51:46Z","58296" +"*SecretFinder.py*",".{0,1000}SecretFinder\.py.{0,1000}","offensive_tool_keyword","secretfinder","SecretFinder is a python script based on LinkFinder written to discover sensitive data like apikeys - accesstoken - authorizations - jwt..etc in JavaScript files","T1083 - T1081 - T1113","TA0003 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/m4ll0k/SecretFinder","1","1","N/A","N/A","N/A","10","2153","405","2024-05-26T09:36:41Z","2020-06-08T10:50:12Z","58298" +"*SecretFinder-master.zip*",".{0,1000}SecretFinder\-master\.zip.{0,1000}","offensive_tool_keyword","secretfinder","SecretFinder is a python script based on LinkFinder written to discover sensitive data like apikeys - accesstoken - authorizations - jwt..etc in JavaScript files","T1083 - T1081 - T1113","TA0003 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/m4ll0k/SecretFinder","1","1","N/A","N/A","N/A","10","2153","405","2024-05-26T09:36:41Z","2020-06-08T10:50:12Z","58299" +"*secrets_dump*",".{0,1000}secrets_dump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","58301" +"*secrets_dump_dcsync*",".{0,1000}secrets_dump_dcsync.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","58302" +"*secretsdump*",".{0,1000}secretsdump.{0,1000}","offensive_tool_keyword","POC","Zerologon CVE exploitation (could be other malicious tools too)","T1210 - T1068","TA0001","N/A","N/A","Exploitation tool","https://github.com/risksense/zerologon","1","1","N/A","N/A","N/A","7","657","146","2020-10-15T18:31:15Z","2020-09-14T19:19:07Z","58305" +"*secretsdump.*.pyc*",".{0,1000}secretsdump\..{0,1000}\.pyc.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","58306" +"*secretsdump.py*",".{0,1000}secretsdump\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","58307" +"*secretsdump.py*",".{0,1000}secretsdump\.py.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","58308" +"*secretsdump.py*",".{0,1000}secretsdump\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","58310" +"*secretsdump.py*",".{0,1000}secretsdump\.py.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","58312" +"*secretsdump.py*",".{0,1000}secretsdump\.py.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","58313" +"*secretsdump.py*",".{0,1000}secretsdump\.py.{0,1000}","offensive_tool_keyword","PassTheCert","tool to authenticate to an LDAP/S server with a certificate through Schannel","T1557 - T1071 - T1021 - T1213 - T1649","TA0006 - TA0008 - TA0009","N/A","Black Basta","Lateral Movement","https://github.com/AlmondOffSec/PassTheCert","1","1","N/A","N/A","10","7","618","76","2024-07-08T22:37:30Z","2022-04-29T09:08:32Z","58315" +"*secretsdump.py*",".{0,1000}secretsdump\.py.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","58316" +"*secretsdump.py*",".{0,1000}secretsdump\.py.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","1","N/A","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","58318" +"*secretsquirrel/the-backdoor-factory*",".{0,1000}secretsquirrel\/the\-backdoor\-factory.{0,1000}","offensive_tool_keyword","the-backdoor-factory","Patch PE ELF Mach-O binaries with shellcode new version in development*","T1055.002 - T1055.004 - T1059.001","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/secretsquirrel/the-backdoor-factory","1","1","N/A","N/A","10","10","3369","788","2023-10-30T14:13:32Z","2013-05-30T01:04:24Z","58319" +"*SecScanC2_admin_*",".{0,1000}SecScanC2_admin_.{0,1000}","offensive_tool_keyword","SecScanC2","SecScanC2 can manage assetment to create P2P network for security scanning & C2. The tool can assist security researchers in conducting penetration testing more efficiently - preventing scanning from being blocked - protecting themselves from being traced.","T1021 - T1090","TA0011 - TA0002 - TA0040 - TA0043","N/A","N/A","C2","https://github.com/T1esh0u/SecScanC2","1","1","#P2P","N/A","10","","N/A","","","","58321" +"*SecScanC2_node_*",".{0,1000}SecScanC2_node_.{0,1000}","offensive_tool_keyword","SecScanC2","SecScanC2 can manage assetment to create P2P network for security scanning & C2. The tool can assist security researchers in conducting penetration testing more efficiently - preventing scanning from being blocked - protecting themselves from being traced.","T1021 - T1090","TA0011 - TA0002 - TA0040 - TA0043","N/A","N/A","C2","https://github.com/T1esh0u/SecScanC2","1","1","#P2P","N/A","10","","N/A","","","","58323" +"*SecScanC2-main*",".{0,1000}SecScanC2\-main.{0,1000}","offensive_tool_keyword","SecScanC2","SecScanC2 can manage assetment to create P2P network for security scanning & C2. The tool can assist security researchers in conducting penetration testing more efficiently - preventing scanning from being blocked - protecting themselves from being traced.","T1021 - T1090","TA0011 - TA0002 - TA0040 - TA0043","N/A","N/A","C2","https://github.com/T1esh0u/SecScanC2","1","1","#P2P","N/A","10","","N/A","","","","58324" +"*securesean/DecryptAutoLogon*",".{0,1000}securesean\/DecryptAutoLogon.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","1","N/A","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","58326" +"*securesocketfunneling*",".{0,1000}securesocketfunneling.{0,1000}","offensive_tool_keyword","securesocketfunneling","Secure Socket Funneling (SSF) is a network tool and toolkit It provides simple and efficient ways to forward data from multiple sockets (TCP or UDP) through a single secure TLS link to a remote computer","T1071.001 - T1573 - T1572","TA0003 - TA0009 - TA0011 ","N/A","N/A","C2","https://securesocketfunneling.github.io/ssf/#home","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","58327" +"*security-onion*",".{0,1000}security\-onion.{0,1000}","offensive_tool_keyword","security-onion","Security Onion is a free and open source Linux distribution for threat hunting. enterprise security monitoring. and log management. It includes Elasticsearch. Logstash. Kibana. Snort. Suricata. Bro. Wazuh. Sguil. Squert. NetworkMiner. and many other security tools. The easy-to-use Setup wizard allows you to build an army of distributed sensors for your enterprise in minutes","T1059 - T1059.001 - T1059.003 - T1059.004","TA0002 - TA0003 - TA0004 - TA0005","N/A","N/A","Exploitation OS","https://github.com/Security-Onion-Solutions/security-onion","1","1","N/A","N/A","N/A","10","3085","523","2021-04-16T12:14:31Z","2015-03-24T20:15:23Z","58328" +"*securycore/Ikeext-Privesc*",".{0,1000}securycore\/Ikeext\-Privesc.{0,1000}","offensive_tool_keyword","Ikeext-Privesc","Windows IKEEXT DLL Hijacking Exploit Tool","T1546.011 - T1574.009 - T1036.004","TA0003 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/securycore/Ikeext-Privesc","1","1","N/A","N/A","10","1","33","52","2018-02-25T13:45:15Z","2018-02-27T11:18:56Z","58330" +"*SecUser1/Necro-Stealer*",".{0,1000}SecUser1\/Necro\-Stealer.{0,1000}","offensive_tool_keyword","Necro-Stealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/Necro-Stealer","1","1","N/A","N/A","8","1","6","1","2022-12-06T16:06:55Z","2022-12-06T15:52:17Z","58331" +"*SecUser1/PredatorTheStealer*",".{0,1000}SecUser1\/PredatorTheStealer.{0,1000}","offensive_tool_keyword","PredatorTheStealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/PredatorTheStealer","1","1","N/A","N/A","8","1","11","2","2022-12-06T16:46:33Z","2022-12-06T16:34:43Z","58332" +"*secxrosqawaefsio3biv2dmi2c5yunf3t7ilwf54czq3v4bi7w6mbfad.onion*",".{0,1000}secxrosqawaefsio3biv2dmi2c5yunf3t7ilwf54czq3v4bi7w6mbfad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","58333" +"*SeDebugPrivilegePoC.exe*",".{0,1000}SeDebugPrivilegePoC\.exe.{0,1000}","offensive_tool_keyword","PrivFu","PoCs for sensitive token privileges such SeDebugPrivilege","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","PrivilegedOperations","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","58336" +"*SeeYouCM-Thief.git*",".{0,1000}SeeYouCM\-Thief\.git.{0,1000}","offensive_tool_keyword","SeeYouCM-Thief","Simple tool to automatically download and parse configuration files from Cisco phone systems searching for SSH credentials","T1110.001 - T1005 - T1071.001","TA0001 - TA0011 - TA0005","N/A","N/A","Discovery","https://github.com/trustedsec/SeeYouCM-Thief","1","1","N/A","N/A","9","2","189","35","2023-05-11T01:04:36Z","2022-01-14T20:12:25Z","58337" +"*SeeYouCM-Thief-main*",".{0,1000}SeeYouCM\-Thief\-main.{0,1000}","offensive_tool_keyword","SeeYouCM-Thief","Simple tool to automatically download and parse configuration files from Cisco phone systems searching for SSH credentials","T1110.001 - T1005 - T1071.001","TA0001 - TA0011 - TA0005","N/A","N/A","Discovery","https://github.com/trustedsec/SeeYouCM-Thief","1","1","N/A","N/A","9","2","189","35","2023-05-11T01:04:36Z","2022-01-14T20:12:25Z","58338" +"*sekurlsa::backupkeys*",".{0,1000}sekurlsa\:\:backupkeys.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58340" +"*sekurlsa::bootkey*",".{0,1000}sekurlsa\:\:bootkey.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58341" +"*sekurlsa::cloudap*",".{0,1000}sekurlsa\:\:cloudap.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58342" +"*sekurlsa::credman*",".{0,1000}sekurlsa\:\:credman.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58343" +"*sekurlsa::dpapi*",".{0,1000}sekurlsa\:\:dpapi.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58344" +"*sekurlsa::dpapisystem*",".{0,1000}sekurlsa\:\:dpapisystem.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58345" +"*sekurlsa::ekeys*",".{0,1000}sekurlsa\:\:ekeys.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. This function dumps DPAPI backup keys for users who have logged on to the system","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58346" +"*sekurlsa::kerberos*",".{0,1000}sekurlsa\:\:kerberos.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58347" +"*sekurlsa::krbtgt*",".{0,1000}sekurlsa\:\:krbtgt.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58348" +"*sekurlsa::livessp*",".{0,1000}sekurlsa\:\:livessp.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58349" +"*sekurlsa::logonpasswords*",".{0,1000}sekurlsa\:\:logonpasswords.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. This function retrieves plaintext credentials from the LSA secrets in memory.","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58351" +"*sekurlsa::minidump*",".{0,1000}sekurlsa\:\:minidump.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58353" +"*sekurlsa::msv*",".{0,1000}sekurlsa\:\:msv.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58354" +"*sekurlsa::process*",".{0,1000}sekurlsa\:\:process.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58355" +"*sekurlsa::pth*",".{0,1000}sekurlsa\:\:pth.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash.This function performs pass-the-hash attacks allowing an attacker to authenticate to a remote system with a stolen hash.","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58356" +"*sekurlsa::ssp*",".{0,1000}sekurlsa\:\:ssp.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58357" +"*sekurlsa::tickets*",".{0,1000}sekurlsa\:\:tickets.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58358" +"*sekurlsa::trust*",".{0,1000}sekurlsa\:\:trust.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58359" +"*sekurlsa::tspkg*",".{0,1000}sekurlsa\:\:tspkg.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58360" +"*sekurlsa::wdigest*",".{0,1000}sekurlsa\:\:wdigest.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58361" +"*self_delete.x64.o*",".{0,1000}self_delete\.x64\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","BOF implementation of the research by @jonasLyk and the drafted PoC from @LloydLabs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/Self_Deletion_BOF","1","1","N/A","N/A","10","10","180","22","2021-10-03T19:10:21Z","2021-10-03T19:01:14Z","58380" +"*Self_Deletion_BOF*",".{0,1000}Self_Deletion_BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","BOF implementation of the research by @jonasLyk and the drafted PoC from @LloydLabs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/Self_Deletion_BOF","1","1","N/A","N/A","10","10","180","22","2021-10-03T19:10:21Z","2021-10-03T19:01:14Z","58381" +"*SeManageVolumeExploit.*",".{0,1000}SeManageVolumeExploit\..{0,1000}","offensive_tool_keyword","SeManageVolumeExploit","This exploit grants full permission on C:\ drive for all users on the machine","T1046 - T1098 - T1222.002","TA0007 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/CsEnox/SeManageVolumeExploit","1","1","N/A","N/A","10","2","110","17","2023-05-29T05:41:16Z","2021-10-11T01:17:04Z","58383" +"*SeManageVolumeExploit-main",".{0,1000}SeManageVolumeExploit\-main","offensive_tool_keyword","SeManageVolumeExploit","This exploit grants full permission on C:\ drive for all users on the machine","T1046 - T1098 - T1222.002","TA0007 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/CsEnox/SeManageVolumeExploit","1","1","N/A","N/A","10","2","110","17","2023-05-29T05:41:16Z","2021-10-11T01:17:04Z","58384" +"*Semperis/GoldenGMSA*",".{0,1000}Semperis\/GoldenGMSA.{0,1000}","offensive_tool_keyword","GoldenGMSA","GolenGMSA tool for working with GMSA passwords","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/Semperis/GoldenGMSA","1","1","N/A","N/A","7","2","144","22","2024-04-11T07:51:57Z","2022-02-03T10:32:05Z","58385" +"*send_ps1_payload*",".{0,1000}send_ps1_payload.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","58392" +"*send_shellcode_via_pipe*",".{0,1000}send_shellcode_via_pipe.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files (BOFs) for shells and lols","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RiccardoAncarani/BOFs","1","1","N/A","N/A","10","10","118","13","2021-09-14T09:03:58Z","2021-08-27T10:04:12Z","58395" +"*send_shellcode_via_pipe*",".{0,1000}send_shellcode_via_pipe.{0,1000}","offensive_tool_keyword","cobaltstrike","LiquidSnake is a tool that allows operators to perform fileless Lateral Movement using WMI Event Subscriptions and GadgetToJScript","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RiccardoAncarani/LiquidSnake","1","1","N/A","N/A","10","10","332","46","2021-09-01T11:53:30Z","2021-08-31T12:23:01Z","58396" +"*SendToPasteBin.ps1*",".{0,1000}SendToPasteBin\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","58417" +"*sense2john.py*",".{0,1000}sense2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","58418" +"*sensepost/goDoH*",".{0,1000}sensepost\/goDoH.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071 - T1001 - T1008 - T1070 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","N/A","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","58419" +"*sensepost/godoh*",".{0,1000}sensepost\/godoh.{0,1000}","offensive_tool_keyword","godoh","godoh is a proof of concept Command and Control framework. written in Golang. that uses DNS-over-HTTPS as a transport medium. Currently supported providers include Google. Cloudflare but also contains the ability to use traditional DNS.","T1071.004 - T1568.002 - T1105 ","TA0011 - TA0005","N/A","N/A","C2","https://github.com/sensepost/godoh","1","1","N/A","N/A","10","10","779","125","2023-12-19T07:21:45Z","2018-10-23T07:24:04Z","58420" +"*sensepost/impersonate*",".{0,1000}sensepost\/impersonate.{0,1000}","offensive_tool_keyword","impersonate","A windows token impersonation tool","T1134 - T1550","TA0004 - TA0003","N/A","N/A","Lateral Movement","https://github.com/sensepost/impersonate","1","1","N/A","N/A","10","4","301","38","2023-04-19T12:53:50Z","2022-10-28T06:30:02Z","58421" +"*sensepost/rattler*",".{0,1000}sensepost\/rattler.{0,1000}","offensive_tool_keyword","rattler","Automated DLL Enumerator","T1174 - T1574.007","TA0005","N/A","N/A","Discovery","https://github.com/sensepost/rattler","1","1","N/A","N/A","9","6","531","135","2017-12-21T18:01:09Z","2016-11-28T12:35:44Z","58423" +"*sensepost/reGeorg*",".{0,1000}sensepost\/reGeorg.{0,1000}","offensive_tool_keyword","reGeorg","The successor to reDuh - pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.","T1090 - T1095 - T1572","TA0003 - TA0011","N/A","FIN13 - IRIDIUM - UNC3524 - Worok - COZY BEAR - FANCY BEAR - EMBER BEAR - Sandworm","Data Exfiltration","https://github.com/sensepost/reGeorg","1","1","N/A","N/A","N/A","10","3075","826","2025-03-06T09:56:16Z","2014-08-08T00:58:12Z","58424" +"*sensepost/ruler*",".{0,1000}sensepost\/ruler.{0,1000}","offensive_tool_keyword","ruler","A tool to abuse Exchange services","T1087 - T1110 - T1133 - T1064 - T1204","TA0007 - TA0006 - TA0003 - TA0002 - TA0005","N/A","APT33","Persistence","https://github.com/sensepost/ruler","1","1","N/A","N/A","10","10","2222","362","2024-06-10T11:03:07Z","2016-08-18T15:05:13Z","58425" +"*sensepost/susinternals*",".{0,1000}sensepost\/susinternals.{0,1000}","offensive_tool_keyword","susinternals","python implementation of PSExec native service implementation","T1569.002 - T1021.002 - T1035","TA0002 - TA0004 - TA0008 - TA0003","N/A","N/A","Lateral Movement","https://github.com/sensepost/susinternals","1","1","N/A","N/A","7","2","194","18","2025-02-11T09:34:50Z","2025-02-10T07:40:36Z","58426" +"*sensepost/wiresocks*",".{0,1000}sensepost\/wiresocks.{0,1000}","offensive_tool_keyword","wiresocks","Docker-compose and Dockerfile to setup a wireguard VPN connection forcing specific TCP traffic through a socks proxy.","T1090.004 - T1572 - T1021.001","TA0011 - TA0002 - TA0040","N/A","N/A","Defense Evasion","https://github.com/sensepost/wiresocks","1","1","N/A","N/A","9","3","287","30","2024-01-19T10:58:20Z","2022-03-23T12:27:07Z","58427" +"*sensitive_files_win.txt*",".{0,1000}sensitive_files_win\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","58428" +"*Sensitivelocalfiles.txt*",".{0,1000}Sensitivelocalfiles\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","58429" +"*senzee1984/EDRPrison*",".{0,1000}senzee1984\/EDRPrison.{0,1000}","offensive_tool_keyword","EDRPrison","Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry","T1562 - T1027","TA0005 - TA0007","N/A","N/A","Defense Evasion","https://github.com/senzee1984/EDRPrison","1","1","N/A","N/A","10","5","401","37","2024-08-02T18:10:02Z","2024-06-30T01:17:04Z","58430" +"*senzee1984/InflativeLoading*",".{0,1000}senzee1984\/InflativeLoading.{0,1000}","offensive_tool_keyword","InflativeLoading","Dynamically convert a native EXE to PIC shellcode by prepending a shellcode stub","T1027 - T1055 - T1140","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/senzee1984/InflativeLoading","1","1","N/A","N/A","10","4","309","64","2024-04-12T17:14:07Z","2024-01-05T03:59:33Z","58431" +"*senzee1984/micr0_shell*",".{0,1000}senzee1984\/micr0_shell.{0,1000}","offensive_tool_keyword","micr0_shell","micr0shell is a Python script that dynamically generates Windows X64 PIC Null-Free reverse shell shellcode.","T1059.003 - T1027.001","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/senzee1984/micr0_shell","1","1","N/A","N/A","9","2","186","30","2024-07-21T08:16:57Z","2023-08-13T02:46:51Z","58432" +"*senzee1984/MutationGate*",".{0,1000}senzee1984\/MutationGate.{0,1000}","offensive_tool_keyword","MutationGate","MutationGate is a new approach to bypass EDR's inline hooking by utilizing hardware breakpoint to redirect the syscall.","T1055.011 - T1564.008 - T1557","TA0005 - TA0042","N/A","N/A","Defense Evasion","https://github.com/senzee1984/MutationGate","1","1","N/A","N/A","8","3","251","34","2024-04-10T03:12:58Z","2024-01-15T04:29:37Z","58433" +"*seq.localtonet.com/api*",".{0,1000}seq\.localtonet\.com\/api.{0,1000}","offensive_tool_keyword","localtonet","LocaltoNet is a reverse proxy that enables you to expose your localhost services to the internet","T1090 - T1102 - T1071 - T1105","TA0010 - TA0011 - TA0009 - TA0003 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/engineseller/localtonet","1","1","N/A","N/A","10","1","6","4","2022-01-31T03:19:25Z","2022-01-31T03:17:18Z","58434" +"*SeRestorePrivilegePoC.exe*",".{0,1000}SeRestorePrivilegePoC\.exe.{0,1000}","offensive_tool_keyword","PrivFu","PoCs for sensitive token privileges such SeDebugPrivilege","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","PrivilegedOperations","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","58435" +"*seriously_nothing_shady_here*",".{0,1000}seriously_nothing_shady_here.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","58436" +"*serve_ps1_payload*",".{0,1000}serve_ps1_payload.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","58438" +"*server/capture/http_ntlm*",".{0,1000}server\/capture\/http_ntlm.{0,1000}","offensive_tool_keyword","metasploit","llmnr spoofing used by Dispossessor ransomware group","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Dispossessor","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","58446" +"*server/modules/csharp/*",".{0,1000}server\/modules\/csharp\/.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","58447" +"*server@egress-asses.com*",".{0,1000}server\@egress\-asses\.com.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","#email","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","58449" +"*server-7566091c4e4a2a24.js*",".{0,1000}server\-7566091c4e4a2a24\.js.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","58452" +"*ServerlessRedirector-main*",".{0,1000}ServerlessRedirector\-main.{0,1000}","offensive_tool_keyword","ServerlessRedirector","Serverless Redirector in various cloud vendor for red team","T1090.003 - T1095 - T1001.003","TA0010 - TA0011 - TA0008","N/A","N/A","Defense Evasion","https://github.com/KINGSABRI/ServerlessRedirector","1","1","N/A","N/A","10","1","72","10","2022-12-08T08:56:02Z","2022-12-08T07:52:49Z","58456" +"*serverscan.linux.elf*",".{0,1000}serverscan\.linux\.elf.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","#linux","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","58458" +"*serverscan.linux.so*",".{0,1000}serverscan\.linux\.so.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","#linux","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","58459" +"*serverScan.win.cna*",".{0,1000}serverScan\.win\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","58460" +"*serverscan_386.exe*",".{0,1000}serverscan_386\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","58461" +"*ServerScan_Air_*.exe*",".{0,1000}ServerScan_Air_.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","58462" +"*ServerScan_Air_*_amd64*",".{0,1000}ServerScan_Air_.{0,1000}_amd64.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","58463" +"*ServerScan_Air_*_i386*",".{0,1000}ServerScan_Air_.{0,1000}_i386.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","58464" +"*serverscan_air-probes.exe*",".{0,1000}serverscan_air\-probes\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","58465" +"*serverscan_amd64.exe*",".{0,1000}serverscan_amd64\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","58466" +"*ServerScan_Pro_*.exe*",".{0,1000}ServerScan_Pro_.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","58467" +"*ServerScan_Pro_*_amd64*",".{0,1000}ServerScan_Pro_.{0,1000}_amd64.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","58468" +"*ServerScan_Pro_*_i386*",".{0,1000}ServerScan_Pro_.{0,1000}_i386.{0,1000}","offensive_tool_keyword","cobaltstrike","ServerScan is a high-concurrency network scanning and service detection tool developed in Golang.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Adminisme/ServerScan","1","1","N/A","N/A","10","10","1595","221","2024-06-16T13:41:34Z","2020-04-03T15:14:12Z","58469" +"*Server-Side-Request-Forgery-Payloads.*",".{0,1000}Server\-Side\-Request\-Forgery\-Payloads\..{0,1000}","offensive_tool_keyword","Offensive-Payloads","List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.","T1210 - T1185 - T1059 - T1400 - T1506 - T1213 ","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/InfoSecWarrior/Offensive-Payloads/","1","1","N/A","N/A","N/A","4","328","117","2024-09-20T09:59:28Z","2022-11-18T09:43:41Z","58473" +"*service/executable/",".{0,1000}service\/executable\/","offensive_tool_keyword","C2 related tools","An anti-virus platform written in the Golang-Gin framework with built-in BypassAV methods such as separation and bundling.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Ed1s0nZ/cool","1","1","N/A","N/A","10","10","686","112","2023-07-13T07:04:30Z","2021-11-10T14:32:34Z","58483" +"*service/executable/compile.exe*",".{0,1000}service\/executable\/compile\.exe.{0,1000}","offensive_tool_keyword","C2 related tools","An anti-virus platform written in the Golang-Gin framework with built-in BypassAV methods such as separation and bundling.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Ed1s0nZ/cool","1","1","N/A","N/A","10","10","686","112","2023-07-13T07:04:30Z","2021-11-10T14:32:34Z","58484" +"*service::preshutdown*",".{0,1000}service\:\:preshutdown.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58485" +"*service_permissions_escalate.rb*",".{0,1000}service_permissions_escalate\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","58486" +"*ServiceHavoc.exe",".{0,1000}ServiceHavoc\.exe","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","58489" +"*servicemove*hid.dll*",".{0,1000}servicemove.{0,1000}hid\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","New Lateral Movement technique by abusing Windows Perception Simulation Service to achieve DLL hijacking code execution.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/ServiceMove-BOF","1","1","N/A","N/A","10","10","291","48","2022-02-23T07:17:38Z","2021-08-16T07:16:31Z","58490" +"*servpw.exe*",".{0,1000}servpw\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://gitlab.com/kalilinux/packages/windows-binaries/-/tree/kali/master/fgdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","58507" +"*servpw64.exe*",".{0,1000}servpw64\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://gitlab.com/kalilinux/packages/windows-binaries/-/tree/kali/master/fgdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","58508" +"*SeSecurityPrivilegePoC.exe*",".{0,1000}SeSecurityPrivilegePoC\.exe.{0,1000}","offensive_tool_keyword","PrivFu","PoCs for sensitive token privileges such SeDebugPrivilege","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","PrivilegedOperations","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","58509" +"*SeShutdownPrivilegePoC.exe*",".{0,1000}SeShutdownPrivilegePoC\.exe.{0,1000}","offensive_tool_keyword","PrivFu","PoCs for sensitive token privileges such SeDebugPrivilege","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","PrivilegedOperations","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","58510" +"*SESSID=../../../../*",".{0,1000}SESSID\=\.\.\/\.\.\/\.\.\/\.\.\/.{0,1000}","offensive_tool_keyword","POC","CVE-2024-3400 exploitation attempt","T1210.001 - T1068 - T1190","TA0001 - TA0002","N/A","N/A","Exploitation tool","https://x.com/HackingLZ/status/1780239802496864474","1","1","#linux","N/A","8","10","N/A","N/A","N/A","N/A","58511" +"*SessionGopher.ps1*",".{0,1000}SessionGopher\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","58512" +"*SeSystemEnvironmentPrivilegePoC.exe*",".{0,1000}SeSystemEnvironmentPrivilegePoC\.exe.{0,1000}","offensive_tool_keyword","PrivFu","PoCs for sensitive token privileges such SeDebugPrivilege","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","PrivilegedOperations","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","58513" +"*set_empty_pw.py*",".{0,1000}set_empty_pw\.py.{0,1000}","offensive_tool_keyword","POC","Zerologon CVE exploitation","T1210 - T1068","TA0001","N/A","N/A","Exploitation tool","https://github.com/risksense/zerologon","1","1","N/A","N/A","N/A","7","657","146","2020-10-15T18:31:15Z","2020-09-14T19:19:07Z","58554" +"*set_rpc_callstack*",".{0,1000}set_rpc_callstack.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","58562" +"*set_svchost_callstack*",".{0,1000}set_svchost_callstack.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","58564" +"*set_wmi_callstack*",".{0,1000}set_wmi_callstack.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","58565" +"*SeTakeOwnershipPrivilegePoC.exe*",".{0,1000}SeTakeOwnershipPrivilegePoC\.exe.{0,1000}","offensive_tool_keyword","PrivFu","PoCs for sensitive token privileges such SeDebugPrivilege","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","PrivilegedOperations","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","58604" +"*setc_webshell*",".{0,1000}setc_webshell.{0,1000}","offensive_tool_keyword","cobaltstrike","Bypass firewall for traffic forwarding using webshell. Pystinger implements SOCK4 proxy and port mapping through webshell. It can be directly used by metasploit-framework - viper- cobalt strike for session online.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/FunnyWolf/pystinger","1","1","N/A","N/A","10","10","1397","205","2021-09-29T13:13:43Z","2019-09-29T05:23:54Z","58605" +"*SeTcbPrivilegePoC.exe*",".{0,1000}SeTcbPrivilegePoC\.exe.{0,1000}","offensive_tool_keyword","PrivFu","PoCs for sensitive token privileges such SeDebugPrivilege","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","PrivilegedOperations","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","58607" +"*Set-DCShadowPermissions*",".{0,1000}Set\-DCShadowPermissions.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","DCShadow is an attack that masks certain actions by temporarily imitating a Domain Controller. If you have Domain Admin or Enterprise Admin privileges in a root domain it can be used for forest-level persistence.","T1550 - T1555 - T1212 - T1558","N/A","N/A","Black Basta","Exploitation tool","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","58615" +"*Set-DCShadowPermissions*",".{0,1000}Set\-DCShadowPermissions.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","58616" +"*Set-DCShadowPermissions*",".{0,1000}Set\-DCShadowPermissions.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","58617" +"*Set-DesktopACLToAllow*",".{0,1000}Set\-DesktopACLToAllow.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","58619" +"*Set-DesktopACLToAllowEveryone*",".{0,1000}Set\-DesktopACLToAllowEveryone.{0,1000}","offensive_tool_keyword","empire","Empire commands. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1155","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","58620" +"*Set-DomainObject*",".{0,1000}Set\-DomainObject.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Targeted kerberoasting by setting SPN","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","58624" +"*Seth-master.zip*",".{0,1000}Seth\-master\.zip.{0,1000}","offensive_tool_keyword","Seth","Perform a MitM attack and extract clear text credentials from RDP connections","T1557 - T1557.001 - T1110 - T1110.001 - T1071 - T1071.001","TA0006 ","N/A","N/A","Sniffing & Spoofing","https://github.com/SySS-Research/Seth","1","1","N/A","N/A","9","10","1423","323","2023-02-09T14:29:05Z","2017-03-10T15:46:38Z","58630" +"*setLoaderFlagZero*",".{0,1000}setLoaderFlagZero.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","58640" +"*Set-MacAttribute.ps1*",".{0,1000}Set\-MacAttribute\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1088","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","58641" +"*Set-MacroSecurityOff.ps1*",".{0,1000}Set\-MacroSecurityOff\.ps1.{0,1000}","offensive_tool_keyword","PowershellTools","Powershell tools used for Red Team / Pentesting","T1087.002 - T1069.001 - T1069.002 - T1598.002 - T1083 - T1558.003 - T1564.001 - T1112","TA0007 - TA0003 - TA0006 - TA0040 - TA0005 - TA0003","N/A","N/A","Exploitation tool","https://github.com/gustanini/PowershellTools","1","1","N/A","N/A","10","1","76","13","2024-01-08T10:33:20Z","2023-10-26T16:49:59Z","58643" +"*SetProcessInjection-main*",".{0,1000}SetProcessInjection\-main.{0,1000}","offensive_tool_keyword","SetProcessInjection","alternate technique allowing execution at an arbitrary memory address on a remote process that can be used to replace the standard CreateRemoteThread call.","T1055 - T1055.008 - T1055.001 - T1055.002 - T1055.012","TA0005 - TA0004 - TA0002","N/A","N/A","Defense Evasion","https://github.com/OtterHacker/SetProcessInjection","1","1","N/A","N/A","9","2","151","27","2023-10-02T09:23:42Z","2023-10-02T08:21:47Z","58658" +"*set-pushover-applicationtoken*",".{0,1000}set\-pushover\-applicationtoken.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","58660" +"*set-pushover-userkeys*",".{0,1000}set\-pushover\-userkeys.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","58661" +"*Set-RemotePSRemoting*",".{0,1000}Set\-RemotePSRemoting.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","58662" +"*Set-RemotePSRemoting.ps1*",".{0,1000}Set\-RemotePSRemoting\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","58663" +"*Set-RemoteShellAccess.ps1*",".{0,1000}Set\-RemoteShellAccess\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","58664" +"*Set-RemoteWMI.ps1*",".{0,1000}Set\-RemoteWMI\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","58665" +"*Set-RemoteWMI.ps1*",".{0,1000}Set\-RemoteWMI\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","58666" +"*SeTrustedCredManAccessPrivilegePoC.exe*",".{0,1000}SeTrustedCredManAccessPrivilegePoC\.exe.{0,1000}","offensive_tool_keyword","PrivFu","PoCs for sensitive token privileges such SeDebugPrivilege","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","PrivilegedOperations","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","58667" +"*Set-ServiceBinPath*",".{0,1000}Set\-ServiceBinPath.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerUp.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","58670" +"*setthreadcontext.x64*",".{0,1000}setthreadcontext\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","58678" +"*setthreadcontext.x86*",".{0,1000}setthreadcontext\.x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","58679" +"*setuid_setgid.py*",".{0,1000}setuid_setgid\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","58682" +"*setup_apfell.sh*",".{0,1000}setup_apfell\.sh.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","58684" +"*setup_obfuscate_xor_key*",".{0,1000}setup_obfuscate_xor_key.{0,1000}","offensive_tool_keyword","cobaltstrike","A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate. integrate. and enhance Cobalt Strike's evasion features!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/BokuLoader","1","1","N/A","N/A","10","10","1312","255","2023-11-22T22:25:50Z","2021-08-15T18:17:28Z","58693" +"*setup_reflective_loader*",".{0,1000}setup_reflective_loader.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","58695" +"*sevagas/macro_pack*",".{0,1000}sevagas\/macro_pack.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","58701" +"*seventeenman/CallBackDump*",".{0,1000}seventeenman\/CallBackDump.{0,1000}","offensive_tool_keyword","cobaltstrike","dump lsass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/seventeenman/CallBackDump","1","1","N/A","N/A","10","10","549","76","2023-07-20T09:03:33Z","2022-09-25T08:29:14Z","58702" +"*sfewer-r7/CVE-2023-27532*",".{0,1000}sfewer\-r7\/CVE\-2023\-27532.{0,1000}","offensive_tool_keyword","VeamHax","Exploit for CVE-2023-27532 against Veeam Backup & Replication (Plaintext credential leaking tool)","T1059 - T1203 - T1040 - T1189 - T1010","TA0001 - TA0002 - TA0009 - TA0011","More_eggs","Akira - FIN6","Exploitation tool","https://github.com/sfewer-r7/CVE-2023-27532","1","1","N/A","N/A","8","2","110","22","2023-03-23T18:03:27Z","2023-03-23T16:08:43Z","58703" +"*sfp_portscan_tcp.py*",".{0,1000}sfp_portscan_tcp\.py.{0,1000}","offensive_tool_keyword","spiderfoot","The OSINT Platform for Security Assessments","T1595 - T1595.002 - T1596 - T1591 - T1591.002","TA0043 ","N/A","N/A","Reconnaissance","https://www.spiderfoot.net/","1","1","N/A","N/A","6","10","N/A","N/A","N/A","N/A","58704" +"*sg.mirrors.cicku.me/blackarch/*/os/*",".{0,1000}sg\.mirrors\.cicku\.me\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","58707" +"*Sha-2-*512.unverified.test-vectors.txt*",".{0,1000}Sha\-2\-.{0,1000}512\.unverified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","58715" +"*Sha-2-256.unverified.test-vectors.txt*",".{0,1000}Sha\-2\-256\.unverified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","58716" +"*Sha-2-384.unverified.test-vectors.txt*",".{0,1000}Sha\-2\-384\.unverified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","58717" +"*shad0w.beacons.keys*",".{0,1000}shad0w\.beacons\.keys.{0,1000}","offensive_tool_keyword","shad0w","A post exploitation framework designed to operate covertly on heavily monitored environments","T1071 - T1090 - T1105 - T1571 - T1001","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/bats3c/shad0w","1","1","N/A","N/A","N/A","10","2090","332","2021-09-29T00:15:36Z","2020-04-28T16:42:07Z","58718" +"*shadawck/glit*",".{0,1000}shadawck\/glit.{0,1000}","offensive_tool_keyword","glit","Retrieve all mails of users related to a git repository a git user or a git organization","T1583 - T1059.001 - T1059.003","TA0002 - TA0003","N/A","N/A","Reconnaissance","https://github.com/shadawck/glit","1","1","N/A","N/A","8","1","49","7","2024-05-01T15:07:51Z","2022-11-14T11:25:10Z","58719" +"*shaddy43/BrowserSnatch*",".{0,1000}shaddy43\/BrowserSnatch.{0,1000}","offensive_tool_keyword","BrowserSnatch","steals important data from all chromium and gecko browsers installed in the system and gather the data in a stealer db to be exfiltrated out. A powerful Browser Stealer","T1081 - T1074 - T1114 - T1005 - T1041 - T1027","TA0006 - TA0009 - TA0010","N/A","N/A","Data Exfiltration","https://github.com/shaddy43/BrowserSnatch","1","1","N/A","N/A","10","3","246","39","2025-03-31T21:04:30Z","2024-08-26T18:38:42Z","58722" +"*shadow_copy.rb*",".{0,1000}shadow_copy\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","58723" +"*shadow1ng/fscan*",".{0,1000}shadow1ng\/fscan.{0,1000}","offensive_tool_keyword","fscan","Vulnerability scanner","T1595","TA0042 - TA0007","N/A","Earth Lusca","Reconnaissance","https://github.com/shadow1ng/fscan","1","1","N/A","N/A","8","10","11931","1725","2025-04-20T11:30:29Z","2020-11-13T16:35:20Z","58724" +"*shadowdump.*",".{0,1000}shadowdump\..{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","58733" +"*ShadowDumper.exe*",".{0,1000}ShadowDumper\.exe.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","1","N/A","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","58734" +"*ShadowForge.py*",".{0,1000}ShadowForge\.py.{0,1000}","offensive_tool_keyword","ShadowForgeC2","ShadowForge Command & Control - Harnessing the power of Zoom API - control a compromised Windows Machine from your Zoom Chats.","T1071.001 - T1569.002 - T1059.001","TA0011 - TA0002 - TA0040","N/A","N/A","C2","https://github.com/0xEr3bus/ShadowForgeC2","1","1","N/A","N/A","10","10","47","7","2023-07-15T11:45:36Z","2023-07-13T11:49:36Z","58735" +"*ShadowForgeC2-main*",".{0,1000}ShadowForgeC2\-main.{0,1000}","offensive_tool_keyword","ShadowForgeC2","ShadowForge Command & Control - Harnessing the power of Zoom API - control a compromised Windows Machine from your Zoom Chats.","T1071.001 - T1569.002 - T1059.001","TA0011 - TA0002 - TA0040","N/A","N/A","C2","https://github.com/0xEr3bus/ShadowForgeC2","1","1","N/A","N/A","10","10","47","7","2023-07-15T11:45:36Z","2023-07-13T11:49:36Z","58736" +"*ShadowHound-ADM.ps1*",".{0,1000}ShadowHound\-ADM\.ps1.{0,1000}","offensive_tool_keyword","ShadowHound","set of PowerShell scripts for Active Directory enumeration","T1087 - T1018 - T1482 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/Friends-Security/ShadowHound","1","1","N/A","N/A","8","4","345","36","2024-12-01T08:06:02Z","2024-11-21T15:01:14Z","58739" +"*ShadowHound-DS.ps1*",".{0,1000}ShadowHound\-DS\.ps1.{0,1000}","offensive_tool_keyword","ShadowHound","set of PowerShell scripts for Active Directory enumeration","T1087 - T1018 - T1482 - T1069","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/Friends-Security/ShadowHound","1","1","N/A","N/A","8","4","345","36","2024-12-01T08:06:02Z","2024-11-21T15:01:14Z","58742" +"*ShadowSpray.Asn1*",".{0,1000}ShadowSpray\.Asn1.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1110.003 - T1098 - T1059 - T1075","TA0001 - TA0008 - TA0009","N/A","Black Basta","Discovery","https://github.com/ShorSec/ShadowSpray","1","1","N/A","N/A","7","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","58759" +"*ShadowSpray.exe*",".{0,1000}ShadowSpray\.exe.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1110.003 - T1098 - T1059 - T1075","TA0001 - TA0008 - TA0009","N/A","Black Basta","Discovery","https://github.com/ShorSec/ShadowSpray","1","1","N/A","N/A","7","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","58761" +"*ShadowSpray.exe*",".{0,1000}ShadowSpray\.exe.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","1","N/A","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","58762" +"*ShadowSpray.sln*",".{0,1000}ShadowSpray\.sln.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1110.003 - T1098 - T1059 - T1075","TA0001 - TA0008 - TA0009","N/A","Black Basta","Discovery","https://github.com/ShorSec/ShadowSpray","1","1","N/A","N/A","7","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","58766" +"*ShadowSpray-master*",".{0,1000}ShadowSpray\-master.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1110.003 - T1098 - T1059 - T1075","TA0001 - TA0008 - TA0009","N/A","Black Basta","Discovery","https://github.com/ShorSec/ShadowSpray","1","1","N/A","N/A","7","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","58767" +"*ShadowStealer.zip*",".{0,1000}ShadowStealer\.zip.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","1","N/A","N/A","10","","N/A","","","","58768" +"*ShadowUser/scvhost.exe*",".{0,1000}ShadowUser\/scvhost\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","58769" +"*ShareAudit.v3.0.0.exe*",".{0,1000}ShareAudit\.v3\.0\.0\.exe.{0,1000}","offensive_tool_keyword","ShareAudit","A tool for auditing network shares in an Active Directory environment","T1135 - T1005 - T1083 - T1210","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/dionach/ShareAudit","1","1","N/A","N/A","8","1","42","15","2019-04-29T10:07:57Z","2019-02-26T16:00:15Z","58775" +"*ShareAudit.v3.0.1.exe*",".{0,1000}ShareAudit\.v3\.0\.1\.exe.{0,1000}","offensive_tool_keyword","ShareAudit","A tool for auditing network shares in an Active Directory environment","T1135 - T1005 - T1083 - T1210","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/dionach/ShareAudit","1","1","N/A","N/A","8","1","42","15","2019-04-29T10:07:57Z","2019-02-26T16:00:15Z","58776" +"*ShareAudit.v3.0.2.exe*",".{0,1000}ShareAudit\.v3\.0\.2\.exe.{0,1000}","offensive_tool_keyword","ShareAudit","A tool for auditing network shares in an Active Directory environment","T1135 - T1005 - T1083 - T1210","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/dionach/ShareAudit","1","1","N/A","N/A","8","1","42","15","2019-04-29T10:07:57Z","2019-02-26T16:00:15Z","58777" +"*ShareAudit-master.zip*",".{0,1000}ShareAudit\-master\.zip.{0,1000}","offensive_tool_keyword","ShareAudit","A tool for auditing network shares in an Active Directory environment","T1135 - T1005 - T1083 - T1210","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/dionach/ShareAudit","1","1","N/A","N/A","8","1","42","15","2019-04-29T10:07:57Z","2019-02-26T16:00:15Z","58778" +"*shareenum.py*",".{0,1000}shareenum\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","58779" +"*SharepointExploiter.ps1*",".{0,1000}SharepointExploiter\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","58781" +"*SharepointSiteExploiter.ps1*",".{0,1000}SharepointSiteExploiter\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","58782" +"*Shares/cme_spider_plus*",".{0,1000}Shares\/cme_spider_plus.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","58783" +"*Shares/finduncshar_*.txt*",".{0,1000}Shares\/finduncshar_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","58784" +"*Sharp_v4_x64*.bin*",".{0,1000}Sharp_v4_x64.{0,1000}\.bin.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","58805" +"*Sharp_v4_x86*.bin*",".{0,1000}Sharp_v4_x86.{0,1000}\.bin.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","58806" +"*SharpAdidnsdumpManager*",".{0,1000}SharpAdidnsdumpManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","58808" +"*SharpADWS.exe*",".{0,1000}SharpADWS\.exe.{0,1000}","offensive_tool_keyword","SharpADWS","SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)","T1087 - T1069 - T1018 - T1083 - T1595","TA0001 - TA0002 - TA0007","N/A","N/A","Discovery","https://github.com/wh0amitz/SharpADWS","1","1","N/A","N/A","7","6","538","59","2024-03-19T08:57:52Z","2024-02-13T17:28:00Z","58811" +"*SharpAllowedToAct.exe*",".{0,1000}SharpAllowedToAct\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58812" +"*sharpapplocker*",".{0,1000}sharpapplocker.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","58820" +"*SharpAppLocker.exe*",".{0,1000}SharpAppLocker\.exe.{0,1000}","offensive_tool_keyword","SharpAppLocker","Useful when you already bypassed AppLocker initially and you don't want to leave PS logs","T1086 - T1569.002 - T1070.003","TA0005 - TA0006","N/A","N/A","Defense Evasion","https://github.com/Flangvik/SharpAppLocker","1","1","N/A","N/A","7","1","99","16","2022-12-08T11:06:40Z","2020-08-01T12:58:36Z","58821" +"*SharpAppLocker.exe*",".{0,1000}SharpAppLocker\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58822" +"*SharpAzbelt-main*",".{0,1000}SharpAzbelt\-main.{0,1000}","offensive_tool_keyword","SharpAzbelt","This is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resources","T1082 - T1003 - T1027 - T1110 - T1078","TA0006 - TA0007 - TA0005 - TA0004 - TA0003","N/A","N/A","Discovery","https://github.com/redskal/SharpAzbelt","1","1","N/A","N/A","8","1","26","7","2023-09-21T21:47:32Z","2023-09-21T21:44:03Z","58825" +"*SharpBlackOut.csproj*",".{0,1000}SharpBlackOut\.csproj.{0,1000}","offensive_tool_keyword","SharpBlackout","Terminate AV/EDR leveraging BYOVD attack","T1562.001 - T1050.005","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/dmcxblue/SharpBlackout","1","1","N/A","N/A","10","1","83","20","2025-03-21T16:33:42Z","2023-08-23T14:16:40Z","58827" +"*SharpBlackout.exe*",".{0,1000}SharpBlackout\.exe.{0,1000}","offensive_tool_keyword","SharpBlackout","Terminate AV/EDR leveraging BYOVD attack","T1562.001 - T1050.005","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/dmcxblue/SharpBlackout","1","1","N/A","N/A","10","1","83","20","2025-03-21T16:33:42Z","2023-08-23T14:16:40Z","58828" +"*SharpBlackOut.pdb*",".{0,1000}SharpBlackOut\.pdb.{0,1000}","offensive_tool_keyword","SharpBlackout","Terminate AV/EDR leveraging BYOVD attack","T1562.001 - T1050.005","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/dmcxblue/SharpBlackout","1","1","N/A","N/A","10","1","83","20","2025-03-21T16:33:42Z","2023-08-23T14:16:40Z","58829" +"*SharpBlackOut.sln*",".{0,1000}SharpBlackOut\.sln.{0,1000}","offensive_tool_keyword","SharpBlackout","Terminate AV/EDR leveraging BYOVD attack","T1562.001 - T1050.005","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/dmcxblue/SharpBlackout","1","1","N/A","N/A","10","1","83","20","2025-03-21T16:33:42Z","2023-08-23T14:16:40Z","58830" +"*SharpBlackout-main*",".{0,1000}SharpBlackout\-main.{0,1000}","offensive_tool_keyword","SharpBlackout","Terminate AV/EDR leveraging BYOVD attack","T1562.001 - T1050.005","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/dmcxblue/SharpBlackout","1","1","N/A","N/A","10","1","83","20","2025-03-21T16:33:42Z","2023-08-23T14:16:40Z","58831" +"*SharpBlock.csproj*",".{0,1000}SharpBlock\.csproj.{0,1000}","offensive_tool_keyword","SharpBlock","A method of bypassing EDR active projection DLL by preventing entry point exection","T1070.004 - T1055.001 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/CCob/SharpBlock","1","1","N/A","N/A","10","10","1140","160","2021-03-31T09:44:48Z","2020-06-14T10:32:16Z","58833" +"*SharpBlock.exe*",".{0,1000}SharpBlock\.exe.{0,1000}","offensive_tool_keyword","SharpBlock","A method of bypassing EDR active projection DLL by preventing entry point exection","T1070.004 - T1055.001 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/CCob/SharpBlock","1","1","N/A","N/A","10","10","1140","160","2021-03-31T09:44:48Z","2020-06-14T10:32:16Z","58834" +"*SharpBlock.sln*",".{0,1000}SharpBlock\.sln.{0,1000}","offensive_tool_keyword","SharpBlock","A method of bypassing EDR active projection DLL by preventing entry point exection","T1070.004 - T1055.001 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/CCob/SharpBlock","1","1","N/A","N/A","10","10","1140","160","2021-03-31T09:44:48Z","2020-06-14T10:32:16Z","58835" +"*SharpBruteForceSSH.cs*",".{0,1000}SharpBruteForceSSH\.cs.{0,1000}","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","1","N/A","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","58836" +"*SharpBruteForceSSH.exe*",".{0,1000}SharpBruteForceSSH\.exe.{0,1000}","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","1","N/A","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","58837" +"*SharpBypassUAC*",".{0,1000}SharpBypassUAC.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Use SharpBypassUAC e.g. from a CobaltStrike beacon","T1558.001 - T1078.002 - T1550.003","TA0008 - TA0009 - TA0003","N/A","Black Basta","Exploitation tool","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","58839" +"*SharpBypassUAC*",".{0,1000}SharpBypassUAC.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","58840" +"*SharpBypassUAC.exe*",".{0,1000}SharpBypassUAC\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58841" +"*SharpC2*.cs*",".{0,1000}SharpC2.{0,1000}\.cs.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","58843" +"*SharpC2*.exe*",".{0,1000}SharpC2.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","58844" +"*sharpc2*client-windows.zip*",".{0,1000}sharpc2.{0,1000}client\-windows\.zip.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","58845" +"*SharpC2.*",".{0,1000}SharpC2\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","58846" +"*SharpC2.API*",".{0,1000}SharpC2\.API.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","58847" +"*SharpC2Event*",".{0,1000}SharpC2Event.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","58848" +"*SharpC2Hub*",".{0,1000}SharpC2Hub.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","58849" +"*SharpC2Webhook*",".{0,1000}SharpC2Webhook.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","58850" +"*SharpCalendar.exe*",".{0,1000}SharpCalendar\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike",".NET Assembly to Retrieve Outlook Calendar Details","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OG-Sadpanda/SharpCalendar","1","1","N/A","N/A","10","10","13","1","2021-10-07T19:42:20Z","2021-10-07T17:11:46Z","58851" +"*SharpCat.exe*",".{0,1000}SharpCat\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","C# alternative to the linux cat command... Prints file contents to console. For use with Cobalt Strike's Execute-Assembly","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OG-Sadpanda/SharpCat","1","1","N/A","N/A","10","10","16","3","2021-07-15T15:01:02Z","2021-07-15T14:57:53Z","58852" +"*SharpChisel*",".{0,1000}SharpChisel.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","58853" +"*SharpChisel.exe*",".{0,1000}SharpChisel\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58854" +"*SharpChrome.cs*",".{0,1000}SharpChrome\.cs.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58860" +"*SharpChrome.exe*",".{0,1000}SharpChrome\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58861" +"*SharpChromium.csproj*",".{0,1000}SharpChromium\.csproj.{0,1000}","offensive_tool_keyword","SharpChromium",".NET 4.0 CLR Project to retrieve Chromium data such as cookies - history and saved logins.","T1555.003 - T1114.001 - T1555.004","TA0006 - TA0003","N/A","COZY BEAR","Credential Access","https://github.com/djhohnstein/SharpChromium","1","1","N/A","N/A","10","8","712","100","2020-10-23T22:28:13Z","2018-08-06T21:25:21Z","58863" +"*SharpChromium.exe*",".{0,1000}SharpChromium\.exe.{0,1000}","offensive_tool_keyword","SharpChromium",".NET 4.0 CLR Project to retrieve Chromium data such as cookies - history and saved logins.","T1555.003 - T1114.001 - T1555.004","TA0006 - TA0003","N/A","COZY BEAR","Credential Access","https://github.com/djhohnstein/SharpChromium","1","1","N/A","N/A","10","8","712","100","2020-10-23T22:28:13Z","2018-08-06T21:25:21Z","58864" +"*SharpChromium.exe*",".{0,1000}SharpChromium\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58865" +"*SharpChromium.sln*",".{0,1000}SharpChromium\.sln.{0,1000}","offensive_tool_keyword","SharpChromium",".NET 4.0 CLR Project to retrieve Chromium data such as cookies - history and saved logins.","T1555.003 - T1114.001 - T1555.004","TA0006 - TA0003","N/A","COZY BEAR","Credential Access","https://github.com/djhohnstein/SharpChromium","1","1","N/A","N/A","10","8","712","100","2020-10-23T22:28:13Z","2018-08-06T21:25:21Z","58866" +"*SharpChromium-master*",".{0,1000}SharpChromium\-master.{0,1000}","offensive_tool_keyword","SharpChromium",".NET 4.0 CLR Project to retrieve Chromium data such as cookies - history and saved logins.","T1555.003 - T1114.001 - T1555.004","TA0006 - TA0003","N/A","COZY BEAR","Credential Access","https://github.com/djhohnstein/SharpChromium","1","1","N/A","N/A","10","8","712","100","2020-10-23T22:28:13Z","2018-08-06T21:25:21Z","58867" +"*SharpClipboard.exe*",".{0,1000}SharpClipboard\.exe.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","1","N/A","N/A","8","1","N/A","N/A","N/A","N/A","58868" +"*SharpClipboard-master.zip*",".{0,1000}SharpClipboard\-master\.zip.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","1","N/A","N/A","8","1","N/A","N/A","N/A","N/A","58869" +"*SharpClipHistory*",".{0,1000}SharpClipHistory.{0,1000}","offensive_tool_keyword","SharpClipHistory","SharpClipHistory is a .NET 4.5 application written in C# that can be used to read the contents of a users clipboard history in Windows 10 starting from the 1809 Build.","T1115 - T1113 - T1015 - T1053 - T1059","TA0003 - TA0007","N/A","N/A","Reconnaissance","https://github.com/FSecureLABS/SharpClipHistory","1","1","N/A","N/A","N/A","2","194","32","2020-01-23T13:39:13Z","2019-04-25T22:17:08Z","58870" +"*sharpcloud.cna*",".{0,1000}sharpcloud\.cna.{0,1000}","offensive_tool_keyword","SharpCloud","Simple C# for checking for the existence of credential files related to AWS - Microsoft Azure and Google Compute.","T1083 - T1059.001 - T1114.002","TA0007 - TA0002 ","N/A","N/A","Credential Access","https://github.com/chrismaddalena/SharpCloud","1","1","N/A","N/A","10","2","171","29","2018-09-18T02:24:10Z","2018-08-20T15:06:22Z","58871" +"*SharpCloud.csproj*",".{0,1000}SharpCloud\.csproj.{0,1000}","offensive_tool_keyword","SharpCloud","Simple C# for checking for the existence of credential files related to AWS - Microsoft Azure and Google Compute.","T1083 - T1059.001 - T1114.002","TA0007 - TA0002 ","N/A","N/A","Credential Access","https://github.com/chrismaddalena/SharpCloud","1","1","N/A","N/A","10","2","171","29","2018-09-18T02:24:10Z","2018-08-20T15:06:22Z","58872" +"*SharpCloud.exe*",".{0,1000}SharpCloud\.exe.{0,1000}","offensive_tool_keyword","SharpCloud","Simple C# for checking for the existence of credential files related to AWS - Microsoft Azure and Google Compute.","T1083 - T1059.001 - T1114.002","TA0007 - TA0002 ","N/A","N/A","Credential Access","https://github.com/chrismaddalena/SharpCloud","1","1","N/A","N/A","10","2","171","29","2018-09-18T02:24:10Z","2018-08-20T15:06:22Z","58873" +"*SharpCloud.exe*",".{0,1000}SharpCloud\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58874" +"*SharpCloud.sln*",".{0,1000}SharpCloud\.sln.{0,1000}","offensive_tool_keyword","SharpCloud","Simple C# for checking for the existence of credential files related to AWS - Microsoft Azure and Google Compute.","T1083 - T1059.001 - T1114.002","TA0007 - TA0002 ","N/A","N/A","Credential Access","https://github.com/chrismaddalena/SharpCloud","1","1","N/A","N/A","10","2","171","29","2018-09-18T02:24:10Z","2018-08-20T15:06:22Z","58875" +"*SharpCloud-master*",".{0,1000}SharpCloud\-master.{0,1000}","offensive_tool_keyword","SharpCloud","Simple C# for checking for the existence of credential files related to AWS - Microsoft Azure and Google Compute.","T1083 - T1059.001 - T1114.002","TA0007 - TA0002 ","N/A","N/A","Credential Access","https://github.com/chrismaddalena/SharpCloud","1","1","N/A","N/A","10","2","171","29","2018-09-18T02:24:10Z","2018-08-20T15:06:22Z","58876" +"*SharpCOM.exe*",".{0,1000}SharpCOM\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58877" +"*SharpCOMManager.cs*",".{0,1000}SharpCOMManager\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","58878" +"*sharpcompile*.exe*",".{0,1000}sharpcompile.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","SharpCompile is an aggressor script for Cobalt Strike which allows you to compile and execute C# in realtime. This is a more slick approach than manually compiling an .NET assembly and loading it into Cobalt Strike. The project aims to make it easier to move away from adhoc PowerShell execution instead creating a temporary assembly and executing ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/SpiderLabs/SharpCompile","1","1","N/A","N/A","10","10","291","58","2020-08-07T12:49:36Z","2018-11-01T17:18:52Z","58879" +"*sharpCompileHandler*",".{0,1000}sharpCompileHandler.{0,1000}","offensive_tool_keyword","cobaltstrike","SharpCompile is an aggressor script for Cobalt Strike which allows you to compile and execute C# in realtime. This is a more slick approach than manually compiling an .NET assembly and loading it into Cobalt Strike. The project aims to make it easier to move away from adhoc PowerShell execution instead creating a temporary assembly and executing ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/SpiderLabs/SharpCompile","1","1","N/A","N/A","10","10","291","58","2020-08-07T12:49:36Z","2018-11-01T17:18:52Z","58880" +"*SharpCompileServer*",".{0,1000}SharpCompileServer.{0,1000}","offensive_tool_keyword","cobaltstrike","SharpCompile is an aggressor script for Cobalt Strike which allows you to compile and execute C# in realtime. This is a more slick approach than manually compiling an .NET assembly and loading it into Cobalt Strike. The project aims to make it easier to move away from adhoc PowerShell execution instead creating a temporary assembly and executing ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/SpiderLabs/SharpCompile","1","1","N/A","N/A","10","10","291","58","2020-08-07T12:49:36Z","2018-11-01T17:18:52Z","58881" +"*SharpCompileServer.exe*",".{0,1000}SharpCompileServer\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","SharpCompile is an aggressor script for Cobalt Strike which allows you to compile and execute C# in realtime. This is a more slick approach than manually compiling an .NET assembly and loading it into Cobalt Strike. The project aims to make it easier to move away from adhoc PowerShell execution instead creating a temporary assembly and executing ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/SpiderLabs/SharpCompile","1","1","N/A","N/A","10","10","291","58","2020-08-07T12:49:36Z","2018-11-01T17:18:52Z","58882" +"*SharpConfigParser.dll*",".{0,1000}SharpConfigParser\.dll.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","58883" +"*SharpCookieMonster*",".{0,1000}SharpCookieMonster.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","58884" +"*sharpcookiemonster*",".{0,1000}sharpcookiemonster.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","58885" +"*SharpCookieMonster*WebSocket4Net.dll*",".{0,1000}SharpCookieMonster.{0,1000}WebSocket4Net\.dll.{0,1000}","offensive_tool_keyword","SharpCookieMonster","This C# project will dump cookies for all sites. even those with httpOnly/secure/session","T1539 - T1606","TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/m0rv4i/SharpCookieMonster","1","1","N/A","N/A","N/A","3","202","44","2023-03-15T09:51:09Z","2020-01-22T18:39:49Z","58886" +"*SharpCookieMonster.csproj*",".{0,1000}SharpCookieMonster\.csproj.{0,1000}","offensive_tool_keyword","SharpCookieMonster","This C# project will dump cookies for all sites. even those with httpOnly/secure/session","T1539 - T1606","TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/m0rv4i/SharpCookieMonster","1","1","N/A","N/A","N/A","3","202","44","2023-03-15T09:51:09Z","2020-01-22T18:39:49Z","58887" +"*SharpCookieMonster.exe*",".{0,1000}SharpCookieMonster\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58888" +"*SharpCookieMonster.exe*",".{0,1000}SharpCookieMonster\.exe.{0,1000}","offensive_tool_keyword","SharpCookieMonster","This C# project will dump cookies for all sites. even those with httpOnly/secure/session","T1539 - T1606","TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/m0rv4i/SharpCookieMonster","1","1","N/A","N/A","N/A","3","202","44","2023-03-15T09:51:09Z","2020-01-22T18:39:49Z","58889" +"*SharpCookieMonster.sln*",".{0,1000}SharpCookieMonster\.sln.{0,1000}","offensive_tool_keyword","SharpCookieMonster","This C# project will dump cookies for all sites. even those with httpOnly/secure/session","T1539 - T1606","TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/m0rv4i/SharpCookieMonster","1","1","N/A","N/A","N/A","3","202","44","2023-03-15T09:51:09Z","2020-01-22T18:39:49Z","58890" +"*SharpCookieMonsterOriginal.exe*",".{0,1000}SharpCookieMonsterOriginal\.exe.{0,1000}","offensive_tool_keyword","SharpCookieMonster","This C# project will dump cookies for all sites. even those with httpOnly/secure/session","T1539 - T1606","TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/m0rv4i/SharpCookieMonster","1","1","N/A","N/A","N/A","3","202","44","2023-03-15T09:51:09Z","2020-01-22T18:39:49Z","58891" +"*SharpCradle*logonpasswords*",".{0,1000}SharpCradle.{0,1000}logonpasswords.{0,1000}","offensive_tool_keyword","cobaltstrike","SharpCradle is a tool designed to help penetration testers or red teams download and execute .NET binaries into memory.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/anthemtotheego/SharpCradle","1","1","N/A","N/A","10","10","279","57","2020-12-30T17:15:51Z","2018-10-23T06:21:53Z","58892" +"*SharpCradle.exe*",".{0,1000}SharpCradle\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","SharpCradle is a tool designed to help penetration testers or red teams download and execute .NET binaries into memory.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/anthemtotheego/SharpCradle","1","1","N/A","N/A","10","10","279","57","2020-12-30T17:15:51Z","2018-10-23T06:21:53Z","58893" +"*SharpCradle.exe*",".{0,1000}SharpCradle\.exe.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","58894" +"*SharpCrashEventLog*",".{0,1000}SharpCrashEventLog.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","58895" +"*SharpCrashEventLog.exe*",".{0,1000}SharpCrashEventLog\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58896" +"*SharpDcomTrigger.exe*",".{0,1000}SharpDcomTrigger\.exe.{0,1000}","offensive_tool_keyword","SharpSystemTriggers","Collection of remote authentication triggers in C#","T1078 - T1059.001 - T1550","TA0008 ","N/A","N/A","Lateral Movement","https://github.com/cube0x0/SharpSystemTriggers","1","1","N/A","N/A","10","5","483","57","2024-05-15T21:24:56Z","2021-09-12T18:18:15Z","58897" +"*SharpDecryptPwd.exe*",".{0,1000}SharpDecryptPwd\.exe.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","1","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","58901" +"*SharpDecryptPwd.exe*",".{0,1000}SharpDecryptPwd\.exe.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","1","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","58902" +"*SharpDir.exe*",".{0,1000}SharpDir\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58905" +"*SharpDllProxy*",".{0,1000}SharpDllProxy.{0,1000}","offensive_tool_keyword","SharpDllProxy","Retrieves exported functions from a legitimate DLL and generates a proxy DLL source code/template for DLL proxy loading or sideloading","T1036 - T1036.005 - T1070 - T1070.004 - T1071 - T1574.002","TA0002 - TA0003 - TA0004","N/A","N/A","Defense Evasion","https://github.com/Flangvik/SharpDllProxy","1","1","N/A","N/A","N/A","8","792","102","2020-07-21T17:14:01Z","2020-07-12T10:46:48Z","58906" +"*SharpDomainSpray.*",".{0,1000}SharpDomainSpray\..{0,1000}","offensive_tool_keyword","SharpDomainSpray","Basic password spraying tool for internal tests and red teaming","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/HunnicCyber/SharpDomainSpray","1","1","N/A","N/A","10","1","90","18","2020-03-21T09:17:48Z","2019-06-05T10:47:05Z","58908" +"*SharpDomainSpray-master*",".{0,1000}SharpDomainSpray\-master.{0,1000}","offensive_tool_keyword","SharpDomainSpray","Basic password spraying tool for internal tests and red teaming","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/HunnicCyber/SharpDomainSpray","1","1","N/A","N/A","10","1","90","18","2020-03-21T09:17:48Z","2019-06-05T10:47:05Z","58909" +"*SharpDoor.exe*",".{0,1000}SharpDoor\.exe.{0,1000}","offensive_tool_keyword","SharpDoor","SharpDoor is alternative RDPWrap written in C# to allowed multiple RDP (Remote Desktop) sessions by patching termsrv.dll file.","T1059 - T1085 - T1070.004","TA0008 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/infosecn1nja/SharpDoor","1","1","N/A","N/A","7","4","311","61","2019-09-30T16:11:24Z","2019-09-29T02:24:07Z","58910" +"*SharpDoor-master*",".{0,1000}SharpDoor\-master.{0,1000}","offensive_tool_keyword","SharpDoor","SharpDoor is alternative RDPWrap written in C# to allowed multiple RDP (Remote Desktop) sessions by patching termsrv.dll file.","T1059 - T1085 - T1070.004","TA0008 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/infosecn1nja/SharpDoor","1","1","N/A","N/A","7","4","311","61","2019-09-30T16:11:24Z","2019-09-29T02:24:07Z","58912" +"*SharpDPAPI.csproj*",".{0,1000}SharpDPAPI\.csproj.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58923" +"*SharpDPAPI.exe*",".{0,1000}SharpDPAPI\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58925" +"*SharpDPAPI.exe*",".{0,1000}SharpDPAPI\.exe.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58926" +"*SharpDPAPI.exe*",".{0,1000}SharpDPAPI\.exe.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","58927" +"*SharpDPAPI.ps1*",".{0,1000}SharpDPAPI\.ps1.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58929" +"*SharpDPAPI.sln*",".{0,1000}SharpDPAPI\.sln.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58930" +"*SharpDPAPI.txt*",".{0,1000}SharpDPAPI\.txt.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58931" +"*SharpDPAPIMachine*.cs",".{0,1000}SharpDPAPIMachine.{0,1000}\.cs","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","58933" +"*SharpDPAPI-master*",".{0,1000}SharpDPAPI\-master.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58934" +"*SharpDump.exe*",".{0,1000}SharpDump\.exe.{0,1000}","offensive_tool_keyword","badrats","control tool (C2) using Python server - Jscript - Powershell and C# implants and communicates via HTTP(S) and SMB","T1059 - T1027 - T1573 - T1071 - T1105","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://gitlab.com/KevinJClark/badrats","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","58935" +"*SharpDump.exe*",".{0,1000}SharpDump\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58936" +"*SharpDump.exe*",".{0,1000}SharpDump\.exe.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","58937" +"*SharpDXWebcam*",".{0,1000}SharpDXWebcam.{0,1000}","offensive_tool_keyword","SharpDXWebcam","Utilizing DirectX and DShowNET assemblies to record video from a host's webcam","T1123 - T1059.001 - T1027.002","TA0009 - TA0005 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/snovvcrash/SharpDXWebcam","1","1","N/A","N/A","8","1","87","10","2023-07-19T21:09:00Z","2023-07-12T03:26:24Z","58938" +"*sharpedrchecker*",".{0,1000}sharpedrchecker.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","58939" +"*SharpEDRChecker.exe*",".{0,1000}SharpEDRChecker\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58940" +"*SharpEDRChecker.exe*",".{0,1000}SharpEDRChecker\.exe.{0,1000}","offensive_tool_keyword","SharpEDRChecker","Checks for the presence of known defensive products such as AV/EDR and logging tools","T1083 - T1518.001 - T1063","TA0007 - TA0005","N/A","N/A","Discovery","https://github.com/PwnDexter/SharpEDRChecker","1","1","N/A","N/A","8","8","706","98","2023-10-09T11:17:49Z","2020-06-16T10:25:00Z","58941" +"*SharpEDRChecker/releases*",".{0,1000}SharpEDRChecker\/releases.{0,1000}","offensive_tool_keyword","SharpEDRChecker","Checks for the presence of known defensive products such as AV/EDR and logging tools","T1083 - T1518.001 - T1063","TA0007 - TA0005","N/A","N/A","Discovery","https://github.com/PwnDexter/SharpEDRChecker","1","1","N/A","N/A","8","8","706","98","2023-10-09T11:17:49Z","2020-06-16T10:25:00Z","58943" +"*SharpEfsPotato.cs*",".{0,1000}SharpEfsPotato\.cs.{0,1000}","offensive_tool_keyword","SharpEfsPotato","Local privilege escalation from SeImpersonatePrivilege using EfsRpc.","T1548.002 - T1134.002","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/bugch3ck/SharpEfsPotato","1","1","N/A","N/A","10","4","317","46","2022-10-17T12:35:06Z","2022-10-17T12:20:47Z","58947" +"*SharpEfsPotato.exe*",".{0,1000}SharpEfsPotato\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpEfsPotato","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","58948" +"*SharpEfsPotato.exe*",".{0,1000}SharpEfsPotato\.exe.{0,1000}","offensive_tool_keyword","SharpEfsPotato","Local privilege escalation from SeImpersonatePrivilege using EfsRpc.","T1548.002 - T1134.002","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/bugch3ck/SharpEfsPotato","1","1","N/A","N/A","10","4","317","46","2022-10-17T12:35:06Z","2022-10-17T12:20:47Z","58949" +"*SharpEfsPotato.exe*",".{0,1000}SharpEfsPotato\.exe.{0,1000}","offensive_tool_keyword","SharpEfsPotato","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpEfsPotato","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","58950" +"*SharpEfsPotato.sln*",".{0,1000}SharpEfsPotato\.sln.{0,1000}","offensive_tool_keyword","SharpEfsPotato","Local privilege escalation from SeImpersonatePrivilege using EfsRpc.","T1548.002 - T1134.002","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/bugch3ck/SharpEfsPotato","1","1","N/A","N/A","10","4","317","46","2022-10-17T12:35:06Z","2022-10-17T12:20:47Z","58951" +"*SharpEfsPotato-master*",".{0,1000}SharpEfsPotato\-master.{0,1000}","offensive_tool_keyword","SharpEfsPotato","Local privilege escalation from SeImpersonatePrivilege using EfsRpc.","T1548.002 - T1134.002","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/bugch3ck/SharpEfsPotato","1","1","N/A","N/A","10","4","317","46","2022-10-17T12:35:06Z","2022-10-17T12:20:47Z","58952" +"*SharpEfsTriggeEfs.exe*",".{0,1000}SharpEfsTriggeEfs\.exe.{0,1000}","offensive_tool_keyword","SharpSystemTriggers","Collection of remote authentication triggers in C#","T1078 - T1059.001 - T1550","TA0008 ","N/A","N/A","Lateral Movement","https://github.com/cube0x0/SharpSystemTriggers","1","1","N/A","N/A","10","5","483","57","2024-05-15T21:24:56Z","2021-09-12T18:18:15Z","58953" +"*SharPersist.exe*",".{0,1000}SharPersist\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58956" +"*SharPersist.exe*",".{0,1000}SharPersist\.exe.{0,1000}","offensive_tool_keyword","SharPersist","SharPersist Windows persistence toolkit written in C#.","T1547 - T1053 - T1027 - T1028 - T1112","TA0003 - TA0008","N/A","N/A","Persistence","https://github.com/fireeye/SharPersist","1","1","N/A","N/A","10","10","1460","257","2023-08-11T00:52:09Z","2019-06-21T13:32:14Z","58957" +"*SharpEventLoader*",".{0,1000}SharpEventLoader.{0,1000}","offensive_tool_keyword","cobaltstrike","Persistence by writing/reading shellcode from Event Log","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/improsec/SharpEventPersist","1","1","N/A","N/A","10","10","371","50","2022-05-27T14:52:02Z","2022-05-20T14:52:56Z","58958" +"*SharpEventLoader*",".{0,1000}SharpEventLoader.{0,1000}","offensive_tool_keyword","SharpEventPersist","Persistence by writing/reading shellcode from Event Log","T1055 - T1070.001 - T1547.001","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/improsec/SharpEventPersist","1","1","N/A","N/A","10","10","371","50","2022-05-27T14:52:02Z","2022-05-20T14:52:56Z","58959" +"*SharpEventLoader.exe*",".{0,1000}SharpEventLoader\.exe.{0,1000}","offensive_tool_keyword","SharpEventPersist","Persistence by writing/reading shellcode from Event Log","T1055 - T1070.001 - T1547.001","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/improsec/SharpEventPersist","1","1","N/A","N/A","10","10","371","50","2022-05-27T14:52:02Z","2022-05-20T14:52:56Z","58960" +"*SharpEventPersist*",".{0,1000}SharpEventPersist.{0,1000}","offensive_tool_keyword","cobaltstrike","Persistence by writing/reading shellcode from Event Log","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/improsec/SharpEventPersist","1","1","N/A","N/A","10","10","371","50","2022-05-27T14:52:02Z","2022-05-20T14:52:56Z","58961" +"*SharpEventPersist*",".{0,1000}SharpEventPersist.{0,1000}","offensive_tool_keyword","SharpEventPersist","Persistence by writing/reading shellcode from Event Log","T1055 - T1070.001 - T1547.001","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/improsec/SharpEventPersist","1","1","N/A","N/A","10","10","371","50","2022-05-27T14:52:02Z","2022-05-20T14:52:56Z","58962" +"*SharpEventPersist.exe*",".{0,1000}SharpEventPersist\.exe.{0,1000}","offensive_tool_keyword","SharpEventPersist","Persistence by writing/reading shellcode from Event Log","T1055 - T1070.001 - T1547.001","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/improsec/SharpEventPersist","1","1","N/A","N/A","10","10","371","50","2022-05-27T14:52:02Z","2022-05-20T14:52:56Z","58963" +"*SharpEventPersist-main*",".{0,1000}SharpEventPersist\-main.{0,1000}","offensive_tool_keyword","SharpEventPersist","Persistence by writing/reading shellcode from Event Log","T1055 - T1070.001 - T1547.001","TA0003 - TA0005","N/A","N/A","Persistence","https://github.com/improsec/SharpEventPersist","1","1","N/A","N/A","10","10","371","50","2022-05-27T14:52:02Z","2022-05-20T14:52:56Z","58964" +"*SharpEvtMute.cs*",".{0,1000}SharpEvtMute\.cs.{0,1000}","offensive_tool_keyword","EvtMute","This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging - mute the event log","T1562.004 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/bats3c/EvtMute","1","1","N/A","N/A","10","3","261","51","2021-04-24T19:23:39Z","2020-08-29T00:13:20Z","58965" +"*SharpEvtMute.exe*",".{0,1000}SharpEvtMute\.exe.{0,1000}","offensive_tool_keyword","EvtMute","This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging - mute the event log","T1562.004 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/bats3c/EvtMute","1","1","N/A","N/A","10","3","261","51","2021-04-24T19:23:39Z","2020-08-29T00:13:20Z","58966" +"*SharpEvtMute.pdb*",".{0,1000}SharpEvtMute\.pdb.{0,1000}","offensive_tool_keyword","EvtMute","This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging - mute the event log","T1562.004 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/bats3c/EvtMute","1","1","N/A","N/A","10","3","261","51","2021-04-24T19:23:39Z","2020-08-29T00:13:20Z","58967" +"*SharpEvtMute.sln*",".{0,1000}SharpEvtMute\.sln.{0,1000}","offensive_tool_keyword","EvtMute","This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging - mute the event log","T1562.004 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/bats3c/EvtMute","1","1","N/A","N/A","10","3","261","51","2021-04-24T19:23:39Z","2020-08-29T00:13:20Z","58968" +"*SharpExcelibur*",".{0,1000}SharpExcelibur.{0,1000}","offensive_tool_keyword","cobaltstrike","Read Excel Spreadsheets (XLS/XLSX) using Cobalt Strike's Execute-Assembly","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OG-Sadpanda/SharpExcelibur","1","1","N/A","N/A","10","10","90","16","2024-09-30T14:28:20Z","2021-07-16T19:48:45Z","58969" +"*SharpExec.exe*",".{0,1000}SharpExec\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58971" +"*SharpExfiltrate.exe*",".{0,1000}SharpExfiltrate\.exe.{0,1000}","offensive_tool_keyword","SharpExfiltrate","Modular C# framework to exfiltrate loot over secure and trusted channels.","T1027 - T1567 - T1561","TA0010 - TA0040 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/Flangvik/SharpExfiltrate","1","1","N/A","N/A","10","2","126","37","2021-09-12T17:08:02Z","2021-09-08T13:17:00Z","58973" +"*SharpExfiltrate.sln*",".{0,1000}SharpExfiltrate\.sln.{0,1000}","offensive_tool_keyword","SharpExfiltrate","Modular C# framework to exfiltrate loot over secure and trusted channels.","T1027 - T1567 - T1561","TA0010 - TA0040 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/Flangvik/SharpExfiltrate","1","1","N/A","N/A","10","2","126","37","2021-09-12T17:08:02Z","2021-09-08T13:17:00Z","58974" +"*SharpExfiltrate-main*",".{0,1000}SharpExfiltrate\-main.{0,1000}","offensive_tool_keyword","SharpExfiltrate","Modular C# framework to exfiltrate loot over secure and trusted channels.","T1027 - T1567 - T1561","TA0010 - TA0040 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/Flangvik/SharpExfiltrate","1","1","N/A","N/A","10","2","126","37","2021-09-12T17:08:02Z","2021-09-08T13:17:00Z","58976" +"*SharpFtpC2*",".{0,1000}SharpFtpC2.{0,1000}","offensive_tool_keyword","SharpFtpC2","A Streamlined FTP-Driven Command and Control Conduit for Interconnecting Remote Systems.","T1572 - T1041 - T1105","TA0011 - TA0002 - TA0040","N/A","N/A","C2","https://github.com/DarkCoderSc/SharpFtpC2","1","1","N/A","N/A","10","10","88","15","2023-11-09T10:37:20Z","2023-06-09T12:41:28Z","58978" +"*SharpGen.dll*",".{0,1000}SharpGen\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","58979" +"*sharpgen.enable_cache*",".{0,1000}sharpgen\.enable_cache.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","58980" +"*sharpgen.py*",".{0,1000}sharpgen\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","58981" +"*sharpgen.set_location*",".{0,1000}sharpgen\.set_location.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","58982" +"*SharpGhost.exe*",".{0,1000}SharpGhost\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","58983" +"*SharpGhosting.exe*",".{0,1000}SharpGhosting\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","58984" +"*SharpGhostTask.csproj*",".{0,1000}SharpGhostTask\.csproj.{0,1000}","offensive_tool_keyword","SharpGhostTask","registry manipulation to create scheduled tasks without triggering the usual event logs.","T1053.005 - T1112 - T1564.001","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/dmcxblue/SharpGhostTask","1","1","N/A","N/A","10","2","114","12","2024-01-05T15:42:55Z","2024-01-04T21:42:33Z","58985" +"*SharpGhostTask.exe*",".{0,1000}SharpGhostTask\.exe.{0,1000}","offensive_tool_keyword","SharpGhostTask","registry manipulation to create scheduled tasks without triggering the usual event logs.","T1053.005 - T1112 - T1564.001","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/dmcxblue/SharpGhostTask","1","1","N/A","N/A","10","2","114","12","2024-01-05T15:42:55Z","2024-01-04T21:42:33Z","58986" +"*SharpGhostTask.sln*",".{0,1000}SharpGhostTask\.sln.{0,1000}","offensive_tool_keyword","SharpGhostTask","registry manipulation to create scheduled tasks without triggering the usual event logs.","T1053.005 - T1112 - T1564.001","TA0003 - TA0005","N/A","N/A","Defense Evasion","https://github.com/dmcxblue/SharpGhostTask","1","1","N/A","N/A","10","2","114","12","2024-01-05T15:42:55Z","2024-01-04T21:42:33Z","58987" +"*SharpGmailC2-main*",".{0,1000}SharpGmailC2\-main.{0,1000}","offensive_tool_keyword","SharpGmailC2","Gmail will act as Server and implant will exfiltrate data via smtp and will read commands from C2 (Gmail) via imap protocol","T1071 - T1071.004 - T1568 - T1568.002 - T1114 - T1114.001","TA0011 - TA0040 - TA0001","N/A","N/A","C2","https://github.com/reveng007/SharpGmailC2","1","1","N/A","N/A","10","10","260","47","2022-12-27T01:45:46Z","2022-11-10T06:48:15Z","58988" +"*SharpGPOAbuse*",".{0,1000}SharpGPOAbuse.{0,1000}","offensive_tool_keyword","SharpGPOAbuse","SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO.","T1546.008 - T1204 - T1134 ","TA0007 - TA0008 - TA0003 - TA0004 ","N/A","N/A","Defense Evasion","https://github.com/FSecureLABS/SharpGPOAbuse","1","1","N/A","N/A","N/A","10","1162","143","2020-12-15T14:48:31Z","2019-04-01T12:10:25Z","58989" +"*SharpGPOAbuse*",".{0,1000}SharpGPOAbuse.{0,1000}","offensive_tool_keyword","SharpGPOAbuse","SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a users edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO.","T1204 - T1484 - T1556 - T1574 - T1562","TA0002 - TA0007","N/A","N/A","Exploitation tool","https://github.com/FSecureLABS/SharpGPOAbuse","1","1","N/A","N/A","N/A","10","1162","143","2020-12-15T14:48:31Z","2019-04-01T12:10:25Z","58990" +"*SharpGPOAbuse.exe*",".{0,1000}SharpGPOAbuse\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpGPOAbuse","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","58991" +"*SharpGPOAbuse.exe*",".{0,1000}SharpGPOAbuse\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","58992" +"*SharpGPOAbuse.exe*",".{0,1000}SharpGPOAbuse\.exe.{0,1000}","offensive_tool_keyword","SharpGPOAbuse","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SharpGPOAbuse","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","58993" +"*SharpGPOAddComputer*",".{0,1000}SharpGPOAddComputer.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","58994" +"*SharpGPOAddLocalAdmin*",".{0,1000}SharpGPOAddLocalAdmin.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","58995" +"*SharpGPOAddUser*Manager*",".{0,1000}SharpGPOAddUser.{0,1000}Manager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","58996" +"*SharpGraphView.exe*",".{0,1000}SharpGraphView\.exe.{0,1000}","offensive_tool_keyword","SharpGraphView","Microsoft Graph API post-exploitation toolkit","T1078.004 - T1114.002","TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010","N/A","N/A","Discovery","https://github.com/mlcsec/SharpGraphView","1","1","N/A","N/A","6","1","94","9","2024-07-13T12:27:38Z","2024-05-04T11:23:42Z","58999" +"*Sharp-HackBrowserData*",".{0,1000}Sharp\-HackBrowserData.{0,1000}","offensive_tool_keyword","cobaltstrike","C# binary with embeded golang hack-browser-data","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/S3cur3Th1sSh1t/Sharp-HackBrowserData","1","1","N/A","N/A","10","10","96","17","2021-12-09T18:58:27Z","2020-12-06T12:28:47Z","59000" +"*Sharp-HackBrowserData*",".{0,1000}Sharp\-HackBrowserData.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555 - T1189 - T1217 - T1185","TA0002 - TA0009 - TA0001 - TA0010","N/A","N/A","Exploitation tool","https://github.com/moonD4rk/HackBrowserData","1","1","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","59001" +"*SharpHandler.exe*",".{0,1000}SharpHandler\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59002" +"*SharpHide.csproj*",".{0,1000}SharpHide\.csproj.{0,1000}","offensive_tool_keyword","SharpHide","Tool to create hidden registry keys","T1112 - T1562 - T1562.001","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/outflanknl/SharpHide","1","1","N/A","N/A","9","5","480","96","2019-10-23T10:44:22Z","2019-10-20T14:25:47Z","59004" +"*SharpHide.exe*",".{0,1000}SharpHide\.exe.{0,1000}","offensive_tool_keyword","SharpHide","Tool to create hidden registry keys","T1112 - T1562 - T1562.001","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/outflanknl/SharpHide","1","1","N/A","N/A","9","5","480","96","2019-10-23T10:44:22Z","2019-10-20T14:25:47Z","59005" +"*SharpHide.sln*",".{0,1000}SharpHide\.sln.{0,1000}","offensive_tool_keyword","SharpHide","Tool to create hidden registry keys","T1112 - T1562 - T1562.001","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/outflanknl/SharpHide","1","1","N/A","N/A","9","5","480","96","2019-10-23T10:44:22Z","2019-10-20T14:25:47Z","59006" +"*SharpHide-master*",".{0,1000}SharpHide\-master.{0,1000}","offensive_tool_keyword","SharpHide","Tool to create hidden registry keys","T1112 - T1562 - T1562.001","TA0005 - TA0003","N/A","N/A","Persistence","https://github.com/outflanknl/SharpHide","1","1","N/A","N/A","9","5","480","96","2019-10-23T10:44:22Z","2019-10-20T14:25:47Z","59007" +"*SharpHide-N*.exe*",".{0,1000}SharpHide\-N.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","59008" +"*SharpHose.exe*",".{0,1000}SharpHose\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59009" +"*SharpHound-*.zip*",".{0,1000}SharpHound\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","59014" +"*sharphound*--stealth*",".{0,1000}sharphound.{0,1000}\-\-stealth.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","59015" +"*sharphound.*",".{0,1000}sharphound\..{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","59016" +"*SharpHound.cna*",".{0,1000}SharpHound\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Aggressor scripts for use with Cobalt Strike 3.0+","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/C0axx/AggressorScripts","1","1","N/A","N/A","10","10","39","12","2019-10-08T12:00:53Z","2019-01-11T15:48:18Z","59017" +"*SharpHound.exe*",".{0,1000}SharpHound\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Aggressor scripts for use with Cobalt Strike 3.0+","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/C0axx/AggressorScripts","1","1","N/A","N/A","10","10","39","12","2019-10-08T12:00:53Z","2019-01-11T15:48:18Z","59019" +"*SharpHound.exe*",".{0,1000}SharpHound\.exe.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59020" +"*sharphound.exe*",".{0,1000}sharphound\.exe.{0,1000}","offensive_tool_keyword","RustHound","Active Directory data collector for BloodHound written in Rust","T1087.002 - T1018 - T1059.003","TA0007 - TA0001 - TA0002","N/A","N/A","Discovery","https://github.com/OPENCYBER-FR/RustHound","1","1","N/A","AD Enumeration","9","10","1013","98","2024-10-21T18:58:20Z","2022-10-12T05:54:35Z","59021" +"*SharpHound.exe*",".{0,1000}SharpHound\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59022" +"*SharpHound.exe*",".{0,1000}SharpHound\.exe.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","59023" +"*SharpHound.exe*",".{0,1000}SharpHound\.exe.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","59024" +"*SharpHound.ps1*",".{0,1000}SharpHound\.ps1.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","59026" +"*SharpHound.ps1*",".{0,1000}SharpHound\.ps1.{0,1000}","offensive_tool_keyword","cobaltstrike","Aggressor scripts for use with Cobalt Strike 3.0+","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/C0axx/AggressorScripts","1","1","N/A","N/A","10","10","39","12","2019-10-08T12:00:53Z","2019-01-11T15:48:18Z","59027" +"*SharpHound.ps1*",".{0,1000}SharpHound\.ps1.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59028" +"*SharpHound.ps1*",".{0,1000}SharpHound\.ps1.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1024 - T1071 - T1029 - T1569","TA0002 - TA0003 - TA0040","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","59029" +"*sharphound.ps1*",".{0,1000}sharphound\.ps1.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","59030" +"*SharpHound.ps1*",".{0,1000}SharpHound\.ps1.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","59031" +"*SharpHound.ps1*",".{0,1000}SharpHound\.ps1.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","59032" +"*SharpHound/releases/download/*",".{0,1000}SharpHound\/releases\/download\/.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","59034" +"*SharpHound2*",".{0,1000}SharpHound2.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","59035" +"*Sharphound2.*",".{0,1000}Sharphound2\..{0,1000}","offensive_tool_keyword","cobaltstrike","Aggressor scripts for use with Cobalt Strike 3.0+","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/C0axx/AggressorScripts","1","1","N/A","N/A","10","10","39","12","2019-10-08T12:00:53Z","2019-01-11T15:48:18Z","59036" +"*SharpHound3*",".{0,1000}SharpHound3.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","59037" +"*Sharphound-Aggressor*",".{0,1000}Sharphound\-Aggressor.{0,1000}","offensive_tool_keyword","cobaltstrike","Aggressor scripts for use with Cobalt Strike 3.0+","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/C0axx/AggressorScripts","1","1","N/A","N/A","10","10","39","12","2019-10-08T12:00:53Z","2019-01-11T15:48:18Z","59038" +"*SharpHoundCommon.*",".{0,1000}SharpHoundCommon\..{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","59039" +"*SharpHoundCommonLib*",".{0,1000}SharpHoundCommonLib.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","59040" +"*SharpHoundCommonLib.dll*",".{0,1000}SharpHoundCommonLib\.dll.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","59041" +"*SharpIncrease-main.zip*",".{0,1000}SharpIncrease\-main\.zip.{0,1000}","offensive_tool_keyword","SharpIncrease","binary padding to add junk data and change the on-disk representation of a file","T1480 - T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/mertdas/SharpIncrease","1","1","N/A","N/A","6","2","148","30","2024-06-28T21:36:46Z","2023-03-14T23:35:32Z","59045" +"*SharpInvoke-SMBExec*",".{0,1000}SharpInvoke\-SMBExec.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","59047" +"*SharpKatz.exe*",".{0,1000}SharpKatz\.exe.{0,1000}","offensive_tool_keyword","link","link is a command and control framework written in rust","T1071 - T1094 - T1132 - T1008 - T1024","TA0011 - TA0002 - TA0005","N/A","N/A","C2","https://github.com/postrequest/link","1","1","N/A","N/A","10","10","575","90","2021-08-18T11:53:55Z","2021-02-02T11:15:43Z","59049" +"*SharpKatz.exe*",".{0,1000}SharpKatz\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59050" +"*SharpKatz.exe*",".{0,1000}SharpKatz\.exe.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","59051" +"*SharpKatz.exe*",".{0,1000}SharpKatz\.exe.{0,1000}","offensive_tool_keyword","XiebroC2","Command and control server - multi-person collaborative penetration testing graphical framework","T1105 - T1573.001 - T1055.001 - T1071 - T1041 - T1059.001 - T1059.008 - T1102","TA0011 - TA0003 - TA0005 - TA0007 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/INotGreen/Xiebro-Plugins","1","1","N/A","N/A","10","10","46","8","2025-02-27T09:17:31Z","2024-02-18T02:01:06Z","59052" +"*SharpkatzManager*",".{0,1000}SharpkatzManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59053" +"*Sharp-Killer.csproj*",".{0,1000}Sharp\-Killer\.csproj.{0,1000}","offensive_tool_keyword","SharpKiller","Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8","T1211 - T1202 - T1218","TA0005","N/A","N/A","Defense Evasion","https://github.com/S1lkys/SharpKiller","1","1","N/A","N/A","10","4","349","45","2024-08-29T12:23:34Z","2023-10-21T17:27:59Z","59054" +"*Sharp-Killer.exe*",".{0,1000}Sharp\-Killer\.exe.{0,1000}","offensive_tool_keyword","SharpKiller","Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8","T1211 - T1202 - T1218","TA0005","N/A","N/A","Defense Evasion","https://github.com/S1lkys/SharpKiller","1","1","N/A","N/A","10","4","349","45","2024-08-29T12:23:34Z","2023-10-21T17:27:59Z","59055" +"*Sharp-Killer.pdb*",".{0,1000}Sharp\-Killer\.pdb.{0,1000}","offensive_tool_keyword","SharpKiller","Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8","T1211 - T1202 - T1218","TA0005","N/A","N/A","Defense Evasion","https://github.com/S1lkys/SharpKiller","1","1","N/A","N/A","10","4","349","45","2024-08-29T12:23:34Z","2023-10-21T17:27:59Z","59056" +"*SharpKiller-main*",".{0,1000}SharpKiller\-main.{0,1000}","offensive_tool_keyword","SharpKiller","Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8","T1211 - T1202 - T1218","TA0005","N/A","N/A","Defense Evasion","https://github.com/S1lkys/SharpKiller","1","1","N/A","N/A","10","4","349","45","2024-08-29T12:23:34Z","2023-10-21T17:27:59Z","59057" +"*SharpLAPS.csproj*",".{0,1000}SharpLAPS\.csproj.{0,1000}","offensive_tool_keyword","SharpLAPS","Retrieve LAPS password from LDAP","T1552.005 - T1212","TA0006 - TA0007","N/A","Dispossessor","Credential Access","https://github.com/swisskyrepo/SharpLAPS","1","1","N/A","N/A","10","5","408","85","2021-02-17T14:32:16Z","2021-02-16T17:27:41Z","59058" +"*SharpLAPS.exe*",".{0,1000}SharpLAPS\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59059" +"*SharpLAPS.exe*",".{0,1000}SharpLAPS\..{0,1000}","offensive_tool_keyword","SharpLAPS","Retrieve LAPS password from LDAP","T1552.005 - T1212","TA0006 - TA0007","N/A","Dispossessor","Credential Access","https://github.com/swisskyrepo/SharpLAPS","1","1","N/A","N/A","10","5","408","85","2021-02-17T14:32:16Z","2021-02-16T17:27:41Z","59060" +"*SharpLAPS.sln*",".{0,1000}SharpLAPS\.sln.{0,1000}","offensive_tool_keyword","SharpLAPS","Retrieve LAPS password from LDAP","T1552.005 - T1212","TA0006 - TA0007","N/A","Dispossessor","Credential Access","https://github.com/swisskyrepo/SharpLAPS","1","1","N/A","N/A","10","5","408","85","2021-02-17T14:32:16Z","2021-02-16T17:27:41Z","59061" +"*SharpLDAP.csproj*",".{0,1000}SharpLDAP\.csproj.{0,1000}","offensive_tool_keyword","SharpLDAP","tool written in C# that aims to do enumeration via LDAP queries","T1018 - T1069.003","TA0007 - TA0011","N/A","N/A","Discovery","https://github.com/mertdas/SharpLDAP","1","1","N/A","N/A","8","1","0","1","2023-01-14T21:52:36Z","2022-11-16T00:38:43Z","59063" +"*SharpLDAP.exe*",".{0,1000}SharpLDAP\.exe.{0,1000}","offensive_tool_keyword","SharpLDAP","tool written in C# that aims to do enumeration via LDAP queries","T1018 - T1069.003","TA0007 - TA0011","N/A","N/A","Discovery","https://github.com/mertdas/SharpLDAP","1","1","N/A","N/A","8","1","0","1","2023-01-14T21:52:36Z","2022-11-16T00:38:43Z","59064" +"*SharpLDAP.sln*",".{0,1000}SharpLDAP\.sln.{0,1000}","offensive_tool_keyword","SharpLDAP","tool written in C# that aims to do enumeration via LDAP queries","T1018 - T1069.003","TA0007 - TA0011","N/A","N/A","Discovery","https://github.com/mertdas/SharpLDAP","1","1","N/A","N/A","8","1","0","1","2023-01-14T21:52:36Z","2022-11-16T00:38:43Z","59065" +"*SharpLDAP-main*",".{0,1000}SharpLDAP\-main.{0,1000}","offensive_tool_keyword","SharpLDAP","tool written in C# that aims to do enumeration via LDAP queries","T1018 - T1069.003","TA0007 - TA0011","N/A","N/A","Discovery","https://github.com/mertdas/SharpLDAP","1","1","N/A","N/A","8","1","0","1","2023-01-14T21:52:36Z","2022-11-16T00:38:43Z","59066" +"*SharpLdapRelayScan*",".{0,1000}SharpLdapRelayScan.{0,1000}","offensive_tool_keyword","SharpLdapRelayScan","SharLdapRealyScan is a tool to check Domain Controllers for LDAP server protections regarding the relay of NTLM authenticationvand it's a C# port of?LdapRelayScan","T1557.001 - T1078.003 - T1046","TA0002 - TA0007 - TA0040","N/A","N/A","Discovery","https://github.com/klezVirus/SharpLdapRelayScan","1","1","N/A","network exploitation tool","7","1","81","18","2022-02-26T22:03:11Z","2022-02-12T08:16:59Z","59067" +"*SharpLdapRelayScan*",".{0,1000}SharpLdapRelayScan.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","59068" +"*SharpMapExec.exe*",".{0,1000}SharpMapExec\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59069" +"*SharpMapExec-main.zip*",".{0,1000}SharpMapExec\-main\.zip.{0,1000}","offensive_tool_keyword","SharpMapExec","A sharpen version of CrackMapExec","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/cube0x0/SharpMapExec","1","1","N/A","N/A","10","7","664","124","2021-11-17T17:53:12Z","2020-12-01T13:03:50Z","59070" +"*SharpMiniDump*",".{0,1000}SharpMiniDump.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59071" +"*SharpMiniDump.exe*",".{0,1000}SharpMiniDump\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59072" +"*SharpMiniDump.exe*",".{0,1000}SharpMiniDump\.exe.{0,1000}","offensive_tool_keyword","SharpMiniDump","Create a minidump of the LSASS process from memory","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/b4rtik/SharpMiniDump","1","1","N/A","N/A","10","3","260","49","2022-11-02T15:47:30Z","2019-09-15T13:45:42Z","59073" +"*SharpMiniDumpManager*",".{0,1000}SharpMiniDumpManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59074" +"*SharpMove.exe*",".{0,1000}SharpMove\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59075" +"*SharpNamedPipePTH*",".{0,1000}SharpNamedPipePTH.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","59076" +"*SharpNamedPipePTH.exe*",".{0,1000}SharpNamedPipePTH\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59077" +"*SharpNBTScan.exe*",".{0,1000}SharpNBTScan\.exe.{0,1000}","offensive_tool_keyword","SharpNBTScan","a NetBIOS scanner. Ghost actors use this tool for hostname and IP address enumeration","T1018 - T1046","TA0007","Ghost Ransomware","N/A","Discovery","https://github.com/BronzeTicket/SharpNBTScan","1","1","N/A","N/A","7","1","71","4","2021-08-06T05:36:55Z","2021-07-12T08:57:39Z","59078" +"*SharpNoPSExec*",".{0,1000}SharpNoPSExec.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","59079" +"*SharpNoPSExec.csproj*",".{0,1000}SharpNoPSExec\.csproj.{0,1000}","offensive_tool_keyword","SharpNoPSExec","Get file less command execution for Lateral Movement.","T1021.006 - T1059.003 - T1105","TA0008 - TA0002 - TA0011","N/A","N/A","Lateral Movement","https://github.com/juliourena/SharpNoPSExec","1","1","N/A","N/A","10","7","615","90","2022-06-03T10:32:55Z","2021-04-24T22:02:38Z","59080" +"*SharpNoPSExec.exe*",".{0,1000}SharpNoPSExec\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59081" +"*SharpNoPSExec.exe*",".{0,1000}SharpNoPSExec\.exe.{0,1000}","offensive_tool_keyword","SharpNoPSExec","Get file less command execution for Lateral Movement.","T1021.006 - T1059.003 - T1105","TA0008 - TA0002 - TA0011","N/A","N/A","Lateral Movement","https://github.com/juliourena/SharpNoPSExec","1","1","N/A","N/A","10","7","615","90","2022-06-03T10:32:55Z","2021-04-24T22:02:38Z","59082" +"*SharpNoPSExec.sln*",".{0,1000}SharpNoPSExec\.sln.{0,1000}","offensive_tool_keyword","SharpNoPSExec","Get file less command execution for Lateral Movement.","T1021.006 - T1059.003 - T1105","TA0008 - TA0002 - TA0011","N/A","N/A","Lateral Movement","https://github.com/juliourena/SharpNoPSExec","1","1","N/A","N/A","10","7","615","90","2022-06-03T10:32:55Z","2021-04-24T22:02:38Z","59083" +"*SharpNoPSExec-master*",".{0,1000}SharpNoPSExec\-master.{0,1000}","offensive_tool_keyword","SharpNoPSExec","Get file less command execution for Lateral Movement.","T1021.006 - T1059.003 - T1105","TA0008 - TA0002 - TA0011","N/A","N/A","Lateral Movement","https://github.com/juliourena/SharpNoPSExec","1","1","N/A","N/A","10","7","615","90","2022-06-03T10:32:55Z","2021-04-24T22:02:38Z","59084" +"*SharpPrinter.exe*",".{0,1000}SharpPrinter\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59089" +"*SharpPrintNightmare*",".{0,1000}SharpPrintNightmare.{0,1000}","offensive_tool_keyword","SharpPrintNightmare","C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527","T1210 - T1574 - T1204 - T1053 - T1021 - T1068 - T1071","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Exploitation tool","https://github.com/cube0x0/CVE-2021-1675","1","1","N/A","N/A","N/A","10","1879","582","2021-07-20T15:28:13Z","2021-06-29T17:24:14Z","59090" +"*SharpPrintNightmare.exe*",".{0,1000}SharpPrintNightmare\.exe.{0,1000}","offensive_tool_keyword","PrintNightmare","PrintNightmare exploitation","T1210 - T1059.001 - T1548.002","TA0001 - TA0002 - TA0004","N/A","Dispossessor","Privilege Escalation","https://github.com/cube0x0/CVE-2021-1675","1","1","N/A","N/A","10","10","1879","582","2021-07-20T15:28:13Z","2021-06-29T17:24:14Z","59091" +"*sharppsexec*",".{0,1000}sharppsexec.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59094" +"*SharpPsExecManager*",".{0,1000}SharpPsExecManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59095" +"*SharpPsExecService.*",".{0,1000}SharpPsExecService\..{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59096" +"*SharpRDP.*.dll.bin*",".{0,1000}SharpRDP\..{0,1000}\.dll\.bin.{0,1000}","offensive_tool_keyword","SharpRDP","Remote Desktop Protocol .NET Console Application for Authenticated Command Execution","T1021.001 - T1059.001 - T1059.003","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/0xthirteen/SharpRDP","1","1","N/A","N/A","10","10","1041","554","2022-11-13T05:29:33Z","2020-01-21T08:31:50Z","59097" +"*SharpRDP.csproj*",".{0,1000}SharpRDP\.csproj.{0,1000}","offensive_tool_keyword","SharpRDP","Remote Desktop Protocol .NET Console Application for Authenticated Command Execution","T1021.001 - T1059.001 - T1059.003","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/0xthirteen/SharpRDP","1","1","N/A","N/A","10","10","1041","554","2022-11-13T05:29:33Z","2020-01-21T08:31:50Z","59098" +"*SharpRDP.exe*",".{0,1000}SharpRDP\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59099" +"*SharpRDP.exe*",".{0,1000}SharpRDP\.exe.{0,1000}","offensive_tool_keyword","SharpRDP","Remote Desktop Protocol .NET Console Application for Authenticated Command Execution","T1021.001 - T1059.001 - T1059.003","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/0xthirteen/SharpRDP","1","1","N/A","N/A","10","10","1041","554","2022-11-13T05:29:33Z","2020-01-21T08:31:50Z","59100" +"*SharpRDP.sln*",".{0,1000}SharpRDP\.sln.{0,1000}","offensive_tool_keyword","SharpRDP","Remote Desktop Protocol .NET Console Application for Authenticated Command Execution","T1021.001 - T1059.001 - T1059.003","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/0xthirteen/SharpRDP","1","1","N/A","N/A","10","10","1041","554","2022-11-13T05:29:33Z","2020-01-21T08:31:50Z","59101" +"*SharpRDPHijack.cs*",".{0,1000}SharpRDPHijack\.cs.{0,1000}","offensive_tool_keyword","SharpRDPHijack","SharpRDPHijack is a proof-of-concept .NET/C# Remote Desktop Protocol (RDP) session hijack utility for disconnected sessions","T1021.001 - T1078.003 - T1059.001","TA0002 - TA0008 - TA0006","N/A","N/A","Lateral Movement","https://github.com/bohops/SharpRDPHijack","1","1","N/A","N/A","10","5","480","80","2024-11-28T06:08:58Z","2020-07-06T02:59:46Z","59102" +"*SharpRDPHijack.exe*",".{0,1000}SharpRDPHijack\.exe.{0,1000}","offensive_tool_keyword","SharpRDPHijack","SharpRDPHijack is a proof-of-concept .NET/C# Remote Desktop Protocol (RDP) session hijack utility for disconnected sessions","T1021.001 - T1078.003 - T1059.001","TA0002 - TA0008 - TA0006","N/A","N/A","Lateral Movement","https://github.com/bohops/SharpRDPHijack","1","1","N/A","N/A","10","5","480","80","2024-11-28T06:08:58Z","2020-07-06T02:59:46Z","59103" +"*SharpRDPHijack-master*",".{0,1000}SharpRDPHijack\-master.{0,1000}","offensive_tool_keyword","SharpRDPHijack","SharpRDPHijack is a proof-of-concept .NET/C# Remote Desktop Protocol (RDP) session hijack utility for disconnected sessions","T1021.001 - T1078.003 - T1059.001","TA0002 - TA0008 - TA0006","N/A","N/A","Lateral Movement","https://github.com/bohops/SharpRDPHijack","1","1","N/A","N/A","10","5","480","80","2024-11-28T06:08:58Z","2020-07-06T02:59:46Z","59104" +"*SharpRDP-master*",".{0,1000}SharpRDP\-master.{0,1000}","offensive_tool_keyword","SharpRDP","Remote Desktop Protocol .NET Console Application for Authenticated Command Execution","T1021.001 - T1059.001 - T1059.003","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/0xthirteen/SharpRDP","1","1","N/A","N/A","10","10","1041","554","2022-11-13T05:29:33Z","2020-01-21T08:31:50Z","59105" +"*SharpRDPThief.csproj*",".{0,1000}SharpRDPThief\.csproj.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","1","N/A","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","59107" +"*SharpRDPThief.exe*",".{0,1000}SharpRDPThief\.exe.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","1","N/A","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","59108" +"*SharpReg.exe*",".{0,1000}SharpReg\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59110" +"*SharpRoast.exe*",".{0,1000}SharpRoast\.exe.{0,1000}","offensive_tool_keyword","Ghostpack-CompiledBinaries","Compiled Binaries for Ghostpack","T1140 - T1559.002 - T1547.002 - T1055 - T1036.004","TA0005 - TA0002 - TA0040 - TA0036","N/A","N/A","Exploitation tool","https://github.com/r3motecontrol/Ghostpack-CompiledBinaries","1","1","N/A","N/A","N/A","10","1313","237","2024-10-24T21:58:54Z","2018-07-25T23:38:15Z","59111" +"*SharpRoast.exe*",".{0,1000}SharpRoast\.exe.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","59112" +"*SharpRODC.exe*",".{0,1000}SharpRODC\.exe.{0,1000}","offensive_tool_keyword","SharpRODC","audit the security of read-only domain controllers","T1012 - T1482 - T1207 - T1208 - T1209 - T1212","TA0007 - TA0008 - TA0006","N/A","N/A","Discovery","https://github.com/wh0amitz/SharpRODC","1","1","N/A","N/A","8","2","115","8","2023-11-27T12:41:52Z","2023-11-24T14:35:49Z","59113" +"*SharpSAMDump.exe*",".{0,1000}SharpSAMDump\.exe.{0,1000}","offensive_tool_keyword","SharpSAMDump","SAM dumping via the registry in C#/.NET","T1003.002 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/jojonas/SharpSAMDump","1","1","N/A","N/A","10","1","48","8","2025-01-16T07:08:58Z","2024-05-27T10:53:27Z","59115" +"*SharpSCCM*",".{0,1000}SharpSCCM.{0,1000}","offensive_tool_keyword","SharpSCCM","SharpSCCM is a post-exploitation tool designed to leverage Microsoft Endpoint Configuration Manager (a.k.a. ConfigMgr. formerly SCCM) for Lateral Movement and credential gathering without requiring access to the SCCM administration console GUI","T1078 - T1077 - T1547.001 - T1021.001 - T1087 - T1555.003","TA0008 - TA0006 - TA0003 - TA0011","N/A","N/A","Lateral Movement","https://github.com/Mayyhem/SharpSCCM/","1","1","N/A","N/A","10","7","626","94","2024-09-16T14:57:49Z","2021-08-19T05:09:19Z","59117" +"*SharpSCCM.csproj*",".{0,1000}SharpSCCM\.csproj.{0,1000}","offensive_tool_keyword","SharpSCCM","SharpSCCM is a post-exploitation tool designed to leverage Microsoft Endpoint Configuration Manager (a.k.a. ConfigMgr. formerly SCCM) for Lateral Movement and credential gathering without requiring access to the SCCM administration console GUI","T1078 - T1077 - T1547.001 - T1021.001 - T1087 - T1555.003","TA0008 - TA0006 - TA0003 - TA0011","N/A","N/A","Lateral Movement","https://github.com/Mayyhem/SharpSCCM/","1","1","N/A","N/A","10","7","626","94","2024-09-16T14:57:49Z","2021-08-19T05:09:19Z","59118" +"*SharpSCCM.exe*",".{0,1000}SharpSCCM\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59119" +"*SharpSCCM.exe*",".{0,1000}SharpSCCM\.exe.{0,1000}","offensive_tool_keyword","SharpSCCM","SharpSCCM is a post-exploitation tool designed to leverage Microsoft Endpoint Configuration Manager (a.k.a. ConfigMgr. formerly SCCM) for Lateral Movement and credential gathering without requiring access to the SCCM administration console GUI","T1078 - T1077 - T1547.001 - T1021.001 - T1087 - T1555.003","TA0008 - TA0006 - TA0003 - TA0011","N/A","N/A","Lateral Movement","https://github.com/Mayyhem/SharpSCCM/","1","1","N/A","N/A","10","7","626","94","2024-09-16T14:57:49Z","2021-08-19T05:09:19Z","59120" +"*SharpSCCM_merged.exe*",".{0,1000}SharpSCCM_merged\.exe.{0,1000}","offensive_tool_keyword","SharpSCCM","SharpSCCM is a post-exploitation tool designed to leverage Microsoft Endpoint Configuration Manager (a.k.a. ConfigMgr. formerly SCCM) for Lateral Movement and credential gathering without requiring access to the SCCM administration console GUI","T1078 - T1077 - T1547.001 - T1021.001 - T1087 - T1555.003","TA0008 - TA0006 - TA0003 - TA0011","N/A","N/A","Lateral Movement","https://github.com/Mayyhem/SharpSCCM/","1","1","N/A","N/A","10","7","626","94","2024-09-16T14:57:49Z","2021-08-19T05:09:19Z","59122" +"*SharpSCShell*",".{0,1000}SharpSCShell.{0,1000}","offensive_tool_keyword","cobaltstrike","Fileless Lateral Movement tool that relies on ChangeServiceConfigA to run command","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/SCShell","1","1","N/A","N/A","10","10","1484","248","2023-07-10T01:31:54Z","2019-11-13T23:39:27Z","59123" +"*SharpSearch.exe*",".{0,1000}SharpSearch\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59124" +"*SharpSecDump.csproj*",".{0,1000}SharpSecDump\.csproj.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","1","N/A","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","59126" +"*SharpSecDump.exe*",".{0,1000}SharpSecDump\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59127" +"*SharpSecDump.exe*",".{0,1000}SharpSecDump\.exe.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","1","N/A","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","59128" +"*SharpSecDump.sln*",".{0,1000}SharpSecDump\.sln.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","1","N/A","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","59129" +"*SharpSecDump-master*",".{0,1000}SharpSecDump\-master.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","1","N/A","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","59130" +"*sharpsecretsdump*",".{0,1000}sharpsecretsdump.{0,1000}","offensive_tool_keyword","CSExec","An alternative to *exec.py from impacket with some builtin tricks","T1059.001 - T1059.005 - T1071.001","TA0002","N/A","N/A","Lateral Movement","https://github.com/Metro-Holografix/CSExec.py","1","1","N/A","private github repo","10","","N/A","","","","59131" +"*SharpShares.csproj*",".{0,1000}SharpShares\.csproj.{0,1000}","offensive_tool_keyword","SharpShares","Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain","T1046 - T1135","TA0007 - TA0001","N/A","Black Basta - BlackSuit - Royal - BianLian - Fog","Discovery","https://github.com/Hackcraft-Labs/SharpShares","1","1","N/A","N/A","10","1","33","7","2023-11-13T14:08:07Z","2023-10-25T10:34:18Z","59132" +"*SharpShares.exe*",".{0,1000}SharpShares\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59133" +"*SharpShares.exe*",".{0,1000}SharpShares\.exe.{0,1000}","offensive_tool_keyword","SharpShares","Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain","T1046 - T1135","TA0007 - TA0001","N/A","Black Basta - BlackSuit - Royal - BianLian - Fog","Discovery","https://github.com/Hackcraft-Labs/SharpShares","1","1","N/A","N/A","10","1","33","7","2023-11-13T14:08:07Z","2023-10-25T10:34:18Z","59134" +"*SharpShares.sln*",".{0,1000}SharpShares\.sln.{0,1000}","offensive_tool_keyword","SharpShares","Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain","T1046 - T1135","TA0007 - TA0001","N/A","Black Basta - BlackSuit - Royal - BianLian - Fog","Discovery","https://github.com/Hackcraft-Labs/SharpShares","1","1","N/A","N/A","10","1","33","7","2023-11-13T14:08:07Z","2023-10-25T10:34:18Z","59135" +"*SharpShellPipe.exe*",".{0,1000}SharpShellPipe\.exe.{0,1000}","offensive_tool_keyword","SharpShellPipe","interactive remote shell access via named pipes and the SMB protocol.","T1056.002 - T1021.002 - T1059.001","TA0005 - TA0009 - TA0002","N/A","N/A","Lateral Movement","https://github.com/DarkCoderSc/SharpShellPipe","1","1","N/A","N/A","8","2","118","14","2025-02-21T12:33:43Z","2023-08-25T15:18:30Z","59136" +"*SharpShellPipe.sln*",".{0,1000}SharpShellPipe\.sln.{0,1000}","offensive_tool_keyword","SharpShellPipe","interactive remote shell access via named pipes and the SMB protocol.","T1056.002 - T1021.002 - T1059.001","TA0005 - TA0009 - TA0002","N/A","N/A","Lateral Movement","https://github.com/DarkCoderSc/SharpShellPipe","1","1","N/A","N/A","8","2","118","14","2025-02-21T12:33:43Z","2023-08-25T15:18:30Z","59137" +"*SharpShellPipe-main*",".{0,1000}SharpShellPipe\-main.{0,1000}","offensive_tool_keyword","SharpShellPipe","interactive remote shell access via named pipes and the SMB protocol.","T1056.002 - T1021.002 - T1059.001","TA0005 - TA0009 - TA0002","N/A","N/A","Lateral Movement","https://github.com/DarkCoderSc/SharpShellPipe","1","1","N/A","N/A","8","2","118","14","2025-02-21T12:33:43Z","2023-08-25T15:18:30Z","59138" +"*SharpShooter.py*",".{0,1000}SharpShooter\.py.{0,1000}","offensive_tool_keyword","SharpShooter","Payload Generation Framework","T1027 - T1059","TA0042","N/A","N/A","Resource Development","https://github.com/mdsecactivebreach/SharpShooter","1","1","N/A","N/A","10","10","1859","361","2024-08-21T12:09:54Z","2018-03-06T20:04:20Z","59139" +"*Sharp-SMBExec.exe*",".{0,1000}Sharp\-SMBExec\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta - APT20 - APT29 - PowerPool","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59141" +"*SharpSniper.exe*",".{0,1000}SharpSniper\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59142" +"*SharpSocks.exe*",".{0,1000}SharpSocks\.exe.{0,1000}","offensive_tool_keyword","SharpSocks","Tunnellable HTTP/HTTPS socks4a proxy written in C# and deployable via PowerShell","T1090 - T1021.001","TA0002","N/A","N/A","C2","https://github.com/nettitude/SharpSocks","1","1","N/A","N/A","10","10","482","84","2023-03-15T19:19:30Z","2017-11-10T13:29:08Z","59143" +"*SharpSocks.pfx*",".{0,1000}SharpSocks\.pfx.{0,1000}","offensive_tool_keyword","SharpSocks","Tunnellable HTTP/HTTPS socks4a proxy written in C# and deployable via PowerShell","T1090 - T1021.001","TA0002","N/A","N/A","C2","https://github.com/nettitude/SharpSocks","1","1","N/A","N/A","10","10","482","84","2023-03-15T19:19:30Z","2017-11-10T13:29:08Z","59144" +"*SharpSocks.resx*",".{0,1000}SharpSocks\.resx.{0,1000}","offensive_tool_keyword","SharpSocks","Tunnellable HTTP/HTTPS socks4a proxy written in C# and deployable via PowerShell","T1090 - T1021.001","TA0002","N/A","N/A","C2","https://github.com/nettitude/SharpSocks","1","1","N/A","N/A","10","10","482","84","2023-03-15T19:19:30Z","2017-11-10T13:29:08Z","59145" +"*SharpSocks.sln*",".{0,1000}SharpSocks\.sln.{0,1000}","offensive_tool_keyword","SharpSocks","Tunnellable HTTP/HTTPS socks4a proxy written in C# and deployable via PowerShell","T1090 - T1021.001","TA0002","N/A","N/A","C2","https://github.com/nettitude/SharpSocks","1","1","N/A","N/A","10","10","482","84","2023-03-15T19:19:30Z","2017-11-10T13:29:08Z","59146" +"*SharpSocksCommon*",".{0,1000}SharpSocksCommon.{0,1000}","offensive_tool_keyword","SharpSocks","Tunnellable HTTP/HTTPS socks4a proxy written in C# and deployable via PowerShell","T1090 - T1021.001","TA0002","N/A","N/A","C2","https://github.com/nettitude/SharpSocks","1","1","N/A","N/A","10","10","482","84","2023-03-15T19:19:30Z","2017-11-10T13:29:08Z","59147" +"*SharpSocksConfig*",".{0,1000}SharpSocksConfig.{0,1000}","offensive_tool_keyword","SharpSocks","Tunnellable HTTP/HTTPS socks4a proxy written in C# and deployable via PowerShell","T1090 - T1021.001","TA0002","N/A","N/A","C2","https://github.com/nettitude/SharpSocks","1","1","N/A","N/A","10","10","482","84","2023-03-15T19:19:30Z","2017-11-10T13:29:08Z","59148" +"*SharpSocksImplant*",".{0,1000}SharpSocksImplant.{0,1000}","offensive_tool_keyword","SharpSocks","Tunnellable HTTP/HTTPS socks4a proxy written in C# and deployable via PowerShell","T1090 - T1021.001","TA0002","N/A","N/A","C2","https://github.com/nettitude/SharpSocks","1","1","N/A","N/A","10","10","482","84","2023-03-15T19:19:30Z","2017-11-10T13:29:08Z","59149" +"*SharpSocksServer*",".{0,1000}SharpSocksServer.{0,1000}","offensive_tool_keyword","SharpSocks","Tunnellable HTTP/HTTPS socks4a proxy written in C# and deployable via PowerShell","T1090 - T1021.001","TA0002","N/A","N/A","C2","https://github.com/nettitude/SharpSocks","1","1","N/A","N/A","10","10","482","84","2023-03-15T19:19:30Z","2017-11-10T13:29:08Z","59150" +"*SharpSocksServer.Sh*",".{0,1000}SharpSocksServer\.Sh.{0,1000}","offensive_tool_keyword","shad0w","A post exploitation framework designed to operate covertly on heavily monitored environments","T1071 - T1090 - T1105 - T1571 - T1001","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/bats3c/shad0w","1","1","N/A","N/A","N/A","10","2090","332","2021-09-29T00:15:36Z","2020-04-28T16:42:07Z","59151" +"*SharpSpawner.cs*",".{0,1000}SharpSpawner\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59152" +"*SharpSphere.exe*",".{0,1000}SharpSphere\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59153" +"*SharpSploit*",".{0,1000}SharpSploit.{0,1000}","offensive_tool_keyword","SharpSploit","SharpSploit is a .NET post-exploitation library written in C# that aims to highlight the attack surface of .NET and make the use of offensive .NET easier for red teamers.","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/cobbr/SharpSploit","1","1","N/A","N/A","10","10","1789","312","2021-08-12T18:23:15Z","2018-09-20T14:22:37Z","59161" +"*SharpSploit.dll*",".{0,1000}SharpSploit\.dll.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","59163" +"*SharpSploit.Enumeration.*",".{0,1000}SharpSploit\.Enumeration\..{0,1000}","offensive_tool_keyword","SharpSploitConsole","Console Application designed to interact with SharpSploit","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/anthemtotheego/SharpSploitConsole","1","1","N/A","N/A","10","2","182","36","2022-02-21T15:12:26Z","2018-10-02T18:57:46Z","59166" +"*SharpSploit.Exe*",".{0,1000}SharpSploit\.Exe.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","59167" +"*SharpSploit.Exe*",".{0,1000}SharpSploit\.Exe.{0,1000}","offensive_tool_keyword","SharpSploit","SharpSploit is a .NET post-exploitation library written in C# that aims to highlight the attack surface of .NET and make the use of offensive .NET easier for red teamers.","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/cobbr/SharpSploit","1","1","N/A","N/A","10","10","1789","312","2021-08-12T18:23:15Z","2018-09-20T14:22:37Z","59168" +"*sharpSploitConsole.exe*",".{0,1000}sharpSploitConsole\.exe.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","59171" +"*sharpSploitConsole.exe*",".{0,1000}sharpSploitConsole\.exe.{0,1000}","offensive_tool_keyword","SharpSploitConsole","Console Application designed to interact with SharpSploit","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/anthemtotheego/SharpSploitConsole","1","1","N/A","N/A","10","2","182","36","2022-02-21T15:12:26Z","2018-10-02T18:57:46Z","59172" +"*SharpSploitConsole.sln*",".{0,1000}SharpSploitConsole\.sln.{0,1000}","offensive_tool_keyword","SharpSploitConsole","Console Application designed to interact with SharpSploit","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/anthemtotheego/SharpSploitConsole","1","1","N/A","N/A","10","2","182","36","2022-02-21T15:12:26Z","2018-10-02T18:57:46Z","59173" +"*SharpSploitConsole_x*",".{0,1000}SharpSploitConsole_x.{0,1000}","offensive_tool_keyword","cobaltstrike","SharpCradle is a tool designed to help penetration testers or red teams download and execute .NET binaries into memory.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/anthemtotheego/SharpCradle","1","1","N/A","N/A","10","10","279","57","2020-12-30T17:15:51Z","2018-10-23T06:21:53Z","59175" +"*SharpSploitConsole_x64.exe*",".{0,1000}SharpSploitConsole_x64\.exe.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","59176" +"*SharpSploitDomainRecon*",".{0,1000}SharpSploitDomainRecon.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59178" +"*SharpSploitDomainReconImpl*",".{0,1000}SharpSploitDomainReconImpl.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59179" +"*SharpSploitService.exe*",".{0,1000}SharpSploitService\.exe.{0,1000}","offensive_tool_keyword","SharpSploit","SharpSploit is a .NET post-exploitation library written in C# that aims to highlight the attack surface of .NET and make the use of offensive .NET easier for red teamers.","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/cobbr/SharpSploit","1","1","N/A","N/A","10","10","1789","312","2021-08-12T18:23:15Z","2018-09-20T14:22:37Z","59180" +"*SharpSploitSvc*",".{0,1000}SharpSploitSvc.{0,1000}","offensive_tool_keyword","SharpSploit","SharpSploit is a .NET post-exploitation library written in C# that aims to highlight the attack surface of .NET and make the use of offensive .NET easier for red teamers.","T1055 - T1086 - T1003 - T1053 - T1547 - T1110 - T1021 - T1070 - T1562 - T1574 - T1543 - T1098","TA0002 - TA0003 - TA0005 - TA0006 - TA0010 - TA0040","N/A","N/A","Exploitation tool","https://github.com/cobbr/SharpSploit","1","1","N/A","N/A","10","10","1789","312","2021-08-12T18:23:15Z","2018-09-20T14:22:37Z","59181" +"*SharpSplunkWhisperer2*",".{0,1000}SharpSplunkWhisperer2.{0,1000}","offensive_tool_keyword","SplunkWhisperer2","Local privilege escalation or remote code execution through Splunk Universal Forwarder (UF) misconfigurations","T1068 - T1059.003 - T1071.001","TA0004 - TA0003 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/cnotin/SplunkWhisperer2","1","1","N/A","N/A","9","10","250","53","2022-09-30T16:41:17Z","2019-02-24T18:05:51Z","59182" +"*SharpSpoolTrigger.exe*",".{0,1000}SharpSpoolTrigger\.exe.{0,1000}","offensive_tool_keyword","SharpSystemTriggers","Collection of remote authentication triggers in C#","T1078 - T1059.001 - T1550","TA0008 ","N/A","N/A","Lateral Movement","https://github.com/cube0x0/SharpSystemTriggers","1","1","N/A","N/A","10","5","483","57","2024-05-15T21:24:56Z","2021-09-12T18:18:15Z","59183" +"*SharpSpray*",".{0,1000}SharpSpray.{0,1000}","offensive_tool_keyword","SharpSpray","This project is a C# port of my PowerSpray.ps1 script. SharpSpray a simple code set to perform a password spraying attack against all users of a domain using LDAP and is compatible with Cobalt Strike.","T1110 - T1558","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/jnqpblc/SharpSpray","1","1","N/A","N/A","N/A","2","195","36","2019-06-30T03:10:52Z","2019-03-04T17:14:07Z","59184" +"*SharpSpray.exe*",".{0,1000}SharpSpray\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59186" +"*SharpSQLPwn*",".{0,1000}SharpSQLPwn.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","59190" +"*SharpSQLPwn*",".{0,1000}SharpSQLPwn.{0,1000}","offensive_tool_keyword","SharpSQLPwn","C# tool to identify and exploit weaknesses within MSSQL instances in Active Directory environments","T1210.002 - T1046 - T1078.003","TA0001 - TA0007 - TA0040","N/A","N/A","Exploitation tool","https://github.com/lefayjey/SharpSQLPwn","1","1","N/A","N/A","N/A","2","111","20","2022-02-13T19:15:36Z","2022-01-20T19:58:07Z","59191" +"*SharpSQLPwn.exe*",".{0,1000}SharpSQLPwn\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59192" +"*SharpSSDP.exe*",".{0,1000}SharpSSDP\.exe.{0,1000}","offensive_tool_keyword","SharpSSDP"," execute SharpSSDP.exe through Cobalt Strike's Beacon ""execute-assembly"" module to discover SSDP related services","T1046 - T1016","TA0007 - TA0005","N/A","N/A","Discovery","https://github.com/rvrsh3ll/SharpSSDP","1","1","N/A","N/A","7","1","17","4","2018-12-16T17:14:28Z","2018-12-16T17:14:12Z","59193" +"*SharpStay.csproj*",".{0,1000}SharpStay\.csproj.{0,1000}","offensive_tool_keyword","SharpStay","SharpStay - .NET Persistence","T1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123","TA0003","N/A","N/A","Persistence","https://github.com/0xthirteen/SharpStay","1","1","N/A","N/A","10","5","475","97","2024-06-26T15:54:52Z","2020-01-24T22:22:07Z","59194" +"*SharpStay.exe*",".{0,1000}SharpStay\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike kit for Persistence","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/0xthirteen/StayKit","1","1","N/A","N/A","10","10","475","73","2020-01-27T14:53:31Z","2020-01-24T22:20:20Z","59195" +"*SharpStay.exe*",".{0,1000}SharpStay\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59196" +"*SharpStay.sln*",".{0,1000}SharpStay\.sln.{0,1000}","offensive_tool_keyword","SharpStay","SharpStay - .NET Persistence","T1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123","TA0003 - TA0008 - TA0011","N/A","N/A","Persistence","https://github.com/0xthirteen/SharpStay","1","1","N/A","N/A","10","5","475","97","2024-06-26T15:54:52Z","2020-01-24T22:22:07Z","59198" +"*SharpStay-master*",".{0,1000}SharpStay\-master.{0,1000}","offensive_tool_keyword","SharpStay","SharpStay - .NET Persistence","T1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123","TA0003 - TA0008 - TA0011","N/A","N/A","Persistence","https://github.com/0xthirteen/SharpStay","1","1","N/A","N/A","10","5","475","97","2024-06-26T15:54:52Z","2020-01-24T22:22:07Z","59199" +"*SharpSvc.exe*",".{0,1000}SharpSvc\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59201" +"*SharpSword.csproj*",".{0,1000}SharpSword\.csproj.{0,1000}","offensive_tool_keyword","SharpSword","Read the contents of MS Word Documents using Cobalt Strike's Execute-Assembly","T1562.004 - T1059.001 - T1021.003","TA0005 - TA0002","N/A","N/A","C2","https://github.com/OG-Sadpanda/SharpSword","1","1","N/A","N/A","8","10","117","11","2024-09-30T15:21:25Z","2021-07-15T14:50:05Z","59202" +"*SharpSword.exe*",".{0,1000}SharpSword\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Read the contents of DOCX files using Cobalt Strike's Execute-Assembly","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OG-Sadpanda/SharpSword","1","1","N/A","N/A","10","10","117","11","2024-09-30T15:21:25Z","2021-07-15T14:50:05Z","59203" +"*SharpSword.exe*",".{0,1000}SharpSword\.exe.{0,1000}","offensive_tool_keyword","SharpSword","Read the contents of MS Word Documents using Cobalt Strike's Execute-Assembly","T1562.004 - T1059.001 - T1021.003","TA0005 - TA0002","N/A","N/A","C2","https://github.com/OG-Sadpanda/SharpSword","1","1","N/A","N/A","8","10","117","11","2024-09-30T15:21:25Z","2021-07-15T14:50:05Z","59204" +"*SharpSword.sln*",".{0,1000}SharpSword\.sln.{0,1000}","offensive_tool_keyword","SharpSword","Read the contents of MS Word Documents using Cobalt Strike's Execute-Assembly","T1562.004 - T1059.001 - T1021.003","TA0005 - TA0002","N/A","N/A","C2","https://github.com/OG-Sadpanda/SharpSword","1","1","N/A","N/A","8","10","117","11","2024-09-30T15:21:25Z","2021-07-15T14:50:05Z","59205" +"*SharpSword-main.*",".{0,1000}SharpSword\-main\..{0,1000}","offensive_tool_keyword","SharpSword","Read the contents of MS Word Documents using Cobalt Strike's Execute-Assembly","T1562.004 - T1059.001 - T1021.003","TA0005 - TA0002","N/A","N/A","C2","https://github.com/OG-Sadpanda/SharpSword","1","1","N/A","N/A","8","10","117","11","2024-09-30T15:21:25Z","2021-07-15T14:50:05Z","59206" +"*SharpSystemTriggers.git*",".{0,1000}SharpSystemTriggers\.git.{0,1000}","offensive_tool_keyword","SharpSystemTriggers","Collection of remote authentication triggers in C#","T1078 - T1059.001 - T1550","TA0008 ","N/A","N/A","Lateral Movement","https://github.com/cube0x0/SharpSystemTriggers","1","1","N/A","N/A","10","5","483","57","2024-05-15T21:24:56Z","2021-09-12T18:18:15Z","59207" +"*SharpSystemTriggers.sln*",".{0,1000}SharpSystemTriggers\.sln.{0,1000}","offensive_tool_keyword","SharpSystemTriggers","Collection of remote authentication triggers in C#","T1078 - T1059.001 - T1550","TA0008 ","N/A","N/A","Lateral Movement","https://github.com/cube0x0/SharpSystemTriggers","1","1","N/A","N/A","10","5","483","57","2024-05-15T21:24:56Z","2021-09-12T18:18:15Z","59208" +"*SharpSystemTriggers-main*",".{0,1000}SharpSystemTriggers\-main.{0,1000}","offensive_tool_keyword","SharpSystemTriggers","Collection of remote authentication triggers in C#","T1078 - T1059.001 - T1550","TA0008 ","N/A","N/A","Lateral Movement","https://github.com/cube0x0/SharpSystemTriggers","1","1","N/A","N/A","10","5","483","57","2024-05-15T21:24:56Z","2021-09-12T18:18:15Z","59209" +"*SharpTask.exe*",".{0,1000}SharpTask\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59210" +"*SharpTemplateResources/cmd/*",".{0,1000}SharpTemplateResources\/cmd\/.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1099","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","59212" +"*SharpTerminator.exe*",".{0,1000}SharpTerminator\.exe.{0,1000}","offensive_tool_keyword","SharpTerminator","Terminate AV/EDR Processes using kernel driver","T1055.003 - T1547.001 - T1053.005 - T1091 - T1014 - T1053.006 - T1053.004 - T1112 - T1112.001","TA0007 - TA0008 - TA0006 - TA0002","N/A","N/A","Exploitation tool","https://github.com/mertdas/SharpTerminator","1","1","N/A","N/A","10","4","341","66","2023-06-12T00:38:54Z","2023-06-11T06:35:51Z","59213" +"*SharpTerminator.git*",".{0,1000}SharpTerminator\.git.{0,1000}","offensive_tool_keyword","SharpTerminator","Terminate AV/EDR Processes using kernel driver","T1055.003 - T1547.001 - T1053.005 - T1091 - T1014 - T1053.006 - T1053.004 - T1112 - T1112.001","TA0007 - TA0008 - TA0006 - TA0002","N/A","N/A","Exploitation tool","https://github.com/mertdas/SharpTerminator","1","1","N/A","N/A","10","4","341","66","2023-06-12T00:38:54Z","2023-06-11T06:35:51Z","59214" +"*SharpTerminator.sln*",".{0,1000}SharpTerminator\.sln.{0,1000}","offensive_tool_keyword","SharpTerminator","Terminate AV/EDR Processes using kernel driver","T1055.003 - T1547.001 - T1053.005 - T1091 - T1014 - T1053.006 - T1053.004 - T1112 - T1112.001","TA0007 - TA0008 - TA0006 - TA0002","N/A","N/A","Exploitation tool","https://github.com/mertdas/SharpTerminator","1","1","N/A","N/A","10","4","341","66","2023-06-12T00:38:54Z","2023-06-11T06:35:51Z","59215" +"*SharpTerminator-main.zip*",".{0,1000}SharpTerminator\-main\.zip.{0,1000}","offensive_tool_keyword","SharpTerminator","Terminate AV/EDR Processes using kernel driver","T1055.003 - T1547.001 - T1053.005 - T1091 - T1014 - T1053.006 - T1053.004 - T1112 - T1112.001","TA0007 - TA0008 - TA0006 - TA0002","N/A","N/A","Exploitation tool","https://github.com/mertdas/SharpTerminator","1","1","N/A","N/A","10","4","341","66","2023-06-12T00:38:54Z","2023-06-11T06:35:51Z","59216" +"*SharpThief.csproj*",".{0,1000}SharpThief\.csproj.{0,1000}","offensive_tool_keyword","SharpThief","A one-click program to steal the icon, resource information, version information, modification time, and digital signature (invalid) to make the program appear legitimate","T1036 - T1070 - T1078 - T1027 - T1202","TA0005 - TA0002 - TA0001","N/A","N/A","Defense Evasion","https://github.com/INotGreen/SharpThief","1","1","N/A","N/A","8","4","372","37","2024-12-17T05:46:39Z","2024-03-05T05:34:50Z","59217" +"*SharpThief.exe*",".{0,1000}SharpThief\.exe.{0,1000}","offensive_tool_keyword","SharpThief","A one-click program to steal the icon, resource information, version information, modification time, and digital signature (invalid) to make the program appear legitimate","T1036 - T1070 - T1078 - T1027 - T1202","TA0005 - TA0002 - TA0001","N/A","N/A","Defense Evasion","https://github.com/INotGreen/SharpThief","1","1","N/A","N/A","8","4","372","37","2024-12-17T05:46:39Z","2024-03-05T05:34:50Z","59218" +"*SharpThief.pdb*",".{0,1000}SharpThief\.pdb.{0,1000}","offensive_tool_keyword","SharpThief","A one-click program to steal the icon, resource information, version information, modification time, and digital signature (invalid) to make the program appear legitimate","T1036 - T1070 - T1078 - T1027 - T1202","TA0005 - TA0002 - TA0001","N/A","N/A","Defense Evasion","https://github.com/INotGreen/SharpThief","1","1","N/A","N/A","8","4","372","37","2024-12-17T05:46:39Z","2024-03-05T05:34:50Z","59219" +"*SharpThief.Properties*",".{0,1000}SharpThief\.Properties.{0,1000}","offensive_tool_keyword","SharpThief","A one-click program to steal the icon, resource information, version information, modification time, and digital signature (invalid) to make the program appear legitimate","T1036 - T1070 - T1078 - T1027 - T1202","TA0005 - TA0002 - TA0001","N/A","N/A","Defense Evasion","https://github.com/INotGreen/SharpThief","1","1","N/A","N/A","8","4","372","37","2024-12-17T05:46:39Z","2024-03-05T05:34:50Z","59220" +"*SharpThief.resources.dll*",".{0,1000}SharpThief\.resources\.dll.{0,1000}","offensive_tool_keyword","SharpThief","A one-click program to steal the icon, resource information, version information, modification time, and digital signature (invalid) to make the program appear legitimate","T1036 - T1070 - T1078 - T1027 - T1202","TA0005 - TA0002 - TA0001","N/A","N/A","Defense Evasion","https://github.com/INotGreen/SharpThief","1","1","N/A","N/A","8","4","372","37","2024-12-17T05:46:39Z","2024-03-05T05:34:50Z","59221" +"*SharpThief.resources.exe*",".{0,1000}SharpThief\.resources\.exe.{0,1000}","offensive_tool_keyword","SharpThief","A one-click program to steal the icon, resource information, version information, modification time, and digital signature (invalid) to make the program appear legitimate","T1036 - T1070 - T1078 - T1027 - T1202","TA0005 - TA0002 - TA0001","N/A","N/A","Defense Evasion","https://github.com/INotGreen/SharpThief","1","1","N/A","N/A","8","4","372","37","2024-12-17T05:46:39Z","2024-03-05T05:34:50Z","59222" +"*SharpThief.sln*",".{0,1000}SharpThief\.sln.{0,1000}","offensive_tool_keyword","SharpThief","A one-click program to steal the icon, resource information, version information, modification time, and digital signature (invalid) to make the program appear legitimate","T1036 - T1070 - T1078 - T1027 - T1202","TA0005 - TA0002 - TA0001","N/A","N/A","Defense Evasion","https://github.com/INotGreen/SharpThief","1","1","N/A","N/A","8","4","372","37","2024-12-17T05:46:39Z","2024-03-05T05:34:50Z","59223" +"*SharpToken.csproj*",".{0,1000}SharpToken\.csproj.{0,1000}","offensive_tool_keyword","SharpToken","SharpToken is a tool for exploiting Token leaks. It can find leaked Tokens from all processes in the system and use them","T1134 - T1101 - T1214 - T1087 - T1038","TA0004 - TA0007","N/A","N/A","Exploitation tool","https://github.com/BeichenDream/SharpToken","1","1","N/A","N/A","N/A","5","467","66","2023-11-24T19:21:57Z","2022-06-30T07:34:57Z","59230" +"*SharpToken.exe*",".{0,1000}SharpToken\.exe.{0,1000}","offensive_tool_keyword","godpotato","GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.","T1134.001 - T1068 - T1055 - T1546.015","TA0004 - TA0006 - TA0011","Ghost Ransomware","N/A","Privilege Escalation","https://github.com/BeichenDream/GodPotato","1","1","N/A","N/A","10","10","1938","236","2023-11-24T19:22:31Z","2022-12-23T14:37:00Z","59231" +"*SharpToken.exe*",".{0,1000}SharpToken\.exe.{0,1000}","offensive_tool_keyword","SharpToken","SharpToken is a tool for exploiting Token leaks. It can find leaked Tokens from all processes in the system and use them","T1134 - T1101 - T1214 - T1087 - T1038","TA0004 - TA0007","N/A","N/A","Exploitation tool","https://github.com/BeichenDream/SharpToken","1","1","N/A","N/A","N/A","5","467","66","2023-11-24T19:21:57Z","2022-06-30T07:34:57Z","59232" +"*SharpToken.git*",".{0,1000}SharpToken\.git.{0,1000}","offensive_tool_keyword","SharpToken","SharpToken is a tool for exploiting Token leaks. It can find leaked Tokens from all processes in the system and use them","T1134 - T1101 - T1214 - T1087 - T1038","TA0004 - TA0007","N/A","N/A","Exploitation tool","https://github.com/BeichenDream/SharpToken","1","1","N/A","N/A","N/A","5","467","66","2023-11-24T19:21:57Z","2022-06-30T07:34:57Z","59233" +"*SharpToken-main.zip*",".{0,1000}SharpToken\-main\.zip.{0,1000}","offensive_tool_keyword","SharpToken","SharpToken is a tool for exploiting Token leaks. It can find leaked Tokens from all processes in the system and use them","T1134 - T1101 - T1214 - T1087 - T1038","TA0004 - TA0007","N/A","N/A","Exploitation tool","https://github.com/BeichenDream/SharpToken","1","1","N/A","N/A","N/A","5","467","66","2023-11-24T19:21:57Z","2022-06-30T07:34:57Z","59234" +"*SharpUnhooker.*",".{0,1000}SharpUnhooker\..{0,1000}","offensive_tool_keyword","SharpUnhooker","C# Based Universal API Unhooker","T1055.012 - T1070.004 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/GetRektBoy724/SharpUnhooker","1","1","N/A","N/A","9","5","400","80","2022-02-18T13:11:11Z","2021-05-17T01:33:38Z","59235" +"*SharpUnhooker-main*",".{0,1000}SharpUnhooker\-main.{0,1000}","offensive_tool_keyword","SharpUnhooker","C# Based Universal API Unhooker","T1055.012 - T1070.004 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/GetRektBoy724/SharpUnhooker","1","1","N/A","N/A","9","5","400","80","2022-02-18T13:11:11Z","2021-05-17T01:33:38Z","59236" +"*SharpUp.exe*",".{0,1000}SharpUp\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59238" +"*SharpUp.exe*",".{0,1000}SharpUp\.exe.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","59239" +"*SharpUp.exe*",".{0,1000}SharpUp\.exe.{0,1000}","offensive_tool_keyword","SharpUp","SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.","T1003 - T1082 - T1057 - T1069 - T1083","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/GhostPack/SharpUp","1","1","N/A","N/A","N/A","10","1344","253","2024-02-14T16:38:26Z","2018-07-24T17:39:33Z","59240" +"*SharpUpManager*",".{0,1000}SharpUpManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59241" +"*SharpVeeamDecryptor.exe*",".{0,1000}SharpVeeamDecryptor\.exe.{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","1","N/A","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","59243" +"*SharpView.exe*",".{0,1000}SharpView\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta - APT29","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59244" +"*Sharpview.exe*",".{0,1000}Sharpview\.exe.{0,1000}","offensive_tool_keyword","SharpPack","collection of C# tools that include functionalities like Kerberoasting - ticket manipulation - Mimikatz - privilege escalation - domain enumeration and more","T1558.003 - T1003 - T1059.004 - T1078 - T1212 - T1087 - T1016 - T1071 - T1555 - T1203","TA0003 - TA0004 - TA0006 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/Lexus89/SharpPack","1","1","N/A","N/A","10","1","78","19","2019-08-12T13:25:25Z","2018-10-01T12:45:16Z","59245" +"*SharpView.exe*",".{0,1000}SharpView\.exe.{0,1000}","offensive_tool_keyword","SharpView","C# implementation of harmj0y's PowerView","T1018 - T1482 - T1087.002 - T1069.002","TA0007 - TA0003 - TA0001","N/A","Conti - APT29","Discovery","https://github.com/tevora-threat/SharpView/","1","1","N/A","N/A","10","10","1032","196","2024-03-22T16:34:09Z","2018-07-24T21:15:04Z","59246" +"*SharpView-master*",".{0,1000}SharpView\-master.{0,1000}","offensive_tool_keyword","SharpView","C# implementation of harmj0y's PowerView","T1018 - T1482 - T1087.002 - T1069.002","TA0007 - TA0003 - TA0001","N/A","Conti - APT29","Discovery","https://github.com/tevora-threat/SharpView/","1","1","N/A","N/A","10","10","1032","196","2024-03-22T16:34:09Z","2018-07-24T21:15:04Z","59248" +"*SharpWebManager.cs*",".{0,1000}SharpWebManager\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59251" +"*SharpWebServer.exe*",".{0,1000}SharpWebServer\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59252" +"*SharpWifiGrabber*",".{0,1000}SharpWifiGrabber.{0,1000}","offensive_tool_keyword","ObfuscatedSharpCollection","obfuscated Sharp Offensive tools","T1003 - T1059 - T1087 - T1555 - T1078 - T1213 - T1569 - T1548 - T1071 - T1566","TA0006 - TA0005 - TA0003 - TA0002 - TA0004 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/ObfuscatedSharpCollection","1","1","N/A","N/A","10","3","206","30","2025-04-18T03:11:19Z","2023-05-14T18:36:15Z","59253" +"*SharpWifiGrabber.exe*",".{0,1000}SharpWifiGrabber\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59254" +"*SharpWMI.exe*",".{0,1000}SharpWMI\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59257" +"*SharpWmiManager*",".{0,1000}SharpWmiManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59260" +"*sharpwmi-N*.exe*",".{0,1000}sharpwmi\-N.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","59261" +"*SharpWSManWinRM.exe*",".{0,1000}SharpWSManWinRM\.exe.{0,1000}","offensive_tool_keyword","WSMan-WinRM","remote commands over WinRM using the WSMan.Automation COM object","T1021.004 - T1059.001","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/bohops/WSMan-WinRM","1","1","N/A","N/A","10","3","236","40","2020-05-12T16:49:01Z","2020-05-12T01:30:42Z","59262" +"*SharpWSUS.*",".{0,1000}SharpWSUS\..{0,1000}","offensive_tool_keyword","SharpWSUS","SharpWSUS is a CSharp tool for Lateral Movement through WSUS","T1047 - T1021.002 - T1021.003 - T1077 - T1069 - T1057 - T1105 - T1028 - T1070.004 - T1053 - T1086 - T1106 - T1059","TA0002 - TA0003 - TA0008","N/A","Black Basta","Lateral Movement","https://github.com/nettitude/SharpWSUS","1","1","N/A","N/A","N/A","5","452","77","2022-11-20T23:41:40Z","2022-05-04T08:27:57Z","59265" +"*SharPyShell*",".{0,1000}SharPyShell.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell is a tiny and obfuscated ASP.NET webshell that executes commands received by an encrypted channel compiling them in memory at runtime.","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","59267" +"*sharpyshell.aspx*",".{0,1000}sharpyshell\.aspx.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","59268" +"*SharPyShell.py*",".{0,1000}SharPyShell\.py.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","59269" +"*SharPyShell_Test.ps1*",".{0,1000}SharPyShell_Test\.ps1.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","59270" +"*SharPyShellPrompt.py*",".{0,1000}SharPyShellPrompt\.py.{0,1000}","offensive_tool_keyword","SharPyShell","SharPyShell - tiny and obfuscated ASP.NET webshell for C# web","T1505.003 - T1059.007 - T1027.002 - T1027.004","TA0002 - TA0003 - TA0004 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/SharPyShell","1","1","N/A","N/A","10","10","955","147","2023-11-26T17:14:06Z","2019-03-10T22:09:40Z","59271" +"*SharpZeroLogon*",".{0,1000}SharpZeroLogon.{0,1000}","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","59272" +"*SharpZeroLogon.exe*",".{0,1000}SharpZeroLogon\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59273" +"*SharpZeroLogon.exe*",".{0,1000}SharpZeroLogon\.exe.{0,1000}","offensive_tool_keyword","SharpZeroLogon","exploit for CVE-2020-1472","T1210 - T1558.003 - T1078.002 - T1098 - T1003.006","TA0001 - TA0004 - TA0005 - TA0006 - TA0003","Ghost Ransomware","N/A","Exploitation tool","https://github.com/leitosama/SharpZeroLogon","1","1","N/A","N/A","10","1","27","17","2021-02-13T10:13:32Z","2021-02-13T09:44:43Z","59274" +"*SharpZippo.exe*",".{0,1000}SharpZippo\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","List/Read contents of Zip files (in memory and without extraction) using CobaltStrike's Execute-Assembly","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OG-Sadpanda/SharpZippo","1","1","N/A","N/A","10","10","59","10","2022-05-24T15:57:33Z","2022-05-24T15:52:31Z","59275" +"*ShawnDEvans/smbmap*",".{0,1000}ShawnDEvans\/smbmap.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","59276" +"*ShawnDEvans/smbmap*",".{0,1000}ShawnDEvans\/smbmap.{0,1000}","offensive_tool_keyword","smbmap","SMBMap allows users to enumerate samba share drives across an entire domain. List share drives. drive permissions. share contents. upload/download functionality. file name auto-download pattern matching. and even execute remote commands. This tool was designed with pen testing in mind. and is intended to simplify searching for potentially sensitive data across large networks.","T1210.001 - T1083 - T1213 - T1021","TA0007 - TA0003 - TA0002 - TA0001","N/A","MuddyWater - Dispossessor","Discovery","https://github.com/ShawnDEvans/smbmap","1","1","N/A","N/A","10","10","1890","359","2025-02-28T18:09:10Z","2015-03-16T13:15:00Z","59277" +"*shehzade/peeping-tom*",".{0,1000}shehzade\/peeping\-tom.{0,1000}","offensive_tool_keyword","peeping-tom","Remote keylogger for Windows written in C++","T1056.001 - T1123 - T1129 - T1113","TA0006 - TA0008 - TA0009","N/A","Dispossessor","Collection","https://github.com/shehzade/peeping-tom","1","1","N/A","keylogger","10","1","3","0","2022-07-24T09:31:59Z","2022-04-15T14:16:41Z","59278" +"*shell_shocked*.js*",".{0,1000}shell_shocked.{0,1000}\.js.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","59288" +"*shell_shocked*.rb*",".{0,1000}shell_shocked.{0,1000}\.rb.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","59289" +"*shell_startup_files_modification.py*",".{0,1000}shell_startup_files_modification\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","59291" +"*Shell3er.ps1*",".{0,1000}Shell3er\.ps1.{0,1000}","offensive_tool_keyword","Shell3er","PowerShell Reverse Shell","T1059.001 - T1021.004 - T1090.002","TA0002 - TA0011","N/A","N/A","C2","https://github.com/yehia-mamdouh/Shell3er/blob/main/Shell3er.ps1","1","1","N/A","N/A","N/A","10","61","14","2023-05-07T16:02:41Z","2023-05-07T15:35:16Z","59295" +"*Shellcode Process Hollowing.csproj*",".{0,1000}Shellcode\sProcess\sHollowing\.csproj.{0,1000}","offensive_tool_keyword","OSEP-Code-Snippets","notable code snippets for Offensive Security's PEN-300 (OSEP) course","T1116 - T1204.002 - T1027.009 - T1021.005 - T1560.001 - T1100 - T1003.001 - T1564.001 - T1047 - T1210 - T1134.002 - T1055 - T1055.011 - T1055.012 - T1204","TA0005 - TA0040 - TA0008 - TA0003 - TA0006 - TA0004","N/A","N/A","Exploitation tool","https://github.com/chvancooten/OSEP-Code-Snippets","1","1","N/A","N/A","8","10","1254","444","2024-01-04T15:17:17Z","2021-03-10T21:34:41Z","59309" +"*Shellcode Process Injector.ps1*",".{0,1000}Shellcode\sProcess\sInjector\.ps1.{0,1000}","offensive_tool_keyword","OSEP-Code-Snippets","notable code snippets for Offensive Security's PEN-300 (OSEP) course","T1116 - T1204.002 - T1027.009 - T1021.005 - T1560.001 - T1100 - T1003.001 - T1564.001 - T1047 - T1210 - T1134.002 - T1055 - T1055.011 - T1055.012 - T1204","TA0005 - TA0040 - TA0008 - TA0003 - TA0006 - TA0004","N/A","N/A","Exploitation tool","https://github.com/chvancooten/OSEP-Code-Snippets","1","1","N/A","N/A","8","10","1254","444","2024-01-04T15:17:17Z","2021-03-10T21:34:41Z","59310" +"*shellcode*shellcode.bin*",".{0,1000}shellcode.{0,1000}shellcode\.bin.{0,1000}","offensive_tool_keyword","KittyStager","KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant called kitten. The purpose of this project is to be able to have a web server and some kitten and be able to use the with any shellcode.","T1021.002 - T1055.012 - T1105","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/Enelg52/KittyStager","1","1","N/A","N/A","10","10","220","40","2023-06-06T11:38:39Z","2022-10-10T11:31:23Z","59312" +"*Shellcode.x64.bin*",".{0,1000}Shellcode\.x64\.bin.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1027 - T1071-001 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/HavocFramework/Havoc","1","1","N/A","N/A","10","10","7449","1050","2025-01-23T23:42:35Z","2022-09-11T13:21:16Z","59315" +"*shellcode_dll.dll*",".{0,1000}shellcode_dll\.dll.{0,1000}","offensive_tool_keyword","WinShellcode","It's a C code project created in Visual Studio that helps you generate shellcode from your C code.","T1059.001 - T1059.003 - T1059.005 - T1059.007 - T1059.004 - T1059.006 - T1218 - T1027.001 - T1564.003 - T1027","TA0002 - TA0006","N/A","N/A","Exploitation tool","https://github.com/DallasFR/WinShellcode","1","1","N/A","N/A","N/A","","N/A","","","","59316" +"*shellcode_dotnet2js*",".{0,1000}shellcode_dotnet2js.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","59318" +"*shellcode_dropper.c*",".{0,1000}shellcode_dropper\.c.{0,1000}","offensive_tool_keyword","darkarmour","Store and execute an encrypted windows binary from inside memorywithout a single bit touching disk.","T1055.012 - T1027 - T1564.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/bats3c/darkarmour","1","1","N/A","N/A","10","8","773","122","2020-04-13T10:56:23Z","2020-04-06T20:48:20Z","59319" +"*shellcode_dynwrapx*",".{0,1000}shellcode_dynwrapx.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","59320" +"*Shellcode_encryption.exe*",".{0,1000}Shellcode_encryption\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","ShellCode_Loader - Msf&CobaltStrike Antivirus ShellCode loader. Shellcode_encryption - Antivirus Shellcode encryption generation tool. currently tested for Antivirus 360 & Huorong & Computer Manager & Windows Defender (other antivirus software not tested).","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Axx8/ShellCode_Loader","1","1","N/A","N/A","10","10","412","47","2022-09-20T07:24:25Z","2022-09-02T14:41:18Z","59321" +"*shellcode_exec.py*",".{0,1000}shellcode_exec\.py.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","59322" +"*shellcode_generator.*",".{0,1000}shellcode_generator\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Shellcode Generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RCStep/CSSG","1","1","N/A","N/A","10","10","654","112","2025-01-08T23:11:49Z","2021-01-12T14:39:06Z","59323" +"*shellcode_generator_help.html*",".{0,1000}shellcode_generator_help\.html.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Shellcode Generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RCStep/CSSG","1","1","N/A","N/A","10","10","654","112","2025-01-08T23:11:49Z","2021-01-12T14:39:06Z","59324" +"*shellcode_inject.csproj*",".{0,1000}shellcode_inject\.csproj.{0,1000}","offensive_tool_keyword","PowerLessShell","PowerLessShell rely on MSBuild.exe to remotely execute PowerShell scripts and commands without spawning powershell.exe. You can also execute raw shellcode using the same approach.","T1218.010 - T1059 - T1105 - T1047 - T1055","TA0002 - TA0011 - TA0008","N/A","N/A","Defense Evasion","https://github.com/Mr-Un1k0d3r/PowerLessShell","1","1","N/A","N/A","N/A","10","1498","256","2023-03-23T13:30:14Z","2017-05-29T23:03:52Z","59325" +"*shellcode_inject.rb*",".{0,1000}shellcode_inject\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59326" +"*shellcode_injectproc.xml*",".{0,1000}shellcode_injectproc\.xml.{0,1000}","offensive_tool_keyword","badrats","control tool (C2) using Python server - Jscript - Powershell and C# implants and communicates via HTTP(S) and SMB","T1059 - T1027 - T1573 - T1071 - T1105","TA0005 - TA0002 - TA0011","N/A","N/A","C2","https://gitlab.com/KevinJClark/badrats","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","59327" +"*ShellCode_Loader.py*",".{0,1000}ShellCode_Loader\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","ShellCode_Loader - Msf&CobaltStrike Antivirus ShellCode loader. Shellcode_encryption - Antivirus Shellcode encryption generation tool. currently tested for Antivirus 360 & Huorong & Computer Manager & Windows Defender (other antivirus software not tested).","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Axx8/ShellCode_Loader","1","1","N/A","N/A","10","10","412","47","2022-09-20T07:24:25Z","2022-09-02T14:41:18Z","59328" +"*shellcode20.exe*",".{0,1000}shellcode20\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","python ShellCode Loader (Cobaltstrike&Metasploit)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OneHone/C--Shellcode","1","1","N/A","N/A","10","10","20","2","2019-11-28T01:53:55Z","2019-11-05T09:48:14Z","59330" +"*shellcode30.exe*",".{0,1000}shellcode30\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","python ShellCode Loader (Cobaltstrike&Metasploit)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OneHone/C--Shellcode","1","1","N/A","N/A","10","10","20","2","2019-11-28T01:53:55Z","2019-11-05T09:48:14Z","59334" +"*shellcode35.exe*",".{0,1000}shellcode35\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","python ShellCode Loader (Cobaltstrike&Metasploit)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OneHone/C--Shellcode","1","1","N/A","N/A","10","10","20","2","2019-11-28T01:53:55Z","2019-11-05T09:48:14Z","59335" +"*shellcode40.exe*",".{0,1000}shellcode40\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","python ShellCode Loader (Cobaltstrike&Metasploit)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/OneHone/C--Shellcode","1","1","N/A","N/A","10","10","20","2","2019-11-28T01:53:55Z","2019-11-05T09:48:14Z","59336" +"*shellcodeCrypter-bin.py*",".{0,1000}shellcodeCrypter\-bin\.py.{0,1000}","offensive_tool_keyword","OSEP-Code-Snippets","notable code snippets for Offensive Security's PEN-300 (OSEP) course","T1116 - T1204.002 - T1027.009 - T1021.005 - T1560.001 - T1100 - T1003.001 - T1564.001 - T1047 - T1210 - T1134.002 - T1055 - T1055.011 - T1055.012 - T1204","TA0005 - TA0040 - TA0008 - TA0003 - TA0006 - TA0004","N/A","N/A","Exploitation tool","https://github.com/chvancooten/OSEP-Code-Snippets","1","1","N/A","N/A","8","10","1254","444","2024-01-04T15:17:17Z","2021-03-10T21:34:41Z","59337" +"*shellcodeCrypter-msfvenom.py*",".{0,1000}shellcodeCrypter\-msfvenom\.py.{0,1000}","offensive_tool_keyword","OSEP-Code-Snippets","notable code snippets for Offensive Security's PEN-300 (OSEP) course","T1116 - T1204.002 - T1027.009 - T1021.005 - T1560.001 - T1100 - T1003.001 - T1564.001 - T1047 - T1210 - T1134.002 - T1055 - T1055.011 - T1055.012 - T1204","TA0005 - TA0040 - TA0008 - TA0003 - TA0006 - TA0004","N/A","N/A","Exploitation tool","https://github.com/chvancooten/OSEP-Code-Snippets","1","1","N/A","N/A","8","10","1254","444","2024-01-04T15:17:17Z","2021-03-10T21:34:41Z","59338" +"*Shellcode-Download_CreateThread_Execution*",".{0,1000}Shellcode\-Download_CreateThread_Execution.{0,1000}","offensive_tool_keyword","Shellcode-Downloader-CreateThread-Execution","This POC gives you the possibility to compile a .exe to completely avoid statically detection by AV/EPP/EDR of your C2-shellcode and download and execute your C2-shellcode which is hosted on your (C2)-webserver.","T1105 - T1055.001 - T1027 - T1203 - T1071","TA0005 - TA0011 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Shellcode-Downloader-CreateThread-Execution","1","1","N/A","N/A","N/A","3","246","51","2023-05-25T02:48:55Z","2022-03-27T07:51:08Z","59339" +"*Shellcode-Downloader-CreateThread-Execution*",".{0,1000}Shellcode\-Downloader\-CreateThread\-Execution.{0,1000}","offensive_tool_keyword","Shellcode-Downloader-CreateThread-Execution","This POC gives you the possibility to compile a .exe to completely avoid statically detection by AV/EPP/EDR of your C2-shellcode and download and execute your C2-shellcode which is hosted on your (C2)-webserver.","T1105 - T1055.001 - T1027 - T1203 - T1071","TA0005 - TA0011 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Shellcode-Downloader-CreateThread-Execution","1","1","N/A","N/A","N/A","3","246","51","2023-05-25T02:48:55Z","2022-03-27T07:51:08Z","59340" +"*shellcodeEncryptDecrypt*",".{0,1000}shellcodeEncryptDecrypt.{0,1000}","offensive_tool_keyword","C2 related tools","An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/mgeeky/ShellcodeFluctuation","1","1","N/A","N/A","10","10","1012","160","2022-06-17T18:07:33Z","2021-09-29T10:24:52Z","59341" +"*shellcode-exec.ps1*",".{0,1000}shellcode\-exec\.ps1.{0,1000}","offensive_tool_keyword","PayGen","FUD metasploit Persistence RAT","T1059.001 - T1209 - T1105 - T1547 - T1027","TA0003 - TA0005 - TA0002 - TA0011","N/A","N/A","Persistence","https://github.com/youhacker55/PayGen","1","1","N/A","N/A","N/A","1","4","0","2023-02-23T00:05:57Z","2021-06-16T20:20:55Z","59342" +"*shellcodeexec.x32*",".{0,1000}shellcodeexec\.x32.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","59343" +"*shellcodeexec.x64*",".{0,1000}shellcodeexec\.x64.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","59344" +"*ShellcodeFluctuation.*",".{0,1000}ShellcodeFluctuation\..{0,1000}","offensive_tool_keyword","C2 related tools","An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/mgeeky/ShellcodeFluctuation","1","1","N/A","N/A","10","10","1012","160","2022-06-17T18:07:33Z","2021-09-29T10:24:52Z","59345" +"*ShellcodeFluctuation64*",".{0,1000}ShellcodeFluctuation64.{0,1000}","offensive_tool_keyword","C2 related tools","An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/mgeeky/ShellcodeFluctuation","1","1","N/A","N/A","10","10","1012","160","2022-06-17T18:07:33Z","2021-09-29T10:24:52Z","59346" +"*ShellcodeFluctuation86*",".{0,1000}ShellcodeFluctuation86.{0,1000}","offensive_tool_keyword","C2 related tools","An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/mgeeky/ShellcodeFluctuation","1","1","N/A","N/A","10","10","1012","160","2022-06-17T18:07:33Z","2021-09-29T10:24:52Z","59347" +"*Shellcode-Hide-main*",".{0,1000}Shellcode\-Hide\-main.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","59348" +"*shellcodeInjection.json*",".{0,1000}shellcodeInjection\.json.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","59349" +"*Shellcode-Loader-master*",".{0,1000}Shellcode\-Loader\-master.{0,1000}","offensive_tool_keyword","Shellcode-Loader","dynamic shellcode loading","T1055 - T1055.012 - T1027 - T1027.005","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/ReversingID/Shellcode-Loader","1","1","N/A","N/A","10","3","244","44","2025-01-25T16:30:56Z","2021-08-08T08:53:03Z","59350" +"*ShellcodeRDI.*",".{0,1000}ShellcodeRDI\..{0,1000}","offensive_tool_keyword","sRDI","Shellcode Reflective DLL Injection - Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode","T1620 - T1055.001 - T1059.004 - T1027 - T1105","TA0005 - TA0004 - TA0002","N/A","N/A","Resource Development","https://github.com/monoxgas/sRDI","1","1","N/A","N/A","N/A","10","2262","473","2023-11-15T10:53:00Z","2017-07-28T19:30:53Z","59351" +"*ShellcodeRDI.py*",".{0,1000}ShellcodeRDI\.py.{0,1000}","offensive_tool_keyword","EvtMute","This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging - mute the event log","T1562.004 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/bats3c/EvtMute","1","1","N/A","N/A","10","3","261","51","2021-04-24T19:23:39Z","2020-08-29T00:13:20Z","59352" +"*ShellcodeRDI.py*",".{0,1000}ShellcodeRDI\.py.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","59353" +"*shellcode-runner.py*",".{0,1000}shellcode\-runner\.py.{0,1000}","offensive_tool_keyword","PayGen","FUD metasploit Persistence RAT","T1059.001 - T1209 - T1105 - T1547 - T1027","TA0003 - TA0005 - TA0002 - TA0011","N/A","N/A","Persistence","https://github.com/youhacker55/PayGen","1","1","N/A","N/A","N/A","1","4","0","2023-02-23T00:05:57Z","2021-06-16T20:20:55Z","59354" +"*ShellcodeTemplate.x64.bin*",".{0,1000}ShellcodeTemplate\.x64\.bin.{0,1000}","offensive_tool_keyword","DllNotificationInjection","A POC of a new threadless process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote processes.","T1055.011 - T1055.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/ShorSec/DllNotificationInjection","1","1","N/A","N/A","10","1","23","3","2023-08-23T13:50:27Z","2023-12-01T12:47:43Z","59355" +"*ShellCodeTester.csproj*",".{0,1000}ShellCodeTester\.csproj.{0,1000}","offensive_tool_keyword","shellcodetester","This tools test generated ShellCodes","T1059.003 - T1059.005 - T1027.002","TA0002 - TA0005 - TA0040","N/A","N/A","Resource Development","https://github.com/helviojunior/shellcodetester","1","1","N/A","N/A","N/A","1","92","30","2024-11-06T00:48:22Z","2019-06-11T04:39:58Z","59357" +"*shellcodetester.exe*",".{0,1000}shellcodetester\.exe.{0,1000}","offensive_tool_keyword","shellcodetester","This tools test generated ShellCodes","T1059.003 - T1059.005 - T1027.002","TA0002 - TA0005 - TA0040","N/A","N/A","Resource Development","https://github.com/helviojunior/shellcodetester","1","1","N/A","N/A","N/A","1","92","30","2024-11-06T00:48:22Z","2019-06-11T04:39:58Z","59358" +"*shellcodetester.git*",".{0,1000}shellcodetester\.git.{0,1000}","offensive_tool_keyword","shellcodetester","This tools test generated ShellCodes","T1059.003 - T1059.005 - T1027.002","TA0002 - TA0005 - TA0040","N/A","N/A","Resource Development","https://github.com/helviojunior/shellcodetester","1","1","N/A","N/A","N/A","1","92","30","2024-11-06T00:48:22Z","2019-06-11T04:39:58Z","59359" +"*shellcodetester.sh*",".{0,1000}shellcodetester\.sh.{0,1000}","offensive_tool_keyword","shellcodetester","This tools test generated ShellCodes","T1059.003 - T1059.005 - T1027.002","TA0002 - TA0005 - TA0040","N/A","N/A","Resource Development","https://github.com/helviojunior/shellcodetester","1","1","N/A","N/A","N/A","1","92","30","2024-11-06T00:48:22Z","2019-06-11T04:39:58Z","59360" +"*ShellCodeTester.sln*",".{0,1000}ShellCodeTester\.sln.{0,1000}","offensive_tool_keyword","shellcodetester","This tools test generated ShellCodes","T1059.003 - T1059.005 - T1027.002","TA0002 - TA0005 - TA0040","N/A","N/A","Resource Development","https://github.com/helviojunior/shellcodetester","1","1","N/A","N/A","N/A","1","92","30","2024-11-06T00:48:22Z","2019-06-11T04:39:58Z","59361" +"*ShellGhost.dll",".{0,1000}ShellGhost\.dll","offensive_tool_keyword","ShellGhost","A memory-based evasion technique which makes shellcode invisible from process start to end","T1055.012 - T1027.002 - T1055.001","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/lem0nSec/ShellGhost","1","1","N/A","N/A","N/A","10","1175","140","2023-10-16T06:40:24Z","2023-07-01T16:56:58Z","59367" +"*ShellGhost.exe*",".{0,1000}ShellGhost\.exe.{0,1000}","offensive_tool_keyword","ShellGhost","A memory-based evasion technique which makes shellcode invisible from process start to end","T1055.012 - T1027.002 - T1055.001","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/lem0nSec/ShellGhost","1","1","N/A","N/A","N/A","10","1175","140","2023-10-16T06:40:24Z","2023-07-01T16:56:58Z","59368" +"*ShellGhost.sln*",".{0,1000}ShellGhost\.sln.{0,1000}","offensive_tool_keyword","ShellGhost","A memory-based evasion technique which makes shellcode invisible from process start to end","T1055.012 - T1027.002 - T1055.001","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/lem0nSec/ShellGhost","1","1","N/A","N/A","N/A","10","1175","140","2023-10-16T06:40:24Z","2023-07-01T16:56:58Z","59369" +"*ShellGhost.vcxproj*",".{0,1000}ShellGhost\.vcxproj.{0,1000}","offensive_tool_keyword","ShellGhost","A memory-based evasion technique which makes shellcode invisible from process start to end","T1055.012 - T1027.002 - T1055.001","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/lem0nSec/ShellGhost","1","1","N/A","N/A","N/A","10","1175","140","2023-10-16T06:40:24Z","2023-07-01T16:56:58Z","59370" +"*ShellGhost_mapping.py*",".{0,1000}ShellGhost_mapping\.py.{0,1000}","offensive_tool_keyword","ShellGhost","A memory-based evasion technique which makes shellcode invisible from process start to end","T1055.012 - T1027.002 - T1055.001","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/lem0nSec/ShellGhost","1","1","N/A","N/A","N/A","10","1175","140","2023-10-16T06:40:24Z","2023-07-01T16:56:58Z","59371" +"*ShellGhost-master.zip*",".{0,1000}ShellGhost\-master\.zip.{0,1000}","offensive_tool_keyword","ShellGhost","A memory-based evasion technique which makes shellcode invisible from process start to end","T1055.012 - T1027.002 - T1055.001","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/lem0nSec/ShellGhost","1","1","N/A","N/A","N/A","10","1175","140","2023-10-16T06:40:24Z","2023-07-01T16:56:58Z","59372" +"*ShellProfilePersistence.json*",".{0,1000}ShellProfilePersistence\.json.{0,1000}","offensive_tool_keyword","merlin","Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT)","T1219 - T1105 - T1071 - T1090 - T1055 - T1047","TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Ne0nd0g/merlin","1","1","N/A","N/A","10","10","5221","826","2025-04-17T15:08:42Z","2017-01-06T11:18:20Z","59373" +"*ShellPwnsh.exe*",".{0,1000}ShellPwnsh\.exe.{0,1000}","offensive_tool_keyword","ShellPwnsh","Reverse Shell in Golang and PowerShell Fud","T1059.001 - T1573.002 - T1105","TA0011 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/BlackShell256/ShellPwnsh","1","1","N/A","N/A","9","10","9","6","2022-05-01T08:42:54Z","2022-04-28T01:26:08Z","59374" +"*ShellPwnsh.go*",".{0,1000}ShellPwnsh\.go.{0,1000}","offensive_tool_keyword","ShellPwnsh","Reverse Shell in Golang and PowerShell Fud","T1059.001 - T1573.002 - T1105","TA0011 - TA0010 - TA0005","N/A","N/A","C2","https://github.com/BlackShell256/ShellPwnsh","1","1","N/A","N/A","9","10","9","6","2022-05-01T08:42:54Z","2022-04-28T01:26:08Z","59375" +"*shellster/LDAPPER*",".{0,1000}shellster\/LDAPPER.{0,1000}","offensive_tool_keyword","LDAPPER","LDAP Querying without the Suck","T1087 - T1069 - T1018","TA0007","N/A","N/A","Discovery","https://github.com/shellster/LDAPPER","1","1","N/A","N/A","7","1","99","11","2024-11-09T03:53:26Z","2020-06-17T16:53:35Z","59376" +"*shellter.exe*",".{0,1000}shellter\.exe.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","59377" +"*shepardsbind_recv.py*",".{0,1000}shepardsbind_recv\.py.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","59378" +"*shepbind_serv.exe*",".{0,1000}shepbind_serv\.exe.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","59379" +"*Sherlock.ps1*",".{0,1000}Sherlock\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","59380" +"*sherlock.ps1*",".{0,1000}sherlock\.ps1.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","59381" +"*Sherlock_Vulns.txt*",".{0,1000}Sherlock_Vulns\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","59382" +"*Shhhavoc.py *",".{0,1000}Shhhavoc\.py\s.{0,1000}","offensive_tool_keyword","Shhhloader","shellcode loader that compiles a C++ stub to bypass AV/EDR","T1027 - T1055 - T1140 - T1218","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/icyguider/Shhhloader","1","1","N/A","N/A","9","10","1186","191","2024-05-08T20:24:35Z","2021-09-28T16:52:24Z","59383" +"*Shhhloader.py*",".{0,1000}Shhhloader\.py.{0,1000}","offensive_tool_keyword","Shhhloader","shellcode loader that compiles a C++ stub to bypass AV/EDR","T1027 - T1055 - T1140 - T1218","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/icyguider/Shhhloader","1","1","N/A","N/A","9","10","1186","191","2024-05-08T20:24:35Z","2021-09-28T16:52:24Z","59384" +"*Shhmon.csproj*",".{0,1000}Shhmon\.csproj.{0,1000}","offensive_tool_keyword","shhmon","Neutering Sysmon via driver unload","T1518.001 ","TA0007","N/A","N/A","Defense Evasion","https://github.com/matterpreter/Shhmon","1","1","N/A","N/A","N/A","3","228","37","2022-10-13T16:56:41Z","2019-09-12T14:13:19Z","59386" +"*Shhmon.exe*",".{0,1000}Shhmon\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59387" +"*Shhmon.exe*",".{0,1000}Shhmon\.exe.{0,1000}","offensive_tool_keyword","shhmon","Neutering Sysmon via driver unload","T1518.001 ","TA0007","N/A","N/A","Defense Evasion","https://github.com/matterpreter/Shhmon","1","1","N/A","N/A","N/A","3","228","37","2022-10-13T16:56:41Z","2019-09-12T14:13:19Z","59388" +"*Shhmon.git*",".{0,1000}Shhmon\.git.{0,1000}","offensive_tool_keyword","shhmon","Neutering Sysmon via driver unload","T1518.001 ","TA0007","N/A","N/A","Defense Evasion","https://github.com/matterpreter/Shhmon","1","1","N/A","N/A","N/A","3","228","37","2022-10-13T16:56:41Z","2019-09-12T14:13:19Z","59389" +"*shinject.nim*",".{0,1000}shinject\.nim.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","59392" +"*shit.fuck.org*",".{0,1000}shit\.fuck\.org.{0,1000}","offensive_tool_keyword","dnschef-ng","DNSChef is a highly configurable DNS proxy for Penetration Testers and Malware Analysts. A DNS proxy (aka ""Fake DNS"") is a tool used for application network traffic analysis among other uses. For example - a DNS proxy can be used to fake requests for ""badguy.com"" to point to a local machine for termination or interception instead of a real host somewhere on the Internet.","T1568 - T1583 - T1071","TA0001 - TA0042 - TA0005","N/A","N/A","Sniffing & Spoofing","https://github.com/byt3bl33d3r/dnschef-ng","1","1","N/A","N/A","8","2","153","14","2023-11-26T06:57:04Z","2021-12-24T21:07:29Z","59394" +"*shmilylty/cheetah*",".{0,1000}shmilylty\/cheetah.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","1","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","59395" +"*shocknawe.py*",".{0,1000}shocknawe\.py.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","59396" +"*Shodan.io*",".{0,1000}Shodan\.io.{0,1000}","offensive_tool_keyword","shodan.io","Shodan is the worlds first search engine for Internet-connected devices.","T1016 - T1597 - T1526 - T1046 - T1087 - T1078 - T1056 - T1018 - T1016 - T1583 - T1589","TA0001 - TA0002 - TA0003 - TA0005 - TA0007 - TA0011","N/A","Black Basta","Reconnaissance","https://www.shodan.io/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","59397" +"*shodanp.py*",".{0,1000}shodanp\.py.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","59398" +"*ShorSec/DavRelayUp*",".{0,1000}ShorSec\/DavRelayUp.{0,1000}","offensive_tool_keyword","DavRelayUp","DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced","T1078 - T1078.004 - T1068","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/ShorSec/DavRelayUp","1","1","N/A","N/A","9","6","542","81","2023-06-05T09:17:06Z","2023-06-05T07:49:39Z","59401" +"*ShorSec/DllNotificationInjection*",".{0,1000}ShorSec\/DllNotificationInjection.{0,1000}","offensive_tool_keyword","DllNotificationInjection","A POC of a new threadless process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote processes.","T1055.011 - T1055.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/ShorSec/DllNotificationInjection","1","1","N/A","N/A","10","1","23","3","2023-08-23T13:50:27Z","2023-12-01T12:47:43Z","59402" +"*ShorSec/ShadowSpray*",".{0,1000}ShorSec\/ShadowSpray.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1110.003 - T1098 - T1059 - T1075","TA0001 - TA0008 - TA0009","N/A","Black Basta","Discovery","https://github.com/ShorSec/ShadowSpray","1","1","N/A","N/A","7","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","59403" +"*Show-BallonTip.ps1*",".{0,1000}Show\-BallonTip\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","59404" +"*Show-BalloonTip.ps1*",".{0,1000}Show\-BalloonTip\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","59405" +"*Show-TargetScreen.ps1*",".{0,1000}Show\-TargetScreen\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","59406" +"*Show-TargetScreen.ps1*",".{0,1000}Show\-TargetScreen\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","59407" +"*shucknt.php*",".{0,1000}shucknt\.php.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","59423" +"*ShuckNT-main*",".{0,1000}ShuckNT\-main.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","59424" +"*ShutdownRepo/pywhisker*",".{0,1000}ShutdownRepo\/pywhisker.{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","1","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","59425" +"*ShutdownRepo/smartbrute*",".{0,1000}ShutdownRepo\/smartbrute.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","59426" +"*ShutdownRepo/smartbrute*",".{0,1000}ShutdownRepo\/smartbrute.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","1","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","59427" +"*sid::clear*",".{0,1000}sid\:\:clear.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","59436" +"*sid::lookup*",".{0,1000}sid\:\:lookup.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","59437" +"*sid::modify*",".{0,1000}sid\:\:modify.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","59438" +"*sid::patch*",".{0,1000}sid\:\:patch.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","59439" +"*sigflip*/Bof/*",".{0,1000}sigflip.{0,1000}\/Bof\/.{0,1000}","offensive_tool_keyword","C2 related tools","SigFlip is a tool for patching authenticode signed PE files (exe. dll. sys ..etc) without invalidating or breaking the existing signature.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/med0x2e/SigFlip","1","1","N/A","N/A","10","10","1139","197","2023-08-27T18:27:50Z","2021-08-08T15:59:19Z","59440" +"*SigFlip.WinTrustData*",".{0,1000}SigFlip\.WinTrustData.{0,1000}","offensive_tool_keyword","cobaltstrike","SigFlip is a tool for patching authenticode signed PE files (exe. dll. sys ..etc) without invalidating or breaking the existing signature.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/med0x2e/SigFlip","1","1","N/A","N/A","10","10","1139","197","2023-08-27T18:27:50Z","2021-08-08T15:59:19Z","59442" +"*SigLoader.*",".{0,1000}SigLoader\..{0,1000}","offensive_tool_keyword","C2 related tools","SigFlip is a tool for patching authenticode signed PE files (exe. dll. sys ..etc) without invalidating or breaking the existing signature.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/med0x2e/SigFlip","1","1","N/A","N/A","10","10","1139","197","2023-08-27T18:27:50Z","2021-08-08T15:59:19Z","59447" +"*SigLoader/sigloader.c*",".{0,1000}SigLoader\/sigloader\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","SigFlip is a tool for patching authenticode signed PE files (exe. dll. sys ..etc) without invalidating or breaking the existing signature.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/med0x2e/SigFlip","1","1","N/A","N/A","10","10","1139","197","2023-08-27T18:27:50Z","2021-08-08T15:59:19Z","59448" +"*SigmaPotato.exe*",".{0,1000}SigmaPotato\.exe.{0,1000}","offensive_tool_keyword","SigmaPotato","SeImpersonate privilege escalation tool","T1134 - T1055 - T1543","TA0004 - TA0005 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/tylerdotrar/SigmaPotato","1","1","N/A","N/A","9","4","326","38","2024-05-16T23:46:04Z","2023-09-09T01:35:42Z","59449" +"*SigmaPotatoCore.exe*",".{0,1000}SigmaPotatoCore\.exe.{0,1000}","offensive_tool_keyword","SigmaPotato","SeImpersonate privilege escalation tool","T1134 - T1055 - T1543","TA0004 - TA0005 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/tylerdotrar/SigmaPotato","1","1","N/A","N/A","9","4","326","38","2024-05-16T23:46:04Z","2023-09-09T01:35:42Z","59450" +"*signal2john.py*",".{0,1000}signal2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","59451" +"*Signal-Labs/NtdllUnpatcher*",".{0,1000}Signal\-Labs\/NtdllUnpatcher.{0,1000}","offensive_tool_keyword","NtdllUnpatcher","code for EDR bypassing","T1070.004 - T1055.001 - T1562.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Signal-Labs/NtdllUnpatcher","1","1","N/A","N/A","10","2","150","33","2019-03-07T11:10:40Z","2019-03-07T10:20:19Z","59452" +"*SignToolEx.exe*",".{0,1000}SignToolEx\.exe.{0,1000}","offensive_tool_keyword","SignToolEx","Patching signtool.exe to accept expired certificates for code-signing","T1553.002 - T1649","TA0005","N/A","N/A","Defense Evasion","https://github.com/hackerhouse-opensource/SignToolEx","1","1","N/A","N/A","8","3","275","47","2024-07-19T17:22:28Z","2023-12-29T14:26:45Z","59454" +"*SignToolExHook.dll*",".{0,1000}SignToolExHook\.dll.{0,1000}","offensive_tool_keyword","SignToolEx","Patching signtool.exe to accept expired certificates for code-signing","T1553.002 - T1649","TA0005","N/A","N/A","Defense Evasion","https://github.com/hackerhouse-opensource/SignToolEx","1","1","N/A","N/A","8","3","275","47","2024-07-19T17:22:28Z","2023-12-29T14:26:45Z","59455" +"*SigPloit*",".{0,1000}SigPloit.{0,1000}","offensive_tool_keyword","SigPloit","SigPloit a signaling security testing framework dedicated to Telecom Security professionals and reasearchers to pentest and exploit vulnerabilites in the signaling protocols used in mobile operators regardless of the geneartion being in use. SigPloit aims to cover all used protocols used in the operators interconnects SS7. GTP (3G). Diameter (4G) or even SIP for IMS and VoLTE infrastructures used in the access layer and SS7 message encapsulation into SIP-T. Recommendations for each vulnerability will be provided to guide the tester and the operator the steps that should be done to enhance their security posture","T1573 - T1562 - T1189 - T1190 - T1201","TA0002 - TA0003 - TA0007 - TA0008","N/A","N/A","Reconnaissance","https://github.com/SigPloiter/SigPloit","1","1","N/A","N/A","N/A","2","164","56","2019-12-17T16:51:23Z","2017-03-30T03:46:03Z","59457" +"*SigThief.py*",".{0,1000}SigThief\.py.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","59459" +"*Sigthief.py*",".{0,1000}Sigthief\.py.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","59460" +"*sigthief.py*",".{0,1000}sigthief\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","59461" +"*SigThief-master*",".{0,1000}SigThief\-master.{0,1000}","offensive_tool_keyword","metatwin","The project is designed as a file resource cloner. Metadata including digital signature is extracted from one file and injected into another","T1553.002 - T1114.001 - T1564.003","TA0006 - TA0010","N/A","N/A","Exploitation tool","https://github.com/threatexpress/metatwin","1","1","N/A","N/A","9","4","345","71","2024-11-19T19:45:59Z","2017-10-08T13:26:00Z","59462" +"*sigwhatever.exe*",".{0,1000}sigwhatever\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","59463" +"*SilenceDefender.ps1*",".{0,1000}SilenceDefender\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","59465" +"*SilenceDefender_ATP.log*",".{0,1000}SilenceDefender_ATP\.log.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","#logfile","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","59466" +"*SilenceDefender_ATP.ps1*",".{0,1000}SilenceDefender_ATP\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","59467" +"*Silent.Crypto.Miner.Builder.zip*",".{0,1000}Silent\.Crypto\.Miner\.Builder\.zip.{0,1000}","offensive_tool_keyword","SilentCryptoMiner","A Silent (Hidden) Free Crypto Miner Builder","T1496 - T1055 - T1546 - T1082 - T1574","TA0042 - TA0005 - TA0003 - TA0009","N/A","N/A","Cryptomining","https://github.com/UnamSanctam/SilentCryptoMiner","1","1","N/A","N/A","9","","N/A","","","","59470" +"*silentbreaksec/Throwback*",".{0,1000}silentbreaksec\/Throwback.{0,1000}","offensive_tool_keyword","Throwback","HTTP/S Beaconing Implant","T1071.001 - T1102 - T1095 - T1573.001 - T1041","TA0011 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/silentbreaksec/Throwback","1","1","N/A","N/A","10","10","306","83","2017-08-25T16:49:12Z","2014-08-08T17:06:24Z","59471" +"*SilentCleanupWinDirBOF*",".{0,1000}SilentCleanupWinDirBOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of UAC Bypass Techniques Weaponized as BOFs","T1548.002 - T1203 - T1055 - T1134.002","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/icyguider/UAC-BOF-Bonanza","1","1","N/A","N/A","10","6","500","65","2024-02-21T22:07:54Z","2024-02-16T14:47:13Z","59472" +"*SilentCryptoMiner-scm-v*",".{0,1000}SilentCryptoMiner\-scm\-v.{0,1000}","offensive_tool_keyword","SilentCryptoMiner","A Silent (Hidden) Free Crypto Miner Builder","T1496 - T1055 - T1546 - T1082 - T1574","TA0042 - TA0005 - TA0003 - TA0009","N/A","N/A","Cryptomining","https://github.com/UnamSanctam/SilentCryptoMiner","1","1","N/A","N/A","9","","N/A","","","","59474" +"*silenthound.py*",".{0,1000}silenthound\.py.{0,1000}","offensive_tool_keyword","SilentHound","Quietly enumerate an Active Directory Domain via LDAP parsing users + admins + groups...","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/layer8secure/SilentHound","1","1","N/A","AD Enumeration","7","5","489","47","2023-01-23T20:41:55Z","2022-07-01T13:49:24Z","59475" +"*silenthound_enum*",".{0,1000}silenthound_enum.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","59476" +"*silenthound_output_*.txt*",".{0,1000}silenthound_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","59477" +"*SilentHound-main*",".{0,1000}SilentHound\-main.{0,1000}","offensive_tool_keyword","SilentHound","Quietly enumerate an Active Directory Domain via LDAP parsing users + admins + groups...","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/layer8secure/SilentHound","1","1","N/A","AD Enumeration","7","5","489","47","2023-01-23T20:41:55Z","2022-07-01T13:49:24Z","59478" +"*silentLsassDump*",".{0,1000}silentLsassDump.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/guervild/BOFs","1","1","N/A","N/A","10","10","161","27","2022-05-02T16:59:24Z","2021-03-15T23:30:22Z","59479" +"*SilentMoonwalk.cpp*",".{0,1000}SilentMoonwalk\.cpp.{0,1000}","offensive_tool_keyword","SilentMoonwalk","PoC Implementation of a fully dynamic call stack spoofer","T1055 - T1055.012 - T1562 - T1562.001 - T1070 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/klezVirus/SilentMoonwalk","1","1","N/A","N/A","9","8","760","100","2024-07-20T10:41:31Z","2022-12-04T13:30:33Z","59480" +"*SilentMoonwalk.exe*",".{0,1000}SilentMoonwalk\.exe.{0,1000}","offensive_tool_keyword","SilentMoonwalk","PoC Implementation of a fully dynamic call stack spoofer","T1055 - T1055.012 - T1562 - T1562.001 - T1070 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/klezVirus/SilentMoonwalk","1","1","N/A","N/A","9","8","760","100","2024-07-20T10:41:31Z","2022-12-04T13:30:33Z","59481" +"*SilentMoonwalk.sln*",".{0,1000}SilentMoonwalk\.sln.{0,1000}","offensive_tool_keyword","SilentMoonwalk","PoC Implementation of a fully dynamic call stack spoofer","T1055 - T1055.012 - T1562 - T1562.001 - T1070 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/klezVirus/SilentMoonwalk","1","1","N/A","N/A","9","8","760","100","2024-07-20T10:41:31Z","2022-12-04T13:30:33Z","59482" +"*SilentMoonwalk-master*",".{0,1000}SilentMoonwalk\-master.{0,1000}","offensive_tool_keyword","SilentMoonwalk","PoC Implementation of a fully dynamic call stack spoofer","T1055 - T1055.012 - T1562 - T1562.001 - T1070 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/klezVirus/SilentMoonwalk","1","1","N/A","N/A","9","8","760","100","2024-07-20T10:41:31Z","2022-12-04T13:30:33Z","59483" +"*SilentProcessExitRegistrySetter.cpp*",".{0,1000}SilentProcessExitRegistrySetter\.cpp.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","1","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","59484" +"*SilentProcessExitRegistrySetter.exe*",".{0,1000}SilentProcessExitRegistrySetter\.exe.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","1","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","59485" +"*silenttrinity*.dll*",".{0,1000}silenttrinity.{0,1000}\.dll.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","59487" +"*silly.host.of.iodine.code.kryo.se*",".{0,1000}silly\.host\.of\.iodine\.code\.kryo\.se.{0,1000}","offensive_tool_keyword","iodine","iodine. iodined - tunnel IPv4 over DNS","T1573.001 - T1573.002 - T1573.003 - T1573.004","TA0011 - TA0010 - TA0002 - TA0005","N/A","EMBER BEAR","C2","https://github.com/yarrick/iodine","1","1","N/A","N/A","10","10","6413","524","2025-04-08T17:44:12Z","2012-02-04T19:51:39Z","59488" +"*SillyRAT.git*",".{0,1000}SillyRAT\.git.{0,1000}","offensive_tool_keyword","SillyRAT","A Cross Platform multifunctional (Windows/Linux/Mac) RAT.","T1055.003 - T1027 - T1105 - T1005","TA0002 - TA0003 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hash3liZer/SillyRAT","1","1","N/A","N/A","N/A","10","792","162","2023-12-09T00:42:07Z","2020-05-10T17:37:37Z","59489" +"*sillyrat.py*",".{0,1000}sillyrat\.py.{0,1000}","offensive_tool_keyword","SillyRAT","A Cross Platform multifunctional (Windows/Linux/Mac) RAT.","T1055.003 - T1027 - T1105 - T1005","TA0002 - TA0003 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/hash3liZer/SillyRAT","1","1","N/A","N/A","N/A","10","792","162","2023-12-09T00:42:07Z","2020-05-10T17:37:37Z","59490" +"*silver*implant.go*",".{0,1000}silver.{0,1000}implant\.go.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","59492" +"*SilverPoision/Rock-ON*",".{0,1000}SilverPoision\/Rock\-ON.{0,1000}","offensive_tool_keyword","Rock-ON","Rock-On is a all in one recon tool that will help your Recon process give a boost. It is mainley aimed to automate the whole process of recon and save the time that is being wasted in doing all this stuffs manually","T1590 - T1210.001 - T1190 - T1213","TA0007 - TA0002 - TA0003","N/A","N/A","Reconnaissance","https://github.com/SilverPoision/Rock-ON","1","1","N/A","N/A","N/A","3","297","69","2019-11-30T04:00:03Z","2019-06-10T04:42:32Z","59494" +"*SimoneLazzaris/ditty*",".{0,1000}SimoneLazzaris\/ditty.{0,1000}","offensive_tool_keyword","POC","POC exploitation for dirty pipe vulnerability","T1543","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SimoneLazzaris/ditty","1","1","N/A","N/A","N/A","1","2","1","2022-03-10T16:15:14Z","2022-03-09T09:20:27Z","59496" +"*Simple Shellcode Runner.csproj*",".{0,1000}Simple\sShellcode\sRunner\.csproj.{0,1000}","offensive_tool_keyword","OSEP-Code-Snippets","notable code snippets for Offensive Security's PEN-300 (OSEP) course","T1116 - T1204.002 - T1027.009 - T1021.005 - T1560.001 - T1100 - T1003.001 - T1564.001 - T1047 - T1210 - T1134.002 - T1055 - T1055.011 - T1055.012 - T1204","TA0005 - TA0040 - TA0008 - TA0003 - TA0006 - TA0004","N/A","N/A","Exploitation tool","https://github.com/chvancooten/OSEP-Code-Snippets","1","1","N/A","N/A","8","10","1254","444","2024-01-04T15:17:17Z","2021-03-10T21:34:41Z","59500" +"*Simple Shellcode Runner.ps1*",".{0,1000}Simple\sShellcode\sRunner\.ps1.{0,1000}","offensive_tool_keyword","OSEP-Code-Snippets","notable code snippets for Offensive Security's PEN-300 (OSEP) course","T1116 - T1204.002 - T1027.009 - T1021.005 - T1560.001 - T1100 - T1003.001 - T1564.001 - T1047 - T1210 - T1134.002 - T1055 - T1055.011 - T1055.012 - T1204","TA0005 - TA0040 - TA0008 - TA0003 - TA0006 - TA0004","N/A","N/A","Exploitation tool","https://github.com/chvancooten/OSEP-Code-Snippets","1","1","N/A","N/A","8","10","1254","444","2024-01-04T15:17:17Z","2021-03-10T21:34:41Z","59501" +"*Simple Shellcode Runner.vba*",".{0,1000}Simple\sShellcode\sRunner\.vba.{0,1000}","offensive_tool_keyword","OSEP-Code-Snippets","notable code snippets for Offensive Security's PEN-300 (OSEP) course","T1116 - T1204.002 - T1027.009 - T1021.005 - T1560.001 - T1100 - T1003.001 - T1564.001 - T1047 - T1210 - T1134.002 - T1055 - T1055.011 - T1055.012 - T1204","TA0005 - TA0040 - TA0008 - TA0003 - TA0006 - TA0004","N/A","N/A","Exploitation tool","https://github.com/chvancooten/OSEP-Code-Snippets","1","1","N/A","N/A","8","10","1254","444","2024-01-04T15:17:17Z","2021-03-10T21:34:41Z","59502" +"*simple_dropper.ninja*",".{0,1000}simple_dropper\.ninja.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","59503" +"*simple_php_web_shell_get.php*",".{0,1000}simple_php_web_shell_get\.php.{0,1000}","offensive_tool_keyword","php-reverse-shell","PHP shells that work on Linux OS - macOS and Windows OS","T1505.003 - T1059.003 - T1100","TA0003 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/ivan-sincek/php-reverse-shell","1","1","N/A","N/A","10","10","482","152","2023-10-03T09:48:21Z","2020-07-14T07:22:54Z","59504" +"*simple_php_web_shell_get.php*",".{0,1000}simple_php_web_shell_get\.php.{0,1000}","offensive_tool_keyword","php-reverse-shell","PHP shells that work on Linux OS - macOS and Windows OS","T1505.003 - T1059.003 - T1100","TA0003 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/ivan-sincek/php-reverse-shell","1","1","N/A","N/A","10","10","482","152","2023-10-03T09:48:21Z","2020-07-14T07:22:54Z","59505" +"*simple_php_web_shell_get__mini_v2.php*",".{0,1000}simple_php_web_shell_get__mini_v2\.php.{0,1000}","offensive_tool_keyword","php-reverse-shell","PHP shells that work on Linux OS - macOS and Windows OS","T1505.003 - T1059.003 - T1100","TA0003 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/ivan-sincek/php-reverse-shell","1","1","N/A","N/A","10","10","482","152","2023-10-03T09:48:21Z","2020-07-14T07:22:54Z","59506" +"*simple_php_web_shell_get_mini.php*",".{0,1000}simple_php_web_shell_get_mini\.php.{0,1000}","offensive_tool_keyword","php-reverse-shell","PHP shells that work on Linux OS - macOS and Windows OS","T1505.003 - T1059.003 - T1100","TA0003 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/ivan-sincek/php-reverse-shell","1","1","N/A","N/A","10","10","482","152","2023-10-03T09:48:21Z","2020-07-14T07:22:54Z","59507" +"*simple_php_web_shell_get_v2.php*",".{0,1000}simple_php_web_shell_get_v2\.php.{0,1000}","offensive_tool_keyword","php-reverse-shell","PHP shells that work on Linux OS - macOS and Windows OS","T1505.003 - T1059.003 - T1100","TA0003 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/ivan-sincek/php-reverse-shell","1","1","N/A","N/A","10","10","482","152","2023-10-03T09:48:21Z","2020-07-14T07:22:54Z","59508" +"*simple_php_web_shell_get_v2.php*",".{0,1000}simple_php_web_shell_get_v2\.php.{0,1000}","offensive_tool_keyword","php-reverse-shell","PHP shells that work on Linux OS - macOS and Windows OS","T1505.003 - T1059.003 - T1100","TA0003 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/ivan-sincek/php-reverse-shell","1","1","N/A","N/A","10","10","482","152","2023-10-03T09:48:21Z","2020-07-14T07:22:54Z","59509" +"*simple_php_web_shell_post.php*",".{0,1000}simple_php_web_shell_post\.php.{0,1000}","offensive_tool_keyword","php-reverse-shell","PHP shells that work on Linux OS - macOS and Windows OS","T1505.003 - T1059.003 - T1100","TA0003 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/ivan-sincek/php-reverse-shell","1","1","N/A","N/A","10","10","482","152","2023-10-03T09:48:21Z","2020-07-14T07:22:54Z","59510" +"*simple_php_web_shell_post_mini.php*",".{0,1000}simple_php_web_shell_post_mini\.php.{0,1000}","offensive_tool_keyword","php-reverse-shell","PHP shells that work on Linux OS - macOS and Windows OS","T1505.003 - T1059.003 - T1100","TA0003 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/ivan-sincek/php-reverse-shell","1","1","N/A","N/A","10","10","482","152","2023-10-03T09:48:21Z","2020-07-14T07:22:54Z","59511" +"*SimpleBackdoorAdmin.dll*",".{0,1000}SimpleBackdoorAdmin\.dll.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SimpleBackdoorAdmin","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","59512" +"*SimpleBackdoorAdmin.dll*",".{0,1000}SimpleBackdoorAdmin\.dll.{0,1000}","offensive_tool_keyword","SimpleBackdoorAdmin","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SimpleBackdoorAdmin","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","59513" +"*SimpleBackdoorAdmin.exe*",".{0,1000}SimpleBackdoorAdmin\.exe.{0,1000}","offensive_tool_keyword","precompiled-binaries","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SimpleBackdoorAdmin","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","59514" +"*SimpleBackdoorAdmin.exe*",".{0,1000}SimpleBackdoorAdmin\.exe.{0,1000}","offensive_tool_keyword","SimpleBackdoorAdmin","executables for penetration testing Windows Active Directory environments","T1016 - T1046 - T1087 - T1082 - T1055 - T1068 - T1083 - T1012 - T1558 - T1097 - T1077 - T1134 - T1550 - T1078 - T1021 - T1072 - T1484 - T1553 - T1557 - T1003 - T1555 - T1134 - T1055 - T1088","TA0007 - TA0008 - TA0004 - TA0006 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/jakobfriedl/precompiled-binaries","1","1","N/A","SimpleBackdoorAdmin","10","2","138","38","2025-03-06T13:02:11Z","2023-08-08T12:21:46Z","59515" +"*simplekeylogger.*",".{0,1000}simplekeylogger\..{0,1000}","offensive_tool_keyword","undertheradar","scripts that afford the pentester AV bypass techniques","T1055.005 - T1027 - T1116 - T1070.004","TA0040 - TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/g3tsyst3m/undertheradar","1","1","N/A","N/A","9","1","11","2","2023-10-08T23:31:33Z","2023-07-01T17:59:20Z","59547" +"*SimpleNtSyscallFuzzer.v11.suo*",".{0,1000}SimpleNtSyscallFuzzer\.v11\.suo.{0,1000}","offensive_tool_keyword","SimpleNTSyscallFuzzer","Fuzzer for Windows kernel syscalls.","T1055.011 - T1218","TA0005 - TA0007","N/A","N/A","Discovery","https://github.com/waleedassar/SimpleNTSyscallFuzzer","1","1","N/A","N/A","7","2","145","25","2024-01-25T02:39:31Z","2022-03-12T10:16:30Z","59548" +"*SimplyEmail.py*",".{0,1000}SimplyEmail\.py.{0,1000}","offensive_tool_keyword","SimplyEmail","SimplyEmail was built arround the concept that tools should do somthing. and do that somthing well. hence simply What is the simple email recon tool? This tool was based off the work of theHarvester and kind of a port of the functionality. This was just an expansion of what was used to build theHarvester and will incorporate his work but allow users to easily build Modules for the Framework. Which I felt was desperately needed after building my first module for theHarvester.","T1210.001 - T1190 - T1583.001 - T1590","TA0007 - TA0002 - ","N/A","N/A","Reconnaissance","https://github.com/SimplySecurity/SimplyEmail","1","1","N/A","N/A","5","10","953","228","2023-01-12T22:20:25Z","2015-10-30T03:12:10Z","59550" +"*SimplyEmail-master*",".{0,1000}SimplyEmail\-master.{0,1000}","offensive_tool_keyword","SimplyEmail","SimplyEmail was built arround the concept that tools should do somthing. and do that somthing well. hence simply What is the simple email recon tool? This tool was based off the work of theHarvester and kind of a port of the functionality. This was just an expansion of what was used to build theHarvester and will incorporate his work but allow users to easily build Modules for the Framework. Which I felt was desperately needed after building my first module for theHarvester.","T1210.001 - T1190 - T1583.001 - T1590","TA0007 - TA0002 - ","N/A","N/A","Reconnaissance","https://github.com/SimplySecurity/SimplyEmail","1","1","N/A","N/A","5","10","953","228","2023-01-12T22:20:25Z","2015-10-30T03:12:10Z","59551" +"*SimplySecurity/SimplyEmail*",".{0,1000}SimplySecurity\/SimplyEmail.{0,1000}","offensive_tool_keyword","SimplyEmail","SimplyEmail was built arround the concept that tools should do somthing. and do that somthing well. hence simply What is the simple email recon tool? This tool was based off the work of theHarvester and kind of a port of the functionality. This was just an expansion of what was used to build theHarvester and will incorporate his work but allow users to easily build Modules for the Framework. Which I felt was desperately needed after building my first module for theHarvester.","T1210.001 - T1190 - T1583.001 - T1590","TA0007 - TA0002 - ","N/A","N/A","Reconnaissance","https://github.com/SimplySecurity/SimplyEmail","1","1","N/A","N/A","5","10","953","228","2023-01-12T22:20:25Z","2015-10-30T03:12:10Z","59552" +"*sin5678/gh0st*",".{0,1000}sin5678\/gh0st.{0,1000}","offensive_tool_keyword","gh0st","Malware RAT with keylogger - dll injection - C2 - Remote control","T1204.002 - T1071.001 - T1027 - T1036.005 - T1055.001 - T1005 - T1056.001 - T1074.001 - T1105 - T1562.001 - T1543.003 - T1547.001 - T1571 - T1573.001 - T1106 - T1219","TA0002 - TA0003 - TA0004 - TA0008 - TA0009 - TA0010 - TA0011","GhostRAT","N/A","Malware","https://github.com/sin5678/gh0st","1","1","N/A","N/A","10","6","508","274","2013-05-08T21:17:26Z","2012-10-05T06:25:36Z","59554" +"*SinclairMakeMeAdmin.adml*",".{0,1000}SinclairMakeMeAdmin\.adml.{0,1000}","offensive_tool_keyword","MakeMeAdmin","Enables users to elevate themselves to administrator-level rights","T1078 - T1059 - T1087","TA0004","N/A","N/A","Privilege Escalation","https://github.com/pseymour/MakeMeAdmin","1","1","N/A","N/A","9","5","430","94","2024-12-22T02:56:23Z","2018-05-29T19:42:58Z","59556" +"*SinclairMakeMeAdmin.admx*",".{0,1000}SinclairMakeMeAdmin\.admx.{0,1000}","offensive_tool_keyword","MakeMeAdmin","Enables users to elevate themselves to administrator-level rights","T1078 - T1059 - T1087","TA0004","N/A","N/A","Privilege Escalation","https://github.com/pseymour/MakeMeAdmin","1","1","N/A","N/A","9","5","430","94","2024-12-22T02:56:23Z","2018-05-29T19:42:58Z","59557" +"*single_reverse_tcp_shell.s*",".{0,1000}single_reverse_tcp_shell\.s.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59558" +"*single_shell_bind_tcp.asm*",".{0,1000}single_shell_bind_tcp\.asm.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59559" +"*single_shell_reverse_tcp.asm*",".{0,1000}single_shell_reverse_tcp\.asm.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59560" +"*single_target_exploit.rb*",".{0,1000}single_target_exploit\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59561" +"*sipdump2john.py*",".{0,1000}sipdump2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","59564" +"*SirepRAT_RCE_as_SYSTEM_on_Windows_IoT_Core_Slides.pdf*",".{0,1000}SirepRAT_RCE_as_SYSTEM_on_Windows_IoT_Core_Slides\.pdf.{0,1000}","offensive_tool_keyword","SirepRAT","RAT tool - Remote Command Execution as SYSTEM on Windows IoT Core","T1059 - T1219 - T1105 - T1021","TA0002 - TA0011 - TA0003","N/A","N/A","C2","https://github.com/SafeBreach-Labs/SirepRAT","1","1","N/A","N/A","7","10","380","89","2020-12-13T09:52:55Z","2019-03-02T19:51:05Z","59567" +"*SirepRAT_RCE_as_SYSTEM_on_Windows_IoT_Core_White_Paper.pdf*",".{0,1000}SirepRAT_RCE_as_SYSTEM_on_Windows_IoT_Core_White_Paper\.pdf.{0,1000}","offensive_tool_keyword","SirepRAT","RAT tool - Remote Command Execution as SYSTEM on Windows IoT Core","T1059 - T1219 - T1105 - T1021","TA0002 - TA0011 - TA0003","N/A","N/A","C2","https://github.com/SafeBreach-Labs/SirepRAT","1","1","N/A","N/A","7","10","380","89","2020-12-13T09:52:55Z","2019-03-02T19:51:05Z","59568" +"*SirepRAT-2.0.0.zip*",".{0,1000}SirepRAT\-2\.0\.0\.zip.{0,1000}","offensive_tool_keyword","SirepRAT","RAT tool - Remote Command Execution as SYSTEM on Windows IoT Core","T1059 - T1219 - T1105 - T1021","TA0002 - TA0011 - TA0003","N/A","N/A","C2","https://github.com/SafeBreach-Labs/SirepRAT","1","1","N/A","N/A","7","10","380","89","2020-12-13T09:52:55Z","2019-03-02T19:51:05Z","59569" +"*Sitadel-master.zip*",".{0,1000}Sitadel\-master\.zip.{0,1000}","offensive_tool_keyword","Sitadel","Web Application Security Scanner","T1592.002 - T1210.001 - T1190.001 - T1046 - T1213 - T1071.001","TA0001 - TA0007 - TA0043 - TA0002 - TA0003","N/A","N/A","Reconnaissance","https://github.com/shenril/Sitadel","1","1","N/A","N/A","5","6","577","112","2023-11-29T01:33:28Z","2018-01-17T09:06:24Z","59574" +"*site-packages/wfuzz*",".{0,1000}site\-packages\/wfuzz.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","59575" +"*-Situational-Awareness-BOF*",".{0,1000}\-Situational\-Awareness\-BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","59576" +"*six2dez/reconftw*",".{0,1000}six2dez\/reconftw.{0,1000}","offensive_tool_keyword","reconftw","reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities","T1595 - T1590 - T1592 - T1596 - T1598 - T1046 - T1599 - T1213 - T1597","TA0043 - TA0042 - TA0007 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/six2dez/reconftw","1","1","#linux","N/A","7","10","6202","982","2025-04-22T13:01:31Z","2020-12-30T23:52:52Z","59577" +"*skahwah*wordsmith*",".{0,1000}skahwah.{0,1000}wordsmith.{0,1000}","offensive_tool_keyword","wordsmith","The aim of Wordsmith is to assist with creating tailored wordlists and usernames that are primarilly based on geolocation.","T1210.001 - T1583.001 - T1583.002","TA0007 - ","N/A","N/A","Credential Access","https://github.com/skahwah/wordsmith","1","1","N/A","N/A","N/A","2","167","20","2018-05-03T13:44:01Z","2016-07-06T14:02:51Z","59579" +"*skalkoto/winexe*",".{0,1000}skalkoto\/winexe.{0,1000}","offensive_tool_keyword","winexe","Winexe remotely executes commands on Windows systems from GNU/Linux","T1059.004 - T1021.005 - T1078.003","TA0002 - TA0008 - TA0011","N/A","APT28","Lateral Movement","https://www.kali.org/tools/winexe/","1","1","#linux #windows","N/A","8","8","N/A","N/A","N/A","N/A","59580" +"*skelsec/evilrdp*",".{0,1000}skelsec\/evilrdp.{0,1000}","offensive_tool_keyword","evilrdp","Th evil twin of aardwolfgui using the aardwolf RDP client library that gives you extended control over the target and additional scripting capabilities from the command line.","T1021.001 - T1056.001 - T1113 - T1078.002 - T1105 - T1090.002 - T1059.001","TA0008 - TA0002 - TA0005 - TA0001 - TA0009 - TA0010 - TA0011","N/A","Black Basta","C2","https://github.com/skelsec/evilrdp","1","1","N/A","N/A","10","10","299","31","2025-03-15T13:37:21Z","2023-11-29T13:44:58Z","59581" +"*skelsec/jackdaw*",".{0,1000}skelsec\/jackdaw.{0,1000}","offensive_tool_keyword","jackdaw","Jackdaw is here to collect all information in your domain. store it in a SQL database and show you nice graphs on how your domain objects interact with each-other an how a potential attacker may exploit these interactions. It also comes with a handy feature to help you in a password-cracking project by storing/looking up/reporting hashes/passowrds/users.","T1087 - T1482 - T1201 - T1213 - T1003","TA0007 - TA0008 - TA0009 - TA0006","N/A","N/A","Reconnaissance","https://github.com/skelsec/jackdaw","1","1","N/A","N/A","N/A","6","576","89","2025-03-15T13:37:50Z","2019-03-27T18:36:41Z","59582" +"*skelsec/pysnaffler*",".{0,1000}skelsec\/pysnaffler.{0,1000}","offensive_tool_keyword","pysnaffler","This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.","T1083 - T1087 - T1114 - T1518","TA0007 - TA0009 - TA0010","N/A","N/A","Collection","https://github.com/skelsec/pysnaffler","1","1","N/A","N/A","10","1","91","5","2025-03-15T13:46:34Z","2023-11-17T21:52:40Z","59583" +"*SkipPasswordAgeCheck*",".{0,1000}SkipPasswordAgeCheck.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","59584" +"*SkipPortScan*",".{0,1000}SkipPortScan.{0,1000}","offensive_tool_keyword","sharphound","C# Data Collector for BloodHound","T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046","TA0007 - TA0043 - TA0005 - TA0042","Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx","APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor","Discovery","https://github.com/BloodHoundAD/SharpHound","1","1","N/A","N/A","N/A","10","904","195","2025-04-18T20:45:04Z","2021-07-12T17:07:04Z","59585" +"*sknux/CVE-2021-21985_PoC*",".{0,1000}sknux\/CVE\-2021\-21985_PoC.{0,1000}","offensive_tool_keyword","POC","CVE-2021-21985 POC exploitation","T1190 - T1059.001 - T1040","TA0001 - TA0003 - TA0009","N/A","Dispossessor","Exploitation tool","https://github.com/sknux/CVE-2021-21985_PoC","1","1","N/A","N/A","7","1","3","1","2021-11-09T19:14:55Z","2021-11-09T19:06:29Z","59586" +"*SkyperTHC/bpf-keylogger*",".{0,1000}SkyperTHC\/bpf\-keylogger.{0,1000}","offensive_tool_keyword","bpf-keylogger","Keylogger written in BPF","T1056.001 - T1053.005","TA0006 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/SkyperTHC/bpf-keylogger","1","1","N/A","N/A","10","1","4","1","2024-01-29T18:08:01Z","2024-01-29T09:34:47Z","59589" +"*SLACKAES256Handler.*",".{0,1000}SLACKAES256Handler\..{0,1000}","offensive_tool_keyword","Nuages","A modular C2 framework","T1071 - T1090 - T1102 - T1027 - T1571","TA0011 - TA0003 - TA0010","N/A","Dispossessor","C2","https://github.com/p3nt4/Nuages","1","1","N/A","N/A","10","10","455","85","2025-04-10T15:34:19Z","2019-05-12T11:00:35Z","59590" +"*sleep_python_bridge.sleepy*",".{0,1000}sleep_python_bridge\.sleepy.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","59597" +"*sleep_python_bridge.striker*",".{0,1000}sleep_python_bridge\.striker.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","59598" +"*sleepmask.x64.o*",".{0,1000}sleepmask\.x64\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","59600" +"*sleepmask.x86.o*",".{0,1000}sleepmask\.x86\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","59601" +"*sleepmask_pivot.x64.o*",".{0,1000}sleepmask_pivot\.x64\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","59602" +"*sleepmask_pivot.x86.o*",".{0,1000}sleepmask_pivot\.x86\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need for for the standard GUI client.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Cobalt-Strike/sleep_python_bridge","1","1","N/A","N/A","10","10","184","32","2023-04-12T15:00:48Z","2021-10-12T18:18:48Z","59603" +"*sleventyeleven/linuxprivchecker*",".{0,1000}sleventyeleven\/linuxprivchecker.{0,1000}","offensive_tool_keyword","linuxprivchecker","search for common privilege escalation vectors such as world writable files. misconfigurations. clear-text passwords and applicable exploits","T1210.001 - T1082 - T1088 - T1547.001","TA0002 - TA0004 - TA0006 - TA0007 - TA0008","N/A","N/A","Privilege Escalation","https://github.com/sleventyeleven/linuxprivchecker/blob/master/linuxprivchecker.py","1","1","#linux","N/A","7","10","1645","524","2022-01-31T10:32:08Z","2016-04-19T13:31:46Z","59605" +"*SlinkyCat.ps1*",".{0,1000}SlinkyCat\.ps1.{0,1000}","offensive_tool_keyword","SlinkyCat","This script performs a series of AD enumeration tasks","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/LaresLLC/SlinkyCat","1","1","N/A","AD Enumeration","7","1","79","8","2023-07-12T15:29:31Z","2023-07-03T23:44:18Z","59606" +"*SlinkyCat-main*",".{0,1000}SlinkyCat\-main.{0,1000}","offensive_tool_keyword","SlinkyCat","This script performs a series of AD enumeration tasks","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/LaresLLC/SlinkyCat","1","1","N/A","AD Enumeration","7","1","79","8","2023-07-12T15:29:31Z","2023-07-03T23:44:18Z","59607" +"*sliver.sh/install*",".{0,1000}sliver\.sh\/install.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","59613" +"*sliver/.sliver*",".{0,1000}sliver\/\.sliver.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","59614" +"*sliver_pcap_parser.py*",".{0,1000}sliver_pcap_parser\.py.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","59616" +"*sliver-client.exe*",".{0,1000}sliver\-client\.exe.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","59618" +"*sliver-client.log*",".{0,1000}sliver\-client\.log.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","#logfile","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","59619" +"*sliver-client_linux*",".{0,1000}sliver\-client_linux.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","#linux","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","59620" +"*sliver-client_macos*",".{0,1000}sliver\-client_macos.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","59621" +"*sliver-client_windows.exe*",".{0,1000}sliver\-client_windows\.exe.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","59622" +"*sliver-dns*",".{0,1000}sliver\-dns.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","59623" +"*SliverKeylogger*",".{0,1000}SliverKeylogger.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/trustedsec/SliverKeylogger","1","1","N/A","N/A","10","10","159","44","2023-09-22T19:39:04Z","2022-06-17T19:32:53Z","59624" +"*sliver-server.*",".{0,1000}sliver\-server\..{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","59633" +"*sliver-server.exe*",".{0,1000}sliver\-server\.exe.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","59634" +"*sliver-server-linux.zip*",".{0,1000}sliver\-server\-linux\.zip.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","#linux","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","59635" +"*sliver-server-macos.zip*",".{0,1000}sliver\-server\-macos\.zip.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","59636" +"*sliver-server-windows.zip*",".{0,1000}sliver\-server\-windows\.zip.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","59637" +"*Slowerzs/PPLSystem*","Slowerzs\/PPLSystem","offensive_tool_keyword","PPLSystem","creates a livedump of the machine through NtDebugSystemControl to extract the COM secret and context, to then inject inside this process.","T1003.002","TA0006","N/A","N/A","Credential Access","https://github.com/Slowerzs/PPLSystem","1","1","N/A","N/A","10","2","190","23","2024-05-29T18:33:35Z","2024-05-22T17:48:49Z","59638" +"*Slowerzs/ThievingFox*",".{0,1000}Slowerzs\/ThievingFox.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","1","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","59639" +"*slowloris.py*",".{0,1000}slowloris\.py.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59640" +"*SluiEOP.ps1*",".{0,1000}SluiEOP\.ps1.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","59641" +"*slyd0g/DLLHijackTest*",".{0,1000}slyd0g\/DLLHijackTest.{0,1000}","offensive_tool_keyword","DLLHijackTest","DLL and PowerShell script to assist with finding DLL hijacks","T1574.002 - T1055.001 - T1059.001 - T1036.005","TA0005 - TA0004 - TA0002","N/A","N/A","Defense Evasion","https://github.com/slyd0g/DLLHijackTest","1","1","N/A","N/A","9","4","335","62","2020-10-01T22:37:36Z","2020-06-20T04:33:01Z","59642" +"*slyd0g/SharpClipboard*",".{0,1000}slyd0g\/SharpClipboard.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","1","N/A","N/A","8","1","N/A","N/A","N/A","N/A","59643" +"*smartbrute.py*",".{0,1000}smartbrute\.py.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","1","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","59649" +"*SmashedPotato.cs*",".{0,1000}SmashedPotato\.cs.{0,1000}","offensive_tool_keyword","SmashedPotato","A modification of @breenmachine original Hot Potato Priv Esc Exploit","T1059 - T1134 - T1201 - T1518","TA0002 - TA0004 - TA0040","N/A","N/A","Exploitation tool","https://github.com/Cn33liz/SmashedPotato","1","1","N/A","N/A","N/A","1","83","35","2016-01-29T14:31:18Z","2016-01-20T20:49:08Z","59650" +"*SmashedPotato.exe*",".{0,1000}SmashedPotato\.exe.{0,1000}","offensive_tool_keyword","SmashedPotato","A modification of @breenmachine original Hot Potato Priv Esc Exploit","T1059 - T1134 - T1201 - T1518","TA0002 - TA0004 - TA0040","N/A","N/A","Exploitation tool","https://github.com/Cn33liz/SmashedPotato","1","1","N/A","N/A","N/A","1","83","35","2016-01-29T14:31:18Z","2016-01-20T20:49:08Z","59651" +"*smb.dcsync*",".{0,1000}smb\.dcsync.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","59655" +"*smb/impacket*",".{0,1000}smb\/impacket.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59656" +"*smb/relay/ntlm*",".{0,1000}smb\/relay\/ntlm.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59657" +"*smb_doublepulsar_rce.*",".{0,1000}smb_doublepulsar_rce\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59659" +"*smb_doublepulsar_rce.rb*",".{0,1000}smb_doublepulsar_rce\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59660" +"*smb_enumshares*",".{0,1000}smb_enumshares.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59661" +"*smb_enumshares.*",".{0,1000}smb_enumshares\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59662" +"*smb_enumusers*",".{0,1000}smb_enumusers.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59663" +"*smb_enumusers.*",".{0,1000}smb_enumusers\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59664" +"*smb_enumusers_domain.*",".{0,1000}smb_enumusers_domain\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59665" +"*smb_eternalblue*",".{0,1000}smb_eternalblue.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-EternalBlue.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","59666" +"*smb_ghost.py*",".{0,1000}smb_ghost\.py.{0,1000}","offensive_tool_keyword","SMBGhost","Simple scanner for CVE-2020-0796 - SMBv3 RCE.","T1210 - T1573 - T1553 - T1216 - T1027","TA0006 - TA0011 - TA0008","N/A","N/A","Discovery","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","7","7","N/A","N/A","N/A","N/A","59667" +"*smb_ms17_010_pass*",".{0,1000}smb_ms17_010_pass.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59668" +"*smb_pipename_stager*",".{0,1000}smb_pipename_stager.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","59669" +"*smb_rras_erraticgopher.*",".{0,1000}smb_rras_erraticgopher\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59670" +"*smb_shadow.*",".{0,1000}smb_shadow\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59671" +"*smb_shadow.rb*",".{0,1000}smb_shadow\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59672" +"*smb_stealth.py*",".{0,1000}smb_stealth\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","59673" +"*smb_win.py*",".{0,1000}smb_win\.py.{0,1000}","offensive_tool_keyword","SMBGhost_RCE_PoC","RCE PoC for CVE-2020-0796 SMBGhost","T1210 - T1059 - T1505 - T1021 - T1027","TA0001 - TA0002 - TA0003 - TA0040","N/A","N/A","Exploitation tool","https://github.com/chompie1337/SMBGhost_RCE_PoC","1","1","N/A","N/A","N/A","10","1339","349","2020-07-02T18:51:47Z","2020-06-02T00:14:47Z","59674" +"*smb1_anonymous_connect_ipc*",".{0,1000}smb1_anonymous_connect_ipc.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-EternalBlue.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","59675" +"*smb1_anonymous_login*",".{0,1000}smb1_anonymous_login.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-EternalBlue.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","59676" +"*smbattack.py*",".{0,1000}smbattack\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","59679" +"*smbattack.py*",".{0,1000}smbattack\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","59680" +"*smbcrawler*",".{0,1000}smbcrawler.{0,1000}","offensive_tool_keyword","smbcrawler","SmbCrawler is a tool that takes credentials and a list of hosts and crawls through those shares","T1077 - T1021 - T1110 - T1083","TA0007 - TA0008","N/A","N/A","Discovery","https://github.com/SySS-Research/smbcrawler","1","1","N/A","N/A","N/A","2","161","21","2025-03-24T07:46:43Z","2021-06-09T19:27:08Z","59684" +"*SMBCrunch-master*",".{0,1000}SMBCrunch\-master.{0,1000}","offensive_tool_keyword","SMBCrunch","SMBCrunch allows a red teamer to quickly identify Windows File Shares in a network - performs a recursive directory listing of the provided shares and can even grab a file from the remote share if it looks like a juicy target.","T1021.002 - T1005 - T1210","TA0001 - TA0002 - TA0003 - TA0009","N/A","N/A","Lateral Movement","https://github.com/Raikia/SMBCrunch","1","1","N/A","N/A","9","2","165","20","2018-03-07T15:50:12Z","2016-03-25T10:10:19Z","59685" +"*SMBeagle.exe*",".{0,1000}SMBeagle\.exe.{0,1000}","offensive_tool_keyword","SMBeagle","SMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host.","T1087.002 - T1021.002 - T1210","TA0007 - TA0008 - TA0003","N/A","N/A","Discovery","https://github.com/punk-security/SMBeagle","1","1","N/A","N/A","9","8","712","80","2025-01-21T22:34:00Z","2021-05-31T19:46:57Z","59686" +"*SMBeagle.sln*",".{0,1000}SMBeagle\.sln.{0,1000}","offensive_tool_keyword","SMBeagle","SMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host.","T1087.002 - T1021.002 - T1210","TA0007 - TA0008 - TA0003","N/A","N/A","Discovery","https://github.com/punk-security/SMBeagle","1","1","N/A","N/A","9","8","712","80","2025-01-21T22:34:00Z","2021-05-31T19:46:57Z","59687" +"*smbeagle_*_linux_amd64.zip*",".{0,1000}smbeagle_.{0,1000}_linux_amd64\.zip.{0,1000}","offensive_tool_keyword","SMBeagle","SMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host.","T1087.002 - T1021.002 - T1210","TA0007 - TA0008 - TA0003","N/A","N/A","Discovery","https://github.com/punk-security/SMBeagle","1","1","#linux","N/A","9","8","712","80","2025-01-21T22:34:00Z","2021-05-31T19:46:57Z","59688" +"*smbeagle_*_linux_arm64.zip*",".{0,1000}smbeagle_.{0,1000}_linux_arm64\.zip.{0,1000}","offensive_tool_keyword","SMBeagle","SMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host.","T1087.002 - T1021.002 - T1210","TA0007 - TA0008 - TA0003","N/A","N/A","Discovery","https://github.com/punk-security/SMBeagle","1","1","#linux","N/A","9","8","712","80","2025-01-21T22:34:00Z","2021-05-31T19:46:57Z","59689" +"*smbeagle_*_win_x64.zip*",".{0,1000}smbeagle_.{0,1000}_win_x64\.zip.{0,1000}","offensive_tool_keyword","SMBeagle","SMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host.","T1087.002 - T1021.002 - T1210","TA0007 - TA0008 - TA0003","N/A","N/A","Discovery","https://github.com/punk-security/SMBeagle","1","1","N/A","N/A","9","8","712","80","2025-01-21T22:34:00Z","2021-05-31T19:46:57Z","59690" +"*SMBetray*",".{0,1000}SMBetray.{0,1000}","offensive_tool_keyword","SMBetray","PoC to demonstrate the ability of an attacker to intercept and modify insecure SMB connections. as well as compromise some secured SMB connections if credentials are known.","T1557 - T1562 - T1553 - T1213","TA0002 - TA0008 - TA0007","N/A","N/A","Sniffing & Spoofing","https://github.com/quickbreach/SMBetray","1","1","N/A","N/A","N/A","4","387","87","2018-08-17T00:45:05Z","2018-08-12T00:38:02Z","59692" +"*smbexec.py*",".{0,1000}smbexec\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","59696" +"*SMBGhost.pcap*",".{0,1000}SMBGhost\.pcap.{0,1000}","offensive_tool_keyword","SMBGhost","Simple scanner for CVE-2020-0796 - SMBv3 RCE.","T1210 - T1573 - T1553 - T1216 - T1027","TA0006 - TA0011 - TA0008","N/A","N/A","Discovery","https://github.com/ollypwn/SMBGhost","1","1","N/A","N/A","7","7","678","194","2020-10-01T08:36:29Z","2020-03-11T15:21:27Z","59697" +"*smblogin-spray.ps1*",".{0,1000}smblogin\-spray\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","59700" +"*smbmapDump*",".{0,1000}smbmapDump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","59705" +"*smbmap-master*",".{0,1000}smbmap\-master.{0,1000}","offensive_tool_keyword","smbmap","SMBMap allows users to enumerate samba share drives across an entire domain. List share drives. drive permissions. share contents. upload/download functionality. file name auto-download pattern matching. and even execute remote commands. This tool was designed with pen testing in mind. and is intended to simplify searching for potentially sensitive data across large networks.","T1210.001 - T1083 - T1213 - T1021","TA0007 - TA0003 - TA0002 - TA0001","N/A","MuddyWater - Dispossessor","Discovery","https://github.com/ShawnDEvans/smbmap","1","1","N/A","N/A","10","10","1890","359","2025-02-28T18:09:10Z","2015-03-16T13:15:00Z","59708" +"*SMBNTLMChallenge*",".{0,1000}SMBNTLMChallenge.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-InveighRelay.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","59710" +"*SMBNTLMResponse*",".{0,1000}SMBNTLMResponse.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","59711" +"*smbpasswd.py*",".{0,1000}smbpasswd\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","59713" +"*SMBRelay.py*",".{0,1000}SMBRelay\.py.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","N/A","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","59714" +"*SMBRelayChallenge*",".{0,1000}SMBRelayChallenge.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-InveighRelay.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","59715" +"*smbrelayclient.py*",".{0,1000}smbrelayclient\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","59716" +"*smbrelayclient.py*",".{0,1000}smbrelayclient\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","59717" +"*smbrelayclient.py*",".{0,1000}smbrelayclient\.py.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","1","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","59718" +"*SMBRelayResponse*",".{0,1000}SMBRelayResponse.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-InveighRelay.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","59719" +"*smbrelayserver.*",".{0,1000}smbrelayserver\..{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","59720" +"*smbrelayserver.py*",".{0,1000}smbrelayserver\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","59721" +"*smbrelayx.py*",".{0,1000}smbrelayx\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","59722" +"*smb-reverse-shell.git*",".{0,1000}smb\-reverse\-shell\.git.{0,1000}","offensive_tool_keyword","smb-reverse-shell","A Reverse Shell which uses an XML file on an SMB share as a communication channel.","T1021.002 - T1027 - T1105","TA0008 - TA0010 - TA0002","N/A","N/A","C2","https://github.com/r1cksec/smb-reverse-shell","1","1","N/A","N/A","10","10","17","0","2024-02-17T12:20:01Z","2022-01-16T21:02:14Z","59723" +"*smb-reverse-shell-main*",".{0,1000}smb\-reverse\-shell\-main.{0,1000}","offensive_tool_keyword","smb-reverse-shell","A Reverse Shell which uses an XML file on an SMB share as a communication channel.","T1021.002 - T1027 - T1105","TA0008 - TA0010 - TA0002","N/A","N/A","C2","https://github.com/r1cksec/smb-reverse-shell","1","1","N/A","N/A","10","10","17","0","2024-02-17T12:20:01Z","2022-01-16T21:02:14Z","59724" +"*smbscan*",".{0,1000}smbscan.{0,1000}","offensive_tool_keyword","smb-scanner","SMB Scanner tool","T1210.001 - T1190 - T1020 - T1213","TA0007 - TA0002 - TA0001","N/A","APT22","Reconnaissance","https://github.com/TechnicalMujeeb/smb-scanner","1","1","N/A","N/A","N/A","1","61","18","2018-03-30T10:25:18Z","2018-03-29T14:13:20Z","59725" +"*smb-scanner*",".{0,1000}smb\-scanner.{0,1000}","offensive_tool_keyword","smb-scanner","SMB Scanner tool","T1210.001 - T1190 - T1020 - T1213","TA0007 - TA0002 - TA0001","N/A","N/A","Reconnaissance","https://github.com/TechnicalMujeeb/smb-scanner","1","1","N/A","N/A","N/A","1","61","18","2018-03-30T10:25:18Z","2018-03-29T14:13:20Z","59726" +"*smb-secrets-revealer.py*",".{0,1000}smb\-secrets\-revealer\.py.{0,1000}","offensive_tool_keyword","smbsr","Lookup for interesting stuff in SMB shares","T1135","TA0001 - TA0007","N/A","N/A","Discovery","https://github.com/oldboy21/SMBSR","1","1","N/A","N/A","7","2","149","23","2023-06-16T14:35:30Z","2021-11-10T16:55:52Z","59728" +"*smbserver.py*",".{0,1000}smbserver\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","59731" +"*smbspider.py*",".{0,1000}smbspider\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","59734" +"*smbsr.py*",".{0,1000}smbsr\.py.{0,1000}","offensive_tool_keyword","SMBSR","Lookup for interesting stuff in SMB shares","T1110.001 - T1046 - T1021.002 - T1077.001 - T1069.002 - T1083 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Reconnaissance","https://github.com/oldboy21/SMBSR","1","1","N/A","N/A","N/A","2","149","23","2023-06-16T14:35:30Z","2021-11-10T16:55:52Z","59735" +"*Smbtouch.exe*",".{0,1000}Smbtouch\.exe.{0,1000}","offensive_tool_keyword","Smbtouch-Scanner","Smbtouch detect whether the target is vulnerable of one of these vulnerabilities: ETERNALBLUE - ETERNALCHAMPION - ETERNALROMANCE - ETERNALSYNERGY","T1210 - T1046 - T1133","TA0007 - TA0043 - TA0008","N/A","APT15 - Turla","Lateral Movement","https://github.com/3gstudent/Smbtouch-Scanner","1","1","N/A","N/A","10","2","140","66","2021-04-17T01:42:06Z","2017-04-21T01:38:55Z","59737" +"*Smbtouch-1.1.1.exe*",".{0,1000}Smbtouch\-1\.1\.1\.exe.{0,1000}","offensive_tool_keyword","Smbtouch-Scanner","Smbtouch detect whether the target is vulnerable of one of these vulnerabilities: ETERNALBLUE - ETERNALCHAMPION - ETERNALROMANCE - ETERNALSYNERGY","T1210 - T1046 - T1133","TA0007 - TA0043 - TA0008","N/A","APT15 - Turla","Lateral Movement","https://github.com/3gstudent/Smbtouch-Scanner","1","1","N/A","N/A","10","2","140","66","2021-04-17T01:42:06Z","2017-04-21T01:38:55Z","59738" +"*Smbtouch-1.1.1.xml*",".{0,1000}Smbtouch\-1\.1\.1\.xml.{0,1000}","offensive_tool_keyword","Smbtouch-Scanner","Smbtouch detect whether the target is vulnerable of one of these vulnerabilities: ETERNALBLUE - ETERNALCHAMPION - ETERNALROMANCE - ETERNALSYNERGY","T1210 - T1046 - T1133","TA0007 - TA0043 - TA0008","N/A","APT15 - Turla","Lateral Movement","https://github.com/3gstudent/Smbtouch-Scanner","1","1","N/A","N/A","10","2","140","66","2021-04-17T01:42:06Z","2017-04-21T01:38:55Z","59739" +"*SmbtouchScanner.py*",".{0,1000}SmbtouchScanner\.py.{0,1000}","offensive_tool_keyword","Smbtouch-Scanner","Smbtouch detect whether the target is vulnerable of one of these vulnerabilities: ETERNALBLUE - ETERNALCHAMPION - ETERNALROMANCE - ETERNALSYNERGY","T1210 - T1046 - T1133","TA0007 - TA0043 - TA0008","N/A","APT15 - Turla","Lateral Movement","https://github.com/3gstudent/Smbtouch-Scanner","1","1","N/A","N/A","10","2","140","66","2021-04-17T01:42:06Z","2017-04-21T01:38:55Z","59740" +"*smicallef/spiderfoot*",".{0,1000}smicallef\/spiderfoot.{0,1000}","offensive_tool_keyword","spiderfoot","The OSINT Platform for Security Assessments","T1595 - T1595.002 - T1596 - T1591 - T1591.002","TA0043 ","N/A","N/A","Reconnaissance","https://www.spiderfoot.net/","1","1","N/A","N/A","6","10","N/A","N/A","N/A","N/A","59750" +"*SMShell.sln*",".{0,1000}SMShell\.sln.{0,1000}","offensive_tool_keyword","SMShell","PoC for a SMS-based shell. Send commands and receive responses over SMS from mobile broadband capable computers","T1021.001 - T1059.006 - T1071.004 - T1069.003","TA0002 - TA0011 - TA0009 - TA0040","N/A","N/A","C2","https://github.com/persistent-security/SMShell","1","1","N/A","N/A","10","10","360","35","2023-05-22T10:40:16Z","2023-05-22T08:26:44Z","59751" +"*smtprelayclient.py*",".{0,1000}smtprelayclient\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","59752" +"*smtprelayclient.py*",".{0,1000}smtprelayclient\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","59753" +"*smtp-user-enum.py*",".{0,1000}smtp\-user\-enum\.py.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","59758" +"*Smug246/Luna-Grabber*",".{0,1000}Smug246\/Luna\-Grabber.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","59759" +"*SnaffCon/Snaffler*",".{0,1000}SnaffCon\/Snaffler.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters and red teamers to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1595 - T1592 - T1589 - T1590 - T1591","TA0043","N/A","N/A","Reconnaissance","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","59764" +"*SnaffCore.csproj*",".{0,1000}SnaffCore\.csproj.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","59765" +"*SnaffCore/ActiveDirectory*",".{0,1000}SnaffCore\/ActiveDirectory.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","59766" +"*SnaffCore/Classifiers*",".{0,1000}SnaffCore\/Classifiers.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","59767" +"*SnaffCore/Concurrency*",".{0,1000}SnaffCore\/Concurrency.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","59768" +"*SnaffCore/Config*",".{0,1000}SnaffCore\/Config.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","59769" +"*SnaffCore/ShareFind*",".{0,1000}SnaffCore\/ShareFind.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","59770" +"*SnaffCore/TreeWalk*",".{0,1000}SnaffCore\/TreeWalk.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","59771" +"*Snaffler.csproj*",".{0,1000}Snaffler\.csproj.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters and red teamers to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1595 - T1592 - T1589 - T1590 - T1591","TA0043","N/A","N/A","Reconnaissance","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","59772" +"*Snaffler.exe*",".{0,1000}Snaffler\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","59773" +"*snaffler.exe*",".{0,1000}snaffler\.exe.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","59774" +"*snaffler.exe*",".{0,1000}snaffler\.exe.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters and red teamers to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1595 - T1592 - T1589 - T1590 - T1591","TA0043","N/A","N/A","Reconnaissance","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","59775" +"*snaffler.log*",".{0,1000}snaffler\.log.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters and red teamers to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1595 - T1592 - T1589 - T1590 - T1591","TA0043","N/A","N/A","Reconnaissance","https://github.com/SnaffCon/Snaffler","1","1","#logfile","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","59776" +"*Snaffler.sln*",".{0,1000}Snaffler\.sln.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","59778" +"*Snaffler.sln*",".{0,1000}Snaffler\.sln.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters and red teamers to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1595 - T1592 - T1589 - T1590 - T1591","TA0043","N/A","N/A","Reconnaissance","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","59779" +"*SnafflerMessage.cs*",".{0,1000}SnafflerMessage\.cs.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","59781" +"*SnafflerMessageType.cs*",".{0,1000}SnafflerMessageType\.cs.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","59782" +"*SnaffPoint.exe*",".{0,1000}SnaffPoint\.exe.{0,1000}","offensive_tool_keyword","SnaffPoint","A tool for pointesters to find candies in SharePoint","T1210.001 - T1087.002 - T1059.006","TA0007 - TA0002 - TA0006","N/A","N/A","Discovery","https://github.com/nheiniger/SnaffPoint","1","1","N/A","N/A","7","3","254","25","2022-11-04T13:26:24Z","2022-08-25T13:16:06Z","59783" +"*SnaffPoint-main*",".{0,1000}SnaffPoint\-main.{0,1000}","offensive_tool_keyword","SnaffPoint","A tool for pointesters to find candies in SharePoint","T1210.001 - T1087.002 - T1059.006","TA0007 - TA0002 - TA0006","N/A","N/A","Discovery","https://github.com/nheiniger/SnaffPoint","1","1","N/A","N/A","7","3","254","25","2022-11-04T13:26:24Z","2022-08-25T13:16:06Z","59784" +"*sneaky_gophish*",".{0,1000}sneaky_gophish.{0,1000}","offensive_tool_keyword","gophish","Hiding GoPhish from the boys in blue","T1566-001 - T1566-002 - T1566-003 - T1056-001 - T1113 - T1567-001","TA0002 - TA0003","N/A","Black Basta","Phishing","https://github.com/puzzlepeaches/sneaky_gophish/","1","1","N/A","N/A","10","2","180","58","2022-12-06T11:58:00Z","2021-06-24T12:41:54Z","59789" +"*sniff.su/Intercepter-NG*",".{0,1000}sniff\.su\/Intercepter\-NG.{0,1000}","offensive_tool_keyword","Intercepter-NG","android wifi sniffer","T1433","TA0006","N/A","N/A","Sniffing & Spoofing","https://github.com/intercepter-ng","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","59790" +"*SniffAir*",".{0,1000}SniffAir.{0,1000}","offensive_tool_keyword","SniffAir","SniffAir is an open-source wireless security framework which provides the ability to easily parse passively collected wireless data as well as launch sophisticated wireless attacks. SniffAir takes care of the hassle associated with managing large or multiple pcap files while thoroughly cross-examining and analyzing the traffic. looking for potential security flaws. Along with the prebuilt queries. SniffAir allows users to create custom queries for analyzing the wireless data stored in the backend SQL database. SniffAir is built on the concept of using these queries to extract data for wireless penetration test reports. The data can also be leveraged in setting up sophisticated wireless attacks included in SniffAir as modules.","T1530 - T1170 - T1059 - T1201","TA0002 - TA0003 - TA0007 - TA0008","N/A","N/A","Sniffing & Spoofing","https://github.com/Tylous/SniffAir","1","1","N/A","network exploitation tool","N/A","10","1206","167","2020-10-14T04:00:27Z","2017-02-20T18:32:32Z","59791" +"*sniffer.py*",".{0,1000}sniffer\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","59794" +"*sniffer-master.zip*",".{0,1000}sniffer\-master\.zip.{0,1000}","offensive_tool_keyword","sniffer","A modern alternative network traffic sniffer.","T1040 - T1052.001 - T1046 - T1552.002","TA0011 - TA0007 - TA0005","N/A","N/A","Sniffing & Spoofing","https://github.com/chenjiandongx/sniffer","1","1","N/A","N/A","N/A","8","769","67","2024-03-02T07:48:19Z","2021-11-08T15:36:03Z","59796" +"*SnifferSpoofer*",".{0,1000}SnifferSpoofer.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","59798" +"*SniffPass.exe*",".{0,1000}SniffPass\.exe.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","59800" +"*sniffpass-x64.zip*",".{0,1000}sniffpass\-x64\.zip.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","59801" +"*snmp_default_pass.txt*",".{0,1000}snmp_default_pass\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59802" +"*social_engineering/web_cloner*",".{0,1000}social_engineering\/web_cloner.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","59839" +"*SocialPwned.git*",".{0,1000}SocialPwned\.git.{0,1000}","offensive_tool_keyword","SocialPwned","SocialPwned is an OSINT tool that allows to get the emails. from a target. published in social networks like Instagram. Linkedin and Twitter to find the possible credential leaks in PwnDB or Dehashed and obtain Google account information via GHunt.","T1596","TA0002","N/A","N/A","Reconnaissance","https://github.com/MrTuxx/SocialPwned","1","1","N/A","N/A","N/A","10","1139","106","2025-01-28T19:07:29Z","2020-04-07T22:25:38Z","59840" +"*socialpwned.py*",".{0,1000}socialpwned\.py.{0,1000}","offensive_tool_keyword","SocialPwned","SocialPwned is an OSINT tool that allows to get the emails. from a target. published in social networks like Instagram. Linkedin and Twitter to find the possible credential leaks in PwnDB or Dehashed and obtain Google account information via GHunt.","T1596","TA0002","N/A","N/A","Reconnaissance","https://github.com/MrTuxx/SocialPwned","1","1","N/A","N/A","N/A","10","1139","106","2025-01-28T19:07:29Z","2020-04-07T22:25:38Z","59841" +"*socialpwned_*.txt*",".{0,1000}socialpwned_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","SocialPwned","SocialPwned is an OSINT tool that allows to get the emails. from a target. published in social networks like Instagram. Linkedin and Twitter to find the possible credential leaks in PwnDB or Dehashed and obtain Google account information via GHunt.","T1596","TA0002","N/A","N/A","Reconnaissance","https://github.com/MrTuxx/SocialPwned","1","1","N/A","N/A","N/A","10","1139","106","2025-01-28T19:07:29Z","2020-04-07T22:25:38Z","59842" +"*SOCK5Server.exe*",".{0,1000}SOCK5Server\.exe.{0,1000}","offensive_tool_keyword","ReverseSock5Proxy","A tiny Reverse Sock5 Proxy","T1090.002 - T1572 - T1071","TA0011 - TA0010","N/A","N/A","C2","https://github.com/Coldzer0/ReverseSock5Proxy","1","1","N/A","N/A","10","10","317","42","2022-11-28T21:18:26Z","2022-11-25T15:12:59Z","59845" +"*SOCK5Server_v0.0.1.zip*",".{0,1000}SOCK5Server_v0\.0\.1\.zip.{0,1000}","offensive_tool_keyword","ReverseSock5Proxy","A tiny Reverse Sock5 Proxy","T1090.002 - T1572 - T1071","TA0011 - TA0010","N/A","N/A","C2","https://github.com/Coldzer0/ReverseSock5Proxy","1","1","N/A","N/A","10","10","317","42","2022-11-28T21:18:26Z","2022-11-25T15:12:59Z","59846" +"*SocketHijacking.*",".{0,1000}SocketHijacking\..{0,1000}","offensive_tool_keyword","ConPtyShell","ConPtyShell - Fully Interactive Reverse Shell for Windows","T1059.001 - T1021.004 - T1056.003","TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antonioCoco/ConPtyShell","1","1","N/A","N/A","10","10","1102","171","2023-01-20T10:52:52Z","2019-09-13T22:11:18Z","59850" +"*socks5_exe.exe*",".{0,1000}socks5_exe\.exe.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","59854" +"*sokaRepo/CoercedPotatoRDLL*",".{0,1000}sokaRepo\/CoercedPotatoRDLL.{0,1000}","offensive_tool_keyword","CoercedPotatoRDLL","Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege","T1055 - T1134 - T1548","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/sokaRepo/CoercedPotatoRDLL","1","1","N/A","N/A","10","3","204","31","2023-11-23T18:58:41Z","2023-11-23T13:22:38Z","59872" +"*Soledge/BlockEtw*",".{0,1000}Soledge\/BlockEtw.{0,1000}","offensive_tool_keyword","BlockEtw",".Net Assembly to block ETW telemetry in current process","T1055.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/Soledge/BlockEtw","1","1","N/A","N/A","10","1","78","19","2020-05-14T19:24:49Z","2020-05-14T02:40:50Z","59881" +"*something.wattahog.org*",".{0,1000}something\.wattahog\.org.{0,1000}","offensive_tool_keyword","dnschef-ng","DNSChef is a highly configurable DNS proxy for Penetration Testers and Malware Analysts. A DNS proxy (aka ""Fake DNS"") is a tool used for application network traffic analysis among other uses. For example - a DNS proxy can be used to fake requests for ""badguy.com"" to point to a local machine for termination or interception instead of a real host somewhere on the Internet.","T1568 - T1583 - T1071","TA0001 - TA0042 - TA0005","N/A","N/A","Sniffing & Spoofing","https://github.com/byt3bl33d3r/dnschef-ng","1","1","N/A","N/A","8","2","153","14","2023-11-26T06:57:04Z","2021-12-24T21:07:29Z","59884" +"*sonarmsng5vzwqezlvtu2iiwwdn3dxkhotftikhowpfjuzg7p3ca5eid.onion*",".{0,1000}sonarmsng5vzwqezlvtu2iiwwdn3dxkhotftikhowpfjuzg7p3ca5eid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","59885" +"*sondr5344ygfweyjbfkw4fhsefv.heliofetch.at*",".{0,1000}sondr5344ygfweyjbfkw4fhsefv\.heliofetch\.at.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","59886" +"*souravbaghz/RadareEye*",".{0,1000}souravbaghz\/RadareEye.{0,1000}","offensive_tool_keyword","RadareEye","Tool for especially scanning nearby devices and execute a given command on its own system while the target device comes in range.","T1125 - T1071 - T1105 - T1057","TA0010 - TA0002 - TA0007","N/A","N/A","Lateral Movement","https://github.com/souravbaghz/RadareEye","1","1","N/A","N/A","N/A","4","364","49","2021-12-11T06:16:37Z","2021-01-07T04:52:58Z","59887" +"*source/byakugan*",".{0,1000}source\/byakugan.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59891" +"*source/dllinject*",".{0,1000}source\/dllinject.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59892" +"*source/flash_exploiter*",".{0,1000}source\/flash_exploiter.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59893" +"*source/javapayload*",".{0,1000}source\/javapayload.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59894" +"*source/psh_exe*",".{0,1000}source\/psh_exe.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59895" +"*source/shtinkering.*",".{0,1000}source\/shtinkering\..{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","59896" +"*SourcePoint*Loader.go*",".{0,1000}SourcePoint.{0,1000}Loader\.go.{0,1000}","offensive_tool_keyword","cobaltstrike","SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tylous/SourcePoint","1","1","N/A","N/A","10","10","1109","156","2025-04-16T17:15:04Z","2021-08-06T20:55:26Z","59903" +"*source-teamserver.sh*",".{0,1000}source\-teamserver\.sh.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","59904" +"*SpaceRunner-master.zip*",".{0,1000}SpaceRunner\-master\.zip.{0,1000}","offensive_tool_keyword","SpaceRunner","enables the compilation of a C# program that will execute arbitrary PowerShell code without launching PowerShell processes through the use of runspace.","T1059.001 - T1027","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Mr-B0b/SpaceRunner","1","1","N/A","N/A","7","2","195","38","2020-07-26T10:39:53Z","2020-07-26T09:31:09Z","59906" +"*SpamChannel-main.zip*",".{0,1000}SpamChannel\-main\.zip.{0,1000}","offensive_tool_keyword","SpamChannel","poof emails from any of the +2 Million domains using MailChannels","T1566 - T1566.001","TA0011","N/A","N/A","Sniffing & Spoofing","https://github.com/byt3bl33d3r/SpamChannel","1","1","N/A","N/A","8","4","335","36","2023-09-21T12:25:03Z","2022-12-20T21:31:55Z","59908" +"*Spartacus-main.zip*",".{0,1000}Spartacus\-main\.zip.{0,1000}","offensive_tool_keyword","Spartacus","Spartacus DLL/COM Hijacking Toolkit","T1574.001 - T1055.001 - T1027.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/Accenture/Spartacus","1","1","N/A","N/A","10","10","1037","141","2024-02-01T13:51:09Z","2022-10-28T09:00:35Z","59910" +"*Spartacus-v2.*-x64.zip*",".{0,1000}Spartacus\-v2\..{0,1000}\-x64\.zip.{0,1000}","offensive_tool_keyword","Spartacus","Spartacus DLL/COM Hijacking Toolkit","T1574.001 - T1055.001 - T1027.002","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/Accenture/Spartacus","1","1","N/A","N/A","10","10","1037","141","2024-02-01T13:51:09Z","2022-10-28T09:00:35Z","59912" +"*spartan-conseil/ratchatpt*",".{0,1000}spartan\-conseil\/ratchatpt.{0,1000}","offensive_tool_keyword","ratchatgpt","ratchatpt a tool using openai api as a C2","T1094 - T1071.001","TA0011 - TA0002","N/A","N/A","C2","https://github.com/spartan-conseil/ratchatpt","1","1","N/A","N/A","10","10","16","6","2023-06-09T12:39:00Z","2023-06-09T09:19:10Z","59913" +"*spartan-conseil/ratchatpt*",".{0,1000}spartan\-conseil\/ratchatpt.{0,1000}","offensive_tool_keyword","ratchatpt","C2 using openAI API","T1094 - T1071.001","TA0011 - TA0002","N/A","N/A","C2","https://github.com/spartan-conseil/ratchatpt","1","1","N/A","risk of False positive","10","10","16","6","2023-06-09T12:39:00Z","2023-06-09T09:19:10Z","59914" +"*spawn/runshellcode*",".{0,1000}spawn\/runshellcode.{0,1000}","offensive_tool_keyword","cobaltstrike","CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for users to call to manipulate the CrossC2 Beacon session. thereby extending the functionality of Cobalt Strike.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/CrossC2/CrossC2Kit","1","1","N/A","N/A","10","10","218","37","2023-08-08T19:52:07Z","2022-06-06T07:00:10Z","59919" +"*spawn_cmd.dll*",".{0,1000}spawn_cmd\.dll.{0,1000}","offensive_tool_keyword","POC","POC to check for CVE-2020-0796 /SMBGhost Expected outcome: cmd.exe launched with system access","T1210.001 - T1213 - T1212 - T1201","TA0007 - TA0002","N/A","N/A","Exploitation tool","https://github.com/ZecOps/CVE-2020-0796-LPE-POC","1","1","N/A","N/A","N/A","3","241","85","2020-04-02T08:01:38Z","2020-03-30T16:06:50Z","59920" +"*SpawnAsAgentManager.cs*",".{0,1000}SpawnAsAgentManager\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59922" +"*spawnasshellcode*",".{0,1000}spawnasshellcode.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59923" +"*SpawnAsShellcodeManager*",".{0,1000}SpawnAsShellcodeManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59924" +"*SpawneRv6yTYhShell*",".{0,1000}SpawneRv6yTYhShell.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","59925" +"*SpawnPPIDAgentManager*",".{0,1000}SpawnPPIDAgentManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59930" +"*SpawnShellcode.cs*",".{0,1000}SpawnShellcode\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59931" +"*SpawnShellcodeManager*",".{0,1000}SpawnShellcodeManager.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","59932" +"*'spawnto_x64'*",".{0,1000}\'spawnto_x64\'.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","59938" +"*spawnto_x64.py*",".{0,1000}spawnto_x64\.py.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","59939" +"*'spawnto_x86'*",".{0,1000}\'spawnto_x86\'.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","59941" +"*spawnto_x86.py*",".{0,1000}spawnto_x86\.py.{0,1000}","offensive_tool_keyword","mythic","A .NET Framework 4.0 Windows Agent","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Apollo/","1","1","N/A","N/A","10","10","472","100","2025-04-10T19:47:06Z","2020-11-09T08:05:16Z","59942" +"*specialtokengroupprivs.py*",".{0,1000}specialtokengroupprivs\.py.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","59943" +"*SpecterOps/Nemesis*",".{0,1000}SpecterOps\/Nemesis.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","59948" +"*Spel_RCE_Bash_EXP.py*",".{0,1000}Spel_RCE_Bash_EXP\.py.{0,1000}","offensive_tool_keyword","POC","RCE PoC of 0-day Vulnerability found in Spring Cloud (SPEL)","T1059 - T1210 - T1507","TA0002 - TA0040 - TA0043","N/A","N/A","Exploitation tool","https://github.com/chaosec2021/Spring-cloud-function-SpEL-RCE","1","1","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","59951" +"*Spel_RCE_POC.py*",".{0,1000}Spel_RCE_POC\.py.{0,1000}","offensive_tool_keyword","POC","RCE PoC of 0-day Vulnerability found in Spring Cloud (SPEL)","T1059 - T1210 - T1507","TA0002 - TA0040 - TA0043","N/A","N/A","Exploitation tool","https://github.com/chaosec2021/Spring-cloud-function-SpEL-RCE","1","1","N/A","N/A","N/A","","N/A","","","","59952" +"*spiderfoot-master*",".{0,1000}spiderfoot\-master.{0,1000}","offensive_tool_keyword","spiderfoot","The OSINT Platform for Security Assessments","T1595 - T1595.002 - T1596 - T1591 - T1591.002","TA0043 ","N/A","N/A","Reconnaissance","https://www.spiderfoot.net/","1","1","N/A","N/A","6","10","N/A","N/A","N/A","N/A","59956" +"*SpiderLabs/DoHC2*",".{0,1000}SpiderLabs\/DoHC2.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","59957" +"*SpiderLabs/Responder*",".{0,1000}SpiderLabs\/Responder.{0,1000}","offensive_tool_keyword","responder","LLMNR. NBT-NS and MDNS poisoner","T1557.001 - T1171 - T1547.011 - T1040","TA0011 - TA0006 - TA0007","N/A","Lazarus Group - APT28 - FANCY BEAR - EMBER BEAR","Sniffing & Spoofing","https://github.com/SpiderLabs/Responder","1","1","N/A","N/A","N/A","10","4656","1722","2020-06-15T18:07:44Z","2012-10-24T14:35:12Z","59958" +"*sploitus.com/exploit?id=6C1081C5-7938-5E83-9079-719C1B071FB5*",".{0,1000}sploitus\.com\/exploit\?id\=6C1081C5\-7938\-5E83\-9079\-719C1B071FB5.{0,1000}","offensive_tool_keyword","POC","Automated PoC exploitation of CVE-2021-44521","T1548 - T1190","TA0006 - TA0008","N/A","N/A","Exploitation tool","https://github.com/QHpix/CVE-2021-44521","1","1","N/A","N/A","N/A","1","9","2","2022-02-24T12:04:40Z","2022-02-24T11:07:34Z","59971" +"*splunk/upload_app_exec/*",".{0,1000}splunk\/upload_app_exec\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59972" +"*splunk_whisperer.py*",".{0,1000}splunk_whisperer\.py.{0,1000}","offensive_tool_keyword","SplunkWhisperer2","Local privilege escalation or remote code execution through Splunk Universal Forwarder (UF) misconfigurations","T1068 - T1059.003 - T1071.001","TA0004 - TA0003 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/cnotin/SplunkWhisperer2","1","1","N/A","N/A","9","10","250","53","2022-09-30T16:41:17Z","2019-02-24T18:05:51Z","59973" +"*splunk_whisperer-master*",".{0,1000}splunk_whisperer\-master.{0,1000}","offensive_tool_keyword","SplunkWhisperer2","Local privilege escalation or remote code execution through Splunk Universal Forwarder (UF) misconfigurations","T1068 - T1059.003 - T1071.001","TA0004 - TA0003 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/cnotin/SplunkWhisperer2","1","1","N/A","N/A","9","10","250","53","2022-09-30T16:41:17Z","2019-02-24T18:05:51Z","59974" +"*SplunkWhisperer2-master*",".{0,1000}SplunkWhisperer2\-master.{0,1000}","offensive_tool_keyword","SplunkWhisperer2","Local privilege escalation or remote code execution through Splunk Universal Forwarder (UF) misconfigurations","T1068 - T1059.003 - T1071.001","TA0004 - TA0003 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/cnotin/SplunkWhisperer2","1","1","N/A","N/A","9","10","250","53","2022-09-30T16:41:17Z","2019-02-24T18:05:51Z","59975" +"*spnroast_*.txt*",".{0,1000}spnroast_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","59978" +"*spoof/llmnr/llmnr_response*",".{0,1000}spoof\/llmnr\/llmnr_response.{0,1000}","offensive_tool_keyword","metasploit","llmnr spoofing used by Dispossessor ransomware group","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Dispossessor","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","59981" +"*SpooferHostsIgnore*",".{0,1000}SpooferHostsIgnore.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","59985" +"*SpooferHostsReply*",".{0,1000}SpooferHostsReply.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","59986" +"*SpooferIPsIgnore*",".{0,1000}SpooferIPsIgnore.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","59988" +"*SpooferIPsReply*",".{0,1000}SpooferIPsReply.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","59989" +"*SpooferLearningDelay*",".{0,1000}SpooferLearningDelay.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","59990" +"*SpooferLearningInterval*",".{0,1000}SpooferLearningInterval.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","59991" +"*SpooferRepeat*",".{0,1000}SpooferRepeat.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","59992" +"*spookflare.py*",".{0,1000}spookflare\.py.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","59996" +"*spool_sploit.py*",".{0,1000}spool_sploit\.py.{0,1000}","offensive_tool_keyword","spoolsploit","A collection of Windows print spooler exploits containerized with other utilities for practical exploitation.","T1204 - T1547 - T1562 - T1003 - T1018 - T1570 - T1005","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/BeetleChunks/SpoolSploit","1","1","N/A","N/A","N/A","6","555","90","2021-07-16T04:49:43Z","2021-07-07T00:32:28Z","59997" +"*SpoolSample_v4.5_x64.exe*",".{0,1000}SpoolSample_v4\.5_x64\.exe.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","60000" +"*SpoolSploit/*",".{0,1000}SpoolSploit\/.{0,1000}","offensive_tool_keyword","spoolsploit","A collection of Windows print spooler exploits containerized with other utilities for practical exploitation.","T1204 - T1547 - T1562 - T1003 - T1018 - T1570 - T1005","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/BeetleChunks/SpoolSploit","1","1","N/A","N/A","N/A","6","555","90","2021-07-16T04:49:43Z","2021-07-07T00:32:28Z","60001" +"*spoolsploit:latest*",".{0,1000}spoolsploit\:latest.{0,1000}","offensive_tool_keyword","spoolsploit","A collection of Windows print spooler exploits containerized with other utilities for practical exploitation.","T1204 - T1547 - T1562 - T1003 - T1018 - T1570 - T1005","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009","N/A","Black Basta","Exploitation tool","https://github.com/BeetleChunks/SpoolSploit","1","1","N/A","N/A","N/A","6","555","90","2021-07-16T04:49:43Z","2021-07-07T00:32:28Z","60002" +"*spoolss_##*",".{0,1000}spoolss_\#\#.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","60003" +"*spoolsystem.cna*",".{0,1000}spoolsystem\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Spectrum Attack Simulation beacons","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas/","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","60006" +"*SpoolTrigger.x64.dl*",".{0,1000}SpoolTrigger\.x64\.dl.{0,1000}","offensive_tool_keyword","cobaltstrike","Spectrum Attack Simulation beacons","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas/","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","60007" +"*SpoolTrigger.x64.dll*",".{0,1000}SpoolTrigger\.x64\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","60008" +"*SpoolTrigger.x86.dl*",".{0,1000}SpoolTrigger\.x86\.dl.{0,1000}","offensive_tool_keyword","cobaltstrike","Spectrum Attack Simulation beacons","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas/","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","60009" +"*SpoolTrigger.x86.dll*",".{0,1000}SpoolTrigger\.x86\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nccgroup/nccfsas","1","1","N/A","N/A","10","10","611","110","2022-08-05T16:25:42Z","2020-06-25T09:33:45Z","60010" +"*Spray365.git*",".{0,1000}Spray365\.git.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","1","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","60016" +"*spray365.py*",".{0,1000}spray365\.py.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","1","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","60017" +"*spray365_results_*.json*",".{0,1000}spray365_results_.{0,1000}\.json.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","1","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","60018" +"*Spray-AD.cna*",".{0,1000}Spray\-AD\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","A Cobalt Strike tool to audit Active Directory user accounts for weak - well known or easy guessable passwords.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Spray-AD","1","1","N/A","N/A","10","10","436","54","2022-04-01T07:03:39Z","2020-01-09T10:10:48Z","60020" +"*Spray-AD.dll*",".{0,1000}Spray\-AD\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","A Cobalt Strike tool to audit Active Directory user accounts for weak - well known or easy guessable passwords.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Spray-AD","1","1","N/A","N/A","10","10","436","54","2022-04-01T07:03:39Z","2020-01-09T10:10:48Z","60021" +"*Spray-AD.exe*",".{0,1000}Spray\-AD\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","A Cobalt Strike tool to audit Active Directory user accounts for weak - well known or easy guessable passwords.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Spray-AD","1","1","N/A","N/A","10","10","436","54","2022-04-01T07:03:39Z","2020-01-09T10:10:48Z","60023" +"*Spray-AD.sln*",".{0,1000}Spray\-AD\.sln.{0,1000}","offensive_tool_keyword","cobaltstrike","A Cobalt Strike tool to audit Active Directory user accounts for weak - well known or easy guessable passwords.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Spray-AD","1","1","N/A","N/A","10","10","436","54","2022-04-01T07:03:39Z","2020-01-09T10:10:48Z","60024" +"*sprayhound-master.zip*",".{0,1000}sprayhound\-master\.zip.{0,1000}","offensive_tool_keyword","sprayhound","Password spraying tool and Bloodhound integration","T1110.003 - T1210.001 - T1069.002","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/Hackndo/sprayhound","1","1","N/A","N/A","N/A","3","231","19","2024-12-31T08:09:37Z","2020-02-06T17:45:37Z","60031" +"*SprayingToolkit.git*",".{0,1000}SprayingToolkit\.git.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","1","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","60036" +"*SprayingToolkit-master.zip*",".{0,1000}SprayingToolkit\-master\.zip.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","1","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","60038" +"*spraykatz*",".{0,1000}spraykatz.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","1","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","60039" +"*Spray-Passwords.ps1*",".{0,1000}Spray\-Passwords\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","60040" +"*spring_framework_malicious_jar*",".{0,1000}spring_framework_malicious_jar.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","60041" +"*Spring-cloud-function-SpEL-RCE*",".{0,1000}Spring\-cloud\-function\-SpEL\-RCE.{0,1000}","offensive_tool_keyword","POC","RCE PoC of 0-day Vulnerability found in Spring Cloud (SPEL)","T1059 - T1210 - T1507","TA0002 - TA0040 - TA0043","N/A","N/A","Exploitation tool","https://github.com/chaosec2021/Spring-cloud-function-SpEL-RCE","1","1","N/A","N/A","N/A","","N/A","","","","60042" +"*spring-core-rce*ROOT.war*",".{0,1000}spring\-core\-rce.{0,1000}ROOT\.war.{0,1000}","offensive_tool_keyword","spring-core-rce","CVE-2022-22965 : about spring core rce","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/Mr-xn/spring-core-rce","1","1","N/A","N/A","N/A","1","50","18","2022-04-01T15:34:03Z","2022-03-30T14:35:00Z","60043" +"*SpyGate-RAT v*.exe*",".{0,1000}SpyGate\-RAT\sv.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","60045" +"*SpyGate-RAT.exe*",".{0,1000}SpyGate\-RAT\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","60046" +"*sql_persister.py*",".{0,1000}sql_persister\.py.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","60052" +"*SQLC2CMDS.dll*",".{0,1000}SQLC2CMDS\.dll.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","60053" +"*SqlClrPayload*",".{0,1000}SqlClrPayload.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","60054" +"*sqldumper.py*",".{0,1000}sqldumper\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","60055" +"*sqli_common_shared.rb*",".{0,1000}sqli_common_shared\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","60056" +"*Sqli-lab*",".{0,1000}Sqli\-lab.{0,1000}","offensive_tool_keyword","sqli-labs","SQLI-LABS is a platform to learn SQLI Following labs are covered for GET and POST scenarios:","T1190 - T1553","TA0002 - TA0008","N/A","N/A","Vulnerability Scanner","https://github.com/Audi-1/sqli-labs","1","1","N/A","N/A","N/A","10","5436","1532","2023-12-11T17:06:16Z","2012-05-19T19:41:26Z","60057" +"*SQL-Injection-Auth-Bypass-Payloads.*",".{0,1000}SQL\-Injection\-Auth\-Bypass\-Payloads\..{0,1000}","offensive_tool_keyword","Offensive-Payloads","List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.","T1210 - T1185 - T1059 - T1400 - T1506 - T1213 ","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/InfoSecWarrior/Offensive-Payloads/","1","1","N/A","N/A","N/A","4","328","117","2024-09-20T09:59:28Z","2022-11-18T09:43:41Z","60058" +"*SQL-Injection-Libraries*",".{0,1000}SQL\-Injection\-Libraries.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","60059" +"*SQL-Injection-Payloads.*",".{0,1000}SQL\-Injection\-Payloads\..{0,1000}","offensive_tool_keyword","Offensive-Payloads","List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.","T1210 - T1185 - T1059 - T1400 - T1506 - T1213 ","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/InfoSecWarrior/Offensive-Payloads/","1","1","N/A","N/A","N/A","4","328","117","2024-09-20T09:59:28Z","2022-11-18T09:43:41Z","60060" +"*SQLiPy.py*",".{0,1000}SQLiPy\.py.{0,1000}","offensive_tool_keyword","sqlipy","SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.","T1190 - T1210 - T1574","TA0002 - TA0040 - TA0043","N/A","N/A","Exploitation tool","https://github.com/codewatchorg/sqlipy","1","1","N/A","network exploitation tool","N/A","3","254","92","2024-06-19T23:38:41Z","2014-09-22T03:25:42Z","60061" +"*SQLiScanner*",".{0,1000}SQLiScanner.{0,1000}","offensive_tool_keyword","SQLiScanner","Automatic SQL injection with Charles and sqlmapapi","T1190 - T1556 - T1210 - T1573","TA0002 - TA0003 - TA0008","N/A","N/A","Vulnerability Scanner","https://github.com/0xbug/SQLiScanner","1","1","N/A","N/A","N/A","9","801","282","2018-05-01T09:59:47Z","2016-08-28T06:06:32Z","60062" +"*sqlmap.conf*",".{0,1000}sqlmap\.conf.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","60075" +"*sqlmap.py*",".{0,1000}sqlmap\.py.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","60076" +"*sqlmap.rb*",".{0,1000}sqlmap\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","60077" +"*sqlmap/data/txt/wordlist.txt*",".{0,1000}sqlmap\/data\/txt\/wordlist\.txt.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","60078" +"*sqlmap4burp*.jar*",".{0,1000}sqlmap4burp.{0,1000}\.jar.{0,1000}","offensive_tool_keyword","burpsuite","Collection of burpsuite plugins","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","network exploitation tool","N/A","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","60079" +"*sqlmapapi.py",".{0,1000}sqlmapapi\.py","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","60081" +"*sqlmapapi.py*",".{0,1000}sqlmapapi\.py.{0,1000}","offensive_tool_keyword","sqlipy","SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.","T1059 - T1213 - T1203","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/codewatchorg/sqlipy","1","1","N/A","network exploitation tool","N/A","3","254","92","2024-06-19T23:38:41Z","2014-09-22T03:25:42Z","60082" +"*sqlmapproject/sqlmap*",".{0,1000}sqlmapproject\/sqlmap.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","60083" +"*sqlmapproject/sqlmap/issues/2442*",".{0,1000}sqlmapproject\/sqlmap\/issues\/2442.{0,1000}","offensive_tool_keyword","ghauri","A cross-platform python based advanced sql injections detection & exploitation tool","T1190 - T1210 - T1095","TA0001 - TA0002 - TA0009","N/A","N/A","Vulnerability Scanner","https://github.com/r0oth3x49/ghauri","1","1","N/A","N/A","8","10","3483","361","2025-02-25T19:09:50Z","2022-10-01T11:21:50Z","60084" +"*SQLmate*",".{0,1000}SQLmate.{0,1000}","offensive_tool_keyword","SQLmate","A friend of SQLmap which will do what you always expected from SQLmap.","T1210 - T1211 - T1021 - T1059","TA0002 - TA0011 - TA0003","N/A","N/A","Vulnerability Scanner","https://github.com/s0md3v/sqlmate","1","1","N/A","N/A","N/A","5","440","119","2019-05-05T15:53:06Z","2017-10-19T19:55:58Z","60085" +"*sqlninja*",".{0,1000}sqlninja.{0,1000}","offensive_tool_keyword","sqlninja","...a SQL Server injection & takeover tool","T1505 - T1526 - T1583 - T1588 - T1590","TA0001 - TA0002 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Vulnerability Scanner","http://sqlninja.sourceforge.net/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","60086" +"*SQLRecon.exe*",".{0,1000}SQLRecon\.exe.{0,1000}","offensive_tool_keyword","SQLRecon","A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation","T1003.003 - T1049 - T1059.005 - T1078.003","TA0005 - TA0006 - TA0002 - TA0004","N/A","Black Basta","Exploitation tool","https://github.com/skahwah/SQLRecon","1","1","N/A","N/A","9","8","719","120","2025-01-10T17:42:49Z","2021-11-19T15:58:49Z","60087" +"*SQLRecon.git*",".{0,1000}SQLRecon\.git.{0,1000}","offensive_tool_keyword","SQLRecon","A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation","T1003.003 - T1049 - T1059.005 - T1078.003","TA0005 - TA0006 - TA0002 - TA0004","N/A","Black Basta","Exploitation tool","https://github.com/skahwah/SQLRecon","1","1","N/A","N/A","9","8","719","120","2025-01-10T17:42:49Z","2021-11-19T15:58:49Z","60088" +"*SQLServer_Accessible_PotentialSensitiveData.txt*",".{0,1000}SQLServer_Accessible_PotentialSensitiveData\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","60089" +"*SQLServer_DefaultLogin.txt*",".{0,1000}SQLServer_DefaultLogin\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","60090" +"*src/cracker.*",".{0,1000}src\/cracker\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60091" +"*src/genmkvpwd.*",".{0,1000}src\/genmkvpwd\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60092" +"*src/john.asm*",".{0,1000}src\/john\.asm.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60094" +"*src/ligolo*",".{0,1000}src\/ligolo.{0,1000}","offensive_tool_keyword","ligolo","ligolo is a simple and lightweight tool for establishing SOCKS5 or TCP tunnels from a reverse connection in complete safety (TLS certificate with elliptical curve)","T1071 - T1021 - T1573","TA0011 - TA0002","N/A","AvosLocker - LockBit","C2","https://github.com/sysdream/ligolo","1","1","N/A","N/A","10","10","1764","224","2023-01-06T19:49:22Z","2020-05-22T07:58:13Z","60095" +"*src/obfuscator.c*",".{0,1000}src\/obfuscator\.c.{0,1000}","offensive_tool_keyword","Striker","Striker is a simple Command and Control (C2) program.","T1071 - T1071.001 - T1071.004 - T1071.005 - T1071.006 - T1071.007 - T1071.008 - T1071.009 - T1071.010 - T1071.012 - T1071.013 - T1071.014 - T1071.015 - T1071.016 - T1071.018 - T1105 - T1105.002 - T1573 - T1573.002 - T1573.003 - T1573.004 - T1573.005","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/4g3nt47/Striker","1","1","N/A","N/A","10","10","301","42","2023-05-04T18:00:05Z","2022-09-07T10:09:41Z","60096" +"*src/Remote/chromeKey/*",".{0,1000}src\/Remote\/chromeKey\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","60097" +"*src/Remote/lastpass/*",".{0,1000}src\/Remote\/lastpass\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","60098" +"*src/Remote/sc_config/*",".{0,1000}src\/Remote\/sc_config\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","60099" +"*src/Remote/sc_create/*",".{0,1000}src\/Remote\/sc_create\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","60100" +"*src/Remote/sc_delete/*",".{0,1000}src\/Remote\/sc_delete\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","60101" +"*src/Remote/sc_start/*",".{0,1000}src\/Remote\/sc_start\/.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike injection BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","60102" +"*src/ShellGhost.c*",".{0,1000}src\/ShellGhost\.c.{0,1000}","offensive_tool_keyword","ShellGhost","A memory-based evasion technique which makes shellcode invisible from process start to end","T1055.012 - T1027.002 - T1055.001","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/lem0nSec/ShellGhost","1","1","N/A","N/A","N/A","10","1175","140","2023-10-16T06:40:24Z","2023-07-01T16:56:58Z","60103" +"*Src/Spray-AD*",".{0,1000}Src\/Spray\-AD.{0,1000}","offensive_tool_keyword","cobaltstrike","A Cobalt Strike tool to audit Active Directory user accounts for weak - well known or easy guessable passwords.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/Spray-AD","1","1","N/A","N/A","10","10","436","54","2022-04-01T07:03:39Z","2020-01-09T10:10:48Z","60104" +"*src/tests/NESSIE/*",".{0,1000}src\/tests\/NESSIE\/.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60105" +"*src/zerologon.c*",".{0,1000}src\/zerologon\.c.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF zerologon exploit","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/ZeroLogon-BOF","1","1","N/A","N/A","10","10","158","37","2022-04-25T11:22:45Z","2020-09-17T02:07:13Z","60107" +"*srvsvc_##*",".{0,1000}srvsvc_\#\#.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","60118" +"*sse-secure-systems/TeamsEnum*",".{0,1000}sse\-secure\-systems\/TeamsEnum.{0,1000}","offensive_tool_keyword","TeamsEnum","User Enumeration of Microsoft Teams users via API","T1589.002 - T1590","TA0007 - TA0001","N/A","Black Basta","Discovery","https://github.com/sse-secure-systems/TeamsEnum","1","1","N/A","N/A","6","2","153","21","2024-03-27T18:14:25Z","2023-04-03T18:35:15Z","60121" +"*ssh2john.py*",".{0,1000}ssh2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60148" +"*sshamble*badkeys*",".{0,1000}sshamble.{0,1000}badkeys.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","1","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","60150" +"*sshamble/badkeys*",".{0,1000}sshamble\/badkeys.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","1","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","60151" +"*sshamble-main.zip*",".{0,1000}sshamble\-main\.zip.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","1","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","60152" +"*sshbrute.py*",".{0,1000}sshbrute\.py.{0,1000}","offensive_tool_keyword","burpsuite","Red Team Toolkit is an Open-Source Django Offensive Web-App which is keeping the useful offensive tools used in the red-teaming together","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/signorrayan/RedTeam_toolkit","1","1","N/A","N/A","N/A","6","561","121","2025-03-28T06:59:25Z","2021-08-18T08:58:14Z","60154" +"*sshBruteForce.exe*",".{0,1000}sshBruteForce\.exe.{0,1000}","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","1","N/A","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","60155" +"*SSHBruteForce.py*",".{0,1000}SSHBruteForce\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","60156" +"*sshimpanzee-1.1-exp*",".{0,1000}sshimpanzee\-1\.1\-exp.{0,1000}","offensive_tool_keyword","sshimpanzee","SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS - ICMP - HTTP Encapsulation - HTTP/Socks Proxies - UDP","T1572 - T1095 - T1090 - T1043","TA0010 - TA0011 - TA0005","N/A","Scattered Spider*","C2","https://github.com/lexfo/sshimpanzee","1","1","N/A","N/A","10","10","263","27","2025-03-05T08:32:56Z","2023-04-03T10:11:27Z","60160" +"*sshimpanzee-main*",".{0,1000}sshimpanzee\-main.{0,1000}","offensive_tool_keyword","sshimpanzee","SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS - ICMP - HTTP Encapsulation - HTTP/Socks Proxies - UDP","T1572 - T1095 - T1090 - T1043","TA0010 - TA0011 - TA0005","N/A","Scattered Spider*","C2","https://github.com/lexfo/sshimpanzee","1","1","N/A","N/A","10","10","263","27","2025-03-05T08:32:56Z","2023-04-03T10:11:27Z","60161" +"*sshkey_persistence.*",".{0,1000}sshkey_persistence\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","60163" +"*sshLooterC*",".{0,1000}sshLooterC.{0,1000}","offensive_tool_keyword","sshLooterC","script to steel password from ssh - Its the C version of sshLooter. which was written in python and have a lot of dependencies to be installed on the infected machine. Now with this C version. you compile it on your machine and send it to the infected machine without installing any dependencies.","T1003 - T1059 - T1083 - T1566 - T1558.003","TA0002 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/mthbernardes/sshLooterC","1","1","N/A","N/A","N/A","3","266","86","2023-06-08T21:12:10Z","2018-12-19T20:25:11Z","60165" +"*ssh-mitm*",".{0,1000}ssh\-mitm.{0,1000}","offensive_tool_keyword","ssh-mitm","An SSH/SFTP man-in-the-middle tool that logs interactive sessions and passwords.","T1040 - T1071 - T1552","TA0006 - TA0007","N/A","N/A","Sniffing & Spoofing","https://github.com/jtesta/ssh-mitm","1","1","N/A","N/A","N/A","10","1657","203","2021-07-02T02:17:26Z","2017-05-16T19:55:10Z","60166" +"*sshmon*hunt*",".{0,1000}sshmon.{0,1000}hunt.{0,1000}","offensive_tool_keyword","shhmon","Neutering Sysmon via driver unload","T1518.001 ","TA0007","N/A","N/A","Defense Evasion","https://github.com/matterpreter/Shhmon","1","1","N/A","N/A","N/A","3","228","37","2022-10-13T16:56:41Z","2019-09-12T14:13:19Z","60167" +"*sshmon*kill*",".{0,1000}sshmon.{0,1000}kill.{0,1000}","offensive_tool_keyword","shhmon","Neutering Sysmon via driver unload","T1518.001 ","TA0007","N/A","N/A","Defense Evasion","https://github.com/matterpreter/Shhmon","1","1","N/A","N/A","N/A","3","228","37","2022-10-13T16:56:41Z","2019-09-12T14:13:19Z","60168" +"*ssh-putty-brute.ps1*",".{0,1000}ssh\-putty\-brute\.ps1.{0,1000}","offensive_tool_keyword","SSH-PuTTY-login-bruteforcer","Turn PuTTY into an SSH login bruteforcing tool.","T1110.002 - T1059.003 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/InfosecMatter/SSH-PuTTY-login-bruteforcer","1","1","N/A","N/A","9","3","285","81","2020-11-21T07:10:26Z","2020-04-25T07:20:14Z","60170" +"*SSH-PuTTY-login-bruteforcer*",".{0,1000}SSH\-PuTTY\-login\-bruteforcer.{0,1000}","offensive_tool_keyword","SSH-PuTTY-login-bruteforcer","Turn PuTTY into an SSH login bruteforcing tool.","T1110.002 - T1059.003 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/InfosecMatter/SSH-PuTTY-login-bruteforcer","1","1","N/A","N/A","9","3","285","81","2020-11-21T07:10:26Z","2020-04-25T07:20:14Z","60171" +"*ssh-shellhost.exe*",".{0,1000}ssh\-shellhost\.exe.{0,1000}","offensive_tool_keyword","reverse-ssh","Statically-linked ssh server with reverse shell functionality for CTFs and such","T1105 - T1572 - T1569.002 - T1090","TA0001 - TA0002 - TA0003 - TA0010 - TA0011 - TA0005 ","N/A","N/A","C2","https://github.com/Fahrj/reverse-ssh","1","1","N/A","N/A","10","10","961","141","2023-02-15T00:16:25Z","2021-07-12T18:26:29Z","60172" +"*SSH-Snake-main*",".{0,1000}SSH\-Snake\-main.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","1","N/A","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","60174" +"*SspiUacBypass*",".{0,1000}SspiUacBypass.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of UAC Bypass Techniques Weaponized as BOFs","T1548.002 - T1203 - T1055 - T1134.002","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/icyguider/UAC-BOF-Bonanza","1","1","N/A","N/A","10","6","500","65","2024-02-21T22:07:54Z","2024-02-16T14:47:13Z","60190" +"*SspiUacBypass.cpp*",".{0,1000}SspiUacBypass\.cpp.{0,1000}","offensive_tool_keyword","SspiUacBypass","Bypassing UAC with SSPI Datagram Contexts","T1548.002","TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/SspiUacBypass","1","1","N/A","N/A","10","5","433","56","2023-09-24T17:33:25Z","2023-09-14T20:59:22Z","60191" +"*SspiUacBypass.exe*",".{0,1000}SspiUacBypass\.exe.{0,1000}","offensive_tool_keyword","SspiUacBypass","Bypassing UAC with SSPI Datagram Contexts","T1548.002","TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/SspiUacBypass","1","1","N/A","N/A","10","5","433","56","2023-09-24T17:33:25Z","2023-09-14T20:59:22Z","60192" +"*SspiUacBypassBOF*",".{0,1000}SspiUacBypassBOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of UAC Bypass Techniques Weaponized as BOFs","T1548.002 - T1203 - T1055 - T1134.002","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/icyguider/UAC-BOF-Bonanza","1","1","N/A","N/A","10","6","500","65","2024-02-21T22:07:54Z","2024-02-16T14:47:13Z","60193" +"*SspiUacBypass-main*",".{0,1000}SspiUacBypass\-main.{0,1000}","offensive_tool_keyword","SspiUacBypass","Bypassing UAC with SSPI Datagram Contexts","T1548.002","TA0004","N/A","N/A","Defense Evasion","https://github.com/antonioCoco/SspiUacBypass","1","1","N/A","N/A","10","5","433","56","2023-09-24T17:33:25Z","2023-09-14T20:59:22Z","60194" +"*SSploitEnumeration*",".{0,1000}SSploitEnumeration.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","60195" +"*SSploitEnumerationDomain*",".{0,1000}SSploitEnumerationDomain.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","60196" +"*SSploitExecution_DynamicInvoke*",".{0,1000}SSploitExecution_DynamicInvoke.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","60197" +"*SSploitExecution_Injection*",".{0,1000}SSploitExecution_Injection.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","60198" +"*SSploitLateralMovement*",".{0,1000}SSploitLateralMovement.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","60199" +"*SSploitPersistence*",".{0,1000}SSploitPersistence.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","60200" +"*SSploitPrivilegeEscalation*",".{0,1000}SSploitPrivilegeEscalation.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","60201" +"*sspr2john.py*",".{0,1000}sspr2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60202" +"*ssrfmap.py*",".{0,1000}ssrfmap\.py.{0,1000}","offensive_tool_keyword","SSRFmap","Automatic SSRF fuzzer and exploitation tool","T1210 - T1211 - T1212 - T1574","TA0002 - TA0007 - TA0008","N/A","N/A","Exploitation tool","https://github.com/swisskyrepo/SSRFmap","1","1","N/A","N/A","N/A","10","3167","538","2025-02-26T19:39:06Z","2018-10-15T19:08:26Z","60206" +"*SSSDKCMExtractor.py*",".{0,1000}SSSDKCMExtractor\.py.{0,1000}","offensive_tool_keyword","LinikatzV2","linikatz is a tool to attack AD on UNIX","T1003.002 - T1558.003 - T1078 - T1550.001","TA0006 - TA0001 - TA0004 - TA0003","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/LinikatzV2","1","1","#linux","N/A","10","2","146","15","2023-10-19T12:26:58Z","2023-10-19T11:07:53Z","60207" +"*StackCrypt-main*",".{0,1000}StackCrypt\-main.{0,1000}","offensive_tool_keyword","StackCrypt","Create a new thread that will suspend every thread and encrypt its stack then going to sleep then decrypt the stacks and resume threads","T1027 - T1055.004 - T1486","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/StackCrypt","1","1","N/A","N/A","9","2","159","27","2023-08-02T02:25:12Z","2023-04-26T03:24:56Z","60208" +"*StackEncrypt.cpp*",".{0,1000}StackEncrypt\.cpp.{0,1000}","offensive_tool_keyword","StackCrypt","Create a new thread that will suspend every thread and encrypt its stack then going to sleep then decrypt the stacks and resume threads","T1027 - T1055.004 - T1486","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/StackCrypt","1","1","N/A","N/A","9","2","159","27","2023-08-02T02:25:12Z","2023-04-26T03:24:56Z","60209" +"*StackEncrypt.exe*",".{0,1000}StackEncrypt\.exe.{0,1000}","offensive_tool_keyword","StackCrypt","Create a new thread that will suspend every thread and encrypt its stack then going to sleep then decrypt the stacks and resume threads","T1027 - T1055.004 - T1486","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/StackCrypt","1","1","N/A","N/A","9","2","159","27","2023-08-02T02:25:12Z","2023-04-26T03:24:56Z","60210" +"*StackEncrypt.sln*",".{0,1000}StackEncrypt\.sln.{0,1000}","offensive_tool_keyword","StackCrypt","Create a new thread that will suspend every thread and encrypt its stack then going to sleep then decrypt the stacks and resume threads","T1027 - T1055.004 - T1486","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/StackCrypt","1","1","N/A","N/A","9","2","159","27","2023-08-02T02:25:12Z","2023-04-26T03:24:56Z","60211" +"*StackEncrypt.vcxproj*",".{0,1000}StackEncrypt\.vcxproj.{0,1000}","offensive_tool_keyword","StackCrypt","Create a new thread that will suspend every thread and encrypt its stack then going to sleep then decrypt the stacks and resume threads","T1027 - T1055.004 - T1486","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/StackCrypt","1","1","N/A","N/A","9","2","159","27","2023-08-02T02:25:12Z","2023-04-26T03:24:56Z","60212" +"*stage.obfuscate*",".{0,1000}stage\.obfuscate.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/malleable-c2","1","1","N/A","N/A","10","10","1676","299","2023-12-13T17:14:22Z","2018-08-14T14:19:43Z","60213" +"*stage_smartinject*",".{0,1000}stage_smartinject.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","60214" +"*stage_transform_x64_prepend*",".{0,1000}stage_transform_x64_prepend.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","60215" +"*stage_transform_x64_strrep1*",".{0,1000}stage_transform_x64_strrep1.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","60216" +"*stage_transform_x86_prepend*",".{0,1000}stage_transform_x86_prepend.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","60217" +"*stage_transform_x86_strrep1*",".{0,1000}stage_transform_x86_strrep1.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike random C2 Profile generator","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/random_c2_profile","1","1","N/A","N/A","10","10","657","88","2023-01-05T21:17:00Z","2021-04-03T20:39:29Z","60218" +"*stage1-remotepipelist.py*",".{0,1000}stage1\-remotepipelist\.py.{0,1000}","offensive_tool_keyword","RemotePipeList","A small tool that can list the named pipes bound on a remote system.","T1047 - T1021.006","TA0008 - TA0002","N/A","N/A","Discovery","https://github.com/outflanknl/C2-Tool-Collection/tree/main/Other/RemotePipeList","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","60219" +"*Stage-gSharedInfoBitmap*",".{0,1000}Stage\-gSharedInfoBitmap.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-MS16135.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","60220" +"*StageListenerCmd*",".{0,1000}StageListenerCmd.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","60223" +"*stager/happy_x64.txt*",".{0,1000}stager\/happy_x64\.txt.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","60224" +"*stager/happy_x86.txt*",".{0,1000}stager\/happy_x86\.txt.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","60225" +"*stager/js/disk*",".{0,1000}stager\/js\/disk.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","60227" +"*stager/js/mshta*",".{0,1000}stager\/js\/mshta.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","60228" +"*stager/sad_x64.txt*",".{0,1000}stager\/sad_x64\.txt.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","60232" +"*stager/sad_x86.txt*",".{0,1000}stager\/sad_x86\.txt.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","60233" +"*stager_bind_pipe*",".{0,1000}stager_bind_pipe.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","60234" +"*stager_bind_pipe*",".{0,1000}stager_bind_pipe.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","60235" +"*stager_bind_tcp*",".{0,1000}stager_bind_tcp.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","60236" +"*stager_bind_tcp*",".{0,1000}stager_bind_tcp.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","60237" +"*stager_hidden_bind_tcp.asm*",".{0,1000}stager_hidden_bind_tcp\.asm.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","60238" +"*stager_sock_find.asm*",".{0,1000}stager_sock_find\.asm.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","60240" +"*stagers/*/aes.py*",".{0,1000}stagers\/.{0,1000}\/aes\.py.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1048","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","60241" +"*stagers/*/diffiehellman.py*",".{0,1000}stagers\/.{0,1000}\/diffiehellman\.py.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1050","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","60242" +"*stagers/*/get_sysinfo.py*",".{0,1000}stagers\/.{0,1000}\/get_sysinfo\.py.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1047","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","60243" +"*stagers/*/rc4.py*",".{0,1000}stagers\/.{0,1000}\/rc4\.py.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1049","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","60244" +"*stagers/mytest_reverse_http.bin*",".{0,1000}stagers\/mytest_reverse_http\.bin.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","60245" +"*stagers/mytest_reverse_https.bin*",".{0,1000}stagers\/mytest_reverse_https\.bin.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","60246" +"*stagers/x64_mytest_reverse_http.bin*",".{0,1000}stagers\/x64_mytest_reverse_http\.bin.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","60247" +"*stagers/x64_mytest_reverse_https.bin*",".{0,1000}stagers\/x64_mytest_reverse_https\.bin.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","60248" +"*stagerx64.bin*",".{0,1000}stagerx64\.bin.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","60251" +"*Staging_w_padding_3.5_x64-cleaned.bin*",".{0,1000}Staging_w_padding_3\.5_x64\-cleaned\.bin.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","60252" +"*Staging_w_padding_3.5_x86-cleaned.bin*",".{0,1000}Staging_w_padding_3\.5_x86\-cleaned\.bin.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","60253" +"*Staging_w_padding_4.X_x64-cleaned.bin*",".{0,1000}Staging_w_padding_4\.X_x64\-cleaned\.bin.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","60254" +"*Staging_w_padding_4.X_x86-cleaned.bin*",".{0,1000}Staging_w_padding_4\.X_x86\-cleaned\.bin.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","60255" +"*Staging_w_padding_v3_x64-cleaned.bin*",".{0,1000}Staging_w_padding_v3_x64\-cleaned\.bin.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","60256" +"*Staging_w_padding_v3_x86-cleaned.bin*",".{0,1000}Staging_w_padding_v3_x86\-cleaned\.bin.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","60257" +"*Staging_w_padding_v4_x64-cleaned.bin*",".{0,1000}Staging_w_padding_v4_x64\-cleaned\.bin.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","60258" +"*Staging_w_padding_v4_x86-cleaned.bin*",".{0,1000}Staging_w_padding_v4_x86\-cleaned\.bin.{0,1000}","offensive_tool_keyword","VenomousSway","VBA payload generation framework","T1059.005","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","60259" +"*stamparm/fetch-some-proxies*",".{0,1000}stamparm\/fetch\-some\-proxies.{0,1000}","offensive_tool_keyword","fetch-some-proxies","Simple Python script for fetching ""some"" (usable) proxies","T1090 - T1071 - T1070","TA0002 - TA0005 - TA0010","N/A","N/A","Defense Evasion","https://github.com/stamparm/fetch-some-proxies","1","1","N/A","N/A","9","6","585","138","2023-03-15T09:14:25Z","2016-10-09T22:39:56Z","60260" +"*standard::answer*",".{0,1000}standard\:\:answer.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","60261" +"*standard::base64*",".{0,1000}standard\:\:base64.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","60262" +"*standard::cd*",".{0,1000}standard\:\:cd.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","60264" +"*standard::cls*",".{0,1000}standard\:\:cls.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","60265" +"*standard::coffee*",".{0,1000}standard\:\:coffee.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","60266" +"*standard::exit*",".{0,1000}standard\:\:exit.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","60267" +"*standard::hostname*",".{0,1000}standard\:\:hostname.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","60268" +"*standard::localtime*",".{0,1000}standard\:\:localtime.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","60269" +"*standard::log*",".{0,1000}standard\:\:log.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","60270" +"*standard::sleep*",".{0,1000}standard\:\:sleep.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","60271" +"*standard::version*",".{0,1000}standard\:\:version.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","60272" +"*stardust50578/rdp_brute*",".{0,1000}stardust50578\/rdp_brute.{0,1000}","offensive_tool_keyword","KPortScan","port scanner used by attackers","T1046 - T1595","TA0043 - TA0001","N/A","Dispossessor","Reconnaissance","https://github.com/stardust50578/rdp_brute","1","1","N/A","N/A","8","1","2","6","2019-05-19T14:25:06Z","2019-05-19T14:29:49Z","60289" +"*StarfireLab/SharpWeb*",".{0,1000}StarfireLab\/SharpWeb.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","1","N/A","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","60290" +"*StarkillerSnackbar.vue*",".{0,1000}StarkillerSnackbar\.vue.{0,1000}","offensive_tool_keyword","empire","Starkiller is a Frontend for Powershell Empire. It is a web application written in VueJS","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Starkiller","1","1","N/A","N/A","10","10","1461","206","2025-03-25T03:30:16Z","2020-03-09T05:48:58Z","60292" +"*staroffice2john.py*",".{0,1000}staroffice2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60293" +"*start_mythic_server.sh*",".{0,1000}start_mythic_server\.sh.{0,1000}","offensive_tool_keyword","mythic","A collaborative multi-platform red teaming framework","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","60304" +"*start_nbnsspoof*",".{0,1000}start_nbnsspoof.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","60305" +"*start_phpsploit_connected.sh*",".{0,1000}start_phpsploit_connected\.sh.{0,1000}","offensive_tool_keyword","PhpSploit","Full-featured C2 framework which silently persists on webserver via evil PHP oneliner","T1505.003 - T1505 - T1059 - T1219 - T1547","TA0003 - TA0011 - TA0005","N/A","N/A","C2","https://github.com/nil0x42/phpsploit","1","1","N/A","N/A","10","10","2331","453","2024-05-06T13:49:14Z","2014-05-21T19:43:03Z","60306" +"*startanotherimplant*",".{0,1000}startanotherimplant.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","60311" +"*Start-CaptureServer.ps1*",".{0,1000}Start\-CaptureServer\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","60312" +"*Start-CaptureServer.ps1*",".{0,1000}Start\-CaptureServer\.ps1.{0,1000}","offensive_tool_keyword","nishang","Antak is a webshell written in ASP.Net which utilizes PowerShell. Antak is a part of Nishang and updates can be found here: https://github.com/samratashok/nishang","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang/tree/master/Antak-WebShell","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","60313" +"*start-keystrokes*",".{0,1000}start\-keystrokes.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","60343" +"*start-keystrokes-writefile*",".{0,1000}start\-keystrokes\-writefile.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","60344" +"*Start-MonitorTCPConnections.ps1*",".{0,1000}Start\-MonitorTCPConnections\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1144","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","60345" +"*Start-ProcessAsUser.ps1*",".{0,1000}Start\-ProcessAsUser\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","60348" +"*Start-PSAmsiClient.ps1*",".{0,1000}Start\-PSAmsiClient\.ps1.{0,1000}","offensive_tool_keyword","PSAmsi","PSAmsi is a tool for auditing and defeating AMSI signatures.","T1059.001 - T1562.001 - T1070.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/cobbr/PSAmsi","1","1","N/A","N/A","7","4","390","74","2018-04-22T20:56:33Z","2017-09-22T11:48:47Z","60350" +"*Start-PSAmsiServer.ps1*",".{0,1000}Start\-PSAmsiServer\.ps1.{0,1000}","offensive_tool_keyword","PSAmsi","PSAmsi is a tool for auditing and defeating AMSI signatures.","T1059.001 - T1562.001 - T1070.004","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/cobbr/PSAmsi","1","1","N/A","N/A","7","4","390","74","2018-04-22T20:56:33Z","2017-09-22T11:48:47Z","60352" +"*Start-SimpleHTTPServer.ps1*",".{0,1000}Start\-SimpleHTTPServer\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","60360" +"*startupfolderperistence.py*",".{0,1000}startupfolderperistence\.py.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","60362" +"*Start-WebcamRecorder.ps1*",".{0,1000}Start\-WebcamRecorder\.ps1.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","60363" +"*Start-WebServer.ps1*",".{0,1000}Start\-WebServer\.ps1.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","60364" +"*static_syscalls_apc_spawn*",".{0,1000}static_syscalls_apc_spawn.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","60369" +"*static_syscalls_dump*",".{0,1000}static_syscalls_dump.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","60370" +"*statistically-likely-usernames*",".{0,1000}statistically\-likely\-usernames.{0,1000}","offensive_tool_keyword","statistically-likely-usernames","This resource contains wordlists for creating statistically likely usernames for use in username-enumeration. simulated password-attacks and other security testing tasks.","T1210.001 - T1583.001 - T1583.002","TA0007 - ","N/A","N/A","Credential Access","https://github.com/insidetrust/statistically-likely-usernames","1","1","N/A","N/A","N/A","10","1064","149","2022-08-31T20:27:53Z","2016-02-14T23:24:39Z","60371" +"*StayKit.cna*",".{0,1000}StayKit\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","StayKit is an extension for Cobalt Strike persistence by leveraging the execute_assembly function with the SharpStay .NET assembly. The aggressor script handles payload creation by reading the template files for a specific execution type.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Persistence","https://github.com/0xthirteen/StayKit","1","1","N/A","N/A","N/A","10","475","73","2020-01-27T14:53:31Z","2020-01-24T22:20:20Z","60372" +"*StayKit.cna*",".{0,1000}StayKit\.cna.{0,1000}","offensive_tool_keyword","StayKit","StayKit - Cobalt Strike persistence kit - StayKit is an extension for Cobalt Strike persistence by leveraging the execute_assembly function with the SharpStay .NET assembly. The aggressor script handles payload creation by reading the template files for a specific execution type.","T1059 - T1053 - T1124","TA0003 - TA0008","N/A","N/A","Exploitation tool","https://github.com/0xthirteen/StayKit","1","1","N/A","N/A","N/A","10","475","73","2020-01-27T14:53:31Z","2020-01-24T22:20:20Z","60373" +"*StayKit.exe*",".{0,1000}StayKit\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","StayKit is an extension for Cobalt Strike persistence by leveraging the execute_assembly function with the SharpStay .NET assembly. The aggressor script handles payload creation by reading the template files for a specific execution type.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Persistence","https://github.com/0xthirteen/StayKit","1","1","N/A","N/A","N/A","10","475","73","2020-01-27T14:53:31Z","2020-01-24T22:20:20Z","60374" +"*StayKit.git*",".{0,1000}StayKit\.git.{0,1000}","offensive_tool_keyword","cobaltstrike","StayKit is an extension for Cobalt Strike persistence by leveraging the execute_assembly function with the SharpStay .NET assembly. The aggressor script handles payload creation by reading the template files for a specific execution type.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Persistence","https://github.com/0xthirteen/StayKit","1","1","N/A","N/A","N/A","10","475","73","2020-01-27T14:53:31Z","2020-01-24T22:20:20Z","60375" +"*steal_token.py*",".{0,1000}steal_token\.py.{0,1000}","offensive_tool_keyword","mythic","Cross-platform post-exploitation HTTP Command & Control agent written in golang","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/merlin","1","1","N/A","N/A","10","10","94","16","2025-04-16T13:05:47Z","2021-01-25T12:36:46Z","60381" +"*steal_token_access_mask*",".{0,1000}steal_token_access_mask.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/malleable-c2","1","1","N/A","N/A","10","10","1676","299","2023-12-13T17:14:22Z","2018-08-14T14:19:43Z","60382" +"*steal-cert.py*",".{0,1000}steal\-cert\.py.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","60383" +"*StealCookie-28050355-D9DF-4CE7-BFBC-4F7DDE890C2A.json*",".{0,1000}StealCookie\-28050355\-D9DF\-4CE7\-BFBC\-4F7DDE890C2A\.json.{0,1000}","offensive_tool_keyword","power-pwn","An offensive and defensive security toolset for Microsoft 365 Power Platform","T1078 - T1078.004 - T1136 - T1136.001 - T1021 - T1021.003 - T1114 - T1114.002","TA0003 - TA0004 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/mbrg/power-pwn","1","1","N/A","N/A","10","10","939","100","2025-03-20T08:54:43Z","2022-06-14T11:40:21Z","60384" +"*StealDhcpSecrets.c*",".{0,1000}StealDhcpSecrets\.c.{0,1000}","offensive_tool_keyword","StealDhcpSecrets","DHCP Server DNS Password Stealer","T1552 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/tree/master/PasswordStealing/DHCP","1","1","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","60385" +"*StealDhcpSecrets.exe*",".{0,1000}StealDhcpSecrets\.exe.{0,1000}","offensive_tool_keyword","StealDhcpSecrets","DHCP Server DNS Password Stealer","T1552 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/tree/master/PasswordStealing/DHCP","1","1","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","60386" +"*StealPowerAutomateToken-C4E7B7DA-54E4-49AB-B634-FCCD77C65025.json*",".{0,1000}StealPowerAutomateToken\-C4E7B7DA\-54E4\-49AB\-B634\-FCCD77C65025\.json.{0,1000}","offensive_tool_keyword","power-pwn","An offensive and defensive security toolset for Microsoft 365 Power Platform","T1078 - T1078.004 - T1136 - T1136.001 - T1021 - T1021.003 - T1114 - T1114.002","TA0003 - TA0004 - TA0005 - TA0001","N/A","N/A","Exploitation tool","https://github.com/mbrg/power-pwn","1","1","N/A","N/A","10","10","939","100","2025-03-20T08:54:43Z","2022-06-14T11:40:21Z","60400" +"*StealTokenDrv_x64.sys*",".{0,1000}StealTokenDrv_x64\.sys.{0,1000}","offensive_tool_keyword","VectorKernel","PoCs for Kernelmode rootkit techniques research.","T1543 - T1055 - T1134 - T1564 - T1070 - T1057 - T1574 - T1562 - T1082 - T1518","TA0003 - TA0005 - TA0004 - TA0008 - TA0007","N/A","N/A","Exploitation tool","https://github.com/daem0nc0re/VectorKernel/","1","1","N/A","N/A","10","4","367","60","2025-01-21T08:22:42Z","2023-11-23T12:36:31Z","60404" +"*Sticky-Keys-Slayer*",".{0,1000}Sticky\-Keys\-Slayer.{0,1000}","offensive_tool_keyword","Sticky-Keys-Slayer","Scans for accessibility tools backdoors via RDP","T1078 - T1015 - T1203","TA0003 - TA0007 - TA0008","N/A","N/A","Reconnaissance","https://github.com/linuz/Sticky-Keys-Slayer","1","1","N/A","N/A","N/A","4","340","71","2018-03-16T15:59:41Z","2016-08-06T18:55:28Z","60408" +"*StickyNotesExtract.exe*",".{0,1000}StickyNotesExtract\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","60409" +"*stinger_client.py*",".{0,1000}stinger_client\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Bypass firewall for traffic forwarding using webshell. Pystinger implements SOCK4 proxy and port mapping through webshell. It can be directly used by metasploit-framework - viper- cobalt strike for session online.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/FunnyWolf/pystinger","1","1","N/A","N/A","10","10","1397","205","2021-09-29T13:13:43Z","2019-09-29T05:23:54Z","60413" +"*stinger_server.exe*",".{0,1000}stinger_server\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Bypass firewall for traffic forwarding using webshell. Pystinger implements SOCK4 proxy and port mapping through webshell. It can be directly used by metasploit-framework - viper- cobalt strike for session online.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/FunnyWolf/pystinger","1","1","N/A","N/A","10","10","1397","205","2021-09-29T13:13:43Z","2019-09-29T05:23:54Z","60414" +"*StompySharps.csproj*",".{0,1000}StompySharps\.csproj.{0,1000}","offensive_tool_keyword","Stompy","Timestomp Tool to flatten MAC times with a specific timestamp","T1070.006","TA0005","N/A","N/A","Defense Evasion","https://github.com/ZephrFish/Stompy","1","1","N/A","N/A","10","1","46","6","2023-10-15T17:38:23Z","2023-10-14T23:40:32Z","60416" +"*StompySharps.exe*",".{0,1000}StompySharps\.exe.{0,1000}","offensive_tool_keyword","Stompy","Timestomp Tool to flatten MAC times with a specific timestamp","T1070.006","TA0005","N/A","N/A","Defense Evasion","https://github.com/ZephrFish/Stompy","1","1","N/A","N/A","10","1","46","6","2023-10-15T17:38:23Z","2023-10-14T23:40:32Z","60417" +"*StompySharps.sln*",".{0,1000}StompySharps\.sln.{0,1000}","offensive_tool_keyword","Stompy","Timestomp Tool to flatten MAC times with a specific timestamp","T1070.006","TA0005","N/A","N/A","Defense Evasion","https://github.com/ZephrFish/Stompy","1","1","N/A","N/A","10","1","46","6","2023-10-15T17:38:23Z","2023-10-14T23:40:32Z","60418" +"*stop-keystrokes*",".{0,1000}stop\-keystrokes.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","60424" +"*stormshadow07*",".{0,1000}stormshadow07.{0,1000}","offensive_tool_keyword","HackTheWorld","An Python Script For Generating Payloads that Bypasses All Antivirus so far","T1566 - T1106 - T1027 - T1059 - T1070","TA0002 - TA0005 - TA0008 - TA0011","N/A","N/A","Defense Evasion","https://github.com/stormshadow07/HackTheWorld","1","1","N/A","N/A","N/A","10","977","169","2024-01-19T12:11:39Z","2018-02-17T11:46:40Z","60548" +"*strip_bof.ps1*",".{0,1000}strip_bof\.ps1.{0,1000}","offensive_tool_keyword","cobaltstrike","A Visual Studio template used to create Cobalt Strike BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/securifybv/Visual-Studio-BOF-template","1","1","N/A","N/A","10","10","304","55","2021-11-17T12:03:42Z","2021-11-13T13:44:01Z","60556" +"*strip2john.py*",".{0,1000}strip2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60557" +"*StrongLoader_x64.exe*",".{0,1000}StrongLoader_x64\.exe.{0,1000}","offensive_tool_keyword","bruteratel","A Customized Command and Control Center for Red Team and Adversary Simulation","T1087-002 - T1071-001 - T1059-003 - T1005 - T1140 - T1482 - T1574-001 - T1562-006 - T1105 - T1036-005 - T1106 - T1046 - T1095 - T1027-002 - T1069-002 - T1057 - T1572 - T1620 - T1021-002 - T1113 - T1518-001 - T1558-003 - T1569-002 - T1204-002 - T1497-003 - T1102 - T1047","TA0002 - TA0003 - TA0011 -TA0010","N/A","BlackSuit - Royal - BlackCat - COZY BEAR - Black Basta","C2","https://bruteratel.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","60559" +"*struts_ext_v2.jar*",".{0,1000}struts_ext_v2\.jar.{0,1000}","offensive_tool_keyword","burpsuite","Collection of burpsuite plugins","T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574","TA0003 - TA0004 - TA0005 - TA0006 - TA0008","N/A","Black Basta","Exploitation tool","https://github.com/Mr-xn/BurpSuite-collections","1","1","N/A","network exploitation tool","N/A","10","3533","676","2025-03-05T12:04:51Z","2020-01-25T02:07:37Z","60561" +"*sty5r4hhb5oihbq2mwevrofdiqbgesi66rvxr5sr573xgvtuvr4cs5yd.onion*",".{0,1000}sty5r4hhb5oihbq2mwevrofdiqbgesi66rvxr5sr573xgvtuvr4cs5yd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","60564" +"*subbrute.exe*",".{0,1000}subbrute.{0,1000}","offensive_tool_keyword","subbrute","A DNS meta-query spider that enumerates DNS records and subdomains.","T1071.001 - T1083 - T1590.001","TA0043 - TA0007?","N/A","ENERGETIC BEAR","Reconnaissance","https://github.com/TheRook/subbrute","1","1","N/A","N/A","5","10","3422","661","2022-01-13T09:25:59Z","2012-06-10T01:08:20Z","60569" +"*subbrute_windows.zip*",".{0,1000}subbrute_windows\.zip.{0,1000}","offensive_tool_keyword","subbrute","A DNS meta-query spider that enumerates DNS records and subdomains.","T1071.001 - T1083 - T1590.001","TA0043 - TA0007?","N/A","ENERGETIC BEAR","Reconnaissance","https://github.com/TheRook/subbrute","1","1","N/A","N/A","5","10","3422","661","2022-01-13T09:25:59Z","2012-06-10T01:08:20Z","60571" +"*subdomain_takeovers.py*",".{0,1000}subdomain_takeovers\.py.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","60572" +"*subdomains-top1million-110000.txt*",".{0,1000}subdomains\-top1million\-110000\.txt.{0,1000}","offensive_tool_keyword","thoth","Automate recon for red team assessments.","T1190 - T1083 - T1018","TA0007 - TA0043 - TA0001","N/A","N/A","Reconnaissance","https://github.com/r1cksec/thoth","1","1","N/A","N/A","7","1","95","10","2025-02-03T12:05:52Z","2021-11-15T13:40:56Z","60579" +"*subdomains-top1million-20000.txt*",".{0,1000}subdomains\-top1million\-20000\.txt.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","60580" +"*subdomain-wordlist.txt*",".{0,1000}subdomain\-wordlist\.txt.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","60583" +"*sublist3r.py*",".{0,1000}sublist3r\.py.{0,1000}","offensive_tool_keyword","Sublist3r","Sublist3r is a python tool designed to enumerate subdomains of websites using OSINT. It helps penetration testers and bug hunters collect and gather subdomains for the domain they are targeting. Sublist3r enumerates subdomains using many search engines such as Google. Yahoo. Bing. Baidu and Ask. Sublist3r also enumerates subdomains using Netcraft. Virustotal. ThreatCrowd. DNSdumpster and ReverseDNS. subbrute was integrated with Sublist3r to increase the possibility of finding more subdomains using bruteforce with an improved wordlist. The credit goes to TheRook who is the author of subbrute.","T1210.001 - T1190 - T1574.001","TA0007 - TA0002 - TA0010","N/A","ENERGETIC BEAR","Reconnaissance","https://github.com/aboul3la/Sublist3r","1","1","N/A","N/A","5","10","10300","2148","2024-08-02T00:00:30Z","2015-12-15T00:55:25Z","60589" +"*Suborner.exe*",".{0,1000}Suborner\.exe.{0,1000}","offensive_tool_keyword","Suborner","The Invisible Account Forger - A simple program to create a Windows account you will only know about ","T1098 - T1175 - T1033","TA0007 - TA0008 - TA0003","N/A","N/A","Persistence","https://github.com/r4wd3r/Suborner","1","1","N/A","N/A","9","5","469","58","2024-11-20T01:34:44Z","2022-04-26T00:12:58Z","60591" +"*Suborner-master.zip*",".{0,1000}Suborner\-master\.zip.{0,1000}","offensive_tool_keyword","Suborner","The Invisible Account Forger - A simple program to create a Windows account you will only know about ","T1098 - T1175 - T1033","TA0007 - TA0008 - TA0003","N/A","N/A","Persistence","https://github.com/r4wd3r/Suborner","1","1","N/A","N/A","9","5","469","58","2024-11-20T01:34:44Z","2022-04-26T00:12:58Z","60592" +"*sudo_inject*",".{0,1000}sudo_inject.{0,1000}","offensive_tool_keyword","sudo_inject","Privilege Escalation by injecting process possessing sudo tokens Inject process that have valid sudo token and activate our own sudo token","T1055 - T1548.001 - T1059.002","TA0002 - TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/nongiach/sudo_inject","1","1","#linux","N/A","N/A","8","712","118","2019-04-14T07:43:35Z","2019-03-24T22:06:22Z","60642" +"*SUDO_KILLER*",".{0,1000}SUDO_KILLER.{0,1000}","offensive_tool_keyword","SUDO_KILLER","sudo exploitation #Abusing sudo #Exploiting Sudo #Linux Privilege Escalation #OSCP If you like the tool and for my personal motivation so as to develop other tools please a +1 star The tool can be used by pentesters. system admins. CTF players. students. System Auditors and trolls :).","T1078 - T1059 - T1204","TA0002 - TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/TH3xACE/SUDO_KILLER","1","1","#linux","N/A","N/A","10","2298","256","2024-12-28T21:52:09Z","2018-12-07T21:08:02Z","60643" +"*sudomy.git*",".{0,1000}sudomy\.git.{0,1000}","offensive_tool_keyword","Sudomy","Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting","T1595 - T1046","TA0002","N/A","N/A","Reconnaissance","https://github.com/screetsec/Sudomy","1","1","#linux","N/A","N/A","10","2139","396","2024-06-27T10:07:42Z","2019-07-26T10:26:34Z","60645" +"*sullo/nikto*",".{0,1000}sullo\/nikto.{0,1000}","offensive_tool_keyword","nikto","Nikto web server scanner","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/sullo/nikto","1","1","#linux","N/A","N/A","10","9184","1306","2025-02-22T14:30:28Z","2012-11-24T04:24:29Z","60648" +"*SunloginClient_11.0.0.33162_X64.exe*",".{0,1000}SunloginClient_11\.0\.0\.33162_X64\.exe.{0,1000}","offensive_tool_keyword","POC","SunloginClient RCE vulnerable version","T1587","TA0001 - TA0003 - TA0009","N/A","N/A","Exploitation tool","https://github.com/Mr-xn/sunlogin_rce","1","1","N/A","N/A","N/A","5","484","195","2022-02-16T16:11:42Z","2022-02-16T14:20:41Z","60649" +"*sunnyelf/cheetah/archive/master.zip*",".{0,1000}sunnyelf\/cheetah\/archive\/master\.zip.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","1","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","60650" +"*superhedgy/AttackSurfaceMapper*",".{0,1000}superhedgy\/AttackSurfaceMapper.{0,1000}","offensive_tool_keyword","AttackSurfaceMapper","AttackSurfaceMapper (ASM) is a reconnaissance tool that uses a mixture of open source intelligence and active techniques to expand the attack surface of your target","T1595 - T1596","TA0043","N/A","N/A","Reconnaissance","https://github.com/superhedgy/AttackSurfaceMapper","1","1","N/A","N/A","6","10","1355","197","2024-04-08T16:13:24Z","2019-08-07T14:32:53Z","60652" +"*Supernova-main.zip*",".{0,1000}Supernova\-main\.zip.{0,1000}","offensive_tool_keyword","Supernova","securely encrypt raw shellcodes","T1027 - T1055.004 - T1140","TA0002 - TA0005 - TA0042","N/A","N/A","Exploitation tool","https://github.com/nickvourd/Supernova","1","1","N/A","N/A","10","9","829","151","2025-04-18T19:15:22Z","2023-08-08T11:30:34Z","60654" +"*supershell*winpty.dll*",".{0,1000}supershell.{0,1000}winpty\.dll.{0,1000}","offensive_tool_keyword","supershell","Supershell is a C2 remote control platform accessed through WEB services. By establishing a reverse SSH tunnel it obtains a fully interactive Shell and supports multi-platform architecture Payload","T1090 - T1059 - T1021","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/tdragon6/Supershell","1","1","N/A","N/A","10","10","1561","196","2023-09-26T13:53:55Z","2023-03-25T15:02:43Z","60655" +"*supershell*winpty-agent.exe*",".{0,1000}supershell.{0,1000}winpty\-agent\.exe.{0,1000}","offensive_tool_keyword","supershell","Supershell is a C2 remote control platform accessed through WEB services. By establishing a reverse SSH tunnel it obtains a fully interactive Shell and supports multi-platform architecture Payload","T1090 - T1059 - T1021","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/tdragon6/Supershell","1","1","N/A","N/A","10","10","1561","196","2023-09-26T13:53:55Z","2023-03-25T15:02:43Z","60656" +"*supp24yy6a66hwszu2piygicgwzdtbwftb76htfj7vnip3getgqnzxid.onion*",".{0,1000}supp24yy6a66hwszu2piygicgwzdtbwftb76htfj7vnip3getgqnzxid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","60657" +"*surajpkhetani/AutoSmuggle*",".{0,1000}surajpkhetani\/AutoSmuggle.{0,1000}","offensive_tool_keyword","AutoSmuggle","Utility to craft HTML or SVG smuggled files for Red Team engagements","T1027.006 - T1598","TA0005 - TA0043","N/A","N/A","Defense Evasion","https://github.com/surajpkhetani/AutoSmuggle","1","1","N/A","N/A","9","3","240","26","2024-03-19T09:26:49Z","2022-03-20T19:02:06Z","60676" +"*suspendresume.x64.*",".{0,1000}suspendresume\.x64\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","60679" +"*suspendresume.x86.*",".{0,1000}suspendresume\.x86\..{0,1000}","offensive_tool_keyword","cobaltstrike","Cobaltstrike Bofs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Remote-OPs-BOF","1","1","N/A","N/A","10","10","959","147","2025-02-26T21:21:25Z","2022-04-25T16:32:08Z","60680" +"*svc_stager.exe*",".{0,1000}svc_stager\.exe.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","60682" +"*SW2_GetSyscallNumber*",".{0,1000}SW2_GetSyscallNumber.{0,1000}","offensive_tool_keyword","cobaltstrike","Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF) via Syswhispers2","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Sh0ckFR/InlineWhispers2","1","1","N/A","N/A","10","10","185","28","2022-07-21T08:40:05Z","2021-11-16T12:47:35Z","60683" +"*SW2_GetSyscallNumber*",".{0,1000}SW2_GetSyscallNumber.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","60684" +"*SW2_HashSyscall*",".{0,1000}SW2_HashSyscall.{0,1000}","offensive_tool_keyword","cobaltstrike","Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF) via Syswhispers2","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Sh0ckFR/InlineWhispers2","1","1","N/A","N/A","10","10","185","28","2022-07-21T08:40:05Z","2021-11-16T12:47:35Z","60685" +"*SW2_PopulateSyscallList*",".{0,1000}SW2_PopulateSyscallList.{0,1000}","offensive_tool_keyword","cobaltstrike","Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF) via Syswhispers2","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Sh0ckFR/InlineWhispers2","1","1","N/A","N/A","10","10","185","28","2022-07-21T08:40:05Z","2021-11-16T12:47:35Z","60686" +"*SW2_PopulateSyscallList*",".{0,1000}SW2_PopulateSyscallList.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","60687" +"*SW2_RVA2VA*",".{0,1000}SW2_RVA2VA.{0,1000}","offensive_tool_keyword","cobaltstrike","Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF) via Syswhispers2","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Sh0ckFR/InlineWhispers2","1","1","N/A","N/A","10","10","185","28","2022-07-21T08:40:05Z","2021-11-16T12:47:35Z","60688" +"*SW2_RVA2VA*",".{0,1000}SW2_RVA2VA.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","60689" +"*SW3_GetSyscallAddress*",".{0,1000}SW3_GetSyscallAddress.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","60690" +"*Sw4mpf0x/PowerLurk*",".{0,1000}Sw4mpf0x\/PowerLurk.{0,1000}","offensive_tool_keyword","Powerlurk","PowerLurk is a PowerShell toolset for building malicious WMI Event Subsriptions","T1084 - T1059.001 - T1546.003 - T1053.005","TA0003 - TA0005 - TA0002 - TA0006","N/A","N/A","Persistence","https://github.com/Sw4mpf0x/PowerLurk","1","1","N/A","N/A","10","4","384","72","2016-07-25T22:19:22Z","2016-07-13T20:07:25Z","60691" +"*swagkarna/Defeat-Defender-V*",".{0,1000}swagkarna\/Defeat\-Defender\-V.{0,1000}","offensive_tool_keyword","Defeat-Defender","script to dismantle complete windows defender protection and even bypass tamper protection - Disable Windows-Defender Permanently.","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/swagkarna/Defeat-Defender-V1.2.0","1","1","N/A","N/A","10","10","1530","316","2023-10-20T17:55:09Z","2020-12-10T07:22:06Z","60692" +"*SwampThing.exe*",".{0,1000}SwampThing\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","EDR Evasion - Combination of SwampThing - TikiTorch","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rkervella/CarbonMonoxide","1","1","N/A","N/A","10","10","25","10","2020-05-28T10:40:20Z","2020-05-15T09:32:25Z","60694" +"*SwampThing.exe*",".{0,1000}SwampThing\.exe.{0,1000}","offensive_tool_keyword","SwampThing","SwampThing lets you to spoof process command line args (x32/64). Essentially you create a process in a suspended state - rewrite the PEB - resume and finally revert the PEB. The end result is that logging infrastructure will record the fake command line args instead of the real ones","T1036.005 - T1564.002","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/FuzzySecurity/Sharp-Suite/tree/master/SwampThing","1","1","N/A","N/A","N/A","10","1131","203","2022-12-22T23:57:19Z","2018-12-10T00:08:37Z","60695" +"*SwampThing.pdb*",".{0,1000}SwampThing\.pdb.{0,1000}","offensive_tool_keyword","SwampThing","SwampThing lets you to spoof process command line args (x32/64). Essentially you create a process in a suspended state - rewrite the PEB - resume and finally revert the PEB. The end result is that logging infrastructure will record the fake command line args instead of the real ones","T1036.005 - T1564.002","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/FuzzySecurity/Sharp-Suite/tree/master/SwampThing","1","1","N/A","N/A","N/A","10","1131","203","2022-12-22T23:57:19Z","2018-12-10T00:08:37Z","60696" +"*SwampThing.sln*",".{0,1000}SwampThing\.sln.{0,1000}","offensive_tool_keyword","SwampThing","SwampThing lets you to spoof process command line args (x32/64). Essentially you create a process in a suspended state - rewrite the PEB - resume and finally revert the PEB. The end result is that logging infrastructure will record the fake command line args instead of the real ones","T1036.005 - T1564.002","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/FuzzySecurity/Sharp-Suite/tree/master/SwampThing","1","1","N/A","N/A","N/A","10","1131","203","2022-12-22T23:57:19Z","2018-12-10T00:08:37Z","60697" +"*SWbemServicesImplant*",".{0,1000}SWbemServicesImplant.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","60700" +"*SweetPotato.cna*",".{0,1000}SweetPotato\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Modified SweetPotato to work with CobaltStrike v4.0","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tycx2ry/SweetPotato_CS","1","1","N/A","N/A","10","10","241","48","2020-04-30T14:27:20Z","2020-04-16T08:01:31Z","60703" +"*SweetPotato.csproj*",".{0,1000}SweetPotato\.csproj.{0,1000}","offensive_tool_keyword","cobaltstrike","Modified SweetPotato to work with CobaltStrike v4.0","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tycx2ry/SweetPotato_CS","1","1","N/A","N/A","10","10","241","48","2020-04-30T14:27:20Z","2020-04-16T08:01:31Z","60704" +"*SweetPotato.exe*",".{0,1000}SweetPotato\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Modified SweetPotato to work with CobaltStrike v4.0","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tycx2ry/SweetPotato_CS","1","1","N/A","N/A","10","10","241","48","2020-04-30T14:27:20Z","2020-04-16T08:01:31Z","60705" +"*SweetPotato.exe*",".{0,1000}SweetPotato\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","60706" +"*SweetPotato.exe*",".{0,1000}SweetPotato\.exe.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","60707" +"*SweetPotato.ImpersonationToken*",".{0,1000}SweetPotato\.ImpersonationToken.{0,1000}","offensive_tool_keyword","cobaltstrike","Modified SweetPotato to work with CobaltStrike v4.0","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tycx2ry/SweetPotato_CS","1","1","N/A","N/A","10","10","241","48","2020-04-30T14:27:20Z","2020-04-16T08:01:31Z","60708" +"*SweetPotato.sln*",".{0,1000}SweetPotato\.sln.{0,1000}","offensive_tool_keyword","cobaltstrike","Modified SweetPotato to work with CobaltStrike v4.0","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tycx2ry/SweetPotato_CS","1","1","N/A","N/A","10","10","241","48","2020-04-30T14:27:20Z","2020-04-16T08:01:31Z","60709" +"*SweetPotato-N*.exe*",".{0,1000}SweetPotato\-N.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","60710" +"*sweetsoftware/Ares*",".{0,1000}sweetsoftware\/Ares.{0,1000}","offensive_tool_keyword","Ares","Python C2 botnet and backdoor ","T1105 - T1102 - T1055","TA0003 - TA0002 - TA0007","N/A","N/A","C2","https://github.com/sweetsoftware/Ares","1","1","N/A","N/A","10","10","1588","477","2023-03-02T12:43:09Z","2015-10-18T12:26:27Z","60711" +"*swisskyrepo/SharpLAPS*",".{0,1000}swisskyrepo\/SharpLAPS.{0,1000}","offensive_tool_keyword","SharpLAPS","Retrieve LAPS password from LDAP","T1552.005 - T1212","TA0006 - TA0007","N/A","Dispossessor","Credential Access","https://github.com/swisskyrepo/SharpLAPS","1","1","N/A","N/A","10","5","408","85","2021-02-17T14:32:16Z","2021-02-16T17:27:41Z","60713" +"*swisskyrepo/SSRFmap*",".{0,1000}swisskyrepo\/SSRFmap.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","60714" +"*SwitchPriv.exe*",".{0,1000}SwitchPriv\.exe.{0,1000}","offensive_tool_keyword","PrivFu","Kernel mode WinDbg extension and PoCs for token privilege investigation.","T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001","TA0007 - TA0008 - TA0002 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","60722" +"*SxNade/Rudrastra*",".{0,1000}SxNade\/Rudrastra.{0,1000}","offensive_tool_keyword","Rudrastra","Make a Fake wireless access point aka Evil Twin","T1491 - T1090.004 - T1557.001","TA0040 - TA0011 - TA0002","N/A","N/A","Sniffing & Spoofing","https://github.com/SxNade/Rudrastra","1","1","N/A","N/A","8","1","67","21","2023-04-22T15:10:42Z","2020-11-05T09:38:15Z","60723" +"*syhunt.com/sandcat/*",".{0,1000}syhunt\.com\/sandcat\/.{0,1000}","offensive_tool_keyword","sandcat","An open-source pentest oriented web browser","T1216 - T1590 - T1071","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/syhunt/sandcat","1","1","N/A","N/A","6","6","525","72","2023-12-21T18:40:27Z","2014-05-20T23:36:21Z","60725" +"*syhunt/sandcat*",".{0,1000}syhunt\/sandcat.{0,1000}","offensive_tool_keyword","sandcat","An open-source pentest oriented web browser","T1216 - T1590 - T1071","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/syhunt/sandcat","1","1","N/A","N/A","6","6","525","72","2023-12-21T18:40:27Z","2014-05-20T23:36:21Z","60726" +"*syhunt-sandcat-*.exe*",".{0,1000}syhunt\-sandcat\-.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","sandcat","An open-source pentest oriented web browser","T1216 - T1590 - T1071","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/syhunt/sandcat","1","1","N/A","N/A","6","6","525","72","2023-12-21T18:40:27Z","2014-05-20T23:36:21Z","60727" +"*synacktiv/DLHell*",".{0,1000}synacktiv\/DLHell.{0,1000}","offensive_tool_keyword","DLHell","Local & remote Windows DLL Proxying","T1574.002 - T1055","TA0005 - TA0002 - TA0004","N/A","N/A","Defense Evasion","https://github.com/synacktiv/DLHell","1","1","N/A","N/A","9","2","163","24","2024-06-17T16:20:10Z","2024-04-17T13:00:12Z","60728" +"*synacktiv/GPOddity*",".{0,1000}synacktiv\/GPOddity.{0,1000}","offensive_tool_keyword","GPOddity","GPO attack vectors through NTLM relaying","T1558.001 - T1552.001","TA0003 - TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/synacktiv/GPOddity","1","1","N/A","N/A","9","3","297","26","2024-11-08T15:14:06Z","2023-09-01T08:13:25Z","60729" +"*synacktiv/Invoke-RunAsWithCert*",".{0,1000}synacktiv\/Invoke\-RunAsWithCert.{0,1000}","offensive_tool_keyword","Invoke-RunAsWithCert","A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine","T1550.003 - T1078 - T1027","TA0006 - TA0005","N/A","N/A","Lateral Movement","https://github.com/synacktiv/Invoke-RunAsWithCert","1","1","N/A","N/A","8","2","150","14","2024-05-13T08:26:56Z","2024-05-03T12:44:21Z","60730" +"*synacktiv/ntdissector*",".{0,1000}synacktiv\/ntdissector.{0,1000}","offensive_tool_keyword","ntdissector","Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.","T1003.003","TA0006 ","N/A","N/A","Credential Access","https://github.com/synacktiv/ntdissector","1","1","N/A","N/A","9","2","139","17","2024-08-16T14:18:35Z","2023-09-05T12:13:47Z","60731" +"*synacktiv/OUned*",".{0,1000}synacktiv\/OUned.{0,1000}","offensive_tool_keyword","Ouned","The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning","T1484 - T1210","TA0001 - TA0004 - TA0005 - TA0009","N/A","N/A","Privilege Escalation","https://github.com/synacktiv/Ouned","1","1","N/A","N/A","10","2","112","14","2025-03-29T14:20:38Z","2024-04-17T10:18:04Z","60732" +"*synacktiv/SCCMSecrets*",".{0,1000}synacktiv\/SCCMSecrets.{0,1000}","offensive_tool_keyword","SCCMSecrets","SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting - initial access and lateral movement.","T1555 - T1078 - T1070 - T1021","TA0006 - TA0008 - TA0001","N/A","N/A","Lateral Movement","https://github.com/synacktiv/SCCMSecrets","1","1","N/A","N/A","8","3","208","22","2024-12-17T14:29:39Z","2024-08-14T09:45:44Z","60733" +"*sync-starkiller*",".{0,1000}sync\-starkiller.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","60735" +"*synergy_httpx.py*",".{0,1000}synergy_httpx\.py.{0,1000}","offensive_tool_keyword","Synergy-httpx","A Python http(s) server designed to assist in red teaming activities such as receiving intercepted data via POST requests and serving content dynamically","T1021.002 - T1105 - T1090","TA0002 - TA0011 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/t3l3machus/Synergy-httpx","1","1","N/A","N/A","8","2","129","17","2024-07-19T06:40:59Z","2023-06-02T10:06:41Z","60739" +"*Synergy-httpx-main*",".{0,1000}Synergy\-httpx\-main.{0,1000}","offensive_tool_keyword","Synergy-httpx","A Python http(s) server designed to assist in red teaming activities such as receiving intercepted data via POST requests and serving content dynamically","T1021.002 - T1105 - T1090","TA0002 - TA0011 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/t3l3machus/Synergy-httpx","1","1","N/A","N/A","8","2","129","17","2024-07-19T06:40:59Z","2023-06-02T10:06:41Z","60740" +"*syscall_inject.rb*",".{0,1000}syscall_inject\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","60743" +"*syscalls.asm*",".{0,1000}syscalls\.asm.{0,1000}","offensive_tool_keyword","cobaltstrike","Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/InlineWhispers","1","1","N/A","N/A","10","10","315","42","2021-11-09T15:39:27Z","2020-12-25T16:52:50Z","60744" +"*syscalls.nim*",".{0,1000}syscalls\.nim.{0,1000}","offensive_tool_keyword","Nimcrypt2",".NET PE & Raw Shellcode Packer/Loader Written in Nim","T1027 - T1202 - T1059.005 - T1105 - T1045","TA0005 - TA0011 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/icyguider/Nimcrypt2","1","1","N/A","N/A","N/A","8","771","124","2023-01-20T22:07:15Z","2022-02-23T15:43:16Z","60745" +"*syscalls_dump.*",".{0,1000}syscalls_dump\..{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","60746" +"*syscalls_inject.*",".{0,1000}syscalls_inject\..{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","60748" +"*syscalls_spawn.*",".{0,1000}syscalls_spawn\..{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","60752" +"*syscallsapcspawn.x64*",".{0,1000}syscallsapcspawn\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","60753" +"*syscalls-asm.h*",".{0,1000}syscalls\-asm\.h.{0,1000}","offensive_tool_keyword","cobaltstrike","Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/InlineWhispers","1","1","N/A","N/A","10","10","315","42","2021-11-09T15:39:27Z","2020-12-25T16:52:50Z","60754" +"*syscallsdump.x64*",".{0,1000}syscallsdump\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","60755" +"*syscallsinject.x64*",".{0,1000}syscallsinject\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","60756" +"*syscallsspawn.x64*",".{0,1000}syscallsspawn\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/ajpc500/BOFs","1","1","N/A","N/A","10","10","583","114","2022-11-01T14:51:07Z","2020-12-19T11:21:40Z","60757" +"*syscallStuff.asm*",".{0,1000}syscallStuff\.asm.{0,1000}","offensive_tool_keyword","HadesLdr","Shellcode Loader Implementing Indirect Dynamic Syscall - API Hashing - Fileless Shellcode retrieving using Winsock2","T1055.012 - T1055.001 - T1547.002","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/CognisysGroup/HadesLdr","1","1","N/A","N/A","10","3","292","47","2023-07-15T21:23:49Z","2023-07-12T11:44:07Z","60758" +"*sysdream/chashell*",".{0,1000}sysdream\/chashell.{0,1000}","offensive_tool_keyword","chashell","Chashell is a Go reverse shell that communicates over DNS. It can be used to bypass firewalls or tightly restricted networks","T1071.004 - T1572 - T1071 - T1027","TA0011 - TA0005 - TA0008","N/A","PYSA","C2","https://github.com/sysdream/chashell","1","1","N/A","N/A","10","10","1068","135","2022-04-05T17:22:14Z","2019-02-15T14:54:48Z","60760" +"*sysdream/ligolo*",".{0,1000}sysdream\/ligolo.{0,1000}","offensive_tool_keyword","ligolo","ligolo is a simple and lightweight tool for establishing SOCKS5 or TCP tunnels from a reverse connection in complete safety (TLS certificate with elliptical curve)","T1071 - T1021 - T1573","TA0011 - TA0002","N/A","AvosLocker - LockBit","C2","https://github.com/sysdream/ligolo","1","1","N/A","N/A","10","10","1764","224","2023-01-06T19:49:22Z","2020-05-22T07:58:13Z","60761" +"*sysmonquiet.*",".{0,1000}sysmonquiet\..{0,1000}","offensive_tool_keyword","sysmonquiet","RDLL for Cobalt Strike beacon to silence Sysmon process","T1055 - T1055.012 - T1063","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/ScriptIdiot/SysmonQuiet","1","1","N/A","N/A","N/A","1","88","16","2022-09-09T12:28:15Z","2022-07-11T14:17:34Z","60766" +"*SysmonQuiet-main*",".{0,1000}SysmonQuiet\-main.{0,1000}","offensive_tool_keyword","sysmonquiet","RDLL for Cobalt Strike beacon to silence Sysmon process","T1055 - T1055.012 - T1063","TA0002 - TA0003 - TA0008","N/A","N/A","Defense Evasion","https://github.com/ScriptIdiot/SysmonQuiet","1","1","N/A","N/A","N/A","1","88","16","2022-09-09T12:28:15Z","2022-07-11T14:17:34Z","60767" +"*SySS-Research/Seth*",".{0,1000}SySS\-Research\/Seth.{0,1000}","offensive_tool_keyword","Seth","Perform a MitM attack and extract clear text credentials from RDP connections","T1557 - T1557.001 - T1110 - T1110.001 - T1071 - T1071.001","TA0006 ","N/A","N/A","Sniffing & Spoofing","https://github.com/SySS-Research/Seth","1","1","N/A","N/A","9","10","1423","323","2023-02-09T14:29:05Z","2017-03-10T15:46:38Z","60769" +"*System32fileWritePermissions.txt*",".{0,1000}System32fileWritePermissions\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","60782" +"*syswhispers.py*",".{0,1000}syswhispers\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF)","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/InlineWhispers","1","1","N/A","N/A","10","10","315","42","2021-11-09T15:39:27Z","2020-12-25T16:52:50Z","60816" +"*syswhispers.py*",".{0,1000}syswhispers\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF) via Syswhispers2","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Sh0ckFR/InlineWhispers2","1","1","N/A","N/A","10","10","185","28","2022-07-21T08:40:05Z","2021-11-16T12:47:35Z","60817" +"*syswhispers.py*",".{0,1000}syswhispers\.py.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1027 - T1055 - T1070 - T1112 - T1140","TA0005 - TA0006 - TA0008","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","60818" +"*syswhispers.py*",".{0,1000}syswhispers\.py.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","60819" +"*syswhispers.py*",".{0,1000}syswhispers\.py.{0,1000}","offensive_tool_keyword","SysWhispers3","SysWhispers on Steroids - AV/EDR evasion via direct system calls.","T1059 - T1573 - T1218 - T1216","TA0002 - TA0008 - TA0011","N/A","N/A","Defense Evasion","https://github.com/klezVirus/SysWhispers3","1","1","N/A","N/A","N/A","10","1414","180","2024-07-31T05:24:06Z","2022-03-07T18:56:21Z","60820" +"*SysWhispers2*",".{0,1000}SysWhispers2.{0,1000}","offensive_tool_keyword","cobaltstrike","Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF) via Syswhispers2","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Sh0ckFR/InlineWhispers2","1","1","N/A","N/A","10","10","185","28","2022-07-21T08:40:05Z","2021-11-16T12:47:35Z","60821" +"*syswhispersv2_x86*",".{0,1000}syswhispersv2_x86.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","60825" +"*szymon1118/logon_backdoor*",".{0,1000}szymon1118\/logon_backdoor.{0,1000}","offensive_tool_keyword","logon_backdoor","automated sticky keys backdoor","T1174 - T1078 - T1546.013","TA0003","N/A","N/A","Persistence","https://github.com/szymon1118/logon_backdoor","1","1","N/A","N/A","6","1","10","4","2016-02-12T11:42:59Z","2016-02-10T22:38:46Z","60828" +"*t.me/dedsecransom*",".{0,1000}t\.me\/dedsecransom.{0,1000}","offensive_tool_keyword","DEDSEC-RANSOMWARE","dedsec ransomware","T1486 - T1489 - T1490 - T1495 - T1488 - T1482","TA0040 - TA0043 - TA0042 - TA0009 - TA0010","N/A","N/A","Ransomware","https://github.com/xelroth/DEDSEC-RANSOMWARE","1","1","N/A","N/A","10","1","7","1","2024-05-17T11:12:23Z","2024-05-17T10:34:03Z","60831" +"*t.me/Melteddd*",".{0,1000}t\.me\/Melteddd.{0,1000}","offensive_tool_keyword","HVNC","Standalone HVNC Client & Server Coded in C++ (Modified Tinynuke)","T1021.005 - T1071 - T1563.002 - T1219","TA0001 - TA0002 - TA0008","N/A","N/A","RMM","https://github.com/Meltedd/HVNC","1","1","N/A","N/A","10","5","445","133","2025-03-27T21:20:10Z","2021-09-03T17:34:44Z","60832" +"*T0XlCv1.rule*",".{0,1000}T0XlCv1\.rule.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60835" +"*T1esh0u/SecScanC2*",".{0,1000}T1esh0u\/SecScanC2.{0,1000}","offensive_tool_keyword","SecScanC2","SecScanC2 can manage assetment to create P2P network for security scanning & C2. The tool can assist security researchers in conducting penetration testing more efficiently - preventing scanning from being blocked - protecting themselves from being traced.","T1021 - T1090","TA0011 - TA0002 - TA0040 - TA0043","N/A","N/A","C2","https://github.com/T1esh0u/SecScanC2","1","1","#P2P","N/A","10","","N/A","","","","60836" +"*t3l3machus/ACEshark*",".{0,1000}t3l3machus\/ACEshark.{0,1000}","offensive_tool_keyword","ACEshark","uncover potential privilege escalation vectors by analyzing windows service configurations and Access Control Entries","T1058 - T1548","TA0004","N/A","N/A","Privilege Escalation","https://github.com/t3l3machus/ACEshark","1","1","N/A","N/A","6","2","109","19","2025-01-15T07:01:48Z","2024-12-28T10:42:29Z","60837" +"*t3l3machus/BabelStrike*",".{0,1000}t3l3machus\/BabelStrike.{0,1000}","offensive_tool_keyword","BabelStrike","The purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin)","T1078 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/t3l3machus/BabelStrike","1","1","N/A","N/A","1","2","132","23","2024-07-19T07:02:42Z","2023-01-10T07:59:00Z","60838" +"*t3l3machus/hoaxshell*",".{0,1000}t3l3machus\/hoaxshell.{0,1000}","offensive_tool_keyword","hoaxshell","An unconventional Windows reverse shell. currently undetected by Microsoft Defender and various other AV solutions. solely based on http(s) traffic","T1059 - T1071 - T1071.001 - T1203","TA0002 - TA0011","N/A","N/A","C2","https://github.com/t3l3machus/hoaxshell","1","1","N/A","N/A","N/A","10","3212","499","2025-01-19T12:29:35Z","2022-07-10T15:36:24Z","60839" +"*t3l3machus/Synergy-httpx*",".{0,1000}t3l3machus\/Synergy\-httpx.{0,1000}","offensive_tool_keyword","Synergy-httpx","A Python http(s) server designed to assist in red teaming activities such as receiving intercepted data via POST requests and serving content dynamically","T1021.002 - T1105 - T1090","TA0002 - TA0011 - TA0005","N/A","N/A","Data Exfiltration","https://github.com/t3l3machus/Synergy-httpx","1","1","N/A","N/A","8","2","129","17","2024-07-19T06:40:59Z","2023-06-02T10:06:41Z","60840" +"*TailorScan_darwin*",".{0,1000}TailorScan_darwin.{0,1000}","offensive_tool_keyword","cobaltstrike","Self-use suture monster intranet scanner - supports port scanning - identifying services - getting title - scanning multiple network cards - ms17010 scanning - icmp survival detection","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/uknowsec/TailorScan","1","1","#linux","N/A","10","10","279","48","2020-11-12T08:29:11Z","2020-11-09T07:38:16Z","60847" +"*TailorScan_freebsd*",".{0,1000}TailorScan_freebsd.{0,1000}","offensive_tool_keyword","cobaltstrike","Self-use suture monster intranet scanner - supports port scanning - identifying services - getting title - scanning multiple network cards - ms17010 scanning - icmp survival detection","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/uknowsec/TailorScan","1","1","N/A","N/A","10","10","279","48","2020-11-12T08:29:11Z","2020-11-09T07:38:16Z","60848" +"*TailorScan_linux_*",".{0,1000}TailorScan_linux_.{0,1000}","offensive_tool_keyword","cobaltstrike","Self-use suture monster intranet scanner - supports port scanning - identifying services - getting title - scanning multiple network cards - ms17010 scanning - icmp survival detection","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/uknowsec/TailorScan","1","1","#linux","N/A","10","10","279","48","2020-11-12T08:29:11Z","2020-11-09T07:38:16Z","60849" +"*TailorScan_netbsd_*",".{0,1000}TailorScan_netbsd_.{0,1000}","offensive_tool_keyword","cobaltstrike","Self-use suture monster intranet scanner - supports port scanning - identifying services - getting title - scanning multiple network cards - ms17010 scanning - icmp survival detection","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/uknowsec/TailorScan","1","1","N/A","N/A","10","10","279","48","2020-11-12T08:29:11Z","2020-11-09T07:38:16Z","60850" +"*TailorScan_openbsd_*",".{0,1000}TailorScan_openbsd_.{0,1000}","offensive_tool_keyword","cobaltstrike","Self-use suture monster intranet scanner - supports port scanning - identifying services - getting title - scanning multiple network cards - ms17010 scanning - icmp survival detection","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/uknowsec/TailorScan","1","1","N/A","N/A","10","10","279","48","2020-11-12T08:29:11Z","2020-11-09T07:38:16Z","60851" +"*TailorScan_windows_*.exe*",".{0,1000}TailorScan_windows_.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Self-use suture monster intranet scanner - supports port scanning - identifying services - getting title - scanning multiple network cards - ms17010 scanning - icmp survival detection","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/uknowsec/TailorScan","1","1","N/A","N/A","10","10","279","48","2020-11-12T08:29:11Z","2020-11-09T07:38:16Z","60852" +"*TakahiroHaruyama/VDR*",".{0,1000}TakahiroHaruyama\/VDR.{0,1000}","offensive_tool_keyword","VDR","Vulnerable driver research tool - result and exploit PoCs","T1547.009 - T1210 - T1068 - T1055","TA0003 - TA0002 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/TakahiroHaruyama/VDR","1","1","N/A","N/A","10","2","192","29","2023-11-01T00:06:55Z","2023-10-23T08:34:44Z","60883" +"*take_shellcode.bat*",".{0,1000}take_shellcode\.bat.{0,1000}","offensive_tool_keyword","WinShellcode","It's a C code project created in Visual Studio that helps you generate shellcode from your C code.","T1059.001 - T1059.003 - T1059.005 - T1059.007 - T1059.004 - T1059.006 - T1218 - T1027.001 - T1564.003 - T1027","TA0002 - TA0006","N/A","N/A","Exploitation tool","https://github.com/DallasFR/WinShellcode","1","1","N/A","N/A","N/A","","N/A","","","","60884" +"*TakeMyRDP*logfile.txt*",".{0,1000}TakeMyRDP.{0,1000}logfile\.txt.{0,1000}","offensive_tool_keyword","TakeMyRDP","An updated version of keystroke logger targeting the Remote Desktop Protocol (RDP) related processes","T1056.001 - T1021.001 - T1057","TA0002 - TA0003 - TA0007","N/A","N/A","Exploitation tool","https://github.com/nocerainfosec/TakeMyRDP2.0","1","1","N/A","N/A","N/A","2","104","9","2023-07-27T03:10:08Z","2023-07-03T12:48:49Z","60886" +"*TakeMyRDP.cpp*",".{0,1000}TakeMyRDP\.cpp.{0,1000}","offensive_tool_keyword","TakeMyRDP","A keystroke logger targeting the Remote Desktop Protocol (RDP) related processes","T1056.001 - T1021.001 - T1057","TA0002 - TA0003 - TA0007","N/A","N/A","Exploitation tool","https://github.com/TheD1rkMtr/TakeMyRDP","1","1","N/A","N/A","N/A","4","386","63","2023-08-02T02:23:28Z","2023-07-02T17:25:33Z","60887" +"*TakeMyRDP.exe*",".{0,1000}TakeMyRDP\.exe.{0,1000}","offensive_tool_keyword","TakeMyRDP","A keystroke logger targeting the Remote Desktop Protocol (RDP) related processes","T1056.001 - T1021.001 - T1057","TA0002 - TA0003 - TA0007","N/A","N/A","Exploitation tool","https://github.com/TheD1rkMtr/TakeMyRDP","1","1","N/A","N/A","N/A","4","386","63","2023-08-02T02:23:28Z","2023-07-02T17:25:33Z","60888" +"*TakeMyRDP.git*",".{0,1000}TakeMyRDP\.git.{0,1000}","offensive_tool_keyword","TakeMyRDP","A keystroke logger targeting the Remote Desktop Protocol (RDP) related processes","T1056.001 - T1021.001 - T1057","TA0002 - TA0003 - TA0007","N/A","N/A","Exploitation tool","https://github.com/TheD1rkMtr/TakeMyRDP","1","1","N/A","N/A","N/A","4","386","63","2023-08-02T02:23:28Z","2023-07-02T17:25:33Z","60889" +"*TakeMyRDP.h*",".{0,1000}TakeMyRDP\.h.{0,1000}","offensive_tool_keyword","TakeMyRDP","An updated version of keystroke logger targeting the Remote Desktop Protocol (RDP) related processes","T1056.001 - T1021.001 - T1057","TA0002 - TA0003 - TA0007","N/A","N/A","Exploitation tool","https://github.com/nocerainfosec/TakeMyRDP2.0","1","1","N/A","N/A","N/A","2","104","9","2023-07-27T03:10:08Z","2023-07-03T12:48:49Z","60890" +"*TakeMyRDP.sln*",".{0,1000}TakeMyRDP\.sln.{0,1000}","offensive_tool_keyword","TakeMyRDP","A keystroke logger targeting the Remote Desktop Protocol (RDP) related processes","T1056.001 - T1021.001 - T1057","TA0002 - TA0003 - TA0007","N/A","N/A","Exploitation tool","https://github.com/TheD1rkMtr/TakeMyRDP","1","1","N/A","N/A","N/A","4","386","63","2023-08-02T02:23:28Z","2023-07-02T17:25:33Z","60891" +"*TakeMyRDP.vcxproj*",".{0,1000}TakeMyRDP\.vcxproj.{0,1000}","offensive_tool_keyword","TakeMyRDP","A keystroke logger targeting the Remote Desktop Protocol (RDP) related processes","T1056.001 - T1021.001 - T1057","TA0002 - TA0003 - TA0007","N/A","N/A","Exploitation tool","https://github.com/TheD1rkMtr/TakeMyRDP","1","1","N/A","N/A","N/A","4","386","63","2023-08-02T02:23:28Z","2023-07-02T17:25:33Z","60892" +"*TakeMyRDP2.0*",".{0,1000}TakeMyRDP2\.0.{0,1000}","offensive_tool_keyword","TakeMyRDP","An updated version of keystroke logger targeting the Remote Desktop Protocol (RDP) related processes","T1056.001 - T1021.001 - T1057","TA0002 - TA0003 - TA0007","N/A","N/A","Exploitation tool","https://github.com/nocerainfosec/TakeMyRDP2.0","1","1","N/A","N/A","N/A","2","104","9","2023-07-27T03:10:08Z","2023-07-03T12:48:49Z","60893" +"*TakeMyRDP-main*",".{0,1000}TakeMyRDP\-main.{0,1000}","offensive_tool_keyword","TakeMyRDP","A keystroke logger targeting the Remote Desktop Protocol (RDP) related processes","T1056.001 - T1021.001 - T1057","TA0002 - TA0003 - TA0007","N/A","N/A","Exploitation tool","https://github.com/TheD1rkMtr/TakeMyRDP","1","1","N/A","N/A","N/A","4","386","63","2023-08-02T02:23:28Z","2023-07-02T17:25:33Z","60894" +"*TakeOwnershipServiceModificationVariant.exe*",".{0,1000}TakeOwnershipServiceModificationVariant\.exe.{0,1000}","offensive_tool_keyword","PrivFu","get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","KernelWritePoCs","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","60902" +"*tanc7/EXOCET-AV-Evasion*",".{0,1000}tanc7\/EXOCET\-AV\-Evasion.{0,1000}","offensive_tool_keyword","EXOCET-AV-Evasion","EXOCET - AV-evading undetectable payload delivery tool","T1055 - T1218.011 - T1027.009 - T1027 - T1105 - T1102.001","TA0005 - TA0001 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/tanc7/EXOCET-AV-Evasion","1","1","N/A","N/A","10","9","840","147","2022-08-16T02:58:39Z","2020-07-15T06:55:13Z","60904" +"*Taonn/EmailAll*",".{0,1000}Taonn\/EmailAll.{0,1000}","offensive_tool_keyword","EmailAll","EmailAll is a powerful Email Collect tool","T1114.001 - T1113 - T1087.003","TA0009 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Taonn/EmailAll","1","1","N/A","N/A","6","8","715","117","2022-03-04T10:36:41Z","2022-02-14T06:55:30Z","60905" +"*tarcisio-marinho/cryptomining*",".{0,1000}tarcisio\-marinho\/cryptomining.{0,1000}","offensive_tool_keyword","cryptomining","A Linux Cyptomining malware","T1496","TA0009","N/A","N/A","Cryptomining","https://github.com/tarcisio-marinho/cryptomining","1","1","#linux","N/A","7","1","36","15","2023-05-05T02:42:59Z","2018-04-07T03:59:52Z","60907" +"*tarcisio-marinho/GonnaCry*",".{0,1000}tarcisio\-marinho\/GonnaCry.{0,1000}","offensive_tool_keyword","GonnaCry","a linux ransomware","T1486 - T1059 - T1020 - T1083 - T1070","TA0040 - TA0005 - TA0009 - TA0010","N/A","N/A","Ransomware","https://github.com/tarcisio-marinho/GonnaCry","1","1","N/A","N/A","10","8","717","402","2025-01-24T13:39:57Z","2017-05-12T23:46:28Z","60908" +"*target_reconftw_ipcidr.txt*",".{0,1000}target_reconftw_ipcidr\.txt.{0,1000}","offensive_tool_keyword","reconftw","reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities","T1595 - T1590 - T1592 - T1596 - T1598 - T1046 - T1599 - T1213 - T1597","TA0043 - TA0042 - TA0007 - TA0001","N/A","N/A","Vulnerability Scanner","https://github.com/six2dez/reconftw","1","1","#linux","N/A","7","10","6202","982","2025-04-22T13:01:31Z","2020-12-30T23:52:52Z","60911" +"*targetedKerberoast.git*",".{0,1000}targetedKerberoast\.git.{0,1000}","offensive_tool_keyword","targetedKerberoast","Kerberoast with ACL abuse capabilities","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/ShutdownRepo/targetedKerberoast","1","1","N/A","N/A","N/A","5","442","63","2024-12-16T07:32:14Z","2021-08-02T20:19:35Z","60913" +"*targetedKerberoast.py*",".{0,1000}targetedKerberoast\.py.{0,1000}","offensive_tool_keyword","targetedKerberoast","Kerberoast with ACL abuse capabilities","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/ShutdownRepo/targetedKerberoast","1","1","N/A","N/A","N/A","5","442","63","2024-12-16T07:32:14Z","2021-08-02T20:19:35Z","60914" +"*targetedkerberoast_attack*",".{0,1000}targetedkerberoast_attack.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","60915" +"*targetedkerberoast_hashes_*.txt*",".{0,1000}targetedkerberoast_hashes_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","60916" +"*targetedkerberoast_output_*.txt*",".{0,1000}targetedkerberoast_output_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","60917" +"*targetedKerberoast-main*",".{0,1000}targetedKerberoast\-main.{0,1000}","offensive_tool_keyword","targetedKerberoast","Kerberoast with ACL abuse capabilities","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/ShutdownRepo/targetedKerberoast","1","1","N/A","N/A","N/A","5","442","63","2024-12-16T07:32:14Z","2021-08-02T20:19:35Z","60918" +"*TartarusGate-master*",".{0,1000}TartarusGate\-master.{0,1000}","offensive_tool_keyword","TartarusGate","TartarusGate Bypassing EDRs","T1055 - T1218.011 - T1027.009 - T1027 - T1105 - T1102.001","TA0005 - TA0001 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/trickster0/TartarusGate","1","1","N/A","N/A","10","6","579","72","2022-01-25T20:54:28Z","2021-11-27T19:46:30Z","60919" +"*tarunkant/Gopherus*",".{0,1000}tarunkant\/Gopherus.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","60920" +"*tastypepperoni/PPLBlade*",".{0,1000}tastypepperoni\/PPLBlade.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","1","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","61040" +"*tastypepperoni/RunAsWinTcb*",".{0,1000}tastypepperoni\/RunAsWinTcb.{0,1000}","offensive_tool_keyword","RunAsWinTcb","RunAsWinTcb uses an userland exploit to run a DLL with a protection level of WinTcb-Light.","T1073.002 - T1055.001 - T1055.002","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/tastypepperoni/RunAsWinTcb","1","1","N/A","N/A","10","2","132","17","2022-08-02T16:35:50Z","2022-07-29T16:36:06Z","61041" +"*TaurusOmar/psobf*",".{0,1000}TaurusOmar\/psobf.{0,1000}","offensive_tool_keyword","psobf","PowerShell Obfuscator","T1027 - T1059 - T1564","TA0005","N/A","N/A","Defense Evasion","https://github.com/TaurusOmar/psobf","1","1","N/A","N/A","6","2","171","30","2024-06-07T02:50:43Z","2024-06-07T01:45:12Z","61042" +"*TcbS4uImpersonationVariant.exe*",".{0,1000}TcbS4uImpersonationVariant\.exe.{0,1000}","offensive_tool_keyword","PrivFu","get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges","T1068 - T1134 - T1134.001 - T1078 - T1059","TA0004 - TA0009 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","KernelWritePoCs","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","61044" +"*tcpreplay*",".{0,1000}tcpreplay.{0,1000}","offensive_tool_keyword","tcpreplay","Tcpreplay is a suite of free Open Source utilities for editing and replaying previously captured network traffic. Originally designed to replay malicious traffic patterns to Intrusion Detection/Prevention Systems. it has seen many evolutions including capabilities to replay to web servers.","T1043 - T1049 - T1052 - T1095 - T1102 - T1124 - T1497 - T1557","TA0001 - TA0002 - TA0007 - TA0011","N/A","N/A","Exploitation tool","https://tcpreplay.appneta.com/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","61050" +"*tcpshell.py*",".{0,1000}tcpshell\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","61051" +"*tdragon6/Supershell*",".{0,1000}tdragon6\/Supershell.{0,1000}","offensive_tool_keyword","supershell","Supershell is a C2 remote control platform accessed through WEB services. By establishing a reverse SSH tunnel it obtains a fully interactive Shell and supports multi-platform architecture Payload","T1090 - T1059 - T1021","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/tdragon6/Supershell","1","1","N/A","N/A","10","10","1561","196","2023-09-26T13:53:55Z","2023-03-25T15:02:43Z","61052" +"*TeamFiltration-v*-linux-x86_64.zip*",".{0,1000}TeamFiltration\-v.{0,1000}\-linux\-x86_64\.zip.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","#linux","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","61060" +"*TeamFiltration-v*-macOS-arm64.zip*",".{0,1000}TeamFiltration\-v.{0,1000}\-macOS\-arm64\.zip.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","61061" +"*TeamFiltration-v*-macOS-x86_64.zip*",".{0,1000}TeamFiltration\-v.{0,1000}\-macOS\-x86_64\.zip.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","61062" +"*TeamFiltration-v*-win-x86_64.zip*",".{0,1000}TeamFiltration\-v.{0,1000}\-win\-x86_64\.zip.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","61063" +"*teams_dump-main.zip*",".{0,1000}teams_dump\-main\.zip.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1555 - T1003 - T1114","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","1","N/A","N/A","9","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","61065" +"*teamServer*ZoomAPI.py*",".{0,1000}teamServer.{0,1000}ZoomAPI\.py.{0,1000}","offensive_tool_keyword","ShadowForgeC2","ShadowForge Command & Control - Harnessing the power of Zoom API - control a compromised Windows Machine from your Zoom Chats.","T1071.001 - T1569.002 - T1059.001","TA0011 - TA0002 - TA0040","N/A","N/A","C2","https://github.com/0xEr3bus/ShadowForgeC2","1","1","N/A","N/A","10","10","47","7","2023-07-15T11:45:36Z","2023-07-13T11:49:36Z","61068" +"*TeamServer.C2Profiles*",".{0,1000}TeamServer\.C2Profiles.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","61069" +"*TeamServer.prop*",".{0,1000}TeamServer\.prop.{0,1000}","offensive_tool_keyword","cobaltstrike","CobaltStrike4.4 one-click deployment script Randomly generate passwords. keys. port numbers. certificates. etc.. to solve the problem that cs4.x cannot run on Linux and report errors","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/AlphabugX/csOnvps","1","1","N/A","N/A","10","10","286","63","2022-03-19T00:10:03Z","2021-12-02T02:10:42Z","61072" +"*TeamServer/Filters/InjectionFilters*",".{0,1000}TeamServer\/Filters\/InjectionFilters.{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","61073" +"*TeamServer/Pivots/*.*",".{0,1000}TeamServer\/Pivots\/.{0,1000}\..{0,1000}","offensive_tool_keyword","SharpC2","Command and Control Framework written in C#","T1071 - T1024 - T1105 - T1090 - T1091 - T1021 - T1573","TA0001 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/rasta-mouse/SharpC2","1","1","N/A","N/A","10","10","399","57","2023-07-27T12:25:54Z","2022-10-26T12:18:07Z","61074" +"*TeamsPhisher.git*",".{0,1000}TeamsPhisher\.git.{0,1000}","offensive_tool_keyword","teamsphisher","Send phishing messages and attachments to Microsoft Teams users","T1566.001 - T1566.002 - T1204.001","TA0001 - TA0005","N/A","Black Basta","Phishing","https://github.com/Octoberfest7/TeamsPhisher","1","1","N/A","N/A","N/A","10","1073","138","2024-06-19T21:41:55Z","2023-07-03T02:19:47Z","61076" +"*teamsphisher.log*",".{0,1000}teamsphisher\.log.{0,1000}","offensive_tool_keyword","teamsphisher","Send phishing messages and attachments to Microsoft Teams users","T1566.001 - T1566.002 - T1204.001","TA0001 - TA0005","N/A","Black Basta","Phishing","https://github.com/Octoberfest7/TeamsPhisher","1","1","N/A","N/A","N/A","10","1073","138","2024-06-19T21:41:55Z","2023-07-03T02:19:47Z","61077" +"*teamsphisher.py*",".{0,1000}teamsphisher\.py.{0,1000}","offensive_tool_keyword","teamsphisher","Send phishing messages and attachments to Microsoft Teams users","T1566.001 - T1566.002 - T1204.001","TA0001 - TA0005","N/A","Black Basta","Phishing","https://github.com/Octoberfest7/TeamsPhisher","1","1","N/A","N/A","N/A","10","1073","138","2024-06-19T21:41:55Z","2023-07-03T02:19:47Z","61078" +"*TeamsPhisher-main.zip*",".{0,1000}TeamsPhisher\-main\.zip.{0,1000}","offensive_tool_keyword","teamsphisher","Send phishing messages and attachments to Microsoft Teams users","T1566.001 - T1566.002 - T1204.001","TA0001 - TA0005","N/A","Black Basta","Phishing","https://github.com/Octoberfest7/TeamsPhisher","1","1","N/A","N/A","N/A","10","1073","138","2024-06-19T21:41:55Z","2023-07-03T02:19:47Z","61079" +"*teamstracker-main*",".{0,1000}teamstracker\-main.{0,1000}","offensive_tool_keyword","teamstracker","using graph proxy to monitor teams user presence","T1552.007 - T1052.001 - T1602","TA0003 - TA0005 - TA0007","N/A","N/A","Reconnaissance","https://github.com/nyxgeek/teamstracker","1","1","N/A","N/A","3","1","54","4","2024-06-27T11:57:35Z","2023-08-15T03:41:46Z","61080" +"*teamviewer_passwords.*",".{0,1000}teamviewer_passwords\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","61092" +"*teamviewer_passwords.rb*",".{0,1000}teamviewer_passwords\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","61093" +"*TeamViewerDecrypt.ps1*",".{0,1000}TeamViewerDecrypt\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","61102" +"*techspence/Adeleginator*",".{0,1000}techspence\/Adeleginator.{0,1000}","offensive_tool_keyword","Adeleginator","tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory","T1087 - T1136 - T1069","TA0007 - TA0003 - TA0004","N/A","N/A","Discovery","https://github.com/techspence/Adeleginator","1","1","N/A","N/A","6","2","179","18","2024-09-18T20:21:42Z","2024-03-04T03:44:52Z","61109" +"*techspence/ScriptSentry*",".{0,1000}techspence\/ScriptSentry.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","61110" +"*Teensypreter.ino*",".{0,1000}Teensypreter\.ino.{0,1000}","offensive_tool_keyword","Pateensy","payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy","T1056.001 - T1200 - T1036 - T1071","TA0002 - TA0005 - TA0011 - TA0006","N/A","N/A","Exploitation tool","https://github.com/screetsec/Pateensy","1","1","N/A","N/A","N/A","2","143","60","2017-01-26T12:02:56Z","2016-03-21T07:29:38Z","61113" +"*telegram2john.py*",".{0,1000}telegram2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","61117" +"*TelegramRAT-main*",".{0,1000}TelegramRAT\-main.{0,1000}","offensive_tool_keyword","TelegramRAT","Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions","T1071.001 - T1105 - T1027","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/machine1337/TelegramRAT","1","1","N/A","N/A","10","10","372","62","2024-01-23T12:05:59Z","2023-06-30T10:59:55Z","61118" +"*templates*HIPS_LIPS_processes.txt*",".{0,1000}templates.{0,1000}HIPS_LIPS_processes\.txt.{0,1000}","offensive_tool_keyword","CSExec","An alternative to *exec.py from impacket with some builtin tricks","T1059.001 - T1059.005 - T1071.001","TA0002","N/A","N/A","Lateral Movement","https://github.com/Metro-Holografix/CSExec.py","1","1","N/A","private github repo","10","","N/A","","","","61140" +"*templates*reflective_assembly_minified.ps1*",".{0,1000}templates.{0,1000}reflective_assembly_minified\.ps1.{0,1000}","offensive_tool_keyword","CSExec","An alternative to *exec.py from impacket with some builtin tricks","T1059.001 - T1059.005 - T1071.001","TA0002","N/A","N/A","Lateral Movement","https://github.com/Metro-Holografix/CSExec.py","1","1","N/A","private github repo","10","","N/A","","","","61141" +"*tenable.com/downloads/nessus*",".{0,1000}tenable\.com\/downloads\/nessus.{0,1000}","offensive_tool_keyword","nessus","Vulnerability scanner","T1046 - T1068 - T1190 - T1201 - T1222 - T1592","TA0001 - TA0002 - TA0007 - TA0011","N/A","N/A","Vulnerability Scanner","https://fr.tenable.com/products/nessus","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","61144" +"*test_beef_debugs_spec*",".{0,1000}test_beef_debugs_spec.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","61153" +"*test_ccache_fromKirbi*",".{0,1000}test_ccache_fromKirbi.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","61154" +"*test_crawler.py*",".{0,1000}test_crawler\.py.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","61155" +"*test_invoke_bof.x64.o*",".{0,1000}test_invoke_bof\.x64\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","Load any Beacon Object File using Powershell!","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/airbus-cert/Invoke-Bof","1","1","N/A","N/A","10","10","250","35","2021-12-09T15:10:41Z","2021-12-09T15:09:22Z","61156" +"*test_litefuzz.py*",".{0,1000}test_litefuzz\.py.{0,1000}","offensive_tool_keyword","litefuzz","A multi-platform fuzzer for poking at userland binaries and servers","T1587.004","TA0009","N/A","N/A","Exploitation tool","https://github.com/sec-tools/litefuzz","1","1","N/A","N/A","7","1","68","9","2024-09-15T22:43:02Z","2021-09-17T14:40:07Z","61157" +"*test_lsassy.*",".{0,1000}test_lsassy\..{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","61158" +"*test_mitm_initialization.py*",".{0,1000}test_mitm_initialization\.py.{0,1000}","offensive_tool_keyword","pyrdp","RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","T1550.002 - T1059.006 - T1071.001","TA0002 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/GoSecure/pyrdp","1","1","N/A","can also be used by blueteam as a honeypot","10","10","1663","257","2025-03-13T05:11:26Z","2018-09-07T19:17:41Z","61159" +"*test_nanodump_exe*",".{0,1000}test_nanodump_exe.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","61160" +"*test_pacu_update.py*",".{0,1000}test_pacu_update\.py.{0,1000}","offensive_tool_keyword","pacu","The AWS exploitation framework designed for testing the security of Amazon Web Services environments.","T1136.003 - T1190 - T1078.004","TA0006 - TA0001","N/A","Scattered Spider*","Framework","https://github.com/RhinoSecurityLabs/pacu","1","1","N/A","N/A","9","10","4651","731","2025-03-20T21:08:57Z","2018-06-13T21:58:59Z","61161" +"*test_tezos2john.py*",".{0,1000}test_tezos2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","61162" +"*TestConsoleApp_YSONET*",".{0,1000}TestConsoleApp_YSONET.{0,1000}","offensive_tool_keyword","ysoserial.net","Deserialization payload generator for a variety of .NET formatters","T1059.007 - T1027.002 - T1059.001","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/pwntester/ysoserial.net","1","1","N/A","N/A","10","10","3385","493","2024-12-23T20:59:47Z","2017-09-18T17:48:08Z","61164" +"*Test-DllExists*",".{0,1000}Test\-DllExists.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","61169" +"*tester@egress-assess.com*",".{0,1000}tester\@egress\-assess\.com.{0,1000}","offensive_tool_keyword","Egress-Assess","Egress-Assess is a tool used to test egress data detection capabilities","T1561 - T1041 - T1558 - T1071 - T1074","TA0010 - TA0011 - TA0008","N/A","Darkhotel - DUBNIUM - Putter Panda","Exploitation tool","https://github.com/FortyNorthSecurity/Egress-Assess","1","1","#email","can be used for data exfiltration simulation","8","7","647","144","2023-08-09T18:40:57Z","2014-12-10T13:39:11Z","61170" +"*tester12345678@gmail.com*",".{0,1000}tester12345678\@gmail\.com.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","#email","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","61171" +"*testHeapOverflow.*",".{0,1000}testHeapOverflow\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","61172" +"*Test-HijackableDll*",".{0,1000}Test\-HijackableDll.{0,1000}","offensive_tool_keyword","PrivescCheck","Privilege Escalation Enumeration Script for Windows","T1053 - T1088","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/itm4n/PrivescCheck","1","1","N/A","N/A","10","10","3230","460","2025-03-05T14:44:17Z","2020-01-16T12:28:10Z","61173" +"*testing.ssi.sh*",".{0,1000}testing\.ssi\.sh.{0,1000}","offensive_tool_keyword","sish","An open source serveo/ngrok alternative. HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH","T1572 - T1090.002","TA0010 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/antoniomika/sish","1","1","N/A","N/A","10","10","4203","325","2025-04-10T20:04:08Z","2019-02-15T15:36:23Z","61177" +"*TestMyPrivs.ps1*",".{0,1000}TestMyPrivs\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","61179" +"*Test-ServiceDaclPermission*",".{0,1000}Test\-ServiceDaclPermission.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","61182" +"*Test-ServiceDaclPermission*",".{0,1000}Test\-ServiceDaclPermission.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerUp.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","61183" +"*tevora-threat/SharpView/*",".{0,1000}tevora\-threat\/SharpView\/.{0,1000}","offensive_tool_keyword","SharpView","C# implementation of harmj0y's PowerView","T1018 - T1482 - T1087.002 - T1069.002","TA0007 - TA0003 - TA0001","N/A","Conti - APT29","Discovery","https://github.com/tevora-threat/SharpView/","1","1","N/A","N/A","10","10","1032","196","2024-03-22T16:34:09Z","2018-07-24T21:15:04Z","61186" +"*TexttoExe.ps1*",".{0,1000}TexttoExe\.ps1.{0,1000}","offensive_tool_keyword","nishang","Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security penetration testing and red teaming. Nishang is useful during all phases of penetration testing.","T1059.001 - T1086 - T1059.003 - T1105 - T1117 - T1059.005","TA0002 - TA0005 - TA0011 - TA0007 - TA0010","N/A","APT27 - APT32 - FANCY BEAR","Framework","https://github.com/samratashok/nishang","1","1","N/A","N/A","N/A","10","9144","2487","2024-04-25T19:39:44Z","2014-05-19T11:48:24Z","61188" +"*tezos2john.py*",".{0,1000}tezos2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","61189" +"*tgscrack.go*",".{0,1000}tgscrack\.go.{0,1000}","offensive_tool_keyword","ASREPRoast","Project that retrieves crackable hashes from KRB5 AS-REP responses for users without kerberoast preauthentication enabled. ","T1558.003","TA0006","N/A","N/A","Credential Access","https://github.com/HarmJ0y/ASREPRoast","1","1","N/A","N/A","N/A","3","202","58","2018-09-25T03:26:00Z","2017-01-14T21:07:57Z","61194" +"*tgsrepcrack.*",".{0,1000}tgsrepcrack\..{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Crack with TGSRepCrack","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","61195" +"*tgsrepcrack.py*",".{0,1000}tgsrepcrack\.py.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","1","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","61196" +"*TGSThief-main*",".{0,1000}TGSThief\-main.{0,1000}","offensive_tool_keyword","TGSThief","get the TGS of a user whose logon session is just present on the computer","T1558 - T1558.003 - T1078 - T1078.005","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/MzHmO/TGSThief","1","1","N/A","N/A","9","2","181","27","2023-07-25T05:30:39Z","2023-07-23T07:47:05Z","61197" +"*TGT_Monitor.ps1*",".{0,1000}TGT_Monitor\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","61200" +"*tgtdelegation.cna*",".{0,1000}tgtdelegation\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","61203" +"*tgtdelegation.x64*",".{0,1000}tgtdelegation\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","61204" +"*tgtdelegation.x86*",".{0,1000}tgtdelegation\.x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","61205" +"*th3rd/heroinn*",".{0,1000}th3rd\/heroinn.{0,1000}","offensive_tool_keyword","Heroinn","A cross platform C2/post-exploitation framework implementation by Rust.","T1027 - T1033 - T1055 - T1071 - T1082 - T1105 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/b23r0/Heroinn","1","1","N/A","N/A","10","10","672","215","2022-10-08T07:27:38Z","2015-05-16T14:54:19Z","61207" +"*TH3xACE/EDR-Test*",".{0,1000}TH3xACE\/EDR\-Test.{0,1000}","offensive_tool_keyword","EDR-Test","Automating EDR Testing with reference to MITRE ATTACK via Cobalt Strike [Purple Team].","T1027 - T1059 - T1105 - T1203 - T1078","TA0007 - TA0005 - TA0011 - TA0002","N/A","N/A","Exploitation tool","https://github.com/TH3xACE/EDR-Test","1","1","N/A","N/A","N/A","2","150","20","2023-03-27T11:39:32Z","2022-03-27T08:58:49Z","61208" +"*thc-hydra.git*",".{0,1000}thc\-hydra\.git.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","61214" +"*thc-hydra.git*",".{0,1000}thc\-hydra\.git.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","61215" +"*the-backdoor-factory-master*",".{0,1000}the\-backdoor\-factory\-master.{0,1000}","offensive_tool_keyword","the-backdoor-factory","Patch PE ELF Mach-O binaries with shellcode new version in development*","T1055.002 - T1055.004 - T1059.001","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/secretsquirrel/the-backdoor-factory","1","1","N/A","N/A","10","10","3369","788","2023-10-30T14:13:32Z","2013-05-30T01:04:24Z","61228" +"*TheCyb3rAlpha/BobTheSmuggler*",".{0,1000}TheCyb3rAlpha\/BobTheSmuggler.{0,1000}","offensive_tool_keyword","BobTheSmuggler","HTML SMUGGLING TOOL 6 allows you to create HTML files with embedded 7z/zip archives. The tool would compress your binary (EXE/DLL) into 7z/zip file format then XOR encrypt the archive and then hides inside PNG/GIF image file format (Image Polyglots)","T1027 - T1204.002 - T1140","TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/TheCyb3rAlpha/BobTheSmuggler","1","1","N/A","N/A","10","6","534","62","2025-03-10T07:32:22Z","2024-01-10T08:04:57Z","61230" +"*TheD1rkMtr/AMSI_patch*",".{0,1000}TheD1rkMtr\/AMSI_patch.{0,1000}","offensive_tool_keyword","AMSI_patch","Patching AmsiOpenSession by forcing an error branching","T1055 - T1055.001 - T1112","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/AMSI_patch","1","1","N/A","N/A","8","2","145","29","2023-08-02T02:27:00Z","2023-02-03T18:11:37Z","61231" +"*TheD1rkMtr/D1rkInject*",".{0,1000}TheD1rkMtr\/D1rkInject.{0,1000}","offensive_tool_keyword","D1rkInject","Threadless injection that loads a module into the target process and stomps it and reverting back memory protections and original memory state","T1055 - T1055.012 - T1055.002 - T1574.002","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/D1rkInject","1","1","N/A","N/A","9","2","177","32","2023-08-02T02:45:46Z","2023-08-02T02:13:55Z","61232" +"*TheD1rkMtr/DocPlz*",".{0,1000}TheD1rkMtr\/DocPlz.{0,1000}","offensive_tool_keyword","DocPlz","Documents Exfiltration and C2 project","T1105 - T1567 - T1071","TA0011 - TA0010 - TA0009","N/A","N/A","Data Exfiltration","https://github.com/TheD1rkMtr/DocPlz","1","1","N/A","N/A","10","2","145","30","2023-10-10T19:01:42Z","2023-10-02T20:49:22Z","61233" +"*TheD1rkMtr/GithubC2*",".{0,1000}TheD1rkMtr\/GithubC2.{0,1000}","offensive_tool_keyword","GithubC2","Github as C2","T1095 - T1071.001","TA0011","N/A","N/A","C2","https://github.com/TheD1rkMtr/GithubC2","1","1","N/A","N/A","10","10","136","37","2023-08-02T02:26:05Z","2023-02-15T00:50:59Z","61234" +"*TheD1rkMtr/HeapCrypt*",".{0,1000}TheD1rkMtr\/HeapCrypt.{0,1000}","offensive_tool_keyword","HeapCrypt","Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap","T1055.001 - T1027 - T1146","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/HeapCrypt","1","1","N/A","N/A","9","3","239","44","2023-08-02T02:24:42Z","2023-03-25T05:19:52Z","61235" +"*TheD1rkMtr/NTDLLReflection*",".{0,1000}TheD1rkMtr\/NTDLLReflection.{0,1000}","offensive_tool_keyword","NTDLLReflection","Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll and trigger exported APIs from the export table","T1055.012 - T1574.002 - T1027.001 - T1218.011","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/NTDLLReflection","1","1","N/A","N/A","9","3","293","45","2023-08-02T02:21:43Z","2023-02-03T17:12:33Z","61236" +"*TheD1rkMtr/Pspersist*",".{0,1000}TheD1rkMtr\/Pspersist.{0,1000}","offensive_tool_keyword","Pspersist","Dropping a powershell script at %HOMEPATH%\Documents\windowspowershell\ that contains the implant's path and whenever powershell process is created the implant will executed too.","T1546 - T1546.013 - T1053 - T1053.005 - T1037 - T1037.001","TA0003","N/A","N/A","Persistence","https://github.com/TheD1rkMtr/Pspersist","1","1","N/A","N/A","10","1","85","24","2023-08-02T02:27:29Z","2023-02-01T17:21:38Z","61237" +"*TheD1rkMtr/Shellcode-Hide*",".{0,1000}TheD1rkMtr\/Shellcode\-Hide.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","61238" +"*TheD1rkMtr/StackCrypt*",".{0,1000}TheD1rkMtr\/StackCrypt.{0,1000}","offensive_tool_keyword","StackCrypt","Create a new thread that will suspend every thread and encrypt its stack then going to sleep then decrypt the stacks and resume threads","T1027 - T1055.004 - T1486","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/StackCrypt","1","1","N/A","N/A","9","2","159","27","2023-08-02T02:25:12Z","2023-04-26T03:24:56Z","61239" +"*TheD1rkMtr/UnhookingPatch*",".{0,1000}TheD1rkMtr\/UnhookingPatch.{0,1000}","offensive_tool_keyword","UnhookingPatch","Bypass EDR Hooks by patching NT API stub and resolving SSNs and syscall instructions at runtime","T1055 - T1055.001 - T1070 - T1070.004 - T1211","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/UnhookingPatch","1","1","N/A","N/A","9","4","304","52","2023-08-02T02:25:38Z","2023-02-08T16:21:03Z","61240" +"*TheGejr/SpringShell*",".{0,1000}TheGejr\/SpringShell.{0,1000}","offensive_tool_keyword","Spring4Shell","Spring4Shell Proof Of Concept/Information CVE-2022-22965","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/TheGejr/SpringShell","1","1","N/A","N/A","N/A","2","127","84","2022-04-04T14:09:11Z","2022-03-30T17:05:46Z","61241" +"*thelinuxchoice/saycheese*",".{0,1000}thelinuxchoice\/saycheese.{0,1000}","offensive_tool_keyword","saycheese","Grab target's webcam shots by link","T1213 - T1071 - T1102 - T1123 - T1185 - T1200","TA0001 - TA0005 - TA0009 - TA0011","N/A","N/A","Phishing","https://github.com/hangetzzu/saycheese","1","1","#linux","N/A","9","10","1175","962","2024-06-18T23:39:41Z","2019-04-29T04:07:00Z","61244" +"*thelinuxchoice/tweetshell*",".{0,1000}thelinuxchoice\/tweetshell.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/SocialBox-Termux","1","1","#linux","N/A","7","10","3581","391","2024-09-02T19:15:22Z","2019-03-28T18:07:05Z","61245" +"*ThePorgs/Exegol-images*",".{0,1000}ThePorgs\/Exegol\-images.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","61247" +"*TheresAFewConors/MSSprinkler*",".{0,1000}TheresAFewConors\/MSSprinkler.{0,1000}","offensive_tool_keyword","MSSprinkler","password spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approach","T1110.003 - T1110.001","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/TheresAFewConors/MSSprinkler","1","1","N/A","N/A","9","1","74","7","2025-02-25T13:32:41Z","2024-09-15T09:54:53Z","61249" +"*TheRook/subbrute*",".{0,1000}TheRook\/subbrute.{0,1000}","offensive_tool_keyword","subbrute","A DNS meta-query spider that enumerates DNS records and subdomains.","T1071.001 - T1083 - T1590.001","TA0043 - TA0007?","N/A","ENERGETIC BEAR","Reconnaissance","https://github.com/TheRook/subbrute","1","1","N/A","N/A","5","10","3422","661","2022-01-13T09:25:59Z","2012-06-10T01:08:20Z","61250" +"*The-Viper-One/Invoke-PowerIncrease*",".{0,1000}The\-Viper\-One\/Invoke\-PowerIncrease.{0,1000}","offensive_tool_keyword","Invoke-PowerIncrease","binary padding to add junk data and change the on-disk representation of a file","T1480 - T1027","TA0005","N/A","N/A","Defense Evasion","https://github.com/The-Viper-One/Invoke-PowerIncrease","1","1","N/A","N/A","8","1","3","0","2024-08-01T18:10:02Z","2024-07-18T17:40:26Z","61251" +"*The-Viper-One/Invoke-RDPThief*",".{0,1000}The\-Viper\-One\/Invoke\-RDPThief.{0,1000}","offensive_tool_keyword","Invoke-RDPThief","perform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentials","T1055 - T1056 - T1071 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/The-Viper-One/Invoke-RDPThief","1","1","N/A","N/A","10","1","62","8","2025-01-21T20:12:33Z","2024-10-01T20:12:00Z","61252" +"*The-Viper-One/PsMapExec*",".{0,1000}The\-Viper\-One\/PsMapExec.{0,1000}","offensive_tool_keyword","PSMapExec","A PowerShell tool heavily inspired by the popular tool CrackMapExec. Far too often I find myself on engagements without access to Linux in order to make use of CrackMapExec.","T1059.001 - T1021.006 - T1110.001 - T1021.001 - T1021.004 - T1021.005 - T1021.003 - T1621","TA0002 - TA0011 - TA0005 - TA0006 - TA0007","N/A","N/A","Exploitation tool","https://github.com/The-Viper-One/PsMapExec","1","1","N/A","N/A","10","10","954","108","2025-03-11T14:38:50Z","2023-06-20T16:57:27Z","61254" +"*thewover/donut*",".{0,1000}thewover\/donut.{0,1000}","offensive_tool_keyword","donut","Donut is a position-independent code that enables in-memory execution of VBScript. JScript. EXE. DLL files and dotNET assemblies. A module created by Donut can either be staged from a HTTP server or embedded directly in the loader itself","T1071.001 - T1059 - T1059.001 - T1059.005 - T1059.006 - T1059.007 - T1562.001 - T1070 - T1105 - T1106 - T1027 - T1027.002 - T1057 - T1055 - T1620","TA0011 - TA0002 - TA0005 - TA0008 - TA0004 - TA0007 - TA0003 - TA0006 - TA0010","N/A","Indrik Spider","Exploitation tool","https://github.com/TheWover/donut","1","1","N/A","N/A","N/A","10","3882","667","2024-10-23T12:19:13Z","2019-03-27T23:24:44Z","61255" +"*thiagopeixoto/winsos-poc*",".{0,1000}thiagopeixoto\/winsos\-poc.{0,1000}","offensive_tool_keyword","winsos-poc","A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.","T1574.002","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/thiagopeixoto/winsos-poc","1","1","N/A","N/A","10","2","111","26","2024-03-10T22:15:50Z","2024-03-10T21:35:08Z","61256" +"*third_party/SharpGen*",".{0,1000}third_party\/SharpGen.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Python API","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/dcsync/pycobalt","1","1","N/A","N/A","10","10","299","56","2022-01-27T07:31:36Z","2018-10-28T00:35:38Z","61259" +"*third-party*winvnc*.dll*",".{0,1000}third\-party.{0,1000}winvnc.{0,1000}\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","61260" +"*ThisIsNotRat-main*",".{0,1000}ThisIsNotRat\-main.{0,1000}","offensive_tool_keyword","ThisIsNotRat","control windows computeur from telegram","T1098 - T1079 - T1105 - T1047 - T1059","TA0010 - TA0009 - TA0002 - TA0005 - TA0011","N/A","N/A","C2","https://github.com/RealBey/ThisIsNotRat","1","1","N/A","N/A","9","10","64","17","2023-09-10T07:39:38Z","2023-09-07T14:07:32Z","61267" +"*thoth-master.zip*",".{0,1000}thoth\-master\.zip.{0,1000}","offensive_tool_keyword","thoth","Automate recon for red team assessments.","T1190 - T1083 - T1018","TA0007 - TA0043 - TA0001","N/A","N/A","Reconnaissance","https://github.com/r1cksec/thoth","1","1","N/A","N/A","7","1","95","10","2025-02-03T12:05:52Z","2021-11-15T13:40:56Z","61269" +"*Thread_Hiijack_Inject_Load.*",".{0,1000}Thread_Hiijack_Inject_Load\..{0,1000}","offensive_tool_keyword","C2 related tools","A shellcode loader written using nim","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/aeverj/NimShellCodeLoader","1","1","N/A","N/A","10","10","656","121","2025-02-18T14:31:45Z","2021-01-19T15:57:01Z","61270" +"*ThreadlessInject.exe*",".{0,1000}ThreadlessInject\.exe.{0,1000}","offensive_tool_keyword","ThreadlessInject","Threadless Process Injection using remote function hooking.","T1055.012 - T1055.003 - T1177","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/CCob/ThreadlessInject","1","1","N/A","N/A","10","8","751","88","2024-09-04T17:11:58Z","2023-02-05T13:50:15Z","61274" +"*ThreadlessInject-master*",".{0,1000}ThreadlessInject\-master.{0,1000}","offensive_tool_keyword","ThreadlessInject","Threadless Process Injection using remote function hooking.","T1055.012 - T1055.003 - T1177","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/CCob/ThreadlessInject","1","1","N/A","N/A","10","8","751","88","2024-09-04T17:11:58Z","2023-02-05T13:50:15Z","61275" +"*ThreadStackSpoofer*",".{0,1000}ThreadStackSpoofer.{0,1000}","offensive_tool_keyword","C2 related tools","Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners and analysts.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/mgeeky/ThreadStackSpoofer","1","1","N/A","N/A","10","10","1109","180","2022-06-17T18:06:35Z","2021-09-26T22:48:17Z","61279" +"*ThreatCheck.csproj*",".{0,1000}ThreatCheck\.csproj.{0,1000}","offensive_tool_keyword","ThreatCheck","Identifies the bytes that Microsoft Defender / AMSI Consumer flags on","T1059.001 - T1059.005 - T1027.002 - T1070.004","TA0002 - TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/ThreatCheck","1","1","N/A","N/A","10","10","1185","143","2024-06-01T16:46:57Z","2020-10-08T11:22:26Z","61280" +"*ThreatCheck.csproj*",".{0,1000}ThreatCheck\.csproj.{0,1000}","offensive_tool_keyword","ThreatCheck","Identifies the bytes that Microsoft Defender / AMSI Consumer flags on","T1059.001 - T1059.005 - T1027.002 - T1070.004","TA0002 - TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/ThreatCheck","1","1","N/A","N/A","10","10","1185","143","2024-06-01T16:46:57Z","2020-10-08T11:22:26Z","61281" +"*ThreatCheck.exe*",".{0,1000}ThreatCheck\.exe.{0,1000}","offensive_tool_keyword","ThreatCheck","Identifies the bytes that Microsoft Defender / AMSI Consumer flags on","T1059.001 - T1059.005 - T1027.002 - T1070.004","TA0002 - TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/ThreatCheck","1","1","N/A","N/A","10","10","1185","143","2024-06-01T16:46:57Z","2020-10-08T11:22:26Z","61283" +"*ThreatCheck-master*",".{0,1000}ThreatCheck\-master.{0,1000}","offensive_tool_keyword","ThreatCheck","Identifies the bytes that Microsoft Defender / AMSI Consumer flags on","T1059.001 - T1059.005 - T1027.002 - T1070.004","TA0002 - TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/ThreatCheck","1","1","N/A","N/A","10","10","1185","143","2024-06-01T16:46:57Z","2020-10-08T11:22:26Z","61284" +"*threatexpress*malleable*",".{0,1000}threatexpress.{0,1000}malleable.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/malleable-c2","1","1","N/A","N/A","10","10","1676","299","2023-12-13T17:14:22Z","2018-08-14T14:19:43Z","61285" +"*threatexpress/cs2modrewrite*",".{0,1000}threatexpress\/cs2modrewrite.{0,1000}","offensive_tool_keyword","cobaltstrike","Convert Cobalt Strike profiles to modrewrite scripts","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/threatexpress/cs2modrewrite","1","1","N/A","N/A","10","10","599","117","2023-01-30T17:47:51Z","2017-06-06T14:53:57Z","61286" +"*threatpatrols/sshamble*",".{0,1000}threatpatrols\/sshamble.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","1","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","61287" +"*threeam7fj33rv5twe5ll7gcrp3kkyyt6ez5stssixnuwh4v3csxdwqd.onion*",".{0,1000}threeam7fj33rv5twe5ll7gcrp3kkyyt6ez5stssixnuwh4v3csxdwqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","61288" +"*throwback_x64.exe*",".{0,1000}throwback_x64\.exe.{0,1000}","offensive_tool_keyword","Throwback","HTTP/S Beaconing Implant","T1071.001 - T1102 - T1095 - T1573.001 - T1041","TA0011 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/silentbreaksec/Throwback","1","1","N/A","N/A","10","10","306","83","2017-08-25T16:49:12Z","2014-08-08T17:06:24Z","61290" +"*throwback_x86.exe*",".{0,1000}throwback_x86\.exe.{0,1000}","offensive_tool_keyword","Throwback","HTTP/S Beaconing Implant","T1071.001 - T1102 - T1095 - T1573.001 - T1041","TA0011 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/silentbreaksec/Throwback","1","1","N/A","N/A","10","10","306","83","2017-08-25T16:49:12Z","2014-08-08T17:06:24Z","61291" +"*throwBackDev.exe*",".{0,1000}throwBackDev\.exe.{0,1000}","offensive_tool_keyword","Throwback","HTTP/S Beaconing Implant","T1071.001 - T1102 - T1095 - T1573.001 - T1041","TA0011 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/silentbreaksec/Throwback","1","1","N/A","N/A","10","10","306","83","2017-08-25T16:49:12Z","2014-08-08T17:06:24Z","61292" +"*ThrowbackDLL.cpp*",".{0,1000}ThrowbackDLL\.cpp.{0,1000}","offensive_tool_keyword","Throwback","HTTP/S Beaconing Implant","T1071.001 - T1102 - T1095 - T1573.001 - T1041","TA0011 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/silentbreaksec/Throwback","1","1","N/A","N/A","10","10","306","83","2017-08-25T16:49:12Z","2014-08-08T17:06:24Z","61293" +"*ThrowbackDLL.exe*",".{0,1000}ThrowbackDLL\.exe.{0,1000}","offensive_tool_keyword","Throwback","HTTP/S Beaconing Implant","T1071.001 - T1102 - T1095 - T1573.001 - T1041","TA0011 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/silentbreaksec/Throwback","1","1","N/A","N/A","10","10","306","83","2017-08-25T16:49:12Z","2014-08-08T17:06:24Z","61294" +"*ThrowbackDLL.vcxproj*",".{0,1000}ThrowbackDLL\.vcxproj.{0,1000}","offensive_tool_keyword","Throwback","HTTP/S Beaconing Implant","T1071.001 - T1102 - T1095 - T1573.001 - T1041","TA0011 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/silentbreaksec/Throwback","1","1","N/A","N/A","10","10","306","83","2017-08-25T16:49:12Z","2014-08-08T17:06:24Z","61295" +"*ThunderDNS*.php*",".{0,1000}ThunderDNS.{0,1000}\.php.{0,1000}","offensive_tool_keyword","ThunderDNS","This tool can forward TCP traffic over DNS protocol","T1095 - T1071.004","TA0011 - TA0003","N/A","N/A","C2","https://github.com/fbkcs/ThunderDNS","1","1","N/A","N/A","10","10","410","63","2019-12-24T12:41:17Z","2018-12-04T15:18:47Z","61296" +"*ThunderDNS*.ps1*",".{0,1000}ThunderDNS.{0,1000}\.ps1.{0,1000}","offensive_tool_keyword","ThunderDNS","This tool can forward TCP traffic over DNS protocol","T1095 - T1071.004","TA0011 - TA0003","N/A","N/A","C2","https://github.com/fbkcs/ThunderDNS","1","1","N/A","N/A","10","10","410","63","2019-12-24T12:41:17Z","2018-12-04T15:18:47Z","61297" +"*ThunderDNS*.py*",".{0,1000}ThunderDNS.{0,1000}\.py.{0,1000}","offensive_tool_keyword","ThunderDNS","This tool can forward TCP traffic over DNS protocol","T1095 - T1071.004","TA0011 - TA0003","N/A","N/A","C2","https://github.com/fbkcs/ThunderDNS","1","1","N/A","N/A","10","10","410","63","2019-12-24T12:41:17Z","2018-12-04T15:18:47Z","61298" +"*ThunderDNS.git*",".{0,1000}ThunderDNS\.git.{0,1000}","offensive_tool_keyword","ThunderDNS","This tool can forward TCP traffic over DNS protocol","T1095 - T1071.004","TA0011 - TA0003","N/A","N/A","C2","https://github.com/fbkcs/ThunderDNS","1","1","N/A","N/A","10","10","410","63","2019-12-24T12:41:17Z","2018-12-04T15:18:47Z","61299" +"*ThunderFox.exe*",".{0,1000}ThunderFox\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","61300" +"*ThunderShell.git*",".{0,1000}ThunderShell\.git.{0,1000}","offensive_tool_keyword","ThunderShell","ThunderShell is a C# RAT that communicates via HTTP requests. All the network traffic is encrypted using a second layer of RC4 to avoid SSL interception and defeat network detection on the target system. RC4 is a weak cipher and is used to help obfuscate the traffic. HTTPS options should be used to provide integrity and strong encryption.","T1021.002 - T1573.002 - T1001.003","TA0008 - TA0011 - TA0040","N/A","LockBit","C2","https://github.com/Mr-Un1k0d3r/ThunderShell","1","1","N/A","N/A","10","10","779","223","2023-03-29T21:57:08Z","2017-09-12T01:11:29Z","61301" +"*ThunderShell.py*",".{0,1000}ThunderShell\.py.{0,1000}","offensive_tool_keyword","ThunderShell","ThunderShell is a C# RAT that communicates via HTTP requests. All the network traffic is encrypted using a second layer of RC4 to avoid SSL interception and defeat network detection on the target system. RC4 is a weak cipher and is used to help obfuscate the traffic. HTTPS options should be used to provide integrity and strong encryption.","T1021.002 - T1573.002 - T1001.003","TA0008 - TA0011 - TA0040","N/A","LockBit","C2","https://github.com/Mr-Un1k0d3r/ThunderShell","1","1","N/A","N/A","10","10","779","223","2023-03-29T21:57:08Z","2017-09-12T01:11:29Z","61302" +"*ThunderShell-master.zip*",".{0,1000}ThunderShell\-master\.zip.{0,1000}","offensive_tool_keyword","ThunderShell","ThunderShell is a C# RAT that communicates via HTTP requests. All the network traffic is encrypted using a second layer of RC4 to avoid SSL interception and defeat network detection on the target system. RC4 is a weak cipher and is used to help obfuscate the traffic. HTTPS options should be used to provide integrity and strong encryption.","T1021.002 - T1573.002 - T1001.003","TA0008 - TA0011 - TA0040","N/A","LockBit","C2","https://github.com/Mr-Un1k0d3r/ThunderShell","1","1","N/A","N/A","10","10","779","223","2023-03-29T21:57:08Z","2017-09-12T01:11:29Z","61303" +"*thw73ky2jphtcfrwoze5ddk3wbkc2t24r55guu3agwjchn3g6p755kyd.onion*",".{0,1000}thw73ky2jphtcfrwoze5ddk3wbkc2t24r55guu3agwjchn3g6p755kyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","61304" +"*thycotic_secretserver_dump.*",".{0,1000}thycotic_secretserver_dump\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","61305" +"*tiagorlampert/CHAOS*",".{0,1000}tiagorlampert\/CHAOS.{0,1000}","offensive_tool_keyword","chaos","CHAOS is a free and open-source Remote Administration Tool that allow generate binaries to control remote operating systems","T1105 - T1059 - T1021 - T1041 - T1569.002 - T1573","TA0002 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/tiagorlampert/CHAOS","1","1","N/A","N/A","10","10","2483","541","2024-10-26T18:02:45Z","2017-07-11T06:54:56Z","61306" +"*tiagorlampert/chaos:latest*",".{0,1000}tiagorlampert\/chaos\:latest.{0,1000}","offensive_tool_keyword","chaos","CHAOS is a free and open-source Remote Administration Tool that allow generate binaries to control remote operating systems","T1105 - T1059 - T1021 - T1041 - T1569.002 - T1573","TA0002 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/tiagorlampert/CHAOS","1","1","N/A","N/A","10","10","2483","541","2024-10-26T18:02:45Z","2017-07-11T06:54:56Z","61307" +"*tiagorlampert/sAINT*",".{0,1000}tiagorlampert\/sAINT.{0,1000}","offensive_tool_keyword","saint","(s)AINT is a Spyware Generator for Windows systems written in Java","T1056.001 - T1125 - T1123 - T1113 - T1105 - T1573.001","TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","C2","https://github.com/tiagorlampert/sAINT","1","1","N/A","N/A","10","10","712","311","2020-04-03T14:34:34Z","2017-11-18T18:43:25Z","61308" +"*tiagorlampert@gmail.com*",".{0,1000}tiagorlampert\@gmail\.com.{0,1000}","offensive_tool_keyword","chaos","CHAOS is a free and open-source Remote Administration Tool that allow generate binaries to control remote operating systems","T1105 - T1059 - T1021 - T1041 - T1569.002 - T1573","TA0002 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/tiagorlampert/CHAOS","1","1","#email","N/A","10","10","2483","541","2024-10-26T18:02:45Z","2017-07-11T06:54:56Z","61309" +"*Tib3rius/AutoRecon*",".{0,1000}Tib3rius\/AutoRecon.{0,1000}","offensive_tool_keyword","AutoRecon","AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.","T1046 - T1018 - T1518 - T1210","TA0007 - TA0003","N/A","N/A","Reconnaissance","https://github.com/Tib3rius/AutoRecon","1","1","N/A","N/A","8","10","5421","912","2025-04-09T18:12:41Z","2019-03-01T23:50:14Z","61310" +"*ticket.kirbi*",".{0,1000}ticket\.kirbi.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz Unconstrained delegation. With administrative privileges on a server with Unconstrained Delegation set we can dump the TGTs for other users that have a connection. If we do this successfully. we can impersonate the victim user towards any service in the domain.","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","61311" +"*ticketConverter.py*",".{0,1000}ticketConverter\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","61314" +"*ticketer.py*",".{0,1000}ticketer\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","61318" +"*ticketsplease.modules.*",".{0,1000}ticketsplease\.modules\..{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","61325" +"*TicketToHashcat.py*",".{0,1000}TicketToHashcat\.py.{0,1000}","offensive_tool_keyword","C2-Tool-Collection","A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques","T1055 - T1218 - T1059 - T1027","TA0002 - TA0003 - TA0008","N/A","N/A","C2","https://github.com/outflanknl/C2-Tool-Collection","1","1","N/A","N/A","10","10","1213","204","2023-10-27T14:16:17Z","2022-04-22T13:43:35Z","61326" +"*TicketToHashcat.py*",".{0,1000}TicketToHashcat\.py.{0,1000}","offensive_tool_keyword","mythic","Athena is a fully-featured cross-platform agent designed using the .NET 6. Athena is designed for Mythic 2.2 and newer","T1071.001 - T1071.002 - T1071.004 - T1119 - T1132 - T1030 - T1573.002 - T1008 - T1095 - T1572 - T1090.001 - T1090.002 - T1090.004","TA0011 - TA0009 - TA0010 - TA0005","N/A","Black Basta","C2","https://github.com/MythicAgents/Athena","1","1","N/A","N/A","10","10","198","40","2025-02-12T17:13:10Z","2022-01-24T20:44:38Z","61327" +"*Tiger-192.test-vectors.txt*",".{0,1000}Tiger\-192\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","61328" +"*tijme/kernel-mii*",".{0,1000}tijme\/kernel\-mii.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/tijme/kernel-mii","1","1","N/A","N/A","10","10","81","24","2023-05-07T18:38:29Z","2022-06-25T11:13:45Z","61331" +"*TikiLoader*Hollower*",".{0,1000}TikiLoader.{0,1000}Hollower.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","61332" +"*TikiLoader.*",".{0,1000}TikiLoader\..{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","61333" +"*TikiLoader.*",".{0,1000}TikiLoader\..{0,1000}","offensive_tool_keyword","cobaltstrike","EDR Evasion - Combination of SwampThing - TikiTorch","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rkervella/CarbonMonoxide","1","1","N/A","N/A","10","10","25","10","2020-05-28T10:40:20Z","2020-05-15T09:32:25Z","61334" +"*TikiLoader.dll*",".{0,1000}TikiLoader\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","61335" +"*TikiLoader.dll*",".{0,1000}TikiLoader\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","EDR Evasion - Combination of SwampThing - TikiTorch","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rkervella/CarbonMonoxide","1","1","N/A","N/A","10","10","25","10","2020-05-28T10:40:20Z","2020-05-15T09:32:25Z","61336" +"*TikiLoader.Injector*",".{0,1000}TikiLoader\.Injector.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","61337" +"*TikiSpawn.dll*",".{0,1000}TikiSpawn\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","61339" +"*TikiSpawn.exe*",".{0,1000}TikiSpawn\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","61340" +"*TikiSpawn.ps1*",".{0,1000}TikiSpawn\.ps1.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","61341" +"*TikiSpawnAs*",".{0,1000}TikiSpawnAs.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","61342" +"*TikiSpawnAsAdmin*",".{0,1000}TikiSpawnAsAdmin.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","61343" +"*TikiSpawnElevated*",".{0,1000}TikiSpawnElevated.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","61344" +"*TikiSpawnWOppid*",".{0,1000}TikiSpawnWOppid.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","61345" +"*TikiSpawnWppid*",".{0,1000}TikiSpawnWppid.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","61346" +"*TikiTorch.exe*",".{0,1000}TikiTorch\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","61347" +"*TikiVader.*",".{0,1000}TikiVader\..{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","61348" +"*timemachine_cmd_injection*",".{0,1000}timemachine_cmd_injection.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","61349" +"*timeroast.ps1*",".{0,1000}timeroast\.ps1.{0,1000}","offensive_tool_keyword","Timeroast","Timeroasting takes advantage of Windows NTP authentication mechanism allowing unauthenticated attackers to effectively request a password hash of any computer or trust account by sending an NTP request with that account's RID","T1558.003 - T1059.003 - T1078.004","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/SecuraBV/Timeroast","1","1","N/A","N/A","10","3","282","28","2023-07-04T07:12:57Z","2023-01-18T09:04:05Z","61350" +"*timeroast.py*",".{0,1000}timeroast\.py.{0,1000}","offensive_tool_keyword","Timeroast","Timeroasting takes advantage of Windows NTP authentication mechanism allowing unauthenticated attackers to effectively request a password hash of any computer or trust account by sending an NTP request with that account's RID","T1558.003 - T1059.003 - T1078.004","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/SecuraBV/Timeroast","1","1","N/A","N/A","10","3","282","28","2023-07-04T07:12:57Z","2023-01-18T09:04:05Z","61351" +"*timwhitez/Doge-Loader*",".{0,1000}timwhitez\/Doge\-Loader.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Shellcode Loader by Golang","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/timwhitez/Doge-Loader","1","1","N/A","N/A","10","10","280","57","2021-04-22T08:24:59Z","2020-10-09T04:47:54Z","61355" +"*tinyurl.com/haxshl*",".{0,1000}tinyurl\.com\/haxshl.{0,1000}","offensive_tool_keyword","hackshell","Make BASH stealthy and hacker friendly with lots of bash functions","T1070.003 - T1059.004 - T1564.001 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/hackerschoice/hackshell","1","1","N/A","N/A","9","3","251","28","2025-04-21T11:23:41Z","2024-07-16T15:56:11Z","61358" +"*Tkn_Access_Check.ps1*",".{0,1000}Tkn_Access_Check\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","61360" +"*tmenochet/PowerDump*",".{0,1000}tmenochet\/PowerDump.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","61373" +"*tmp.pico.sh*",".{0,1000}tmp\.pico\.sh.{0,1000}","offensive_tool_keyword","pico","hacker labs - open source and managed web services leveraging SSH","T1021.005 - T1078 - T1105 - T1109 - T1197 - T1213","TA0005 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/picosh/pico","1","1","N/A","N/A","10","10","1129","36","2025-04-22T17:33:17Z","2022-08-24T03:14:52Z","61378" +"*Tmprovider.dll*",".{0,1000}Tmprovider\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","61379" +"*to_powershell.ducky_script*",".{0,1000}to_powershell\.ducky_script.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","61385" +"*toggle_privileges.cna*",".{0,1000}toggle_privileges\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Syscall BOF to arbitrarily add/detract process token privilege rights.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/Toggle_Token_Privileges_BOF","1","1","N/A","N/A","10","10","55","20","2024-07-10T16:20:39Z","2021-09-14T17:47:08Z","61386" +"*toggle_privileges_bof.*",".{0,1000}toggle_privileges_bof\..{0,1000}","offensive_tool_keyword","cobaltstrike","Syscall BOF to arbitrarily add/detract process token privilege rights.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/Toggle_Token_Privileges_BOF","1","1","N/A","N/A","10","10","55","20","2024-07-10T16:20:39Z","2021-09-14T17:47:08Z","61387" +"*Toggle_Token_Privileges_BOF*",".{0,1000}Toggle_Token_Privileges_BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Syscall BOF to arbitrarily add/detract process token privilege rights.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/Toggle_Token_Privileges_BOF","1","1","N/A","N/A","10","10","55","20","2024-07-10T16:20:39Z","2021-09-14T17:47:08Z","61388" +"*ToggleWDigest*",".{0,1000}ToggleWDigest.{0,1000}","offensive_tool_keyword","cobaltstrike","A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/WdToggle","1","1","N/A","N/A","10","10","219","31","2023-05-03T19:51:43Z","2020-12-23T13:42:25Z","61389" +"*token::elevate*",".{0,1000}token\:\:elevate.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","61399" +"*token::whoami*",".{0,1000}token\:\:whoami.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","61400" +"*TokenDump.exe*",".{0,1000}TokenDump\.exe.{0,1000}","offensive_tool_keyword","PrivFu","Kernel mode WinDbg extension and PoCs for token privilege investigation.","T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001","TA0007 - TA0008 - TA0002 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","61401" +"*Token-Impersonation.ps1*",".{0,1000}Token\-Impersonation\.ps1.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","61408" +"*TokenKidnapping.cpp*",".{0,1000}TokenKidnapping\.cpp.{0,1000}","offensive_tool_keyword","MultiPotato","get SYSTEM via SeImpersonate privileges","T1548.002 - T1134.002","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S3cur3Th1sSh1t/MultiPotato","1","1","N/A","N/A","10","6","518","92","2021-11-20T16:20:23Z","2021-11-19T15:50:55Z","61409" +"*TokenKidnapping.cpp*",".{0,1000}TokenKidnapping\.cpp.{0,1000}","offensive_tool_keyword","RoguePotato","Windows Local Privilege Escalation from Service Account to System","T1055.002 - T1078.003 - T1070.004","TA0005 - TA0004 - TA0002","N/A","N/A","Privilege Escalation","https://github.com/antonioCoco/RoguePotato","1","1","N/A","N/A","10","10","1081","131","2021-01-09T20:43:07Z","2020-05-10T17:38:28Z","61410" +"*TokenKidnapping.exe*",".{0,1000}TokenKidnapping\.exe.{0,1000}","offensive_tool_keyword","MultiPotato","get SYSTEM via SeImpersonate privileges","T1548.002 - T1134.002","TA0004 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S3cur3Th1sSh1t/MultiPotato","1","1","N/A","N/A","10","6","518","92","2021-11-20T16:20:23Z","2021-11-19T15:50:55Z","61411" +"*TokenPlayer-v0.3.exe*",".{0,1000}TokenPlayer\-v0\.3\.exe.{0,1000}","offensive_tool_keyword","TokenPlayer","Manipulating and Abusing Windows Access Tokens","T1134 - T1484 - T1055 - T1078","TA0004 - TA0005 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S1ckB0y1337/TokenPlayer","1","1","N/A","N/A","10","3","274","45","2021-01-15T16:07:47Z","2020-08-20T23:05:49Z","61412" +"*TokenPlayer-v0.4.exe*",".{0,1000}TokenPlayer\-v0\.4\.exe.{0,1000}","offensive_tool_keyword","TokenPlayer","Manipulating and Abusing Windows Access Tokens","T1134 - T1484 - T1055 - T1078","TA0004 - TA0005 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S1ckB0y1337/TokenPlayer","1","1","N/A","N/A","10","3","274","45","2021-01-15T16:07:47Z","2020-08-20T23:05:49Z","61413" +"*TokenPlayer-v0.5.exe*",".{0,1000}TokenPlayer\-v0\.5\.exe.{0,1000}","offensive_tool_keyword","TokenPlayer","Manipulating and Abusing Windows Access Tokens","T1134 - T1484 - T1055 - T1078","TA0004 - TA0005 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S1ckB0y1337/TokenPlayer","1","1","N/A","N/A","10","3","274","45","2021-01-15T16:07:47Z","2020-08-20T23:05:49Z","61414" +"*TokenPlayer-v0.6.exe*",".{0,1000}TokenPlayer\-v0\.6\.exe.{0,1000}","offensive_tool_keyword","TokenPlayer","Manipulating and Abusing Windows Access Tokens","T1134 - T1484 - T1055 - T1078","TA0004 - TA0005 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S1ckB0y1337/TokenPlayer","1","1","N/A","N/A","10","3","274","45","2021-01-15T16:07:47Z","2020-08-20T23:05:49Z","61415" +"*TokenPlayer-v0.7.exe*",".{0,1000}TokenPlayer\-v0\.7\.exe.{0,1000}","offensive_tool_keyword","TokenPlayer","Manipulating and Abusing Windows Access Tokens","T1134 - T1484 - T1055 - T1078","TA0004 - TA0005 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S1ckB0y1337/TokenPlayer","1","1","N/A","N/A","10","3","274","45","2021-01-15T16:07:47Z","2020-08-20T23:05:49Z","61416" +"*TokenPlayer-v0.8.exe*",".{0,1000}TokenPlayer\-v0\.8\.exe.{0,1000}","offensive_tool_keyword","TokenPlayer","Manipulating and Abusing Windows Access Tokens","T1134 - T1484 - T1055 - T1078","TA0004 - TA0005 - TA0006","N/A","N/A","Privilege Escalation","https://github.com/S1ckB0y1337/TokenPlayer","1","1","N/A","N/A","10","3","274","45","2021-01-15T16:07:47Z","2020-08-20T23:05:49Z","61417" +"*tokenprivs.cpp*",".{0,1000}tokenprivs\.cpp.{0,1000}","offensive_tool_keyword","elevationstation","elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","61418" +"*tokenprivs.exe*",".{0,1000}tokenprivs\.exe.{0,1000}","offensive_tool_keyword","elevationstation","elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","61419" +"*TokenStealer.cpp*",".{0,1000}TokenStealer\.cpp.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","1","N/A","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","61421" +"*TokenStealer.exe*",".{0,1000}TokenStealer\.exe.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","1","N/A","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","61422" +"*TokenStealer.sln*",".{0,1000}TokenStealer\.sln.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","1","N/A","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","61423" +"*TokenStealer.vcxproj*",".{0,1000}TokenStealer\.vcxproj.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","1","N/A","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","61424" +"*TokenStealer-master*",".{0,1000}TokenStealer\-master.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","1","N/A","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","61425" +"*TokenStealing.cs*",".{0,1000}TokenStealing\.cs.{0,1000}","offensive_tool_keyword","PrivFu","Kernel mode WinDbg extension and PoCs for token privilege investigation.","T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001","TA0007 - TA0008 - TA0002 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","61426" +"*TokenStealing.exe*",".{0,1000}TokenStealing\.exe.{0,1000}","offensive_tool_keyword","PrivFu","Kernel mode WinDbg extension and PoCs for token privilege investigation.","T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001","TA0007 - TA0008 - TA0002 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","61427" +"*TokenStomp.exe*",".{0,1000}TokenStomp\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","61428" +"*TokenStripBOF/src*",".{0,1000}TokenStripBOF\/src.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File to delete token privileges and lower the integrity level to untrusted for a specified process","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/nick-frischkorn/TokenStripBOF","1","1","N/A","N/A","10","10","44","7","2022-06-15T21:29:24Z","2022-06-15T02:13:13Z","61429" +"*TokenTactics.psd1*",".{0,1000}TokenTactics\.psd1.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","61430" +"*TokenTactics.psd1*",".{0,1000}TokenTactics\.psd1.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","1","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","61431" +"*TokenTactics.psm1*",".{0,1000}TokenTactics\.psm1.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","61432" +"*TokenTactics.psm1*",".{0,1000}TokenTactics\.psm1.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","1","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","61433" +"*TokenTactics-main.zip*",".{0,1000}TokenTactics\-main\.zip.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","61434" +"*TokenUniverse.dproj*",".{0,1000}TokenUniverse\.dproj.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","1","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","61435" +"*TokenUniverse.exe*",".{0,1000}TokenUniverse\.exe.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","1","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","61436" +"*TokenUniverse-master.zip*",".{0,1000}TokenUniverse\-master\.zip.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","1","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","61437" +"*TokenUniverse-x64.zip*",".{0,1000}TokenUniverse\-x64\.zip.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","1","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","61438" +"*TokenUniverse-x86.zip*",".{0,1000}TokenUniverse\-x86\.zip.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","1","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","61439" +"*Tokenvator*.exe*",".{0,1000}Tokenvator.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","Tokenvator","A tool to elevate privilege with Windows Tokens","T1134 - T1078","TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/0xbadjuju/Tokenvator","1","1","N/A","N/A","N/A","10","1038","201","2023-10-06T13:17:05Z","2017-12-08T01:29:11Z","61441" +"*Tokenvator.csproj*",".{0,1000}Tokenvator\.csproj.{0,1000}","offensive_tool_keyword","Tokenvator","A tool to elevate privilege with Windows Tokens","T1134 - T1078","TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/0xbadjuju/Tokenvator","1","1","N/A","N/A","N/A","10","1038","201","2023-10-06T13:17:05Z","2017-12-08T01:29:11Z","61442" +"*Tokenvator.exe*",".{0,1000}Tokenvator\.exe.{0,1000}","offensive_tool_keyword","Tokenvator","A tool to elevate privilege with Windows Tokens","T1134 - T1078","TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/0xbadjuju/Tokenvator","1","1","N/A","N/A","N/A","10","1038","201","2023-10-06T13:17:05Z","2017-12-08T01:29:11Z","61443" +"*Tokenvator.git*",".{0,1000}Tokenvator\.git.{0,1000}","offensive_tool_keyword","Tokenvator","A tool to elevate privilege with Windows Tokens","T1134 - T1078","TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/0xbadjuju/Tokenvator","1","1","N/A","N/A","N/A","10","1038","201","2023-10-06T13:17:05Z","2017-12-08T01:29:11Z","61444" +"*Tokenvator.pdb*",".{0,1000}Tokenvator\.pdb.{0,1000}","offensive_tool_keyword","Tokenvator","A tool to elevate privilege with Windows Tokens","T1134 - T1078","TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/0xbadjuju/Tokenvator","1","1","N/A","N/A","N/A","10","1038","201","2023-10-06T13:17:05Z","2017-12-08T01:29:11Z","61445" +"*Tokenvator.Plugins*",".{0,1000}Tokenvator\.Plugins.{0,1000}","offensive_tool_keyword","Tokenvator","A tool to elevate privilege with Windows Tokens","T1134 - T1078","TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/0xbadjuju/Tokenvator","1","1","N/A","N/A","N/A","10","1038","201","2023-10-06T13:17:05Z","2017-12-08T01:29:11Z","61446" +"*Tokenvator.Resources*",".{0,1000}Tokenvator\.Resources.{0,1000}","offensive_tool_keyword","Tokenvator","A tool to elevate privilege with Windows Tokens","T1134 - T1078","TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/0xbadjuju/Tokenvator","1","1","N/A","N/A","N/A","10","1038","201","2023-10-06T13:17:05Z","2017-12-08T01:29:11Z","61447" +"*Tokenvator.sln*",".{0,1000}Tokenvator\.sln.{0,1000}","offensive_tool_keyword","Tokenvator","A tool to elevate privilege with Windows Tokens","T1134 - T1078","TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/0xbadjuju/Tokenvator","1","1","N/A","N/A","N/A","10","1038","201","2023-10-06T13:17:05Z","2017-12-08T01:29:11Z","61448" +"*Tokenvator/MonkeyWorks*",".{0,1000}Tokenvator\/MonkeyWorks.{0,1000}","offensive_tool_keyword","Tokenvator","A tool to elevate privilege with Windows Tokens","T1134 - T1078","TA0003 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/0xbadjuju/Tokenvator","1","1","N/A","N/A","N/A","10","1038","201","2023-10-06T13:17:05Z","2017-12-08T01:29:11Z","61449" +"*token-vault.cna*",".{0,1000}token\-vault\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","In-memory token vault BOF for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Henkru/cs-token-vault","1","1","N/A","N/A","10","10","142","25","2022-08-18T11:02:42Z","2022-07-29T17:50:10Z","61451" +"*token-vault.x64.o*",".{0,1000}token\-vault\.x64\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","In-memory token vault BOF for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Henkru/cs-token-vault","1","1","N/A","N/A","10","10","142","25","2022-08-18T11:02:42Z","2022-07-29T17:50:10Z","61452" +"*token-vault.x86.o*",".{0,1000}token\-vault\.x86\.o.{0,1000}","offensive_tool_keyword","cobaltstrike","In-memory token vault BOF for Cobalt Strike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Henkru/cs-token-vault","1","1","N/A","N/A","10","10","142","25","2022-08-18T11:02:42Z","2022-07-29T17:50:10Z","61453" +"*TokenViewer.exe*",".{0,1000}TokenViewer\.exe.{0,1000}","offensive_tool_keyword","PrivFu","Kernel mode WinDbg extension and PoCs for token privilege investigation.","T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001","TA0007 - TA0008 - TA0002 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu","1","1","N/A","N/A","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","61454" +"*tokyoneon/Chimera*",".{0,1000}tokyoneon\/Chimera.{0,1000}","offensive_tool_keyword","chimera","Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.","T1027.002 - T1059.001 - T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/tokyoneon/Chimera/","1","1","N/A","N/A","10","10","1493","252","2021-11-09T12:39:59Z","2020-09-01T07:42:22Z","61455" +"*tomcarver16/ADSearch*",".{0,1000}tomcarver16\/ADSearch.{0,1000}","offensive_tool_keyword","adsearch","A tool to help query AD via the LDAP protocol","T1087 - T1069.002 - T1018","TA0003 - TA0002 - TA0007","N/A","N/A","Reconnaissance","https://github.com/tomcarver16/ADSearch","1","1","N/A","N/A","N/A","6","536","57","2024-09-25T16:13:13Z","2020-06-17T22:21:41Z","61456" +"*tomcat_mgr_default_userpass.txt*",".{0,1000}tomcat_mgr_default_userpass\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","61457" +"*tomcat-rootprivesc-deb.sh*",".{0,1000}tomcat\-rootprivesc\-deb\.sh.{0,1000}","offensive_tool_keyword","CDK","CDK is an open-sourced container penetration toolkit","T1610 - T1611 - T1203 - T1059.004 - T1564.004","TA0001 - TA0002 - TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/cdk-team/CDK","1","1","#linux","N/A","9","10","4164","566","2025-03-08T14:00:06Z","2020-11-05T09:18:51Z","61458" +"*tomcat-rootprivesc-deb.sh*",".{0,1000}tomcat\-rootprivesc\-deb\.sh.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","61459" +"*Tool-PassView*",".{0,1000}Tool\-PassView.{0,1000}","offensive_tool_keyword","Tool-PassView","Password recovery or exploitation","T1003 - T1021 - T1056 - T1110 - T1212","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/password_recovery_tools.html","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","61464" +"*Top109Million-probable-v2.txt*",".{0,1000}Top109Million\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61469" +"*Top12Thousand-probable-v2.txt*",".{0,1000}Top12Thousand\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61470" +"*Top1575-probable-v2.txt*",".{0,1000}Top1575\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61471" +"*Top1pt6Million-probable-v2.txt*",".{0,1000}Top1pt6Million\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61472" +"*Top207-probable-v2.txt*",".{0,1000}Top207\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61473" +"*Top29Million-probable-v2.txt*",".{0,1000}Top29Million\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61474" +"*Top2Billion-probable-v2.txt*",".{0,1000}Top2Billion\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61475" +"*Top304Thousand-probable-v2.txt*",".{0,1000}Top304Thousand\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61476" +"*Top353Million-probable-v2.txt*",".{0,1000}Top353Million\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61477" +"*topotam.exe*",".{0,1000}topotam\.exe.{0,1000}","offensive_tool_keyword","petipotam","PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.","T1557.001 - T1021","TA0008","N/A","N/A","Lateral Movement","https://github.com/topotam/PetitPotam","1","1","N/A","N/A","10","10","1944","290","2024-08-15T03:52:26Z","2021-07-18T18:19:54Z","61478" +"*topotam/PetitPotam*",".{0,1000}topotam\/PetitPotam.{0,1000}","offensive_tool_keyword","petipotam","PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.","T1557.001 - T1021","TA0008","N/A","N/A","Lateral Movement","https://github.com/topotam/PetitPotam","1","1","N/A","N/A","10","10","1944","290","2024-08-15T03:52:26Z","2021-07-18T18:19:54Z","61479" +"*tor_hiddenservices.rb*",".{0,1000}tor_hiddenservices\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","61484" +"*tor_services.py*",".{0,1000}tor_services\.py.{0,1000}","offensive_tool_keyword","tor","Tor is a python based module for using tor proxy/network services on windows - osx - linux with just one click","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0005 - TA0010 - TA0011","N/A","Dispossessor - APT28 - APT29 - Leviathan","Defense Evasion","https://github.com/r0oth3x49/Tor","1","1","#linux","N/A","N/A","2","156","42","2018-04-21T10:55:00Z","2016-09-22T11:22:33Z","61485" +"*tor2web/Tor2web*",".{0,1000}tor2web\/Tor2web.{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","61491" +"*tor2web-cert.pem*",".{0,1000}tor2web\-cert\.pem.{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","61493" +"*tor2web-default.conf*",".{0,1000}tor2web\-default\.conf.{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","61494" +"*tor2web-dh.pem*",".{0,1000}tor2web\-dh\.pem.{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","61495" +"*tor2web-intermediate.pem*",".{0,1000}tor2web\-intermediate\.pem.{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","61498" +"*tor2web-key.pem*",".{0,1000}tor2web\-key\.pem.{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","61499" +"*TORAnonymizer.ps1*",".{0,1000}TORAnonymizer\.ps1.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","61501" +"*TorBrowser-*macos_ALL.dmg*",".{0,1000}TorBrowser\-.{0,1000}macos_ALL\.dmg.{0,1000}","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","#macos","N/A","9","10","N/A","N/A","N/A","N/A","61502" +"*torbrowser-install-*_ALL.exe",".{0,1000}torbrowser\-install\-.{0,1000}_ALL\.exe","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","61503" +"*torbrowser-install-win*.exe*",".{0,1000}torbrowser\-install\-win.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","61504" +"*torbrowser-install-win64*",".{0,1000}torbrowser\-install\-win64.{0,1000}","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","61505" +"*tor-browser-linux*_ALL.tar.xz*",".{0,1000}tor\-browser\-linux.{0,1000}_ALL\.tar\.xz.{0,1000}","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","#linux","N/A","9","10","N/A","N/A","N/A","N/A","61506" +"*torpastezr7464pevuvdjisbvaf4yqi4n7sgz7lkwgqwxznwy5duj4ad.onion*",".{0,1000}torpastezr7464pevuvdjisbvaf4yqi4n7sgz7lkwgqwxznwy5duj4ad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","61514" +"*torproject.org/dist/torbrowser/*.*",".{0,1000}torproject\.org\/dist\/torbrowser\/.{0,1000}\..{0,1000}","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - BlackBasta","Data Exfiltration","torproject.org","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","61515" +"*torproject.org/download/download/*",".{0,1000}torproject\.org\/download\/download\/.{0,1000}","offensive_tool_keyword","torproject","Browse Privately. Explore Freely. Defend yourself against tracking and surveillance. Circumvent censorship.","T1090 - T1134 - T1188 - T1307 - T1497 - T1560","TA0001 - TA0002 - TA0005 - TA0011","N/A","Dispossessor - Black Basta","Data Exfiltration","torproject.org","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","61516" +"*--tor-proxy*--pwndb*",".{0,1000}\-\-tor\-proxy.{0,1000}\-\-pwndb.{0,1000}","offensive_tool_keyword","SocialPwned","SocialPwned is an OSINT tool that allows to get the emails. from a target. published in social networks like Instagram. Linkedin and Twitter to find the possible credential leaks in PwnDB or Dehashed and obtain Google account information via GHunt.","T1596","TA0002","N/A","N/A","Reconnaissance","https://github.com/MrTuxx/SocialPwned","1","1","N/A","N/A","N/A","10","1139","106","2025-01-28T19:07:29Z","2020-04-07T22:25:38Z","61517" +"*totally-not-meterpreter.7z*",".{0,1000}totally\-not\-meterpreter\.7z.{0,1000}","offensive_tool_keyword","dnskire","A tool for file infiltration over DNS","T1071.004 - T1071.001 - T1048","TA0010 - TA0005 - TA0011","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","Data Exfiltration","https://github.com/0xtosh/dnskire","1","1","N/A","N/A","7","1","17","0","2023-12-07T21:42:34Z","2022-09-10T17:56:30Z","61523" +"*tothi/dll-hijack-by-proxying*",".{0,1000}tothi\/dll\-hijack\-by\-proxying.{0,1000}","offensive_tool_keyword","dll-hijack-by-proxying","Exploiting DLL Hijacking by DLL Proxying Super Easily","T1174 - T1574.007","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tothi/dll-hijack-by-proxying","1","1","N/A","N/A","7","5","498","103","2023-07-09T22:11:34Z","2020-07-08T18:11:17Z","61524" +"*trailofbits/onesixtyone*",".{0,1000}trailofbits\/onesixtyone.{0,1000}","offensive_tool_keyword","onesixtyone","Fast SNMP scanner. onesixtyone takes a different approach to SNMP scanning. It takes advantage of the fact that SNMP is a connectionless protocol and sends all SNMP requests as fast as it can. Then the scanner waits for responses to come back and logs them in a fashion similar to Nmap ping sweeps","T1046 - T1018","TA0007 - TA0005","N/A","N/A","Reconnaissance","https://github.com/trailofbits/onesixtyone","1","1","N/A","N/A","N/A","6","594","90","2023-04-11T18:21:38Z","2014-02-07T17:02:49Z","61533" +"*trainr3kt/MemReader_BoF*",".{0,1000}trainr3kt\/MemReader_BoF.{0,1000}","offensive_tool_keyword","cobaltstrike","MemReader Beacon Object File will allow you to search and extract specific strings from a target process memory and return what is found to the beacon output","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trainr3kt/MemReader_BoF","1","1","N/A","N/A","10","10","46","6","2023-12-05T23:25:22Z","2021-04-21T20:51:25Z","61534" +"*trainr3kt/Readfile_BoF*",".{0,1000}trainr3kt\/Readfile_BoF.{0,1000}","offensive_tool_keyword","cobaltstrike","MemReader Beacon Object File will allow you to search and extract specific strings from a target process memory and return what is found to the beacon output","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trainr3kt/Readfile_BoF","1","1","N/A","N/A","10","10","21","5","2022-06-21T04:50:39Z","2021-04-01T03:47:56Z","61535" +"*translate.google.com/translate?&anno=2&u=$c2server*",".{0,1000}translate\.google\.com\/translate\?\&anno\=2\&u\=\$c2server.{0,1000}","offensive_tool_keyword","BabyShark","This is a basic C2 generic server written in Python and Flask.","T1547.001 - T1059.003 - T1132.001 - T1140 - T1083 - T1070.004 - T1105 - T1056.001 - T1057 - T1012 - T1053.005 - T1218.005 - T1082 - T1016 - T1033","TA0006 - TA0011 - TA0040","N/A","Kimsuky","C2","https://github.com/UnkL4b/BabyShark","1","1","N/A","N/A","10","10","189","30","2021-07-03T00:18:18Z","2020-06-02T12:27:20Z","61544" +"*tree_connect_andx_request*",".{0,1000}tree_connect_andx_request.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Exploit-EternalBlue.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","61545" +"*Trevohack/DynastyPersist*",".{0,1000}Trevohack\/DynastyPersist.{0,1000}","offensive_tool_keyword","DynastyPersist","Linux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd Service","T1055 - T1037 - T1078 - T1547 - T1546 - T1556","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/Trevohack/DynastyPersist","1","1","#linux","N/A","9","2","153","17","2024-05-16T05:19:48Z","2023-08-13T15:05:42Z","61547" +"*TrevorC2*",".{0,1000}TrevorC2.{0,1000}","offensive_tool_keyword","trevorc2","Command and Control via Legitimate Behavior over HTTP","T1105 - T1071 - T1070","TA0011","N/A","N/A","C2","https://github.com/trustedsec/trevorc2","1","1","N/A","N/A","10","10","1271","271","2022-01-31T20:16:24Z","2017-10-27T15:59:28Z","61548" +"*trevorsaudi/Mshikaki*",".{0,1000}trevorsaudi\/Mshikaki.{0,1000}","offensive_tool_keyword","Mshikaki","A shellcode injection tool capable of bypassing AMSI. Features the QueueUserAPC() injection technique and supports XOR encryption","T1055.012 - T1116 - T1027.002 - T1562.001","TA0005 - TA0006 - TA0040 - TA0002","N/A","N/A","Exploitation tool","https://github.com/trevorsaudi/Mshikaki","1","1","N/A","N/A","9","2","135","25","2023-11-26T18:13:40Z","2023-09-03T16:35:50Z","61551" +"*trevorspray.cli*",".{0,1000}trevorspray\.cli.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61555" +"*trevorspray.py*",".{0,1000}trevorspray\.py.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61558" +"*TREVORspray-dev*",".{0,1000}TREVORspray\-dev.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61562" +"*TREVORspray-master*",".{0,1000}TREVORspray\-master.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61563" +"*TREVORspray-trevorspray*",".{0,1000}TREVORspray\-trevorspray.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61564" +"*tricks01.hwtxt*",".{0,1000}tricks01\.hwtxt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","61565" +"*trickster0/EDR_Detector*",".{0,1000}trickster0\/EDR_Detector.{0,1000}","offensive_tool_keyword","EDR_Detector","detect EDR agents on a machine","T1518.001 - T1063","TA0007 - TA0009","N/A","N/A","Collection","https://github.com/trickster0/EDR_Detector","1","1","N/A","N/A","7","1","93","14","2021-11-05T08:10:05Z","2019-08-24T20:50:09Z","61566" +"*trickster0/Enyx*",".{0,1000}trickster0\/Enyx.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","61567" +"*trickster0/NamelessC2*",".{0,1000}trickster0\/NamelessC2.{0,1000}","offensive_tool_keyword","NamelessC2","A C2 with all its components written in Rust","T1102 - T1573.001 - T1027 - T1219 - T1205","TA0011 - TA0003 - TA0005 - TA0010","N/A","N/A","C2","https://github.com/trickster0/NamelessC2","1","1","N/A","N/A","10","10","266","33","2024-09-26T21:21:20Z","2024-09-26T21:06:37Z","61568" +"*trickster0/TartarusGate*",".{0,1000}trickster0\/TartarusGate.{0,1000}","offensive_tool_keyword","TartarusGate","TartarusGate Bypassing EDRs","T1055 - T1218.011 - T1027.009 - T1027 - T1105 - T1102.001","TA0005 - TA0001 - TA0002 - TA0009","N/A","N/A","Defense Evasion","https://github.com/trickster0/TartarusGate","1","1","N/A","N/A","10","6","579","72","2022-01-25T20:54:28Z","2021-11-27T19:46:30Z","61569" +"*TR-SLimey/wraith-RAT*",".{0,1000}TR\-SLimey\/wraith\-RAT.{0,1000}","offensive_tool_keyword","wraith","A free and open-source, modular Remote Administration Tool (RAT) / Payload Dropper written in Go(lang) with a flexible command and control (C2) system.","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/wraith-labs/wraith","1","1","N/A","N/A","10","10","223","49","2023-12-03T22:16:27Z","2020-01-23T17:09:23Z","61639" +"*truecrypt2john.py*",".{0,1000}truecrypt2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","61641" +"*truerustyy/wcreddump*",".{0,1000}truerustyy\/wcreddump.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","1","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","61642" +"*trufflesecurity/trufflehog*",".{0,1000}trufflesecurity\/trufflehog.{0,1000}","offensive_tool_keyword","truffleHog","Searches through git repositories for secrets. digging deep into commit history and branches. This is effective at finding secrets accidentally committed.","T1552 - T1596 - T1083","TA0009 - TA0005 - TA0002","N/A","Scattered Spider*","Reconnaissance","https://github.com/dxa4481/truffleHog","1","1","#linux","N/A","6","10","18812","1839","2025-04-22T17:32:40Z","2016-12-31T05:08:12Z","61651" +"*TruffleSnout.exe*",".{0,1000}TruffleSnout\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","61652" +"*TrustedPathDLLHijack*",".{0,1000}TrustedPathDLLHijack.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of UAC Bypass Techniques Weaponized as BOFs","T1548.002 - T1203 - T1055 - T1134.002","TA0005 - TA0004","N/A","N/A","Privilege Escalation","https://github.com/icyguider/UAC-BOF-Bonanza","1","1","N/A","N/A","10","6","500","65","2024-02-21T22:07:54Z","2024-02-16T14:47:13Z","61657" +"*TrustedPath-UACBypass-BOF*",".{0,1000}TrustedPath\-UACBypass\-BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike beacon object file implementation for trusted path UAC bypass. The target executable will be called without involving cmd.exe by using DCOM object.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/TrustedPath-UACBypass-BOF","1","1","N/A","N/A","10","10","133","40","2021-08-16T07:49:55Z","2021-08-07T03:40:33Z","61658" +"*trustedsec/DitExplorer*",".{0,1000}trustedsec\/DitExplorer.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","1","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","61659" +"*trustedsec/social-engineer-toolkit*",".{0,1000}trustedsec\/social\-engineer\-toolkit.{0,1000}","offensive_tool_keyword","social-engineer-toolkit","The Social-Engineer Toolkit is an open-source penetration testing framework designed for social engineering. SET has a number of custom attack vectors that allow you to make a believable attack quickly. SET is a product of TrustedSec","T1566 - T1598","TA0001 - TA0002 - TA0003 - TA0009","N/A","N/A","Exploitation tool","https://github.com/trustedsec/social-engineer-toolkit","1","1","N/A","N/A","N/A","10","11798","2922","2024-10-21T15:46:18Z","2012-12-31T22:01:33Z","61660" +"*trustedsec/specula*",".{0,1000}trustedsec\/specula.{0,1000}","offensive_tool_keyword","specula","Specula is a C2 framework that allows for interactive operations of an implant that runs purely in the context of outlook","T1071.001 - T1105 - T1204 - T1548.002 - T1071 - T1562","TA0011 - TA0002 - TA0003 - TA0006 - TA0008 - TA0007 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/trustedsec/specula","1","1","N/A","N/A","10","10","191","21","2024-09-23T09:25:33Z","2023-12-07T15:59:52Z","61661" +"*trustedsec/unicorn*",".{0,1000}trustedsec\/unicorn.{0,1000}","offensive_tool_keyword","unicorn","Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory","T1059.001 - T1055.012 - T1027.002 - T1547.009","TA0002 - TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/trustedsec/unicorn","1","1","N/A","N/A","N/A","10","3818","816","2024-01-24T20:02:33Z","2013-06-19T08:38:06Z","61662" +"*TryA9ain/BypassAddUser*",".{0,1000}TryA9ain\/BypassAddUser.{0,1000}","offensive_tool_keyword","BypassAddUser","Bypass antivirus software to add users","T1562.001 - T1078.002 - T1136.001","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TryA9ain/BypassAddUser","1","1","N/A","N/A","6","1","46","8","2020-12-12T05:11:35Z","2020-12-12T04:15:06Z","61666" +"*ts::logonpasswords*",".{0,1000}ts\:\:logonpasswords.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","61675" +"*ts::mstsc*",".{0,1000}ts\:\:mstsc.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","61676" +"*ts::multirdp*",".{0,1000}ts\:\:multirdp.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","61677" +"*ts::remote*",".{0,1000}ts\:\:remote.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","61678" +"*ts::sessions*",".{0,1000}ts\:\:sessions.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","61679" +"*tspkg/decryptor.py*",".{0,1000}tspkg\/decryptor\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","61689" +"*tun2socks/releases/download*",".{0,1000}tun2socks\/releases\/download.{0,1000}","offensive_tool_keyword","tun2socks","socks tunneling","T1572 - T1090 - T1071 - T1573 - T1205","TA0010 - TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/xjasonlyu/tun2socks","1","1","N/A","N/A","10","10","3785","513","2025-04-15T21:19:25Z","2019-07-16T03:25:40Z","61693" +"*tun2socks-main.zip*",".{0,1000}tun2socks\-main\.zip.{0,1000}","offensive_tool_keyword","tun2socks","socks tunneling","T1572 - T1090 - T1071 - T1573 - T1205","TA0010 - TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/xjasonlyu/tun2socks","1","1","N/A","N/A","10","10","3785","513","2025-04-15T21:19:25Z","2019-07-16T03:25:40Z","61694" +"*tun2socks-windows-*.exe*",".{0,1000}tun2socks\-windows\-.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","tun2socks","socks tunneling","T1572 - T1090 - T1071 - T1573 - T1205","TA0010 - TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/xjasonlyu/tun2socks","1","1","N/A","N/A","10","10","3785","513","2025-04-15T21:19:25Z","2019-07-16T03:25:40Z","61695" +"*TunnelGRE/Augustus*",".{0,1000}TunnelGRE\/Augustus.{0,1000}","offensive_tool_keyword","Augustus","Augustus is a Golang loader that execute shellcode utilizing the process hollowing technique with anti-sandbox and anti-analysis measures. The shellcode is encrypted with the Triple DES (3DES) encryption algorithm.","T1055.012 - T1027.002 - T1136.001 - T1562.001","TA0005 - TA0002 - TA0003","N/A","N/A","Exploitation tool","https://github.com/TunnelGRE/Augustus","1","1","N/A","N/A","6","2","131","26","2024-07-27T14:47:45Z","2023-08-21T15:08:40Z","61710" +"*TunnelVision/pushrouteconfig.sh*",".{0,1000}TunnelVision\/pushrouteconfig\.sh.{0,1000}","offensive_tool_keyword","TunnelVision","TunnelVision uses DHCP option 121 to manipulate routing tables and decloak VPN traffic","T1557 - T1498.003","TA0009 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/leviathansecurity/TunnelVision","1","1","N/A","N/A","9","2","132","17","2024-05-08T19:40:13Z","2024-03-11T22:24:56Z","61724" +"*turn_keylogger*",".{0,1000}turn_keylogger.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","61734" +"*TVqQAAMAAAAEAAAA*",".{0,1000}TVqQAAMAAAAEAAAA.{0,1000}","offensive_tool_keyword","base64","start of an executable payload in base64","T1574.002 - T1547.008 - T1059.001","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/matterpreter/OffensiveCSharp/tree/master/MockDirUACBypass","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","61738" +"*Tw1sm/PySQLRecon*",".{0,1000}Tw1sm\/PySQLRecon.{0,1000}","offensive_tool_keyword","PySQLRecon","Offensive MSSQL toolkit written in Python, based off SQLRecon","T1040 - T1078 - T1072 - T1223 - T1059 - T1213","TA0001 - TA0002 - TA0007 - TA0009","N/A","N/A","Exploitation tool","https://github.com/Tw1sm/PySQLRecon","1","1","N/A","N/A","10","3","201","15","2025-01-12T02:14:59Z","2023-09-03T01:14:35Z","61741" +"*Tw1sm/RITM*",".{0,1000}Tw1sm\/RITM.{0,1000}","offensive_tool_keyword","RITM","python Man in the middle ","T1557.002 - T1040 - T1098.002 - T1557.001 - T1552.001","TA0006 - TA0007 - TA0009 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/Tw1sm/RITM","1","1","N/A","N/A","9","3","292","27","2024-11-20T14:27:24Z","2022-10-05T01:10:33Z","61742" +"*Tw1sm/spraycharles*",".{0,1000}Tw1sm\/spraycharles.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","1","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","61743" +"*twittor.py*",".{0,1000}twittor\.py.{0,1000}","offensive_tool_keyword","twittor","A fully featured backdoor that uses Twitter as a C&C server ","T1105 - T1102 - T1041","TA0003 - TA0002 - TA0007","N/A","N/A","C2","https://github.com/PaulSec/twittor","1","1","N/A","N/A","10","10","771","217","2020-09-30T13:47:31Z","2015-09-09T07:23:25Z","61746" +"*twittor-master.zip*",".{0,1000}twittor\-master\.zip.{0,1000}","offensive_tool_keyword","twittor","A fully featured backdoor that uses Twitter as a C&C server ","T1105 - T1102 - T1041","TA0003 - TA0002 - TA0007","N/A","N/A","C2","https://github.com/PaulSec/twittor","1","1","N/A","N/A","10","10","771","217","2020-09-30T13:47:31Z","2015-09-09T07:23:25Z","61747" +"*Tycx2ry/SweetPotato*",".{0,1000}Tycx2ry\/SweetPotato.{0,1000}","offensive_tool_keyword","cobaltstrike","Modified SweetPotato to work with CobaltStrike v4.0","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tycx2ry/SweetPotato_CS","1","1","N/A","N/A","10","10","241","48","2020-04-30T14:27:20Z","2020-04-16T08:01:31Z","61749" +"*tylerdotrar/SigmaPotato*",".{0,1000}tylerdotrar\/SigmaPotato.{0,1000}","offensive_tool_keyword","SigmaPotato","SeImpersonate privilege escalation tool","T1134 - T1055 - T1543","TA0004 - TA0005 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/tylerdotrar/SigmaPotato","1","1","N/A","N/A","9","4","326","38","2024-05-16T23:46:04Z","2023-09-09T01:35:42Z","61750" +"*Tylous/Ivy*",".{0,1000}Tylous\/Ivy.{0,1000}","offensive_tool_keyword","ivy","Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory","T1059 - T1204 - T1547","TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/optiv/Ivy","1","1","N/A","N/A","10","8","744","129","2023-08-18T17:30:14Z","2021-11-18T18:29:20Z","61751" +"*Tylous/SourcePoint*",".{0,1000}Tylous\/SourcePoint.{0,1000}","offensive_tool_keyword","cobaltstrike","SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Tylous/SourcePoint","1","1","N/A","N/A","10","10","1109","156","2025-04-16T17:15:04Z","2021-08-06T20:55:26Z","61752" +"*Tylous/ZipExec*",".{0,1000}Tylous\/ZipExec.{0,1000}","offensive_tool_keyword","ZipExec","A unique technique to execute binaries from a password protected zip","T1560.001 - T1204.002 - T1059.005","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Tylous/ZipExec","1","1","N/A","N/A","9","10","1026","153","2022-07-01T16:25:26Z","2021-10-19T21:03:44Z","61753" +"*TypeError/domained*",".{0,1000}TypeError\/domained.{0,1000}","offensive_tool_keyword","domained","A domain name enumeration tool","T1593 - T1594 - T1595 - T1567","TA0007 - TA0009 - TA0004","N/A","N/A","Reconnaissance","https://github.com/TypeError/domained","1","1","N/A","N/A","N/A","8","726","157","2021-04-11T09:54:50Z","2017-08-18T00:03:39Z","61754" +"*U2hlbGxjb2RlIFBhdGg=*",".{0,1000}U2hlbGxjb2RlIFBhdGg\=.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","61761" +"*uac_bypass*",".{0,1000}uac_bypass.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","61769" +"*uac_bypass_bluetooth_win10.lua*",".{0,1000}uac_bypass_bluetooth_win10\.lua.{0,1000}","offensive_tool_keyword","OffensiveLua","Offensive Lua is a collection of offensive security scripts written in Lua with FFI","T1059 - T1218.011 - T1105 - T1021.002 - T1564.001 - T1112 - T1113 - T1204.002 - T1547.002","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/hackerhouse-opensource/OffensiveLua","1","1","N/A","N/A","8","2","184","25","2023-11-17T00:35:10Z","2023-10-25T17:21:13Z","61770" +"*uac_easinvoker.*",".{0,1000}uac_easinvoker\..{0,1000}","offensive_tool_keyword","elevationstation","elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","61771" +"*Uacbypass.dll*",".{0,1000}Uacbypass\.dll.{0,1000}","offensive_tool_keyword","xeno-rat","Xeno-RAT is an open-source remote access tool (RAT) developed in C# providing a comprehensive set of features for remote system management. Has features such as HVNC - live microphone - reverse proxy and much much more","T1133 - T1021.001 - T1563.002 - T1113 - T1123 - T1571 - T1090","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011","N/A","N/A","C2","https://github.com/moom825/xeno-rat","1","1","N/A","N/A","10","10","1225","323","2024-03-05T06:22:36Z","2023-10-17T06:41:56Z","61774" +"*uacbypass_files*",".{0,1000}uacbypass_files.{0,1000}","offensive_tool_keyword","elevationstation","elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","61776" +"*UACBypass-BOF*",".{0,1000}UACBypass\-BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File implementation of Event Viewer deserialization UAC bypass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/TrustedPath-UACBypass-BOF","1","1","N/A","N/A","10","10","133","40","2021-08-16T07:49:55Z","2021-08-07T03:40:33Z","61777" +"*UACBypassCMSTP.ps1*",".{0,1000}UACBypassCMSTP\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","61778" +"*UACBypassedService.exe*",".{0,1000}UACBypassedService\.exe.{0,1000}","offensive_tool_keyword","SCMUACBypass","SCM UAC Bypass","T1548.002 - T1088","TA0004 - TA0002","N/A","N/A","Defense Evasion","https://github.com/rasta-mouse/SCMUACBypass","1","1","N/A","N/A","8","1","97","17","2023-09-05T17:24:49Z","2023-09-04T13:11:17Z","61781" +"*UACBypassExecuteCMDAsync.py*",".{0,1000}UACBypassExecuteCMDAsync\.py.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","61782" +"*uac-schtasks*",".{0,1000}uac\-schtasks.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","61788" +"*uac-silentcleanup*",".{0,1000}uac\-silentcleanup.{0,1000}","offensive_tool_keyword","cobaltstrike","New UAC bypass for Silent Cleanup for CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EncodeGroup/UAC-SilentClean","1","1","N/A","N/A","10","10","192","31","2021-07-14T13:51:02Z","2020-10-07T13:25:21Z","61789" +"*uac-token-duplication*",".{0,1000}uac\-token\-duplication.{0,1000}","offensive_tool_keyword","cobaltstrike","Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://www.cobaltstrike.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","61790" +"*UACTokenManipulationManager.cs*",".{0,1000}UACTokenManipulationManager\.cs.{0,1000}","offensive_tool_keyword","RedPeanut","RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.","T1055 - T1057 - T1059.001 - T1106 - T1003 - T1071 - T1036 - T1027","TA0002 - TA0003 - TA0004 - TA0011","N/A","N/A","C2","https://github.com/b4rtik/RedPeanut","1","1","N/A","N/A","10","10","328","81","2023-07-07T21:33:22Z","2019-08-22T07:49:50Z","61791" +"*uaf2john.*",".{0,1000}uaf2john\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","61792" +"*ubiq-eu1.picopool.org*",".{0,1000}ubiq\-eu1\.picopool\.org.{0,1000}","offensive_tool_keyword","lolminer","NVIDIA+AMD GPU Miner","T1496","TA0040","N/A","N/A","Cryptomining","https://github.com/Lolliedieb/lolMiner-releases","1","1","N/A","N/A","9","10","2781","601","2025-02-01T20:03:57Z","2018-10-27T20:35:03Z","61794" +"*udmp-parser-main*",".{0,1000}udmp\-parser\-main.{0,1000}","offensive_tool_keyword","udmp-parser","A Cross-Platform C++ parser library for Windows user minidumps.","T1005 - T1059.003 - T1027.002","TA0009 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/0vercl0k/udmp-parser","1","1","N/A","N/A","6","3","202","23","2024-11-20T15:58:21Z","2022-01-30T18:56:21Z","61797" +"*uhttpsharp.*",".{0,1000}uhttpsharp\..{0,1000}","offensive_tool_keyword","cobaltstrike","SharpCompile is an aggressor script for Cobalt Strike which allows you to compile and execute C# in realtime. This is a more slick approach than manually compiling an .NET assembly and loading it into Cobalt Strike. The project aims to make it easier to move away from adhoc PowerShell execution instead creating a temporary assembly and executing ","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/SpiderLabs/SharpCompile","1","1","N/A","N/A","10","10","291","58","2020-08-07T12:49:36Z","2018-11-01T17:18:52Z","61803" +"*uiredn4njfsa4234bafb32ygjdawfvs.frascuft.com*",".{0,1000}uiredn4njfsa4234bafb32ygjdawfvs\.frascuft\.com.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","61806" +"*uknowsec/CreateService*",".{0,1000}uknowsec\/CreateService.{0,1000}","offensive_tool_keyword","CreateService","Creating a persistent service","T1543.003 - T1547.001 - T1050","TA0003","N/A","N/A","Persistence","https://github.com/uknowsec/CreateService","1","1","N/A","N/A","4","2","105","27","2021-04-26T06:43:12Z","2020-09-23T05:03:52Z","61808" +"*uknowsec/JuicyPotato*",".{0,1000}uknowsec\/JuicyPotato.{0,1000}","offensive_tool_keyword","JuicyPotato","Windows Local Privilege Escalation from Service Account to System","T1055.012 - T1068 - T1548.002 - T1505.003","TA0004 - TA0003 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/uknowsec/JuicyPotato","1","1","N/A","N/A","10","2","190","46","2021-07-01T05:28:41Z","2021-06-10T12:06:13Z","61809" +"*uknowsec/keylogger*",".{0,1000}uknowsec\/keylogger.{0,1000}","offensive_tool_keyword","keylogger","Keyboard recording","T1056.001","TA0006 - TA0009","N/A","N/A","Collection","https://github.com/uknowsec/keylogger","1","1","N/A","N/A","9","2","140","35","2021-05-19T08:33:58Z","2020-11-10T07:15:50Z","61810" +"*uknowsec/SharpAVKB*",".{0,1000}uknowsec\/SharpAVKB.{0,1000}","offensive_tool_keyword","SharpAVKB","Windows Antivirus Comparison and Patch Number Comparison","T1082 - T1518 - T1083","TA0007","N/A","N/A","Discovery","https://github.com/uknowsec/SharpAVKB","1","1","N/A","N/A","4","1","58","24","2019-10-28T06:50:30Z","2019-10-14T12:44:22Z","61811" +"*uknowsec/SharpEventLog*",".{0,1000}uknowsec\/SharpEventLog.{0,1000}","offensive_tool_keyword","SharpEventLog","reads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetration","T1078 - T1087.001","TA0007","N/A","N/A","Discovery","https://github.com/uknowsec/SharpEventLog","1","1","N/A","N/A","4","3","205","34","2019-10-15T06:26:52Z","2019-10-15T06:14:32Z","61813" +"*uknowsec/TailorScan*",".{0,1000}uknowsec\/TailorScan.{0,1000}","offensive_tool_keyword","cobaltstrike","Self-use suture monster intranet scanner - supports port scanning - identifying services - getting title - scanning multiple network cards - ms17010 scanning - icmp survival detection","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/uknowsec/TailorScan","1","1","N/A","N/A","10","10","279","48","2020-11-12T08:29:11Z","2020-11-09T07:38:16Z","61814" +"*UlBDIFNlcnZlciBIb3N0*",".{0,1000}UlBDIFNlcnZlciBIb3N0.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","61816" +"*UlBDIFNlcnZlciBQb3J0*",".{0,1000}UlBDIFNlcnZlciBQb3J0.{0,1000}","offensive_tool_keyword","C2 related tools","Cooolis-ms is a code execution tool that includes Metasploit Payload Loader. Cobalt Strike External C2 Loader. and Reflective DLL injection. Its positioning is to avoid some codes that we will execute and contain characteristics in static killing. and help red team personnel It is more convenient and quick to switch from the Web container environment to the C2 environment for further work.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","N/A","C2","https://github.com/Rvn0xsy/Cooolis-ms","1","1","N/A","N/A","10","10","916","138","2024-08-12T13:07:54Z","2019-03-31T14:23:57Z","61817" +"*Ullaakut/Gorsair*",".{0,1000}Ullaakut\/Gorsair.{0,1000}","offensive_tool_keyword","Gorsair","Gorsair hacks its way into remote docker containers that expose their APIs","T1552","TA0006","N/A","N/A","Exploitation tool","https://github.com/Ullaakut/Gorsair","1","1","N/A","N/A","N/A","9","851","70","2023-12-19T18:44:32Z","2018-08-02T16:49:14Z","61818" +"*UltraSnaffCore.csproj*",".{0,1000}UltraSnaffCore\.csproj.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","61820" +"*UltraSnaffler.sln*",".{0,1000}UltraSnaffler\.sln.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 - T1003.009 - T1003.010 - T1003.011 - T1003.012 - T1003.013 - T1003.014 - T1003.015 - T1003.016 - T1003.017 - T1003.018 - T1003.019 - T1003.020 - T1003.021 - T1003.022 - T1003.023 - T1003.024 - T1003.025 - T1003.026 - T1003.027 - T1003.028 - T1003.029 - T1003.030 - T1003.031 - T1003.032 - T1003.033 - T1003.034 - T1003.035 - T1003.036 - T1003.037 - T1003.038 - T1003.039 - T1003.040 - T1003.041 - T1003.042 - T1003.043 - T1003.044 - T1003.045 - T1003.046 - T1003.047 - T1003.048 - T1003.049 - T1003.050 - T1003.051 - T1003.052 - T1003.053 - T1003.054 - T1003.055 - T1003.056 - T1003.057 - T1003.058 - T1003.059 - T1003.060 - T1003.061 - T1003.062 - T1003.063 - T1003.064 - T1003.065 - T1003.066 - T1003.067 - T1003.068 - T1003.069 - T1003.070 - T1003.071 - T1003.072 - T1003.073 - T1003.074 - T1003.075 - T1003.076 - T1003.077 - T1003.078 - T1003.079 - T1003.080 - T1003.081 - T1003.082 - T1003.083 - T1003.084 - T1003.085 - T1003.086 - T1003.087 - T1003.088 - T1003.089 - T1003.090 - T1003.091 - T1003.092 - T1003.093 - T1003.094 - T1003.095 - T1003.096 - T1003.097 - T1003.098 - T1003.099 - T1003.100 - T1003.101 - T1003.102 - T1003.103 - T1003.104 - T1003.105 - T1003.106 - T1003.107 - T1003.108 - T1003.109 - T1003.110 - T1003.111 - T1003.112 - T1003.113 - T1003.114 - T1003.115 - T1003.116 - T1003.117 - T1003.118 - T1003.119 - T1003.120 - T1003.121 - T1003.122 - T1003.123 - T1003","TA0003 - TA0004","N/A","N/A","Exploitation tool","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","61821" +"*UltraSnaffler.sln*",".{0,1000}UltraSnaffler\.sln.{0,1000}","offensive_tool_keyword","Snaffler","Snaffler is a tool for pentesters and red teamers to help find delicious candy needles (creds mostly but it's flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment)","T1595 - T1592 - T1589 - T1590 - T1591","TA0043","N/A","N/A","Reconnaissance","https://github.com/SnaffCon/Snaffler","1","1","N/A","N/A","N/A","10","2341","232","2025-04-03T04:19:29Z","2020-03-30T07:03:47Z","61822" +"*UmaRex01/HookSentry*",".{0,1000}UmaRex01\/HookSentry.{0,1000}","offensive_tool_keyword","HookSentry","tool for inspecting system DLLs loaded into processes - looking for functions hooked from AV/EDR.","T1055.001 - T1055 - T1057","TA0007 - TA0005","N/A","N/A","Defense Evasion","https://github.com/UmaRex01/HookSentry","1","1","N/A","N/A","6","1","27","2","2025-04-02T12:30:58Z","2024-11-20T18:09:39Z","61835" +"*UMJjAiNUUtvNww0lBj9tzWegwphuIn6hNP9eeIDfOrcHJ3nozYFPT-Jl7WsmbmjZnQXUesoJkcJkpdYEdqgQFE6QZgjWVsLSSDonL28DYDVJ*",".{0,1000}UMJjAiNUUtvNww0lBj9tzWegwphuIn6hNP9eeIDfOrcHJ3nozYFPT\-Jl7WsmbmjZnQXUesoJkcJkpdYEdqgQFE6QZgjWVsLSSDonL28DYDVJ.{0,1000}","offensive_tool_keyword","cobaltstrike","Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt Strike 3.x","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","1531","425","2021-05-18T14:45:39Z","2014-07-14T15:02:42Z","61836" +"*umutcamliyurt/PingRAT*",".{0,1000}umutcamliyurt\/PingRAT.{0,1000}","offensive_tool_keyword","PingRAT","secretly passes Command and Control (C2) traffic through firewalls using ICMP payloads","T1071.004 - T1573.001","TA0011 - TA0042","N/A","N/A","C2","https://github.com/umutcamliyurt/PingRAT","1","1","N/A","N/A","10","10","416","55","2023-09-29T22:26:15Z","2023-09-29T22:07:46Z","61838" +"*Un1k0d3r/SCShell*",".{0,1000}Un1k0d3r\/SCShell.{0,1000}","offensive_tool_keyword","cobaltstrike","Fileless Lateral Movement tool that relies on ChangeServiceConfigA to run command","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Mr-Un1k0d3r/SCShell","1","1","N/A","N/A","10","10","1484","248","2023-07-10T01:31:54Z","2019-11-13T23:39:27Z","61846" +"*uname=FUZZ&pass=FUZZ*",".{0,1000}uname\=FUZZ\&pass\=FUZZ.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","61849" +"*Unconstrained_Delegation_Systems.txt*",".{0,1000}Unconstrained_Delegation_Systems\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","61851" +"*unDefender-master*",".{0,1000}unDefender\-master.{0,1000}","offensive_tool_keyword","unDefender","Killing your preferred antimalware by abusing native symbolic links and NT paths.","T1562.001 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/APTortellini/unDefender","1","1","N/A","N/A","10","4","358","81","2022-01-29T12:35:31Z","2021-08-21T14:45:39Z","61852" +"*undertheradar-main*",".{0,1000}undertheradar\-main.{0,1000}","offensive_tool_keyword","undertheradar","scripts that afford the pentester AV bypass techniques","T1055.005 - T1027 - T1116 - T1070.004","TA0040 - TA0005 - TA0009","N/A","N/A","Defense Evasion","https://github.com/g3tsyst3m/undertheradar","1","1","N/A","N/A","9","1","11","2","2023-10-08T23:31:33Z","2023-07-01T17:59:20Z","61853" +"*undgrddapc4reaunnrdrmnagvdelqfvmgycuvilgwb5uxm25sxawaoqd.onion*",".{0,1000}undgrddapc4reaunnrdrmnagvdelqfvmgycuvilgwb5uxm25sxawaoqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","61854" +"*UnhookingKnownDlls.*",".{0,1000}UnhookingKnownDlls\..{0,1000}","offensive_tool_keyword","ntdlll-unhooking-collection","unhooking ntdll from disk - from KnownDlls - from suspended process - from remote server (fileless)","T1055 - T1055.001 - T1070 - T1070.004 - T1101 - T1574 - T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/ntdlll-unhooking-collection","1","1","N/A","N/A","9","2","188","38","2023-08-02T02:26:33Z","2023-02-07T16:54:15Z","61860" +"*UnhookingNtdll_disk.*",".{0,1000}UnhookingNtdll_disk\..{0,1000}","offensive_tool_keyword","ntdlll-unhooking-collection","unhooking ntdll from disk - from KnownDlls - from suspended process - from remote server (fileless)","T1055 - T1055.001 - T1070 - T1070.004 - T1101 - T1574 - T1574.002","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/ntdlll-unhooking-collection","1","1","N/A","N/A","9","2","188","38","2023-08-02T02:26:33Z","2023-02-07T16:54:15Z","61861" +"*UnhookingPatch-main*",".{0,1000}UnhookingPatch\-main.{0,1000}","offensive_tool_keyword","UnhookingPatch","Bypass EDR Hooks by patching NT API stub and resolving SSNs and syscall instructions at runtime","T1055 - T1574","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/SaadAhla/UnhookingPatch","1","1","N/A","N/A","8","4","304","52","2023-08-02T02:25:38Z","2023-02-08T16:21:03Z","61862" +"*UnhookingPatch-main*",".{0,1000}UnhookingPatch\-main.{0,1000}","offensive_tool_keyword","UnhookingPatch","Bypass EDR Hooks by patching NT API stub and resolving SSNs and syscall instructions at runtime","T1055 - T1055.001 - T1070 - T1070.004 - T1211","TA0005","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/UnhookingPatch","1","1","N/A","N/A","9","4","304","52","2023-08-02T02:25:38Z","2023-02-08T16:21:03Z","61863" +"*UniByAv*",".{0,1000}UniByAv.{0,1000}","offensive_tool_keyword","UniByAv","UniByAv is a simple obfuscator that take raw shellcode and generate executable that are Anti-Virus friendly. The obfuscation routine is purely writtend in assembly to remain pretty short and efficient. In a nutshell the application generate a 32 bits xor key and brute force the key at run time then perform the decryption of the actually shellcode.","T1027 - T1059 - T1029","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/Mr-Un1k0d3r/UniByAv","1","1","N/A","N/A","N/A","3","N/A","N/A","N/A","N/A","61864" +"*unicorn-master.zip*",".{0,1000}unicorn\-master\.zip.{0,1000}","offensive_tool_keyword","unicorn","Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory","T1059.001 - T1055.012 - T1027.002 - T1547.009","TA0002 - TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/trustedsec/unicorn","1","1","N/A","N/A","N/A","10","3818","816","2024-01-24T20:02:33Z","2013-06-19T08:38:06Z","61866" +"*Uninstall-SQLC2AgentPs*",".{0,1000}Uninstall\-SQLC2AgentPs.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","61871" +"*Uninstall-SQLC2Server*",".{0,1000}Uninstall\-SQLC2Server.{0,1000}","offensive_tool_keyword","PowerUpSQL","PowerUpSQL includes functions that support SQL Server discovery. weak configuration auditing. privilege escalation on scale. and post exploitation actions such as OS command execution. It is intended to be used during internal penetration tests and red team engagements. However. PowerUpSQL also includes many functions that can be used by administrators to quickly inventory the SQL Servers in their ADS domain and perform common threat hunting tasks related to SQL Server.","T1078.002 - T1547.001 - T1059.001 - T1106 - T1550.002 - T1087 - T1003 - T1053 - T1047","TA0003 - TA0002 - TA0008 - TA0011 - TA0006","N/A","Black Basta","C2","https://github.com/NetSPI/PowerUpSQL","1","1","N/A","N/A","10","10","2564","472","2024-12-12T18:09:39Z","2016-06-22T01:22:39Z","61872" +"*Unit-259/DataBouncing*",".{0,1000}Unit\-259\/DataBouncing.{0,1000}","offensive_tool_keyword","DataBouncing","Data Bouncing is a technique for transmitting data between two endpoints using DNS lookups and HTTP header manipulation","T1048 - T1041","TA0010","N/A","N/A","Data Exfiltration","https://github.com/Unit-259/DataBouncing","1","1","N/A","N/A","9","1","15","0","2025-03-12T07:34:04Z","2025-03-12T06:58:51Z","61874" +"*unix_cached_ad_hashes.rb*",".{0,1000}unix_cached_ad_hashes\.rb.{0,1000}","offensive_tool_keyword","linikatz","linikatz is a tool to attack AD on UNIX","T1003.002 - T1558.003 - T1078 - T1550.001","TA0006 - TA0001 - TA0004 - TA0003","N/A","N/A","Exploitation tool","https://github.com/CiscoCXSecurity/linikatz","1","1","#linux","N/A","10","6","552","79","2023-10-19T17:01:47Z","2018-11-15T22:19:47Z","61878" +"*unix_kerberos_tickets.rb*",".{0,1000}unix_kerberos_tickets\.rb.{0,1000}","offensive_tool_keyword","linikatz","linikatz is a tool to attack AD on UNIX","T1003.002 - T1558.003 - T1078 - T1550.001","TA0006 - TA0001 - TA0004 - TA0003","N/A","N/A","Exploitation tool","https://github.com/CiscoCXSecurity/linikatz","1","1","#linux","N/A","10","6","552","79","2023-10-19T17:01:47Z","2018-11-15T22:19:47Z","61879" +"*UnkL4b/BabyShark*",".{0,1000}UnkL4b\/BabyShark.{0,1000}","offensive_tool_keyword","BabyShark","This is a basic C2 generic server written in Python and Flask.","T1547.001 - T1059.003 - T1132.001 - T1140 - T1083 - T1070.004 - T1105 - T1056.001 - T1057 - T1012 - T1053.005 - T1218.005 - T1082 - T1016 - T1033","TA0006 - TA0011 - TA0040","N/A","Kimsuky","C2","https://github.com/UnkL4b/BabyShark","1","1","N/A","N/A","10","10","189","30","2021-07-03T00:18:18Z","2020-06-02T12:27:20Z","61880" +"*unkvolism/Fuck-Etw*",".{0,1000}unkvolism\/Fuck\-Etw.{0,1000}","offensive_tool_keyword","Fuck-Etw","Bypass the Event Trace Windows(ETW) and unhook ntdll.","T1070.004 - T1055.001","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/unkvolism/Fuck-Etw","1","1","N/A","N/A","10","2","102","13","2023-09-29T21:19:10Z","2023-09-25T18:59:10Z","61882" +"*UnlinkDLL.exe*",".{0,1000}UnlinkDLL\.exe.{0,1000}","offensive_tool_keyword","UnlinkDLL","DLL Unlinking from InLoadOrderModuleList - InMemoryOrderModuleList - InInitializationOrderModuleList and LdrpHashTable","T1055 - T1027 - T1070","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/frkngksl/UnlinkDLL","1","1","N/A","N/A","7","1","57","13","2023-12-15T12:04:00Z","2023-12-13T14:37:33Z","61890" +"*UnlinkDLL-main*",".{0,1000}UnlinkDLL\-main.{0,1000}","offensive_tool_keyword","UnlinkDLL","DLL Unlinking from InLoadOrderModuleList - InMemoryOrderModuleList - InInitializationOrderModuleList and LdrpHashTable","T1055 - T1027 - T1070","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/frkngksl/UnlinkDLL","1","1","N/A","N/A","7","1","57","13","2023-12-15T12:04:00Z","2023-12-13T14:37:33Z","61893" +"*unmarshal_cmd_exec.*",".{0,1000}unmarshal_cmd_exec\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","61898" +"*UnmarshalPwn.*",".{0,1000}UnmarshalPwn\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","61899" +"*UnmarshalPwn.exe*",".{0,1000}UnmarshalPwn\.exe.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","61900" +"*unode/firefox_decrypt*",".{0,1000}unode\/firefox_decrypt.{0,1000}","offensive_tool_keyword","firefox_decrypt","Firefox Decrypt is a tool to extract passwords from Mozilla","T1555.003 - T1112 - T1056.001","TA0006 - TA0009 - TA0040","N/A","N/A","Credential Access","https://github.com/unode/firefox_decrypt","1","1","N/A","N/A","10","10","2172","317","2024-11-08T13:52:34Z","2014-01-17T13:25:02Z","61901" +"*UnquotedPath.csproj*",".{0,1000}UnquotedPath\.csproj.{0,1000}","offensive_tool_keyword","UnquotedPath","Outputs a list of unquoted service paths that aren't in System32/SysWow64 to plant a PE into","T1543.003 - T1036.005 - T1057","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/matterpreter/OffensiveCSharp/tree/master/UnquotedPath","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","61903" +"*UnquotedPath.exe*",".{0,1000}UnquotedPath\.exe.{0,1000}","offensive_tool_keyword","UnquotedPath","Outputs a list of unquoted service paths that aren't in System32/SysWow64 to plant a PE into","T1543.003 - T1036.005 - T1057","TA0007 - TA0003","N/A","N/A","Discovery","https://github.com/matterpreter/OffensiveCSharp/tree/master/UnquotedPath","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","61904" +"*unshackle-main*",".{0,1000}unshackle\-main.{0,1000}","offensive_tool_keyword","unshackle","Unshackle is an open-source tool to bypass Windows and Linux user passwords from a bootable USB based on Linux","T1110.004 - T1059.004 - T1070.004","TA0006 - TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Fadi002/unshackle","1","1","#linux #windows","N/A","10","10","1899","125","2023-11-10T19:48:10Z","2023-07-19T22:30:28Z","61914" +"*unshackle-v1.0.iso*",".{0,1000}unshackle\-v1\.0\.iso.{0,1000}","offensive_tool_keyword","unshackle","Unshackle is an open-source tool to bypass Windows and Linux user passwords from a bootable USB based on Linux","T1110.004 - T1059.004 - T1070.004","TA0006 - TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/Fadi002/unshackle","1","1","#linux #windows","N/A","10","10","1899","125","2023-11-10T19:48:10Z","2023-07-19T22:30:28Z","61915" +"*untested_payloads.rb*",".{0,1000}untested_payloads\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","61919" +"*UnwindInspector.exe*",".{0,1000}UnwindInspector\.exe.{0,1000}","offensive_tool_keyword","SilentMoonwalk","PoC Implementation of a fully dynamic call stack spoofer","T1055 - T1055.012 - T1562 - T1562.001 - T1070 - T1070.004","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/klezVirus/SilentMoonwalk","1","1","N/A","N/A","9","8","760","100","2024-07-20T10:41:31Z","2022-12-04T13:30:33Z","61920" +"*upload.nolog.cz*",".{0,1000}upload\.nolog\.cz.{0,1000}","offensive_tool_keyword","upload.nolog.cz","sharing platform","T1567.002","TA0010","N/A","N/A","Data Exfiltration","https://upload.nolog.cz/","1","1","#filehostingservice","N/A","8","10","N/A","N/A","N/A","N/A","61943" +"*UploadFileImplant*",".{0,1000}UploadFileImplant.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","61948" +"*UrbanBishop.exe*",".{0,1000}UrbanBishop\.exe.{0,1000}","offensive_tool_keyword","Sharp-Suite","C# offensive tools","T1027 - T1059.001 - T1562.001 - T1136.001","TA0004 - TA0005 - TA0040 - TA0002","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Sharp-Suite","1","1","N/A","N/A","N/A","10","1131","203","2022-12-22T23:57:19Z","2018-12-10T00:08:37Z","61958" +"*Uri3n/Thread-Pool-Injection-PoC*",".{0,1000}Uri3n\/Thread\-Pool\-Injection\-PoC.{0,1000}","offensive_tool_keyword","Thread-Pool-Injection-PoC","Proof of concept code for thread pool based process injection in Windows.","T1055.011","TA0005","N/A","N/A","Defense Evasion","https://github.com/Uri3n/Thread-Pool-Injection-PoC","1","1","N/A","N/A","8","2","115","13","2025-03-29T23:14:47Z","2024-01-24T07:42:08Z","61959" +"*ursnif_IcedID.profile*",".{0,1000}ursnif_IcedID\.profile.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Malleable C2 Design and Reference Guide","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/BC-SECURITY/Malleable-C2-Profiles","1","1","N/A","N/A","10","10","362","46","2023-06-11T17:38:36Z","2020-08-28T22:37:09Z","61963" +"*us.mirrors.cicku.me/blackarch/*/os/*",".{0,1000}us\.mirrors\.cicku\.me\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","61964" +"*UseBeaconCmd*",".{0,1000}UseBeaconCmd.{0,1000}","offensive_tool_keyword","sliver","Sliver is an open source cross-platform adversary emulation/red team framework","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta","C2","https://github.com/BishopFox/sliver","1","1","N/A","N/A","10","10","9218","1249","2025-04-21T17:52:43Z","2019-01-17T22:07:38Z","62001" +"*UsePrtAdminAccount*",".{0,1000}UsePrtAdminAccount.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","62009" +"*UsePrtImperonsationAccount*",".{0,1000}UsePrtImperonsationAccount.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","62010" +"*user_eq_pass_valid_cme_*.txt*",".{0,1000}user_eq_pass_valid_cme_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","62015" +"*--user_file*--password_file*",".{0,1000}\-\-user_file.{0,1000}\-\-password_file.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","1","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","62016" +"*user_password.rb*",".{0,1000}user_password\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62017" +"*UserHunterImplant*",".{0,1000}UserHunterImplant.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","62037" +"*UsernameAsPasswordCreds.txt*",".{0,1000}UsernameAsPasswordCreds\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","62042" +"*userpass_cme_check*",".{0,1000}userpass_cme_check.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","62043" +"*userpass_kerbrute_check*",".{0,1000}userpass_kerbrute_check.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","62044" +"*UserPassBruteForce*",".{0,1000}UserPassBruteForce.{0,1000}","offensive_tool_keyword","ruler","A tool to abuse Exchange services","T1087 - T1110 - T1133 - T1064 - T1204","TA0007 - TA0006 - TA0003 - TA0002 - TA0005","N/A","APT33","Persistence","https://github.com/sensepost/ruler","1","1","N/A","N/A","10","10","2222","362","2024-06-10T11:03:07Z","2016-08-18T15:05:13Z","62045" +"*users_asreproast.txt*",".{0,1000}users_asreproast\.txt.{0,1000}","offensive_tool_keyword","adhunt","Tool for exploiting Active Directory Enviroments - enumeration","T1018 - T1087 - T1087.002 - T1069 - T1069.002","TA0007 - TA0003 - TA0001","N/A","N/A","Discovery","https://github.com/karendm/ADHunt","1","1","N/A","AD Enumeration","7","1","46","10","2023-08-10T18:55:39Z","2023-06-20T13:24:10Z","62056" +"*users_dcsrp_full.txt*",".{0,1000}users_dcsrp_full\.txt.{0,1000}","offensive_tool_keyword","adhunt","Tool for exploiting Active Directory Enviroments - enumeration","T1018 - T1087 - T1087.002 - T1069 - T1069.002","TA0007 - TA0003 - TA0001","N/A","N/A","Discovery","https://github.com/karendm/ADHunt","1","1","N/A","AD Enumeration","7","1","46","10","2023-08-10T18:55:39Z","2023-06-20T13:24:10Z","62057" +"*users_kerberoasting.txt*",".{0,1000}users_kerberoasting\.txt.{0,1000}","offensive_tool_keyword","adhunt","Tool for exploiting Active Directory Enviroments - enumeration","T1018 - T1087 - T1087.002 - T1069 - T1069.002","TA0007 - TA0003 - TA0001","N/A","N/A","Discovery","https://github.com/karendm/ADHunt","1","1","N/A","AD Enumeration","7","1","46","10","2023-08-10T18:55:39Z","2023-06-20T13:24:10Z","62058" +"*users_list_cme_ldap_nullsess_*",".{0,1000}users_list_cme_ldap_nullsess_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","62059" +"*users_list_kerbrute_*",".{0,1000}users_list_kerbrute_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","62060" +"*users_list_ridbrute_*",".{0,1000}users_list_ridbrute_.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","62061" +"*users_no_req_pass.txt*",".{0,1000}users_no_req_pass\.txt.{0,1000}","offensive_tool_keyword","adhunt","Tool for exploiting Active Directory Enviroments - enumeration","T1018 - T1087 - T1087.002 - T1069 - T1069.002","TA0007 - TA0003 - TA0001","N/A","N/A","Discovery","https://github.com/karendm/ADHunt","1","1","N/A","AD Enumeration","7","1","46","10","2023-08-10T18:55:39Z","2023-06-20T13:24:10Z","62062" +"*users_no_req_pass_full.txt*",".{0,1000}users_no_req_pass_full\.txt.{0,1000}","offensive_tool_keyword","adhunt","Tool for exploiting Active Directory Enviroments - enumeration","T1018 - T1087 - T1087.002 - T1069 - T1069.002","TA0007 - TA0003 - TA0001","N/A","N/A","Discovery","https://github.com/karendm/ADHunt","1","1","N/A","AD Enumeration","7","1","46","10","2023-08-10T18:55:39Z","2023-06-20T13:24:10Z","62063" +"*UsoDllLoader*",".{0,1000}UsoDllLoader.{0,1000}","offensive_tool_keyword","UsoDllLoader","This PoC shows a technique that can be used to weaponize privileged file write vulnerabilities on Windows. It provides an alternative to the DiagHub DLL loading exploit ","T1210.001 - T1055 - T1574.001","TA0007 - TA0002 - TA0001","N/A","N/A","Exploitation tool","https://github.com/itm4n/UsoDllLoader","1","1","N/A","N/A","N/A","4","386","100","2020-06-06T11:05:12Z","2019-08-01T17:58:16Z","62098" +"*usr/share/seclists*",".{0,1000}usr\/share\/seclists.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","62100" +"*util.nimplant*",".{0,1000}util\.nimplant.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","62105" +"*util/dot_net_deserialization/*",".{0,1000}util\/dot_net_deserialization\/.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62106" +"*v1k1ngfr.github.io/fuegoshell/*",".{0,1000}v1k1ngfr\.github\.io\/fuegoshell\/.{0,1000}","offensive_tool_keyword","fuegoshell","Fuegoshell is a powershell oneliner generator for Windows remote shell re-using TCP 445","T1059.001 - T1203","TA0002 - TA0011 - TA0008","N/A","N/A","Lateral Movement","https://github.com/v1k1ngfr/fuegoshell","1","1","N/A","N/A","10","1","44","7","2024-04-27T09:03:28Z","2024-04-27T08:06:03Z","62115" +"*v1k1ngfr/fuegoshell*",".{0,1000}v1k1ngfr\/fuegoshell.{0,1000}","offensive_tool_keyword","fuegoshell","Fuegoshell is a powershell oneliner generator for Windows remote shell re-using TCP 445","T1059.001 - T1203","TA0002 - TA0011 - TA0008","N/A","N/A","Lateral Movement","https://github.com/v1k1ngfr/fuegoshell","1","1","N/A","N/A","10","1","44","7","2024-04-27T09:03:28Z","2024-04-27T08:06:03Z","62116" +"*V1V1/DecryptTeamViewer*",".{0,1000}V1V1\/DecryptTeamViewer.{0,1000}","offensive_tool_keyword","DecryptTeamViewer","Enumerate and decrypt TeamViewer credentials from Windows registry","T1552.001 - T1003 - T1119 - T1012","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/V1V1/DecryptTeamViewer","1","1","N/A","N/A","7","3","241","62","2021-12-05T09:19:56Z","2020-02-07T07:50:47Z","62117" +"*V3n0M-Scanner*",".{0,1000}V3n0M\-Scanner.{0,1000}","offensive_tool_keyword","V3n0M-Scanner","V3n0M is a free and open source scanner. Evolved from baltazars scanner. it has adapted several new features that improve fuctionality and usability. It is mostly experimental software. This program is for finding and executing various vulnerabilities. It scavenges the web using dorks and organizes the URLs it finds. Use at your own risk.","T1210.001 - T1190 - T1191 - T1595","TA0007 - TA0002 - TA0008 - TA0010","N/A","N/A","Vulnerability Scanner","https://github.com/v3n0m-Scanner/V3n0M-Scanner","1","1","N/A","N/A","N/A","10","1503","413","2023-11-14T23:05:16Z","2013-10-21T06:05:17Z","62118" +"*v4d1/Dome*",".{0,1000}v4d1\/Dome.{0,1000}","offensive_tool_keyword","DOME","DOME - A subdomain enumeration tool","T1583 - T1595 - T1190","TA0011 - TA0009","N/A","N/A","Reconnaissance","https://github.com/v4d1/Dome","1","1","N/A","N/A","5","6","531","74","2024-02-07T09:12:17Z","2022-02-20T15:09:40Z","62119" +"*vanhauser-thc/thc-hydra*",".{0,1000}vanhauser\-thc\/thc\-hydra.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","62122" +"*vault::cred*",".{0,1000}vault\:\:cred.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets. keyword taken from hayabusa-rules win_alert_mimikatz_keywords.yml","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","62123" +"*Vbad/VBad.py*",".{0,1000}Vbad\/VBad\.py.{0,1000}","offensive_tool_keyword","vbad","VBad is fully customizable VBA Obfuscation Tool combined with an MS Office document generator. It aims to help Red & Blue team for attack or defense.","T1564 - T1117 - T1204 - T1070","TA0002 - TA0008 - TA0011","N/A","N/A","Defense Evasion","https://github.com/Pepitoh/Vbad","1","1","N/A","N/A","8","6","544","127","2017-10-15T12:56:18Z","2016-03-09T12:36:04Z","62127" +"*vba-macro-mac-persistence.vbs*",".{0,1000}vba\-macro\-mac\-persistence\.vbs.{0,1000}","offensive_tool_keyword","phishing-HTML-linter","Phishing and Social-Engineering related scripts","T1566.001 - T1056.001","TA0040 - TA0001","N/A","N/A","Phishing","https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing","1","1","N/A","N/A","10","10","2689","527","2023-06-27T19:16:49Z","2018-02-02T21:24:03Z","62128" +"*vba-windows-persistence.vbs*",".{0,1000}vba\-windows\-persistence\.vbs.{0,1000}","offensive_tool_keyword","phishing-HTML-linter","Phishing and Social-Engineering related scripts","T1566.001 - T1056.001","TA0040 - TA0001","N/A","N/A","Phishing","https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing","1","1","N/A","N/A","10","10","2689","527","2023-06-27T19:16:49Z","2018-02-02T21:24:03Z","62130" +"*vbs_obfuscator.vbs*",".{0,1000}vbs_obfuscator\.vbs.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","62143" +"*vbs_ofuscator.vbs*",".{0,1000}vbs_ofuscator\.vbs.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","62144" +"*vbs-obfuscator.py*",".{0,1000}vbs\-obfuscator\.py.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","N/A","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","62146" +"*VBS-UEFI-Locks-Bypass/Config.xml*",".{0,1000}VBS\-UEFI\-Locks\-Bypass\/Config\.xml.{0,1000}","offensive_tool_keyword","WindowsDowndate","A tool that takes over Windows Updates to craft custom downgrades and expose past fixed vulnerabilities","T1072 - T1486 - T1505.002 - T1495 - T1499.004","TA0005 - TA0004 - TA0003 ","N/A","N/A","Defense Evasion","https://github.com/SafeBreach-Labs/WindowsDowndate","1","1","N/A","N/A","10","7","663","88","2024-10-26T10:18:49Z","2024-01-08T19:42:47Z","62147" +"*VbulletinWidgetTemplateRce.py*",".{0,1000}VbulletinWidgetTemplateRce\.py.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","62148" +"*vcenter_forge_saml_token*",".{0,1000}vcenter_forge_saml_token.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62149" +"*vcenter_secrets_dump.*",".{0,1000}vcenter_secrets_dump\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62150" +"*vcenter_secrets_dump.rb*",".{0,1000}vcenter_secrets_dump\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62151" +"*vdi2john.pl*",".{0,1000}vdi2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","62153" +"*VectorKernel-main.zip*",".{0,1000}VectorKernel\-main\.zip.{0,1000}","offensive_tool_keyword","VectorKernel","PoCs for Kernelmode rootkit techniques research.","T1543 - T1055 - T1134 - T1564 - T1070 - T1057 - T1574 - T1562 - T1082 - T1518","TA0003 - TA0005 - TA0004 - TA0008 - TA0007","N/A","N/A","Exploitation tool","https://github.com/daem0nc0re/VectorKernel/","1","1","N/A","N/A","10","4","367","60","2025-01-21T08:22:42Z","2023-11-23T12:36:31Z","62158" +"*vectra-ai-research/MAAD-AF*",".{0,1000}vectra\-ai\-research\/MAAD\-AF.{0,1000}","offensive_tool_keyword","MAAD-AF","MAAD Attack Framework - An attack tool for simple fast & effective security testing of M365 & Azure AD. ","T1078.001 - T1552.001 - T1558.001 - T1003.001 - T1110.003 - T1555.003 - T1558.002 - T1087.001 - T1087.002 - T1214.001 - T1562.001 - T1088 - T1559.001 - T1106 - T1204","TA0006 - TA0004 - TA0008 - TA0007 - TA0002 - TA0005","N/A","N/A","Exploitation tool","https://github.com/vectra-ai-research/MAAD-AF","1","1","N/A","N/A","8","4","396","56","2024-09-27T16:43:52Z","2023-02-09T02:08:07Z","62159" +"*veeam_credential_dump.*",".{0,1000}veeam_credential_dump\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62160" +"*veeam_dump_mssql.ps1*",".{0,1000}veeam_dump_mssql\.ps1.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","62162" +"*veeam_dump_postgresql.ps1*",".{0,1000}veeam_dump_postgresql\.ps1.{0,1000}","offensive_tool_keyword","NetExec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1110 - T1135 - T1047 - T1078 - T1087 - T1021","TA0006 - TA0007 - TA0003 - TA0008 - TA0005","N/A","N/A","Exploitation tool","https://github.com/Pennyw0rth/NetExec","1","1","N/A","N/A","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","62163" +"*veeam-creds-main*",".{0,1000}veeam\-creds\-main.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","1","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","62164" +"*Veeam-Get-Creds.ps1*",".{0,1000}Veeam\-Get\-Creds\.ps1.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","1","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","62165" +"*VeeamGetCreds.yaml*",".{0,1000}VeeamGetCreds\.yaml.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","1","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","62166" +"*VeeamHax_TemporaryKey.pfx*",".{0,1000}VeeamHax_TemporaryKey\.pfx.{0,1000}","offensive_tool_keyword","VeamHax","Exploit for CVE-2023-27532 against Veeam Backup & Replication (Plaintext credential leaking tool)","T1059 - T1203 - T1040 - T1189 - T1010","TA0001 - TA0002 - TA0009 - TA0011","More_eggs","Akira - FIN6","Exploitation tool","https://github.com/sfewer-r7/CVE-2023-27532","1","1","N/A","N/A","8","2","110","22","2023-03-23T18:03:27Z","2023-03-23T16:08:43Z","62167" +"*veeampot.py*",".{0,1000}veeampot\.py.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","1","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","62168" +"*veqlxhq7ub5qze3qy56zx2cig2e6tzsgxdspkubwbayqije6oatma6id.onion*",".{0,1000}veqlxhq7ub5qze3qy56zx2cig2e6tzsgxdspkubwbayqije6oatma6id\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","62173" +"*verovaleros/domain_analyzer*",".{0,1000}verovaleros\/domain_analyzer.{0,1000}","offensive_tool_keyword","domain_analyzer","Analyze the security of any domain by finding all the information possible","T1560 - T1590 - T1200 - T1213 - T1057","TA0002 - TA0009","N/A","N/A","Reconnaissance","https://github.com/eldraco/domain_analyzer","1","1","N/A","N/A","6","10","1858","241","2022-12-29T10:57:33Z","2017-08-08T18:52:34Z","62175" +"*vh.4everproxy.com/secure/*",".{0,1000}vh\.4everproxy\.com\/secure\/.{0,1000}","offensive_tool_keyword","4everproxy","proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://www.4everproxy.com/","1","1","N/A","this pattern could be observed in any proxyfied site","6","10","N/A","N/A","N/A","N/A","62177" +"*victim_host_generator.py*",".{0,1000}victim_host_generator\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","62178" +"*Villain.git*",".{0,1000}Villain\.git.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","62185" +"*Villain/Core*",".{0,1000}Villain\/Core.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","62186" +"*villain_core.py*",".{0,1000}villain_core\.py.{0,1000}","offensive_tool_keyword","Villain","Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells. enhance their functionality with additional features (commands. utilities etc) and share them among connected sibling servers (Villain instances running on different machines).","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/t3l3machus/Villain","1","1","#linux","N/A","10","10","3992","642","2025-01-19T18:37:12Z","2022-10-25T22:02:59Z","62187" +"*vincent.letoux@gmail.com*",".{0,1000}vincent\.letoux\@gmail\.com.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/gentilkiwi/mimikatz","1","1","#email","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","62192" +"*vip.youwe.shell.core.shell*",".{0,1000}vip\.youwe\.shell\.core\.shell.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","62193" +"*vip.youwe.shell.shells.payloads.java*",".{0,1000}vip\.youwe\.shell\.shells\.payloads\.java.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","62194" +"*vip.youwe.shell.shells.plugins.java*",".{0,1000}vip\.youwe\.shell\.shells\.plugins\.java.{0,1000}","offensive_tool_keyword","Godzilla","Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities.","T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568","TA0001 - TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/BeichenDream/Godzilla","1","1","N/A","N/A","10","10","4096","551","2024-07-17T07:56:35Z","2020-08-17T17:27:56Z","62195" +"*viper/*.sock*",".{0,1000}viper\/.{0,1000}\.sock.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","62196" +"*viper-dev.conf*",".{0,1000}viper\-dev\.conf.{0,1000}","offensive_tool_keyword","viperc2","viperpython backend - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1566-001 - T1566-002 - T1566-003 - T1003 - T1055 - T1036 - T1105 - T1057 - T1574-001 - T1569-002 - T1070 - T1135 - T1005 - T1065 - T1069 - T1027 - T1021 - T1086 - T1087 - T1096 - T1560","TA0002 - TA0003","N/A","Black Basta","C2","https://github.com/FunnyWolf/viperpython","1","1","N/A","N/A","10","","N/A","","","","62197" +"*viperzip.exe*",".{0,1000}viperzip\.exe.{0,1000}","offensive_tool_keyword","viperc2","vipermsf Metasploit - Viper is a graphical intranet penetration tool which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Black Basta","Framework","https://github.com/FunnyWolf/vipermsf","1","1","N/A","N/A","N/A","","N/A","","","","62200" +"*VirtualAlllocEx/Payload-Download-Cradles*",".{0,1000}VirtualAlllocEx\/Payload\-Download\-Cradles.{0,1000}","offensive_tool_keyword","Payload-Download-Cradles","download cradles to bypass AV/EPP/EDR in context of download cradle detections","T1105 - T1027 - T1203 - T1071","TA0005 - TA0009 - TA0002","N/A","N/A","Defense Evasion","https://github.com/VirtualAlllocEx/Payload-Download-Cradles","1","1","N/A","N/A","10","3","256","51","2022-07-07T07:20:36Z","2021-05-14T08:56:54Z","62220" +"*viRu5/GoogleChromeAutoLaunch.py*",".{0,1000}viRu5\/GoogleChromeAutoLaunch\.py.{0,1000}","offensive_tool_keyword","Python-Rootkit","full undetectable python RAT which can bypass almost all antivirus and open a backdoor inside any windows machine which will establish a reverse https Metasploit connection to your listening machine","T1100 - T1027 - T1219 - T1560.001 - T1021.005","TA0005 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/0xIslamTaha/Python-Rootkit","1","1","N/A","N/A","10","10","606","145","2024-10-29T16:56:39Z","2016-06-09T10:49:54Z","62223" +"*virusscan_bypass.rb*",".{0,1000}virusscan_bypass\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62225" +"*VirusTotalC2.*",".{0,1000}VirusTotalC2\..{0,1000}","offensive_tool_keyword","VirusTotalC2","Abusing VirusTotal API to host our C2 traffic. usefull for bypassing blocking firewall rules if VirusTotal is in the target white list and in case you don't have C2 infrastructure. now you have a free one","T1071.004 - T1102 - T1021.002","TA0011 - TA0008 - TA0042","N/A","N/A","C2","https://github.com/RATandC2/VirusTotalC2","1","1","N/A","N/A","10","10","27","81","2022-09-28T15:10:44Z","2022-09-28T15:12:42Z","62226" +"*Visual-Studio-BOF-template*",".{0,1000}Visual\-Studio\-BOF\-template.{0,1000}","offensive_tool_keyword","cobaltstrike","A Visual Studio template used to create Cobalt Strike BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/securifybv/Visual-Studio-BOF-template","1","1","N/A","N/A","10","10","304","55","2021-11-17T12:03:42Z","2021-11-13T13:44:01Z","62227" +"*VITE_STRIKER_API*",".{0,1000}VITE_STRIKER_API.{0,1000}","offensive_tool_keyword","Striker","Striker is a simple Command and Control (C2) program.","T1071 - T1071.001 - T1071.004 - T1071.005 - T1071.006 - T1071.007 - T1071.008 - T1071.009 - T1071.010 - T1071.012 - T1071.013 - T1071.014 - T1071.015 - T1071.016 - T1071.018 - T1105 - T1105.002 - T1573 - T1573.002 - T1573.003 - T1573.004 - T1573.005","TA0002 - TA0003 - TA0004","N/A","N/A","C2","https://github.com/4g3nt47/Striker","1","1","N/A","N/A","10","10","301","42","2023-05-04T18:00:05Z","2022-09-07T10:09:41Z","62228" +"*ViziosDe/MDExclusionParser*",".{0,1000}ViziosDe\/MDExclusionParser.{0,1000}","offensive_tool_keyword","MDExclusionParser","PowerShell script to quickly scan Event Log ID 5007 and 1121 for published Windows Defender Exclusions and Attack Surface Reduction (ASR) rule configuration.","T1562.001","TA0005 - TA0007","N/A","N/A","Defense Evasion","https://github.com/ViziosDe/MDExclusionParser","1","1","N/A","N/A","5","1","6","1","2024-06-12T14:17:08Z","2024-06-12T11:56:07Z","62231" +"*vkvsgl7lhipjirmz6j5ubp3w3bwvxgcdbpi3fsbqngfynetqtw4w5hyd.onion*",".{0,1000}vkvsgl7lhipjirmz6j5ubp3w3bwvxgcdbpi3fsbqngfynetqtw4w5hyd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","62232" +"*vletoux/MakeMeEnterpriseAdmin*",".{0,1000}vletoux\/MakeMeEnterpriseAdmin.{0,1000}","offensive_tool_keyword","Amnesiac","Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments","T1021.002 - T1550.002","TA0008","N/A","Black Basta","Framework","https://github.com/Leo4j/Amnesiac","1","1","N/A","N/A","10","5","415","63","2025-03-18T09:32:04Z","2023-10-31T15:06:25Z","62233" +"*vletoux/NTLMInjector*",".{0,1000}vletoux\/NTLMInjector.{0,1000}","offensive_tool_keyword","NTLMInjector","restore the user password after a password reset (get the previous hash with DCSync)","T1555 - T1556.003 - T1078 - T1110.003 - T1201 - T1003","TA0001 - TA0003 - TA0004 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/vletoux/NTLMInjector","1","1","N/A","N/A","10","2","167","29","2017-06-08T19:01:21Z","2017-06-04T07:25:36Z","62234" +"*VMSA-2023-0001.py*",".{0,1000}VMSA\-2023\-0001\.py.{0,1000}","offensive_tool_keyword","vRealizeLogInsightRCE","POC for VMSA-2023-0001 affecting VMware vRealize Log Insight which includes the following CVEs: VMware vRealize Log Insight Directory Traversal Vulnerability (CVE-2022-31706) VMware vRealize Log Insight broken access control Vulnerability (CVE-2022-31704) VMware vRealize Log Insight contains an Information Disclosure Vulnerability (CVE-2022-31711)","T1190 - T1071 - T1003 - T1069 - T1110 - T1222","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007","N/A","Black Basta","Exploitation tool","https://github.com/horizon3ai/vRealizeLogInsightRCE","1","1","N/A","Added to cover the POC exploitation used in massive ransomware campagne that exploit public facing Vmware ESXI product ","4","2","149","22","2023-01-31T11:41:08Z","2023-01-30T22:01:08Z","62237" +"*vmware_view_planner*uploadlog_rce*",".{0,1000}vmware_view_planner.{0,1000}uploadlog_rce.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62240" +"*vmware_vrni_rce_cve_2023_20887.rb*",".{0,1000}vmware_vrni_rce_cve_2023_20887\.rb.{0,1000}","offensive_tool_keyword","POC","VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)","T1068 - T1190.001 - T1210.002 - T1059.001 - T1059.003 - T1190 - T1569.002","TA0005 - TA0002 - TA0001 - TA0040 - TA0043","N/A","N/A","Exploitation tool","https://github.com/sinsinology/CVE-2023-20887","1","1","N/A","N/A","N/A","3","232","43","2023-06-13T14:39:17Z","2023-06-13T13:17:23Z","62241" +"*vmware_workspace_one_access_cve_*.rb",".{0,1000}vmware_workspace_one_access_cve_.{0,1000}\.rb","offensive_tool_keyword","POC","POC for VMWARE CVE-2022-22954","T1190 - T1203 - T1068 - T1210","TA0001 - TA0002 - TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/rapid7/metasploit-framework/blob/62bfe03b50a22785b59a069319520531f2663b2b/modules/exploits/linux/http/vmware_workspace_one_access_cve_2022_22954.rb","1","1","N/A","N/A","N/A","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62242" +"*VMware-vRealize-Log-Insight.cert*",".{0,1000}VMware\-vRealize\-Log\-Insight\.cert.{0,1000}","offensive_tool_keyword","vRealizeLogInsightRCE","POC for VMSA-2023-0001 affecting VMware vRealize Log Insight which includes the following CVEs: VMware vRealize Log Insight Directory Traversal Vulnerability (CVE-2022-31706) VMware vRealize Log Insight broken access control Vulnerability (CVE-2022-31704) VMware vRealize Log Insight contains an Information Disclosure Vulnerability (CVE-2022-31711)","T1190 - T1071 - T1003 - T1069 - T1110 - T1222","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007","N/A","Black Basta","Exploitation tool","https://github.com/horizon3ai/vRealizeLogInsightRCE","1","1","N/A","Added to cover the POC exploitation used in massive ransomware campagne that exploit public facing Vmware ESXI product","4","2","149","22","2023-01-31T11:41:08Z","2023-01-30T22:01:08Z","62243" +"*vmx2john.py*",".{0,1000}vmx2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","62244" +"*vnc_password_osx.md*",".{0,1000}vnc_password_osx\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62246" +"*vnc_passwords.txt*",".{0,1000}vnc_passwords\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62247" +"*vncdumpdll*",".{0,1000}vncdumpdll.{0,1000}","offensive_tool_keyword","vncpwdump","vnc password sniffer","T1003.003 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.codebus.net/d-2v0u.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62248" +"*vncinject.rb*",".{0,1000}vncinject\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62249" +"*vncpcap2john.*",".{0,1000}vncpcap2john\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","62252" +"*vncpwdump.*",".{0,1000}vncpwdump\..{0,1000}","offensive_tool_keyword","vncpwdump","vnc password sniffer","T1003.003 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.codebus.net/d-2v0u.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62253" +"*vnperistence.py*",".{0,1000}vnperistence\.py.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","62261" +"*VolumeShadowCopyTools.ps1*",".{0,1000}VolumeShadowCopyTools\.ps1.{0,1000}","offensive_tool_keyword","Powersploit","PowerSploit contains a PowerShell script which utilizes the volume shadow copy service to create a new volume that could be used for extraction of files","T1003 - T1103 - T1213","TA0006 - TA0009 - TA0010","N/A","Dispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - Turla","Collection","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62265" +"*VolumeShadowCopyTools.ps1*",".{0,1000}VolumeShadowCopyTools\.ps1.{0,1000}","offensive_tool_keyword","PSAttack","PSAttack contains over 100 commands for Privilege Escalation - Recon and Data Exfilitration","T1059 - T1212 - T1012 - T1087 - T1005 - T1041 - T1020","TA0002 - TA0004 - TA0005 - TA0007 - TA0010 - TA0008","N/A","N/A","Exploitation tool","https://github.com/GDSSecurity/PSAttack","1","1","N/A","N/A","10","1","45","15","2017-04-04T20:37:33Z","2016-02-22T23:45:22Z","62266" +"*voukatas/Commander*",".{0,1000}voukatas\/Commander.{0,1000}","offensive_tool_keyword","Commander","A command and control (C2) server","T1021 - T1027 - T1059","TA0011 - TA0005 - TA0002","N/A","N/A","C2","https://github.com/voukatas/Commander","1","1","N/A","N/A","10","10","56","16","2024-07-05T11:05:30Z","2023-02-03T16:46:33Z","62269" +"*vpfxasdwnuewedfn.azurewebsites.net*",".{0,1000}vpfxasdwnuewedfn\.azurewebsites\.net.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","62271" +"*vRealizeLogInsightRCE*",".{0,1000}vRealizeLogInsightRCE.{0,1000}","offensive_tool_keyword","vRealizeLogInsightRCE","POC for VMSA-2023-0001 affecting VMware vRealize Log Insight which includes the following CVEs: VMware vRealize Log Insight Directory Traversal Vulnerability (CVE-2022-31706) VMware vRealize Log Insight broken access control Vulnerability (CVE-2022-31704) VMware vRealize Log Insight contains an Information Disclosure Vulnerability (CVE-2022-31711)","T1190 - T1071 - T1003 - T1069 - T1110 - T1222","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007","N/A","Black Basta","Exploitation tool","https://github.com/horizon3ai/vRealizeLogInsightRCE","1","1","N/A","Added to cover the POC exploitation used in massive ransomware campagne that exploit public facing Vmware ESXI product ","4","2","149","22","2023-01-31T11:41:08Z","2023-01-30T22:01:08Z","62275" +"*Vsaver-Rat v.0.1.exe*",".{0,1000}Vsaver\-Rat\sv\.0\.1\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","62280" +"*vssenum.x64.*",".{0,1000}vssenum\.x64\..{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","62293" +"*vssenum.x86.*",".{0,1000}vssenum\.x86\..{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","62294" +"*vtiger_crm_upload_exploit*",".{0,1000}vtiger_crm_upload_exploit.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","62296" +"*vulfocus/spring-core-rce-*",".{0,1000}vulfocus\/spring\-core\-rce\-.{0,1000}","offensive_tool_keyword","SpringCore0day","SpringCore0day from share.vx-underground.org & some additional links","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","N/A","Exploitation tool","https://github.com/craig/SpringCore0day","1","1","N/A","N/A","N/A","4","394","194","2022-03-31T11:54:22Z","2022-03-30T15:50:28Z","62297" +"*vulmon*Vulmap*",".{0,1000}vulmon.{0,1000}Vulmap.{0,1000}","offensive_tool_keyword","Vulmap","Vulmap is an open-source online local vulnerability scanner project. It consists of online local vulnerability scanning programs for Windows and Linux operating systems. These scripts can be used for defensive and offensive purposes. It is possible to make vulnerability assessments using these scripts. Also. they can be used for privilege escalation by pentesters/red teamers.","T1210.001 - T1190 - T1059 - T1213","TA0007 - TA0002 - TA0008 - TA0011","N/A","N/A","Vulnerability Scanner","https://github.com/vulmon/Vulmap","1","1","#linux #windows","N/A","10","10","965","194","2023-03-18T23:56:41Z","2018-09-07T15:49:36Z","62298" +"*Vulnerabilities/RPCDump*",".{0,1000}Vulnerabilities\/RPCDump.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","62299" +"*vulnfactory.org/exploits/*.c*",".{0,1000}vulnfactory\.org\/exploits\/.{0,1000}\.c.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","62301" +"*vulns/apache.txt*",".{0,1000}vulns\/apache\.txt.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","62302" +"*vulns/iis.txt*",".{0,1000}vulns\/iis\.txt.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","62303" +"*vulns/jrun.txt*",".{0,1000}vulns\/jrun\.txt.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","62304" +"*vulns/tomcat.txt*",".{0,1000}vulns\/tomcat\.txt.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","62305" +"*vulnweb.com/FUZZ*",".{0,1000}vulnweb\.com\/FUZZ.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","62306" +"*vu-ls/Crassus*",".{0,1000}vu\-ls\/Crassus.{0,1000}","offensive_tool_keyword","Crassus","Crassus Windows privilege escalation discovery tool","T1068 - T1003 - T1003.003 - T1046","TA0004 - TA0007","N/A","N/A","Privilege Escalation","https://github.com/vu-ls/Crassus","1","1","N/A","N/A","10","6","571","59","2024-11-08T14:11:39Z","2023-01-12T21:01:52Z","62308" +"*vxCrypt0r/Voidgate*",".{0,1000}vxCrypt0r\/Voidgate.{0,1000}","offensive_tool_keyword","Voidgate","bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes","T1027 - T1070 - T1055","TA0005","N/A","N/A","Defense Evasion","https://github.com/undergroundwires/privacy.sexy","1","1","N/A","N/A","9","10","4632","198","2025-04-21T21:36:39Z","2019-12-31T14:38:28Z","62310" +"*vyrus001/go-mimikatz*",".{0,1000}vyrus001\/go\-mimikatz.{0,1000}","offensive_tool_keyword","mimikatz","Mimikatz keywords and commands Well known to extract plaintexts passwords. hash. PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash. pass-the-ticket or build Golden tickets","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Exploitation tool","https://github.com/vyrus001/go-mimikatz","1","1","N/A","N/A","10","7","619","105","2022-09-08T18:14:20Z","2015-10-22T08:43:38Z","62312" +"*vysecurity/ANGRYPUPPY*",".{0,1000}vysecurity\/ANGRYPUPPY.{0,1000}","offensive_tool_keyword","cobaltstrike","Bloodhound Attack Path Automation in CobaltStrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/vysecurity/ANGRYPUPPY","1","1","N/A","N/A","10","10","316","87","2020-04-26T17:35:31Z","2017-07-11T14:18:07Z","62313" +"*vzzf6yg67cffqndnwg56e4psw45rup45f2mis7bwblg5fs7e5voagsqd.onion*",".{0,1000}vzzf6yg67cffqndnwg56e4psw45rup45f2mis7bwblg5fs7e5voagsqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","62314" +"*W2F1dG9ydW5dDQpzaGVsbGV4ZWN1dGU9eTMyNHNlZHguZXhlDQppY29uPSVTeXN0ZW1Sb290JVxzeXN0ZW0zMlxTSEVMTDMyLmRsbCw0DQphY3Rpb249T3BlbiBmb2xkZXIgdG8gdmlldyBmaWxlcw0Kc2hlbGxcZGVmYXVsdD1PcGVuDQpzaGVsbFxkZWZhdWx0XGNvbW1hbmQ9eTMyNHNlZHguZXhlDQpzaGVsbD1kZWZhdWx0*",".{0,1000}W2F1dG9ydW5dDQpzaGVsbGV4ZWN1dGU9eTMyNHNlZHguZXhlDQppY29uPSVTeXN0ZW1Sb290JVxzeXN0ZW0zMlxTSEVMTDMyLmRsbCw0DQphY3Rpb249T3BlbiBmb2xkZXIgdG8gdmlldyBmaWxlcw0Kc2hlbGxcZGVmYXVsdD1PcGVuDQpzaGVsbFxkZWZhdWx0XGNvbW1hbmQ9eTMyNHNlZHguZXhlDQpzaGVsbD1kZWZhdWx0.{0,1000}","offensive_tool_keyword","EDRaser","EDRaser is a powerful tool for remotely deleting access logs & Windows event logs & databases and other files on remote machines.","T1070.004 - T1027 - T1564.001","TA0005 - TA0040 - TA0003","N/A","N/A","Defense Evasion","https://github.com/SafeBreach-Labs/EDRaser","1","1","N/A","N/A","10","4","363","49","2024-04-06T17:42:40Z","2023-08-10T04:30:45Z","62326" +"*w32-speaking-shellcode.asm*",".{0,1000}w32\-speaking\-shellcode\.asm.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62335" +"*w32-speaking-shellcode.bin*",".{0,1000}w32\-speaking\-shellcode\.bin.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62336" +"*w32-speaking-shellcode-eaf.bin*",".{0,1000}w32\-speaking\-shellcode\-eaf\.bin.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62337" +"*WAF-bypass-Cheat-Sheet*",".{0,1000}WAF\-bypass\-Cheat\-Sheet.{0,1000}","offensive_tool_keyword","WAF-bypass-Cheat-Sheet","WAF/IPS/DLP bypass Cheat Sheet","T1210 - T1204 - T1061 - T1133 - T1190","TA0001 - TA0002 - TA0003","N/A","N/A","Defense Evasion","https://github.com/Bo0oM/WAF-bypass-Cheat-Sheet","1","1","N/A","N/A","N/A","5","422","65","2018-11-28T20:34:17Z","2018-11-28T19:34:02Z","62342" +"*wafw00f*",".{0,1000}wafw00f.{0,1000}","offensive_tool_keyword","wafw00f","To do its magic. WAFW00F does the following Sends a normal HTTP request and analyses the response. this identifies a number of WAF solutions. If that is not successful. it sends a number of (potentially malicious) HTTP requests and uses simple logic to deduce which WAF it is. If that is also not successful. it analyses the responses previously returned and uses another simple algorithm to guess if a WAF or security solution is actively responding to our attacks.","T1210.001 - T1190 - T1589","TA0007 - TA0002 - TA0008","N/A","N/A","Defense Evasion","https://github.com/EnableSecurity/wafw00f","1","1","N/A","N/A","N/A","10","5606","966","2024-12-31T06:49:33Z","2014-05-14T17:08:16Z","62344" +"*waleedassar/SimpleNTSyscallFuzzer*",".{0,1000}waleedassar\/SimpleNTSyscallFuzzer.{0,1000}","offensive_tool_keyword","SimpleNTSyscallFuzzer","Fuzzer for Windows kernel syscalls.","T1055.011 - T1218","TA0005 - TA0007","N/A","N/A","Discovery","https://github.com/waleedassar/SimpleNTSyscallFuzzer","1","1","N/A","N/A","7","2","145","25","2024-01-25T02:39:31Z","2022-03-12T10:16:30Z","62346" +"*wapiti.git*",".{0,1000}wapiti\.git.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","62353" +"*wapiti.py*",".{0,1000}wapiti\.py.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","62354" +"*wapiti3-*.tar.gz*",".{0,1000}wapiti3\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","62355" +"*wapiti3-*-any.whl*",".{0,1000}wapiti3\-.{0,1000}\-any\.whl.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","62356" +"*wapiti3/bin*",".{0,1000}wapiti3\/bin.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","62357" +"*wapiti-getcookie*",".{0,1000}wapiti\-getcookie.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","62358" +"*wappalyzer.py*",".{0,1000}wappalyzer\.py.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","62359" +"*warberry*",".{0,1000}warberry.{0,1000}","offensive_tool_keyword","warberry","WarBerryPi is a RaspberryPi based hardware implant that has the ability to go on stealth mode when used in acuiring informational data from a target network. especially useful during read teaming engagements. Its designed with a special feature that allows it to get the needed information within the shortest time possible. WarBerryPis scripts are designed in such way to avoid noise in the network as much as possible.","T1589 - T1539 - T1562","TA0002 - TA0003 - TA0007","N/A","N/A","Exploitation tool","https://github.com/secgroundzero/warberry","1","1","N/A","N/A","N/A","10","2223","289","2019-11-09T00:09:44Z","2016-05-10T16:25:03Z","62360" +"*warpzoneclient.cpp*",".{0,1000}warpzoneclient\.cpp.{0,1000}","offensive_tool_keyword","elevationstation","elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","62361" +"*warpzoneclient.exe*",".{0,1000}warpzoneclient\.exe.{0,1000}","offensive_tool_keyword","elevationstation","elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","62362" +"*warpzoneclient.exe*",".{0,1000}warpzoneclient\.exe.{0,1000}","offensive_tool_keyword","elevationstation","elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","62363" +"*warpzoneclient.sln*",".{0,1000}warpzoneclient\.sln.{0,1000}","offensive_tool_keyword","elevationstation","elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","62364" +"*warpzoneclient.vcxproj*",".{0,1000}warpzoneclient\.vcxproj.{0,1000}","offensive_tool_keyword","elevationstation","elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative","T1548.002 - T1055 - T1574.002 - T1078.003","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/g3tsyst3m/elevationstation","1","1","N/A","N/A","N/A","4","368","45","2023-11-02T23:52:51Z","2023-06-10T03:30:59Z","62365" +"*washingtonP1974/Rev-Shell*",".{0,1000}washingtonP1974\/Rev\-Shell.{0,1000}","offensive_tool_keyword","Rev-Shell","Basic script to generate reverse shell payloads","T1055.011 - T1021.005 - T1560.001","TA0002 - TA0005 - TA0042 - TA0011","N/A","N/A","C2","https://github.com/washingtonP1974/Rev-Shell","1","1","N/A","N/A","3","10","29","1","2024-03-20T13:58:21Z","2024-03-20T13:37:12Z","62366" +"*WatermelonMakeup.azurewebsites.net*",".{0,1000}WatermelonMakeup\.azurewebsites\.net.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","62368" +"*wavestone-cdt/EDRSandblast*",".{0,1000}wavestone\-cdt\/EDRSandblast.{0,1000}","offensive_tool_keyword","EDRSandBlast","EDRSandBlast is a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections","T1547.002 - T1055.001 - T1205","TA0004 - TA0005","N/A","COZY BEAR","Defense Evasion","https://github.com/wavestone-cdt/EDRSandblast","1","1","N/A","N/A","10","10","1633","292","2024-08-30T20:30:31Z","2021-11-02T15:02:42Z","62369" +"*wavestone-cdt/Invoke-CleverSpray*",".{0,1000}wavestone\-cdt\/Invoke\-CleverSpray.{0,1000}","offensive_tool_keyword","Invoke-CleverSpray","Password Spraying Script detecting current and previous passwords of Active Directory User","T1110.003 - T1110.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/wavestone-cdt/Invoke-CleverSpray","1","1","N/A","N/A","10","1","65","11","2021-09-09T07:35:32Z","2018-11-29T10:05:25Z","62370" +"*wavvs/nanorobeus*",".{0,1000}wavvs\/nanorobeus.{0,1000}","offensive_tool_keyword","nanorobeus","COFF file (BOF) for managing Kerberos tickets.","T1558.003 - T1208","TA0006 - TA0007","N/A","N/A","C2","https://github.com/wavvs/nanorobeus","1","1","N/A","N/A","10","10","294","31","2023-07-02T12:56:27Z","2022-07-04T00:33:30Z","62371" +"*waza1234*",".{0,1000}waza1234.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation default password","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","62374" +"*WazeHell/sam-the-admin*",".{0,1000}WazeHell\/sam\-the\-admin.{0,1000}","offensive_tool_keyword","POC","POC exploitation for CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user","T1548 - T1134 - T1078.002 - T1078","TA0003 - TA0008 - TA0002","N/A","N/A","Exploitation tool","https://github.com/WazeHell/sam-the-admin/tree/main/utils","1","1","N/A","N/A","N/A","10","1012","193","2022-07-10T22:23:13Z","2021-12-11T15:10:30Z","62376" +"*wce*getlsasrvaddr.exe*",".{0,1000}wce.{0,1000}getlsasrvaddr\.exe.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","1","N/A","N/A","8","4","N/A","N/A","N/A","N/A","62385" +"*wce-master.zip*",".{0,1000}wce\-master\.zip.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","1","N/A","N/A","8","4","N/A","N/A","N/A","N/A","62386" +"*wce-universal.exe*",".{0,1000}wce\-universal\.exe.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","1","N/A","N/A","8","4","N/A","N/A","N/A","N/A","62387" +"*wcfrelayserver.py*",".{0,1000}wcfrelayserver\.py.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File (BOF) to obtain a usable TGT for the current user and does not require elevated privileges on the host","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/connormcgarr/tgtdelegation","1","1","N/A","N/A","10","10","173","24","2021-11-26T16:45:05Z","2021-11-22T18:42:57Z","62388" +"*wcfrelayserver.py*",".{0,1000}wcfrelayserver\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","62389" +"*WCMCredentials.txt*",".{0,1000}WCMCredentials\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","62390" +"*WDExtract-master*",".{0,1000}WDExtract\-master.{0,1000}","offensive_tool_keyword","WDExtract","Extract Windows Defender database from vdm files and unpack it","T1059 - T1005 - T1119","TA0002 - TA0009 - TA0003","N/A","N/A","Defense Evasion","https://github.com/hfiref0x/WDExtract/","1","1","N/A","N/A","8","5","440","61","2020-02-10T06:53:43Z","2019-04-19T17:33:48Z","62393" +"*wdigest!g_fParameter_UseLogonCredential*",".{0,1000}wdigest!g_fParameter_UseLogonCredential.{0,1000}","offensive_tool_keyword","cobaltstrike","A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/WdToggle","1","1","N/A","N/A","10","10","219","31","2023-05-03T19:51:43Z","2020-12-23T13:42:25Z","62395" +"*wdigest!g_IsCredGuardEnabled*",".{0,1000}wdigest!g_IsCredGuardEnabled.{0,1000}","offensive_tool_keyword","cobaltstrike","A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/outflanknl/WdToggle","1","1","N/A","N/A","10","10","219","31","2023-05-03T19:51:43Z","2020-12-23T13:42:25Z","62396" +"*wdigest/decryptor.py*",".{0,1000}wdigest\/decryptor\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","62397" +"*weak1337/Alcatraz*",".{0,1000}weak1337\/Alcatraz.{0,1000}","offensive_tool_keyword","Alcatraz","x64 binary obfuscator","T1027 - T1140","TA0004 - TA0042","N/A","N/A","Defense Evasion","https://github.com/weak1337/Alcatraz","1","1","N/A","N/A","10","10","1808","267","2023-07-14T14:19:01Z","2022-12-21T17:27:56Z","62406" +"*weakpass.com/crack-js*",".{0,1000}weakpass\.com\/crack\-js.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","62407" +"*weakpass.com/generate*",".{0,1000}weakpass\.com\/generate.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","62408" +"*weakpass.com/wordlist/*",".{0,1000}weakpass\.com\/wordlist\/.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","62409" +"*weakpass/crack-js*",".{0,1000}weakpass\/crack\-js.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","62410" +"*weakpass_3.7z*",".{0,1000}weakpass_3\.7z.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","62411" +"*weakpass_3a.7z.torrent*",".{0,1000}weakpass_3a\.7z\.torrent.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","62412" +"*weakpass-main.*",".{0,1000}weakpass\-main\..{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","62413" +"*web_cloner/interceptor*",".{0,1000}web_cloner\/interceptor.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","62416" +"*webapi/nemesis_api.py*",".{0,1000}webapi\/nemesis_api\.py.{0,1000}","offensive_tool_keyword","nemesis","An offensive data enrichment pipeline","T1592 - T1583 - T1595 - T1590","TA0042 - TA0043","N/A","Black Basta","Resource Development","https://github.com/SpecterOps/Nemesis","1","1","N/A","N/A","9","7","672","65","2025-04-17T21:55:10Z","2023-07-13T18:24:24Z","62418" +"*WebBrowserPassView.cfg*",".{0,1000}WebBrowserPassView\.cfg.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","62420" +"*WebBrowserPassView.exe*",".{0,1000}WebBrowserPassView\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","62421" +"*WebBrowserPassView.exe*",".{0,1000}WebBrowserPassView\.exe.{0,1000}","offensive_tool_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62422" +"*WebBrowserPassView.pdb*",".{0,1000}WebBrowserPassView\.pdb.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","62423" +"*WebBrowserPassView.zip*",".{0,1000}WebBrowserPassView\.zip.{0,1000}","offensive_tool_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62424" +"*webcam-capture-0.3.10.jar*",".{0,1000}webcam\-capture\-0\.3\.10\.jar.{0,1000}","offensive_tool_keyword","saint","(s)AINT is a Spyware Generator for Windows systems written in Java","T1056.001 - T1125 - T1123 - T1113 - T1105 - T1573.001","TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","C2","https://github.com/tiagorlampert/sAINT","1","1","N/A","N/A","10","10","712","311","2020-04-03T14:34:34Z","2017-11-18T18:43:25Z","62425" +"*web-hacking-toolkit.git*",".{0,1000}web\-hacking\-toolkit\.git.{0,1000}","offensive_tool_keyword","web-hacking-toolkit","A web hacking toolkit Docker image with GUI applications support.","T1210 - T1059 - T1105 - T1189 - T1071","TA0001 - TA0002 - TA0011 - TA0005","N/A","N/A","Exploitation tool","https://github.com/signedsecurity/web-hacking-toolkit","1","1","N/A","N/A","N/A","","N/A","","","","62433" +"*webinject64.dll*",".{0,1000}webinject64\.dll.{0,1000}","offensive_tool_keyword","Pyramid","a tool to help operate in EDRs' blind spots","T1055 - T1106 - T1127 - T1129 - T1559","TA0002 - TA0005 - TA0003","N/A","Black Basta","Defense Evasion","https://github.com/naksyn/Pyramid","1","1","N/A","N/A","10","8","727","89","2024-12-02T04:08:53Z","2022-08-13T11:51:37Z","62435" +"*Webremote TorCT Client.exe*",".{0,1000}Webremote\sTorCT\sClient\.exe.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","62436" +"*webshell_execute*",".{0,1000}webshell_execute.{0,1000}","offensive_tool_keyword","Ninja","Open source C2 server created for stealth red team operations","T1021 - T1055 - T1071 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","Black Basta","C2","https://github.com/ahmedkhlief/Ninja","1","1","N/A","N/A","10","10","806","170","2022-09-26T16:07:43Z","2020-03-04T14:17:22Z","62438" +"*WebSocketReverseShellDotNet*",".{0,1000}WebSocketReverseShellDotNet.{0,1000}","offensive_tool_keyword","WebSocketReverseShellDotNet","A .NET-based Reverse Shell, it establishes a link to the command and control for subsequent guidance.","T1071 - T1105","TA0011 - TA0002","N/A","N/A","C2","https://github.com/The-Hustler-Hattab/WebSocketReverseShellDotNet","1","1","N/A","N/A","10","10","1","0","2024-04-18T01:00:48Z","2023-12-03T03:35:24Z","62440" +"*weg7sdx54bevnvulapqu6bpzwztryeflq3s23tegbmnhkbpqz637f2yd.onion*",".{0,1000}weg7sdx54bevnvulapqu6bpzwztryeflq3s23tegbmnhkbpqz637f2yd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","62445" +"*wemo2ysyeq6km2nqhcrz63dkdhez3j25yw2nvn7xba2z4h7v7gyrfgid.onion*",".{0,1000}wemo2ysyeq6km2nqhcrz63dkdhez3j25yw2nvn7xba2z4h7v7gyrfgid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","62451" +"*werdhaihai/AtlasReaper*",".{0,1000}werdhaihai\/AtlasReaper.{0,1000}","offensive_tool_keyword","AtlasReaper","A command-line tool for reconnaissance and targeted write operations on Confluence and Jira instances.","T1210.002 - T1078.003 - T1046 ","TA0001 - TA0007 - TA0040","N/A","N/A","Reconnaissance","https://github.com/werdhaihai/AtlasReaper","1","1","N/A","N/A","3","3","255","28","2023-09-14T23:50:33Z","2023-06-24T00:18:41Z","62453" +"*werfault_shtinkering*",".{0,1000}werfault_shtinkering.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","62454" +"*werfault_silent_process_exit*",".{0,1000}werfault_silent_process_exit.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","62455" +"*WerTrigger.exe*",".{0,1000}WerTrigger\.exe.{0,1000}","offensive_tool_keyword","WerTrigger","Weaponizing for privileged file writes bugs with windows problem reporting","T1059.003 - T1055.001 - T1127.001 - T1546.008","TA0002 - TA0004 ","N/A","N/A","Privilege Escalation","https://github.com/sailay1996/WerTrigger","1","1","N/A","N/A","9","3","221","36","2022-05-10T17:36:49Z","2020-05-20T11:27:56Z","62456" +"*WerTrigger-master*",".{0,1000}WerTrigger\-master.{0,1000}","offensive_tool_keyword","WerTrigger","Weaponizing for privileged file writes bugs with windows problem reporting","T1059.003 - T1055.001 - T1127.001 - T1546.008","TA0002 - TA0004 ","N/A","N/A","Privilege Escalation","https://github.com/sailay1996/WerTrigger","1","1","N/A","N/A","9","3","221","36","2022-05-10T17:36:49Z","2020-05-20T11:27:56Z","62457" +"*wfencode.bat*",".{0,1000}wfencode\.bat.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","62509" +"*wfencode.py*",".{0,1000}wfencode\.py.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","62510" +"*wfpayload.bat*",".{0,1000}wfpayload\.bat.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","62512" +"*wfpayload.py*",".{0,1000}wfpayload\.py.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","62513" +"*WfpEscalation.exe*",".{0,1000}WfpEscalation\.exe.{0,1000}","offensive_tool_keyword","NoFilter","Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.","T1548 - T1548.002 - T1055 - T1055.004","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/deepinstinct/NoFilter","1","1","N/A","N/A","9","3","298","48","2024-10-29T07:30:35Z","2023-07-30T09:25:38Z","62514" +"*WfpTokenDup.exe*",".{0,1000}WfpTokenDup\.exe.{0,1000}","offensive_tool_keyword","PrivFu","ArtsOfGetSystem privesc tools","T1134 - T1134.001 - T1078 - T1059 - T1075","TA0004","N/A","N/A","Privilege Escalation","https://github.com/daem0nc0re/PrivFu/","1","1","N/A","ArtsOfGetSystem","10","9","849","122","2025-01-21T05:22:50Z","2021-12-28T13:14:25Z","62516" +"*wfuzz.bat*",".{0,1000}wfuzz\.bat.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","62518" +"*wfuzz.py*",".{0,1000}wfuzz\.py.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","62520" +"*wfuzz/wordlist*",".{0,1000}wfuzz\/wordlist.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","62522" +"*wfuzz-cli.py*",".{0,1000}wfuzz\-cli\.py.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","62523" +"*wfuzzp.py*",".{0,1000}wfuzzp\.py.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","62524" +"*Wh04m1001/DFSCoerce*",".{0,1000}Wh04m1001\/DFSCoerce.{0,1000}","offensive_tool_keyword","DFSCoerce","PoC for MS-DFSNM coerce authentication using NetrDfsRemoveStdRoot and NetrDfsAddStdRoot?","T1550.001 - T1078.003 - T1046","TA0002 - TA0007 - TA0040","N/A","Dispossessor","Exploitation tool","https://github.com/Wh04m1001/DFSCoerce","1","1","N/A","N/A","10","8","769","98","2022-09-09T17:45:41Z","2022-06-18T12:38:37Z","62536" +"*wh0amitz/BypassCredGuard*",".{0,1000}wh0amitz\/BypassCredGuard.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","1","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","62537" +"*wh0amitz/KRBUACBypass*",".{0,1000}wh0amitz\/KRBUACBypass.{0,1000}","offensive_tool_keyword","KRBUACBypass","UAC Bypass By Abusing Kerberos Tickets","T1548.002 - T1558 - T1558.003","TA0004 - TA0006","N/A","N/A","Defense Evasion","https://github.com/wh0amitz/KRBUACBypass","1","1","N/A","N/A","8","5","496","62","2023-08-10T02:51:59Z","2023-07-27T12:08:12Z","62538" +"*wh0amitz/PetitPotato*",".{0,1000}wh0amitz\/PetitPotato.{0,1000}","offensive_tool_keyword","PetitPotato","Local privilege escalation via PetitPotam (Abusing impersonate privileges)","T1134.005 - T1548.001","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/wh0amitz/PetitPotato","1","1","N/A","N/A","10","5","430","52","2023-03-30T10:45:00Z","2022-04-19T19:59:19Z","62539" +"*wh0amitz/S4UTomato*",".{0,1000}wh0amitz\/S4UTomato.{0,1000}","offensive_tool_keyword","S4UTomato","Escalate Service Account To LocalSystem via Kerberos","T1558 - T1558.002 - T1548.002 - T1078 - T1078.004","TA0006 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/wh0amitz/S4UTomato","1","1","N/A","N/A","10","4","394","76","2023-09-14T08:53:19Z","2023-07-30T11:51:57Z","62540" +"*wh0amitz/SharpADWS*",".{0,1000}wh0amitz\/SharpADWS.{0,1000}","offensive_tool_keyword","SharpADWS","SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)","T1087 - T1069 - T1018 - T1083 - T1595","TA0001 - TA0002 - TA0007","N/A","N/A","Discovery","https://github.com/wh0amitz/SharpADWS","1","1","N/A","N/A","7","6","538","59","2024-03-19T08:57:52Z","2024-02-13T17:28:00Z","62541" +"*wh0amitz/SharpRODC*",".{0,1000}wh0amitz\/SharpRODC.{0,1000}","offensive_tool_keyword","SharpRODC","audit the security of read-only domain controllers","T1012 - T1482 - T1207 - T1208 - T1209 - T1212","TA0007 - TA0008 - TA0006","N/A","N/A","Discovery","https://github.com/wh0amitz/SharpRODC","1","1","N/A","N/A","8","2","115","8","2023-11-27T12:41:52Z","2023-11-24T14:35:49Z","62542" +"*Wh1t3Fox/polenum*",".{0,1000}Wh1t3Fox\/polenum.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","62543" +"*whatlicense-main.zip*",".{0,1000}whatlicense\-main\.zip.{0,1000}","offensive_tool_keyword","whatlicense","WinLicense key extraction via Intel PIN","T1056 - T1056.001 - T1518 - T1518.001","TA0005 - TA0006","N/A","N/A","Exploitation tool","https://github.com/charlesnathansmith/whatlicense","1","1","N/A","N/A","6","2","101","25","2024-04-09T05:30:56Z","2023-07-10T11:57:44Z","62545" +"*whereami.cna*",".{0,1000}whereami\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object File (BOF) that uses handwritten shellcode to return the process Environment strings without touching any DLL's.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/whereami","1","1","N/A","N/A","10","10","172","27","2023-03-13T15:56:38Z","2021-08-19T22:32:34Z","62549" +"*whereami.x64*",".{0,1000}whereami\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object File (BOF) that uses handwritten shellcode to return the process Environment strings without touching any DLL's.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/whereami","1","1","N/A","N/A","10","10","172","27","2023-03-13T15:56:38Z","2021-08-19T22:32:34Z","62550" +"*WheresMyImplant.cs*",".{0,1000}WheresMyImplant\.cs.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","62551" +"*WheresMyImplant.git*",".{0,1000}WheresMyImplant\.git.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","62552" +"*WheresMyImplant.sln*",".{0,1000}WheresMyImplant\.sln.{0,1000}","offensive_tool_keyword","WheresMyImplant","A Bring Your Own Land Toolkit that Doubles as a WMI Provider","T1055 - T1027 - T1045 - T1105 - T1132 - T1021 - T1124 - T1005 - T1071","TA0002 - TA0004 - TA0005 - TA0007 - TA0008 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/0xbadjuju/WheresMyImplant","1","1","N/A","N/A","10","10","285","58","2018-10-31T16:56:51Z","2017-09-22T19:40:40Z","62553" +"*Whirlpool-Orig-512.verified.test-vectors.txt*",".{0,1000}Whirlpool\-Orig\-512\.verified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","62556" +"*Whirlpool-Tweak-512.verified.test-vectors.txt*",".{0,1000}Whirlpool\-Tweak\-512\.verified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","62557" +"*Whisker.exe*",".{0,1000}Whisker\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","62561" +"*whiskeysaml.py*",".{0,1000}whiskeysaml\.py.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","62562" +"*whiskeysamlandfriends*",".{0,1000}whiskeysamlandfriends.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","62563" +"*Whitecat18/Rust-for-Malware-Development*",".{0,1000}Whitecat18\/Rust\-for\-Malware\-Development.{0,1000}","offensive_tool_keyword","Rust-for-Malware-Development","malware development using Rust","T1055.001 - T1027 - T1204 - T1518 - T1056 - T1021 - T1587/001","TA0005 - TA0003 - TA0007 - TA0009 - TA0004 - TA0008 - TA0042","N/A","N/A","Exploitation tool","https://github.com/Whitecat18/Rust-for-Malware-Development","1","1","N/A","N/A","8","10","2123","53","2025-04-22T18:09:57Z","2024-02-12T16:55:06Z","62564" +"*WhiteOakSecurity/GoAWSConsoleSpray*",".{0,1000}WhiteOakSecurity\/GoAWSConsoleSpray.{0,1000}","offensive_tool_keyword","GoAWSConsoleSpray","brute-force AWS IAM Console credentials to discover valid logins for user accounts","T1078 - T1110 - T1187 - T1110.001","TA0006 - TA0007 - TA0003 - TA0001","N/A","N/A","Credential Access","https://github.com/WhiteOakSecurity/GoAWSConsoleSpray","1","1","N/A","N/A","9","1","29","5","2022-06-15T18:16:21Z","2022-06-15T18:11:39Z","62565" +"*whoami.nim*",".{0,1000}whoami\.nim.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","62574" +"*WhoamiGetTokenInfo*",".{0,1000}WhoamiGetTokenInfo.{0,1000}","offensive_tool_keyword","cobaltstrike","Situational Awareness commands implemented using Beacon Object Files","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/trustedsec/CS-Situational-Awareness-BOF","1","1","N/A","N/A","10","10","1389","234","2025-03-26T19:36:31Z","2020-07-15T16:21:18Z","62576" +"*wietze/Invoke-ArgFuscator*",".{0,1000}wietze\/Invoke\-ArgFuscator.{0,1000}","offensive_tool_keyword","Invoke-ArgFuscator","generate obfuscated command-lines for common system-native executables","T1027 - T1059 - T1202","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/wietze/Invoke-ArgFuscator","1","1","N/A","N/A","10","2","161","28","2025-04-14T21:24:29Z","2022-11-20T17:59:23Z","62580" +"*wifi/airpwn*",".{0,1000}wifi\/airpwn.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62581" +"*wifi/dnspwn*",".{0,1000}wifi\/dnspwn.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62582" +"*wifi_dump_linux*",".{0,1000}wifi_dump_linux.{0,1000}","offensive_tool_keyword","venom","venom - C2 shellcode generator/compiler/handler","T1027 - T1055 - T1071 - T1505 - T1566 - T1570","TA0001 - TA0002 - TA0003 - TA0008 - TA0010","N/A","N/A","Resource Development","https://github.com/r00t-3xp10it/venom","1","1","#linux","N/A","N/A","10","1852","601","2023-12-09T00:42:22Z","2016-11-16T10:40:04Z","62585" +"*wifi_fake_auth.*",".{0,1000}wifi_fake_auth\..{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","62586" +"*WiFi_Hacker.ino*",".{0,1000}WiFi_Hacker\.ino.{0,1000}","offensive_tool_keyword","Pateensy","payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy","T1056.001 - T1200 - T1036 - T1071","TA0002 - TA0005 - TA0011 - TA0006","N/A","N/A","Exploitation tool","https://github.com/screetsec/Pateensy","1","1","N/A","N/A","N/A","2","143","60","2017-01-26T12:02:56Z","2016-03-21T07:29:38Z","62587" +"*wifi_pineapple_csrf*",".{0,1000}wifi_pineapple_csrf.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","62588" +"*wifi_recon_handshakes*",".{0,1000}wifi_recon_handshakes.{0,1000}","offensive_tool_keyword","bettercap","The Swiss Army knife for 802.11 - BLE - IPv4 and IPv6 networks reconnaissance and MITM attacks.","T1046 - T1190 - T1059 - T1053 - T1001.002 - T1110.001 - T1113 - T1132 - T1048","TA0010 - TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011 - TA0010","N/A","N/A","Sniffing & Spoofing","https://github.com/bettercap/bettercap","1","1","#linux","network exploitation tool","10","10","17525","1526","2025-04-16T22:28:20Z","2018-01-07T15:30:41Z","62589" +"*wifibroot.py*",".{0,1000}wifibroot\.py.{0,1000}","offensive_tool_keyword","wifibroot","A Wireless (WPA/WPA2) Pentest/Cracking tool. Captures & Crack 4-way handshake and PMKID key. Also. supports a deauthentication/jammer mode for stress testing","T1018 - T1040 - T1095 - T1113 - T1210 - T1437 - T1499 - T1557 - T1562 - T1573","TA0001 - TA0002 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://github.com/hash3liZer/WiFiBroot","1","1","N/A","network exploitation tool","N/A","10","1008","182","2021-01-15T09:07:36Z","2018-07-30T10:57:22Z","62590" +"*wifi-bruteforcer*",".{0,1000}wifi\-bruteforcer.{0,1000}","offensive_tool_keyword","wifi-bruteforcer-fsecurify","Android application to brute force WiFi passwords without requiring a rooted device.","T1110 - T1555 - T1051 - T1081","TA0002 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/faizann24/wifi-bruteforcer-fsecurify","1","1","N/A","network exploitation tool","N/A","10","1324","319","2022-04-16T02:59:36Z","2017-01-02T17:54:33Z","62591" +"*wifi-bruteforcer*",".{0,1000}wifi\-bruteforcer.{0,1000}","offensive_tool_keyword","wifi-bruteforcer-fsecurity","Wifi bruteforcer","T1110 - T1114 - T1601 - T1602 - T1603","TA0003 - TA0008","N/A","N/A","Credential Access","https://github.com/faizann24/wifi-bruteforcer-fsecurify","1","1","N/A","network exploitation tool","N/A","10","1324","319","2022-04-16T02:59:36Z","2017-01-02T17:54:33Z","62592" +"*wifidump.cna*",".{0,1000}wifidump\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Various Cobalt Strike BOFs","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rvrsh3ll/BOF_Collection","1","1","N/A","N/A","10","10","635","57","2022-10-16T13:57:18Z","2020-07-16T18:24:55Z","62593" +"*wifijammer*",".{0,1000}wifijammer.{0,1000}","offensive_tool_keyword","wifijammer","wifijammer","T1497 - T1498 - T1531","TA0001 - TA0040","N/A","N/A","Exploitation tool","https://github.com/DanMcInerney/wifijammer","1","1","N/A","network exploitation tool","N/A","10","4082","790","2024-07-20T02:47:48Z","2014-01-26T07:54:39Z","62594" +"*WifiPasswords.ps1*",".{0,1000}WifiPasswords\.ps1.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","62595" +"*wifiphisher*",".{0,1000}wifiphisher.{0,1000}","offensive_tool_keyword","wifiphisher","The Rogue Access Point Framework.","T1553.003 - T1562 - T1539","TA0002 - TA0007 - ","N/A","N/A","Framework","https://github.com/wifiphisher/wifiphisher","1","1","N/A","N/A","N/A","10","13758","2642","2025-02-04T21:04:05Z","2014-09-26T12:47:28Z","62596" +"*WiFi-Pumpkin*",".{0,1000}WiFi\-Pumpkin.{0,1000}","offensive_tool_keyword","WiFi-Pumpkin","Framework for Rogue Wi-Fi Access Point Attack.","T1562 - T1530 - T1552 - T1553 - T1561","TA0005 - TA0006 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/P0cL4bs/WiFi-Pumpkin","1","1","N/A","N/A","N/A","10","3121","722","2020-04-18T19:32:52Z","2015-06-27T00:56:21Z","62597" +"*Wifite.py*",".{0,1000}Wifite\.py.{0,1000}","offensive_tool_keyword","wifite2","This repo is a complete re-write of wifite. a Python script for auditing wireless networks.Run wifite. select your targets. and Wifite will automatically start trying to capture or crack the password.","T1590 - T1170 - T1595","TA0002 - TA0003 - TA0007","N/A","N/A","Credential Access","https://github.com/derv82/wifite2","1","1","N/A","network exploitation tool","N/A","10","6838","1403","2024-08-20T12:34:38Z","2015-05-30T06:09:52Z","62603" +"*wifite2.git*",".{0,1000}wifite2\.git.{0,1000}","offensive_tool_keyword","wifite2","This repo is a complete re-write of wifite. a Python script for auditing wireless networks.Run wifite. select your targets. and Wifite will automatically start trying to capture or crack the password.","T1590 - T1170 - T1595","TA0002 - TA0003 - TA0007","N/A","N/A","Credential Access","https://github.com/derv82/wifite2","1","1","N/A","network exploitation tool","N/A","10","6838","1403","2024-08-20T12:34:38Z","2015-05-30T06:09:52Z","62604" +"*willfindlay/bpf-keylogger*",".{0,1000}willfindlay\/bpf\-keylogger.{0,1000}","offensive_tool_keyword","bpf-keylogger","Keylogger written in BPF","T1056.001 - T1053.005","TA0006 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/willfindlay/bpf-keylogger","1","1","N/A","N/A","10","1","2","2","2020-01-13T20:17:02Z","2019-12-25T16:27:28Z","62607" +"*win_chrome_password_extractor.py*",".{0,1000}win_chrome_password_extractor\.py.{0,1000}","offensive_tool_keyword","C2_Server","C2 server to connect to a victim machine via reverse shell","T1090 - T1090.001 - T1071 - T1071.001","TA0011 ","N/A","N/A","C2","https://github.com/reveng007/C2_Server","1","1","N/A","N/A","10","10","54","18","2022-02-27T02:00:02Z","2021-03-05T12:35:45Z","62619" +"*win_fake_malware.*",".{0,1000}win_fake_malware\..{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","62620" +"*win_keylogger.py*",".{0,1000}win_keylogger\.py.{0,1000}","offensive_tool_keyword","C2_Server","C2 server to connect to a victim machine via reverse shell","T1090 - T1090.001 - T1071 - T1071.001","TA0011 ","N/A","N/A","C2","https://github.com/reveng007/C2_Server","1","1","N/A","N/A","10","10","54","18","2022-02-27T02:00:02Z","2021-03-05T12:35:45Z","62621" +"*win_rev_http.exe*",".{0,1000}win_rev_http\.exe.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","62622" +"*win_rev_https.exe*",".{0,1000}win_rev_https\.exe.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","62623" +"*win_rev_tcp.exe*",".{0,1000}win_rev_tcp\.exe.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","62624" +"*win_wlan_passwd_and_wanip_extractor.py*",".{0,1000}win_wlan_passwd_and_wanip_extractor\.py.{0,1000}","offensive_tool_keyword","C2_Server","C2 server to connect to a victim machine via reverse shell","T1090 - T1090.001 - T1071 - T1071.001","TA0011 ","N/A","N/A","C2","https://github.com/reveng007/C2_Server","1","1","N/A","N/A","10","10","54","18","2022-02-27T02:00:02Z","2021-03-05T12:35:45Z","62625" +"*win32_stage_boot_reverse_shell_revert.asm*",".{0,1000}win32_stage_boot_reverse_shell_revert\.asm.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62652" +"*win32_stage_uploadexec.asm*",".{0,1000}win32_stage_uploadexec\.asm.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62653" +"*win32_stage_winexec.asm*",".{0,1000}win32_stage_winexec\.asm.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62654" +"*Win32kLeaker.*",".{0,1000}Win32kLeaker\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62655" +"*Win7Elevate.*",".{0,1000}Win7Elevate\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62673" +"*Win7ElevateDll.*",".{0,1000}Win7ElevateDll\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62674" +"*WinBruteLogon.dpr*",".{0,1000}WinBruteLogon\.dpr.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","1","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","62677" +"*WinBruteLogon.dproj*",".{0,1000}WinBruteLogon\.dproj.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","1","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","62678" +"*WinBruteLogon.exe*",".{0,1000}WinBruteLogon\.exe.{0,1000}","offensive_tool_keyword","redpill","Assist reverse tcp shells in post-exploration tasks","T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003","TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/r00t-3xp10it/redpill","1","1","N/A","N/A","10","3","218","52","2024-03-19T15:03:16Z","2021-02-20T23:59:07Z","62679" +"*WinBruteLogon.exe*",".{0,1000}WinBruteLogon\.exe.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","1","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","62680" +"*WinBruteLogon.exe*",".{0,1000}WinBruteLogon\.exe.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","1","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","62681" +"*WinBruteLogon.res*",".{0,1000}WinBruteLogon\.res.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","1","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","62682" +"*win-brute-logon-master.zip*",".{0,1000}win\-brute\-logon\-master\.zip.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","1","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","62683" +"*WinCreds.exe*",".{0,1000}WinCreds\.exe.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","62684" +"*windapsearch.py*",".{0,1000}windapsearch\.py.{0,1000}","offensive_tool_keyword","windapsearch","Python script to enumerate users - groups and computers from a Windows domain through LDAP queries","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/ropnop/windapsearch","1","1","N/A","AD Enumeration","7","9","866","154","2022-04-20T07:40:42Z","2016-08-10T21:43:30Z","62686" +"*windapsearch_enum*",".{0,1000}windapsearch_enum.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","62687" +"*windapsearch_py2.py*",".{0,1000}windapsearch_py2\.py.{0,1000}","offensive_tool_keyword","windapsearch","Python script to enumerate users - groups and computers from a Windows domain through LDAP queries","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/ropnop/windapsearch","1","1","N/A","AD Enumeration","7","9","866","154","2022-04-20T07:40:42Z","2016-08-10T21:43:30Z","62688" +"*windapsearch-master*",".{0,1000}windapsearch\-master.{0,1000}","offensive_tool_keyword","windapsearch","Python script to enumerate users - groups and computers from a Windows domain through LDAP queries","T1087.002 - T1018 - T1069.002","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/ropnop/windapsearch","1","1","N/A","AD Enumeration","7","9","866","154","2022-04-20T07:40:42Z","2016-08-10T21:43:30Z","62689" +"*WinDefenderKiller*",".{0,1000}WinDefenderKiller.{0,1000}","offensive_tool_keyword","WinDefenderKiller","Windows Defender Killer | C++ Code Disabling Permanently Windows Defender using Registry Keys","T1562.001 - T1055.002 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/S12cybersecurity/WinDefenderKiller","1","1","N/A","N/A","10","5","448","67","2023-07-27T11:06:24Z","2023-07-25T10:32:25Z","62690" +"*winDefKiller.exe*",".{0,1000}winDefKiller\.exe.{0,1000}","offensive_tool_keyword","WinDefenderKiller","Windows Defender Killer | C++ Code Disabling Permanently Windows Defender using Registry Keys","T1562.001 - T1055.002 - T1070.004","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/S12cybersecurity/WinDefenderKiller","1","1","N/A","N/A","10","5","448","67","2023-07-27T11:06:24Z","2023-07-25T10:32:25Z","62691" +"*WindfarmDynamite.cdproj*",".{0,1000}WindfarmDynamite\.cdproj.{0,1000}","offensive_tool_keyword","WindfarmDynamite","WindfarmDynamite is a proof-of-concept for code injection using the Windows Notification Facility (WNF). Of interest here is that this avoids suspect thread orchestration APIs (like CreateRemoteThread)","T1055.013 - T1546.008","TA0005 - TA0004","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Sharp-Suite/tree/master/WindfarmDynamite","1","1","N/A","N/A","N/A","10","1131","203","2022-12-22T23:57:19Z","2018-12-10T00:08:37Z","62692" +"*WindfarmDynamite.exe*",".{0,1000}WindfarmDynamite\.exe.{0,1000}","offensive_tool_keyword","WindfarmDynamite","WindfarmDynamite is a proof-of-concept for code injection using the Windows Notification Facility (WNF). Of interest here is that this avoids suspect thread orchestration APIs (like CreateRemoteThread)","T1055.013 - T1546.008","TA0005 - TA0004","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Sharp-Suite/tree/master/WindfarmDynamite","1","1","N/A","N/A","N/A","10","1131","203","2022-12-22T23:57:19Z","2018-12-10T00:08:37Z","62693" +"*WindfarmDynamite.sln*",".{0,1000}WindfarmDynamite\.sln.{0,1000}","offensive_tool_keyword","WindfarmDynamite","WindfarmDynamite is a proof-of-concept for code injection using the Windows Notification Facility (WNF). Of interest here is that this avoids suspect thread orchestration APIs (like CreateRemoteThread)","T1055.013 - T1546.008","TA0005 - TA0004","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Sharp-Suite/tree/master/WindfarmDynamite","1","1","N/A","N/A","N/A","10","1131","203","2022-12-22T23:57:19Z","2018-12-10T00:08:37Z","62694" +"*windows*lsa_secrets.py*",".{0,1000}windows.{0,1000}lsa_secrets\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","62712" +"*windows/c_payload_util*",".{0,1000}windows\/c_payload_util.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62718" +"*Windows/lazagne.spec*",".{0,1000}Windows\/lazagne\.spec.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","62721" +"*windows/meterpreter/bind_tcp*",".{0,1000}windows\/meterpreter\/bind_tcp.{0,1000}","offensive_tool_keyword","metasploit","exploits often used by ransomware groups","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven - Dispossessor","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62722" +"*windows/samdump.go*",".{0,1000}windows\/samdump\.go.{0,1000}","offensive_tool_keyword","Slackor","A Golang implant that uses Slack as a command and control server","T1059.003 - T1071.004 - T1562.001","TA0002 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/Coalfire-Research/Slackor","1","1","N/A","N/A","10","10","463","108","2023-02-25T03:35:15Z","2019-06-18T16:01:37Z","62724" +"*windows/shell_reverse_tcp*",".{0,1000}windows\/shell_reverse_tcp.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62725" +"*windows/smb/ms17_010_psexec*",".{0,1000}windows\/smb\/ms17_010_psexec.{0,1000}","offensive_tool_keyword","metasploit","exploit used by Dispossessor ransomware group","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Dispossessor","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62726" +"*windows/x64/meterpreter/reverse_tcp*",".{0,1000}windows\/x64\/meterpreter\/reverse_tcp.{0,1000}","offensive_tool_keyword","killer","evade AVs and EDRs or security tools","T1564 - T1027 - T1070","TA0005","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","Defense Evasion","https://github.com/0xHossam/Killer","1","1","N/A","N/A","10","9","804","128","2024-07-02T10:24:43Z","2023-04-08T16:29:52Z","62728" +"*windows/x64/meterpreter/reverse_tcp*",".{0,1000}windows\/x64\/meterpreter\/reverse_tcp.{0,1000}","offensive_tool_keyword","OSEP-Code-Snippets","notable code snippets for Offensive Security's PEN-300 (OSEP) course","T1116 - T1204.002 - T1027.009 - T1021.005 - T1560.001 - T1100 - T1003.001 - T1564.001 - T1047 - T1210 - T1134.002 - T1055 - T1055.011 - T1055.012 - T1204","TA0005 - TA0040 - TA0008 - TA0003 - TA0006 - TA0004","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","Exploitation tool","https://github.com/chvancooten/OSEP-Code-Snippets","1","1","N/A","N/A","8","10","1254","444","2024-01-04T15:17:17Z","2021-03-10T21:34:41Z","62729" +"*windows/x64/meterpreter/reverse_tcp*",".{0,1000}windows\/x64\/meterpreter\/reverse_tcp.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","62730" +"*windows/x64/meterpreter_reverse_tcp*",".{0,1000}windows\/x64\/meterpreter_reverse_tcp.{0,1000}","offensive_tool_keyword","charlotte","c++ fully undetected shellcode launcher","T1055.012 - T1059.003 - T1027.002","TA0005 - TA0040","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","Defense Evasion","https://github.com/9emin1/charlotte","1","1","N/A","N/A","10","10","976","211","2021-06-11T04:44:18Z","2021-05-13T07:32:03Z","62731" +"*windows/x64/meterpreter_reverse_tcp*",".{0,1000}windows\/x64\/meterpreter_reverse_tcp.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","62732" +"*windows/x64/meterpreter_reverse_tcp*",".{0,1000}windows\/x64\/meterpreter_reverse_tcp.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","FIN11 - FIN7 - Silence group - MuddyWater - FIN6 - GCMAN - Turla","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","62733" +"*windows/x64/shell_reverse_tcp*",".{0,1000}windows\/x64\/shell_reverse_tcp.{0,1000}","offensive_tool_keyword","metasploit","exploit used by Dispossessor ransomware group","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","Dispossessor","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62734" +"*windows/x64/shell_reverse_tcp*",".{0,1000}windows\/x64\/shell_reverse_tcp.{0,1000}","offensive_tool_keyword","reverse-shell-generator","Reverse Shell Generator","T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041","TA0011 - TA0010- TA0002","N/A","N/A","C2","https://github.com/0dayCTF/reverse-shell-generator","1","1","N/A","N/A","10","10","3312","702","2024-10-31T22:38:04Z","2021-02-27T00:53:13Z","62735" +"*windows_agent/asm/x64/alter_pe_sections*",".{0,1000}windows_agent\/asm\/x64\/alter_pe_sections.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","62738" +"*windows_agent/asm/x86/alter_pe_sections*",".{0,1000}windows_agent\/asm\/x86\/alter_pe_sections.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","62739" +"*windows_agent/dll_main.*",".{0,1000}windows_agent\/dll_main\..{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","62740" +"*windows_agent/exe_main.*",".{0,1000}windows_agent\/exe_main\..{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","62741" +"*windows_agent/win_*.c*",".{0,1000}windows_agent\/win_.{0,1000}\.c.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","62742" +"*windows_agent/win_named_pipe.*",".{0,1000}windows_agent\/win_named_pipe\..{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","62743" +"*windows_agent/win_shell.*",".{0,1000}windows_agent\/win_shell\..{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","62744" +"*windows_autologin.md*",".{0,1000}windows_autologin\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62745" +"*windows_console_interceptor*dll_main.c*",".{0,1000}windows_console_interceptor.{0,1000}dll_main\.c.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","62746" +"*windows_console_interceptor*exe_main.c*",".{0,1000}windows_console_interceptor.{0,1000}exe_main\.c.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","62747" +"*windows_console_interceptor*interceptor.*",".{0,1000}windows_console_interceptor.{0,1000}interceptor\..{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","62748" +"*windows_credentials.py*",".{0,1000}windows_credentials\.py.{0,1000}","offensive_tool_keyword","monkey","Infection Monkey - An automated pentest tool","T1078 - T1135 - T1046 - T1087 - T1105","TA0007 - TA0008 - TA0001 - TA0011","N/A","N/A","Exploitation tool","https://github.com/guardicore/monkey","1","1","N/A","N/A","N/A","10","6779","798","2025-02-28T15:41:56Z","2015-08-30T07:22:51Z","62749" +"*windows_key.py*",".{0,1000}windows_key\.py.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","62751" +"*windows_recon.bat*",".{0,1000}windows_recon\.bat.{0,1000}","offensive_tool_keyword","Windows-Privilege-Escalation","Windows Privilege Escalation Techniques and Scripts","T1055 - T1548 - T1078","TA0004 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/frizb/Windows-Privilege-Escalation","1","1","N/A","N/A","N/A","9","861","190","2020-03-25T22:35:02Z","2017-05-12T13:09:50Z","62752" +"*windows_sam_hivenightmare.md*",".{0,1000}windows_sam_hivenightmare\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62753" +"*windows_sam_hivenightmare.rb*",".{0,1000}windows_sam_hivenightmare\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62754" +"*windows10_ntfs_crash_dos*",".{0,1000}windows10_ntfs_crash_dos.{0,1000}","offensive_tool_keyword","POC","PoC for a NTFS crash that I discovered. in various Windows versions Type of issue: denial of service. One can generate blue-screen-of-death using a handcrafted NTFS image. This Denial of Service type of attack. can be driven from user mode. limited user account or Administrator. It can even crash the system if it is in locked state.","T1499.002 - T1059.001 - T1538.002","TA0002 - TA0007 - TA0008","N/A","N/A","DDOS","https://github.com/mtivadar/windows10_ntfs_crash_dos","1","1","N/A","N/A","N/A","7","600","131","2024-05-04T20:18:36Z","2018-04-27T19:31:59Z","62756" +"*Windows7-BypassLogon-Screen.ino*",".{0,1000}Windows7\-BypassLogon\-Screen\.ino.{0,1000}","offensive_tool_keyword","Pateensy","payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy","T1056.001 - T1200 - T1036 - T1071","TA0002 - TA0005 - TA0011 - TA0006","N/A","N/A","Exploitation tool","https://github.com/screetsec/Pateensy","1","1","N/A","N/A","N/A","2","143","60","2017-01-26T12:02:56Z","2016-03-21T07:29:38Z","62757" +"*windows-defender-remover-main.zip*",".{0,1000}windows\-defender\-remover\-main\.zip.{0,1000}","offensive_tool_keyword","windows-defender-remover","hacktool used to remove Windows Defender","T1089 - T1562.001 - T1562.004","TA0005 - TA0040","N/A","Black Basta","Defense Evasion","https://github.com/ionuttbara/windows-defender-remover","1","1","N/A","N/A","10","10","5266","354","2025-02-13T20:21:07Z","2021-08-13T20:44:46Z","62759" +"*WindowsExploits*",".{0,1000}WindowsExploits.{0,1000}","offensive_tool_keyword","Exploits","A curated archive of complied and tested public Windows exploits.","T1213 - T1210 - T1188 - T1055","TA0001 - TA0009 - TA0008","N/A","N/A","Exploitation tool","https://github.com/WindowsExploits/Exploits","1","1","N/A","N/A","N/A","10","1275","534","2020-05-29T19:09:52Z","2017-06-05T15:39:22Z","62762" +"*windows-exploit-suggester.*",".{0,1000}windows\-exploit\-suggester\..{0,1000}","offensive_tool_keyword","cobaltstrike","Erebus CobaltStrike post penetration testing plugin","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/DeEpinGh0st/Erebus","1","1","N/A","N/A","10","10","1518","221","2021-10-28T06:20:51Z","2019-09-26T09:32:00Z","62763" +"*windows-forkbomb.ino*",".{0,1000}windows\-forkbomb\.ino.{0,1000}","offensive_tool_keyword","Pateensy","payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy","T1056.001 - T1200 - T1036 - T1071","TA0002 - TA0005 - TA0011 - TA0006","N/A","N/A","Exploitation tool","https://github.com/screetsec/Pateensy","1","1","N/A","N/A","N/A","2","143","60","2017-01-26T12:02:56Z","2016-03-21T07:29:38Z","62764" +"*WindowsLies*BlockWindows*",".{0,1000}WindowsLies.{0,1000}BlockWindows.{0,1000}","offensive_tool_keyword","BlockWindows","Stop Windows 7 through 10 Nagging and Spying updates. Tasks. IPs. and services. Works with Windows 7 through 10","T1059 - T1562 - T1053 - T1543","TA0002 - TA0003 - TA0004 - TA0008","N/A","N/A","Defense Evasion","https://github.com/WindowsLies/BlockWindows","1","1","N/A","N/A","N/A","7","641","96","2020-04-11T15:38:12Z","2015-08-26T01:17:57Z","62765" +"*Windows-Post-Exploitation*",".{0,1000}Windows\-Post\-Exploitation.{0,1000}","offensive_tool_keyword","Windows-Post-Exploitation","Windows Post Exploitation list of tools on github. could also be related to folder name","T1021 - T1059 - T1078 - T1056 - T1028 - T1053 - T1003","TA0002 - TA0003 - TA0004 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Exploitation tool","https://github.com/emilyanncr/Windows-Post-Exploitation","1","1","N/A","N/A","N/A","6","533","117","2021-09-20T01:47:13Z","2017-11-18T04:16:41Z","62766" +"*windows-privesc-check*",".{0,1000}windows\-privesc\-check.{0,1000}","offensive_tool_keyword","Windows-Privilege-Escalation","Windows Privilege Escalation Techniques and Scripts","T1055 - T1548 - T1078","TA0004 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/frizb/Windows-Privilege-Escalation","1","1","N/A","N/A","N/A","9","861","190","2020-03-25T22:35:02Z","2017-05-12T13:09:50Z","62767" +"*Windows-Privilege-Escalation*",".{0,1000}Windows\-Privilege\-Escalation.{0,1000}","offensive_tool_keyword","Windows-Privilege-Escalation","Windows Privilege Escalation Techniques and Scripts","T1055 - T1548 - T1078","TA0004 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/frizb/Windows-Privilege-Escalation","1","1","N/A","N/A","N/A","9","861","190","2020-03-25T22:35:02Z","2017-05-12T13:09:50Z","62768" +"*WindowsShareFinder.cs*",".{0,1000}WindowsShareFinder\.cs.{0,1000}","offensive_tool_keyword","SMBeagle","SMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host.","T1087.002 - T1021.002 - T1210","TA0007 - TA0008 - TA0003","N/A","N/A","Discovery","https://github.com/punk-security/SMBeagle","1","1","N/A","N/A","9","8","712","80","2025-01-21T22:34:00Z","2021-05-31T19:46:57Z","62769" +"*windows-subbrute.zip*",".{0,1000}windows\-subbrute\.zip.{0,1000}","offensive_tool_keyword","subbrute","A DNS meta-query spider that enumerates DNS records and subdomains.","T1071.001 - T1083 - T1590.001","TA0043 - TA0007?","N/A","ENERGETIC BEAR","Reconnaissance","https://github.com/TheRook/subbrute","1","1","N/A","N/A","5","10","3422","661","2022-01-13T09:25:59Z","2012-06-10T01:08:20Z","62771" +"*winexesvc32.exe*",".{0,1000}winexesvc32\.exe.{0,1000}","offensive_tool_keyword","winexe","Winexe remotely executes commands on Windows systems from GNU/Linux","T1059.004 - T1021.005 - T1078.003","TA0002 - TA0008 - TA0011","N/A","APT28","Lateral Movement","https://www.kali.org/tools/winexe/","1","1","#linux #windows","N/A","8","8","N/A","N/A","N/A","N/A","62775" +"*winexesvc64.exe*",".{0,1000}winexesvc64\.exe.{0,1000}","offensive_tool_keyword","winexe","Winexe remotely executes commands on Windows systems from GNU/Linux","T1059.004 - T1021.005 - T1078.003","TA0002 - TA0008 - TA0011","N/A","APT28","Lateral Movement","https://www.kali.org/tools/winexe/","1","1","#linux #windows","N/A","8","8","N/A","N/A","N/A","N/A","62776" +"*WinhttpShellcode.cpp*",".{0,1000}WinhttpShellcode\.cpp.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","62778" +"*WinhttpShellcode.exe*",".{0,1000}WinhttpShellcode\.exe.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","62779" +"*WinhttpShellcode.sln*",".{0,1000}WinhttpShellcode\.sln.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","62780" +"*WinhttpShellcode.vcxproj*",".{0,1000}WinhttpShellcode\.vcxproj.{0,1000}","offensive_tool_keyword","Shellcode-Hide","simple shellcode Loader - Encoders (base64 - custom - UUID - IPv4 - MAC) - Encryptors (AES) - Fileless Loader (Winhttp socket)","T1059.003 - T1027 - T1132 - T1027.002 - T1045 - T1027.004 - T1105","TA0005 - TA0001 - TA0003","N/A","N/A","Defense Evasion","https://github.com/TheD1rkMtr/Shellcode-Hide","1","1","N/A","N/A","9","5","416","109","2023-08-02T02:22:20Z","2023-02-05T17:31:43Z","62781" +"*Win-Ops-Master.*",".{0,1000}Win\-Ops\-Master\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62782" +"*Winpayloads*",".{0,1000}Winpayloads.{0,1000}","offensive_tool_keyword","Winpayloads","Undetectable Windows Payload Generation with extras Running on Python2.7","T1203 - T1027 - T1059","TA0002 - TA0003 - TA0007","N/A","N/A","Defense Evasion","https://github.com/nccgroup/Winpayloads","1","1","N/A","N/A","N/A","10","1593","335","2022-11-08T08:14:23Z","2015-10-09T09:29:49Z","62783" +"*winPEAS.bat*",".{0,1000}winPEAS\.bat.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","62784" +"*winPEAS.bat*",".{0,1000}winPEAS\.bat.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","62785" +"*winPEAS.bat*",".{0,1000}winPEAS\.bat.{0,1000}","offensive_tool_keyword","PEASS-ng","PEASS-ng - Privilege Escalation Awesome Scripts suite","T1098","TA0004 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/peass-ng/PEASS-ng","1","1","N/A","N/A","10","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","62786" +"*WinPEAS.exe*",".{0,1000}WinPEAS\.exe.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","62787" +"*winPEAS.exe*",".{0,1000}winPEAS\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","62788" +"*winPEAS.ps1*",".{0,1000}winPEAS\.ps1.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","62792" +"*winPEAS.txt*",".{0,1000}winPEAS\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","62793" +"*winPEASany.exe*",".{0,1000}winPEASany\.exe.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","62794" +"*winPEASany.exe*",".{0,1000}winPEASany\.exe.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","62795" +"*winPEASany_ofs.exe*",".{0,1000}winPEASany_ofs\.exe.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","62796" +"*winPEASany_ofs.exe*",".{0,1000}winPEASany_ofs\.exe.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","62797" +"*winPEAS-Obfuscated*",".{0,1000}winPEAS\-Obfuscated.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","62798" +"*winPEASps1*",".{0,1000}winPEASps1.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","62799" +"*winPEASx64.exe*",".{0,1000}winPEASx64\.exe.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","62800" +"*winPEASx64.exe*",".{0,1000}winPEASx64\.exe.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","62801" +"*winPEASx64_ofs.exe*",".{0,1000}winPEASx64_ofs\.exe.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","62802" +"*winPEASx86.exe*",".{0,1000}winPEASx86\.exe.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","62803" +"*winPEASx86.exe*",".{0,1000}winPEASx86\.exe.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","62804" +"*winPEASx86_ofs.exe*",".{0,1000}winPEASx86_ofs\.exe.{0,1000}","offensive_tool_keyword","exegol","Fully featured and community-driven hacking environment with hundreds of offensive tools","T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559","TA0043 - TA0002 - TA0004 - TA0011 - TA0003","N/A","Black Basta","Exploitation tool","https://github.com/ThePorgs/Exegol","1","1","N/A","N/A","10","10","2354","209","2025-04-09T16:56:24Z","2020-03-09T19:12:11Z","62805" +"*winPEASx86_ofs.exe*",".{0,1000}winPEASx86_ofs\.exe.{0,1000}","offensive_tool_keyword","PEASS","PEASS - Privilege Escalation Awesome Scripts SUITE","T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002","TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005","N/A","Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor","Privilege Escalation","https://github.com/carlospolop/PEASS-ng","1","1","N/A","N/A","N/A","10","17347","3209","2025-04-01T04:29:00Z","2019-01-13T19:58:24Z","62806" +"*Win-PS2EXE.exe*",".{0,1000}Win\-PS2EXE\.exe.{0,1000}","offensive_tool_keyword","PS2EXE","Module to compile powershell scripts to executables","T1027.001 - T1564.003 - T1564.005","TA0002 - TA0006","N/A","N/A","Exploitation tool","https://github.com/MScholtes/PS2EXE","1","1","N/A","N/A","N/A","10","1395","217","2025-01-05T11:26:50Z","2019-11-08T09:25:02Z","62807" +"*WinPwn.exe*",".{0,1000}WinPwn\.exe.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","62810" +"*WinPwn.ps1*",".{0,1000}WinPwn\.ps1.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","62811" +"*winpwnage.functions*",".{0,1000}winpwnage\.functions.{0,1000}","offensive_tool_keyword","pupy","PupyRAT is a C2 and post-exploitation framework written in python and C","T1548.002 - T1134.001 - T1087.001 - T1557.001 - T1071.001 - T1560.001 - T1123 - T1547.001 - T1547.013 - T1059.001 - T1059.006 - T1136.001 - T1136.002 - T1543.002 - T1555 - T1555.003 - T1114.001 - T1573.002 - T1041 - T1083 - T1070.001 - T1105 - T1056.001 - T1046 - T1135 - T1003.001 - T1003.004 - T1003.005 - T1057 - T1055.001 - T1021.001 - T1113 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1552.001 - T1550.003 - T1125 - T1497.001","TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","Black Basta - Magic Hound - APT33 - Cutting Kitten","C2","https://github.com/n1nj4sec/pupy","1","1","N/A","N/A","10","10","8671","1822","2024-03-22T08:52:53Z","2015-09-21T17:30:53Z","62812" +"*winreconstreamline.bat*",".{0,1000}winreconstreamline\.bat.{0,1000}","offensive_tool_keyword","Windows-Privilege-Escalation","Windows Privilege Escalation Techniques and Scripts","T1055 - T1548 - T1078","TA0004 - TA0005 - TA0040","N/A","N/A","Privilege Escalation","https://github.com/frizb/Windows-Privilege-Escalation","1","1","N/A","N/A","N/A","9","861","190","2020-03-25T22:35:02Z","2017-05-12T13:09:50Z","62815" +"*winregistry.py*",".{0,1000}winregistry\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/SecureAuthCorp/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","62816" +"*winrm_command_shell.rb*",".{0,1000}winrm_command_shell\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62819" +"*winrm_script_exec.*",".{0,1000}winrm_script_exec\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62820" +"*winrmdll.*",".{0,1000}winrmdll\..{0,1000}","offensive_tool_keyword","cobaltstrike","C++ WinRM API via Reflective DLL","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/mez-0/winrmdll","1","1","N/A","N/A","10","10","144","28","2021-09-11T13:44:16Z","2021-09-11T13:40:22Z","62823" +"*WinSCPPasswdExtractor*",".{0,1000}WinSCPPasswdExtractor.{0,1000}","offensive_tool_keyword","WinSCPPasswdExtractor","Extract WinSCP Credentials from any Windows System or winscp config file","T1003.001 - T1083 - T1145","TA0003 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/NeffIsBack/WinSCPPasswdExtractor","1","1","N/A","N/A","N/A","1","16","3","2025-03-19T15:26:16Z","2022-12-20T11:55:55Z","62828" +"*WinShellcode.git*",".{0,1000}WinShellcode\.git.{0,1000}","offensive_tool_keyword","WinShellcode","It's a C code project created in Visual Studio that helps you generate shellcode from your C code.","T1059.001 - T1059.003 - T1059.005 - T1059.007 - T1059.004 - T1059.006 - T1218 - T1027.001 - T1564.003 - T1027","TA0002 - TA0006","N/A","N/A","Exploitation tool","https://github.com/DallasFR/WinShellcode","1","1","N/A","N/A","N/A","","N/A","","","","62829" +"*WinShellcode-main*",".{0,1000}WinShellcode\-main.{0,1000}","offensive_tool_keyword","WinShellcode","It's a C code project created in Visual Studio that helps you generate shellcode from your C code.","T1059.001 - T1059.003 - T1059.005 - T1059.007 - T1059.004 - T1059.006 - T1218 - T1027.001 - T1564.003 - T1027","TA0002 - TA0006","N/A","N/A","Exploitation tool","https://github.com/DallasFR/WinShellcode","1","1","N/A","N/A","N/A","","N/A","","","","62830" +"*Winsocky-main*",".{0,1000}Winsocky\-main.{0,1000}","offensive_tool_keyword","cobaltstrike","Winsocket for Cobalt Strike.","T1572 - T1041 - T1105","TA0011 - TA0002 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/WKL-Sec/Winsocky","1","1","N/A","N/A","10","10","98","18","2023-07-06T11:47:18Z","2023-06-22T07:00:22Z","62831" +"*WINspect.ps1*",".{0,1000}WINspect\.ps1.{0,1000}","offensive_tool_keyword","WINspect","WINspect is part of a larger project for auditing different areas of Windows environments.It focuses on enumerating different parts of a Windows machine to identify security weaknesses and point to components that need further hardening.can be used by attacker ","T1018 - T1082 - T1057 - T1547.001 - T1053","TA0003 - TA0006 - TA0008 - TA0010","N/A","N/A","Reconnaissance","https://github.com/A-mIn3/WINspect","1","1","N/A","N/A","N/A","6","576","100","2019-01-09T12:56:57Z","2017-08-10T15:10:10Z","62832" +"*win-x64-DynamicKernelWinExecCalc*",".{0,1000}win\-x64\-DynamicKernelWinExecCalc.{0,1000}","offensive_tool_keyword","Dinjector","Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL","T1055 - T1055.012 - T1055.001 - T1027.002","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Metro-Holografix/DInjector","1","1","N/A","private github repo","8","","N/A","","","","62835" +"*WiperPoc.exe*",".{0,1000}WiperPoc\.exe.{0,1000}","offensive_tool_keyword","ContainYourself","Abuses the Windows containers framework to bypass EDRs.","T1562 - T1562.004 - T1212 - T1212.002 - T1055 - T1055.015","TA0005","N/A","N/A","Defense Evasion","https://github.com/deepinstinct/ContainYourself","1","1","N/A","N/A","10","4","310","39","2023-08-31T07:26:22Z","2023-07-12T14:47:24Z","62837" +"*wireghoul/htshells*",".{0,1000}wireghoul\/htshells.{0,1000}","offensive_tool_keyword","htshells","Self contained htaccess shells and attacks","T1059 - T1059.007 - T1027 - T1027.001 - T1070.004","TA0005 - TA0011 - TA0002 - TA0003","N/A","N/A","C2","https://github.com/wireghoul/htshells","1","1","N/A","N/A","10","10","1048","193","2022-02-17T00:26:23Z","2011-05-16T02:21:59Z","62839" +"*wireless/captures.py*",".{0,1000}wireless\/captures\.py.{0,1000}","offensive_tool_keyword","wifibroot","A Wireless (WPA/WPA2) Pentest/Cracking tool. Captures & Crack 4-way handshake and PMKID key. Also. supports a deauthentication/jammer mode for stress testing","T1018 - T1040 - T1095 - T1113 - T1210 - T1437 - T1499 - T1557 - T1562 - T1573","TA0001 - TA0002 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://github.com/hash3liZer/WiFiBroot","1","1","N/A","network exploitation tool","N/A","10","1008","182","2021-01-15T09:07:36Z","2018-07-30T10:57:22Z","62841" +"*wireless/cracker.py*",".{0,1000}wireless\/cracker\.py.{0,1000}","offensive_tool_keyword","wifibroot","A Wireless (WPA/WPA2) Pentest/Cracking tool. Captures & Crack 4-way handshake and PMKID key. Also. supports a deauthentication/jammer mode for stress testing","T1018 - T1040 - T1095 - T1113 - T1210 - T1437 - T1499 - T1557 - T1562 - T1573","TA0001 - TA0002 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://github.com/hash3liZer/WiFiBroot","1","1","N/A","network exploitation tool","N/A","10","1008","182","2021-01-15T09:07:36Z","2018-07-30T10:57:22Z","62842" +"*wireless/pmkid.py*",".{0,1000}wireless\/pmkid\.py.{0,1000}","offensive_tool_keyword","wifibroot","A Wireless (WPA/WPA2) Pentest/Cracking tool. Captures & Crack 4-way handshake and PMKID key. Also. supports a deauthentication/jammer mode for stress testing","T1018 - T1040 - T1095 - T1113 - T1210 - T1437 - T1499 - T1557 - T1562 - T1573","TA0001 - TA0002 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://github.com/hash3liZer/WiFiBroot","1","1","N/A","network exploitation tool","N/A","10","1008","182","2021-01-15T09:07:36Z","2018-07-30T10:57:22Z","62843" +"*wireless/sniper.py*",".{0,1000}wireless\/sniper\.py.{0,1000}","offensive_tool_keyword","wifibroot","A Wireless (WPA/WPA2) Pentest/Cracking tool. Captures & Crack 4-way handshake and PMKID key. Also. supports a deauthentication/jammer mode for stress testing","T1018 - T1040 - T1095 - T1113 - T1210 - T1437 - T1499 - T1557 - T1562 - T1573","TA0001 - TA0002 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://github.com/hash3liZer/WiFiBroot","1","1","N/A","network exploitation tool","N/A","10","1008","182","2021-01-15T09:07:36Z","2018-07-30T10:57:22Z","62844" +"*wireless_attack_tools.py*",".{0,1000}wireless_attack_tools\.py.{0,1000}","offensive_tool_keyword","hackingtool","ALL IN ONE Hacking Tool For Hackers","T1059 - T1078 - T1105 - T1110 - T1566","TA0002 - TA0008 - TA0009 - TA0005 - TA0007","N/A","N/A","Exploitation tool","https://github.com/Z4nzu/hackingtool","1","1","N/A","N/A","N/A","10","52217","5629","2025-03-03T15:17:19Z","2020-04-11T09:21:31Z","62845" +"*wirelesskeyview.exe*",".{0,1000}wirelesskeyview\.exe.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1083 - T1552","TA0006 ","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","62846" +"*wirelesskeyview.exe*",".{0,1000}wirelesskeyview\.exe.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1016 - T1021 - T1056 - T1110 - T1212 - T1552 - T1557","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","62847" +"*wirelesskeyview.zip*",".{0,1000}wirelesskeyview\.zip.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1083 - T1552","TA0006 ","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","62848" +"*wirelesskeyview.zip*",".{0,1000}wirelesskeyview\.zip.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1016 - T1021 - T1056 - T1110 - T1212 - T1552 - T1557","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","62849" +"*WirelessKeyView_x64.exe*",".{0,1000}WirelessKeyView_x64\.exe.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1083 - T1552","TA0006 ","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","62850" +"*WirelessKeyView_x64.exe*",".{0,1000}WirelessKeyView_x64\.exe.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1016 - T1021 - T1056 - T1110 - T1212 - T1552 - T1557","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","62851" +"*wirelesskeyview-no-command-line.zip*",".{0,1000}wirelesskeyview\-no\-command\-line\.zip.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1083 - T1552","TA0006 ","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","62852" +"*wirelesskeyview-no-command-line.zip*",".{0,1000}wirelesskeyview\-no\-command\-line\.zip.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1016 - T1021 - T1056 - T1110 - T1212 - T1552 - T1557","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","62853" +"*wirelesskeyview-x64.zip*",".{0,1000}wirelesskeyview\-x64\.zip.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1083 - T1552","TA0006 ","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","62854" +"*wirelesskeyview-x64.zip*",".{0,1000}wirelesskeyview\-x64\.zip.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1016 - T1021 - T1056 - T1110 - T1212 - T1552 - T1557","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","62855" +"*wiresocks-main*",".{0,1000}wiresocks\-main.{0,1000}","offensive_tool_keyword","wiresocks","Docker-compose and Dockerfile to setup a wireguard VPN connection forcing specific TCP traffic through a socks proxy.","T1090.004 - T1572 - T1021.001","TA0011 - TA0002 - TA0040","N/A","N/A","Defense Evasion","https://github.com/sensepost/wiresocks","1","1","N/A","N/A","9","3","287","30","2024-01-19T10:58:20Z","2022-03-23T12:27:07Z","62870" +"*wiresocks-redsocks*",".{0,1000}wiresocks\-redsocks.{0,1000}","offensive_tool_keyword","wiresocks","Docker-compose and Dockerfile to setup a wireguard VPN connection forcing specific TCP traffic through a socks proxy.","T1090.004 - T1572 - T1021.001","TA0011 - TA0002 - TA0040","N/A","N/A","Defense Evasion","https://github.com/sensepost/wiresocks","1","1","N/A","N/A","9","3","287","30","2024-01-19T10:58:20Z","2022-03-23T12:27:07Z","62871" +"*WithSecureLabs/physmem2profit*",".{0,1000}WithSecureLabs\/physmem2profit.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","1","N/A","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","62886" +"*Witness.py*",".{0,1000}Witness\.py.{0,1000}","offensive_tool_keyword","EyeWitness","EyeWitness is designed to take screenshots of websites provide some server header info. and identify default credentials if known.EyeWitness is designed to run on Kali Linux. It will auto detect the file you give it with the -f flag as either being a text file with URLs on each new line. nmap xml output. or nessus xml output. The --timeout flag is completely optional. and lets you provide the max time to wait when trying to render and screenshot a web page.","T1564 - T1518 - T1210 - T1514 - T1552","TA0002 - TA0007","N/A","N/A","Reconnaissance","https://github.com/FortyNorthSecurity/EyeWitness","1","1","#linux","N/A","N/A","10","5263","870","2024-10-22T22:50:50Z","2014-02-26T16:23:25Z","62887" +"*WitnessMe*",".{0,1000}WitnessMe.{0,1000}","offensive_tool_keyword","WitnessMe","WitnessMe is primarily a Web Inventory tool inspired by Eyewitness. its also written to be extensible allowing you to create custom functionality that can take advantage of the headless browser it drives in the back-end.","T1210.001 - T1593.001 - T1593.002","TA0010 - ","N/A","N/A","Reconnaissance","https://github.com/byt3bl33d3r/WitnessMe","1","1","N/A","N/A","N/A","8","747","111","2024-09-23T18:34:55Z","2019-07-06T05:25:10Z","62888" +"*WKL-Sec/dcomhijack*",".{0,1000}WKL\-Sec\/dcomhijack.{0,1000}","offensive_tool_keyword","dcomhijack","Lateral Movement Using DCOM with impacket and DLL Hijacking","T1570 - T1021.003 - T1574.001 - T1574.002","TA0008 - TA0003 - TA0005","N/A","N/A","Lateral Movement","https://github.com/WKL-Sec/dcomhijack","1","1","N/A","N/A","7","3","290","24","2023-06-18T20:34:03Z","2023-06-17T20:23:24Z","62892" +"*WKL-Sec/dcomhijack*",".{0,1000}WKL\-Sec\/dcomhijack.{0,1000}","offensive_tool_keyword","dcomhijack","Lateral Movement Using DCOM and DLL Hijacking","T1021 - T1021.003 - T1574 - T1574.007 - T1574.002","TA0008 - TA0005 - TA0002","N/A","N/A","Lateral Movement","https://github.com/WKL-Sec/dcomhijack","1","1","N/A","N/A","10","3","290","24","2023-06-18T20:34:03Z","2023-06-17T20:23:24Z","62893" +"*WKL-Sec/HiddenDesktop*",".{0,1000}WKL\-Sec\/HiddenDesktop.{0,1000}","offensive_tool_keyword","cobaltstrike","Hidden Desktop (often referred to as HVNC) is a tool that allows operators to interact with a remote desktop session without the user knowing. The VNC protocol is not involved but the result is a similar experience. This Cobalt Strike BOF implementation was created as an alternative to TinyNuke/forks that are written in C++","T1021.001 - T1133","TA0005 - TA0002","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/WKL-Sec/HiddenDesktop","1","1","N/A","N/A","10","10","1213","187","2023-12-07T17:15:48Z","2023-05-21T00:57:43Z","62894" +"*WKL-Sec/Winsocky*",".{0,1000}WKL\-Sec\/Winsocky.{0,1000}","offensive_tool_keyword","cobaltstrike","Winsocket for Cobalt Strike.","T1572 - T1041 - T1105","TA0011 - TA0002 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/WKL-Sec/Winsocky","1","1","N/A","N/A","10","10","98","18","2023-07-06T11:47:18Z","2023-06-22T07:00:22Z","62895" +"*wkssvc_##*",".{0,1000}wkssvc_\#\#.{0,1000}","offensive_tool_keyword","cobaltstrike","A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/bluscreenofjeff/Malleable-C2-Randomizer","1","1","N/A","N/A","10","10","444","87","2022-09-09T15:50:16Z","2017-05-31T15:44:43Z","62896" +"*wlbsctrl_payload.bat*",".{0,1000}wlbsctrl_payload\.bat.{0,1000}","offensive_tool_keyword","Ikeext-Privesc","Windows IKEEXT DLL Hijacking Exploit Tool","T1546.011 - T1574.009 - T1036.004","TA0003 - TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/securycore/Ikeext-Privesc","1","1","N/A","N/A","10","1","33","52","2018-02-25T13:45:15Z","2018-02-27T11:18:56Z","62898" +"*WldpBypass.cs*",".{0,1000}WldpBypass\.cs.{0,1000}","offensive_tool_keyword","CheeseTools","tools for Lateral Movement/Code Execution","T1021.006 - T1059.003 - T1105","TA0008 - TA0002","N/A","N/A","Lateral Movement","https://github.com/klezVirus/CheeseTools","1","1","N/A","N/A","10","8","706","143","2021-08-17T20:22:56Z","2020-08-24T01:28:12Z","62899" +"*wlh3dpptx2gt7nsxcor37a3kiyaiy6qwhdv7o6nl6iuniu5ycze5ydid.onion*",".{0,1000}wlh3dpptx2gt7nsxcor37a3kiyaiy6qwhdv7o6nl6iuniu5ycze5ydid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","62900" +"*wmap_crawler.rb*",".{0,1000}wmap_crawler\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62903" +"*wmeye.csproj*",".{0,1000}wmeye\.csproj.{0,1000}","offensive_tool_keyword","WMEye","WMEye is a post exploitation tool that uses WMI Event Filter and MSBuild Execution for Lateral Movement","T1047 - T1053.005 - T1124 - T1203 - T1569.002","TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/pwn1sher/WMEye","1","1","N/A","N/A","8","4","365","59","2021-12-24T05:38:50Z","2021-09-07T08:18:30Z","62904" +"*wmeye.sln*",".{0,1000}wmeye\.sln.{0,1000}","offensive_tool_keyword","WMEye","WMEye is a post exploitation tool that uses WMI Event Filter and MSBuild Execution for Lateral Movement","T1047 - T1053.005 - T1124 - T1203 - T1569.002","TA0008 - TA0011","N/A","N/A","Lateral Movement","https://github.com/pwn1sher/WMEye","1","1","N/A","N/A","8","4","365","59","2021-12-24T05:38:50Z","2021-09-07T08:18:30Z","62906" +"*Wmi_Persistence.ps1*",".{0,1000}Wmi_Persistence\.ps1.{0,1000}","offensive_tool_keyword","cobaltstrike","A CobaltStrike script that uses various WinAPIs to maintain permissions. including API setting system services. setting scheduled tasks. managing users. etc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/yanghaoi/CobaltStrike_CNA","1","1","N/A","N/A","10","10","540","86","2022-01-18T12:47:55Z","2021-04-21T13:10:11Z","62909" +"*wmi_persistence.rb*",".{0,1000}wmi_persistence\.rb.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","62910" +"*WMIBackdoor.ps1*",".{0,1000}WMIBackdoor\.ps1.{0,1000}","offensive_tool_keyword","RandomPS-Scripts","create or remove a backdoor using WMI event subscriptions","T1546.003 - T1059.001 - T1102","TA0005 - TA0002 - TA0003","N/A","N/A","Persistence","https://github.com/xorrior/RandomPS-Scripts","1","1","N/A","N/A","10","4","318","86","2017-12-29T17:16:42Z","2015-02-25T04:52:01Z","62911" +"*wmic/wmic.cmd*",".{0,1000}wmic\/wmic\.cmd.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","62961" +"*wmicexe-whitelisting-bypass-hacking.html*",".{0,1000}wmicexe\-whitelisting\-bypass\-hacking\.html.{0,1000}","offensive_tool_keyword","macro_pack","The macro_pack is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. Now it also handles various shortcuts formats.","T1587 - T1588 - T1027 - T1204 ","TA0005 - TA0002 - TA0008 - TA0011 - TA0042","N/A","Black Basta","Resource Development","https://github.com/sevagas/macro_pack","1","1","N/A","N/A","10","10","2241","412","2024-08-15T14:21:39Z","2017-10-03T18:30:06Z","62962" +"*WMIcmd.exe*",".{0,1000}WMIcmd.{0,1000}","offensive_tool_keyword","WMIcmd","This tool allows us to execute commands via WMI and get information not otherwise available via this channel.","T1059.001 - T1021 - T1210.001","TA0002 - TA0007 - TA0008","N/A","MAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEAR","Discovery","https://github.com/nccgroup/WMIcmd","1","1","N/A","N/A","N/A","4","332","77","2017-06-24T18:37:16Z","2017-05-17T06:50:12Z","62963" +"*WMICStager*",".{0,1000}WMICStager.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","62964" +"*wmi-event-lateral-movement.*",".{0,1000}wmi\-event\-lateral\-movement\..{0,1000}","offensive_tool_keyword","cobaltstrike","LiquidSnake is a tool that allows operators to perform fileless Lateral Movement using WMI Event Subscriptions and GadgetToJScript","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RiccardoAncarani/LiquidSnake","1","1","N/A","N/A","10","10","332","46","2021-09-01T11:53:30Z","2021-08-31T12:23:01Z","62965" +"*WMI-EventSub.cpp*",".{0,1000}WMI\-EventSub\.cpp.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of beacon BOF written to learn windows and cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Yaxser/CobaltStrike-BOF","1","1","N/A","N/A","10","10","347","57","2023-02-24T13:12:14Z","2020-10-08T01:12:41Z","62966" +"*WMIExec.git*",".{0,1000}WMIExec\.git.{0,1000}","offensive_tool_keyword","wmiexec","Set of python scripts which perform different ways of command execution via WMI protocol","T1021.005 - T1047 - T1059.001 - T1059.003 - T1059.005","TA0008 - TA0002 - TA0011","N/A","Dispossessor - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Exploitation tool","https://github.com/WKL-Sec/wmiexec","1","1","N/A","N/A","N/A","2","159","27","2023-06-29T03:30:09Z","2023-06-21T13:15:04Z","62970" +"*wmiexec_scheduledjob.py*",".{0,1000}wmiexec_scheduledjob\.py.{0,1000}","offensive_tool_keyword","wmiexec","Set of python scripts which perform different ways of command execution via WMI protocol","T1021.005 - T1047 - T1059.001 - T1059.003 - T1059.005","TA0008 - TA0002 - TA0011","N/A","Dispossessor - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Exploitation tool","https://github.com/WKL-Sec/wmiexec","1","1","N/A","N/A","N/A","2","159","27","2023-06-29T03:30:09Z","2023-06-21T13:15:04Z","62974" +"*wmiexec_win32process.py*",".{0,1000}wmiexec_win32process\.py.{0,1000}","offensive_tool_keyword","wmiexec","Set of python scripts which perform different ways of command execution via WMI protocol","T1021.005 - T1047 - T1059.001 - T1059.003 - T1059.005","TA0008 - TA0002 - TA0011","N/A","Dispossessor - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Exploitation tool","https://github.com/WKL-Sec/wmiexec","1","1","N/A","N/A","N/A","2","159","27","2023-06-29T03:30:09Z","2023-06-21T13:15:04Z","62975" +"*wmiexec2.0.py*",".{0,1000}wmiexec2\.0\.py.{0,1000}","offensive_tool_keyword","wmiexec2","wmiexec2.0 is the same wmiexec that everyone knows and loves (debatable). This 2.0 version is obfuscated to avoid well known signatures from various AV engines.","T1021.005 - T1047 - T1059.001 - T1059.003 - T1059.005","TA0008 - TA0002 - TA0011","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/ice-wzl/wmiexec2","1","1","N/A","N/A","9","1","34","1","2024-06-12T17:56:15Z","2023-02-07T22:10:08Z","62976" +"*wmiexec2.py*",".{0,1000}wmiexec2\.py.{0,1000}","offensive_tool_keyword","wmiexec2","wmiexec2.0 is the same wmiexec that everyone knows and loves (debatable). This 2.0 version is obfuscated to avoid well known signatures from various AV engines.","T1021.005 - T1047 - T1059.001 - T1059.003 - T1059.005","TA0008 - TA0002 - TA0011","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/ice-wzl/wmiexec2","1","1","N/A","N/A","9","1","34","1","2024-06-12T17:56:15Z","2023-02-07T22:10:08Z","62977" +"*wmiexec2-main*",".{0,1000}wmiexec2\-main.{0,1000}","offensive_tool_keyword","wmiexec2","wmiexec2.0 is the same wmiexec that everyone knows and loves (debatable). This 2.0 version is obfuscated to avoid well known signatures from various AV engines.","T1021.005 - T1047 - T1059.001 - T1059.003 - T1059.005","TA0008 - TA0002 - TA0011","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/ice-wzl/wmiexec2","1","1","N/A","N/A","9","1","34","1","2024-06-12T17:56:15Z","2023-02-07T22:10:08Z","62978" +"*WMIExecHash.*",".{0,1000}WMIExecHash\..{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","62979" +"*WMIExecHash.boo",".{0,1000}WMIExecHash\.boo","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","62980" +"*WMIExec-main*",".{0,1000}WMIExec\-main.{0,1000}","offensive_tool_keyword","wmiexec","Set of python scripts which perform different ways of command execution via WMI protocol","T1021.005 - T1047 - T1059.001 - T1059.003 - T1059.005","TA0008 - TA0002 - TA0011","N/A","Dispossessor - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Exploitation tool","https://github.com/WKL-Sec/wmiexec","1","1","N/A","N/A","N/A","2","159","27","2023-06-29T03:30:09Z","2023-06-21T13:15:04Z","62981" +"*wmiexec-Pro.git*",".{0,1000}wmiexec\-Pro\.git.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","62982" +"*wmiexec-pro.py*",".{0,1000}wmiexec\-pro\.py.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","62983" +"*wmiexec-Pro/tarball*",".{0,1000}wmiexec\-Pro\/tarball.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","62984" +"*wmiexec-Pro/zipball*",".{0,1000}wmiexec\-Pro\/zipball.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","62985" +"*wmi-lateral-movement.*",".{0,1000}wmi\-lateral\-movement\..{0,1000}","offensive_tool_keyword","cobaltstrike","LiquidSnake is a tool that allows operators to perform fileless Lateral Movement using WMI Event Subscriptions and GadgetToJScript","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RiccardoAncarani/LiquidSnake","1","1","N/A","N/A","10","10","332","46","2021-09-01T11:53:30Z","2021-08-31T12:23:01Z","62988" +"*WMImplant*",".{0,1000}WMImplant.{0,1000}","offensive_tool_keyword","WMImplant","WMImplant is a PowerShell based tool that leverages WMI to both perform actions against targeted machines. but also as the C2 channel for issuing commands and receiving results. WMImplant will likely require local administrator permissions on the targeted machine.","T1021 - T1059 - T1047 - T1057 - T1049","TA0002 - TA0003 - TA0008 - TA0009 - TA0011","N/A","N/A","C2","https://github.com/FortyNorthSecurity/WMImplant","1","1","N/A","N/A","N/A","10","813","146","2024-06-25T12:02:26Z","2016-05-24T14:00:14Z","62989" +"*WMIPersist.*",".{0,1000}WMIPersist\..{0,1000}","offensive_tool_keyword","WMIPersistence","An example of how to perform WMI Event Subscription persistence using C#","T1547.008 - T1084 - T1053 - T1059.003","TA0003 - TA0004 - TA0002","N/A","N/A","Persistence","https://github.com/mdsecactivebreach/WMIPersistence","1","1","N/A","N/A","N/A","2","113","30","2019-05-29T09:48:46Z","2019-05-29T09:40:01Z","62990" +"*wmipersist.py*",".{0,1000}wmipersist\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Lateral Movement","https://github.com/fortra/impacket","1","1","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","62991" +"*wmipersist.py*",".{0,1000}wmipersist\.py.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","62992" +"*wmipersistence.py*",".{0,1000}wmipersistence\.py.{0,1000}","offensive_tool_keyword","silenttrinity","SILENTTRINITY is modern. asynchronous. multiplayer & multiserver C2/post-exploitation framework powered by Python 3 and .NETs DLR. Its the culmination of an extensive amount of research into using embedded third-party .NET scripting languages to dynamically call .NET APIs. a technique the author coined as BYOI (Bring Your Own Interpreter). The aim of this tool and the BYOI concept is to shift the paradigm back to PowerShell style like attacks (as it offers much more flexibility over traditional C# tradecraft) only without using PowerShell in anyway.","T1548.002 - T1134.001 - T1087.002 - T1010 - T1547.001 - T1059.001 - T1059.003 - T1059.006 - T1543.003 - T1555.003 - T1555.004 - T1546.001 - T1546.003 - T1546.015 - T1041 - T1083 - T1564.003 - T1562.001 - T1562.003 - T1070 - T1070.004 - T1105 - T1056.001 - T1056.002 - T1556 - T1112 - T1106 - T1046 - T1135 - T1003.001 - T1069.001 - T1069.002 - T1057 - T1055 - T1012 - T1021.003 - T1021.006 - T1018 - T1113 - T1518.001 - T1558.003 - T1082 - T1033 - T1007 - T1124 - T1552.006 - T1047","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","C2","https://github.com/byt3bl33d3r/SILENTTRINITY","1","1","N/A","N/A","N/A","10","2239","416","2023-12-06T17:17:24Z","2018-09-25T15:17:30Z","62993" +"*WMIPersistence.vbs*",".{0,1000}WMIPersistence\.vbs.{0,1000}","offensive_tool_keyword","phishing-HTML-linter","Phishing and Social-Engineering related scripts","T1566.001 - T1056.001","TA0040 - TA0001","N/A","N/A","Phishing","https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing","1","1","N/A","N/A","10","10","2689","527","2023-06-27T19:16:49Z","2018-02-02T21:24:03Z","62994" +"*WMIPersistImplant*",".{0,1000}WMIPersistImplant.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","62995" +"*WMI-ProcessCreate.cpp*",".{0,1000}WMI\-ProcessCreate\.cpp.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of beacon BOF written to learn windows and cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Yaxser/CobaltStrike-BOF","1","1","N/A","N/A","10","10","347","57","2023-02-24T13:12:14Z","2020-10-08T01:12:41Z","62996" +"*WMIReg.exe*",".{0,1000}WMIReg\.exe.{0,1000}","offensive_tool_keyword","sharpcollection","Nightly builds of common C# offensive tools. fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.","T1059 - T1027 - T1036 - T1562 - T1045 - T1024 - T1070 - T1574 - T1071 - T1078 - T1003 - T1072 - T1075 - T1077 - T1079 - T1083 - T1105 - T1106 - T1120 - T1135 - T1158 - T1204 - T1214 - T1215 - T1220 - T1221 - T1222 - T1223 - T1224 - T1227 - T1247 - T12","TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0010 - TA0011","N/A","Black Basta","Exploitation tool","https://github.com/Flangvik/SharpCollection","1","1","N/A","N/A","10","10","2452","358","2025-04-18T03:38:55Z","2020-06-05T12:50:00Z","62997" +"*WmiSploit.git*",".{0,1000}WmiSploit\.git.{0,1000}","offensive_tool_keyword","Wmisploit","WmiSploit is a small set of PowerShell scripts that leverage the WMI service for post-exploitation use.","T1087 - T1059.001 - T1047","TA0003 - TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/secabstraction/WmiSploit","1","1","N/A","N/A","N/A","2","164","34","2015-08-28T23:56:00Z","2015-03-15T03:30:02Z","62999" +"*WmiSploit-master/zip*",".{0,1000}WmiSploit\-master\/zip.{0,1000}","offensive_tool_keyword","Wmisploit","WmiSploit is a small set of PowerShell scripts that leverage the WMI service for post-exploitation use.","T1087 - T1059.001 - T1047","TA0003 - TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/secabstraction/WmiSploit","1","1","N/A","N/A","N/A","2","164","34","2015-08-28T23:56:00Z","2015-03-15T03:30:02Z","63000" +"*WNFarmDynamite_h.cs*",".{0,1000}WNFarmDynamite_h\.cs.{0,1000}","offensive_tool_keyword","WindfarmDynamite","WindfarmDynamite is a proof-of-concept for code injection using the Windows Notification Facility (WNF). Of interest here is that this avoids suspect thread orchestration APIs (like CreateRemoteThread)","T1055.013 - T1546.008","TA0005 - TA0004","N/A","N/A","Exploitation tool","https://github.com/FuzzySecurity/Sharp-Suite/tree/master/WindfarmDynamite","1","1","N/A","N/A","N/A","10","1131","203","2022-12-22T23:57:19Z","2018-12-10T00:08:37Z","63001" +"*wolfexp.net/other/Gh0st_RAT/demo.rar*",".{0,1000}wolfexp\.net\/other\/Gh0st_RAT\/demo\.rar.{0,1000}","offensive_tool_keyword","gh0st","Malware RAT with keylogger - dll injection - C2 - Remote control","T1204.002 - T1071.001 - T1027 - T1036.005 - T1055.001 - T1005 - T1056.001 - T1074.001 - T1105 - T1562.001 - T1543.003 - T1547.001 - T1571 - T1573.001 - T1106 - T1219","TA0002 - TA0003 - TA0004 - TA0008 - TA0009 - TA0010 - TA0011","GhostRAT","N/A","Malware","https://github.com/sin5678/gh0st","1","1","N/A","N/A","10","6","508","274","2013-05-08T21:17:26Z","2012-10-05T06:25:36Z","63002" +"*woqjumaahi662ka26jzxyx7fznbp4kg3bsjar4b52tqkxgm2pylcjlad.onion*",".{0,1000}woqjumaahi662ka26jzxyx7fznbp4kg3bsjar4b52tqkxgm2pylcjlad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","63003" +"*word_gen_b_varlen.*",".{0,1000}word_gen_b_varlen\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","63004" +"*word_unc_injector.*",".{0,1000}word_unc_injector\..{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","63005" +"*Wordlist/ftp_p.txt*",".{0,1000}Wordlist\/ftp_p\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63006" +"*Wordlist/ftp_u.txt*",".{0,1000}Wordlist\/ftp_u\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63007" +"*Wordlist/ftp_up.txt*",".{0,1000}Wordlist\/ftp_up\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63008" +"*Wordlist/mssql_up.txt*",".{0,1000}Wordlist\/mssql_up\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63009" +"*Wordlist/mysql_up.txt*",".{0,1000}Wordlist\/mysql_up\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63010" +"*Wordlist/oracle_up.txt*",".{0,1000}Wordlist\/oracle_up\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63011" +"*Wordlist/pass.txt*",".{0,1000}Wordlist\/pass\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63012" +"*Wordlist/pop_p.txt*",".{0,1000}Wordlist\/pop_p\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63013" +"*Wordlist/pop_u.txt*",".{0,1000}Wordlist\/pop_u\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63014" +"*Wordlist/postgres_up.txt*",".{0,1000}Wordlist\/postgres_up\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63015" +"*Wordlist/smtp_p.txt*",".{0,1000}Wordlist\/smtp_p\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63016" +"*Wordlist/smtp_u.txt*",".{0,1000}Wordlist\/smtp_u\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63017" +"*Wordlist/snmp.txt*",".{0,1000}Wordlist\/snmp\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63018" +"*Wordlist/sql_p.txt*",".{0,1000}Wordlist\/sql_p\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63019" +"*Wordlist/sql_u.txt*",".{0,1000}Wordlist\/sql_u\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63020" +"*Wordlist/ssh_p.txt*",".{0,1000}Wordlist\/ssh_p\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63021" +"*Wordlist/ssh_u.txt*",".{0,1000}Wordlist\/ssh_u\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63022" +"*Wordlist/ssh_up.txt*",".{0,1000}Wordlist\/ssh_up\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63023" +"*Wordlist/telnet_p.txt*",".{0,1000}Wordlist\/telnet_p\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63024" +"*Wordlist/telnet_u.txt*",".{0,1000}Wordlist\/telnet_u\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63025" +"*Wordlist/telnet_up.txt*",".{0,1000}Wordlist\/telnet_up\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63026" +"*Wordlist/user.txt*",".{0,1000}Wordlist\/user\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63027" +"*Wordlist/vnc_p.txt*",".{0,1000}Wordlist\/vnc_p\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63028" +"*Wordlist/windows_u.txt*",".{0,1000}Wordlist\/windows_u\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63029" +"*Wordlist/windows_up.txt*",".{0,1000}Wordlist\/windows_up\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63030" +"*wordlist_TLAs.txt*",".{0,1000}wordlist_TLAs\.txt.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","63031" +"*wordlist-nthash-reversed*",".{0,1000}wordlist\-nthash\-reversed.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","63033" +"*wordlist-probable.txt*",".{0,1000}wordlist\-probable\.txt.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","63034" +"*wordlists*all_in_one.7z*",".{0,1000}wordlists.{0,1000}all_in_one\.7z.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","63035" +"*wordlists*rmg.txt*",".{0,1000}wordlists.{0,1000}rmg\.txt.{0,1000}","offensive_tool_keyword","remote-method-guesser","remote-method-guesser?(rmg) is a?Java RMI?vulnerability scanner and can be used to identify and verify common security vulnerabilities on?Java RMI?endpoints.","T1210.002 - T1046 - T1078.003","TA0001 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/qtc-de/remote-method-guesser","1","1","N/A","N/A","6","9","860","108","2024-07-03T19:40:54Z","2019-11-04T11:37:38Z","63036" +"*wordlists*rmiscout.txt*",".{0,1000}wordlists.{0,1000}rmiscout\.txt.{0,1000}","offensive_tool_keyword","remote-method-guesser","remote-method-guesser?(rmg) is a?Java RMI?vulnerability scanner and can be used to identify and verify common security vulnerabilities on?Java RMI?endpoints.","T1210.002 - T1046 - T1078.003","TA0001 - TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/qtc-de/remote-method-guesser","1","1","N/A","N/A","6","9","860","108","2024-07-03T19:40:54Z","2019-11-04T11:37:38Z","63037" +"*wordlists/dynamic-all.txt*",".{0,1000}wordlists\/dynamic\-all\.txt.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","63038" +"*wordlists/fasttrack.txt*",".{0,1000}wordlists\/fasttrack\.txt.{0,1000}","offensive_tool_keyword","cerbrutus","Network brute force tool. written in Python. Faster than other existing solutions (including the main leader in the network brute force market).","T1110 - T1040 - T1496","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/Cerbrutus-BruteForcer/cerbrutus","1","1","N/A","N/A","N/A","4","385","57","2021-08-22T19:05:45Z","2021-07-07T19:11:40Z","63039" +"*wordlists/rockyou.txt'*",".{0,1000}wordlists\/rockyou\.txt\'.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","63040" +"*wordlists/subdomains-5000.txt*",".{0,1000}wordlists\/subdomains\-5000\.txt.{0,1000}","offensive_tool_keyword","DOME","DOME - A subdomain enumeration tool","T1583 - T1595 - T1190","TA0011 - TA0009","N/A","N/A","Reconnaissance","https://github.com/v4d1/Dome","1","1","N/A","N/A","5","6","531","74","2024-02-07T09:12:17Z","2022-02-20T15:09:40Z","63041" +"*wordlists/top1million.txt*",".{0,1000}wordlists\/top1million\.txt.{0,1000}","offensive_tool_keyword","DOME","DOME - A subdomain enumeration tool","T1583 - T1595 - T1190","TA0011 - TA0009","N/A","N/A","Reconnaissance","https://github.com/v4d1/Dome","1","1","N/A","N/A","5","6","531","74","2024-02-07T09:12:17Z","2022-02-20T15:09:40Z","63042" +"*WorldWind Stealer.zip*",".{0,1000}WorldWind\sStealer\.zip.{0,1000}","offensive_tool_keyword","WorldWind-Stealer","WorldWind Stealer This stealer sends logs directly to your telegram id from a Bot that YOU Create with telegram","T1114.002 - T1071.001 - T1552.002","TA0011 - TA0005 - TA0040","N/A","N/A","Malware","https://github.com/Leecher21/WorldWind-Stealer","1","1","N/A","N/A","10","1","20","2","2023-03-25T09:54:01Z","2023-02-07T11:44:42Z","63045" +"*WorldWind-Stealer*",".{0,1000}WorldWind\-Stealer.{0,1000}","offensive_tool_keyword","WorldWind-Stealer","WorldWind Stealer This stealer sends logs directly to your telegram id from a Bot that YOU Create with telegram","T1114.002 - T1071.001 - T1552.002","TA0011 - TA0005 - TA0040","N/A","N/A","Malware","https://github.com/Leecher21/WorldWind-Stealer","1","1","N/A","N/A","10","1","20","2","2023-03-25T09:54:01Z","2023-02-07T11:44:42Z","63046" +"*wpapcap2john.*",".{0,1000}wpapcap2john\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","63049" +"*wp-exploitable-plugins.txt*",".{0,1000}wp\-exploitable\-plugins\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","63050" +"*wpscanteam/tap/wpscan*",".{0,1000}wpscanteam\/tap\/wpscan.{0,1000}","offensive_tool_keyword","WPScan","WPScan is a black box WordPress vulnerability scanner.","T1190 - T1210.001 - T1195","TA0007 - TA0010 - ","N/A","ENERGETIC BEAR - EMBER BEAR","Vulnerability Scanner","https://github.com/wpscanteam/wpscan","1","1","#linux","N/A","6","10","8959","1283","2025-04-07T11:27:58Z","2012-07-11T20:27:47Z","63053" +"*wpscanteam/wpscan*",".{0,1000}wpscanteam\/wpscan.{0,1000}","offensive_tool_keyword","WPScan","WPScan is a black box WordPress vulnerability scanner.","T1190 - T1210.001 - T1195","TA0007 - TA0010 - ","N/A","ENERGETIC BEAR - EMBER BEAR","Vulnerability Scanner","https://github.com/wpscanteam/wpscan","1","1","#linux","N/A","6","10","8959","1283","2025-04-07T11:27:58Z","2012-07-11T20:27:47Z","63054" +"*Wra7h/SingleDose*",".{0,1000}Wra7h\/SingleDose.{0,1000}","offensive_tool_keyword","SingleDose","SingleDose is a framework to build shellcode load/process injection techniques","T1055 - T1185","TA0005 - TA0003","N/A","N/A","Defense Evasion","https://github.com/Wra7h/SingleDose","1","1","N/A","N/A","10","2","155","29","2023-05-15T19:46:43Z","2021-08-28T05:04:50Z","63056" +"*wraith-labs/wraith*",".{0,1000}wraith\-labs\/wraith.{0,1000}","offensive_tool_keyword","wraith","A free and open-source, modular Remote Administration Tool (RAT) / Payload Dropper written in Go(lang) with a flexible command and control (C2) system.","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/wraith-labs/wraith","1","1","N/A","N/A","10","10","223","49","2023-12-03T22:16:27Z","2020-01-23T17:09:23Z","63057" +"*wrap_execute_assembly*",".{0,1000}wrap_execute_assembly.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","63058" +"*wrap_execute_encoded_powershell*",".{0,1000}wrap_execute_encoded_powershell.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","63059" +"*wrap_get_clipboard*",".{0,1000}wrap_get_clipboard.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","63060" +"*wrap_inject_shellc*",".{0,1000}wrap_inject_shellc.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","63061" +"*wrap_load_memfd*",".{0,1000}wrap_load_memfd.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","63062" +"*wrap_unhook_ntdll*",".{0,1000}wrap_unhook_ntdll.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","63063" +"*write_cs_teamserver*",".{0,1000}write_cs_teamserver.{0,1000}","offensive_tool_keyword","cobaltstrike","generate CobaltStrike's cross-platform payload","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/gloxec/CrossC2","1","1","N/A","N/A","10","10","2383","352","2023-11-20T10:54:46Z","2020-01-16T16:39:09Z","63067" +"*write_payload_dll_transacted*",".{0,1000}write_payload_dll_transacted.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","63068" +"*write_what_where.py*",".{0,1000}write_what_where\.py.{0,1000}","offensive_tool_keyword","POC","POC to check for CVE-2020-0796 / SMBGhost","T1210.001 - T1213 - T1212 - T1201","TA0007 - TA0002","N/A","N/A","Exploitation tool","https://github.com/ZecOps/CVE-2020-0796-LPE-POC","1","1","N/A","N/A","N/A","3","241","85","2020-04-02T08:01:38Z","2020-03-30T16:06:50Z","63069" +"*WriteAndExecuteShellcode*",".{0,1000}WriteAndExecuteShellcode.{0,1000}","offensive_tool_keyword","cobaltstrike","TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process. allocates a region of memory. writes shellcode into that region. and then uses CreateRemoteThread to execute said shellcode. Both the process and shellcode are specified by the user. The primary use case is as a JavaScript/VBScript loader via DotNetToJScript. which can be utilised in a variety of payload types such as HTA and VBA.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rasta-mouse/TikiTorch","1","1","N/A","N/A","10","10","761","139","2021-10-24T10:29:46Z","2019-02-19T14:49:17Z","63070" +"*WriteDLLPermission.txt*",".{0,1000}WriteDLLPermission\.txt.{0,1000}","offensive_tool_keyword","WinPwn","Automation for internal Windows Penetrationtest AD-Security","T1003 - T1087 - T1069 - T1047 - T1547.001 - T1035","TA0006 - TA0007 - TA0002 - TA0005 - TA0040","N/A","Dispossessor - Black Basta","Exploitation tool","https://github.com/S3cur3Th1sSh1t/WinPwn","1","1","N/A","N/A","10","10","3473","535","2024-11-26T07:50:22Z","2018-03-07T12:51:25Z","63072" +"*Write-HijackDll*",".{0,1000}Write\-HijackDll.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","Invoke-BypassUAC.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","63075" +"*Write-HijackDll*",".{0,1000}Write\-HijackDll.{0,1000}","offensive_tool_keyword","empire","Empire scripts functions. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1106","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","PowerUp.ps1","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","63076" +"*Write-HijackDll*",".{0,1000}Write\-HijackDll.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","63077" +"*WritePayloadDllTransacted*",".{0,1000}WritePayloadDllTransacted.{0,1000}","offensive_tool_keyword","cobaltstrike","A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/EspressoCake/PPLDump_BOF","1","1","N/A","N/A","10","10","140","25","2021-09-24T07:10:04Z","2021-09-24T07:05:59Z","63088" +"*Write-PortscanOut*",".{0,1000}Write\-PortscanOut.{0,1000}","offensive_tool_keyword","AutoRDPwn","AutoRDPwn is a post-exploitation framework created in Powershell designed primarily to automate the Shadow attack on Microsoft Windows computers","T1078 - T1021.001 - T1003.001 - T1547.009 - T1543.003 - T1056.001 - T1021.002","TA0004 - TA0003 - TA0006 - TA0002 - TA0008","N/A","N/A","Framework","https://github.com/JoelGMSec/AutoRDPwn","1","1","N/A","N/A","10","10","1103","499","2022-09-04T20:44:27Z","2018-07-29T08:22:20Z","63089" +"*Write-PrivescCheckAsciiReport*",".{0,1000}Write\-PrivescCheckAsciiReport.{0,1000}","offensive_tool_keyword","empire","Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1157","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/BC-SECURITY/Empire","1","1","N/A","N/A","10","10","4527","608","2025-04-07T03:02:25Z","2019-08-01T04:22:31Z","63090" +"*Write-ServiceBinary*",".{0,1000}Write\-ServiceBinary.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Exploit an unquoted service path vulnerability to spawn a beacon","T1550 - T1555 - T1212 - T1558","N/A","N/A","Black Basta","Exploitation tool","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","63091" +"*WSAAcceptBackdoor-master.zip*",".{0,1000}WSAAcceptBackdoor\-master\.zip.{0,1000}","offensive_tool_keyword","WSAAcceptBackdoor","Winsock accept() Backdoor Implant","T1574.001 - T1059 - T1213 - T1105 - T1546","TA0003 - TA0004 - TA0005","N/A","N/A","Persistence","https://github.com/EgeBalci/WSAAcceptBackdoor","1","1","N/A","N/A","10","2","112","23","2021-02-13T19:18:41Z","2021-02-13T15:59:01Z","63101" +"*wscript_elevator*",".{0,1000}wscript_elevator.{0,1000}","offensive_tool_keyword","cobaltstrike","The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/ElevateKit","1","1","N/A","N/A","10","10","912","203","2020-06-22T21:12:24Z","2016-12-08T03:51:09Z","63102" +"*WScriptBypassUAC*",".{0,1000}WScriptBypassUAC.{0,1000}","offensive_tool_keyword","empire","Empire scripts paths. Empire is an open source. cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python. the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries","T1548.002 - T1134 - T1134.002 - T1134.005 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560 - T1119 - T1020 - T1547.001 - T1547.005 - T1547.009 - T1217 - T1115 - T1059.001 - T1059.003 - T1136.001 - T1136.002 - T1543.003 - T1555.003 - T1484.001 - T1482 - T1114.001 - T1573.002 - T1546.008 - T1041 - T1567.001 - T1567.002 - T1068 - T1210 - T1083 - T1615 - T1574.001 - T1574.004 - T1574.007 - T1574.008 - T1574.009 - T1070.006 - T1105 - T1056.001 - T1056.004 - T1106 - T1046 - T1135 - T1040 - T1027 - T1003.001 - T1057 - T1055 - T1021.003 - T1021.004 - T1053.005 - T1113 - T1518.001 - T1558.001 - T1558.002 - T1558.003 - T1082 - T1016 - T1049 - T1033 - T1569.002 - T1127.001 - T1552.001 - T1552.004 - T1550.002 - T1125 - T1102.002 - T1131","TA0004 - TA0006 - TA0007 - TA0040 - TA0010 - TA0011 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Dispossessor - APT19 - APT33 - APT41 - Avaddon - BlackByte - BlackCat - CL0P - Conti - CopyKittens - FIN10 - FIN13 - HEXANE - Hive - Indrik Spider - LazyScripter - Leviathan - LockBit - MuddyWater - PYSA - Silence - Turla - Vice Society - WIRTE - Wizard Spider - CopyKittens - INDRIK SPIDER - Black Basta","Framework","https://github.com/EmpireProject/Empire","1","1","N/A","N/A","10","10","7589","2850","2020-01-19T22:50:59Z","2015-08-05T18:25:57Z","63103" +"*wstunnel/pkgs/container/wstunnel*",".{0,1000}wstunnel\/pkgs\/container\/wstunnel.{0,1000}","offensive_tool_keyword","wstunnel","Tunnel all your traffic over websocket protocol - Bypass firewalls/DPI - Static binary available","T1572 - T1090 - T1071","TA0005- TA0010 - TA0011","N/A","Scattered Spider*","Data Exfiltration","https://github.com/erebe/wstunnel","1","1","N/A","N/A","10","10","4759","404","2025-04-15T11:07:11Z","2016-05-14T23:58:43Z","63115" +"*wstunnel_*_darwin_amd64.tar.gz*",".{0,1000}wstunnel_.{0,1000}_darwin_amd64\.tar\.gz.{0,1000}","offensive_tool_keyword","wstunnel","Tunnel all your traffic over websocket protocol - Bypass firewalls/DPI - Static binary available","T1572 - T1090 - T1071","TA0005- TA0010 - TA0011","N/A","Scattered Spider*","Data Exfiltration","https://github.com/erebe/wstunnel","1","1","#linux","N/A","10","10","4759","404","2025-04-15T11:07:11Z","2016-05-14T23:58:43Z","63116" +"*wstunnel_*_linux_amd64.tar.gz*",".{0,1000}wstunnel_.{0,1000}_linux_amd64\.tar\.gz.{0,1000}","offensive_tool_keyword","wstunnel","Tunnel all your traffic over websocket protocol - Bypass firewalls/DPI - Static binary available","T1572 - T1090 - T1071","TA0005- TA0010 - TA0011","N/A","Scattered Spider*","Data Exfiltration","https://github.com/erebe/wstunnel","1","1","#linux","N/A","10","10","4759","404","2025-04-15T11:07:11Z","2016-05-14T23:58:43Z","63117" +"*wstunnel_*_linux_arm64.tar.gz*",".{0,1000}wstunnel_.{0,1000}_linux_arm64\.tar\.gz.{0,1000}","offensive_tool_keyword","wstunnel","Tunnel all your traffic over websocket protocol - Bypass firewalls/DPI - Static binary available","T1572 - T1090 - T1071","TA0005- TA0010 - TA0011","N/A","Scattered Spider*","Data Exfiltration","https://github.com/erebe/wstunnel","1","1","#linux","N/A","10","10","4759","404","2025-04-15T11:07:11Z","2016-05-14T23:58:43Z","63118" +"*wstunnel_*_linux_armv7.tar.gz*",".{0,1000}wstunnel_.{0,1000}_linux_armv7\.tar\.gz.{0,1000}","offensive_tool_keyword","wstunnel","Tunnel all your traffic over websocket protocol - Bypass firewalls/DPI - Static binary available","T1572 - T1090 - T1071","TA0005- TA0010 - TA0011","N/A","Scattered Spider*","Data Exfiltration","https://github.com/erebe/wstunnel","1","1","#linux","N/A","10","10","4759","404","2025-04-15T11:07:11Z","2016-05-14T23:58:43Z","63119" +"*wstunnel_*_windows_386.tar.gz*",".{0,1000}wstunnel_.{0,1000}_windows_386\.tar\.gz.{0,1000}","offensive_tool_keyword","wstunnel","Tunnel all your traffic over websocket protocol - Bypass firewalls/DPI - Static binary available","T1572 - T1090 - T1071","TA0005- TA0010 - TA0011","N/A","Scattered Spider*","Data Exfiltration","https://github.com/erebe/wstunnel","1","1","N/A","N/A","10","10","4759","404","2025-04-15T11:07:11Z","2016-05-14T23:58:43Z","63120" +"*wstunnel_*_windows_amd64.tar.gz*",".{0,1000}wstunnel_.{0,1000}_windows_amd64\.tar\.gz.{0,1000}","offensive_tool_keyword","wstunnel","Tunnel all your traffic over websocket protocol - Bypass firewalls/DPI - Static binary available","T1572 - T1090 - T1071","TA0005- TA0010 - TA0011","N/A","Scattered Spider*","Data Exfiltration","https://github.com/erebe/wstunnel","1","1","N/A","N/A","10","10","4759","404","2025-04-15T11:07:11Z","2016-05-14T23:58:43Z","63121" +"*WSUSpendu*",".{0,1000}WSUSpendu.{0,1000}","offensive_tool_keyword","WSUSpendu","At BlackHat USA 2015. the WSUSpect attack scenario has been released.Approximately at the same time. some french engineers have been wondering if it would be possible to use a compromised WSUS server to extend the compromise to its clients. similarly to this WSUSpect attack. After letting this topic rest for almost two years. we've been able. at Alsid and ANSSI. to demonstrate this attack.","T1563 - T1204 - T1210 - T1071","TA0001 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/AlsidOfficial/WSUSpendu","1","1","N/A","N/A","N/A","10","N/A","N/A","N/A","N/A","63122" +"*wsuxploit*",".{0,1000}wsuxploit.{0,1000}","offensive_tool_keyword","wsuxploit","This is a MiTM weaponized exploit script to inject 'fake' updates into non-SSL WSUS traffic. It is based on the WSUSpect Proxy application that was introduced to public on the Black Hat USA 2015 presentation. 'WSUSpect Compromising the Windows Enterprise via Windows Update","T1557.001 - T1557.002 - T1573 - T1210.001","TA0001 - TA0002 - TA0007 - TA0008","N/A","N/A","Sniffing & Spoofing","https://github.com/pimps/wsuxploit","1","1","N/A","N/A","N/A","3","284","45","2022-11-25T10:04:15Z","2017-06-30T01:06:41Z","63123" +"*wts_enum_remote_processes*",".{0,1000}wts_enum_remote_processes.{0,1000}","offensive_tool_keyword","cobaltstrike","Collection of Beacon Object Files (BOFs) for shells and lols","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/RiccardoAncarani/BOFs","1","1","N/A","N/A","10","10","118","13","2021-09-14T09:03:58Z","2021-08-27T10:04:12Z","63124" +"*wtyafjyhwqrgo4a45wdvvwhen3cx4euie73qvlhkhvlrexljoyuklaad.onion*",".{0,1000}wtyafjyhwqrgo4a45wdvvwhen3cx4euie73qvlhkhvlrexljoyuklaad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","63126" +"*wumb0/rust_bof*",".{0,1000}wumb0\/rust_bof.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike Beacon Object Files (BOFs) written in rust with rust core and alloc.","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/wumb0/rust_bof","1","1","N/A","N/A","10","10","262","27","2024-02-08T20:45:00Z","2022-02-28T23:46:00Z","63127" +"*WwBTAHkAcwB0AGUAbQAuAFMAZQBjAHUAcgBpAHQAeQAuAFAAcgBpAG4AYwBpAHAAYQBsAC4AVwBpAG4AZABvAHcAcwBJAGQAZQBuAHQAaQB0AHkAXQA6ADoARwBlAHQAQwB1AHIAcgBlAG4AdAAoACkALgBuAGEAbQBlAAoA*",".{0,1000}WwBTAHkAcwB0AGUAbQAuAFMAZQBjAHUAcgBpAHQAeQAuAFAAcgBpAG4AYwBpAHAAYQBsAC4AVwBpAG4AZABvAHcAcwBJAGQAZQBuAHQAaQB0AHkAXQA6ADoARwBlAHQAQwB1AHIAcgBlAG4AdAAoACkALgBuAGEAbQBlAAoA.{0,1000}","offensive_tool_keyword","nimbo-c2","Nimbo-C2 is yet another (simple and lightweight) C2 framework","T1059 - T1078 - T1102 - T1105 - T1132 - T1136 - T1140 - T1204 - T1219 - T1543 - T1547 - T1553 - T1573 - T1574 - T1608","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0011","N/A","N/A","C2","https://github.com/itaymigdal/Nimbo-C2","1","1","N/A","N/A","10","10","392","48","2024-10-20T10:44:20Z","2022-10-08T19:02:58Z","63137" +"*www.4everproxy.com/tor-proxy*",".{0,1000}www\.4everproxy\.com\/tor\-proxy.{0,1000}","offensive_tool_keyword","4everproxy","proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://www.4everproxy.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","63140" +"*www.ampliasecurity.com/research/wce12*",".{0,1000}www\.ampliasecurity\.com\/research\/wce12.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","1","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","63142" +"*www.bad-rat.de.vu*",".{0,1000}www\.bad\-rat\.de\.vu.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","63145" +"*www.crackmd5.ru*",".{0,1000}www\.crackmd5\.ru.{0,1000}","offensive_tool_keyword","crackmd5.ru","site to crack md5 hashes used by Dispossessor ransomware groups and many others","T1003.002 - T1027 - T1213","TA0006 - TA0008 - TA0040","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","63146" +"*www.exploit-db.com/download/*",".{0,1000}www\.exploit\-db\.com\/download\/.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","63148" +"*www.ftp.ne.jp/Linux/packages/blackarch/*/os/*",".{0,1000}www\.ftp\.ne\.jp\/Linux\/packages\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","63149" +"*www.kali.org/get-kali/*",".{0,1000}www\.kali\.org\/get\-kali\/.{0,1000}","offensive_tool_keyword","kali","Kali Linux usage","T1210.001 - T1185 - T1059 - T1400 - T1506 - T1213","TA0001 - TA0002 - TA0009","N/A","Black Basta","Exploitation OS","https://www.kali.org/","1","1","#linux","N/A","10","10","N/A","N/A","N/A","N/A","63152" +"*www.leviathansecurity.com/blog/tunnelvision*",".{0,1000}www\.leviathansecurity\.com\/blog\/tunnelvision.{0,1000}","offensive_tool_keyword","TunnelVision","TunnelVision uses DHCP option 121 to manipulate routing tables and decloak VPN traffic","T1557 - T1498.003","TA0009 - TA0040","N/A","N/A","Sniffing & Spoofing","https://github.com/leviathansecurity/TunnelVision","1","1","N/A","N/A","9","2","132","17","2024-05-08T19:40:13Z","2024-03-11T22:24:56Z","63153" +"*www.mirrorservice.org/sites/blackarch.org/blackarch/*/os/*",".{0,1000}www\.mirrorservice\.org\/sites\/blackarch\.org\/blackarch\/.{0,1000}\/os\/.{0,1000}","offensive_tool_keyword","blackarch","offensive distribution - url used by the OS for updates","T1071.001 - T1105","TA0009","N/A","N/A","Exploitation OS","https://github.com/BlackArch/blackarch","1","1","N/A","N/A","10","10","2969","595","2025-04-22T06:14:44Z","2012-08-16T16:03:43Z","63158" +"*www.nicerat.com*",".{0,1000}www\.nicerat\.com.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","1","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","63159" +"*www.revshells.com*",".{0,1000}www\.revshells\.com.{0,1000}","offensive_tool_keyword","Rev-Shell","Basic script to generate reverse shell payloads","T1055.011 - T1021.005 - T1560.001","TA0002 - TA0005 - TA0042 - TA0011","N/A","N/A","C2","https://github.com/washingtonP1974/Rev-Shell","1","1","N/A","N/A","3","10","29","1","2024-03-20T13:58:21Z","2024-03-20T13:37:12Z","63161" +"*www.securityfocus.com/archive/1/514379*",".{0,1000}www\.securityfocus\.com\/archive\/1\/514379.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","63162" +"*www.tinymet.com*",".{0,1000}www\.tinymet\.com.{0,1000}","offensive_tool_keyword","TinyMet","meterpreter stager","T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043","N/A","CL0P - FIN7 - FIN11 - Silence group - GOLD EVERGREEN","C2","https://github.com/SherifEldeeb/TinyMet","1","1","N/A","N/A","10","10","128","43","2019-08-20T04:39:22Z","2014-05-17T13:31:55Z","63165" +"*www.tor2web.org*",".{0,1000}www\.tor2web\.org.{0,1000}","offensive_tool_keyword","tor2web","Tor2web is an HTTP proxy software that enables access to Tor Hidden Services by mean of common web browsers","T1090 - T1071","TA0001 - TA0005","N/A","N/A","Defense Evasion","https://github.com/tor2web/Tor2web","1","1","N/A","N/A","9","8","718","177","2024-05-24T11:51:09Z","2011-12-17T15:14:02Z","63166" +"*www.vsecurity.com/download/tools/*",".{0,1000}www\.vsecurity\.com\/download\/tools\/.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","63167" +"*www.wfuzz.org*",".{0,1000}www\.wfuzz\.org.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","63168" +"*wxfuzz.bat*",".{0,1000}wxfuzz\.bat.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","63170" +"*wxfuzz.py*",".{0,1000}wxfuzz\.py.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","63171" +"*wxxp3rny7w3j6gkel56iomdw2ztfzqxlsdw3fyezrnohgh767bau6dqd.onion*",".{0,1000}wxxp3rny7w3j6gkel56iomdw2ztfzqxlsdw3fyezrnohgh767bau6dqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","63172" +"*wy35mxvqxff4vufq64v4rrahxltn6ry33hjoogydwti6wbqutjaxrvid.onion*",".{0,1000}wy35mxvqxff4vufq64v4rrahxltn6ry33hjoogydwti6wbqutjaxrvid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","63173" +"*x64/CelestialSpark.asm*",".{0,1000}x64\/CelestialSpark\.asm.{0,1000}","offensive_tool_keyword","CelestialSpark","A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders Stardust","T1572 - T1048 - T1041 - T1105","TA0005 - TA0011 - TA0010","N/A","N/A","C2","https://github.com/Karkas66/CelestialSpark","1","1","N/A","N/A","10","10","103","10","2025-03-27T12:47:34Z","2024-04-11T12:17:22Z","63179" +"*x64PELoader/*.exe*",".{0,1000}x64PELoader\/.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","63183" +"*x64win-DynamicNoNull-WinExec-PopCalc-Shellcode*",".{0,1000}x64win\-DynamicNoNull\-WinExec\-PopCalc\-Shellcode.{0,1000}","offensive_tool_keyword","Dinjector","Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL","T1055 - T1055.012 - T1055.001 - T1027.002","TA0005 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Metro-Holografix/DInjector","1","1","N/A","private github repo","8","","N/A","","","","63184" +"*x86_64-unknown-uefi*",".{0,1000}x86_64\-unknown\-uefi.{0,1000}","offensive_tool_keyword","bootkit-rs","Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus)","T1542.004 - T1067.002 - T1012 - T1053.005 - T1057","TA0002 - TA0040 - TA0003 - TA0001","N/A","N/A","Defense Evasion","https://github.com/memN0ps/bootkit-rs","1","1","N/A","N/A","N/A","6","528","67","2023-09-12T07:23:15Z","2023-04-11T03:53:15Z","63185" +"*x86PELoader/*.exe*",".{0,1000}x86PELoader\/.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","63186" +"*x86PELoader/test_agent_dll*",".{0,1000}x86PELoader\/test_agent_dll.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","63187" +"*x86PELoader/test_agent_exe*",".{0,1000}x86PELoader\/test_agent_exe.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","63188" +"*x86PELoader/test_proxy_dll*",".{0,1000}x86PELoader\/test_proxy_dll.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","63189" +"*x86PELoader/test_proxy_exe*",".{0,1000}x86PELoader\/test_proxy_exe.{0,1000}","offensive_tool_keyword","AlanFramework","Alan Framework is a post-exploitation framework useful during red-team activities.","T1055 - T1071 - T1060 - T1560 - T1021 - T1005 - T1018","TA0002 - TA0005 - TA0011 - TA0008 - TA0010","N/A","N/A","C2","https://github.com/enkomio/AlanFramework","1","1","N/A","N/A","10","10","472","72","2024-01-24T20:30:39Z","2021-01-26T22:56:50Z","63190" +"*x90skysn3k/brutespray*",".{0,1000}x90skysn3k\/brutespray.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","1","N/A","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","63191" +"*xaitax/Chrome-App-Bound-Encryption-Decryption*",".{0,1000}xaitax\/Chrome\-App\-Bound\-Encryption\-Decryption.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","1","N/A","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","63192" +"*xaitax/TotalRecall*",".{0,1000}xaitax\/TotalRecall.{0,1000}","offensive_tool_keyword","TotalRecall","extracts and displays data from the Recall feature in Windows 11","T1005 - T1113 - T1056.001 - T1003","TA0009 - TA0010 - TA0006 - TA0007","N/A","N/A","Sniffing & Spoofing","https://github.com/xaitax/TotalRecall","1","1","N/A","N/A","10","10","2011","159","2024-06-08T09:25:08Z","2024-06-03T16:38:04Z","63193" +"*xato-net-10-million-usernames.txt*",".{0,1000}xato\-net\-10\-million\-usernames\.txt.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","63195" +"*X-C2-Beacon*",".{0,1000}X\-C2\-Beacon.{0,1000}","offensive_tool_keyword","DoHC2","DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH). This is built for the popular Adversary Simulation and Red Team Operations Software Cobalt Strike","T1090.004 - T1021.002 - T1071.001","TA0011 - TA0008","N/A","N/A","C2","https://github.com/SpiderLabs/DoHC2","1","1","N/A","N/A","10","10","443","95","2020-08-07T12:48:13Z","2018-10-23T19:40:23Z","63196" +"*x-cod3r/Remote-administration-tools-archive*",".{0,1000}x\-cod3r\/Remote\-administration\-tools\-archive.{0,1000}","offensive_tool_keyword","Malware RAT collection","from Malware RAT samples","T1105 - T1059 - T1109 - T1016 - T1071.001 - T1082 - T1027 - T1083 - T1056 - T1106 - T1078 - T1053","TA0011 - TA0009 - TA0006 - TA0003 - TA0002 - TA0005 - TA0007","N/A","N/A","Malware","https://github.com/x-cod3r/Remote-administration-tools-archive","1","1","N/A","N/A","9","1","93","30","2023-10-03T15:08:22Z","2023-10-03T13:09:00Z","63197" +"*xelroth/DEDSEC-RANSOMWARE*",".{0,1000}xelroth\/DEDSEC\-RANSOMWARE.{0,1000}","offensive_tool_keyword","DEDSEC-RANSOMWARE","dedsec ransomware","T1486 - T1489 - T1490 - T1495 - T1488 - T1482","TA0040 - TA0043 - TA0042 - TA0009 - TA0010","N/A","N/A","Ransomware","https://github.com/xelroth/DEDSEC-RANSOMWARE","1","1","N/A","N/A","10","1","7","1","2024-05-17T11:12:23Z","2024-05-17T10:34:03Z","63202" +"*xelroth/ShadowStealer*",".{0,1000}xelroth\/ShadowStealer.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","1","N/A","N/A","10","","N/A","","","","63203" +"*xeno rat client.exe*",".{0,1000}xeno\srat\sclient\.exe.{0,1000}","offensive_tool_keyword","xeno-rat","Xeno-RAT is an open-source remote access tool (RAT) developed in C# providing a comprehensive set of features for remote system management. Has features such as HVNC - live microphone - reverse proxy and much much more","T1133 - T1021.001 - T1563.002 - T1113 - T1123 - T1571 - T1090","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011","N/A","N/A","C2","https://github.com/moom825/xeno-rat","1","1","N/A","N/A","10","10","1225","323","2024-03-05T06:22:36Z","2023-10-17T06:41:56Z","63204" +"*xeno rat server.exe*",".{0,1000}xeno\srat\sserver\.exe.{0,1000}","offensive_tool_keyword","xeno-rat","Xeno-RAT is an open-source remote access tool (RAT) developed in C# providing a comprehensive set of features for remote system management. Has features such as HVNC - live microphone - reverse proxy and much much more","T1133 - T1021.001 - T1563.002 - T1113 - T1123 - T1571 - T1090","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011","N/A","N/A","C2","https://github.com/moom825/xeno-rat","1","1","N/A","N/A","10","10","1225","323","2024-03-05T06:22:36Z","2023-10-17T06:41:56Z","63205" +"*xeno%20rat%20client.exe*",".{0,1000}xeno\%20rat\%20client\.exe.{0,1000}","offensive_tool_keyword","xeno-rat","Xeno-RAT is an open-source remote access tool (RAT) developed in C# providing a comprehensive set of features for remote system management. Has features such as HVNC - live microphone - reverse proxy and much much more","T1133 - T1021.001 - T1563.002 - T1113 - T1123 - T1571 - T1090","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011","N/A","N/A","C2","https://github.com/moom825/xeno-rat","1","1","N/A","N/A","10","10","1225","323","2024-03-05T06:22:36Z","2023-10-17T06:41:56Z","63206" +"*xeno%20rat%20server.exe*",".{0,1000}xeno\%20rat\%20server\.exe.{0,1000}","offensive_tool_keyword","xeno-rat","Xeno-RAT is an open-source remote access tool (RAT) developed in C# providing a comprehensive set of features for remote system management. Has features such as HVNC - live microphone - reverse proxy and much much more","T1133 - T1021.001 - T1563.002 - T1113 - T1123 - T1571 - T1090","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011","N/A","N/A","C2","https://github.com/moom825/xeno-rat","1","1","N/A","N/A","10","10","1225","323","2024-03-05T06:22:36Z","2023-10-17T06:41:56Z","63207" +"*Xeno_manager.exe*",".{0,1000}Xeno_manager\.exe.{0,1000}","offensive_tool_keyword","xeno-rat","Xeno-RAT is an open-source remote access tool (RAT) developed in C# providing a comprehensive set of features for remote system management. Has features such as HVNC - live microphone - reverse proxy and much much more","T1133 - T1021.001 - T1563.002 - T1113 - T1123 - T1571 - T1090","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 - TA0011","N/A","N/A","C2","https://github.com/moom825/xeno-rat","1","1","N/A","N/A","10","10","1225","323","2024-03-05T06:22:36Z","2023-10-17T06:41:56Z","63208" +"*xforcered/CredBandit*",".{0,1000}xforcered\/CredBandit.{0,1000}","offensive_tool_keyword","cobaltstrike","Proof of concept Beacon Object File (BOF) that uses static x64 syscalls to perform a complete in memory dump of a process and send that back through your already existing Beacon communication channel","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/xforcered/CredBandit","1","1","N/A","N/A","10","10","240","26","2021-07-14T17:42:41Z","2021-03-17T15:19:33Z","63218" +"*xforcered/Detect-Hooks*",".{0,1000}xforcered\/Detect\-Hooks.{0,1000}","offensive_tool_keyword","cobaltstrike","Proof of concept Beacon Object File (BOF) that attempts to detect userland hooks in place by AV/EDR","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/xforcered/Detect-Hooks","1","1","N/A","N/A","10","10","100","6","2021-07-22T20:13:16Z","2021-07-23T16:10:37Z","63219" +"*xforwardedfor.py*",".{0,1000}xforwardedfor\.py.{0,1000}","offensive_tool_keyword","sqlmap","Automatic SQL injection and database takeover tool.","T1190 - T1556 - T1574","TA0001 - TA0002 - TA0005 - TA0007 - TA0042","N/A","Black Basta - Ajax Security Team - APT41 - ENERGETIC BEAR - APT35","Exploitation tool","https://github.com/sqlmapproject/sqlmap","1","1","#linux","N/A","N/A","10","33939","5862","2025-04-05T12:41:50Z","2012-06-26T09:52:15Z","63220" +"*xFreed0m/RDPassSpray*",".{0,1000}xFreed0m\/RDPassSpray.{0,1000}","offensive_tool_keyword","RDPassSpray","Python3 tool to perform password spraying using RDP","T1110.003 - T1059.006 - T1076.001","TA0001 - TA0002 - TA0008","N/A","N/A","Exploitation tool","https://github.com/xFreed0m/RDPassSpray","1","1","N/A","N/A","10","7","648","244","2023-08-17T15:09:50Z","2019-06-05T17:10:42Z","63221" +"*xfrm_poc*lucky0*",".{0,1000}xfrm_poc.{0,1000}lucky0.{0,1000}","offensive_tool_keyword","linux-exploit-suggester","Linux privilege escalation auditing tool","T1078 - T1068 - T1055","TA0004 - TA0003","N/A","N/A","Privilege Escalation","https://github.com/The-Z-Labs/linux-exploit-suggester","1","1","#linux","N/A","10","10","5909","1133","2024-02-17T11:44:50Z","2016-10-06T21:55:51Z","63223" +"*XiaoliChan/wmiexec-Pro*",".{0,1000}XiaoliChan\/wmiexec\-Pro.{0,1000}","offensive_tool_keyword","wmiexec-pro","The new generation of wmiexec.py with new features whole the operations only work with port 135 (don't need smb connection) for AV evasion in Lateral Movement","T1021.006 - T1560.001","TA0008 - TA0040","N/A","HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - DEV-0270 - MUSTANG PANDA","Lateral Movement","https://github.com/XiaoliChan/wmiexec-Pro","1","1","N/A","N/A","10","10","1070","134","2024-11-23T12:19:10Z","2023-04-04T06:24:07Z","63226" +"*XiebroC2-main.zip*",".{0,1000}XiebroC2\-main\.zip.{0,1000}","offensive_tool_keyword","XiebroC2","Command and control server - multi-person collaborative penetration testing graphical framework","T1105 - T1573.001 - T1055.001 - T1071 - T1041 - T1059.001 - T1059.008 - T1102","TA0011 - TA0003 - TA0005 - TA0007 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/INotGreen/XiebroC2","1","1","N/A","N/A","10","10","1200","192","2025-02-28T09:44:43Z","2024-02-15T15:46:07Z","63227" +"*XiebroC2-v*.7z*",".{0,1000}XiebroC2\-v.{0,1000}\.7z.{0,1000}","offensive_tool_keyword","XiebroC2","Command and control server - multi-person collaborative penetration testing graphical framework","T1105 - T1573.001 - T1055.001 - T1071 - T1041 - T1059.001 - T1059.008 - T1102","TA0011 - TA0003 - TA0005 - TA0007 - TA0009 - TA0010","N/A","N/A","C2","https://github.com/INotGreen/XiebroC2","1","1","N/A","N/A","10","10","1200","192","2025-02-28T09:44:43Z","2024-02-15T15:46:07Z","63228" +"*xillwillx/tricky.lnk*",".{0,1000}xillwillx\/tricky\.lnk.{0,1000}","offensive_tool_keyword","tricky.lnk","VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute","T1027 - T1036 - T1218.010","TA0002 - TA0003 - TA0008","N/A","N/A","Phishing","https://github.com/xillwillx/tricky.lnk","1","1","N/A","N/A","N/A","2","114","33","2020-12-19T23:42:10Z","2016-10-26T21:25:06Z","63229" +"*x-ishavocframework*",".{0,1000}x\-ishavocframework.{0,1000}","offensive_tool_keyword","havoc","Havoc is a modern and malleable post-exploitation command and control framework","T1573-001 - T1573-002 - T1573-003 - T1573-004 - T1573-005 - T1059-001 - T1059-003 - T1059-004 - T1003 - T1055 - T1036 - T1105 - T1218 - T1057 - T1574-001 - T1569-002","TA0002 - TA0003","N/A","Dispossessor","C2","https://github.com/its-a-feature/Mythic","1","1","N/A","N/A","10","10","3586","465","2025-04-16T18:01:45Z","2018-07-05T02:09:59Z","63231" +"*xjakumydulag5z65c7kd4agbxfyajpbrj6wfanj3koyhb5asq2x4e7yd.onion*",".{0,1000}xjakumydulag5z65c7kd4agbxfyajpbrj6wfanj3koyhb5asq2x4e7yd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","63232" +"*xjasonlyu/tun2socks*",".{0,1000}xjasonlyu\/tun2socks.{0,1000}","offensive_tool_keyword","tun2socks","socks tunneling","T1572 - T1090 - T1071 - T1573 - T1205","TA0010 - TA0011 - TA0008 - TA0005","N/A","N/A","C2","https://github.com/xjasonlyu/tun2socks","1","1","N/A","N/A","10","10","3785","513","2025-04-15T21:19:25Z","2019-07-16T03:25:40Z","63233" +"*xlowfznrg4wf7dli.onion*",".{0,1000}xlowfznrg4wf7dli\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","63235" +"*xmendez/wfuzz*",".{0,1000}xmendez\/wfuzz.{0,1000}","offensive_tool_keyword","wfuzz","Web application fuzzer.","T1210.001 - T1190 - T1595","TA0007 - TA0002 - TA0010","N/A","N/A","Reconnaissance","https://github.com/xmendez/wfuzz","1","1","#linux","N/A","9","10","6148","1384","2024-08-18T01:36:10Z","2014-10-22T21:23:49Z","63236" +"*XML-External-Entity-(XXE)-Payloads*",".{0,1000}XML\-External\-Entity\-\(XXE\)\-Payloads.{0,1000}","offensive_tool_keyword","Offensive-Payloads","List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.","T1210 - T1185 - T1059 - T1400 - T1506 - T1213 ","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/InfoSecWarrior/Offensive-Payloads/","1","1","N/A","N/A","N/A","4","328","117","2024-09-20T09:59:28Z","2022-11-18T09:43:41Z","63237" +"*xmr.2miners.com*",".{0,1000}xmr\.2miners\.com.{0,1000}","offensive_tool_keyword","SilentCryptoMiner","A Silent (Hidden) Free Crypto Miner Builder","T1496 - T1055 - T1546 - T1082 - T1574","TA0042 - TA0005 - TA0003 - TA0009","N/A","N/A","Cryptomining","https://github.com/UnamSanctam/SilentCryptoMiner","1","1","N/A","N/A","9","","N/A","","","","63238" +"*xnsbsjciylsg23zfmrv6ocuyh7ha5zexeouchlr3zsi5suda4arpeyqd.onion*",".{0,1000}xnsbsjciylsg23zfmrv6ocuyh7ha5zexeouchlr3zsi5suda4arpeyqd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","63259" +"*XOR Shellcode Encoder.csproj*",".{0,1000}XOR\sShellcode\sEncoder\.csproj.{0,1000}","offensive_tool_keyword","OSEP-Code-Snippets","notable code snippets for Offensive Security's PEN-300 (OSEP) course","T1116 - T1204.002 - T1027.009 - T1021.005 - T1560.001 - T1100 - T1003.001 - T1564.001 - T1047 - T1210 - T1134.002 - T1055 - T1055.011 - T1055.012 - T1204","TA0005 - TA0040 - TA0008 - TA0003 - TA0006 - TA0004","N/A","N/A","Exploitation tool","https://github.com/chvancooten/OSEP-Code-Snippets","1","1","N/A","N/A","8","10","1254","444","2024-01-04T15:17:17Z","2021-03-10T21:34:41Z","63260" +"*XOR_b64_encrypted*covenant.txt*",".{0,1000}XOR_b64_encrypted.{0,1000}covenant\.txt.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","63264" +"*XOR_b64_encrypted*covenant2.txt*",".{0,1000}XOR_b64_encrypted.{0,1000}covenant2\.txt.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","63265" +"*XOR_b64_encrypted*havoc.txt*",".{0,1000}XOR_b64_encrypted.{0,1000}havoc\.txt.{0,1000}","offensive_tool_keyword","Executable_Files","Database for custom made as well as publicly available stage-2 or beacons or stageless payloads used by loaders/stage-1/stagers or for further usage of C2 as well","T1071 - T1071.001 - T1105 - T1041 - T1102","TA0011 - TA0005 - TA0010","N/A","Black Basta","Exploitation tool","https://github.com/reveng007/Executable_Files","1","1","N/A","N/A","10","1","10","2","2025-02-11T08:08:04Z","2021-12-10T15:04:35Z","63266" +"*xor_payload*",".{0,1000}xor_payload.{0,1000}","offensive_tool_keyword","cobaltstrike","A simple python packer to easily bypass Windows Defender","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/Unknow101/FuckThatPacker","1","1","N/A","N/A","10","10","637","84","2022-04-03T18:20:01Z","2020-08-13T07:26:07Z","63269" +"*XorEncoder.py*",".{0,1000}XorEncoder\.py.{0,1000}","offensive_tool_keyword","inceptor","Template-Driven AV/EDR Evasion Framework","T1562.001 - T1059.003 - T1027.002 - T1070.004","TA0005 - TA0040","N/A","N/A","Defense Evasion","https://github.com/klezVirus/inceptor","1","1","N/A","N/A","10","10","1668","270","2023-11-03T09:33:21Z","2021-08-02T15:35:57Z","63271" +"*XorEncryptPayload.cpp*",".{0,1000}XorEncryptPayload\.cpp.{0,1000}","offensive_tool_keyword","Voidgate","bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes","T1027 - T1070 - T1055","TA0005","N/A","N/A","Defense Evasion","https://github.com/undergroundwires/privacy.sexy","1","1","N/A","N/A","9","10","4632","198","2025-04-21T21:36:39Z","2019-12-31T14:38:28Z","63272" +"*XorEncryptPayload.exe*",".{0,1000}XorEncryptPayload\.exe.{0,1000}","offensive_tool_keyword","Voidgate","bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes","T1027 - T1070 - T1055","TA0005","N/A","N/A","Defense Evasion","https://github.com/undergroundwires/privacy.sexy","1","1","N/A","N/A","9","10","4632","198","2025-04-21T21:36:39Z","2019-12-31T14:38:28Z","63273" +"*XorEncryptPayload.vcxproj*",".{0,1000}XorEncryptPayload\.vcxproj.{0,1000}","offensive_tool_keyword","Voidgate","bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes","T1027 - T1070 - T1055","TA0005","N/A","N/A","Defense Evasion","https://github.com/undergroundwires/privacy.sexy","1","1","N/A","N/A","9","10","4632","198","2025-04-21T21:36:39Z","2019-12-31T14:38:28Z","63274" +"*XOR-Payloads.py*",".{0,1000}XOR\-Payloads\.py.{0,1000}","offensive_tool_keyword","poshc2","keywords from poshc2 usage - a proxy aware C2 framework used to aid red teamers with post-exploitation and Lateral Movement.","T1548.002 - T1134 - T1134.002 - T1087.001 - T1087.002 - T1557.001 - T1071.001 - T1560.001 - T1119 - T1110 - T1555 - T1482 - T1546.003 - T1068 - T1210 - T1083 - T1056.001 - T1046 - T1040 - T1003.001 - T1201 - T1069.001 - T1055 - T1090 - T1082 - T1016 - T1049 - T1007 - T1569.002 - T1552.001 - T1550.002 - T1047","TA0004 - TA0008 - TA0009 - TA0011 - TA0006 - TA0003 - TA0007 - TA0005 - TA0010","N/A","Black Basta - APT33 - HEXANE - Sandworm - Dispossessor","C2","https://github.com/nettitude/PoshC2","1","1","N/A","N/A","10","10","1908","340","2025-03-06T11:10:20Z","2018-07-23T08:53:32Z","63275" +"*xpipe*lsass*",".{0,1000}xpipe.{0,1000}lsass.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF to list Windows Pipes & return their Owners & DACL Permissions","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/xPipe","1","1","N/A","N/A","10","10","77","23","2023-03-08T15:51:47Z","2021-12-07T22:56:30Z","63279" +"*xpipe.cna*",".{0,1000}xpipe\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF to list Windows Pipes & return their Owners & DACL Permissions","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/boku7/xPipe","1","1","N/A","N/A","10","10","77","23","2023-03-08T15:51:47Z","2021-12-07T22:56:30Z","63280" +"*xpn*ntlmquic*",".{0,1000}xpn.{0,1000}ntlmquic.{0,1000}","offensive_tool_keyword","ntlmquic","POC tools for exploring SMB over QUIC protocol","T1210.002 - T1210.003 - T1210.004","TA0001","N/A","N/A","Exploitation tool","https://github.com/xpn/ntlmquic","1","1","N/A","network exploitation tool","6","2","122","15","2022-04-06T11:22:11Z","2022-04-05T13:01:02Z","63281" +"*xpn/AppProxyC2*",".{0,1000}xpn\/AppProxyC2.{0,1000}","offensive_tool_keyword","AppProxyC2","simple POC to show how to tunnel traffic through Azure Application Proxy","T1090 - T1572 - T1071","TA0005 - TA0008 - TA0011","N/A","N/A","C2","https://github.com/xpn/AppProxyC2","1","1","N/A","N/A","9","10","69","18","2021-04-21T13:02:15Z","2021-04-21T10:46:16Z","63282" +"*Xre0uS/MultiDump*",".{0,1000}Xre0uS\/MultiDump.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","1","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","63284" +"*xRET2pwn/PickleC2*",".{0,1000}xRET2pwn\/PickleC2.{0,1000}","offensive_tool_keyword","PickleC2","PickleC2 is a post-exploitation and Lateral Movements framework","T1059.006 - T1021 - T1071 - T1550 - T1560 - T1570","TA0011 - TA0010 - TA0008","N/A","N/A","C2","https://github.com/xRET2pwn/PickleC2","1","1","N/A","N/A","10","10","91","20","2021-07-26T21:12:04Z","2021-07-13T09:16:19Z","63285" +"*XRMod_h64e.exe*",".{0,1000}XRMod_h64e\.exe.{0,1000}","offensive_tool_keyword","Xrulez","XRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.","T1078 - T1105 - T1059 - T1566","TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Persistence","https://github.com/FSecureLABS/Xrulez","1","1","N/A","N/A","10","2","162","45","2018-12-11T16:33:08Z","2016-08-31T10:10:10Z","63286" +"*XRulez.%2B.XRMod.rwdi.binaries.zip*",".{0,1000}XRulez\.\%2B\.XRMod\.rwdi\.binaries\.zip.{0,1000}","offensive_tool_keyword","Xrulez","XRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.","T1078 - T1105 - T1059 - T1566","TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Persistence","https://github.com/FSecureLABS/Xrulez","1","1","N/A","N/A","10","2","162","45","2018-12-11T16:33:08Z","2016-08-31T10:10:10Z","63291" +"*XRulez.%2B.XRMod.x64.binaries.zip*",".{0,1000}XRulez\.\%2B\.XRMod\.x64\.binaries\.zip.{0,1000}","offensive_tool_keyword","Xrulez","XRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.","T1078 - T1105 - T1059 - T1566","TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Persistence","https://github.com/FSecureLABS/Xrulez","1","1","N/A","N/A","10","2","162","45","2018-12-11T16:33:08Z","2016-08-31T10:10:10Z","63292" +"*XRulez.%2B.XRMod.x86.binaries.zip*",".{0,1000}XRulez\.\%2B\.XRMod\.x86\.binaries\.zip.{0,1000}","offensive_tool_keyword","Xrulez","XRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.","T1078 - T1105 - T1059 - T1566","TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Persistence","https://github.com/FSecureLABS/Xrulez","1","1","N/A","N/A","10","2","162","45","2018-12-11T16:33:08Z","2016-08-31T10:10:10Z","63293" +"*XRulez_h64d.dll*",".{0,1000}XRulez_h64d\.dll.{0,1000}","offensive_tool_keyword","Xrulez","XRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.","T1078 - T1105 - T1059 - T1566","TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Persistence","https://github.com/FSecureLABS/Xrulez","1","1","N/A","N/A","10","2","162","45","2018-12-11T16:33:08Z","2016-08-31T10:10:10Z","63296" +"*XRulez_h64e.exe*",".{0,1000}XRulez_h64e\.exe.{0,1000}","offensive_tool_keyword","Xrulez","XRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.","T1078 - T1105 - T1059 - T1566","TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Persistence","https://github.com/FSecureLABS/Xrulez","1","1","N/A","N/A","10","2","162","45","2018-12-11T16:33:08Z","2016-08-31T10:10:10Z","63297" +"*XRulez_rwdi86d.dll*",".{0,1000}XRulez_rwdi86d\.dll.{0,1000}","offensive_tool_keyword","Xrulez","XRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.","T1078 - T1105 - T1059 - T1566","TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Persistence","https://github.com/FSecureLABS/Xrulez","1","1","N/A","N/A","10","2","162","45","2018-12-11T16:33:08Z","2016-08-31T10:10:10Z","63298" +"*XRulezDll_rwdi64.dll*",".{0,1000}XRulezDll_rwdi64\.dll.{0,1000}","offensive_tool_keyword","Xrulez","XRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.","T1078 - T1105 - T1059 - T1566","TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Persistence","https://github.com/FSecureLABS/Xrulez","1","1","N/A","N/A","10","2","162","45","2018-12-11T16:33:08Z","2016-08-31T10:10:10Z","63299" +"*xscreensaver_log_priv_esc*",".{0,1000}xscreensaver_log_priv_esc.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","63301" +"*xshell_xftp_password.md*",".{0,1000}xshell_xftp_password\.md.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","63302" +"*XSS-labs*",".{0,1000}XSS\-labs.{0,1000}","offensive_tool_keyword","xss-labs","small set of PHP scripts to practice exploiting XSS and CSRF injection vulns","T1059.003 - T1190 - T1600","TA0002 - TA0007 - ","N/A","N/A","Vulnerability Scanner","https://github.com/paralax/xss-labs","1","1","N/A","N/A","N/A","1","60","27","2017-12-22T19:38:15Z","2016-03-24T19:43:37Z","63307" +"*XSS-Payloads*",".{0,1000}XSS\-Payloads.{0,1000}","offensive_tool_keyword","XSS-Payloads","A fine collection of selected javascript payloads.","T1059 - T1068 - T1071 - T1506","TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011","N/A","N/A","Vulnerability Scanner","http://www.xss-payloads.com/","1","1","N/A","N/A","N/A","8","N/A","N/A","N/A","N/A","63308" +"*xssrays.js*",".{0,1000}xssrays\.js.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","63309" +"*xssrays.rb*",".{0,1000}xssrays\.rb.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","63310" +"*xssrays_spec.rb*",".{0,1000}xssrays_spec\.rb.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","63311" +"*xssraysdetail.rb*",".{0,1000}xssraysdetail\.rb.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","63312" +"*xssraysscan.rb*",".{0,1000}xssraysscan\.rb.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","63313" +"*xsukax-Wordlist-All.7z*",".{0,1000}xsukax\-Wordlist\-All\.7z.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","63315" +"*xtr4nge/FruityC2*",".{0,1000}xtr4nge\/FruityC2.{0,1000}","offensive_tool_keyword","FruityC2","ruityC2 is a post-exploitation framework based on the deployment of agents on compromised machines","T1090 - T1572 - T1071.001","TA0010 - TA0011 - TA0008 - TA0005","N/A","MuddyWater","C2","https://github.com/xtr4nge/FruityC2","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","10","10","208","67","2017-12-04T17:05:23Z","2017-01-11T17:27:45Z","63317" +"*xvt-void/EnableAllTokenPrivs*",".{0,1000}xvt\-void\/EnableAllTokenPrivs.{0,1000}","offensive_tool_keyword","EnableAllTokenPrivs","Enable or Disable TokenPrivilege(s)","T1134 - T1055","TA0004 - TA0005","N/A","N/A","Defense Evasion","https://github.com/xvt-void/EnableAllTokenPrivs","1","1","N/A","N/A","7","1","13","5","2024-05-17T12:43:43Z","2024-02-17T15:39:25Z","63318" +"*xw7au5pnwtl6lozbsudkmyd32n6gnqdngitjdppybudan3x3pjgpmpid.onion*",".{0,1000}xw7au5pnwtl6lozbsudkmyd32n6gnqdngitjdppybudan3x3pjgpmpid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","63319" +"*XWorm-v5-Remote-Access-Tool*",".{0,1000}XWorm\-v5\-Remote\-Access\-Tool.{0,1000}","offensive_tool_keyword","Rhadamanthys","Fake Xworm - Rhadamanthys infostealer","T1583 - T1110 - T1082 - T1505 - T1567 - T1573","TA0006 - TA0003 - TA0004 - TA0005 - TA0009","N/A","N/A","Malware","https://github.com/koyaxZ/XWorm-v5-Remote-Access-Tool","1","1","N/A","N/A","10","","N/A","","","","63322" +"*XXEinjector*",".{0,1000}XXEinjector.{0,1000}","offensive_tool_keyword","XXEinjector","XXEinjector automates retrieving files using direct and out of band methods. Directory listing only works in Java applications. Bruteforcing method needs to be used for other applications.","T1573.001 - T1573.002 - T1574","TA0007 - ","N/A","N/A","Vulnerability Scanner","https://github.com/enjoiz/XXEinjector","1","1","N/A","N/A","10","10","1619","319","2024-12-01T15:25:27Z","2015-05-16T10:56:14Z","63324" +"*xxePayloads.ini*",".{0,1000}xxePayloads\.ini.{0,1000}","offensive_tool_keyword","wapiti","Web vulnerability scanner written in Python3","T1592 - T1592.003","TA0007 - TA0040","N/A","N/A","Vulnerability Scanner","https://github.com/wapiti-scanner/wapiti","1","1","N/A","N/A","N/A","10","1372","212","2025-04-16T11:41:00Z","2020-06-06T20:17:55Z","63325" +"*X-YSOSERIAL-NET*",".{0,1000}X\-YSOSERIAL\-NET.{0,1000}","offensive_tool_keyword","ysoserial.net","Deserialization payload generator for a variety of .NET formatters","T1059.007 - T1027.002 - T1059.001","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/pwntester/ysoserial.net","1","1","N/A","N/A","10","10","3385","493","2024-12-23T20:59:47Z","2017-09-18T17:48:08Z","63327" +"*yanncam/ShuckNT*",".{0,1000}yanncam\/ShuckNT.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","63337" +"*YaraFilters*lsassdump.yar*",".{0,1000}YaraFilters.{0,1000}lsassdump\.yar.{0,1000}","offensive_tool_keyword","EvtMute","This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging - mute the event log","T1562.004 - T1055.001 - T1070.004","TA0040 - TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/bats3c/EvtMute","1","1","N/A","N/A","10","3","261","51","2021-04-24T19:23:39Z","2020-08-29T00:13:20Z","63338" +"*yarrick/iodine*",".{0,1000}yarrick\/iodine.{0,1000}","offensive_tool_keyword","iodine","iodine. iodined - tunnel IPv4 over DNS","T1573.001 - T1573.002 - T1573.003 - T1573.004","TA0011 - TA0010 - TA0002 - TA0005","N/A","EMBER BEAR","C2","https://github.com/yarrick/iodine","1","1","N/A","N/A","10","10","6413","524","2025-04-08T17:44:12Z","2012-02-04T19:51:39Z","63341" +"*yasserbdj96/hiphp*",".{0,1000}yasserbdj96\/hiphp.{0,1000}","offensive_tool_keyword","hiphp","The BackDoor of HIPHP gives you the power to control websites based on PHP using HTTP/HTTPS protocol. By sending files - tokens and commands through port 80s POST/GET method - users can access a range of activities such as downloading and editing files. It also allows for connecting to Tor networks with password protection for extra security.","T1105 - T1071.001 - T1132 - T1505 - T1608 - T1560 ","TA0011 - TA0001 - TA0002 - TA0009","N/A","N/A","C2","https://github.com/yasserbdj96/hiphp","1","1","N/A","N/A","10","10","217","33","2025-04-19T07:05:12Z","2021-04-05T20:29:57Z","63342" +"*yasserjanah/CVE-2020-5902*",".{0,1000}yasserjanah\/CVE\-2020\-5902.{0,1000}","offensive_tool_keyword","POC","exploit code for F5-Big-IP (CVE-2020-5902)","T1210","TA0008","N/A","N/A","Exploitation tool","https://github.com/yasserjanah/CVE-2020-5902","1","1","N/A","N/A","N/A","1","43","15","2023-05-22T23:32:39Z","2020-07-06T01:12:23Z","63343" +"*YaWNdpwplLwycqWQDCyruhAFsYjWjnBA*",".{0,1000}YaWNdpwplLwycqWQDCyruhAFsYjWjnBA.{0,1000}","offensive_tool_keyword","ThunderShell","ThunderShell is a C# RAT that communicates via HTTP requests. All the network traffic is encrypted using a second layer of RC4 to avoid SSL interception and defeat network detection on the target system. RC4 is a weak cipher and is used to help obfuscate the traffic. HTTPS options should be used to provide integrity and strong encryption.","T1021.002 - T1573.002 - T1001.003","TA0008 - TA0011 - TA0040","N/A","LockBit","C2","https://github.com/Mr-Un1k0d3r/ThunderShell","1","1","N/A","N/A","10","10","779","223","2023-03-29T21:57:08Z","2017-09-12T01:11:29Z","63344" +"*Yaxser/Backstab*",".{0,1000}Yaxser\/Backstab.{0,1000}","offensive_tool_keyword","Backstab","A tool to kill antimalware protected processes","T1562.001 - T1569 - T1059","TA0005 - TA0040 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Yaxser/Backstab","1","1","N/A","N/A","10","10","1435","244","2021-06-19T20:01:52Z","2021-06-15T16:02:11Z","63345" +"*yck1509/ConfuserEx*",".{0,1000}yck1509\/ConfuserEx.{0,1000}","offensive_tool_keyword","ConfuserEx","ConfuserEx is a widely used open source obfuscator often found in malware","T1027 - T1045","TA0005 ","N/A","N/A","Defense Evasion","https://github.com/yck1509/ConfuserEx","1","1","N/A","N/A","6","10","3629","1661","2019-05-14T14:23:56Z","2014-03-28T07:00:26Z","63347" +"*YDHCUI/csload.net*",".{0,1000}YDHCUI\/csload\.net.{0,1000}","offensive_tool_keyword","cobaltstrike","A cobaltstrike shellcode loader - past domestic mainstream antivirus software","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/YDHCUI/csload.net","1","1","N/A","N/A","10","10","122","15","2021-05-21T02:36:03Z","2021-05-20T08:24:16Z","63348" +"*YDHCUI/manjusaka*",".{0,1000}YDHCUI\/manjusaka.{0,1000}","offensive_tool_keyword","cobaltstrike","Chinese clone of cobaltstrike","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/YDHCUI/manjusaka","1","1","N/A","N/A","10","10","818","150","2023-05-09T03:31:53Z","2022-03-18T08:16:04Z","63349" +"*yehia-mamdouh/Lsassx*",".{0,1000}yehia\-mamdouh\/Lsassx.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","1","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","63351" +"*yehia-mamdouh/Shell3er*",".{0,1000}yehia\-mamdouh\/Shell3er.{0,1000}","offensive_tool_keyword","Shell3er","PowerShell Reverse Shell","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/yehia-mamdouh/Shell3er","1","1","N/A","N/A","9","10","61","14","2023-05-07T16:02:41Z","2023-05-07T15:35:16Z","63352" +"*yehia-mamdouh/var0xshell*",".{0,1000}yehia\-mamdouh\/var0xshell.{0,1000}","offensive_tool_keyword","var0xshell","var0xshell - shell with xor encryption","T1059 - T1204 - T1105 - T1136 - T1021","TA0002 - TA0003 - TA0011","N/A","N/A","C2","https://github.com/yehia-mamdouh/var0xshell/tree/main","1","1","N/A","N/A","8","10","4","1","2023-01-09T06:53:42Z","2023-01-08T21:34:26Z","63353" +"*yeuajcizwytgmrntijhxphs6wn5txp2prs6rpndafbsapek3zd4ubcid.onion*",".{0,1000}yeuajcizwytgmrntijhxphs6wn5txp2prs6rpndafbsapek3zd4ubcid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","63354" +"*yisier/nps*",".{0,1000}yisier\/nps.{0,1000}","offensive_tool_keyword","nps","chinese intranet penetration proxy server","T1090 - T1071 - T1102 - T1075 - T1133","TA0002 - TA0011 - TA0010","N/A","N/A","Defense Evasion","https://github.com/yisier/nps","1","1","N/A","N/A","9","10","2674","327","2025-04-17T09:43:50Z","2022-09-14T06:24:00Z","63356" +"*yogeshojha/rengine*",".{0,1000}yogeshojha\/rengine.{0,1000}","offensive_tool_keyword","rengine","reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines recon data correlation and organization continuous monitoring backed by a database and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with","T1595.003 - T1590.002 - T1083 - T1071","TA0007 - TA0005 - TA0043","N/A","N/A","Reconnaissance","https://github.com/yogeshojha/rengine","1","1","N/A","N/A","N/A","10","7866","1195","2025-02-24T01:03:27Z","2020-05-03T12:13:12Z","63363" +"*YOLOP0wn/POSTDump*",".{0,1000}YOLOP0wn\/POSTDump.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection.","T1003.001 - T1055 - T1564.001","TA0005 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","1","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","63365" +"*You_spin_me__round.ino*",".{0,1000}You_spin_me__round\.ino.{0,1000}","offensive_tool_keyword","Pateensy","payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy","T1056.001 - T1200 - T1036 - T1071","TA0002 - TA0005 - TA0011 - TA0006","N/A","N/A","Exploitation tool","https://github.com/screetsec/Pateensy","1","1","N/A","N/A","N/A","2","143","60","2017-01-26T12:02:56Z","2016-03-21T07:29:38Z","63379" +"*youhacker55/PayGen*",".{0,1000}youhacker55\/PayGen.{0,1000}","offensive_tool_keyword","PayGen","FUD metasploit Persistence RAT","T1059.001 - T1209 - T1105 - T1547 - T1027","TA0003 - TA0005 - TA0002 - TA0011","N/A","N/A","Persistence","https://github.com/youhacker55/PayGen","1","1","N/A","N/A","N/A","1","4","0","2023-02-23T00:05:57Z","2021-06-16T20:20:55Z","63381" +"*yo-yo-yo-jbo/hotkeyz*",".{0,1000}yo\-yo\-yo\-jbo\/hotkeyz.{0,1000}","offensive_tool_keyword","hotkeyz","Hotkey-based keylogger for Windows","T1056.001","TA0006 - TA0009","N/A","N/A","Sniffing & Spoofing","https://github.com/yo-yo-yo-jbo/hotkeyz","1","1","N/A","N/A","9","1","21","1","2024-10-17T17:50:19Z","2024-06-03T21:23:16Z","63399" +"*ysoserial-*.zip",".{0,1000}ysoserial\-.{0,1000}\.zip","offensive_tool_keyword","ysoserial.net","Deserialization payload generator for a variety of .NET formatters","T1059.007 - T1027.002 - T1059.001","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/pwntester/ysoserial.net","1","1","N/A","N/A","10","10","3385","493","2024-12-23T20:59:47Z","2017-09-18T17:48:08Z","63402" +"*ysoserial.exe*",".{0,1000}ysoserial\.exe.{0,1000}","offensive_tool_keyword","arsenal","Arsenal is just a quick inventory and launcher for hacking programs","T1596 - T1587","TA0042 - TA0001","N/A","N/A","Exploitation tool","https://github.com/Orange-Cyberdefense/arsenal","1","1","N/A","commands cheat sheets","8","10","3399","511","2024-11-29T14:48:20Z","2020-09-02T13:24:50Z","63403" +"*ysoserial.exe*",".{0,1000}ysoserial\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Beacon Object File implementation of Event Viewer deserialization UAC bypass","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/netero1010/TrustedPath-UACBypass-BOF","1","1","N/A","N/A","10","10","133","40","2021-08-16T07:49:55Z","2021-08-07T03:40:33Z","63404" +"*ysoserial.exe*",".{0,1000}ysoserial\.exe\s.{0,1000}","offensive_tool_keyword","ysoserial.net","Deserialization payload generator for a variety of .NET formatters","T1059.007 - T1027.002 - T1059.001","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/pwntester/ysoserial.net","1","1","N/A","N/A","10","10","3385","493","2024-12-23T20:59:47Z","2017-09-18T17:48:08Z","63405" +"*ysoserial.net*",".{0,1000}ysoserial\.net.{0,1000}","offensive_tool_keyword","ysoserial.net","Deserialization payload generator for a variety of .NET formatters","T1059.007 - T1027.002 - T1059.001","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/pwntester/ysoserial.net","1","1","N/A","N/A","10","10","3385","493","2024-12-23T20:59:47Z","2017-09-18T17:48:08Z","63406" +"*ysoserial.sln*",".{0,1000}ysoserial\.sln.{0,1000}","offensive_tool_keyword","ysoserial.net","Deserialization payload generator for a variety of .NET formatters","T1059.007 - T1027.002 - T1059.001","TA0005 - TA0040","N/A","N/A","Exploitation tool","https://github.com/pwntester/ysoserial.net","1","1","N/A","N/A","10","10","3385","493","2024-12-23T20:59:47Z","2017-09-18T17:48:08Z","63407" +"*ytisf/PyExfil*",".{0,1000}ytisf\/PyExfil.{0,1000}","offensive_tool_keyword","PyExfil","A Python Package for Data Exfiltration","T1041 - T1567 - T1027","TA0011 - TA0009 - TA0002","N/A","N/A","Data Exfiltration","https://github.com/ytisf/PyExfil","1","1","N/A","N/A","10","8","782","141","2024-05-07T07:58:02Z","2014-11-27T19:06:24Z","63408" +"*ytmrdnutyd5drtny.azurewebsites.net*",".{0,1000}ytmrdnutyd5drtny\.azurewebsites\.net.{0,1000}","offensive_tool_keyword","PeriscopeC2","walmart's C2 - complete adversarial operations toolkit (C2 - stagers - agents - automated ephemeral redirectors and task runners - a complete phishing engine)","T1071 - T1105 - T1090 - T1568 - T1204 - T1566 - T1059","TA0011 - TA0010 - TA0008 - TA0002 - TA0001","N/A","N/A","C2","https://github.com/malcomvetter/Periscope","1","1","N/A","N/A","9","","N/A","","","","63409" +"*yunuscadirci/CallStranger*",".{0,1000}yunuscadirci\/CallStranger.{0,1000}","offensive_tool_keyword","POC","Vulnerability checker for Callstranger (CVE-2020-12695). An attacker can use this vulnerability for Bypassing DLP for exfiltrating data. Using millions of Internet-facing UPnP device as source of amplified reflected TCP DDoS / SYN Flood? Scanning internal ports from Internet facing UPnP devices This script only simulates data exfiltration","T1046 - T1595 - T1587","TA0001 - TA0002 - TA0009","N/A","N/A","Exploitation tool","https://github.com/yunuscadirci/CallStranger","1","1","N/A","N/A","N/A","5","403","63","2021-08-07T16:48:55Z","2020-06-08T07:37:49Z","63412" +"*YwBhAGwAYwA=*",".{0,1000}YwBhAGwAYwA\=.{0,1000}","offensive_tool_keyword","cobaltstrike","Ladon is a large-scale intranet penetration tool. which can be modularized by PowerShell. plugged in CS. loaded in memory and has no file scanning","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","Ghost Ransomware","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/k8gege/Ladon","1","1","N/A","N/A","10","10","5025","880","2025-03-24T13:53:59Z","2019-11-02T06:22:41Z","63414" +"*z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion*",".{0,1000}z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","63421" +"*Z4nzu/hackingtool*",".{0,1000}Z4nzu\/hackingtool.{0,1000}","offensive_tool_keyword","hackingtool","ALL IN ONE Hacking Tool For Hackers","T1059 - T1078 - T1105 - T1110 - T1566","TA0002 - TA0008 - TA0009 - TA0005 - TA0007","N/A","N/A","Exploitation tool","https://github.com/Z4nzu/hackingtool","1","1","N/A","N/A","N/A","10","52217","5629","2025-03-03T15:17:19Z","2020-04-11T09:21:31Z","63422" +"*z6vidveub2ypo3d3x7omsmcxqwxkkmvn5y3paoufyd2tt4bfbkg33kid.onion*",".{0,1000}z6vidveub2ypo3d3x7omsmcxqwxkkmvn5y3paoufyd2tt4bfbkg33kid\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","63423" +"*zabbix_session_exp.py*",".{0,1000}zabbix_session_exp\.py.{0,1000}","offensive_tool_keyword","POC","POC exploitaiton of zabbix saml bypass exp vulnerability cve-2022-23131 (Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML)","T1548 - T1190","TA0001 - TA0002","N/A","N/A","Exploitation tool","https://github.com/Mr-xn/cve-2022-23131","1","1","N/A","N/A","N/A","2","151","47","2024-08-11T18:14:56Z","2022-02-18T11:51:47Z","63428" +"*zblurx/certsync*",".{0,1000}zblurx\/certsync.{0,1000}","offensive_tool_keyword","certsync","Dump NTDS with golden certificates and UnPAC the hash","T1553.002 - T1003.001 - T1145 - T1649","TA0002 - TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/zblurx/certsync","1","1","N/A","N/A","10","7","633","66","2024-03-20T10:58:15Z","2023-01-31T15:37:12Z","63434" +"*zblurx/dploot*",".{0,1000}zblurx\/dploot.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","63435" +"*zcgonvh/DCOMPotato*",".{0,1000}zcgonvh\/DCOMPotato.{0,1000}","offensive_tool_keyword","DCOMPotato","Service DCOM Object and SeImpersonatePrivilege abuse.","T1548.002 - T1134.002","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/zcgonvh/DCOMPotato","1","1","N/A","N/A","10","4","356","48","2022-12-09T01:57:53Z","2022-12-08T14:56:13Z","63436" +"*ze677xuzard4lx4iul2yzf5ks4gqqzoulgj5u4n5n4bbbsxjbfr7eayd.onion*",".{0,1000}ze677xuzard4lx4iul2yzf5ks4gqqzoulgj5u4n5n4bbbsxjbfr7eayd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","63437" +"*zed2john.py*",".{0,1000}zed2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","63438" +"*zenoss_3x_command_execution*",".{0,1000}zenoss_3x_command_execution.{0,1000}","offensive_tool_keyword","beef","BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.","T1201 - T1505.003","TA0001 - TA0002","N/A","Rocket Kitten","Framework","https://github.com/beefproject/beef","1","1","N/A","N/A","8","10","10174","2256","2025-04-22T14:01:20Z","2011-11-23T06:53:25Z","63441" +"*zeonrefpbompx6rwdqa5hxgtp2cxgfmoymlli3azoanisze33pp3x3yd.onion*",".{0,1000}zeonrefpbompx6rwdqa5hxgtp2cxgfmoymlli3azoanisze33pp3x3yd\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","63442" +"*zephrax/linux-pam-backdoor*",".{0,1000}zephrax\/linux\-pam\-backdoor.{0,1000}","offensive_tool_keyword","linux-pam-backdoor","Linux PAM Backdoor","T1547.001 - T1556.003","TA0003 - TA0004","N/A","N/A","Persistence","https://github.com/zephrax/linux-pam-backdoor","1","1","#linux","N/A","10","4","328","85","2023-11-13T11:29:44Z","2017-06-08T21:14:34Z","63443" +"*ZephrFish/ADFSDump-PS*",".{0,1000}ZephrFish\/ADFSDump\-PS.{0,1000}","offensive_tool_keyword","ADFSDump-PS","ADFSDump to assist with GoldenSAML","T1078 - T1552.004 - T1558.004","TA0006 ","N/A","N/A","Credential Access","https://github.com/ZephrFish/ADFSDump-PS","1","1","N/A","N/A","10","1","31","8","2024-05-20T00:00:19Z","2024-05-19T00:46:28Z","63444" +"*ZephrFish/Stompy*",".{0,1000}ZephrFish\/Stompy.{0,1000}","offensive_tool_keyword","Stompy","Timestomp Tool to flatten MAC times with a specific timestamp","T1070.006","TA0005","N/A","N/A","Defense Evasion","https://github.com/ZephrFish/Stompy","1","1","N/A","N/A","10","1","46","6","2023-10-15T17:38:23Z","2023-10-14T23:40:32Z","63445" +"*zer0condition/mhydeath*",".{0,1000}zer0condition\/mhydeath.{0,1000}","offensive_tool_keyword","mhydeath","Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.","T1562.001","TA0040 - TA0005","N/A","Black Basta","Defense Evasion","https://github.com/zer0condition/mhydeath","1","1","N/A","N/A","10","4","397","71","2023-08-22T08:01:04Z","2023-08-22T07:15:36Z","63446" +"*zer0condition/ZeroHVCI*",".{0,1000}zer0condition\/ZeroHVCI.{0,1000}","offensive_tool_keyword","ZeroHVCI","Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229","T1068 - T1564 - T1014 - T1499","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/zer0condition/ZeroHVCI","1","1","N/A","N/A","7","2","198","43","2024-10-26T17:08:38Z","2024-07-20T07:29:18Z","63447" +"*zeroday-powershell*",".{0,1000}zeroday\-powershell.{0,1000}","offensive_tool_keyword","zeroday-powershell","This will exploit the Windows operating system allowing you to modify the file Some.dll.","T1203 - T1574.001 - T1546.011","TA0002 - TA0007 - TA0008","N/A","N/A","Exploitation tool","https://github.com/OneLogicalMyth/zeroday-powershell","1","1","N/A","N/A","N/A","4","326","86","2018-09-12T09:03:04Z","2018-09-10T16:34:14Z","63448" +"*zerologon.py*",".{0,1000}zerologon\.py.{0,1000}","offensive_tool_keyword","POC","Zerologon CVE exploitation","T1210 - T1071","TA0008 - TA0006","N/A","N/A","Exploitation tool","https://github.com/michaelpoznecki/zerologon","1","1","N/A","N/A","N/A","1","10","4","2020-09-15T16:31:59Z","2020-09-15T05:32:24Z","63450" +"*zerologon.x64*",".{0,1000}zerologon\.x64.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF zerologon exploit","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/ZeroLogon-BOF","1","1","N/A","N/A","10","10","158","37","2022-04-25T11:22:45Z","2020-09-17T02:07:13Z","63451" +"*zerologon.x86*",".{0,1000}zerologon\.x86.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF zerologon exploit","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/ZeroLogon-BOF","1","1","N/A","N/A","10","10","158","37","2022-04-25T11:22:45Z","2020-09-17T02:07:13Z","63452" +"*zerologon_check*",".{0,1000}zerologon_check.{0,1000}","offensive_tool_keyword","linWinPwn","linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks","T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016","TA0007 - TA0009 - TA0003 - TA0002 - TA0005","N/A","Black Basta","Discovery","https://github.com/lefayjey/linWinPwn","1","1","#linux","N/A","10","10","1953","283","2025-04-15T14:51:50Z","2021-12-16T22:13:10Z","63453" +"*ZeroLogon-BOF*",".{0,1000}ZeroLogon\-BOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Cobalt Strike BOF zerologon exploit","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/rsmudge/ZeroLogon-BOF","1","1","N/A","N/A","10","10","158","37","2022-04-25T11:22:45Z","2020-09-17T02:07:13Z","63454" +"*ZeroMemoryEx/Amsi-Killer*",".{0,1000}ZeroMemoryEx\/Amsi\-Killer.{0,1000}","offensive_tool_keyword","Amsi-Killer","Lifetime AMSI bypass","T1562.001","TA0005","N/A","N/A","Defense Evasion","https://github.com/ZeroMemoryEx/Amsi-Killer","1","1","N/A","N/A","10","7","624","90","2023-09-26T00:49:22Z","2023-02-26T19:05:14Z","63457" +"*ZeroMemoryEx/Blackout*",".{0,1000}ZeroMemoryEx\/Blackout.{0,1000}","offensive_tool_keyword","Blackout","kill anti-malware protected processes using BYOVD","T1055 - T1562.001","TA0005 - TA0004","N/A","N/A","Defense Evasion","https://github.com/ZeroMemoryEx/Blackout","1","1","N/A","N/A","N/A","10","935","137","2023-07-21T17:35:09Z","2023-05-25T23:54:21Z","63458" +"*ZeroPointSecurity/BadWindowsService*",".{0,1000}ZeroPointSecurity\/BadWindowsService.{0,1000}","offensive_tool_keyword","BadWindowsService","An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities","T1068 - T1211 - T1050","TA0004 - TA0005","N/A","N/A","Privilege Escalation","https://github.com/eladshamir/BadWindowsService","1","1","N/A","N/A","10","1","58","10","2022-08-25T14:22:25Z","2022-08-19T15:38:05Z","63459" +"*zerosum0x0*",".{0,1000}zerosum0x0.{0,1000}","offensive_tool_keyword","zerosum0x0","github repo username hosting backdoors pocs and exploitation tools","N/A","N/A","N/A","N/A","Exploitation tool","https://github.com/zerosum0x0","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","63461" +"*zerosum0x0*koadic*",".{0,1000}zerosum0x0.{0,1000}koadic.{0,1000}","offensive_tool_keyword","koadic","Koadic. or COM Command & Control. is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire. The major difference is that Koadic does most of its operations using Windows Script Host (a.k.a. JScript/VBScript). with compatibility in the core to support a default installation of Windows 2000 with no service packs (and potentially even versions of NT4) all the way through Windows 10.","T1548.002 - T1071.001 - T1547.001 - T1115 - T1059.001 - T1059.003 - T1059.005 - T1005 - T1573.002 - T1083 - T1564.003 - T1105 - T1046 - T1135 - T1003.002 - T1003.003 - T1055.001 - T1021.001 - T1053.005 - T1218.005 - T1218.010 - T1218.011 - T1082 - T1016 - T1033 - T1569.002 - T1047","TA0004 - TA0011 - TA0003 - TA0008 - TA0002 - TA0009 - TA0010 - TA0005 - TA0006 - TA0007","N/A","PYSA - BlackCat - Black Basta - LockBit - APT28 - LazyScripter - Sidewinder - MuddyWater - FANCY BEAR","C2","https://github.com/offsecginger/koadic","1","1","N/A","N/A","10","10","290","83","2022-01-03T01:07:01Z","2022-01-03T01:05:43Z","63462" +"*zeze-zeze/NamedPipeMaster*",".{0,1000}zeze\-zeze\/NamedPipeMaster.{0,1000}","offensive_tool_keyword","NamedPipeMaster","a tool used to analyze monitor and interact with named pipes - allows dll injection and impersonation","T1055.001 - T1134.001 - T1010 - T1550.002","TA0007 - TA0008 - TA0004 - TA0005","N/A","N/A","Exploitation tool","https://github.com/zeze-zeze/NamedPipeMaster","1","1","N/A","N/A","9","2","161","15","2024-10-27T05:24:11Z","2024-08-23T02:03:44Z","63463" +"*zha0gongz1/DesertFox*",".{0,1000}zha0gongz1\/DesertFox.{0,1000}","offensive_tool_keyword","cobaltstrike","Implement load Cobalt Strike & Metasploit&Sliver shellcode with golang","T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047","TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","C2","https://github.com/zha0gongz1/DesertFox","1","1","N/A","N/A","10","10","125","26","2023-02-02T07:02:12Z","2021-02-04T09:04:13Z","63467" +"*Ziconius/FudgeC2*",".{0,1000}Ziconius\/FudgeC2.{0,1000}","offensive_tool_keyword","FudgeC2","FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.","T1021.002 - T1105 - T1059.001 - T1059.003","TA0008 - TA0011 - TA0002","N/A","N/A","C2","https://github.com/Ziconius/FudgeC2","1","1","N/A","N/A","10","10","253","54","2023-05-01T21:13:56Z","2018-09-09T21:05:21Z","63468" +"*ZipExec/Cryptor*",".{0,1000}ZipExec\/Cryptor.{0,1000}","offensive_tool_keyword","ZipExec","A unique technique to execute binaries from a password protected zip","T1560.001 - T1204.002 - T1059.005","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Tylous/ZipExec","1","1","N/A","N/A","9","10","1026","153","2022-07-01T16:25:26Z","2021-10-19T21:03:44Z","63472" +"*ZipExec/Loader*",".{0,1000}ZipExec\/Loader.{0,1000}","offensive_tool_keyword","ZipExec","A unique technique to execute binaries from a password protected zip","T1560.001 - T1204.002 - T1059.005","TA0005 - TA0002","N/A","N/A","Defense Evasion","https://github.com/Tylous/ZipExec","1","1","N/A","N/A","9","10","1026","153","2022-07-01T16:25:26Z","2021-10-19T21:03:44Z","63473" +"*zippy.nim*",".{0,1000}zippy\.nim.{0,1000}","offensive_tool_keyword","nimplant","A light-weight first-stage C2 implant written in Nim","T1059-001 - T1027 - T1036","TA0002 - TA0005 - TA0002","N/A","Black Basta","C2","https://github.com/chvancooten/NimPlant","1","1","N/A","N/A","10","10","871","111","2025-03-28T18:53:57Z","2023-02-13T13:42:39Z","63475" +"*zjoxyw5mkacojk5ptn2iprkivg5clow72mjkyk5ttubzxprjjnwapkad.onion*",".{0,1000}zjoxyw5mkacojk5ptn2iprkivg5clow72mjkyk5ttubzxprjjnwapkad\.onion.{0,1000}","offensive_tool_keyword","ransomware_notes","detection patterns retrieved in ransomware notes archives","T1486","TA0040","N/A","N/A","Ransomware","https://github.com/threatlabz/ransomware_notes","1","1","N/A","N/A","10","4","354","55","2025-04-04T19:06:04Z","2022-08-01T15:14:59Z","63476" +"*zMarch/Orc*",".{0,1000}zMarch\/Orc.{0,1000}","offensive_tool_keyword","Orc","Orc is a post-exploitation framework for Linux written in Bash","T1059.004 - T1036.005 - T1070.002 - T1012 - T1082 - T1003 - T1555.003 - T1049 - T1134.001 - T1202","TA0005 - TA0003 - TA0002 - TA0006 - TA0011","N/A","N/A","Exploitation tool","https://github.com/zMarch/Orc","1","1","#linux","N/A","9","4","395","53","2019-11-12T18:21:27Z","2018-08-16T11:31:39Z","63479" +"*zs5460/portscan*",".{0,1000}zs5460\/portscan.{0,1000}","offensive_tool_keyword","portscan","A simple TCP and UDP portscanner written in Go","T1595 - T1596 - T1594","TA0007 - TA0009","N/A","N/A","Discovery","https://github.com/zs5460/portscan","1","1","N/A","N/A","N/A","1","14","4","2022-11-11T09:26:47Z","2019-06-04T09:00:00Z","63507" +"*zsploit-1.txt*",".{0,1000}zsploit\-1\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","63511" +"*zsploit-2.txt*",".{0,1000}zsploit\-2\.txt.{0,1000}","offensive_tool_keyword","metasploit","Metasploit is a widely-used. open-source framework designed for penetration testing. vulnerability assessment. and exploit development. It provides security professionals and researchers with a comprehensive platform to discover. exploit. and validate vulnerabilities in computer systems and networks. Metasploit includes a large database of pre-built exploits. payloads. and auxiliary modules that can be used to test various attack vectors. identify security weaknesses. and simulate real-world cyberattacks. By utilizing Metasploit. security teams can better understand potential threats and improve their overall security posture.","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","63512" +"*ztgrace*changeme*",".{0,1000}ztgrace.{0,1000}changeme.{0,1000}","offensive_tool_keyword","changeme","A default credential scanner.","T1110 - T1114 - T1112 - T1056","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/ztgrace/changeme","1","1","N/A","N/A","N/A","10","1478","251","2021-12-26T10:20:11Z","2016-03-11T17:10:34Z","63513" +"*zyn3rgy/LdapRelayScan*",".{0,1000}zyn3rgy\/LdapRelayScan.{0,1000}","offensive_tool_keyword","LdapRelayScan","Check for LDAP protections regarding the relay of NTLM authentication","T1557","TA0001 - TA0006","N/A","N/A","Reconnaissance","https://github.com/zyn3rgy/LdapRelayScan","1","1","N/A","N/A","8","5","492","70","2024-11-19T21:11:53Z","2022-01-16T06:50:44Z","63518" +"*zzzteph/weakpass*",".{0,1000}zzzteph\/weakpass.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","63519" +"nanodump*","nanodump.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","63581" +"pandasec888/taowu-cobalt_strike","pandasec888\/taowu\-cobalt_strike","offensive_tool_keyword","taowu-cobalt-strike","Collection of hacktools binaries","T1003 - T1059 - T1087 - T1110 - T1135 - T1047 - T1078 - T1086 - T1098 - T1212 - T1021 - T1056 - T1071 - T1210 - T1484 - T1555 - T1055 - T1005 - T1090 - T1080 - T1204 - T1496 - T1114 - T1562 - T1482 - T1505 - T1548 - T1560 - T1566 - T1218 - T1547 - T1070 - T1206 - T1208","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011","N/A","N/A","Exploitation tool","https://github.com/pandasec888/taowu-cobalt_strike/tree/312fec79b3413ecfc06bc43efccfcbc1383a3566","1","1","N/A","N/A","10","10","1797","330","2023-10-31T09:13:10Z","2020-07-05T10:13:00Z","63587" +"*/agents/bin/minidump.exe*",".{0,1000}\/agents\/bin\/minidump\.exe.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63622" +"*/bin/ntdsdump.elf*",".{0,1000}\/bin\/ntdsdump\.elf.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63623" +"*/bin/samdump.elf*",".{0,1000}\/bin\/samdump\.elf.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63624" +"*/c2VuePlugin.js*",".{0,1000}\/c2VuePlugin\.js.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63625" +"*/DeimosC2.git*",".{0,1000}\/DeimosC2\.git.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63627" +"*/DeimosC2/releases/download/*",".{0,1000}\/DeimosC2\/releases\/download\/.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63628" +"*/DeimosC2/releases/tag/*",".{0,1000}\/DeimosC2\/releases\/tag\/.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63629" +"*/DeimosC2/tarball/*",".{0,1000}\/DeimosC2\/tarball\/.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63630" +"*/DeimosC2/zipball/*",".{0,1000}\/DeimosC2\/zipball\/.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63631" +"*/lsadump.elf*",".{0,1000}\/lsadump\.elf.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63632" +"*/lsadump.exe*",".{0,1000}\/lsadump\.exe.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63633" +"*/lsassparse.py*",".{0,1000}\/lsassparse\.py.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63634" +"*/ntdsdump.exe*",".{0,1000}\/ntdsdump\.exe.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63636" +"*/ondisk_dropper_tcp.pl*",".{0,1000}\/ondisk_dropper_tcp\.pl.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63637" +"*/ondisk_dropper_tcp.ps1*",".{0,1000}\/ondisk_dropper_tcp\.ps1.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63638" +"*/ondisk_dropper_tcp.py*",".{0,1000}\/ondisk_dropper_tcp\.py.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63639" +"*/ondisk_dropper_tcp.sh*",".{0,1000}\/ondisk_dropper_tcp\.sh.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63640" +"*/samdump.exe*",".{0,1000}\/samdump\.exe.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63641" +"*/screengrab.elf*",".{0,1000}\/screengrab\.elf.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63642" +"*/screengrab.exe*",".{0,1000}\/screengrab\.exe.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63643" +"*/server/bin/minidump.elf*",".{0,1000}\/server\/bin\/minidump\.elf.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63644" +"*/server/bin/minidump.exe*",".{0,1000}\/server\/bin\/minidump\.exe.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63645" +"*/shadowdump.elf*",".{0,1000}\/shadowdump\.elf.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63646" +"*/shadowdump.exe*",".{0,1000}\/shadowdump\.exe.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63647" +"*/TCPAgent_Win_32_ARM.exe*",".{0,1000}\/TCPAgent_Win_32_ARM\.exe.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63648" +"*/TCPAgent_Win_32_Intel.exe*",".{0,1000}\/TCPAgent_Win_32_Intel\.exe.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63649" +"*/TCPAgent_Win_64_ARM.exe*",".{0,1000}\/TCPAgent_Win_64_ARM\.exe.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63650" +"*/TCPAgent_Win_64_Intel.exe*",".{0,1000}\/TCPAgent_Win_64_Intel\.exe.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63651" +"*deimos-server.ataplatform.io*",".{0,1000}deimos\-server\.ataplatform\.io.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63695" +"*DeimosC2_darwin.zip*",".{0,1000}DeimosC2_darwin\.zip.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63696" +"*DeimosC2_linux.zip*",".{0,1000}DeimosC2_linux\.zip.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63697" +"*DeimosC2_windows.zip*",".{0,1000}DeimosC2_windows\.zip.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63698" +"*DeimosC2/DeimosC2*",".{0,1000}DeimosC2\/DeimosC2.{0,1000}","offensive_tool_keyword","deimosc2","DeimosC2 is a Golang command and control framework for post-exploitation.","T1573-001 - T1573-002 - T1572 - T1008 - T1071 - T1090-001 - T1090-004 - T1090-007","TA0011","N/A","N/A","C2","https://github.com/DeimosC2/DeimosC2","1","1","N/A","N/A","10","10","1113","162","2025-04-17T17:49:44Z","2020-06-30T19:24:13Z","63699" +"*.sharepoint.com*pD9-tk*",".{0,1000}\.sharepoint\.com.{0,1000}pD9\-tk.{0,1000}","offensive_tool_keyword","GraphStrike","Cobalt Strike HTTPS beaconing over Microsoft Graph API - default string in file names https://x.com/Octoberfest73/status/1896596953632526504","T1102 - T1071.001 ","TA0002 - TA0005 - TA0011","N/A","Black Basta","C2","https://github.com/RedSiege/GraphStrike","1","1","N/A","https://redsiege.com/blog/2024/01/graphstrike-developer/","10","10","585","95","2024-06-25T11:18:19Z","2024-01-02T00:18:44Z","63708" +"*www.netexec.wiki*",".{0,1000}www\.netexec\.wiki.{0,1000}","offensive_tool_keyword","Netexec","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1021 - T1087 - T1135","TA0008 - TA0007 - TA0009","N/A","N/A","Lateral Movement","N/A","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","63715" +"*aircrack-ng.org*",".{0,1000}aircrack\-ng\.org.{0,1000}","offensive_tool_keyword","aircrack","Wi-Fi password cracking tool used for capturing and cracking WEP and WPA-PSK keys","T1557.002 - T1040","TA0006 - TA0009","N/A","N/A","Credential Access","N/A","1","1","N/A","N/A","8","8","N/A","N/A","N/A","N/A","63716" +"*enum4linux/enum4linux*",".{0,1000}enum4linux\/enum4linux.{0,1000}","offensive_tool_keyword","enum4linux","Enum4linux is a tool for enumerating information from Windows and Samba systems. It attempts to offer similar functionality to enum.exe ","T1018 - T1087.002 - T1135 - T1049 - T1033","TA0007 - TA0009","N/A","N/A","Reconnaissance","https://github.com/CiscoCXSecurity/enum4linux","1","1","#linux","N/A","10","10","1260","243","2024-10-11T14:41:57Z","2015-07-31T21:06:03Z","63723" +"*crackstation.net*",".{0,1000}crackstation\.net.{0,1000}","offensive_tool_keyword","crackstation","online password hash cracking tool that uses a large precomputed lookup table (rainbow table) to recover plaintext passwords from their hash values - commonly used to crack credentials after hash extraction.","T1110.002 - T1111 - T1555","TA0006 - TA0008","N/A","N/A","Credential Access","https://crackstation.net/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","63726" +"*assets.bishopfox.com*",".{0,1000}assets\.bishopfox\.com.{0,1000}","offensive_tool_keyword","sliver","hosts a variety of offensive security tools","T1059 - T1105 - T1027 - T1090.001 - T1071.001 - T1219 - T1053.005 - T1547.001","TA0002 - TA0005 - TA0011 - TA0003 - TA0008","N/A","N/A","C2","bishopfox.com","1","1","N/A","N/A","8","10","N/A","N/A","N/A","N/A","63727" +"*opt.rapid7.com*",".{0,1000}opt\.rapid7\.com.{0,1000}","offensive_tool_keyword","metasploit","opt.rapid7.com is associated with Rapid7 Metasploit Framework and other security tools used for offensive security","T1001 - T1021 - T1024 - T1033 - T1047 - T1075 - T1059 - T1064 - T1090 - T1204 -T1210 - T1218","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0011 - TA0010 - TA0040","N/A","FANCY BEAR - EMBER BEAR - Sandworm - Turla - MAZE - LockBit - Bassterlord* - Conti - Hive - Fog - Black Basta - MoneyTaker - INDRIK SPIDER - APT39 - GOLD DUPONT - Common Raven","Framework","https://github.com/rapid7/metasploit-framework","1","1","N/A","N/A","10","10","35400","14272","2025-04-22T20:14:59Z","2011-08-30T06:13:20Z","63728" +"*pentest-tools.com*",".{0,1000}pentest\-tools\.com.{0,1000}","offensive_tool_keyword","pentest-tools","cloud-based offensive security platform offering a wide range of automated penetration testing utilities","T1595.002 - T1046 - T1083 - T1059 - T1190 - T1203","TA0007 - TA0001 - TA0002","N/A","N/A","Collection","pentest-tools.com","1","1","N/A","N/A","7","9","N/A","N/A","N/A","N/A","63729" +"*swisskyrepo.github.io*",".{0,1000}swisskyrepo\.github\.io.{0,1000}","offensive_tool_keyword","pentest-tools","cloud-based offensive security platform offering a wide range of automated penetration testing utilities","T1595.002 - T1046 - T1083 - T1059 - T1190 - T1203","TA0007 - TA0001 - TA0002","N/A","N/A","Collection","N/A","1","1","N/A","N/A","7","9","N/A","N/A","N/A","N/A","63730" +"*/SSH-Stealer.git*",".{0,1000}\/SSH\-Stealer\.git.{0,1000}","offensive_tool_keyword","SSH-Stealer","Smart keylogging capability to steal SSH Credentials including password & Private Key","T1056.001 - T1552.004 - T1556.004 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/DarkSpaceSecurity/SSH-Stealer","1","1","N/A","N/A","2","2","125","22","2025-03-26T04:23:00Z","2025-03-16T01:24:58Z","63736" +"*DarkSpaceSecurity/SSH-Stealer*",".{0,1000}DarkSpaceSecurity\/SSH\-Stealer.{0,1000}","offensive_tool_keyword","SSH-Stealer","Smart keylogging capability to steal SSH Credentials including password & Private Key","T1056.001 - T1552.004 - T1556.004 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/DarkSpaceSecurity/SSH-Stealer","1","1","N/A","N/A","2","2","125","22","2025-03-26T04:23:00Z","2025-03-16T01:24:58Z","63737" +"*sshKeylogger.*",".{0,1000}sshKeylogger\..{0,1000}","offensive_tool_keyword","SSH-Stealer","Smart keylogging capability to steal SSH Credentials including password & Private Key","T1056.001 - T1552.004 - T1556.004 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/DarkSpaceSecurity/SSH-Stealer","1","1","N/A","N/A","2","2","125","22","2025-03-26T04:23:00Z","2025-03-16T01:24:58Z","63739" +"*/sshKeylogger/*",".{0,1000}\/sshKeylogger\/.{0,1000}","offensive_tool_keyword","SSH-Stealer","Smart keylogging capability to steal SSH Credentials including password & Private Key","T1056.001 - T1552.004 - T1556.004 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/DarkSpaceSecurity/SSH-Stealer","1","1","N/A","N/A","2","2","125","22","2025-03-26T04:23:00Z","2025-03-16T01:24:58Z","63740" +"*/SharpPSLoader.git*",".{0,1000}\/SharpPSLoader\.git.{0,1000}","offensive_tool_keyword","SharpPSLoader","Simple .NET loader for loading and executing Powershell payloads","T1059.001 - T1562.001 - T1027 - T1055 - T1216","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/ChoiSG/SharpPSLoader","1","1","N/A","N/A","6","1","16","5","2021-11-05T01:35:10Z","2021-10-05T04:02:29Z","63744" +"*ChoiSG/SharpPSLoader*",".{0,1000}ChoiSG\/SharpPSLoader.{0,1000}","offensive_tool_keyword","SharpPSLoader","Simple .NET loader for loading and executing Powershell payloads","T1059.001 - T1562.001 - T1027 - T1055 - T1216","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/ChoiSG/SharpPSLoader","1","1","N/A","N/A","6","1","16","5","2021-11-05T01:35:10Z","2021-10-05T04:02:29Z","63745" +"*SharpPSLoader.exe*",".{0,1000}SharpPSLoader\.exe.{0,1000}","offensive_tool_keyword","SharpPSLoader","Simple .NET loader for loading and executing Powershell payloads","T1059.001 - T1562.001 - T1027 - T1055 - T1216","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/ChoiSG/SharpPSLoader","1","1","N/A","N/A","6","1","16","5","2021-11-05T01:35:10Z","2021-10-05T04:02:29Z","63746" +"*SharpPSLoaderConsole.exe*",".{0,1000}SharpPSLoaderConsole\.exe.{0,1000}","offensive_tool_keyword","SharpPSLoader","Simple .NET loader for loading and executing Powershell payloads","T1059.001 - T1562.001 - T1027 - T1055 - T1216","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/ChoiSG/SharpPSLoader","1","1","N/A","N/A","6","1","16","5","2021-11-05T01:35:10Z","2021-10-05T04:02:29Z","63747" +"*Invoke-SingleByteXOR*",".{0,1000}Invoke\-SingleByteXOR.{0,1000}","offensive_tool_keyword","SharpPSLoader","Simple .NET loader for loading and executing Powershell payloads","T1059.001 - T1562.001 - T1027 - T1055 - T1216","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/ChoiSG/SharpPSLoader","1","1","N/A","N/A","6","1","16","5","2021-11-05T01:35:10Z","2021-10-05T04:02:29Z","63752" +"*Invoke-Bloodhound*",".{0,1000}Invoke\-Bloodhound.{0,1000}","offensive_tool_keyword","SharpPSLoader","Simple .NET loader for loading and executing Powershell payloads","T1059.001 - T1562.001 - T1027 - T1055 - T1216","TA0002 - TA0005","N/A","N/A","Defense Evasion","https://github.com/ChoiSG/SharpPSLoader","1","1","N/A","N/A","6","1","16","5","2021-11-05T01:35:10Z","2021-10-05T04:02:29Z","63753" +"*/Chrome-Password-Recovery.git*",".{0,1000}\/Chrome\-Password\-Recovery\.git.{0,1000}","offensive_tool_keyword","Chrome-Password-Recovery","recover Google Chrome Logins","T1555.003 - T1005 - T1027","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/SaturnsVoid/Chrome-Password-Recovery","1","1","N/A","N/A","8","1","75","31","2021-02-05T00:36:39Z","2017-04-07T17:32:27Z","63758" +"*SaturnsVoid/Chrome-Password-Recovery*",".{0,1000}SaturnsVoid\/Chrome\-Password\-Recovery.{0,1000}","offensive_tool_keyword","Chrome-Password-Recovery","recover Google Chrome Logins","T1555.003 - T1005 - T1027","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/SaturnsVoid/Chrome-Password-Recovery","1","1","N/A","N/A","8","1","75","31","2021-02-05T00:36:39Z","2017-04-07T17:32:27Z","63759" +"*Chrome Password Recovery.go*",".{0,1000}Chrome\sPassword\sRecovery\.go.{0,1000}","offensive_tool_keyword","Chrome-Password-Recovery","recover Google Chrome Logins","T1555.003 - T1005 - T1027","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/SaturnsVoid/Chrome-Password-Recovery","1","1","N/A","N/A","8","1","75","31","2021-02-05T00:36:39Z","2017-04-07T17:32:27Z","63760" +"*Aur3ns/lsassStealer*",".{0,1000}Aur3ns\/lsassStealer.{0,1000}","offensive_tool_keyword","Morpheus","Morpheus is a memory dumper that extracts lsass.exe in RAM and exfiltrates it via forged NTP packets","T1003.001 - T1043 - T1041 - T1027","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/Aur3ns/lsassStealer","1","1","N/A","N/A","8","1","89","15","2025-04-05T17:35:13Z","2024-12-15T16:02:49Z","63762" +"*Aur3ns/Morpheus*",".{0,1000}Aur3ns\/Morpheus.{0,1000}","offensive_tool_keyword","Morpheus","Morpheus is a memory dumper that extracts lsass.exe in RAM and exfiltrates it via forged NTP packets","T1003.001 - T1043 - T1041 - T1027","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/Aur3ns/Morpheus","1","1","N/A","N/A","8","1","89","15","2025-04-05T17:35:13Z","2024-12-15T16:02:49Z","63763"